NewMaxio Metering is now available — usage-based billing for Advanced Billing.Learn more
/

Understand GDPR Data Processing

··

Last updated on Sep 19, 2026

Under GDPR, Advanced Billing acts as a data processor on your behalf: you manage consent and data governance as the Merchant, and Maxio keeps the systems handling your Customer data secure and compliant.

When you need these lists

The sub-processors, third-party vendors, and integration partners named below are what you need when completing a privacy impact assessment, preparing for an audit, or answering a Customer's question about how their personal data is handled.

Our GDPR compliance commitments

The commitments below describe what Maxio takes on as your processor, and they are the points most often asked about in a privacy impact assessment or vendor review.

  • Safeguard your data through secure infrastructure, encryption, and access controls.
  • Maintain certifications (e.g., EU-U.S. Privacy Shield or successors) to support cross-border data transfers.
  • Disclose all sub-processors and conduct ongoing reviews of their GDPR compliance.
  • Maintain detailed compliance records, audit trails, and system logs.
  • Provide tools and workflows to support data subject rights (DSRs), such as right-to-access and right-to-erasure.
  • Offer standardized Data Processing Addendums (DPAs) for all customers.
  • Promptly notify your designated account contact in the event of a security breach, in accordance with our incident response protocols.

How to request a Data Processing Addendum (DPA)

Our standard Data Processing Addendum (DPA) is available for Advanced Billing customers. To request a copy, email support@maxio.com and our Legal team will respond within 3–5 business days.

Data processors

When a Merchant’s employee accesses the Advanced Billing system, we use various data processors. These do not receive personal information about subscribers or end-customers.

Sub-processors

These services may store or process personal data of your subscribers, depending on your configuration:

Third-party integration partners

Maxio provides optional integrations through APIs, built-in connectors, and webhooks. We do not evaluate the GDPR compliance of these third-party services. Merchants are responsible for conducting their own due diligence and ensuring appropriate data processing agreements are in place.

  • Your chosen Gateway or Payment Processor
  • Avalara
  • Xero
  • QuickBooks Online
  • Salesforce
  • Mailchimp
  • Shopify
  • Twilio

For the roles GDPR defines and how they map to you and Maxio, see Understand GDPR Compliance.

For the card-data standards that apply alongside GDPR and which self-assessment questionnaire fits your setup, see Understand PCI Compliance.

To see what Maxio's session replay tool captures and how to opt out, see Understand FullStory Session Replay.

Still need help?
Reach out and our support team will take it from here.

Contact support