Diagnostics

For billing, fraud detection, and troubleshooting purposes, we collect certain information from your users as part of their use of your services. In general, all information processed by our services is fully encrypted, meaning YAXI cannot read the clear text unless the data is explicitly recorded. Below is a detailed description of the information we process or store, which you can include in your privacy policy to inform your users.

Web server logs

For each HTTP request you issue, our web server automatically logs the following information:

Information Example

Masked source IP address and port

2001:a61:2758:::3686

Timestamp

11/Apr/2025:17:24:56.150

Requested endpoint

GET /collect-payment/confirm HTTP/1.1

HTTP response status of the request

200

User agent

Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:137.0) Gecko/20100101 Firefox/137.0

Service call records

For each service call, we record the following anonymous information:

Information Example

Your user’s account servicing payment service provider

N26

The connection that was used

connection-132565f6-16fc-4586-8087-af886d34d4f8

Amount and currency, if any

€50.00

Timestamp

2025-03-28 13:42:12.103

A YAXI internal ID

request-ff55ea9e-44e5-4043-8b1e-b3a977028ec8

ID assigned by the account servicing payment service provider, if any

payment-81529843-b867-47ba-b63c-0b933ac76a25

We use this data for the following purposes:

  • To account the usage of our services to you.

  • To allow you to view and review past service calls.

  • To compile statistics.

  • To address claims of fraud. If we have reasonable grounds to suspect fraud, we may be obliged to disclose the relevant records for further investigation. In this case, we will notify you of this disclosure.

For fraud investigation purposes, we are required to retain this information for up to seven years.

Observability traces

To monitor and improve the reliability and performance of our services, we collect anonymous traces that include the following information:

Information Example

Anonymized IP

Vxp4ig

Timestamp

2025-03-28 13:42:12.103

Requested endpoint

GET /collect-payment/confirm

User agent

Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:137.0) Gecko/20100101 Firefox/137.0

Your ticket ID

ef3837d8-b2b0-42be-8718-64fc7551c6b7

Service ID

Account or CollectPayment

API key ID

api-key-1fd568f1-6df5-47f2-bf9a-65e5e1056c3c

Tenant ID

tenant-a79c6537-caa6-45bd-aef3-bb86cbfbccb3

Connection ID

connection-a1d5708d-ebee-4320-8609-10d6ddf90be7

Invocation ID

invocation-1e2658ec-6583-4b7f-adca-f945f88ed368

Session ID

session-17e5fdc4-c27c-4b6d-adf7-9edc8c35beff

Context ID

context-031e1a9c-7e48-488a-9055-d626742fa35f

Encryption Session Key ID

17fe3157ec087750a94163d7defe708fb59f851ccb2f2f86de818b6db552d5e1

Messages we log explicitly

HIRMS codes: 9010 HIRMG codes: 9050, 9800, 9340 or Unexpected error response with status 404 Not Found

The messages we log explicitly to our observability traces never contain personally identifiable information. Also see Diagnostic archive.

Additionally, when the request triggered a call to a remote system, the following information is recorded:

Information Example

Timestamp

2025-03-28 13:42:12.103

Duration

150ms

Endpoint with blanked IDs

GET /consents/v1/<ID>

Response status

200

Remote system’s response ID (value of x-response-id, x-ing-response-id, x-request-id or x-fapi-interaction-id header if present)

c813fbac-a203-490d-a367-86aad58aaaaf

The data is stored for 90 days.

Diagnostic archive

To help troubleshoot any issues you or your users may encounter, we create an encrypted diagnostic archive for each service call. This archive includes a detailed request log. While our service removes sensitive information (such as online banking credentials), it may still contain personal data. The encrypted diagnostic archive is inaccessible to YAXI, but only YAXI has the key to decrypt it, meaning that neither you nor YAXI can access its contents without your cooperation.

With your user’s informed consent, you may share the encrypted diagnostic archive with YAXI for debugging purposes. Please note that diagnostic archives are not stored permanently and are only available to you for a limited time. YAXI deletes diagnostic archives you shared as soon as the issue is resolved, or no later than 14 days.