Corporate merch in other countries:AMArmeniaGEGeorgiaTRTürkiyeRSSerbiaAEUAECYCyprusITItalyPTPortugalESSpain

PCI-DSS compliance — SAQ-A scope and what it means

We don't touch card data — all payments via certified processor. SAQ-A scope means simplest, safest setup for Poland clients.

SAQ-A — outsourced cardholder data environment

SAQ-A applies because card data is fully outsourced to a PCI-DSS Level 1 processor. We never see PAN, never store CVV, never process card data on our servers. Our role is redirect/iframe only.

Tokenization for recurring billing

Repeat customers pay via tokens. Tokens are not card numbers — useless if exposed, scoped to our merchant ID. Token vault held by processor, not by us.

Network and quarterly scans

ASV-approved external scans quarterly. Internal vulnerability scans monthly. Pentest annually. Findings remediated to processor's SLA.

Poland — local payment context

Poland customers commonly pay via wire transfer or SEPA SDD for B2B. Card payments handled via processor with VAT 23% reverse-charge handling. KSeF flow happens after payment confirmation — never holds card data.

FAQ

Are you PCI-DSS Level 1?

No — SAQ-A. Level 1 applies to processors handling millions of transactions. We outsource to a Level 1 processor.

Can we see your AoC?

Yes — Attestation of Compliance shared under NDA.

3DS/SCA support?

Yes — Strong Customer Authentication via 3D Secure 2.x, mandatory for EEA card transactions under PSD2.

Refunds — how long?

Card refunds: 3-10 business days depending on issuer. SEPA: 1-3 days. Wire: 1-5 days.

Chargebacks?

Handled by processor — we cooperate with evidence package within 48 hours.

Need compliance documentation?