
i2c and GDPR
CertReports found no public GDPR evidence for i2c as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.
Evidence
- Kind
- listing
- Issued or listed
- 8 Mar 2017
- Expires or valid through
- 20 May 2027
- Scope
- i2c Inc. provides payment processing services through an online software-as-a-service platform. We make these services available to our clients who use the i2c platform to collect, store and process personal data from their end-user customers. In most cases, the personal data collected, stored and processed on our platform is done so on behalf of our clients. There are some cases where we may process personal data collected from customers on our own behalf. Whether on behalf of our clients or on our own behalf, the personal data we collect may be used in connection with the following activities: • Developing, implementing and operating our websites; • Facilitating sales and marketing campaigns including loyalty programs; • Processing customer applications to open payment card accounts, digital/electronic payment accounts, and depository accounts; • Processing payment authorization requests and payment transactions; • Verifying customer identity information (this may be a legal/regulatory requirement); • Responding to customer service and support requests received via telephone, instant messaging, email and postal mail; • Monitoring, detecting and preventing fraud; • Providing compliance services; • Providing compliance and security audit and assurance reports (for example: PCI, SSAE18 SOC1&2, ISO27001, ISO27701, ISO22301 and ISO18295); • Other related financial services. In providing its services, i2c may disclose European end-user customer’s personal data (excluding Visitor and HR data) to the Financial Institutions that provide payment card services to those end-users. These Financial Institutions are i2c’s clients and act as Data Controllers granting authority for i2c to collect personal data on their behalf. As directed by the Financial Institutions, i2c may disclose personal data to the Payment Networks (Visa, Mastercard, American Express, etc.) or other third-party business partners (Data Processors) under contract with the Financial Institutions to process personal data on their behalf. Additionally, i2c may disclose personal data to banking regulators, government authorities, courts of law, law enforcement agencies, dispute-resolution agencies, or other such bodies as it may be required to by law.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | i2c Inc.: Active: SW-US Certification, EU-US Certification, UK Extension Certification | Live pagesha256 1bd6b0f1ce |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is i2c GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Alternatives with GDPR evidence
Similar vendors (shared product tags or the Payments category) whose GDPR row is verified or vendor-stated, ranked by similarity.