S3™ Network Rules
Updated March 11, 2026
A copy of the S3™ network rules can be found below. Message specs are also available upon request by contacting [email protected].
Optum Financial, Inc. (“Optum”), in operating the S3™ Network (the “Network”), has established these S3™ Network Rules (“Network Rules”) that are designed to minimize risks and provide a consistent, secure, and reliable network experience, while additionally supporting the varying needs of the marketplace. These Network Rules are set and modified by Optum to support the use and operation of the Network and represent a binding contract between Optum, Merchants, and each Network Participant. In addition to these Network Rules, conduct of Merchants and Network Participants is governed by the S3™ Network Technical Specifications (“Technical Specifications”), incorporated by reference herein. These Network Rules are intended to be read in concert with the S3™ Network Merchant Agreement (the “Agreement”) and the Technical Specifications (collectively, the “Network Agreements”). Capitalized terms used but not defined in these Network Rules shall have the respective meanings assigned to them in the Agreement or the Technical Specifications. In the event of a conflict, the terms of the Network Rules and Technical Specifications shall take precedence over the terms of the Agreement. We have the right to make changes to the Network Rules and Technical Specifications as set forth in the terms of the Network Agreements. Failure to comply with the Network Agreements may result in penalties assessed against a Merchant or Network Participant by Optum, up to and inclusive of removal or suspension from the Network. By transacting on the Network, you agree to be bound by the terms of these Network Rules.
I. Participating on the Network
- The Network Rules. The Network Rules set forth the policies and procedures governing your acceptance of Cards and participation on the Network. The Network Rules are designed to allow us to serve all Merchants consistently, and as such, we require all Merchants, as well as any third parties contracted by a Merchant to perform services related to acceptance of Cards or transacting on the Network, to operate under the Network You agree to be bound by and to accept all provisions in these Network Rules as a condition to your ability to accept Cards and to transact on the Network.
- Capitalized terms used but not defined in these Network Rules shall have the respective meanings assigned to them in the Agreement or the Technical Specifications.
- Changes to the Network Rules and Technical Specifications. We reserve the right to make both scheduled and unscheduled changes to the Network Rules and Technical Specifications, as set forth herein (collectively “Change Notices”). You agree to accept all such changes, and to abide by the changed provisions, except where prohibited by Applicable You must provide us with an email address for delivery of all Change Notices, to be included in Section 14(b) of the Agreement. You are responsible for alerting us to any changes to this email address. All Change Notices shall be deemed delivered upon sending by Optum. Failure by you to provide an email address, or to update us as to changes or issues with the email address you previously provided, shall not relieve you of the obligations denoted herein.
- Scheduled Changes/Compliance Date. Optum may publish scheduled changes to the Network Rules and Technical Specifications, every six (6) months (“Scheduled Change Notice”). Merchant shall have eighteen (18) months from the date Optum sends the Scheduled Change Notice to Merchant to implement the enhancements or changes included in the Scheduled Change Notice (“Compliance Date”). Scheduled Change Notices shall be delivered via email, to the email provided by you in Section 14(b) of the Agreement, or you may contact us at [email protected] to request a copy of any Scheduled Change Notice.
Unscheduled Changes. Urgent updates to the Network Rules and Technical Specifications deemed critical for Network operation, security, or for other reasons as may be determined by Optum, may be released in separate, unscheduled releases at any time (“Unscheduled Change Notices”). Such Unscheduled Change Notices shall take effect ten (10) business days after they are sent to you, unless another effective date is specified in the notice (“Unscheduled Change Notice Compliance Date”). Unscheduled Change Notices shall be delivered via email, to the email provided by you in Section 14(b) of the Agreement, or you may contact us at [email protected] to request a copy of any Unscheduled Change Notice.
Change Notice Compliance Requirements. Merchant shall comply with all Change Notices by making all updates necessary to implement the referenced enhancements in any Change Notice by the applicable Compliance Date or Unscheduled Change Notice Compliance Date.
Non-Compliance. You must ensure that you, and any third parties engaged by you, comply with these Network Rules, Technical Specifications, and any applicable Change Notices related thereto. Failure to comply with the Network Rules, Technical Specifications, or any Change Notices may impact your ability to successfully process Transactions and may result in fines and/or penalties being assessed against you by us, as well as potential removal or suspension from the Network. Failure by a Merchant to comply with any and all Change Notices which results in an interruption of service for the Network, shall be solely the responsibility of Merchant, and all costs or penalties incurred by Merchant or Optum associated with Merchant’s failure shall be the sole responsibility and at the sole cost of Merchant.
Network Rules and Technical Specifications Waiver. In Optum’s sole discretion, a Merchant may request, and Optum may grant, exceptions to certain of these Network Rules and/or the Technical Specifications (each, a “Waiver”). Any Waiver request must be made in accordance with Optum’s then-current Waiver Policy and is subject to every eligibility criterion, documentation requirement, and other limitations set forth in that Policy. No Waiver is effective unless (i) Optum grants it in a writing signed (or electronically authenticated) by an authorized Optum representative and (ii) that writing expressly identifies the provision(s) waived or modified, the conditions attached, and the period for which the Waiver applies. Both the Waiver request and, if granted, the Waiver itself are governed by the Waiver Policy and by all conditions, restrictions, and time limits stated in Optum’s written approval. Each Waiver is specific to the requesting Merchant, granted solely for that Merchant’s benefit, applies only to the circumstances described in the approval, and does not waive, modify, or amend any other provisions of the Network Rules. Optum may revoke or modify a Waiver in accordance with the Waiver Policy. For the avoidance of doubt, the S3 Network Merchant Agreement may not be modified or amended via a Waiver.
- Third Parties. In the event Merchant has contracted with a third party to perform services related to the Network, Transactions, or similar, as contemplated herein, Merchant shall be solely responsible for compliance by those third parties with these Network Rules and the Technical Specifications, and further, shall indemnify Optum and its Affiliates for all Losses which may occur as a result of services performed by said third parties. Optum reserves the right to refuse access to the Network, or to accept Transactions submitted by, any third party contracted by Merchant, unless otherwise prohibited by Applicable Law. See also, “Use of Third Parties.”
- Joining the Network. You must provide the Merchant Information and Required Information required by Optum to be evaluated for participation on the Network. We reserve the right to decline access to the Network to any Merchant or Merchant Location, in our sole discretion, unless otherwise prohibited by Applicable Once you are authorized to submit Transactions on the Network, you must adhere to all of the requirements of the Network Agreements, or be subject to removal from the Network, or we may assess other fines or penalties as further detailed in the Network Agreements.
- Merchant Identification Number. Your Merchant Identification Number is a unique number we assign to you and your Merchant Locations. If you have more than one Merchant Location, we may assign you a separate Merchant Identification Number for We reserve the right to refuse to assign a Merchant Identification Number or grant Card acceptance privileges to a Merchant or Merchant Location. Your Merchant Identification Number is the sole property of Optum and you shall only use it for operating your Card acceptance relationship with us. You shall not assign or otherwise transfer any Merchant Identification Number to any other party. You are responsible for safeguarding your Merchant Identification Number(s).
- Bank Identification Numbers. Optum shall be responsible for providing the Card to Cardholders, with the applicable Bank Identification Number (“BIN”), whether the Card is an S3™ Card or a dual-branded Card in partnership with another unaffiliated network.
- Merchant Information.
- Merchant Information and Communication. You must have provided all requested information, as may be required by Optum, as fully detailed in the Network Agreements, including Required We may obtain, verify, record, and analyze information (including your telephone calls) that identifies each person (which may, in our sole discretion, include information about your owners) agreeing to accept the Card and participate on the Network, as well as information that may be provided in subsequent calls or interactions with us. We will use such information to improve our services, prevent fraud, or for our or our Affiliates other business purposes. When you agree to accept the Card and transact on the Network, we may ask for your business name, a business street address, a business phone number, and a business federal tax identification number (“TIN”), as further detailed in the Agreement. (Collectively, “Merchant Information”.)
- Required Merchant Information. We may ask for some or all of the information listed below from any Merchant seeking to participate on the Network (“Required Information”). Any such information requested by us, in accordance with this Section, shall be provided by Merchant as a condition precedent to transacting on the Network. This list is not exhaustive, and we may require additional personal information about all categories of people, including significant owners, authorized signers, (If requested, such additional information requests shall be included in the definition of Required Information.) Required Information includes:
- banking information (e.g., routing number, Bank Account, bank name) (See related Bank Account provisions in the Agreement and the “Merchant Bank Account Information” Exhibit), verified by a third party;
- legal name of business or corporate owner registered with the Internal Revenue Service (“IRS”);
- federal tax identification number as registered with the IRS;
- full physical address/location (including hours of operation);
- geolocation (latitude and longitude);
- franchise location and franchisee information where applicable;
- telephone number at which we can contact you (e.g., your business telephone number), telephone number at which your customers may contact you (e.g., your customer service telephone number);
- email address at which we can contact you (e.g., your business email address);
- email address at which your customers may contact you (e.g., your customer service email address);
- website URL;
- goods/services offered (type of business);
- method of doing business (e.g., mail-order, internet, storefront);
- form of organization (e.g., sole proprietorship, partnership, limited liability company, corporation, non-profit, government);
- publicly traded or privately held organization;
- ownership/control (e.g., sale of business, change in control of business);
- significant owners that control 25% or more of your business. If you do not have a single significant owner that controls 25% or more, you still must provide one For each significant owner or owner, provide: name, full home physical address/location, Social Security Number or date of birth, authorized signer information, name and title, Social Security Number, other critical business information that helps us contact or do business with you (e.g., change of Processor); and
- Any additional information as may be required to comply with Applicable Law or other processing requirements.
- Merchant Significant Owner and Personnel Information Requests. Additionally, we may request or require that you provide information about your significant owners, personnel (e.g., authorized signers), and Merchant Locations, including: name, street address, date of birth, an identification number (e.g., a Social Security Number).
- Use of Merchant Information. Pursuant to the Agreement, we may use and share Merchant Information (or Merchant Significant Owner Information, where applicable) for our or our Affiliates’ business purposes and as otherwise permitted by Applicable Law. We use reasonable administrative, technical, and physical security measures to protect Merchant Information consistent with the sensitivity of the information.
- Verification and Disclosure of Information. You acknowledge that when you provide information to us that such information may be disclosed and shared with your agents, subcontractors, Affiliates, and other parties, including Optum and its Affiliates, industry organizations, and reporting agencies, for any purpose permitted by Applicable Law. Optum collects and retains such information, shares such information with Affiliates and its other business lines, and may use such information to improve services, prevent fraud, and for other business purposes, including conducting analytics and making information available to certain third parties, including for tax reconciliation or expense management services and their users. You further acknowledge that, by entering into the Agreement with us, you provide permission to obtain or disclose information in connection with the Network Agreements, consent to our or our Affiliate’s disclosure of such information for the foregoing purposes, and hereby release and waive any right or Claim arising out of or related to such disclosure, including defamation claims, even if the information that is disclosed is incorrect or incomplete.
- Changes to Merchant Information. You must notify us of any additions, deletions, and/or modifications to your Merchant Information. Specifically, you must notify us immediately of changes related to any of the Required Information detailed in this Section.
- Merchant Location Changes. Merchant shall provide an updated Merchant Location list within sixty (60) days of a Merchant Location becoming available to receive Transactions, whether by virtue of acquisition, change of ownership, new build, etc. Merchant shall also provided an updated Merchant Location list within five (5) business days a Merchant Location or brand being decommissioned.
- Compliance with the Technical Specifications. Subject to and in accordance with the Technical Specifications, Merchant shall be obligated to update and maintain the Merchant POS System and/or E-commerce system integration and connectivity to include technical and communication services necessary for automated processing of Transactions at all times. Failure to update and maintain the Merchant POS System, in accordance with the Network Agreements, may result in penalties assessed against Merchant, up to and including suspension or removal from the Network. (Refer to “Suspension” Section herein.)
- Merchant Location Closing. If you close any Merchant Location, you must notify us immediately and additionally follow these guidelines:
- You must convey your closure policies to the Cardholder prior to completion of a Charge.
- If you are not providing refunds or exchanges, you must post notices that all sales are “final” at easily identified locations, such as at the front door, near the POS System, on your websites, and/or in catalogs.
- Your return and cancellation policies must be clearly disclosed at the time of sale.
- Support and Customer Service
- Cardholder Support
- Optum may provide assistance to Cardholders regarding the Network or use of the Card via the website, mobile application, phone, and/or email, in accordance with Optum’s agreements with Clients, where required;
- Merchant shall maintain its own program to meet its customer support obligations, and such obligations shall be considered outside the scope of these Network Rules. For the avoidance of doubt, while Optum may from time-to-time have occasion to interact with Merchant customers in its role as Network operator or as a program manager for its Clients, Optum and its Affiliates shall have no obligation to Merchant to provide customer support to Merchant customers.
- To the extent Merchant receives complaints or feedback from its customers related to the Network or any other Optum product or service, Merchant shall share such feedback with Optum during the quarterly planning meetings, as contemplated in the Marketing Requirements, or on such other cadence and via such means as may be agreed by the Parties.
- Merchant Support by Optum
- Post-Implementation support, where applicable, shall be provided in accordance with the terms of the Agreement, and as may be further agreed by the Parties in an applicable statement of work.
- Reporting
- Provide Merchant with access to certain administrative and reporting tools for the Network related to the Agreement, as may be agreed upon by the Parties and incorporated in the Agreement or a related document;
- Upon Optum’s direct receipt of a request by a Merchant or a third-party directed or authorized by Merchant to make a request, provide such Merchant or third-party with Merchant Data about that Merchant, as Optum may be authorized to do under Applicable Law;
- Suspension. If Optum deems that Merchant has not satisfactorily fulfilled its obligations pursuant to the Network Agreements, Optum, at its discretion, may suspend Merchant’s participation in the (Refer to “Term and Termination” Section of the Agreement.)
- Records. Optum will keep records relating to the services provided under the Network Agreements for the later of Optum’s record retention policy requirements or requirements under Applicable Law.
- Cardholder Support
II. Card Acceptance
- Card Acceptance, Generally
- Upon acceptance onto the Network and finalization of the Implementation Plan has occurred, Merchant shall accept all Cards, Programs, and Purses at all Merchant Location, all cashier-assisted and self-checkout lanes, and all other checkout options, via all form factors, at all times, unless otherwise prohibited by the terms of the Network Agreements or Applicable Law, or unless otherwise agreed by the Parties in writing.
- Merchant must be capable of accepting Magnetic Stripe, keyed entry, and barcode-based, including but not limited to barcode from mobile, form Where applicable, Merchant must implement Europay, Mastercard, and Visa (“EMV”) and/or Near-Field Communication (“NFC”) technology as required within the Technical Specifications. (EMV® is a registered trademark in the U.S. and other countries and an unregistered trademark elsewhere. The EMV trademark is owned by EMVCo, LLC.)
- Physical forms of Cards, including plastic and mobile devices, must be accepted;
- Only the person whose name appears on a Card is entitled to use Cards are not transferable.
- Non-Exclusivity. Merchant shall not permit exclusive or preferential acceptance of any network or card above any other network or card, unless otherwise consistent with the choice of the Cardholder. Merchant shall additionally not express a preference for use of a particular card or network or means of payment.
- No Minimum or Maximum Charge Limits. Merchant shall not require of a Cardholder a minimum or maximum Transaction amount for a Card to be accepted for a Transaction on the
- Appropriate Acceptance. Merchant shall ensure that Item information provided to Optum for the Transaction appropriately reflects the composition of Cardholder’s total Order, as may be required in the Technical Specifications.
- Prohibited Uses of the Card. You must not accept the Card for any of the following:
- for purchase of any Items that we deem to be non-compliant under a Program;
- for government-issued benefits Cards, any Transactions prohibited or not qualified for payment under the applicable regulations for the relevant government entity (e.g. Centers for Medicare & Medicaid Services, state food or housing benefit programs, or other similar government programs);
- amounts that do not represent bona fide sales of goods or services at your Merchant Locations; for example, purchases at your Merchant Locations by owners (or their family members) or employees contrived for cash flow purposes, or payments that you have accepted in order to advance cash to Cardholders in connection with the Transaction;
- amounts that do not represent bona fide, direct sales by your Merchant Location to Cardholders made in the ordinary course of your business;
- Charges that the Cardholder has not specifically approved;
- any costs or fees over the normal price of the goods or services, inclusive of sales and use taxes, qualified for payment under the eligible program that the Cardholder has not specifically approved;
- damages, losses, penalties, or fines of any kind;
- unlawful/illegal activities, fraudulent business transactions or when providing the goods or services is unlawful/illegal (e.g., unlawful/illegal online internet sales of prescription medications or controlled substances; sales of any goods that infringe the rights of a rights-holder under laws applicable to us, you, or the Cardholder);
- overdue amounts or amounts covering returned, previously dishonored or stop-payment checks (e.g., where the Card is used as a payment of last resort);
- amounts that represent repayment of a cash advance including, but not limited to, payday loans, pawn loans, or payday advances;
- sales by third parties;
- or other items of which Optum or its Affiliates notifies you; and
- a Card may not be used as a method of age verification.
- Receipts. Merchant will present coverage and eligibility information in Cardholder receipts reflecting Transaction Receipts shall include sufficient information to inform Cardholder of Items covered, applicable Purse applied, and identifying Card information, including total benefit amount applied, amount per Purse utilized, and Card used. Receipts shall comply with all requirements included in the Technical Specifications. (See also “Transaction Records” requirements as detailed herein.)
- Treatment of Cardholder Information. Any and all Cardholder Information is confidential and the sole property of the Issuer, Optum, or its Except as otherwise specified, you must not disclose Cardholder Information, nor use nor store it, other than to facilitate Transactions at your Merchant Locations in accordance with the Agreement. For more information about data treatment, see the “Data Ownership, Licensing, Authorized Use, and Access” Section of the Agreement.
- E-commerce Card Acceptance. An E-commerce Transactions platform may be supported at the discretion of Optum. The details of such integration shall be found in the applicable Implementation Plan, or as otherwise may be agreed between the Parties in writing.
- Cardholder Support. Merchant will provide in-store, and/or digital customer support for Cardholders to assist with returns, product concerns and general Additionally, the POS System must be designed in accordance with the Technical Specifications and support all necessary Transaction related function, including but not limited to correct display, Transaction representation, etc.
Account Management. Merchant shall provide a single point of contact to serve as the primary account manager for day-to-day topics and issues. Additionally, Merchant shall provide an escalation contact to address any matters not resolved with the account manager. In addition, the Parties shall meet on a mutually agreed upon basis to review Transaction performance.
Ongoing Training.
Updated Training Materials. Periodically, Optum may refresh training materials regarding the Network, Cards and/or Programs. Such changes to training materials, and related Program or technical changes as may be required, shall be delivered to Merchant via a Change Notice. Merchant shall share and train its employees and agents on such updates as required by the Change Notice Compliance deadlines delineated herein.
Refresher Trainings. Merchant shall perform year-end refresher training on the Network and Card acceptance procedures, as well as before the launch of any new Program updates at all Merchant Locations.
- Training Audit. In accordance with the requirements set forth in your Agreement with us, Merchant shall cooperate with Optum’s performance of an audit of Merchant’s compliance with the requirements of this Section at any time, including a third-party audit or mystery shopping audit. To the extent the audit returns findings of non-compliance by Merchant, Merchant agrees to cooperate with Optum to have the audit repeated at in time in the ensuing six (6) month period, following the non-compliant results finding, in Optum’s discretion.
III. Transaction Processing
- Transaction Process. All valid Transactions begin with a Cardholder’s decision to make a purchase. Whether the physical Card is used to facilitate a Card Present Charge, or the Cardholder provides their Cardholder Information over the phone, via mail-order, or the internet, the Transaction must not be completed without the Card and/or information provided by the Cardholder. All Transactions must be processed in accordance with the Technical Specifications, including but not limited to those listed in this Section.
- Card Acceptance Requirements. To accept the Card for Charges at your Merchant Locations, you must:
- Clearly and conspicuously, disclose all material terms of sale before obtaining an Authorization, and clearly and conspicuously inform Cardholders at all points of interaction (e.g., sales conducted in person, over the internet, mobile or via mail or telephone order) about what entity is making the sales offer, so that the Cardholder can clearly distinguish you from any other party involved in the interaction (e.g., a vendor of goods or provider of services you may engage, or another Merchant seeking to conduct business with the Cardholder).
- The Transaction Data you collect to facilitate the Charge must be, or have been, provided directly to you by the Cardholder.
- You must not accept or have accepted Transaction Data from, nor shall you provide or have provided Transaction Data to, any third parties other than those authorized by If you fail to comply with this requirement, you may be assessed non-compliance fees and/or be removed from the Network, in Optum’s sole discretion.
- You must comply with all Technical Specifications to be authorized to accept Transactions on the Network.
- In-Person Charges. “In-Person Charges” refer to Charges in which the Card and Cardholder are present at the point of An example of this is when a Cardholder presents a Card to the you at a Merchant Location. For all In-Person Charges, the Card must be presented.
- Electronic Charges. Electronic POS Systems automatically capture required information from the Card so it can be used to request Authorization for the Charge. Electronic charges can be conducted in a variety of ways depending on the type of Card Merchant is required to accept the type of Electronic charge as may be required by Optum and the Technical Specifications, as updated from time-to-time. You must work with your POS System provider if you have questions about your POS System capabilities, as it relates to the various methods of electronic charges. Two methods of conducting electronic charges include via Magnetic Stripe Cards or Mobile Devices.
- Magnetic Stripe Cards. Magnetic Stripe Cards contain Cardholder and Card account information on the Magnetic Stripe on the Card, or in a contactless Chip embedded in the For Magnetic Stripe Card Transactions, when presented with a Card at the point of sale, you must:
- Verify that the Card is not visibly altered or mutilated, and otherwise comply with the Fraud Prevention requirements as designated herein;
- Capture Magnetic Stripe data by swiping the Card (unless the Charge was already initiated by waving the contactless Chip Card in close proximity to the POS System as described herein;
- Obtain an Authorization approval,
- Verify the Card’s Expiration Date,
- Match the Card Number and the Expiration Date on the Card to the same information on the Transaction Record, and
- Ensure the name that prints on the Transaction Record matches the name on the front of the Card, except when Cardholder name is not captured on the Transaction Record or for Cards that do not show a name on their face.
- Mobile Devices. Mobile Devices include an Issuer-approved and Optum-recognized electronic device (including but not limited to, a mobile telephone, tablet, or wearable device) that is enabled to initiate a Transaction. When presented with a Mobile Device for a Card Present Charge, you should:
- Capture Magnetic Stripe or Card data by having the Cardholder wave the Mobile Device in close proximity to the reader or magnetic swipe-enabled POS System.
- Obtain an Authorization approval;
- Include an indicator in the Authorization that the Transaction is a mobile Transaction, if applicable.
- If a Mobile Device initiated Transaction cannot be processed for any reason, you should request that the Cardholder provide the companion physical Card and complete the Transaction by following the relevant Card acceptance procedures outlined above.
- Key-Entered Charges. There are instances when you may need to key-enter an In-Person Charge. This occurs most often when the POS System cannot read the If the Card cannot be read electronically, and you wish to key-enter the Transaction, then you must:
- Verify that the Card is not visibly altered or mutilated;
- Key-enter the data;
- Obtain an Authorization approval;
- Verify the Card’s Expiration Date;
- Match the Card Number and the Expiration Date on the Card to the same information on the Transaction Record;
- Validate the Card’s presence by taking an imprint of the Card (the imprint is for your records).
- Failure to validate the Card’s presence by taking an imprint of the Card can render you liable for Charge Reversals if the Cardholder disputes the You may still be subject to other fraud Charge Reversals, including counterfeit, lost, stolen, and non-received for manually key-entered Transactions. If you are presented with a Card and manually key-enter the Transaction, you may be subject to counterfeit, lost/stolen and non-received fraud Charge Reversals. Charges initiated with a contactless-enabled mobile device must not be key-entered. (Refer to “Disputed Charges, Charge Reversals and Inquiries” Section herein.)
- Actions for In-Person Charges. The following describes the course of action required during an In-Person Charge Transaction process:
- If the Card is obviously altered or counterfeit, you must not accept the Card.
- If the Cardholder is attempting to use the Card outside the Expiration Date, do not accept the Advise the Cardholder to contact the customer service number on the back of the Card.
- If it appears that someone other than the Cardholder is attempting to use the Card, do not accept the Indicate that Cards are non-transferrable and that only the person whose name appears on the Card is permitted to use the Card.
- If you are unable to obtain Authorization electronically, contact Optum for assistance.
- If the Card does not display the appropriate Network logo as required by Optum and further detailed in the “Marketing Exhibit” to Agreement, you must not accept the Card.
- If the Authorization is declined, do not accept the Card and follow your Merchant policies for handling various Authorization responses.
- If the Card Number and Expiration Date on the Card do not match the Transaction Record, the name on the Transaction Record does not match the name on the Card, and/or the appearance of the Card or actions of the customer appear suspicious, decline to accept the Card. Failure to act in a commercially reasonable manner in your acceptance or refusal to accept the Card shall result in your potential removal from the Network, and you shall be liable for any Losses related to your failure. (Refer to “Fraud Prevention” Section herein.
- Card Not Present Charges. For Card Not Present charges, such as mail-order, telephone-order, and Internet Orders, you do not get the opportunity to inspect the physical Card, and therefore fraud might be more difficult to detect. For Card Not Present Charges, you must create a Transaction Record, as defined We reserve the right to initiate a Charge Reversal for any Card Not Present Charge that the Cardholder denies making or authorizing. The information you must obtain in order to proceed with a Card Not Present Transaction includes:
- Card Number or token (Required);
- Card or token Expiration Date (Required);
- Card Security Code (CSC) (Required);
- Name as it appears on the Card (Recommended);
- Cardholder’s billing address (Recommended); and
- Ship-to address, if different from the billing address (Recommended).
- Internet Charge Requirements. Optum will not be liable for actual or alleged fraudulent Transactions over the Internet and we will have the right to Charge Reverse for those Charges. Additionally, if a Disputed Charge arises involving a Card Not Present Charge that is an Internet Charge, we may Charge Reverse for the full amount of the Charge, consistent with the Disputed Charge Section herein. For Internet Orders, you must:
- Use any separate Merchant Identification Number(s) held by you for Internet Orders in all your requests for Authorization and Submission of Charges, and
- Provide us written notice of any change in your internet address, in accordance with the Agreement.
- Credentials-on-File. If you store Cardholder Information for Transaction processing, you must ensure the credentials-on-file include any Cardholder account data, including, but not limited to, PAN or token, that is stored by or on behalf of Merchants. You must obtain Cardholder consent before storing Cardholder Information and/or credentials. You must also, at all times, comply with the Technical Specifications and all applicable PCI DSS requirements related to storage of Cardholder Information and Cardholder Data.
- Transaction Record. You must create a Transaction Record for every Charge. For each Charge submitted electronically, you must create an electronically reproducible Transaction Record, that complies with the Technical Specifications. (See also “Receipt Information” in the Technical Specifications.) (Known herein as “Transaction ”) The Transaction Record (and a copy of the customer’s Receipt) must disclose the Authorization approval code and your return and/or cancellation policies. If the Cardholder wants to use different Cards for payment of a purchase, you may create a separate Transaction Record for each Card used. However, if the Cardholder is using a single Card for payment of a purchase, you must not divide the purchase into more than one Charge, nor create more than one Transaction Record. For all Transaction Records, you must:
- Submit the Charge for payment.
- Retain the original or electronically stored Transaction Record (as applicable) and all documents evidencing the Charge, or reproducible records thereof, for six (6) months.
- Provide a copy of the Transaction Record to the Cardholder via the Receipt.
- Pursuant to Applicable Law, truncate the Card Number and do not print the Card’s Expiration Date on the copies of Transaction Records/Receipts delivered to Truncated Card Number digits must be masked with replacement characters such as “x,” “*,” or “#,” and not blank spaces or numbers.
- Processing a Credit. A Credit may occur when a Merchant processes a refund for purchases or payments made on the You must submit Credits to us within seven (7) days of determining that a Credit is due and create a Credit Record that complies with our requirements, as detailed in the Technical Specifications. You must not issue a Credit when there is no corresponding Charge, nor issue a Credit in exchange for cash or other consideration from a Cardholder. You must submit all Credits under the Merchant Identification Number of the Merchant Location where the Charge originated. If available, you must send Authorization information obtained from the original Charge that is being credited. A Credit must be issued in the currency in which the original Charge was submitted to us. You must issue Credits to the Card used to make the original purchase. Follow these steps to issue a Credit:
- Obtain an Authorization approval;
- Create a Credit Record;
- Compare the last four digits on the Transaction Record against the Card presented (when applicable); and
- Provide a copy of the Credit Record to the Cardholder.
- Use of Third Parties. You may retain, at your expense, third parties, such as processors, terminal providers, vendors, or other agents, contracted on your As noted herein, you remain financially and otherwise liable for all obligations (including confidentiality obligations and compliance with the Technical Specifications and these Network Rules), services, and functions such third parties perform under the Agreement for you (e.g., the technical requirements of authorizing and submitting Transactions to us) as if you performed such obligations, services, and functions yourself. You are responsible and liable for all problems and expenses caused by your third parties, including any Settlement payments misdirected to other parties because of the misprogramming of your POS System by your third parties, as contemplated herein.
IV. Authorization
- Generally. The Authorization process begins when you provide an Authorization request to us for a Transaction on the After requesting Authorization, you receive an Authorization response which you use, in part, to determine whether to proceed with the Charge. For every Charge, you are required to obtain an Authorization approval. For every Credit, we recommend that you obtain an Authorization approval for the full amount of the refund in accordance with the terms of the Network Agreements. The Authorization approval must be for the full amount of the Charge. All Authorizations must be submitted in accordance with these Network Rules and the Technical Specification.
- An Authorization is Not a Guarantee. An Authorization approval does not guarantee that: (i) the person making the Charge is the Cardholder, (ii) the Charge is in fact valid or bona fide, (iii) you will be paid for the Charge, (iv) you will not be subject to a Charge Reversal, or (v) the Charge you submit will not be rejected.
- Authorization Time Limit. Authorization approvals for Charges are valid for seven (7) days after the Authorization date. You must obtain a new approval if you submit the Charge to us more than seven (7) days after the original Authorization The new approval must be included in the Transaction Record. If either of the Authorization requests is Declined, do not provide the goods or services or submit the Charge. If you do, you will be subject to a Charge Reversal.
- Authorization Process. Upon presentation of a Card by a Cardholder, the POS System will capture the Card information and transfer it to the Network. The Network will then return the Authorization approval or Decline back to the Data points required by the Network to process a Transaction are detailed in the Technical Specifications.
- Possible Authorization Responses. Refer to the Technical Specifications.
- Failed Authorization Requests. If there is any failure during the Authorization process, whether it be a timeout, or other technical issue that results in the Transaction being cancelled, you must send a void request to Optum for Authorization, in accordance with the Technical Specifications.
- Obtaining an Authorization. You must ensure that all Authorization requests comply with the Technical Specifications and these Network If the Authorization request does not comply with these requirements, the Authorization was Declined, or for which no approval code was obtained, we may reject the Submission or we may exercise a Charge Reversal. If the Card is unreadable and you have to key-enter the Charge to obtain an Authorization then you must follow the requirements for key-entered Charges, as designated herein. If you use an electronic POS System to obtain Authorization, the approval must be printed automatically on the Transaction Record. Occasionally, obtaining an electronic Authorization may not be possible (e.g., due to POS System problems, Network outages, or other disruptions of an electronic Charge). In these instances, please contact us for support.
V. Settlement
- Settlement Generally. The Settlement amount is determined by totaling the Submissions adjusted for any and all applicable debits and Credits.
- Settlement Amount. Your Settlement amount will be the face amount of Charges submitted from your Merchant Locations pursuant to the Agreement, less all applicable deductions, rejections, and withholdings, which may include: (i) Discounts, (ii) amounts you owe us or our Affiliates, (iii) amounts for which we have processed Charge Reversals, (iv) amounts for which you have submitted Credits. We will subtract from our payment to you, the full amount of all applicable deductions, rejections and withholdings, but if we cannot, then you must pay us promptly upon receipt of our notification of any amount due and owing. We will pay you the Settlement amount in U.S. dollars, according to the terms of the Network Agreements, consistent with the terms of the “Settlement and Network Fees” Exhibit to the Agreement.
- Source of Payment. By participating on the Network, Merchant accepts that Cards and Programs facilitated by Optum are funded via different sources – i.e., health plan payers, employers, consumer packaged goods entities, manufacturers, or any other entity willing to fund a Merchant shall receive the full price for the Item, regardless of the source of funding for payment, irrespective of whether Merchant maintains physical locations and/or an online presence.
- Network Fee. The Network Fee is an amount that we charge you for accepting the Card, which amount is a percentage of the face amount of the Charge that you submit, or a flat per Transaction fee, or a combination of both (“Network Fee”). Your initial Network Fee is indicated in the Agreement or otherwise provided to you in writing by In addition to your Network Fee, we may charge you additional fees and assessments. We may adjust any of these amounts and may change any other amount we charge you for accepting the Card. We will notify you of such fees, such adjustments and charges, and assessments, and any different fees that apply to you. (See the “Settlement and Network Fees” Exhibit to the Agreement.)
- Bank Account. Merchant shall establish and maintain a Bank Account to receive credits and debits for Transactions via ACH and as further detailed in the Agreement. You must provide us with the bank’s name and bank routing information, and your Bank Account number, and you must notify your bank that we will have access to your account for crediting the Bank You must immediately notify us of any changes to your Bank Account information. Failure to notify us of such changes may cause us to delay your Settlement. The policies of the financial institution at which you have a Bank Account govern when funds are available from the Bank Account. We will not be responsible for any obligations, damages, or liabilities in excess of the amount of the applicable credit, or adjustment, to your Bank Account in the event that your bank does not honor any such item or improperly applies it to your Bank Account. You are required to maintain a Bank Account at a financial institution domiciled in the United States for the purposes of the Agreement. (See Exhibit to the Agreement, “Merchant Bank Account Information,” as well as the “Settlement and Network Fees” Exhibit to the Agreement, for more information.)
- Method of Payment. We will direct Settlement amounts to you electronically via ACH to the Bank Account you designate, per this Section and as stated in the You agree that the Bank Account is the account into which payments for Charges (and any other Settlement amounts) will be made. (See Exhibit to the Agreement, “Merchant Bank Account Information,” as well as the “Settlement and Network Fees” Exhibit to the Agreement, for more information.)
- ACH Requirements. The bank you designate in the United States must have access to the Federal Reserve System to receive transactions via You must participate in electronic pay and we will direct Settlement amounts to you electronically via ACH to the Bank Account you designate at a bank in the United States that participates in the ACH. You hereby agree that we shall have direct access to the Bank Account and you hereby grant to us or our designee all necessary rights to credit or debit, as appropriate, any and all amounts that may be due in accordance with the Network Agreements to or from the Bank Account. If necessary, you agree to execute any and all documentation, as may be determined by your Bank or us, to grant us or our designee said rights. You hereby agree that such credits and debits shall be in accordance with the Nacha Operating Rules and Guidelines, and you agree to be bound by such terms. The Nacha Operating Rules and Guidelines are available at www.nacha.org, or its successor website. If we are required to pay you by check, we may assess a fee. (See “Settlement and Network Fees” Exhibit to the Agreement.)
- Speed of Payment. Subject to Applicable Law, we shall direct payment to the Bank Account that you designate. Unless otherwise agreed in writing, we will use commercially reasonable efforts to initiate ACH payment to your Bank Account after our receipt of the Charge prior to our cutoff time for receiving and processing Charges, as detailed in the If your payment date falls on a day when banks are not open for processing ACH payments, we will initiate payment on the next day banks are open for such processing. (Note that the ACH network does not operate on Saturdays, Sundays, or Federal Reserve Holidays.) Generally, we will electronically remit funds for authorized Transactions to your Bank Account within two (2) business days after the Transactions are submitted to us in accordance with these Network Rules.
- Reconciliation. We may provide to you a Settlement file or other reconciliation report, as may be agreed between the Parties, that contains an itemized list of Transactions, including amounts, deductions, and totals by Settlement day. The Settlement file can be used to reconcile the activity included in the ACH file at a Transaction level. (See “Settlement and Network Fees” Exhibit to the Agreement.)
- Payment Errors or Omissions. You must notify us in writing of any error or omission you believed to have occurred related to your Network Fee or other fees or payments for Charges, Credits or Charge Reversals within ninety (90) days of the transmission of the payment file containing such claimed error or If you do not provide such notice within the required timeframe, we will consider the matter to be conclusively settled as complete and correct in respect of such amounts, except for any erroneous payments by us. If we determine at any time that we have paid you in error, we will initiate a Charge Reversal or Adjustment, where applicable, to recover such erroneous payment. If you receive any payment from us not owed to you under the Agreement, you must immediately notify us and return such payment to us promptly. We have the right to withhold future payments to you until we fully recover the amount. We have no obligation to pay any party other than you under the Network Agreements.
- Adjustments. Optum may initiate an adjustment, if the rewards, benefits, and/or discounted pricing was erroneously (a) charged to a Client and/or credited to Merchant, or (b) not charged to a Client and/or not credited to Merchant (“Adjustments”). Appropriate documentation will be provided to Merchant, as applicable, in a timely manner, in support of all Adjustments, in a manner which may be agreed upon by the Parties. In the event Merchant disputes an Adjustment, failure to reach a solution within five (5) business days of Merchant being noticed of an Adjustment will result in the Merchant owing a credit to Client for the full amount of any Adjustment. The aforementioned timelines may be changed by Optum based on fraudulent activity.
VI. Add-On Services
- Payment Processing Services. Where applicable, payment processing services may include services in addition to the Network Transaction processing functions offered to Merchants who participate on the Network. Such services may include, for example, tokenization or add-on payment processing functions, above and beyond the Settlement and Credit functions offered to Merchants who participate on the Network. This service may be offered as an optional API or web page, as may be agreed between you and us.
- Tokenization Services. Tokenization Services includes optional services in which the Merchant may exchange Card data for a reusable payment token to process Transactions.
- Bill Pay Services. Where applicable, certain bill pay services may be provided by the Network, via third-party relationships, and made available to Cardholders at certain Merchant (Refer to the “Bill Pay Services” Exhibit to the Agreement for more information.)
- Further Agreement Required. All such additional services shall require and be subject to further agreement between the Parties, such as via a mutually agreed statement of Any and all further agreements reached pursuant to this Section shall additionally be subject to the terms of the Network Agreements.
VII. Protecting Cardholder Information
- Data Security Policy. Optum requires, as part of your responsibilities, that you comply with the data security provisions in the Network Agreements and Optum’s Security Addendum, attached as Exhibit “A” hereto, which may be updated and provided to you with thirty (30) days to comply with any changes, as well as all data security requirements otherwise denoted in the Network Agreements. These requirements apply to all your equipment, systems, and networks (and their components) on which Encryption Keys, Cardholder Data, or Sensitive Authentication Data (or a combination of each) are stored, processed, or transmitted.
- Optum Audit Rights. Optum has the right to periodically request documents verifying that the Merchant’s security policies are in place or request for a live audit to verify Merchant’s security controls. The Merchant is required to provide assistance whenever Optum makes such requests. The Merchant must assist Optum in any follow-up inquiries or audits related to these policies. (See “Audit” Section in the Agreement for further details.)
- Standards for Protection of Encryption Keys, Cardholder Data, and Sensitive Authentication Data. You must, and you must cause your third parties, to:
- Store Cardholder Data only to facilitate Network Transactions in accordance with, and as required by, the Network Agreements.
- Comply with the current PCI DSS and other PCI SSC requirements applicable to your processing, storing, or transmitting of Cardholder Data or Sensitive Authentication Data no later than the effective date for implementing that version of the applicable requirement.
- Use, when deploying new or replacement Personal Identification Number (“PIN”) entry devices, POS Systems, or payment applications (or all three of these), only those that are PCI SCC-Approved.
- You must protect all Optum Transaction Records, and Credit records retained pursuant to the Agreement in accordance with these data security provisions which may be updated from time to You must use these records only for purposes of the Network Agreements and safeguard them accordingly.
- You are financially and otherwise liable to us for ensuring your third parties’ compliance with this Section.
- Data Incident Management Obligations. You must notify us immediately and in no case later than twenty-four (24) hours after discovery of a Data To notify us, contact the Optum Incident Response Program (EIRP) at 888-848-3375, or, or email at [email protected]. You must also notify your Network representative at [email protected]. You must designate an individual as your contact regarding such Data Incident. In addition, you must:
- Conduct a thorough forensic investigation of each Data incident.
- For Data Incidents involving 10,000 or more unique Card Numbers, you must engage a PCI Forensic Investigator (PFI) to conduct this investigation within five (5) days following discovery of a Data Incident. The unedited forensic investigation report must be provided to us within ten (10) business days of its completion. Forensic investigation reports must be completed using the current Forensic Incident Final Report Template available from PCI. Such report must include forensic reviews, reports on compliance, and all other information related to the Data Incident; identify the cause of the Data Incident; confirm whether or not you were in compliance with the PCI DSS at the time of the Data Incident; and verify your ability to prevent future Data Incidents by (i) providing a plan for remediating all PCI DSS deficiencies, and (ii) participating in a compliance program, as defined by Optum.
- Promptly provide to us a list of all compromised Card (We reserve the right to conduct our own internal analysis to identify Card Numbers involved in the Data Incident.)
- Upon our request, provide validation by a Qualified Security Assessor (QSA) that the deficiencies have been remediated.
- Fewer than 10,000 Unique Card Numbers. Notwithstanding the foregoing we may, in our sole discretion, require you to engage a PFI to conduct an investigation of a Data Incident for Data Incidents involving fewer than 10,000 unique Card Numbers. Any such investigation must comply with the requirements set forth above in this Section and must be completed within the timeframe required by us. Further, we may, in our sole discretion, separately engage a PFI to conduct an investigation for any Data Incident and may charge the cost of such investigation to you.
- Merchant Cooperation. You agree to work with us to resolve any issues which may occur as a result of the Data Incident, including working with us for communications to Cardholders affected by the Data Incident and providing (and obtaining any waivers necessary to provide) to us all relevant information to verify your ability to prevent future Data Incidents. As may be required by Applicable Law, we shall have the right to disclose information about any Data Incident to Cardholders, Issuers, other Network Participants, and the general public.
- Indemnity Obligations and Limitation of Liability for a Data Incident. You shall indemnify Optum and its Affiliates for any and all Data Incidents consistent with the terms of the Agreement, and the applicable Limitation of Liability provisions shall apply from same. Optum further reserves the right to assess a non-compliance fee for your failure to comply with the Data Security obligations denoted herein. Your indemnity obligations for Data Incidents shall be considered direct damages under the Network Agreements, and shall not be considered incidental, indirect, speculative, consequential, special, punitive, or exemplary damages; provided that such obligations do not include damages related to or in the nature of lost profits or revenues, loss of goodwill, or loss of business opportunities.
- Security Addendum. Nothing in this Section shall be deemed to supplant or take the place of any requirements with respect to a “Security Incident,” as defined in the “Security Addendum,” attached hereto as Exhibit A. In the event of a conflict between this Section and the Security Addendum, the terms of the Security Addendum shall control.
VIII. Fraud Prevention
- Strategies for Deterring Fraud. You should implement multiple layers of fraud protection to help secure your business. These layers may include a combination of your POS System procedures and controls as well as implementation of fraud mitigation Your first layer for mitigating fraud is to follow our Card acceptance policies and procedures, as outlined in these Network Rules. Other fraud mitigation strategies that you choose to implement may include any combination of: (i) recognition of suspicious behaviors or circumstances that may signal fraudulent activity (ii) implementation of fraud mitigation tools that take advantage of risk controls to identify fraudulent activity, (iii) additional risk models or controls that you can develop internally or obtain externally from third parties.
- Card Acceptance. A critical component in your overall fraud mitigation strategy is to follow our Card Acceptance procedures, as detailed in the Network Merchant’s failure to comply with these Network Rules and our Card Acceptance procedures, particularly those failures which result in fraud, shall be the sole liability of Merchant, including but not limited to all costs or Losses associated therewith. As a prudent Merchant, you must always be aware of circumstances that may indicate a fraudulent scheme or suspicious behaviors that may flag a fraudulent customer.
- Card Security. The Merchant is expected to fully utilize the security features of the Card being used in the Transaction, up to the highest form factor, such that all possible validation checks can be performed by the Issuer and/or Network on items such as Transaction categorization, track data, CSC, and/or Expiration Date in accordance with the Optum Transaction Specifications.
- Fraud Mitigation Support. The Merchant should be prepared to assist Optum in mitigating identified fraud by providing the appropriate resources commensurate with the level of fraud occurring, as directed by Optum.
- Best Practices. The following are examples of some best practices which a Merchant may employ to aid in the prevention of While Optum considers these best practices based on its knowledge of the industry, it is the responsibility of Merchant to consult with its own fraud experts to determine how to mitigate fraud risks to its business and the Network. Nothing herein shall relieve Merchant of its responsibilities contained in these Network Agreements with respect to fraud mitigation. Merchant acknowledges that it has not acted in reliance upon the following examples in developing its own fraud mitigation strategies. Subject to the foregoing, some best practices may include:
- For in-store purchases:
- When swiping or scanning a Card, the cashier should first inspect the Card for any signs of tampering or Any Card that appears suspicious must not be allowed to use for a purchase.
- If a customer uses multiple Cards (three or more) for a single or multiple Transactions, this is a red flag for fraudulent behavior. The cashier should proceed with caution.
- For unattended point-of-sale stations, beware of customers that are processing many Transactions using multiple If the customer is using a printed barcode instead of a physical Card, this may be an indicator of fraudulent behavior.
- Ensure that your employees are properly trained in the above best practices so they can be prepared to identify potential fraudulent activity. Also, please note that Fraud can come from a Merchant’s own employees. The Merchant is ultimately responsible for the fraud committed by its employees.
- For online purchases:
- To prevent cyber hacking, ensure that your website/app meets commercially acceptable security standards for an E-commerce site.
- Employ fraud detection tools to further enhance your website security and discourage fraudulent activity.
- For in-store purchases:
- Investigations Assistance. Merchants should cooperate with the Network and/or law enforcement in investigation of fraudulent activity related to Card use, where possible and in compliance with Applicable Law. Investigation assistance may include the following: (i) Interviewing suspects, witnesses, employees; (ii) Obtaining physical evidence; (iii) Recovering lost Cards; (iv) Performing any other reasonable investigative assistance as directed by law enforcement.
IX. Risk Evaluation
- Prohibited and Restricted Merchants. Some Merchants are not eligible (or may become ineligible) to accept the Card. We may suspend acceptance of Cards by you or terminate the Agreement (including immediate termination without prior notice to you) if we determine or have reason to believe, in our sole discretion, that you meet any of the following criteria:
- Participation as a Merchant on our Network or acceptance of Cards (or both) by you may cause us not to be in compliance with Applicable Laws, regulations, or rules.
- You do not have a verifiable physical address within the United States, Puerto Rico, S. Virgin Islands, or other U.S. territories and possessions, and can only be reached by telephone.
- You are involved (or knowingly participate or have participated) in a fraudulent or illegal activity.
- You are identified as a sponsor of international terrorism, as warranting special measures due to money laundering concerns, or as noncooperative with international anti-money laundering principles or procedures.
- Your business activity includes or is predominantly focused on activities that Optum deems in its sole discretion to be high risk (Classification in a High-Risk program, as such term relates to Disproportionate Disputed Charge activity or other Transaction activity, shall not be construed to authorize a business activity or Merchant that is considered high risk under this Section.)
- You do not clearly and readily disclose principal owners and managers to facilitate Optum’s compliance with customer identification and anti-money laundering principles or procedures.
- Additionally, we may suspend acceptance of Cards by you or terminate the Agreement if: (1) You are listed on the S. Department of Treasury, Office of Foreign Assets Control, Specially Designated Nationals and Blocked Persons List (available at www.treas.gov/ofac); (2) You are listed on the U.S. Department of State’s Terrorist Exclusion List (available at www.state.gov); (3) You are located in or operating under license issued by a jurisdiction identified by the U.S. Department of State as a sponsor of international terrorism, by the U.S. Secretary of the Treasury as warranting special measures due to money laundering concerns, or as noncooperative with international anti-money laundering principles or procedures by an intergovernmental group or organization of which the United States is a member; (4) Your verifiable physical address is not located in the United States, Puerto Rico, U.S. Virgin Islands, or other U.S. territories and possessions.
- Monitoring. After you become a Merchant on the Network, we monitor to identify potential risks, assess your financial status and compliance with the Network Agreements. We use internal and third-party information to monitor you for actions or behaviors which may put us, Issuers, Clients, or Cardholders at risk. Based on the results of our monitoring, we reserve the right to take action to mitigate our risk, up to and including removing a Merchant from the Network.
- Fraudulent, Deceptive, or Unfair Business Practices, Illegal Activities, or Prohibited Uses of the Card. If we determine, or have reason to believe, that you engage or have engaged (or knowingly participate or knowingly have participated) in any conduct Optum deems fraudulent, deceptive, unfair business practices, illegal activities, or prohibited uses of Cards, including but not limited to, in any scheme that defrauds us, Issuers, Clients, and/or Cardholders; or in a business practice that we deem fraudulent, deceptive and/or unfair, we may take corrective action, which may include but is not limited to: (1) exercising Charge Reversals, rejecting Charges, or withholding Settlements, or (2) termination of the Agreement and your participation on the Network (including immediate termination without prior notice to you).
- High-Risk Program. If, after initial onboarding, you have not kept your integration current, following the latest versions of the Network Rules and Technical Specifications, or if you meet our criteria for Disproportionate Disputed Charges, as defined herein, you may be placed in a High-Risk Notwithstanding anything to the contrary in the Network Agreements, while you are in a High-Risk program, all Disputed Charges will immediately result in a Charge Reversal with no opportunity to respond. While in a High-Risk program, you may be assessed Network Fees as per the High-Risk Fee Tier. Refer to the “Merchant Fees” Section herein, and the “Settlement and Network Fees” Exhibit to the Agreement. See also “Participating on the Network” in these Network Rules.
X. Disputed Charges, Charge Reversals and Inquiries
- Disputed Charges Generally. Charges may be disputed for a variety of In general, most Disputed Charges stem from: (1) Cardholder dissatisfaction with some aspect of the purchase, (e.g., a failure to receive the merchandise, duplicate billing of a Charge, incorrect billing amount), (2) unrecognized Charge where the Cardholder requests additional information, (3) Cardholder billed for goods or services not yet received, or (4) actual or alleged fraudulent Transactions. If a Cardholder disputes a Charge, we open a case. If a case is opened, we may initiate a Charge Reversal to you immediately or send you a request for information about a Disputed Charge. (See also, “Inquiry.”) You must not suggest or require Cardholders to waive their right to dispute any Transaction, as a condition to accepting the Card.
- Disputed Charges Rights. With respect to a Disputed Charge, we may send you an Inquiry prior to exercising a Charge Reversal. If we determine we have sufficient information to resolve the Disputed Charge in favor of the Cardholder, we will exercise our Charge Reversal rights. All judgments regarding resolution of Disputed Charges are at our sole discretion. We may reinvestigate a previously Disputed Charge if a Cardholder provides new or additional information after we review the initial supporting documentation. In such case, you may be required to provide additional information to support the validity of the Charge. You must not resubmit a Disputed Charge after it has been resolved in favor of the Cardholder. We will Charge Reverse all such Disputed Charges that are resubmitted. If you have established a process whereby your third party will receive and manage Disputed Charges on your behalf, you agree that we are not liable for your third party’s failure to perform its responsibilities to you, including responding to us within the dispute resolution timelines set out in the Network Agreements.
- Charge Reversal Rights. We have rights to perform Charge Reversals:
- Whenever Cardholders bring Disputed Charges, as described in this Section, or have rights under Applicable Law or contract to withhold payments;
- In cases of actual or alleged fraud relating to Charges;
- If you do not comply with the Agreement (including sending incomplete or incorrect Transaction Data in Submissions), even if we had notice when we paid you for a Charge that you did not so comply and even if you obtained Authorization for the Charge in question; or
- As provided elsewhere in the Agreement.
- Disputed Charges Process. The following are the steps in the Disputed Charges Process:
- Case is Opened. We may take one of the following actions, based upon the information provided by you, the Cardholder, Issuer, or Network: (1) We may send you a Charge Reversal or, if we cannot resolve the Disputed Charge without further information from you, an (2) We may resolve the Disputed Charge in your favor and either take no further action (if we have not previously exercised a Charge Reversal) or reverse our previous Charge Reversal.
- Merchant Receives a Charge Reversal or Inquiry. Based on information available to us we will send you either a Charge Reversal or an The Charge Reversal or Inquiry that we will send to you includes information about the Charge in question, required documentation that you must send us to support the Charge, and a deadline by which your response must be received.
- Merchant Responds. You may respond to the Charge Reversal or Inquiry by: (1) providing the required documentation to support the validity of the Charge (See “Compelling Evidence” herein.), (2) authorizing a Charge Reversal to your Settlement Amount or Bank Account, (3) issuing a Credit to the Card Number, or (4) issuing a partial Credit to the Card Number and providing us with supporting documentation for the remainder of the Charge and the reason for providing only a partial If you choose to contest a Charge Reversal, we may charge you a fee for facilitating the resolution process. (Note: If you choose not to respond to our Inquiry, we will initiate a debit to your Bank Account or Settlement Amount with a “No Reply” Charge Reversal.)
- Optum Reviews. We will review your response to ensure it includes all the required and requested pieces of information about the Disputed Charge. Upon receipt of the required information, we will determine whether to process, reverse, or uphold the Charge Reversal.
- Disputed Charge is Resolved. When a Disputed Charge is resolved, one of the following may occur: (1) We will notify the Cardholder of the resolution, with consideration to any supporting documentation you (2) We will notify you of a Charge Reversal and initiate a debit to your Bank Account or Settlement Amount.
- Charge Reversals and Inquiries Response Timeframe. You must respond in writing to a Charge Reversal and/or Inquiry within five (5) calendar days.
- Charge Reversal Information. When we process a Charge Reversal to you, we will provide information about the Charge Reversal. For each Charge Reversal, we will include with our response: (1) Description – brief description of the Charge Reversal reason, (2) Information provided with the Charge Reversal, such as information provided by the Cardholder to support the Charge Reversal (documentation may not be provided with the Charge Reversal if it was preceded by an Inquiry), (3) Support required to request a Charge Reversal, e.g. examples of required documentation if you request a Charge Reversal.
- Compelling Evidence. The following shall be considered compelling evidence for decisioning a Charge Reversal:
- Compelling Evidence for goods/services not received or only partially received. Allowable Compelling Evidence for goods/services not received or only partially received. Charge Reversal request must include one (1) of the following items:
- For Transactions involving goods or services, evidence to prove that there is a link between the person who received the goods or services and the Cardholder (e.g., photographs, emails); or
- For Card Not Present Transactions where the goods are picked up at Merchant Locations: (1) The Merchant must provide the Cardholder or authorized third party signature on the pickup form as well as additional proof to demonstrate that the identity of the Cardholder or authorized third party was verified at the time of pickup; or
- For E-commerce Transactions representing the sale of Digital Goods or Services downloaded from a Merchant’s website or application or accessed online, one (1) of the following must be provided: (1) Proof that the Cardholder’s IP address at the time of purchase matches the IP address where the digital goods were downloaded, or (2) Proof the Cardholder’s email address provided at the time of purchase matches the email address used to deliver the digital goods, or (3) Proof that the Merchant’s website was accessed by the Cardholder for goods or services after the Transaction Date.
- Compelling Evidence for Card Not Present Fraud. Allowable Compelling Evidence for Card Not Present Charge Reversal request must include one (1) of the following items:
- For Transactions involving the shipment of goods or services, proof that the Transaction contains a shipping address that matches a previously used shipping address from an undisputed Transaction, or
- For E-commerce Transactions involving the sale of goods or services, provide all of the following: (1) Cardholder name linked to the account with the Merchant and (2) Description of the goods or services and the date/time they were purchased and downloaded, accessed, or provided to the Cardholder, (3) Proof that the device and Card used for the disputed Transaction was used in a previous Transaction that was not disputed; or
- For Recurring Billing Transactions initiated on the Merchant’s website all of the following must be provided: (1) Proof of a legally binding contract held between the Merchant and the Cardholder and (2) Proof the Cardholder accessed the Merchant’s website or application to establish services on or before the Transaction date, and (3) Proof the Cardholder received the goods or services, and (4) Proof of a previous Transaction that was not disputed.
- Compelling Evidence for goods/services not received or only partially received. Allowable Compelling Evidence for goods/services not received or only partially received. Charge Reversal request must include one (1) of the following items:
- Charge Reversal and Inquiry Monitoring. We monitor the number of Disputed Charges for all Merchants and Merchant Locations on the Network. Your Disputed Charges may be considered disproportionate if any of the following conditions are present: (1) You are unable to provide supporting documentation for Charges consistently, (2) The number of “No Reply” and “Insufficient Information” Charge Reversals from you is deemed to be excessive relative to your prior history or industry (Collectively, “Disproportionate Disputed Charges.”) If any of the preceding conditions occur, notwithstanding anything to the contrary in the Agreement, we may require you to create a reserve or apply other restrictions to your participation on the Network, in our sole discretion. (See “Protective Actions” Sections of the Agreement.) The list of conditions above is not exhaustive and does not reflect all circumstances under which we will act to protect our interests.
- Excessive Disputed Charges. Your Disputed Charges may be considered excessive in either of these conditions:
- We receive a disproportionately high number of Disputed Charges relative to your prior history or industry standards.
- The ratio of Disputed Charges to total Transactions exceeds one percent (1%) for the calendar month.
- How We Process Charge Reversals. We may process a Charge Reversal by (i) deducting, withholding, recouping from, or otherwise offsetting against our payments to you or by initiating a debit of your Bank Account, or we may notify you of your obligation to pay us, which you must do promptly and fully; or (ii) reversing a Charge for which we have not paid you. Our failure to demand payment does not waive our Charge Reversal rights. In the event of a Charge Reversal, we will not refund the Network Fee or any other fees or assessments, or we will otherwise recoup such amounts from you.
XI. Marketing Requirements
- General. Merchant shall comply with all provisions of the Network Agreements with respect to marketing, including but not limited to those requirements contained in the “Marketing Exhibit” to the Agreement, referred to collectively in the Network Agreements as the “Marketing Requirements.”
- Marketing Program Development. Merchant shall work with Optum on Marketing Programs designed to stimulate Network usage, as well as Card acquisition, usage, activation, and retention. Merchant and Optum shall mutually develop a Marketing Plan at the beginning of the Term and memorialize the terms of the proposed Marketing Plan. (Refer to the “Marketing Exhibit” to the Agreement.) Following the execution of any Marketing Program, Merchant agrees to provide information, as may be reasonably requested by Optum, to be reviewed during regularly scheduled business reviews, to determine the success of Marketing Program. Marketing Programs shall include, but not be limited to, how logos will appear together, color/font guidelines, which brand appears first in written communications, and approval of all creative communications that include the Optum Brand. Use of any Party’s Mark shall be governed by the terms of the Network Agreement and limited to use of those approved Marks authorized for use by each Party, respectively. (Refer to “Form License Agreement/Approved Marks” Exhibit to the Agreement.)
- Campaigns/Promotions. We may, from time-to-time, develop specific campaigns or “promotions” as part of a Marketing Program, to which you may be invited to participate. We retain the right to determine if you are eligible for any such campaign or “promotion.” If we determine that you are eligible for such a campaign, you have the right to decide whether you will elect to If you do elect to participate, you must comply with all requirements of the campaign or “promotion,” as proscribed by us.
- Approval of Marketing Materials. All copy shall conform to the space, style, and format requirements established by You will have the opportunity to review and accept all Marketing Materials within no later than five (5) business days following receipt of such materials, which approval shall not be unreasonably withheld. You must not create or distribute any Marketing Materials unless we have expressly approved in writing both the channel and content for any such Marketing Materials. For the avoidance of doubt, Optum shall have final approval over all Marketing Materials related to the Network, Optum or its Affiliates Marks, and reserves the right not to approve any Marketing Materials or other collateral for any reason. You accept full responsibility for the accuracy of the Marketing Materials reviewed by you in accordance with this Section.
- Signage. Within thirty (30) days of joining the Network, Merchant shall display Network signage (including Optum, and/or Network, name, branding, and/or logo) at Merchant Location points-of-sale, entrances, shelf tags, end cap promotions, , as well as other forms of signage, and/or information, to be leveraged at both physical and E-commerce websites, including but not limited to check-outs, in accordance with the standard package that Optum will provide to the Merchant. (Refer to the “Marketing Exhibit” to the Agreement for additional information.)
- In-Store/Digital Marketing Materials and Schedule. Optum shall retain final and exclusive approval rights over all Marketing Materials, including all digital content on a website or application operated by you, using the Optum or Network branding or Merchant shall use only approved in-store and digital Marketing Materials, abiding by the Optum-provided schedule/calendar included in the “Marketing Exhibit” to the Agreement. Marketing Materials and other assets must be live and removed according to said schedule.
- Planning Meetings and Case Studies. Merchant shall attend a joint marketing planning meeting with Optum, at a minimum, quarterly, to be scheduled jointly by the Merchant shall allow Optum to conduct a case study with a named executive of Merchant, to be jointly determined by the Parties, within six (6) months of the Effective Date of the Agreement, and at any point during the term of the Agreement, or at such other time as may be mutually agreed by the Parties.
- License. You hereby grant us a non-exclusive, non-transferable, royalty-free license to use those of your Marks, as set forth in the Marketing Program or as otherwise necessary to promote the Network, Optum, or its Affiliates, and any copy you submit hereunder, in any communications media (e.g., television, radio, print or online promotions), in connection with and solely to identify and promote the Network. We shall not alter or modify your Marks in any way. (See “Form License Agreement/Approved Marks” Exhibit to the Agreement.)
- Marketing Audit. You shall, on not less than five (5) business days’ prior written notice from us, permit our representatives to audit your facilities, business practices, and records, in connection with the Marketing Program, as necessary to verify your compliance with the terms of this Section. You further agree and consent to any market testing, “secret shopper” testing, or other methods we may employe to confirm your compliance with the terms of this Section.
- No Reverse Engineering. You shall not, directly or indirectly, for your benefit or the benefit of any other party, discover, reverse engineer, decompile, decode or otherwise use any segmentation criteria, Cardholder Information, any information obtained through hyperlinks, or any reports to (i) establish the personal identity of any Cardholder or (ii) identify any individual or group as Cardholders for any purpose, including, without limitation, to create a group or segment composed exclusively of Cardholders. In no event shall you use segmentation criteria, Cardholder Information, or any information obtained through hyperlinks, to target, direct any marketing or solicitation, or conduct analyses solely of Cardholders on the basis of such persons being Cardholders. You shall not, directly or indirectly, distribute, share, market, or sell Cardholder Information, segmentation criteria, any reports, or any information obtained through hyperlinks to any third parties (which term, for the purposes of this Section, includes your Affiliates).
- Confidentiality. The Parties agree to treat any information received from the other in connection with any Marketing Program as Confidential Information, as defined in and subject to the requirements of the Agreement.
- Intellectual Property Rights. Nothing in this Section shall be so construed as to restrict, impair, or deprive Optum, its Affiliates, or Merchant of any of its respective intellectual property rights that existed prior to, or arise in connection with, the development of a Marketing Program or related Marketing Materials, as contemplated by this Section.
- Termination. Optum reserves the right to terminate a Marketing Plan or related initiative, at any time, including but not limited to, due to limitations related to Applicable Law.
- Permitted Use of Information. For the purpose of communicating your acceptance of the Card, Optum or its Affiliates may use your name, address (including website addresses or URLs), customer service telephone numbers, logo, on-premises photography, up to date Merchant Locations and physical addresses and/or industry classification in any media at any time. (See “Form License Agreement/Approved Marks“ Exhibit to the ) The information is based on what you have provided to us or that is otherwise publicly available. In addition, the information you provide to us may be transferred to our Affiliates throughout the world, for our business purposes and in our sole discretion. Regardless of where we process your information, Optum still protects it in the manner described in its online privacy statement and according to all Applicable Laws. For more information on Optum’s Online Privacy Statement, please visit https://www.optum.com/en/privacy-policy.html.
XII. Merchant Fees
- Generally. Merchant agrees to pay all fees to Optum, as agreed between the Parties, and as reflected in the “Settlement and Network Fees” Exhibit to Agreement, in addition to all other fees as may be agreed between the Parties during the Term.
- Fee Types. Some fees which may be charged by Optum, as further detailed in the Agreement:
- Early Termination Fees. Optum reserves the right to charge Merchant a fee as a result of Early Termination (“Early Termination Fee”). See “Early Termination Penalties” Section in the Agreement for additional information.
- Network Fees. An amount that we charge you for accepting the Card, which amount is a percentage of the face amount of the Charge that you submit, or a flat per Transaction fee, or a combination of both.
- Authorization Fees. The fixed (per-Transaction) component of your Network Fee is considered the Authorization Fee.
- Disputed Charge Fees. The amount we charge you for facilitating a dispute resolution process for a given Disputed Charge.
- Fee Tiers. You may be subject to different Network Fees based on the channel (e.g. Card Present, Internet, key-entered) you use to submit Transactions to us.
- High-Risk Fee Tier. If you are in a High-Risk program, you will be assessed Network Fees as per the High-Risk Fee Tier.
Table of Exhibits
Exhibit A: Security Addendum
- DEFINITIONS AND GENERAL REQUIREMENTS
- Definitions
- “Customer Information” means personally identifiable information provided by or on behalf of Customer or processed by Vendor on behalf of Customer, including: (i) protected health information (as defined by HIPAA); (ii) non-public personal information (as defined by GLBA); (iii) personal data (as defined by GDPR); or (iv) cardholder data (as defined by the Payment Card Industry Data Security Standard).
- “Customer Information Systems” means Customer’s (including its Affiliates’ and other vendors’) IT and network systems, including cloud systems and devices.
- “Mitigate” means Vendor has deployed security controls to:
- reduce the harmful effects, or potential thereof, and related risks of a Security Vulnerability in accordance with industry standards, and
- contain the adverse effects of a Security Incident to a level reasonably acceptable by Customer.
- “Resolve” means Vendor has corrected the root cause of the Security Vulnerability weakness to prevent its reoccurrence and, in the case of a Security Incident, ensured that the incident is not continuing.
- “Security Incident” means any unauthorized access, use, disclosure, modification, or destruction of Customer Information, or interference with the operations of the Vendor Information Systems or Customer Information Systems via access given to Vendor.
- “Security Vulnerability” means a weakness in the Vendor Information Systems or Vendor’s security procedures, internal controls, or implementation that could be exploited as part of a Security Incident.
- “Vendor Information Systems” means Vendor’s (and its subcontractors’) IT, network, and cloud systems that are used for Vendor Processing, or can be used directly or indirectly to access systems used for Vendor Processing or Customer Information Systems.
- “Vendor Processing” means any information creation, collection, storage or processing performed by Vendor or its subcontractors of Customer Information.
- Security Program. Vendor shall maintain a comprehensive security program (“Vendor Security Program”), with controls that are operating effectively and which are designed to protect the confidentiality, integrity, availability, and security of the Customer Information and Vendor Information Systems, and prevent unauthorized use of Vendor’s ability to access the Customer information Systems. The Vendor Security Program shall: (a) at least meet the security requirements of the certification Vendor obtains in accordance with section 2, this agreement, and applicable laws, (b) include a formal risk management framework with at least annual risk assessments to ensure continued compliance with this Exhibit, and (c) include written policies and procedures documenting the physical, administrative and technical safeguards, which assign responsibility and accountability for each element to specific individuals.
- Subcontractors. If any Vendor subcontractor has access to Customer Information or Customer Information Systems, then Vendor shall have a written agreement with the subcontractor that requires the subcontractor to comply with obligations substantially equivalent to Vendor’s obligations under this Exhibit (including in relation to any further sub-contracting).
- Definitions
- ASSESSMENT & CERTIFICATION
- Security Risk Assessment. No more than once per calendar year (except in the event of a Security Incident, a novel security risk, a demand by a regulator with jurisdiction over the information being processed by Vendor, or a material change in either the scope of services being provided to Customer or in the Vendor Information Systems), Vendor shall cooperate with information security assessments regarding the Vendor Information Systems as requested by Customer’s Enterprise Security and Resilience Office (“ESRO”). At ESRO’s request, Vendor shall provide reasonable information regarding the Vendor Information Systems and the Vendor Security Program and their conformance with the requirements of this Exhibit, reasonable supporting documentation, demonstrations of all security tools and systems, and access to parts of facilities where Vendor Processing occurs, each as reasonably necessary to demonstrate to ESRO the Vendor’s conformance with the requirements of this Exhibit. To the extent the Vendor Information System utilizes a well-established third party public cloud provider (namely either Microsoft Azure, Google Cloud Platform, or Amazon Web Services) (a “PCP”), the parties shall use reasonable efforts to utilize reviews of the PCP’s relevant documents and supporting information, as well as Vendor’s own configuration settings in the PCP’s system, to perform the assessment. If a security assessment identifies any non-compliance with this Exhibit, then Vendor shall resolve the deficiency within a reasonable timeframe mutually agreed by the parties and provide written evidence of the resolution.
- Independent Security Certification. Vendor shall maintain either (a) two-year HITRUST r2 or (b) such other independent security certification or attestation acceptable to Customer during the term (and thereafter for as long as it holds or has access to Customer Information or Customer Information Systems) with a scope covering the Vendor Information Systems and the Vendor Security Program. Vendor shall provide the certificate and supporting documentation as requested by Customer, and shall provide Customer reasonable advance written notice of any lapse or potential lapse in certification coverage.
- Security Testing. Vendor shall perform security tests of the Vendor Information Systems, including perimeter vulnerability scans and penetration testing, internal infrastructure vulnerability testing, and application security testing, as appropriate and in any event at least annually. Upon Customer’s reasonable request, Vendor shall provide an executive summary of penetration and perimeter test results and the Resolution progress of material Security Vulnerabilities identified in such testing upon Customer’s request.
- SECURITY INCIDENTS AND VULNERABILITY MANAGEMENT
- Security Incidents. Vendor shall (a) implement systems and processes to detect and log access (including unsuccessful Security Incidents) to Vendor Information Systems, Customer Information Systems via Vendor access points, and Customer Information, (b) maintain formal processes to detect, identify, report, respond to, Mitigate, and Resolve Security Incidents in a timely manner, (c) provide Customer on request with logs (where required by Customer’s regulators) and supporting information relating to Security Incidents, (d) track unsuccessful attempted Security Incidents, and (e) notify Customer of Security Incidents (using the communication methods specified in the standards linked in section 5) and Mitigate and Resolve the incidents within the following timeframes:
Requirement | Timeframe |
Written or telephonic notice to Customer | As soon as possible, and in any event within 24 hours of discovering the Security Incident |
Mitigate the Security Incident | 24 hours of discovering the Security Incident or as otherwise mutually agreed by the parties (such agreement to not be unreasonably withheld or delayed) |
Provide Customer with a written resolution plan | 48 hours of Customer request, and thereafter as the resolution plan is materially changed, until the Security Incident has been fully Resolved |
Resolve the Security Incident | 5 business days of discovering the Security Incident or as otherwise agreed (such agreement to not be unreasonably withheld or delayed) |
- Vulnerability Management. Vendor shall (a) maintain formal processes to detect, identify, report, respond to, Mitigate, and Resolve Security Vulnerabilities in a timely manner; (b) upon becoming aware of a Security Vulnerability, assign a risk level aligned to the Common Vulnerability Scoring System (CVSS) (see https://www.first.org/cvss/); and (c) Mitigate Security Vulnerabilities within the timeframes set forth in the table below or as otherwise mutually agreed by the parties; and (d) Resolve such Security Vulnerabilities as soon as reasonably possible and in accordance with industry best practices.
Risk Level (and CVSS score) | Mitigation |
Critical (9.0 – 10.0) | 24 hours |
High (7.0 – 8.9) | 7 days |
Medium (4.0 – 6.9) | 30 days |
- SPECIFIC CONTROLS
- Access. Vendor shall maintain appropriate access controls to Vendor Information Systems and Customer Information, including limiting user access and privileges to the minimum necessary to perform assigned Vendor shall only give access to Customer Information Systems to users who have been pre-approved by Customer (which will require confirmation of background checks and may be revoked). Vendor shall ensure its users only attempt to access the applications, systems, and data in the Customer Information Systems that have been authorized by Customer, and to the minimum extent necessary to perform the services.
- User Devices. Vendor shall ensure that its users only use Vendor (or subcontractor) issued and managed IT devices to access Customer Information and Customer Information Systems. Vendor shall maintain controls on Vendor Information Systems to prevent Customer Information being stored on removable media, unless pre-approved by Customer. Vendor shall implement reasonable controls designed to monitor and prevent Customer Information from being sent via social media, personal email accounts, or similar personal means of transmission.
- Revoking User Access. If a Vendor user ceases to be an employee or contractor of Vendor or its subcontractor, or otherwise involved in delivering the services, then Vendor shall both (a) revoke access to Customer Information, and (b) if the user has access to the Customer Information Systems, either revoke access to the Customer Information Systems if controlled by Vendor or otherwise notify Customer, each within one business day of the user no longer requiring access or immediately if the user has been involuntarily terminated.
- Physical Controls. Vendor shall ensure appropriate physical security controls (including facility and environmental controls) are in place to prevent unauthorized physical access to Vendor Information Systems and areas in which Customer Information is stored or processed.
- Security Standards. Vendor shall comply with the UHG Security Standards set out in https://www.unitedhealthgroup.com/suppliers/supplier-policies.html, as of the date this Exhibit came into effect. Customer may revise the standards by giving notice by email to Vendor and Vendor shall meet any additional or enhanced standards within 180 days of being notified to the extent the revised standards are required by laws applicable to Customer (or earlier if required by applicable laws). Notwithstanding the foregoing, should Vendor object to any of the proposed changes then it shall notify Customer within 30 days of Vendor’s receipt of notice and the parties shall reasonably endeavour to resolve the objection.