verkyc Customer Terms of Service
The operator details (name, registration number, address, contact) will be added to this document once approved. The terms apply as set out in this version.
Version of 3 October 2026.
1. Parties and subject matter
1.1. These terms are concluded between [to be confirmed] (registration number [to be confirmed], address [to be confirmed], the "Operator") and the organisation or sole trader that accepted them when registering in the console at https://console.verkyc.com or that signed an order form (the "Customer").
1.2. The Operator gives the Customer access to the verkyc service (the "Service"): the application programming interface (API), the console, the applicant verification page (hosted flow), the embeddable module and the mobile SDKs, and performs the verification services listed in section 3.
1.3. The terms are accepted by action: by ticking the acceptance box when the organisation registers in the console or by signing an order form. Acceptance is recorded with the version of the terms, the time and the account of the Customer's employee.
1.4. The following form an integral part of these terms: the Data Processing Agreement (DPA), the Service Level Agreement (SLA), the Privacy Policy, the Customer's price plan and order forms. In case of conflict, the DPA prevails on personal data, the SLA on availability and the price plan on prices.
2. Definitions
2.1. Applicant: a natural person whose identity is verified at the Customer's request, as well as the representative of an organisation and its related persons when an organisation is verified.
2.2. Case: all materials, checks and decisions concerning one applicant or one organisation.
2.3. Result: the outcome of the checks of a case, listing the checks performed and not performed, reasons, limitations and a signed report.
2.4. Live environment and sandbox: operating modes of the Service. The sandbox processes synthetic data only; uploading real personal data to the sandbox is prohibited.
3. Services
3.1. At the Customer's request the Service:
- receives images of an identity document, assesses their quality and authenticity features, reads the machine readable zone and the document data;
- reads and verifies the electronic chip of the document (NFC) against the certificates of the issuing states, where this check is available for the country;
- checks the presence of the applicant (liveness) and compares the applicant's face with the document photo, where processing of biometric data is permitted for the country and scenario;
- checks an organisation against open registers, including its directors, shareholders and ultimate beneficial owners;
- screens against official sanctions lists, lists of politically exposed persons and adverse media;
- produces a report signed with the Operator's electronic signature, with a log of the checks.
3.2. By default the result of the service is an evidence assessment (evidence_assessment): the Service establishes whether the submitted materials meet the verification rules of the Customer's policy. The result is not an identification within the meaning of the anti-money laundering law of any country and does not replace the Customer's own duty to identify its client, where the Customer has such a duty. Identification under the requirements of a specific law (statutory_identification) is provided only in the countries and scenarios for which an approved compliance map is in force in the Service; the list is shown in the console under "Legal applicability".
3.3. The set of capabilities depends on the country of the document and is enabled per capability. Before data collection starts, the Customer and the applicant see which checks are available for the country and with which limitations. A check that is not available ends with the status "not performed" and a reason and is not treated as passed.
3.4. The Customer takes the decision on a case. The Service applies the policy rules configured by the Customer and shows the grounds for each outcome. The Customer ensures human review of disputed cases where applicable law requires it and handles applicants' requests to review a decision.
4. Customer obligations
4.1. The Customer:
- determines the purposes of the verification and the legal bases for processing applicants' personal data and states them in the organisation's legal profile in the console before working in the live environment;
- informs applicants and obtains their consent in the form required by the law of the applicant's country, including written consent to the processing of biometric data; the Service provides the consent screen of the hosted flow for this and records the confirmation;
- complies with the requirements of its own law on the storage of personal data of its citizens and on cross-border transfer, including notification of the supervisory authority where required;
- uses results only for the purposes stated in the legal profile;
- does not upload data that is not needed for the verification and does not submit requests about persons who have given no ground for a check;
- keeps API keys, employee accounts and second factors secure;
- complies with the sanctions restrictions that apply to it and to its clients.
4.2. The Customer must not use the Service to monitor persons, to profile them beyond the purpose of the verification, to take decisions based solely on automated processing where the law of the applicant's country requires human involvement, or to verify persons below the age at which the law of their country allows them to consent on their own, without the consent of a legal representative.
5. Operator obligations
5.1. The Operator:
- runs the Service at the level set out in the SLA;
- processes applicants' personal data on behalf of and on documented instructions of the Customer in accordance with the DPA;
- hosts data in the processing region eu-de-1 (Germany) and does not transfer it to other countries except as listed in the DPA;
- does not use applicants' data to train models without a separate instruction of the Customer and a legal basis for that purpose; such use is switched off by default;
- notifies the Customer of security incidents affecting its data within the time limits of the DPA;
- keeps a log of checks and decisions sufficient to reproduce the result.
6. Accounts and access
6.1. Customer employees get access to the console by invitation. Signing in to the console requires a second factor. The Customer assigns roles to its employees and is responsible for their actions.
6.2. The Operator may suspend an API key or an account if there are signs of compromise, bulk data extraction or a breach of these terms, notifying the Customer and stating the reason.
7. Prices and payment
7.1. Services are paid under the Customer's price plan per billable unit (check, report, request to a paid source). An invoice is issued for a closed period based on the usage log; repeated requests to the same source within the caching period are not charged again.
7.2. Payment is made through the payment provider shown in the console or by bank transfer to the details on the invoice. An invoice is paid when the funds are received.
7.3. The Operator may change the price plan by notifying the Customer at least 30 days in advance. New prices apply to periods starting after the change takes effect.
8. Intellectual property
8.1. All rights to the Service, its software, models, documentation and trademarks belong to the Operator or its licensors. The Customer receives a non-exclusive right to use the Service within these terms for their duration.
8.2. The Customer may use results and reports of its cases without restriction within the purposes of processing. Data of sources is used on the source's terms stated in the report.
9. Confidentiality
9.1. Each party keeps confidential the information received from the other in performing these terms, except information that is public or must be disclosed by law. The obligation lasts five years after termination and, for personal data, without time limit.
10. Liability
10.1. The Operator is liable for direct damage caused by its fault in performing these terms. The Operator's total liability for any 12 months is limited to the amounts paid by the Customer for those 12 months. The limitation does not apply to damage caused intentionally or by gross negligence or to breaches of data protection obligations where applicable law does not allow such a limitation.
10.2. The Operator is not liable for decisions the Customer takes based on a verification, for inaccurate data of official sources or for the unavailability of sources outside the Operator's control; such cases are shown in the result by the status of the check and its limitations.
10.3. The Customer indemnifies the Operator against damage and costs from third-party claims arising from processing for which the Customer had no legal basis or did not obtain a required consent.
11. Term, changes and termination
11.1. These terms are concluded for an indefinite period from acceptance. Either party may terminate them by 30 days' notice; the Operator may also terminate immediately for a material breach of sections 4 and 7 by the Customer.
11.2. The Operator may change these terms by publishing a new version at https://verkyc.com and notifying the Customer in the console at least 30 days before it takes effect. Changes required by law may take effect within the time set by law.
11.3. On termination the Operator, at the Customer's choice, returns the case data in a machine-readable format and deletes it in accordance with the DPA. Data that the Operator must retain by law is kept for the required period and is not used otherwise.
12. Governing law and disputes
12.1. These terms are governed by [to be confirmed]. Data protection rules of the applicant's country apply to the extent they are mandatory for the parties.
12.2. Disputes are settled by negotiation and, failing agreement within 30 days, by the courts at the Operator's seat, unless mandatory rules provide otherwise.
13. Contacts
Operator: [to be confirmed], [to be confirmed]. Contact: [to be confirmed]. Personal data questions: privacy@verkyc.com.