PRIVACY NOTICE FOR EU\EEA & UK-BASED CUSTOMERS ONLY
VERSION 1.0 EFFECTIVE DATE: Jun 24, 2026
1. INTRODUCTION
This document, herein referred to as the “Privacy Notice”, outlines the privacy practices of Partnerway OÜ, trading as Spendbase (“We”, “us”, “our”, “Spendbase”) and governs the processing of personal data in connection with the provision of our digital banking, payment, and financial technology services (“Services”) to the EU\EEA & UK-based customers (“Customers”) defined below.
Your continued use of the Services constitutes your acknowledgment of, and agreement to, the privacy practices described in this Privacy Notice. In the event of any concern relating to this Privacy Notice or how we handle your Personal Data, feel free to contact us at:
Data Protection Officer Attn: Privacy and Compliance Email: privacy@test-partneway.prod.spendbase.co
2. APPLICABILITY TO THE CUSTOMER
Spendbase provides business-to-business financial technology services, including corporate card programs and related platform services. All Spendbase accounts are opened and maintained exclusively for business purposes.
Therefore, this Privacy Notice applies to Customers, namely:
- Business Customers that enter into a contractual relationship with Spendbase, who are treated as commercial entities (“Business Customer”), and
- Individuals who access or use Spendbase services on behalf of a Business Customer, including employees, officers, and cardholders, who act solely in a business or employment capacity (“Authorized User”)
3. ABOUT SPENDBASE
For the purposes of GDPR and UK GDPR, Spendbase acts as data controller in respect of the processing activities described in this Privacy Notice. Our details are set out below.
| Field | Description |
| Legal name | Partnerway OÜ (trading as Spendbase) |
| Registration No | 16379208 |
| Address | Harju maakond, Tallinn, Kesklinna linnaosa, Tornimäe tn 3 // 5 // 7, 10145, Estonia |
| corporate@test-partneway.prod.spendbase.co | |
| Email (privacy matters) | privacy@test-partneway.prod.spendbase.co |
In accordance with applicable law, Spendbase may act as:
- Independent Data Controller for Personal Data processed for its own legal, compliance, fraud prevention, security, and AML/KYC obligations.
- Data Processor with respect to Authorized User Personal Data processed on behalf of Business Customers for account administration, expense management, and related platform purposes, under applicable data processing agreements.
For information on how this dual-capacity arrangement affects the processing of Authorized User Personal Data, please refer to Section 12 (Authorized Users) below.
A Data Processing Agreement (“DPA“) governing Spendbase’s processing of Personal Data on behalf of Business Customers is available upon request. The DPA sets out the obligations of each party in connection with the processing of Authorized User data and takes precedence over this Privacy Notice to the extent of any inconsistency.
Regulated Service Providers. For UK Customers, cards and accounts are issued by Moorwand Ltd, a company incorporated in England and Wales (company number 08491211), registered office at Fora, 3 Lloyds Avenue, London, EC3N 3DS, authorised by the Financial Conduct Authority under the Electronic Money Regulations 2011 (FRN 900709). For EEA Customers, cards and accounts are issued by Heuro SAS, in partnership with Moorwand Ltd. Heuro SAS is authorised by the Autorité de Contrôle Prudentiel et de Résolution (ACPR) under licence number 17478. These institutions, together with Mastercard International and other payment network partners that participate in the delivery of the Services, process Personal Data as independent controllers for their own regulated purposes — including AML/CTF compliance, sanctions screening, Suspicious Activity Report (SAR) filing, fraud risk management, tokenisation services and account number provisioning, and obligations arising under their own authorisations and applicable financial services regulation. Data flows to these parties constitute disclosures between independent controllers, not processing instructions from Spendbase. Each such institution is independently accountable to its own regulators (including the FCA, ACPR, and applicable national competent authorities) for the Personal Data it receives. Business Customers and Authorised Users may be subject to those institutions’ own privacy notices in addition to this Notice.
4. REGULATORY FRAMEWORK
Where applicable, Spendbase processes Personal Data in compliance with:
- Regulation (EU) 2016/679 (General Data Protection Regulation — GDPR);
- UK GDPR and the Data Protection Act 2018 (for UK Customers);
- Directive (EU) 2015/2366 (PSD2) and applicable national implementing measures;
- Regulation (EU) 2022/2554 (DORA) and its regulatory technical standards;
- Applicable AML/KYC legislation, including Directive (EU) 2018/843 (5AMLD) and national implementing measures;
- Contractual obligations with our Regulated Service Providers, card scheme rules, and applicable financial services regulation.
5. PERSONAL DATA WE COLLECT
Spendbase collects and processes Personal Data only to the extent necessary to provide the Services, comply with applicable legal and regulatory obligations, prevent fraud and misuse, and operate and secure Spendbase and its Services. Depending on the customer type, we collect Personal Data as follows:
| Category | Description | Applies To |
| Identity & Contact | Name, date of birth, address, email (personal and work), phone number, employment information, government-issued ID, driver’s license number, job title | Authorized User |
| Business Information | Legal and trade names, registration and tax identifiers, incorporation details, ownership and beneficial owner information, signatory information | Business Customer |
| Financial Information | Account data, corporate card details, transaction history, payment records, expenses, and merchant information | Business Customer; Authorized User |
| Compliance & Risk | KYC/KYB records, sanctions screening results, fraud monitoring data, dispute and investigation records, PEP and adverse media screening | Business Customer; Authorized User |
| Authentication & Access | Security credentials, access permissions, role assignments, activity logs | Business Customer; Authorized User |
| Communications | Customer support inquiries, correspondence, and feedback; communications may be recorded where permitted by law and with appropriate notice | Business Customer; Authorized User |
| Digital Wallet & Tokenisation Data | Device account numbers (DANs), token identifiers, wallet provider identifiers, and device/app identifiers generated when a Card is added to a digital wallet | Authorized User |
| Technical & Usage | Device identifiers, IP address, browser type, operating system, access timestamps, and platform interaction data | Business Customer; Authorized User |
All Authorized User Personal Data is processed solely in connection with the individual’s professional or employment relationship with the relevant Business Customer. Spendbase does not intentionally collect Personal Data for personal, family, or household purposes, does not direct its Services to children, and does not knowingly collect Personal Data from individuals under the age of 18.
Where permitted by law, Spendbase may create and use aggregated or de-identified data derived from Personal Data for analytics, reporting, benchmarking, and service improvement. Such data does not identify any individual and is not treated as Personal Data under applicable law.
6. SOURCES OF PERSONAL DATA
Spendbase collects Personal Data from the following lawful and transparent sources:
| Source | Description |
| Business Customer (direct) | Provided during onboarding, account setup, and ongoing administration via applications, forms, platform inputs, and communications |
| Authorized User (direct) | Provided when accessing the platform, activating accounts, using corporate cards, submitting expenses, or contacting support |
| Business Customer (about Authorized Users) | Provided to grant platform access, issue cards, manage permissions, and meet legal obligations. Business Customers are responsible for ensuring such disclosures are lawful and that required notifications have been made to Authorized Users |
| Third-Party Service Providers | Identity verification, KYC/KYB sanctions and PEP screening, fraud prevention, and transaction monitoring providers; payment networks, card issuers, and Regulated Service Providers; infrastructure, security, and analytics providers; public or government sources where permitted by law |
| Automatically Collected | Technical and usage data collected via cookies and similar technologies when Business Customers or Authorized Users access the Spendbase platform or website |
7. LAWFUL BASES AND PURPOSES OF PROCESSING
Under GDPR and UK GDPR, Spendbase is required to identify a lawful basis for each processing activity. Spendbase processes Personal Data on the following legal bases pursuant to Article 6 GDPR (and, for special category data, Article 9 GDPR where applicable) and for the purposes consistent with the nature of our Services. Personal Data is not used for purposes incompatible with the original reason it was collected.
| Purpose | Description | Applicable Lawful Basis |
| Providing Services | Onboarding Business Customers and Authorized Users; establishing and managing accounts and corporate card programs; processing transactions and payments; enabling expense management, reporting, and account controls; providing customer support | Depending on the data category collected: Art. 6(1)(b) Performance of a contract; Art. 6(1)(c) Legal obligation |
| Legal & Regulatory Compliance | Complying with AML, KYC/KYB, PEP/sanctions screening, DORA, PSD2, tax, recordkeeping obligations, and responding to lawful requests from regulators, courts, or law enforcement | Depending on the data category collected: Art. 6(1)(c) Legal obligation, Art. 6(1)(e) Public task |
| Fraud, Security & Risk | Monitoring transactions and platform activity, performing risk assessments, enforcing access controls, and maintaining audit and security logs to prevent, detect, and respond to fraud, unauthorized access, and other harmful activities | Art. 6(1)(f) Legitimate interests (Spendbase’s and third parties’ interests in security and financial crime prevention) |
| Service Improvement | Analyzing and improving the functionality, reliability, and performance of the platform; troubleshooting, testing, analytics, and quality assurance. De-identified or aggregated data is used where feasible | Art. 6(1)(f) Legitimate interests |
| Communications | Sending account notifications, operational updates, security alerts, policy changes, and support communications. Communications are limited to what is relevant to the provision and administration of the Services | Depending on the data category collected: Art. 6(1)(b) Performance of a contract; Art. 6(1)(c) Legal obligation |
| Marketing (Limited) | Providing information about Services, features, or updates relevant to an existing business relationship, where permitted by law. Spendbase does not engage in consumer-style targeted advertising. Opt-out available at any time by emailing privacy@test-partneway.prod.spendbase.co or using the unsubscribe link in any marketing communication | Art. 6(1)(f) Legitimate interests (existing business relationship); or Art. 6(1)(a) Consent, where required |
| Legal Claims | Establishing, exercising, or defending legal claims; compliance with court orders and regulatory investigations | Depending on the data category collected: Art. 6(1)(b) Performance of a contract; Art. 6(1)(c) Legal obligation |
| Aggregated / De-Identified Uses | Benchmarking, analytics, reporting, and product development using data that does not identify individuals. Such data is not Personal Data under applicable law | Permitted use; not Personal Data |
Legitimate interests assessment. Where Spendbase relies on Art. 6(1)(f) (legitimate interests), it has assessed that the processing is necessary for the legitimate interest pursued, and that this interest is not overridden by the interests or fundamental rights and freedoms of the data subjects concerned. Data subjects may request further information on these assessments or object to such processing — see Section 14 (Data Subject Rights) below.
8. HOW WE SHARE PERSONAL DATA
Spendbase does not sell Personal Data and does not disclose Personal Data except as necessary to operate the Services, comply with legal and regulatory obligations, protect the security and integrity of the platform, or as otherwise permitted by law. All service providers are contractually required to maintain privacy and security practices consistent with this Notice and applicable law.
| Recipient | Purpose of Sharing |
| Regulated Service Providers (Moorwand Ltd; Heuro SAS) | Account establishment, e-money issuance, card issuance, transaction processing, fraud monitoring, and regulatory compliance. Disclosures to these institutions are made on a controller-to-controller basis — they process Customer Personal Data for their own independent legal and regulatory purposes, including PSD2, AML, and applicable financial regulations. Spendbase is not responsible for the subsequent processing of Personal Data by these institutions in their capacity as independent controllers. Business Customers and Authorized Users may receive separate privacy notices from these institutions. |
| Mastercard International | Card scheme rules compliance, transaction authorisation, fraud prevention, and dispute processing |
| Digital Wallet Providers (Apple Pay, Google Pay) | Token provisioning, card-on-file management, and transaction authentication. Wallet providers receive tokenised card credentials and limited transaction data as independent controllers subject to their own privacy notices and card scheme tokenisation rules. Spendbase does not control the processing of Personal Data by wallet providers once a token has been provisioned |
| Service Providers & Vendors | KYC/KYB and identity verification, sanctions and PEP screening, fraud prevention, payment processing, customer support, cloud infrastructure, security, analytics, and communications. Providers are bound by data processing agreement to use data only for specified purposes and to implement appropriate technical and organisational safeguards |
| Business Customers & Authorized Administrators | Personal Data relating to Authorized Users may be shared with the relevant Business Customer and its designated administrators for account administration, expense management, reporting, and compliance oversight. Spendbase acts on Business Customer instructions and applicable law |
| Regulators & Competent Authorities | Data Protection Authorities, FCA, Finantsinspektsioon, Bank of Lithuania, Financial Intelligence Units, courts, and law enforcement where required or permitted by law — including for regulatory reporting, lawful orders, and the exercise or defence of legal claims |
| Corporate Transaction Parties | In connection with a merger, acquisition, reorganization, sale of assets, or financing, subject to appropriate confidentiality protections and applicable legal requirements |
| Aggregated / De-Identified Data | Analytics, reporting, and benchmarking — in a form that does not identify any individual. Not treated as Personal Data under applicable law |
9. DATA RETENTION
Personal Data is retained only for as long as necessary to fulfill the purposes for which it was collected, in accordance with applicable legal and regulatory requirements, contractual obligations, and our internal data governance policies.
| Category | Retention Rationale | Indicative Period |
| AML / KYC / KYB Records | 5AMLD, national AML legislation, regulatory obligations | Minimum 5 years from the end of the business relationship or the date of the occasional transaction, whichever is later |
| Transaction Records | PSD2 Art. 25; DORA record-keeping; financial regulatory requirements; dispute resolution; tax obligations | 5 years from the end of the business relationship |
| Account & Contractual Records | Contract enforcement, audit, regulatory inspection | 7 years from the end of the business relationship |
| Fraud & Security Logs | DORA incident reporting obligations; fraud investigation; legal defence | 7 years from incident date |
| Communications & Support Records | Quality assurance, dispute resolution | 3 years (based on GDPR-request retention period) |
| Digital Wallet & Tokenisation Data | Card scheme tokenisation rules; chargeback and dispute resolution window | Duration of card validity + 18 months |
| Marketing Preferences | Consent management and opt-out records | 3 years (based on GDPR-request retention period) |
| Aggregated / De-Identified Data | Analytics, benchmarking — does not identify individuals | Retained indefinitely as permitted by law |
Where retention is no longer required, Personal Data is securely deleted, anonymized, or de-identified in accordance with applicable policies and technical controls.
10. DATA SECURITY & SAFEGUARDS
Spendbase implements and maintains administrative, technical, and physical safeguards designed to protect Personal Data against unauthorized access, disclosure, alteration, or destruction, consistent with the Article 32 GDPR and applicable law, including DORA requirements on ICT risk management.
- Administrative safeguards: Policies and procedures governing data access, confidentiality, employee training, incident response, vendor management, and compliance oversight. Access to Personal Data is limited to personnel and service providers who require it for legitimate business purposes and who are subject to confidentiality obligations.
- Technical safeguards: Access controls, multi-factor authentication, encryption in transit and at rest, logging and monitoring, network security controls, and vulnerability management.
- Incident response: Spendbase maintains procedures to detect, respond to, and recover from security incidents. Where required by GDPR Art. 33, Spendbase will notify the competent supervisory authority within 72 hours of becoming aware of a notifiable personal data breach. Where required by Art. 34, affected data subjects will be notified without undue delay. Where the breach affects card programme operations, Spendbase will also notify Moorwand Ltd and Heuro SAS in accordance with its contractual obligations and applicable card scheme incident reporting requirements.
While Spendbase takes reasonable and appropriate measures to protect Personal Data, no system or method of transmission can be guaranteed to be completely secure. Business Customers and Authorized Users are responsible for maintaining the confidentiality of their access credentials and for using the Services in a secure manner.
11. INTERNATIONAL DATA TRANSFER
Spendbase is a global technology company. Personal Data collected in connection with the Services may be processed in countries outside the EU/EEA or United Kingdom, including in the United States. Key infrastructure providers include:
- Amazon Web Services (AWS) — mainly EU/EEA regions (including Ireland and Frankfurt), rarely US;
- Google Cloud Platform (GCP) — EU/EEA regions and the US;
- Other sub-processors as disclosed in the DPA.
Where Personal Data is transferred to a third country, Spendbase relies on the following transfer mechanisms, as applicable:
- European Commission adequacy decisions;
- Standard Contractual Clauses (SCCs) and\or UK International Data Transfer Agreements (IDTAs)
- Other appropriate safeguards pursuant to Art. 46 GDPR or Art. 46 UK GDPR, as applicable.
Business Customers may request further information on transfer destinations, applicable safeguards, and copies of relevant transfer mechanisms by contacting privacy@test-partneway.prod.spendbase.co
Personal Data processed by Moorwand Ltd and Heuro SAS in their capacity as independent controllers may be subject to separate international transfer arrangements under their own regulatory frameworks, including transfers to Mastercard International’s processing infrastructure. Customers should refer to those institutions’ own privacy notices for further information.
12. AUTHORIZED USERS
Spendbase processes Personal Data relating to Authorized Users solely in connection with the Services provided to the relevant Business Customer and in accordance with Business Customer instructions, applicable contractual terms, and applicable law.
Business Customer responsibilities. Business Customers are responsible for: (i) determining which individuals are authorized to access the Services and managing their access rights and credentials; (ii) ensuring that Authorized User information provided to Spendbase is accurate, current, and lawfully obtained; (iii) informing Authorized Users about how their Personal Data is collected, used, and shared in connection with the Services, including through internal policies and notices where required by applicable employment, privacy, and data protection laws; and (iv) ensuring their use of Authorized User data complies with applicable law.
Spendbase’s role. With respect to Authorized User data processed on behalf of Business Customers for platform administration purposes, Spendbase acts as a Data Processor and does not control or determine the purpose or means of such processing. With respect to data processed for Spendbase’s own legal, compliance, fraud prevention, and security obligations, Spendbase acts as an Independent Controller.
Authorized User requests. Authorized Users should direct requests relating to access, correction, or deletion of their Personal Data primarily to the Business Customer that authorized their access to the Services. Where required by law or contract, Spendbase will assist Business Customers in responding to such requests. In the event an Authorized User submits a privacy request directly to Spendbase, Spendbase will endeavor to transfer the request to the relevant Business Customer without undue delay and provide such information as is permitted by law.
13. COOKIES & ANALYTICS
Spendbase uses cookies and similar technologies in connection with its websites and platform to operate, secure, and improve the Services. These technologies help ensure platform functionality, protect against fraud and unauthorized access, support analytics and performance monitoring, and maintain service reliability.
Cookies and similar technologies may collect information such as device identifiers, IP address, browser type, operating system, language preferences, access timestamps, and interaction data. This information is used for technical, security, and operational purposes.
Spendbase uses the following categories of technologies:
- Strictly necessary: Required for the operation, security, and authentication of the platform. Cannot be disabled without impairing functionality.
- Functional and performance: Help remember user preferences, analyze platform performance, and diagnose technical issues.
- Analytics: Help understand how the Services are used and improve functionality. Analytics tools are configured to support business operations and are not used for cross-context behavioral advertising.
Spendbase does not engage in consumer-style behavioral advertising and does not use cookies for cross-context behavioral advertising. Non-essential (other than strictly necessary) cookies are placed only with the prior consent of the user, which may be withdrawn at any time via the cookie management tool available on the Spendbase website. Where required by applicable law, Spendbase provides appropriate notices and choices regarding the use of cookies and similar technologies through platform settings or browser controls.
14. DATA SUBJECT RIGHTS
Under GDPR and UK GDPR, individuals whose Personal Data is processed by Spendbase as data controller have the following rights. Because Spendbase operates in a business-to-business context and processes most data in an employment or commercial capacity, some rights may be subject to limitations or exemptions under applicable law.
| Right | Description |
| Right to Access | Request confirmation of whether Personal Data is processed and, if so, access to that data and related information. Response within one month (extendable by two months in complex cases, with notice) |
| Right to Rectification | Request correction of inaccurate, incomplete, or outdated Personal Data |
| Right to Erasure | Request deletion of Personal Data where no legal retention obligation or other legitimate basis applies. Subject to applicable exemptions including AML/KYC legal retention obligations |
| Right to Restriction | Request restriction of processing in defined circumstances, including while the accuracy of data is contested or an objection is being considered |
| Right to Data Portability | Where processing is based on consent or contract and carried out by automated means, receive Personal Data in a structured, commonly used, and machine-readable format, and transmit it to another controller |
| Right to Object | Object to processing based on legitimate interests (Art. 6(1)(f)) or for direct marketing purposes. Spendbase will cease processing unless it demonstrates compelling legitimate grounds that override the data subject’s interests |
| Right not to be subject to Automated Decision-making | Right not to be subject to solely automated decisions (including profiling) that produce legal or similarly significant effects, unless permitted by law or explicit consent has been obtained. Spendbase does not currently use solely automated decision-making that produces such effects |
| Right to Withdraw Consent | Where processing is based on consent, withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal |
How to exercise your rights. To exercise any right listed above, Customer shall submit a written request to privacy@test-partneway.prod.spendbase.co with the subject line “Data Subject Request” and include: (i) data subject full name and email address associated with the account; (ii) the name of the Business Customer data subject is affiliated with; (iii) a description of the right data subject wishes to exercise; and (iv) any additional information reasonably necessary to verify the identity.
Spendbase will verify identity before processing any request and will respond within one calendar month of receipt. Where requests are complex or numerous, this period may be extended by up to two further months, in which case Spendbase will inform the data subject within the initial one-month period. Spendbase will not retaliate against any individual for exercising a privacy right or filing a complaint. Authorised Users should generally direct requests to the Business Customer that authorised their access to the Services.
Right to lodge a complaint. Customers shall have the right to lodge a complaint with a supervisory authority. The competent lead supervisory authority for Spendbase is the
- Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) — www.aki.ee — for EU GDPR matters;
- Information Commissioner’s Office (ICO) — www.ico.org.uk — for UK GDPR matters.
- Customers also have the right to lodge a complaint with the data protection authority in their own EU Member State or UK.
Where Personal Data is processed by Moorwand Ltd or Heuro SAS in their capacity as independent controllers — including card transaction records and e-money account data — data subjects should direct requests relating to such data directly to the relevant institution using the contact details in their respective privacy notices available at the following links: Moorwand Privacy Policy and Heuro SAS Privacy Policy.
15. CHANGES TO THIS PRIVACY NOTICE
Spendbase may update this Privacy Notice from time to time to reflect changes in our practices, services, legal or regulatory requirements, or operational needs. When we make material changes, we will provide notice through the Spendbase platform by updating the Effective Date shown on this document.
In the event of significant changes that may materially affect how Personal Data is processed, Spendbase will use available means of communication to notify affected Business Customers and Authorized Users before the changes take effect, in accordance with applicable law.
Continued use of the Services after an updated Privacy Notice becomes effective constitutes acknowledgment of the revised Notice, to the extent permitted by law.
16. DEFINITIONS
For purposes of this Privacy Notice, the following terms have the meanings set forth below:
| Term | Meaning |
| Authorized User | An individual, including employees, officers, and authorized cardholders, whom a Business Customer authorizes to access or use the Spendbase Services on the Business Customer’s behalf. |
| Business Customer | A legal entity or organization that enters into a contractual relationship with Spendbase for the provision of business-focused financial or payment services. |
| Controller/ Data Controller |
An entity that determines the purposes and means of the processing of Personal Data as defined in Art. 4(7) GDPR. |
| DPA | Data Processing Agreement — the contractual document governing the terms on which Spendbase processes Personal Data on behalf of a Business Customer. |
| GDPR | Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data. |
| Personal Data | Any information relating to an identified or identifiable natural person (‘data subject’), as defined in Art. 4(1) GDPR. |
| Processor/ Data Processor | A natural or legal person which processes Personal Data on behalf of the controller, as defined in Art. 4(8) GDPR. |
| Regulated Service Provider | Moorwand Ltd (for UK) or Heuro SAS (for EEA), being regulated financial institutions that issue cards and e-money accounts under the Programme. |
| Services | The products and services made available through the Spendbase platform, including corporate card programmes, digital accounts, expense management, and related financial technology services. |
| SCC/IDTA | Standard Contractual Clauses (European Commission-approved) or International Data Transfer Agreement (UK ICO-approved) — mechanisms used to ensure appropriate safeguards for international data transfers. |
| UK GDPR | The GDPR as incorporated into UK law by the European Union (Withdrawal) Act 2018, as amended by the Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019. |
Table of contents
1. INTRODUCTION 2. APPLICABILITY TO THE CUSTOMER 3. ABOUT SPENDBASE 4. REGULATORY FRAMEWORK 5. PERSONAL DATA WE COLLECT 6. SOURCES OF PERSONAL DATA 7. LAWFUL BASES AND PURPOSES OF PROCESSING 8. HOW WE SHARE PERSONAL DATA 9. DATA RETENTION 10. DATA SECURITY & SAFEGUARDS 11. INTERNATIONAL DATA TRANSFER 12. AUTHORIZED USERS 13. COOKIES & ANALYTICS 14. DATA SUBJECT RIGHTS 15. CHANGES TO THIS PRIVACY NOTICE 16. DEFINITIONS