Skip to content

Terms of service

Draft last updated

Draft: not yet in force. This page is a draft and not yet in force. It describes how the KYCVerify service at kycverify.me processes data; the bracketed fields are still to be completed and reviewed with counsel. Questions: hello@kycverify.me.

1. Agreement

These terms govern your use of [service name] (the "Service") provided by [Organisation legal name] ("we"). By creating an account you agree to them on behalf of the organisation you represent ("you"), and confirm you are authorised to do so. If you have signed an order form or master agreement with us, it prevails where it conflicts with these terms.

2. Definitions

End user
A person you invite to complete a verification.
Session
One verification of one end user, created through the API or the console.
Customer data
Data you or your end users submit to the Service, including verification results.
Documentation
The product documentation at [/docs], including the description of each check and its limits.

3. The Service

The Service lets you create verification sessions, collect identity documents, selfies and Indian identity artefacts from end users, run the checks described in the Documentation, review results and receive decisions by API and webhook. The Documentation forms part of these terms.

4. Accounts and access

  • You are responsible for everything done with your accounts, API keys and webhook secrets. Give team members only the roles they need.
  • Keep API keys on your servers. Tell us promptly at hello@kycverify.me if you suspect a key or account is compromised, and revoke the key in the console.
  • Sandbox apps and test keys are for evaluation only and must not be used to verify real people for production purposes.

5. Your responsibilities

  • Have a lawful basis to verify the people you invite and give them the notices the law requires, including for biometric data, and obtain any consent required.
  • Decide whether the checks meet your regulatory obligations. The Service does not certify compliance with any law or regulation.
  • Hold any registration or licence your use requires, for example to perform Aadhaar offline verification.
  • Review decisions that need a person, and do not rely on an automated result where the law requires human involvement.
  • Not use the Service to verify people without their knowledge, to discriminate unlawfully, or for any unlawful purpose.

6. Acceptable use

  • Do not attempt to access data of other customers, probe or bypass security controls, or exceed the rate limits deliberately.
  • Do not upload content you have no right to process, or malware.
  • Do not resell or white-label the Service without our written agreement.
  • Do not use the Service to build a competing product by systematically extracting its outputs.

7. Limits of the checks

Checks reduce risk; they do not eliminate it. Liveness is active challenge-response and is not certified presentation-attack detection. PAN validation is structural and does not query a government database. Sanctions screening covers only the lists named in the Documentation and is performed when a session is submitted, not continuously. We publish no accuracy rates, and results are provided to support your decision, not to replace it.

8. Customer data

You own customer data. You grant us the rights needed to provide the Service. Where we process personal data on your behalf, the Data processing agreement applies and forms part of these terms. We do not use customer data to train models or for any purpose other than providing the Service.

9. Fees

The sandbox is free for testing. Live and enterprise usage are charged as agreed in writing with you. [Invoicing, payment terms, taxes and price-change notice.]

10. Availability and changes

[Service levels, if any, or a statement that the Service is provided without a service-level commitment.] We may change the Service; we will give [notice period] notice of changes that materially reduce its functionality, and keep the API backward-compatible within a version where we reasonably can.

11. Suspension

We may suspend access, with notice where practical, if your use breaches these terms, threatens the security of the Service or other customers, or is required by law. We will restore access once the cause is resolved.

12. Confidentiality and intellectual property

Each party keeps the other's confidential information confidential and uses it only for this agreement. We own the Service and its software; you own your data and your configuration. Feedback you give us may be used without obligation.

13. Warranties, liability and indemnities

[Warranty disclaimer, limitation and exclusion of liability, and indemnities appropriate to your jurisdiction and commercial position. Review the balance carefully: identity-verification contracts often allocate consent and regulatory risk to the customer.]

14. Term and termination

These terms last until ended. Either party may end them with [notice period] notice, or immediately for a material breach not cured within [period]. On termination you may export your results for [period]; we then delete customer data within [period], unless the law requires us to keep it.

15. General

  • Notices: to us at hello@kycverify.me; to you at the account owner's email.
  • Assignment: neither party may assign these terms without consent, except to a successor of its business.
  • Entire agreement: these terms, the DPA, any order form and the Documentation are the whole agreement.
  • Governing law and courts: the laws of [jurisdiction]; the courts of [city] have exclusive jurisdiction.