Keep the purpose in view

A payment reference, a customer record and a trade document each have a purpose. The information needed to reconcile an invoice may differ from the information required to confirm membership or support an approval. Define that purpose before deciding who needs access.

For a proposed CapitalPay implementation, the data discussion should cover the systems connected, the organisations involved and the records exchanged. It should identify the controller and processor responsibilities applicable to that service.

Access and accountability

A useful access model distinguishes the person creating a record, the person approving an action and the person reviewing an exception. Data exports, changes to access and support requests belong in that conversation too.

Retention, hosting, incident handling and the applicable provider controls should be addressed in the service documentation. Ask for the information relevant to your implementation when discussing requirements with our team.

Using this website

Our contact form collects the details you provide so the team can handle your enquiry. Please share a summary rather than customer files or sensitive payment information. The privacy notice explains the website’s use of personal information.

Report a concern

Send a brief description to support@capitalpay.co.uk. Include the service or page involved and a way to contact you. Keep passwords, authentication codes and card details out of the message.