Offcanvas

Terms & Conditions

TERMS & CONDITIONS

CARDBIZ PAYMENT SERVICES SDN. BHD.
(THIRD PARTY ACQUIRER – MERCHANT SERVICES AGREEMENT)**

These Terms and Conditions (“T&C”) constitute a legally binding agreement between:

CARDBIZ PAYMENT SERVICES SDN. BHD.
(Company No. 201001003874 (888463-T))
a company incorporated in Malaysia and operating as a Third Party Acquirer (“TPA”) under authorization from licensed Acquirer Banks,
(hereinafter referred to as “CARDBIZ”),

AND

The merchant entity approved and onboarded for card payment acceptance,
(hereinafter referred to as the “Merchant”).

CARDBIZ and the Merchant shall be collectively referred to as the “Parties.”

1. DEFINITIONS

For the purposes of these T&C:

  • Acquirer” means the licensed financial institution or payment system operator authorizing CARDBIZ to perform merchant acquiring, processing, monitoring and settlement functions as a TPA.
  • Agreement” means these T&C, the Merchant Application Form, schedules, annexures, operating guidelines, and any amendments issued by CARDBIZ.
  • Card” means any valid Visa, Mastercard, MyDebit or other payment scheme card designated for acceptance.
  • Card Scheme Rules” means all rules, regulations, technical standards, compliance frameworks and advisories issued by Visa, Mastercard, MyDebit (PayNet), UnionPay or any global/local card network.
  • Cardholder” means an individual authorized to use a Card.
  • Chargeback” means a reversal of a Transaction initiated by the Acquirer, card issuer or card scheme.
  • Merchant Outlet” means any physical or online location from which the Merchant conducts business.
  • PCI-DSS” means the Payment Card Industry Data Security Standard.
  • Services” means card acceptance, processing, settlement, fraud monitoring, risk management, reporting issuance and any related services rendered by CARDBIZ.

2. APPOINTMENT AND SCOPE

2.1 The Merchant is hereby appointed by CARDBIZ, acting under authority of licensed Acquirer Banks, to accept and process Card transactions for the sale of goods and/or services.

2.2 CARDBIZ shall provide the Merchant with card acceptance capability, including terminals, integrations, systems access, onboarding, due diligence processing, transaction routing and settlement processing.

2.3 The Merchant acknowledges that CARDBIZ acts as a TPA, and that final settlement and acquiring liability resides with the respective Acquirer Bank.

2.4 The Merchant agrees to comply with all instructions, manuals, circulars, advisories and operational requirements issued by CARDBIZ or the Acquirer.

3. PROVISION AND USE OF EQUIPMENT

3.1 CARDBIZ may provide POS terminals, card readers, payment gateways, software or related equipment (“Equipment”).

3.2 Risk of loss or damage to the Equipment transfers to the Merchant upon delivery.

3.3 The Merchant shall:
(a) maintain the Equipment in good working condition;
(b) not modify, reverse engineer or tamper with the Equipment;
(c) use the Equipment exclusively for lawful card transactions approved under this Agreement;
(d) promptly report any fault, tampering or compromise.

3.4 CARDBIZ reserves the right to replace or retrieve the Equipment at any time.

4. MERCHANT OBLIGATIONS

The Merchant shall at all times:

4.1 Accept Cards
Accept all valid and unexpired Cards for legitimate transactions and not discriminate between Cards.

4.2 Authorization
Obtain transaction authorization through approved systems prior to completing any sale.

4.3 Prohibited Transactions
Not accept Cards for:
(a) cash-equivalent items;
(b) illegal or restricted businesses;
(c) transactions not corresponding to actual delivery of goods/services;
(d) transactions performed on behalf of another business (“factoring”).

4.4 Transaction Processing Standards
The Merchant shall:
(a) ensure accuracy of transaction data;
(b) not split transactions;
(c) not manually key-in transactions unless permitted;
(d) maintain proper sales drafts and records.

4.5 Compliance with Laws and Standards
The Merchant shall comply with:

  • PCI-DSS;
  • Bank Negara Malaysia regulations;
  • AMLA and AML/CFT requirements;
  • Card Scheme Rules;
  • Consumer protection and e-commerce laws.

4.6 Prohibited Storage of Data
The Merchant shall not store any prohibited cardholder data including CVV2, PIN, or magnetic stripe data.

4.7 E-commerce Merchant Obligations (if applicable)
The Merchant shall display:
(a) clear product descriptions and pricing;
(b) refund/return policies;
(c) privacy policy;
(d) legal identity and contact information.

4.8 Change of Business
The Merchant shall notify CARDBIZ in writing prior to any change in ownership, corporate structure, business model, risk category, MCC, domain name or other material change.

5. FEES AND SETTLEMENT

5.1 The Merchant shall pay:
(a) Merchant Discount Rate (MDR);
(b) transaction fees;
(c) terminal rental fees;
(d) onboarding, compliance or maintenance charges;
(e) any penalties or assessments imposed by card schemes.

5.2 Notwithstanding Clause 5.2, CARDBIZ reserves the right to revise the Merchant Discount Rate (MDR), fees or pricing with immediate effect and without prior notice where such revision is required due to:
(a) inaccurate, incomplete or misleading information provided by the Merchant;
(b) changes in the Merchant’s risk profile, business model, MCC or transaction behavior;
(c) excessive chargebacks, disputes, refunds or fraud indicators;
(d) directives, assessments or requirements imposed by the Acquirer, card schemes or regulatory authorities; or
(e) breach or suspected breach of this Agreement or applicable laws.

Any revised MDR shall apply prospectively and shall not affect transactions already settled.

5.3 Settlement of funds shall be made net of fees, chargebacks, penalties and reserves.

5.4 CARDBIZ may implement a rolling reserve, upfront deposit, collateral or withholding arrangement where required due to Merchant risk profile.

5.5 CARDBIZ may withhold, delay, suspend or place a hold on settlement funds, in whole or in part, without prior notice, where:
(a) the Merchant has provided false, inaccurate, incomplete or misleading information during onboarding or at any time thereafter;
(b) there is a discrepancy between declared and actual business activities;
(c) there is suspected fraud, AML/CFT concern, scheme rule violation or regulatory risk; or
(d) supporting documents requested by CARDBIZ are not provided within the stipulated timeframe.

Settlement shall remain on hold until the issue is resolved to CARDBIZ’s satisfaction.

6. CHARGEBACKS AND DISPUTES

6.1 CARDBIZ and/or the Acquirer may charge back any transaction that:

is disputed by the Cardholder;

lacks proper authorization;

violates scheme rules;

is fraudulent or suspicious;

involves non-delivery of goods/services;

involves counterfeit, duplicated or invalid card data.

6.2 The Merchant shall reimburse CARDBIZ for all chargebacks, penalties, handling fees and assessments.

6.3 CARDBIZ may deduct such amounts from settlement, Merchant’s account or any reserve held.

6.4 Merchant must supply supporting documents within the stipulated timeframe; failure to do so shall result in automatic chargeback acceptance.

7. FRAUD CONTROL, AML/CFT AND REGULATORY OBLIGATIONS

7.1 The Merchant shall implement anti-fraud controls and report suspicious transactions immediately.

7.2 CARDBIZ may suspend settlements or freeze funds pending investigative procedures.

7.3 Merchant must comply with AMLA, FATF requirements, and BNM guidelines on AML/CFT.

7.4 CARDBIZ may terminate the Merchant immediately where AML/CFT breaches are identified.

7.5 CARDBIZ may suspend settlement, freeze funds or restrict transaction processing immediately where information provided by the Merchant is found to be false, misleading or materially inaccurate, pending investigation and remedial action.

8. DATA SECURITY AND PCI-DSS COMPLIANCE

8.1 The Merchant shall strictly adhere to PCI-DSS requirements.

8.2 In the event of a data breach, the Merchant shall:
(a) grant CARDBIZ and forensic auditors full access to systems;
(b) bear all costs of investigation, remediation and scheme fines;
(c) notify affected parties as required by law;
(d) immediately implement corrective actions.

8.3 Non-compliance with PCI-DSS constitutes serious breach warranting suspension or termination.

9. AUDIT, INSPECTION AND REPORTING

9.1 CARDBIZ, the Acquirer, card schemes or regulatory authorities may inspect Merchant premises, systems, books and records at any time.

9.2 The Merchant shall provide full cooperation and access during such inspections.

9.3 CARDBIZ may require periodic compliance declarations, PCI certifications, risk questionnaires or self-assessment forms.

10. SUSPENSION AND TERMINATION

10.1 CARDBIZ may suspend or terminate the Merchant’s access immediately where:
(a) there is suspected fraud, illegal activity or data compromise;
(b) excessive chargebacks or dispute ratios occur;
(c) the Merchant breaches any material term of this Agreement;
(d) the Merchant becomes insolvent or ceases business;
(e) regulatory or scheme directives mandate suspension.

10.2 The Merchant may terminate this Agreement with thirty (30) days’ written notice.

10.3 CARDBIZ may withhold settlement funds for up to one hundred eighty (180) days post-termination to cover chargeback exposure.

10.4 Termination does not affect accrued liabilities.

11. LIABILITY AND INDEMNITY

11.1 The Merchant shall indemnify and hold harmless CARDBIZ, the Acquirer and card schemes against any loss, liability, penalty, cost or damage arising from:

  • breach of these T&C;
  • fraud or misconduct;
  • unauthorized or illegal transactions;
  • data compromise or PCI non-compliance;
  • breach of regulatory obligations;
  • misrepresentation to cardholders.

11.2 CARDBIZ shall not be liable for:

  • indirect or consequential losses;
  • business interruption;
  • loss of profits;
  • system downtimes not caused by CARDBIZ’s negligence.

12. CONFIDENTIALITY AND DATA PROTECTION

12.1 Both Parties shall maintain confidentiality of all information exchanged under this Agreement.

12.2 CARDBIZ may disclose Merchant information to:

  • Acquirers;
  • regulators;
  • card schemes;
  • law enforcement agencies;
  • service providers under confidentiality obligations.

12.3 The Merchant warrants compliance with the Personal Data Protection Act 2010 (PDPA).

13. GOVERNING LAW AND DISPUTE RESOLUTION

13.1 These T&C shall be governed by and construed in accordance with the laws of Malaysia.

13.2 Any dispute shall be subject to the exclusive jurisdiction of the Malaysian courts.

13.3 CARDBIZ may pursue injunctive or other equitable relief where appropriate.

14. MISCELLANEOUS

14.1 CARDBIZ may amend these T&C by written notice or publication on its website, and continued use of the Services constitutes acceptance.

14.2 The Merchant may not assign or transfer its rights under this Agreement without CARDBIZ’s prior written consent.

14.3 No failure to enforce shall constitute a waiver.

14.4 If any provision is held invalid, the remainder shall remain in full force.

14.5 These T&C bind the Parties and their successors.

We’re here to serve your needs








    We’re here to serve your needs

    [contact-form-7 id="16199" title="Contact form PopUp"]