Legal
Payment security statement
How card details are transmitted and handled.
Card data is never received by the Supplier
Card details are entered into hosted fields served directly by the payment service provider. The card number, expiry date and security code pass from the cardholder's browser to the provider without traversing the Supplier's systems.
The Supplier therefore never receives, processes or stores a primary account number. No card number is written to a database, a log file or a backup under the Supplier's control. What the Supplier receives back from the provider is the card scheme, the last four digits, the authorisation outcome and the 3-D Secure outcome.
This design places the Supplier in PCI DSS scope SAQ A rather than SAQ A-EP.
Transport security
All connections are served over TLS 1.2 or later. HTTP Strict Transport Security is set with a two-year maximum age, subdomain inclusion and preload. The certificate is issued to the trading legal entity.
Authentication of transactions
3-D Secure 2 strong customer authentication is applied to every transaction in the European Economic Area and the United Kingdom, including the initial authentication of any stored credential.
The Supplier does not pursue SCA exemptions and does not route transactions as mail-order or telephone-order. Both remove the liability shift that authentication provides, and MOTO carries no shift at all while still counting towards the Supplier's fraud numerator. The authentication is worth more than the conversion it costs.
Page integrity
Payment pages are subject to change detection, and script integrity is enforced by a content security policy that permits no third-party script origin. A script cannot be introduced onto a payment page by a tag manager, an advertising integration or a change to page markup alone. These controls implement PCI DSS v4.0.1 requirements 6.4.3 and 11.6.1.
Fraud controls
Address verification and card security code checks are applied to every transaction. Velocity limits, device fingerprinting, and rules comparing the card issuer's country with the destination country are applied, together with protection against card testing and enumeration. High-value orders are declined on an address-verification mismatch.
These are payment controls. They sit behind the substantive control on this site, which is that no order may be placed from an account that has not been manually approved.
Reducing disputes
The Supplier subscribes to chargeback alert services, and every consignment is tracked with signature on delivery above the published threshold. Order confirmations state the descriptor that will appear on the cardholder's statement, so a legitimate charge is recognisable.
Descriptor
Charges appear as DOHRNA RESEARCH REAGENTS. The descriptor is echoed beneath the pay control at checkout and repeated in the order confirmation. The city field of the descriptor carries dohrna.com.
Merchant outlet country: Malta.
Access and hosting
Hosting and primary processing are located within the European Economic Area. Access to account and order records is restricted by role to operators with an operational need. Administrative access requires multi-factor authentication.
Reporting a vulnerability
Suspected vulnerabilities should be reported to support@dohrna.com, marked for the attention of [[REGULATORY_CONTACT_NAME]]. Reports are acknowledged within two business days. The Supplier asks that a reported issue is not disclosed publicly until it has been addressed.
Payment service provider and acquirer
Acquirer: [[ACQUIRER_NAME]]. Merchant category code: [[ASSIGNED_MCC]]. The acquirer's registration under the Visa High Integrity Risk Acquiring Programme is recorded at [[ACQUIRER_VIRP_REGISTRATION]].
