Contractual DPA
Where a customer requires a data processing agreement, controller/processor roles, processing instructions, retention, subprocessors and transfer terms should be documented in the signed agreement for that deployment.
Data-handling information for organizations evaluating VisaPathways enterprise APIs.
Enterprise customers should send only the facts required by the documented API contract. VisaPathways evaluation records use hashes, rule identity, verdicts, reason codes, evidence references and traces to support auditability. API usage monitoring is designed not to store raw API keys or full request bodies.
Where a customer requires a data processing agreement, controller/processor roles, processing instructions, retention, subprocessors and transfer terms should be documented in the signed agreement for that deployment.
This page is procurement information, not a claim that VisaPathways has obtained a particular privacy or security certification or that every customer's regulatory obligations are automatically satisfied.
Contact us with your organization, intended use case, jurisdictions and any required DPA or vendor-assessment materials.