**TERMS & CONDITIONS

CARDBIZ PAYMENT SERVICES SDN. BHD.
(THIRD PARTY ACQUIRER – MERCHANT SERVICES AGREEMENT) **

 

These Terms and Conditions (“T&C”) constitute a legally binding agreement between:

 

CARDBIZ PAYMENT SERVICES SDN. BHD.
(Company No.
201001003874 (888463-X))
a company incorporated in Malaysia and operating as a Third-Party Acquirer (“TPA”) under authorization from licensed Acquirer Banks,(hereinafter referred to as “CARDBIZ”),

 

AND

 

The merchant entity approved and onboarded for card payment acceptance, (hereinafter referred to as the “Merchant”).

 

CARDBIZ and the Merchant shall be collectively referred to as the “Parties.”

 

1. DEFINITIONS

For the purposes of these T&C:

l  Acquirer” means the licensed financial institution or payment system operator authorizing CARDBIZ to perform merchant acquiring, processing, monitoring and settlement functions as a TPA.

l  Agreement” means these T&C, the Merchant Application Form, schedules, annexures, operating guidelines, and any amendments issued by CARDBIZ.

l  Card” means any valid Visa, Mastercard, MyDebit or other payment scheme card designated for acceptance.

l  Card Scheme Rules” means all rules, regulations, technical standards, compliance frameworks and advisories issued by Visa, Mastercard, MyDebit (PayNet), UnionPay or any global/local card network.

l  Cardholder” means an individual authorized to use a Card.

l  Chargeback” means a reversal of a Transaction initiated by the Acquirer, card issuer or card scheme.

l  Merchant Outlet” means any physical or online location from which the Merchant conducts business.

l  PCI-DSS” means the Payment Card Industry Data Security Standard.

l  Services” means card acceptance, processing, settlement, fraud monitoring, risk management, reporting issuance and any related services rendered by CARDBIZ.“Equipment” means any physical POS terminals, card readers, Soundbox devices, SIM cards, or related hardware provided by CARDBIZ to the Merchant to facilitate transaction acceptance.

l  CardBiz Pay Gateway” means the online e-commerce payment gateway, application programming interfaces (APIs), software development kits (SDKs), plugins, and digital integration platforms provided by CARDBIZ to enable online transaction processing.

l  Soundbox” means the audio-assisted standalone hardware device provided by CARDBIZ that broadcasts real-time voice and/or visual confirmation alerts for successful QR or alternative digital payment transactions.

l  Payment Scheme Rules” means all rules, regulations, operating guidelines, technical standards, compliance frameworks, and advisories issued by Visa, Mastercard, MyDebit (Payments Network Malaysia Sdn Bhd – PayNet), FPX, UnionPay, Alipay+, or any global or local payment network
provider.

 

2. APPOINTMENT AND SCOPE

2.1 The Merchant is hereby appointed by CARDBIZ, acting under authority of licensed Acquirer Banks, to accept and process Card transactions for the sale of goods and/or services.

2.2 CARDBIZ shall provide the Merchant with card acceptance capability, including terminals, integrations, systems access, onboarding, due diligence processing, transaction routing and settlement processing.

2.3 The Merchant acknowledges that CARDBIZ acts as a TPA, and that final settlement and acquiring liability resides with the respective Acquirer Bank.


2.4 The Merchant agrees to comply with all instructions, manuals, circulars, advisories and operational requirements issued by CARDBIZ or the Acquirer.

 

3. PROVISION AND USE OF EQUIPMENT

3.1 CARDBIZ may provide POS terminals, card readers, payment gateways, software or related equipment (“Equipment”).

3.2 Risk of loss or damage to the Equipment transfers to the Merchant upon delivery.

3.3 The Merchant shall:

a)      maintain the Equipment in good working condition;

b)     not modify, reverse engineer or tamper with the Equipment;

c)      use the Equipment exclusively for lawful card transactions approved under this Agreement;

d)     promptly report any fault, tampering or compromise.

 

3.4 CARDBIZ reserves the right to replace or retrieve the Equipment at any time.

 

3.5 Soundbox Specific Terms: The Merchant acknowledges that the Soundbox relies entirely on cellular telco networks or Wi-Fi connectivity, as well as an active power supply. The Merchant shall ensure that the Soundbox is kept powered on, unmuted, and positioned clearly within the retail outlet during business hours. CARDBIZ shall not be held liable for any failed, not broadcast, or delayed audio confirmations resulting
from telecom network outages, signal degradation, device muting, or hardware tampering by the Merchant’s staff or third parties. The Merchant remains
legally bound to verify successful payment status via the official CardBiz merchant portal or terminal dashboard in the event of an audio discrepancy.

 

3.6 CardBiz Pay Gateway and Security Credentials: For e-commerce and online transaction acceptance, CARDBIZ will issue unique integration credentials, including but not limited to merchant tokens, encryption keys, and API credentials, to the Merchant. The Merchant shall maintain the absolute confidentiality and security of these credentials. The Merchant is solely liable for any transaction manipulation, data breaches,
fraudulent order injections, or unauthorized system access arising from leaked, poorly integrated, or compromised API keys on the Merchant’s website, mobile application, or hosting servers.

 

4. MERCHANT OBLIGATIONS

The Merchant shall at all times:

 

4.1 Accept Cards
Accept all valid and unexpired Cards for legitimate transactions and not discriminate between Cards.

 

4.2 Authorization
Obtain transaction authorization through approved systems prior to completing any sale.

 

4.3 Prohibited Transactions
Not accept Cards for:

a)      cash-equivalent items;

b)     illegal or restricted businesses;

c)      transactions not corresponding to actual delivery of goods/services;

d)     transactions performed on behalf of another business (“factoring”).

 

4.4 Transaction Processing Standards
The Merchant shall:

a)      ensure accuracy of transaction data;

b)     not split transactions;

c)      not manually key-in transactions unless permitted;

d)     maintain proper sales drafts and records.

 

4.5 Compliance with Laws and Standards
The Merchant shall comply with:

a)      PCI-DSS;

b)     Bank Negara Malaysia regulations;

c)      AMLATFPUAA  requirements;

d)    Card Scheme Rules;

e)     Consumer protection and e-commerce laws.

 

4.6 Prohibited Storage of Data
The Merchant shall not store any prohibited cardholder data including CVV2, PIN, or magnetic stripe data.

 

4.7 E-commerce Merchant Obligations (if applicable)
The Merchant shall display:

a)      clear product descriptions and pricing;

b)     refund/return policies;

c)      privacy policy;

d)     legal identity and contact information.

 

4.8 Change of Business
The Merchant shall notify CARDBIZ in writing prior to any change in ownership, corporate structure, business model, risk category, MCC, domain name or other material change.

 

4.9 Record Retention

The Merchant shall maintain and retain copies of all transaction receipts relating to its transactions for a period of seven (7) years.

 

5. FEES AND SETTLEMENT

5.1 The Merchant shall pay:

a)      Merchant Discount Rate (MDR);

b)     transaction fees;

c)      terminal rental fees;

d)     onboarding, compliance or maintenance charges;

e)     any penalties or assessments imposed by card schemes.

 

5.2 Notwithstanding Clause 5.2, CARDBIZ reserves the right to revise the Merchant Discount Rate (MDR), fees or pricing with immediate effect and without prior notice where such revision is required due to:

a)      inaccurate, incomplete or misleading information provided by the Merchant;

b)     changes in the Merchant’s risk profile, business model, MCC or transaction behavior;

c)      excessive chargebacks, disputes, refunds or fraud indicators;

d)     directives, assessments or requirements imposed by the Acquirer, card schemes or regulatory authorities;

e)     Or breach or suspected breach of this Agreement or applicable laws.

f)       Revision is directly necessitated by directives, revised interchange frameworks, rules, or circulars issued by Bank Negara Malaysia (BNM), PayNet, or international Card Schemes

 

5.3 Any revised MDR shall apply prospectively and shall not affect transactions already settled.

5.4 CARDBIZ may implement a rolling reserve, upfront deposit, collateral or withholding arrangement where required due to Merchant risk profile.

 

5.5 CARDBIZ may withhold, delay, suspend or place a hold on settlement funds, in whole or in part, without prior notice, where:

a)      the Merchant has provided false, inaccurate, incomplete or misleading information during onboarding or at any time thereafter;

b)     there is a discrepancy between declared and actual business activities;

c)      there is suspected fraud, AMLATFPUAA concern, scheme rule violation or regulatory risk; or

d)     supporting documents requested by CARDBIZ are not provided within the stipulated timeframe.

 

5.6 CARDBIZ will make every reasonable effort to process and release settlements, refunds, and reimbursements to the Merchant in a prompt and timely  manner.

 

5.7 The Merchant acknowledges and agrees that CARDBIZ is not responsible or liable for any transaction delays or processing errors caused by factors beyond its reasonable control. This includes, but is not limited to, banking system outages, third-party payment processor delays, network failures, or other unforeseen external disruptions.

 

5.8 Cross-Border Currency and Settlement:
All transactions successfully routed via international payment schemes, international cards, or cross-border QR frameworks (including but not limited to DuitNow QR Cross-Border and Alipay+) will be converted into and settled exclusively in Ringgit Malaysia (RM). The conversion rate shall be determined
dynamically based on the prevailing foreign exchange settlement rates applied by PayNet, the respective Card Schemes, or CARDBIZ’s partner Acquirer Banks at the transaction processing timestamp, net of all applicable cross-border processing and interchange fees.

 

5.39 Settlement of funds shall be made net of fees, chargebacks, penalties and reserves. Settlement shall remain on hold until the issue is resolved to CARDBIZ’s satisfaction.

 

6. CHARGEBACKS AND DISPUTES

6.1 CARDBIZ and/or the Acquirer may charge back any transaction that:

a)      is disputed by the Cardholder;

b)     lacks proper authorization;

c)      violates scheme rules;

d)     is fraudulent or suspicious;

e)     involves non-delivery of goods/services;

f)       involves counterfeit, duplicated or invalid card data.

 

6.2 The Merchant shall reimburse CARDBIZ for all chargebacks, penalties, handling fees and assessments.

6.3 CARDBIZ may deduct such amounts from settlement, Merchant’s account or any reserve held.

6.4 Merchant must supply supporting documents within the stipulated timeframe; failure to do so shall result in automatic chargeback acceptance.

 

6.5 CARDBIZ is not responsible for any financial losses, damages, or chargebacks incurred by the Merchant or a customer due to lost, stolen, or compromised payment details, PINs, passwords, or account credentials used in fraudulent transactions.

 

6.6 The Merchant agrees that CARDBIZ is not liable for any losses stemming from unauthorized account access or the use of stolen credentials on the platform, unless such losses are a direct result of CARDBIZ’s own intentional misconduct or gross negligence.

 

7. FRAUD CONTROL, AMLATFPUAA  AND REGULATORY OBLIGATIONS

7.1 The Merchant shall implement anti-fraud controls and report suspicious transactions immediately.

7.2 CARDBIZ may suspend settlements or freeze funds pending investigative procedures.

7.3 Merchant must comply with AMLATFPUAA , FATF requirements, and BNM guidelines on AMLATFPUAA .

7.4 CARDBIZ may terminate the Merchant immediately where AMLATFPUAA  breaches are identified.

 

7.5 CARDBIZ may suspend settlement, freeze funds or restrict transaction processing immediately where information provided by the Merchant is found to be false, misleading or materially inaccurate, pending investigation and remedial action.

 

7.6 CARDBIZ reserves the absolute rights, at its sole discretion to perform investigation on any suspicious transaction made by the Merchant at any time. Merchant agrees to disclose required information and fully cooperate with CARDBIZ and/or any other parties on the investigation. Merchant shall be fully responsible and bear all costs for CARDBIZ to conduct the investigation.

 

7.7 In the event the investigation reveals that the suspicious payment transaction(s) is a fraudulent, illegal and/or unlawful payment transaction, Merchant shall not be entitled to any refund, and it shall be lawful for CARDBIZ to retain such funds for any indefinite period or release such funds to the authority according to applicable law. The Merchant shall not be entitled to claim any form of compensation for any losses incurred.

 

8. DATA SECURITY AND PCI-DSS COMPLIANCE

8.1 The Merchant shall strictly adhere to PCI-DSS requirements.

8.2 In the event of a data breach, the
Merchant shall:

a)      grant CARDBIZ and forensic auditors full access to systems;

b)     bear all costs of investigation, remediation and scheme fines;

c)      notify affected parties as required by law;

d)     immediately implement corrective actions.

 

8.3 Non-compliance with PCI-DSS constitutes serious breach warranting suspension or termination.

 

9. AUDIT, INSPECTION AND REPORTING

9.1 CARDBIZ, the Acquirer, card schemes or regulatory authorities have the right to inspect and audit the Merchant’s physical premises, technical systems, databases, books, and operational records at any time.

9.2 The Merchant must fully cooperate with any audit or inspection. This includes granting physical access to premises, providing remote or on-site access to relevant software and hardware systems, and delivering requested documents or records without delay.

9.3 Upon request, the Merchant shall promptly provide CARDBIZ with:

a)      Up-to-date PCI-DSS compliance certificates or Self-Assessment Questionnaires (SAQ).

b)     Completed risk assessments, security questionnaires, or periodic compliance declarations.

c)      Any other documentation required by CARDBIZ to verify compliance with card scheme rules or local laws.

 

9.4 CARDBIZ reserves the right to conduct immediate, unannounced inspections without prior notice if fraud, a security breach, or a serious violation of this Agreement is suspected.

 

10. SUSPENSION AND TERMINATION

10.1 CARDBIZ may suspend or terminate the Merchant’s access immediately where:

a)      there is breach of AMLATFPUAA, suspected fraud, illegal activity or data compromise;

b)     excessive chargebacks or dispute ratios occur;

c)      the Merchant and/or its employees breaches any material term of this Agreement;

d)      the Merchant becomes insolvent or ceases business;

e)      regulatory or scheme directives mandate suspension.

 

10.2 The Merchant may terminate this Agreement with thirty (30) days’ written notice.

10.3 CARDBIZ may withhold settlement funds for up to one hundred eighty (180) days post-termination to cover chargeback exposure.

10.4 Termination does not affect accrued liabilities.

 

11. LIABILITY AND INDEMNITY

11.1 The Merchant shall indemnify and hold harmless CARDBIZ, the Acquirer and card schemes against any loss, liability, penalty, cost or damage arising from:

a)      Agreement Breaches: Any violation of these Terms & Conditions, the Merchant Services Agreement, or any specific provision contained within them.

b)     Negligence & Misconduct: Any mistakes, neglect, fraud, willful misconduct, or intentionally wrongful acts or omissions by the Merchant, their staff, contractors, or representatives.

c)      Transaction Issues: Any unauthorized, fraudulent, or illegal transactions committed by or linked to the Merchant, their team, or their customers.

d)     Third-Party Defamation: Any successful third-party claims alleging libel or slander stemming from how the Merchant manages or processes transactions.

e)      System Charges & Penalties: Any penalty fees, charges, or financial assessments levied by any Payment Scheme, card networks, regulatory bodies due to the Merchant’s activities.

f)       External Directives: Any situation where a government authority compels CARDBIZ to make payments due to illegal or fraudulent transactions occurring beyond CARDBIZ’s control.

g)      Data Security & Compliance: Any data compromise, security breaches, or failure to comply with Payment Card Industry (PCI) data security standards.

h)     Rights Infringement: Any actual or alleged violation of a third party’s legal rights, including intellectual property rights, in connection with the services provided.

i)       Legal & Regulatory Violations: Any breach of statutory or regulatory obligations by the Merchant.

j)       Customer Misrepresentation: Any false, misleading, or inaccurate statements made by the Merchant to cardholders.

  

11.2 CARDBIZ will not be held responsible, liable, or financially accountable to the Merchant for the following:

a)      Indirect Impacts: Any indirect, incidental, special, or consequential losses.

b)     Operational Disruptions: Business interruptions, operational downtime, or loss of business data.

c)      Financial Reductions: Lost profits, revenue, etc

d)     System Outages: Technical system downtimes, network failures, or service interruptions, provided they were not directly caused by CARDBIZ’s own gross negligence or willful misconduct.

 

11.3 Neither CARDBIZ nor its officers, directors, agents, shareholders, or employees will be liable to the Merchant for any indirect, incidental, special, exemplary, punitive, or consequential damages. This exclusion explicitly covers business interruptions, loss of profits, lost revenue, lost data, or missed business opportunities, even if CARDBIZ was warned that such damages could occur.

 

11.4 The Merchant acknowledges that any issues, technical errors, or damages resulting from the use of the Merchant website integration are entirely outside of CARDBIZ’s control and responsibility.

 

11.5 CARDBIZ is not liable for any direct or indirect damages including loss of profits, data, or business resulting from the use, failure, or malfunction of any third-party plugins selected by the Merchant.

 

12. CONFIDENTIALITY AND DATA PROTECTION

12.1 Both Parties shall maintain confidentiality of all information exchanged under this Agreement.

12.2 The Merchant authorizes and consents to CARDBIZ and its representative to obtain information pertaining to this application from any source, including but not limited to credit information, from the Inland Revenue Board (IRB) Authorities, Employees Provident Fund (EPF), other financial institutions, Central Credit Reference Information System (CCRIS), Credit Tip-Off Service (CTOS), Experian Credit & Information Services (Experian) (formerly RAM Credit Information (RAMCI)), SME Credit Bureau, any other credit reference agencies, any other person, individual and/or entity, as CARDBIZ deem appropriate, without assigning any reason whatsoever.

 

12.3 The Merchant expressly consents and authorizes CARDBIZ to disclose to Bank Negara Malaysia, Payments Network Malaysia (PayNet), any other regulatory bodies, law enforcement agencies, financial institutions, authorities such as debt collection agents, any person(s) in or outside Malaysia including but not limited to the Group Companies within CARDBIZ, whether residing, situated, carrying on business, incorporated or constituted within or outside Malaysia, including but not limited to the respective agents, authorized and appointed outsourcing agents for purpose of providing integrated services, maintaining and storing records (financial or otherwise), at any time and without liability, any information and particulars (financial or otherwise) relating to the Merchant and accounts, financing and conduct thereof for such purposes as CARDBIZ deem fit or appropriate.

 

12.4 By accepting this agreement, the
Merchant hereby agrees and expressly consents and shall be deemed to have given their consent to allow CARDBIZ and/or their respective holding companies, subsidiaries, associates, partners, agents and merchants or related corporations to use, process, disclose, transfer or to deal with the Merchant’s
personal data (if any), whether in electronic or other form and whether provided orally or in writing to CARDBIZ, including but not limited to such personal data as are provided in the application form and any changes thereto and any other personal, financial or sensitive personal data about the Merchant as CARDBIZ deems appropriate (collectively “Personal Data”) for the following purposes:


a)      To facilitate the delivery of services or products and the marketing and promotion of services or products whether present or future, to the Merchant;


b)     Those purposes specifically provided for in any particular service or product offered by CARDBIZ and/or their respective holding companies, subsidiaries, associates, partners, agents and merchants or related corporations;


c)      CARDBIZ’s internal record keeping, maintenance and updating of any information database(s), customer service-related matters and other administrative purposes, including audits, fraud monitoring and prevention;


d)     To communicate with the Merchant, including responding to the Merchant’s enquiries;


e)     Meeting or complying with any legal, regulatory or statutory requirements relating to CARDBIZ’s provision of services and products and to make disclosure under the requirements of any applicable law, legislation, rule, ruling, regulation, direction, court order, by-law, guideline, circular, code (collectively “laws”) applicable to CARDBIZ or any member companies of CARDBIZ’s Group Companies;


f)       Research, benchmarking and statistical analysis; and/or


g)      Other reasons that are required or permitted under the Personal Data Protection Act 2010 or other applicable laws.

 

12.5 The Merchant warrants compliance with the Personal Data Protection Act 2010 (PDPA) acknowledge and agree with the CARDBIZ Group Privacy    Notice available at www.cardbiz.com.my

 

13. GOVERNING LAW AND DISPUTE RESOLUTION


13.1 These T&C shall be governed by and construed in accordance with the laws of Malaysia.

13.2 Any dispute shall be subject to the exclusive jurisdiction of the Malaysian courts.

13.3 CARDBIZ may pursue injunctive or other equitable relief where appropriate.

 

14. MISCELLANEOUS


14.1 Right to Amend and Deemed Acceptance: CARDBIZ reserves the right to amend, vary, modify, or replace these Terms and Conditions, operational guidelines, or schedules at any time by publishing the updated version on the official CardBiz company website (https://www.cardbiz.com.my/terms-conditions). CARDBIZ will notify merchants of material modifications via website announcement, email notification, terminal
display message, or merchant e-statement. It is the Merchant’s ongoing responsibility to review the website regularly for updates. The Merchant’s
continued routing of transactions, deployment of physical terminals, use of the Soundbox, or integration of the CardBiz Pay Gateway after the effective date of any amendment shall constitute the Merchant’s unconditional, conclusive, and legally binding acceptance of the revised Terms and Conditions.

14.2 The Merchant may not assign or transfer its rights under this Agreement without CARDBIZ’s prior written consent.

14.3 No failure to enforce shall constitute a waiver.

14.4 If any provision is held invalid, the remainder shall remain in full force.

14.5 These T&C bind the Parties and their successors.