Addendum on Payment Methods

You, User, Beneficiary

and

GoCredible B.V. (hereinafter referred to as “GoCredible”), a private limited liability company with statutory seat in Amsterdam, registered with the Dutch Chamber of Commerce under number 63715791,

Hereinafter jointly referred to as the Parties.

Recitals:
Whereas:

Definitions
The terms used in this Addendum which are not yet defined in the User Agreement, the Platform Agreement, or the User Terms—or which are relevant for the interpretation of this Addendum—are defined below:

TermDefinition
AcquirerThe card-accepting organization of a Brand
APIThe application provided by GoCredible
BeneficiaryThe party for whose account and risk the payment services are used
Payment SchemeThe owner of a payment method
BrandThe trademark of a payment method
cPSPCollecting Payment Service Provider
CTAPSecure communication protocol
DeviceA mobile communication device used by the payer to initiate payments
PFACAbbreviation for Payment Facilitator
Payment FacilitatorA service provider that processes payments for a Beneficiary on behalf of an Acquirer
PlatformThe organization that has entered into an agreement with GoCredible and the Beneficiary regarding the splitP payment service, and that provides transaction data to GoCredible
Rules & RegulationsThe rules and policies of a Payment Scheme, Acquirer or host
SEPAEuropean standard for payment processing within the Single European Payment Area
SoftPOSA software-based solution allowing card payments to be accepted on a mobile device or tablet
ReversalThe repayment of a successful direct debit transaction at the request of the initiator
Three Party AgreementAn agreement involving the Beneficiary, the Acquirer and GoCredible; also referred to as a Tripartite Agreement

1.         Changes applicable to you
1.1       GoCredible’s services are regularly updated, expanded, and improved. These modifications may include the addition of new payment methods, technical updates, or the involvement of different service providers.

1.2       By signing this Addendum, you agree that its content may be amended from time to time.

1.3       By using any payment method via GoCredible, both the Beneficiary and the Platform agree that the version of the Addendum available online at the time of use shall apply. The current version can be accessed at: https://www.gocredible.nl/addendum_betaalmethoden.

1.4       The Beneficiary must always have a legitimate legal basis for offering a payment method in order to receive funds and must issue a receipt to the payer for each (partial) payment.

1.5       It is strictly prohibited to offer a payment service on behalf of another party. You may not register or allow others to register on your behalf.

2.         Payment Methods Offered
2.1       In accordance with Article 1.5 of the User Agreement, GoCredible provides its payment service using the payment methods agreed upon with the Platform. The Platform may select one or more of the available payment methods offered by GoCredible for the purpose of collecting funds on behalf of the Beneficiary.

2.2       GoCredible offers the following payment methods:

a. Point of Sale (POS)
Acceptance of debit or credit card payments via a CTAP-certified payment terminal:

  1. Maestro & Debit Mastercard
  2. VPAY & VISA Debit
  3. Bancontact Debit Cards
  4. Mastercard Credit Cards
  5. Visa Credit Cards
  6. American Express Credit Cards

b. SoftPOS
Acceptance of debit or credit card payments on an Android device, Android smartphone, or via “Tap to Pay” on iPhone or iPad:

  1. Maestro & Debit Mastercard
  2. VPAY & VISA Debit
  3. Mastercard Credit Card
  4. Visa Credit Card

c. Online Payment Methods
Acceptance of payments where the cardholder is not physically present (e.g., for online purchases, MOTO transactions, and recurring payments):

  1. iDEAL
  2. Online debit and credit card payments including 3D Secure, Apple Pay or Google Pay

d. Bank-Based Payment Methods

  1. Bank transfers such as SCT (SEPA Credit Transfer)
  2. Direct debits such as SDD (SEPA Direct Debit), B2B Direct Debit (for businesses), and CORE Direct Debit (for consumers)

2.3       Not all payment methods are suitable for every type of service. GoCredible reserves the right to refuse activation or availability of certain payment methods.

2.4       Payment services may only be offered within the European Economic Area (EEA) and in countries for which GoCredible has granted prior written approval.

2.5       GoCredible may freely determine how transactions are routed among Acquirers.

3.         Involved Parties and Roles
3.1       GoCredible is a licensed payment service provider, supervised by De Nederlandsche Bank (DNB), and registered under number R130345.

3.2       GoCredible holds the necessary registrations and accreditations with issuers of payment methods and with its partner service providers to be able to offer the payment methods mentioned in this Addendum.

3.2.1    GoCredible is accredited as a Collecting Payment Service Provider (cPSP) with Currence for iDEAL (https://www.ideal.nl/acquirers-en-cpsps).

3.2.2    GoCredible is accredited as an Acceptant Payment Service Provider (aPSP) with the Dutch Payments Association for (POS) debit card transactions (https://www.betaalvereniging.nl).

3.3       GoCredible has entered into acquiring agreements (as Payment Facilitator – PFAC) with Coöperatieve Rabobank U.A., Fiserv (formerly EMS – European Merchant Services B.V.), American Express, and Tintel B.V. (“Tintel”).

3.4       GoCredible is free to choose its Acquirers and may change service providers at its sole discretion, without prior consent from the Platform or the Beneficiary.

3.5       The Beneficiary and the Platform consent to GoCredible sharing information, required documentation and/or agreements with Acquirers and Payment Schemes, including all necessary account information and personal data, to enable such parties to initiate and process payment transactions and fulfil their obligations toward the Beneficiary under their general terms and conditions.

3.6       GoCredible shall only share such data where required under the applicable Rules & Regulations for the purpose of executing payment transactions or to ensure that all parties involved in a payment transaction meet their (legal) obligations.

4.         External Rules and Regulations of Payment Method Owners or Providers
4.1       The external rules and regulations (“Rules & Regulations”) of the respective Payment Method owners and providers apply to GoCredible, the Platform, and the Beneficiary when using the offered payment methods.

4.1.1    For iDEAL, the applicable rules include those issued by Currence. These rules are binding and form an integral part of this Addendum. Users must comply with Currence’s technical and operational requirements, such as the correct implementation of the iDEAL button and the adherence to security guidelines. These requirements can be obtained via Currence or GoCredible. Brand materials can be found at:
https://www.ideal.nl/marketing-idealGoCredible

4.1.2    GoCredible is registered as a PFAC (Payment Facilitator) with Mastercard under PFAC ID 26354. Acceptance of Maestro, Debit Mastercard, and Mastercard is subject to Mastercard’s rules, which are integral to this Addendum. These are available in English at:
https://www.mastercard.us/content/dam/public/mastercardcom/na/global-site/documents/mastercard-bcrs.pdf

4.1.3 GoCredible is registered as a PFAC with Visa under PFAC ID 10081756. Acceptance of VPAY, Visa Debit, and Visa credit cards is subject to Visa’s applicable rules, which are also part of this Addendum. These are available in English at:
https://usa.visa.com/support/consumer/visa-rules.html

4.1.4    GoCredible is registered as a PFAC with American Express. Acceptance of American Express payments is subject to the rules of the AEXP organisation, which form an integral part of this Addendum. These are available at:
https://www.americanexpress.com/content/dam/amex/nl/merchant/pdfs/NL-merchant-terms-and-conditions-2021.pdf

4.1.5    GoCredible is accredited as a payment institution for receiving SEPA credit transfers (SCT) and acts as an Acceptant for SEPA direct debits (SDD) through Rabobank. Rules for acceptance of CORE and B2B direct debit transactions are based on the Dutch Payments Association’s standards, international frameworks, and the General Banking Conditions of Rabobank. SEPA Direct Debit users must comply with rules for mandates, refund rights and European regulatory compliance.

4.1.6 The Bancontact system complies with SEPA requirements. The acceptance of Bancontact is subject to the rules of the Payconiq by Bancontact organisation, forming an integral part of this Addendum. These can be accessed at:
https://www.bancontact.com/nl/hoe-werkt-het/legale-en-administratieve-specificaties

4.2       GoCredible’s acquiring services via Tintel are subject to the general terms and conditions of Tintel (trading as “Pay.”):
https://www.pay.nl/algemene-voorwaarden
By signing this Addendum, the Beneficiary also enters into a Three Party Agreement with Tintel and accepts these terms and conditions.

4.3       GoCredible’s services via Fiserv are subject to Fiserv’s general terms and conditions (https://www.emspay.com/nl/nl/legal/algemene-voorwaarden) and the EMS privacy policy (https://emspay.eu/privacy-information-notice). By signing this Addendum, the Beneficiary also enters into a Three Party Agreement with Fiserv and GoCredible.

4.4       If the Platform or the Beneficiary require support for the implementation of one or more payment methods, or for compliance with applicable rules and guidelines, they may request assistance from the relevant providers or from GoCredible in writing.

4.5       Certain Payment Schemes require the Beneficiary to enter into a direct relationship with the owner of the scheme—either to ensure continuity of payment services or when transaction volume exceeds specified limits. This takes the form of a Three Party Agreement.


5.         Technical Integration & Connectivity
5.1       GoCredible enters into technical agreements with the Platform regarding the integration environment. The Platform does so on behalf of the Beneficiary.

5.2       When retrieving transactions via the API, instructing the API application, or triggering API-related errors, GoCredible applies a fair use policy. In the event of excessive or unnecessary load on the GoCredible application, GoCredible reserves the right to temporarily suspend access to the API and/or to charge additional fees.

5.3       GoCredible is not responsible for the technical functioning or performance of the Platform.


6.         Obligations and Responsibilities
6.1       In addition to Article 10 of the User Agreement, GoCredible specifically draws the attention of the Platform and the Beneficiary to the obligations and responsibilities that fall outside GoCredible’s direct sphere of influence. It is the responsibility of both the Platform and the Beneficiary to inform themselves properly and fully of such obligations. GoCredible is not a party to the contractual relationship between Platform and Beneficiary.

6.2       When a payment method is used, the Beneficiary and the Platform are responsible for complying with all obligations associated with that specific payment method. Non-compliance or insufficient compliance may result in liability for any penalties imposed by the relevant Payment Scheme.

6.3       The Platform shall make every reasonable effort to ensure that the Beneficiary uses the payment services lawfully, and that such services are not used for illegal or fraudulent purposes. The Platform shall also ensure that each Beneficiary’s activities comply with all applicable laws and regulations, and with the obligations under the User Agreement, the User Terms, applicable annexes, and this Addendum.

6.4       The Beneficiary may only offer payments that relate to the business activity agreed with GoCredible prior to concluding the User Agreement.

6.5       The Beneficiary may only offer payments at the location(s) explicitly agreed with GoCredible prior to concluding the User Agreement.

6.6       The country code of the Beneficiary, the terminal, and the host must be identical and correspond to the actual country of operation. If irregularities are detected, fines imposed by Payment Schemes will be charged to GoCredible, and the Beneficiary shall always be liable for reimbursing such fines.

6.7       The Beneficiary must not submit fraudulent, unauthorised, or misleading payment transactions.

6.8       The Beneficiary shall not operate in sectors prohibited by any Payment Scheme.

6.9       The Beneficiary agrees to complete GoCredible’s onboarding process truthfully and in good faith. Creditworthiness checks may form part of the onboarding process.

6.10     The Beneficiary shall provide sufficiently verifiable external information to validate their (online) sales locations and activities, and/or verify any previously submitted information.

6.11 The cardholder must be able to clearly identify where and for what the payment was made. A “statement descriptor” (i.e., the name appearing on the account statement) must be submitted to GoCredible in advance for each payment. The descriptor must allow the cardholder to recognise the source and nature of the transaction.

6.12 The Beneficiary and the Platform must clearly indicate which Brands are accepted. All Brand logos or expressions must be equal in size, placement and visibility. The intellectual property rights in such materials remain with the respective Brand owners.

6.13 The Beneficiary and the Platform must at all times comply with:

7.         Processing of Payment Transactions
7.1       The splitP payment service acts as a conduit: funds are only remitted to the rightful recipient once received and once all applicable conditions for disbursement are met.

7.2       Payment transactions include Refunds, Chargebacks, and Offline Transactions.

7.3       GoCredible may suspend payments in the following cases:

7.4       It is prohibited to process a transaction in which the full amount is paid out in cash to the cardholder. Partial or full cash refunds (commonly referred to as “cashback”) are not supported by GoCredible and are not permitted.

7.5       GoCredible is not liable for delays in the receipt or disbursement of funds or for errors in debit or credit bookings caused by third parties, including but not limited to card networks or financial institutions used by the Beneficiary for banking transactions.

7.6       Refund
7.6.1    In the case of a refund, the Beneficiary instructs GoCredible—via the Platform—to return received funds to the cardholder.

7.6.2    The refund amount shall never exceed the original amount paid for the relevant good or service.

7.6.3    GoCredible may impose software-based limitations on the amount and frequency of refunds where technically possible. However, this may not be feasible for all payment methods. The Beneficiary remains fully responsible and liable for the correct and lawful use of refund functionality, even if the refund option was not explicitly agreed or technical limits have not been properly set.

7.6.4    As refunds are vulnerable to error and fraud, authorisation of a refund must be adequately secured. The Beneficiary shall monitor proper and legitimate use of refund procedures.

7.6.5 It is mandatory to configure the online platform, payment terminal, or connected/integrated cash register in such a way that every refund requires the use of a unique password or login code. This security measure may not be removed or disabled.

7.6.6 The Beneficiary bears all risk related to unauthorised, incorrect or unlawful use of the refund functionality.

7.6.7 GoCredible reserves the right to offer payment services without a refund option.

7.6.8 GoCredible reserves the right to deny execution of a refund, for example in case of (suspected) fraud.

7.6.9 The Beneficiary is jointly and severally liable to GoCredible for the total amount of refunded payments. Refunds will be offset against payment settlements due to the Beneficiary. Any positive or negative balance resulting from such offset will be booked to or debited from the settlement account. If the balance on that account is insufficient to cover the negative balance from refunds, the Beneficiary must repay the outstanding amount to GoCredible immediately and without further notice.

7.7       Chargeback
7.7.1 In the event of a chargeback, a card-issuing institution may compel GoCredible to reverse an already executed payment. Chargebacks are not limited to credit card transactions and may apply to nearly all payment methods.

7.7.2 The Beneficiary acknowledges and accepts full liability for all chargebacks and related liabilities arising from transactions processed under the User Agreement and this Addendum.

7.7.3 The Beneficiary indemnifies GoCredible against all claims brought by card issuers and Payment Schemes in connection with chargebacks. This liability continues to apply even after termination of the User Agreement, as chargebacks may occur long after the transaction date.

7.7.4 The Beneficiary may dispute a chargeback and GoCredible will provide reasonable assistance in the defence process. However, the Beneficiary remains solely responsible for providing evidence and for complying with the required response deadlines.

7.7.5 The Beneficiary is jointly and severally liable to GoCredible for the full amounts of all chargebacks.

7.7.6 Chargebacks will be invoiced by GoCredible to the Beneficiary. The Beneficiary shall pay such invoices without delay.

7.7.7 GoCredible may require the Beneficiary to provide a security deposit or other form of financial guarantee, prior to the commencement of services, in order to mitigate chargeback-related financial risks.

7.8       Offline transactions
7.8.1    SoftPOS allows offline card payments to be processed. The Tripartite Agreement with Tintel applies to this softPOS transaction processing. Tintel’s general terms and conditions apply to these offline transactions (https://www.pay.nl/algemene-voorwaarden).

7.8.2    Offline transactions (softPOS) are not always verified directly with the (payment) card issuer, but are first stored on the cardholder’s device. When the device comes online, the transaction is presented to the (payment) card issuer. This can result in various events, such as the card payment being invalid, unsuccessful, or not being processed or permitted to be processed. GoCredible, together with its partners, makes every effort to prevent and ensure the transaction is successful.

7.8.3    The risk of unsuccessful softPOS transactions accepted offline rests entirely with the Beneficiary.

7.8.4    GoCredible may require the Beneficiary to deposit an amount in escrow or otherwise provide a guarantee for the service in order to limit the financial risks for GoCredible.

7.9       Pre-authorization
7.9.1    When using pre-authorization, the pre-authorization must be formally completed within the maximum timeframe.

7.9.2    If a completion message for the authorization is not received, payment transactions will not be processed. Payment plans may charge penalties for this. The beneficiary is always liable to GoCredible for this penalty.

7.9.3    GoCredible accepts no liability for unregistered or late registrations of orders or for incomplete pre-authorizations.

7.10     Direct Debit
7.10.1  When a Euro Direct Debit Order is submitted, the GoCredible application provides a technical response in response to receipt of the order. This received order is then forwarded to the processing agencies.

7.10.2  There are several reasons why a Direct Debit Order cannot be successfully processed, which are beyond GoCredible’s control. These rejection reasons are included in our technical documentation.

7.10.3  After the funds have been received and disbursed by GoCredible, the originator of the direct debit may object and request their bank to reverse the transaction. This is called a reversal or reversal, which GoCredible must comply with.

7.10.4  The beneficiary must have a valid direct debit authorization. Failure to do so may result in a penalty based on an Unauthorized Direct Debit Report (also called an “MOI”). In the event of an MOI, the reversal right period may be extended.

7.10.5 The Beneficiary indemnifies GoCredible against all chargebacks. This liability remains in effect even after termination of the agreement.

7.10.6 The Beneficiary is jointly and severally liable to GoCredible for the chargeback amounts.

7.10.7 GoCredible will invoice the Beneficiary for chargebacks or offset them against amounts payable to the Beneficiary. If the amount payable is insufficient to offset the refund payments, the Beneficiary will immediately and independently pay the amount owed to GoCredible.

7.10.8 GoCredible may require the Beneficiary to deposit an amount in escrow or otherwise provide a guarantee prior to providing the service to limit GoCredible’s financial risks.





8.         Information Technology, Security, and Protection of Personal Data
8.1       Information technology security is crucial for reliable payment transactions. The Platform and the Beneficiary acknowledge and accept their own responsibility for this within the chain and make written agreements with each other on these matters.

8.2       The Platform and the Beneficiary shall endeavor to prevent unauthorized access to payment transactions.

8.3       You are responsible for installing, maintaining, and securing the information technology and communication tools you use with adequate anti-virus software, firewall software, and other appropriate security measures.

8.4       Safety and security updates are performed promptly, completely, and correctly.

8.5       You are obligated to follow instructions from GoCredible or the payment method provider regarding security.

8.6       CTAP-certified payment terminals must always have the most up-to-date (security) software installed. Security updates may not be neglected, delayed, or frustrated. A MSG authorization may not be removed if it is required for secure processing.

8.7       When a third party repairs or maintains a payment terminal, access security must remain in effect. When a third party repairs or maintains a payment terminal using softPOS, the softPOS software must be removed before performing the repair or maintenance.

8.8       The providers of your chosen payment methods may impose additional security requirements, such as those arising from the Payment Card Industry Data Security Standards (PCI-DSS). You are responsible for determining whether these requirements apply and, if so, for demonstrably complying with them. You will be liable for any damage caused by your actions.

8.9       Upon request, the Beneficiary or Platform must provide GoCredible with proof of PCI-DSS compliance on their own domain.

8.10     The Platform and Beneficiary shall ensure adequate security measures for data protection (such as encryption and access control).

8.11     The Platform and Beneficiary shall ensure that personal data are processed in accordance with the GDPR and that they comply with relevant legislation applicable to the parties.

8.12     The Platform and the Beneficiary must notify us immediately of any (suspected) problems and/or irregularities in the processing of (personal) data for the payment service, including suspected or actual unauthorized use, security incidents, and data breaches.

8.13     GoCredible is entitled to suspend its services in the event of non-compliance with these provisions or requirements. In such cases, the Platform or the Beneficiary are not entitled to compensation for direct or indirect damages.

9.         Liability & Indemnification
9.1       The Beneficiary shall indemnify GoCredible and its partners against all damages, fines, or claims arising from violations, errors, or negligence by the Beneficiary or Platform with respect to the User Agreement or Platform Agreement, the User Terms, the applicable appendix(es), and this Addendum.

9.2       The Beneficiary and Platform declare that they are aware of and will act in accordance with all rules and regulations of the Payment Schemes and will immediately implement any changes thereto or instructions from these parties.

9.3       The Beneficiary and Platform are liable for all liabilities arising from the Rules & Regulations in the event of non-compliance with these obligations and all fines relating to transactions processed under this Agreement. The Beneficiary and Platform shall indemnify GoCredible against all claims from Acquirers and Payment Schemes. This liability shall continue to apply even after termination of this Agreement.

9.4       The Beneficiary and Platform are fully liable for:

– All chargebacks and refunds;

– Fines imposed by a Payment Scheme, card issuer, or acquirer;

– Claims, fines, or damages resulting from data breaches;

– Claims, fines, or damages resulting from non-compliance with PCI-DSS requirements;

– Tax or legal claims or fines arising from the Beneficiary’s activities.

9.5       Beneficiary and Platform shall indemnify GoCredible against all claims from users of payment methods, payment method providers, Payment Schemes and/or third parties relating to payment transactions and all acts or omissions of Beneficiary or Platform, or relating to non-compliance with requirements imposed on Beneficiary, Platform and users by payment method providers and/or Payment Schemes, including any liability of user, Beneficiary and Platform, and Beneficiary and Platform shall indemnify GoCredible and hold GoCredible harmless from and against all associated costs (including legal fees) reasonably incurred by GoCredible in connection with any such claim.


10.       Other Provisions
10.1     GoCredible reserves the right to request information from the Platform and/or the Beneficiary regarding the (intended) use of a payment method, (intended) transactions, the party itself, the replacement or updating of expired documents, and other information if this is reasonably necessary to provide our services, or to comply with our (legal) obligations and regulations.

10.2     If the Beneficiary and/or Platform fail to adequately comply with the requests referred to in the previous paragraph, GoCredible may decide or be required to suspend or discontinue its services. In such cases, GoCredible may also be required to report this to an authority, supervisory authority, or government agency. GoCredible is not required to share such a report with the Beneficiary or the Platform.

10.3     The Beneficiary and the Platform will cooperate with questions and requests if a supervisory authority of GoCredible, a Payment Scheme, or an Acquirer requires GoCredible to do so in order to comply with its (legal) obligations.

10.4     In the event of any conflict or ambiguity between this Addendum and the User Agreement or Platform Agreement, this Addendum shall prevail. In the event of any conflict between this Addendum and the Rules & Regulations, the Rules & Regulations shall prevail.

10.5     Changes in legislation, technical specifications of the API or Platform, or Rules & Regulations may lead to amendments to this Addendum. The current version of this Addendum can be found at https://www.gocredible.nl/addendum_betaalmethodes.

10.6     Dutch law applies to GoCredible’s services.