If our company uses a third party to process and transmit credit card information. Meaning the online tools that we use does not reside within the company. Are we still qualified for PCI DSS?