IV. PCI DSS Compliance Statement
Payment Card Industry Data Security Standard Statement
PCI DSS v4.0 Compliance Statement – ZALEX MINING LIMITED
1. Purpose of Statement
This website accepts card payments including Visa and Mastercard. We strictly comply with PCI DSS v4.0, the global security standard for payment card data, to safeguard all cardholders’ payment information and mitigate risks of unauthorised card use, data breaches and payment fraud.
2. Scope of Payment Data Processing & Segregation Controls
2.1 This website does not collect, store or cache full bank card numbers, CVV security codes or card expiry dates. The checkout page embeds a hosted iFrame payment window operated by a Level 1 PCI-compliant third-party payment service provider. Card numbers and card security credentials are transmitted entirely within the encrypted environment of the payment service provider; our servers have no access to raw card data.
2.2 Network segmentation is fully implemented between the website and payment gateway. The payment page runs on an independent secure domain with third-party tracking scripts blocked to defend against Magecart card-skimming attacks.
3. Implementation of Six Core PCI DSS Security Controls
• Secure Network Architecture: Full-site HTTPS with TLS 1.3 encryption; firewalls and intrusion detection systems monitor server access 24/7.
• Cardholder Data Encryption Protection: All payment tokens and transaction records are stored with AES 256 encryption. Full card numbers are truncated; only the last four digits are retained for reconciliation purposes.
• Ongoing Vulnerability Management: Monthly server anti-malware scans and quarterly third-party security penetration testing to remediate system and plugin vulnerabilities promptly.
• Restrictive Access Control: Only authorised finance personnel may retrieve payment reconciliation records. Multi-factor authentication is required for backend login, and full audit logs are maintained for all operations.
• Continuous Security Monitoring: Uninterrupted surveillance of payment transactions to identify unauthorised card usage and fraudulent orders; suspicious transactions are automatically blocked.
• Information Security Governance: Internal staff non-disclosure agreements prohibit unauthorised export of payment-related data; regular PCI security awareness training is conducted.
4. Compliance Validation Method
This website qualifies for SAQ A Self-Assessment (hosted payment page model with no local storage of card data). We complete the PCI Self-Assessment Questionnaire annually, retain supporting compliance documentation, and cooperate with security audits initiated by card schemes and payment institutions at any time.
5. Commitment to User Payment Security
• No website staff, suppliers or third-party partners shall obtain any bank card payment information.
• In the event of fraudulent card use caused by website security vulnerabilities, we will support cardholders and issuing banks in transaction tracing and assist fund recovery.
• We will never request full card numbers, SMS verification codes or CVV codes from customers. Any messages requesting such information constitute fraud.
6. Dispute Provisions
Unauthorised card use resulting from customers voluntarily disclosing card information or clicking phishing links is excluded from the scope of security guarantee provided herein. Affected customers shall contact their issuing banks independently for resolution.

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.