Understand GDPR Data Processing
Last updated on Sep 19, 2026
Under GDPR, Advanced Billing acts as a data processor on your behalf: you manage consent and data governance as the Merchant, and Maxio keeps the systems handling your Customer data secure and compliant.
When you need these lists
The sub-processors, third-party vendors, and integration partners named below are what you need when completing a privacy impact assessment, preparing for an audit, or answering a Customer's question about how their personal data is handled.
Our GDPR compliance commitments
The commitments below describe what Maxio takes on as your processor, and they are the points most often asked about in a privacy impact assessment or vendor review.
- Safeguard your data through secure infrastructure, encryption, and access controls.
- Maintain certifications (e.g., EU-U.S. Privacy Shield or successors) to support cross-border data transfers.
- Disclose all sub-processors and conduct ongoing reviews of their GDPR compliance.
- Maintain detailed compliance records, audit trails, and system logs.
- Provide tools and workflows to support data subject rights (DSRs), such as right-to-access and right-to-erasure.
- Offer standardized Data Processing Addendums (DPAs) for all customers.
- Promptly notify your designated account contact in the event of a security breach, in accordance with our incident response protocols.
How to request a Data Processing Addendum (DPA)
Our standard Data Processing Addendum (DPA) is available for Advanced Billing customers. To request a copy, email support@maxio.com and our Legal team will respond within 3–5 business days.
Data processors
When a Merchant’s employee accesses the Advanced Billing system, we use various data processors. These do not receive personal information about subscribers or end-customers.
Sub-processors
These services may store or process personal data of your subscribers, depending on your configuration:
- Amazon Web Services
- SumoLogic
- SendGrid (if email is enabled)
- Avalara (if tax integration is enabled)
- Honeybadger
- Heroku
- Google Cloud
Third-party integration partners
Maxio provides optional integrations through APIs, built-in connectors, and webhooks. We do not evaluate the GDPR compliance of these third-party services. Merchants are responsible for conducting their own due diligence and ensuring appropriate data processing agreements are in place.
- Your chosen Gateway or Payment Processor
- Avalara
- Xero
- QuickBooks Online
- Salesforce
- Mailchimp
- Shopify
- Twilio
Related information
For the roles GDPR defines and how they map to you and Maxio, see Understand GDPR Compliance.
For the card-data standards that apply alongside GDPR and which self-assessment questionnaire fits your setup, see Understand PCI Compliance.
To see what Maxio's session replay tool captures and how to opt out, see Understand FullStory Session Replay.
Still need help?
Reach out and our support team will take it from here.
