Understand GDPR Compliance
Last updated on Sep 19, 2026
Maxio complies with the General Data Protection Regulation (GDPR) and provides the tooling you need to meet your own obligations under it. The sections below cover which GDPR role Maxio takes on, which one you take on, and what Maxio does on your behalf.
Controller and processor roles
The GDPR defines roles for handling personal data: a data controller determines how and why data is collected, while a data processor acts on the controller’s behalf. Maxio Advanced Billing functions as your data processor, and you, as the merchant, typically serve as the data controller.
How Maxio helps you stay compliant
Maxio provides the technical foundation and operational support needed to meet your obligations as a data controller by:
- Safeguarding personal data through secure infrastructure and encryption.
- Maintaining compliance with applicable global privacy standards.
- Offering features to support data subject rights.
- Alerting you promptly in the event of a breach.
Related information
For the named sub-processors, third-party vendors, and integration partners involved in Maxio's data processing, sign in and see Understand GDPR Data Processing.
For the card-data standards that apply alongside GDPR, see Understand PCI Compliance.
To see what Maxio's session replay tool captures and how to opt out, see Understand FullStory Session Replay.
Still need help?
Reach out and our support team will take it from here.
