Text in a dashed box, like this, is a placeholder to be completed before the document takes effect.
1. About these terms
These terms of service (“Terms”) govern access to and use of the ChrysoSure AI platform, its APIs, SDK, hosted journeys and related services (together, the “Service”). The Service is provided by [Legal entity name], registered in [jurisdiction] under number [company number] (“ChrysoSure”, “we”, “us”).
The Service is for businesses only. The Terms form an agreement between ChrysoSure and the organisation named in an order form or other written agreement that refers to them (“Customer”, “you”). If there is a conflict, a signed order form or master agreement takes precedence over these Terms. The data processing agreement (“DPA”) takes precedence on matters of personal data. The person accepting these Terms confirms that they have authority to bind the Customer.
Access to the Service is by agreement with us. There is no self-service sign-up.
2. Definitions
- Customer Data: data, including personal data, that you or your users submit to the Service or that the Service processes for you.
- Output: results the Service generates from Customer Data, for example risk ratings, screening matches, alerts, scores, drafted narratives, recommendations and report files.
- Authorised Users: your employees and contractors whom you permit to use the Service.
- Agent: an AI feature of the Service that gathers information and proposes actions.
3. Using the Service
Access. Subject to these Terms and payment of the fees, we grant you a non-exclusive, non-transferable right for your Authorised Users to use the Service during the subscription term, for your internal business purposes.
Accounts. You are responsible for your Authorised Users, for keeping their credentials secure, and for all activity under your accounts. Use single sign-on and multi-factor authentication where available. Tell us promptly at security@chrysosureai.com if you suspect unauthorised access.
Changes. We improve the Service over time. We will not make a change that materially reduces the core functionality of a module you subscribe to during your subscription term without telling you in advance. [Notice period]
4. Your compliance responsibilities
The Service supports your financial crime compliance programme. It does not replace it. In particular:
- You remain responsible for your regulatory obligations and for every decision you make, including whether to onboard, decline, exit, block, report or clear a customer, transaction or match.
- The Service produces report files but does not file them. You decide whether and what to file with any regulator or financial intelligence unit, and you file it yourself.
- Mapping is not certification. Our mapping of platform controls to laws and frameworks is there to help you. It does not make you compliant with any law.
- You are responsible for the people whose data you process. That means having a lawful basis, giving the notices the law requires, obtaining any consent that is needed (including written consent under biometric privacy laws), and meeting your record-keeping duties.
- Automated decisions. If you configure the Service so that a result takes effect without human review, you are responsible for making sure that is lawful, including under Article 22 of the GDPR, and for giving people the safeguards the law requires.
- Not a consumer reporting agency. ChrysoSure is not a consumer reporting agency. You must not use Output as a consumer report, or as the basis for decisions about eligibility for credit, insurance, employment or housing, in a way that would make the US Fair Credit Reporting Act or a similar law apply, unless we have agreed in writing. [Review FCRA position]
- Confidentiality of reports. You are responsible for keeping suspicious activity reports confidential and for avoiding tipping off, including in any outreach you send through the Service.
5. Artificial intelligence, screening data and Output
Human review. Agents and other AI features gather evidence and make recommendations. The Service requires human approval before an agent’s proposal to file a report, decline or exit a customer, block activity or confirm a sanctions match takes effect. You must not configure or use the Service to bypass these approval steps.
Accuracy. AI Output, including drafted narratives and data read from documents, can be incomplete or wrong. Screening depends on sanctions, politically exposed person, adverse media and registry sources. Some are published by governments and others come from third parties, and none of them is guaranteed to be complete or current at any moment. Document, chip, selfie and presence checks reduce the risk of fraud; they do not eliminate it. No system detects all financial crime. You should review Output before relying on it.
Rules and models. You are responsible for the rules, thresholds, workflows and models you configure or train. We recommend backtesting rules before they go live.
6. Acceptable use
You must not, and must not allow anyone else to:
- use the Service in breach of any law, including data protection, anti-discrimination, consumer protection, sanctions and export control laws;
- use the Service to profile, monitor or make decisions about people for purposes other than meeting legal and regulatory obligations, preventing financial crime or fraud, and managing risk. This includes surveillance of individuals, employee monitoring and political or journalistic targeting;
- make decisions based on race, ethnicity, religion, sex, sexual orientation, disability or another protected characteristic, except where the law requires or permits it;
- submit personal data without a lawful basis, or biometric data without any notice and consent the law requires;
- use outreach features to send marketing, unsolicited messages or anything other than requests connected with verification and compliance;
- circumvent human approval steps, access controls, rate limits or security measures, or access another customer’s data;
- probe, scan or test the vulnerability of the Service, except under our vulnerability disclosure policy or with our written permission;
- upload malware or content designed to manipulate AI features into acting outside their instructions;
- copy, frame, reverse engineer, decompile or build a competing product from the Service, its Output, its models or its documentation, except where the law allows this despite a contractual restriction;
- resell, sublicense or provide the Service to third parties, or use it on behalf of anyone other than yourself, unless we have agreed in writing;
- extract, republish or redistribute screening or watchlist data beyond what you need for your own compliance purposes;
- use the Service for, or on behalf of, a person or country subject to sanctions that apply to you or to us.
We may suspend access that breaches this section, as described in section 12.
7. Customer Data
Ownership. As between you and us, you own Customer Data and Output. You grant us the rights we need to host, process and transmit Customer Data to provide, secure and support the Service, and to meet our legal obligations.
Data protection. Where we process personal data for you, we do so as your processor or service provider under the DPA. The DPA forms part of these Terms and is available from privacy@chrysosureai.com. Our privacy notice describes the processing in more detail.
Model training. We do not use your Customer Data to train models that serve other customers. Models you train on your own data are for your use only. [Confirm before launch]
Shared fraud signals. If you opt in to the shared fraud-signal network, you authorise us to share hashed identifiers from your confirmed fraud cases with other participants, as described in our privacy notice. You can opt out at any time. Opting out stops future contributions.
Service data. We may collect technical and usage data about how the Service operates and use it to run, secure and improve the Service. We may use aggregated data that does not identify you, your users or any individual.
Data residency. You choose the region where your Customer Data is primarily stored, from those we offer.
8. Security
We maintain technical and organisational security measures appropriate to the nature of Customer Data, as described in the DPA and on our security page. We will notify you of a security incident affecting your Customer Data as the DPA requires.
We do not currently hold SOC 2 or ISO 27001 certification. We will not represent otherwise.
9. Third-party services
The Service relies on third-party providers, including hosting, message delivery, language model and screening data providers. We are responsible for our subprocessors as the DPA sets out.
Some integrations you choose to connect, such as your own identity provider, data warehouse or AI agents connected over the Model Context Protocol, are governed by your own terms with those providers. We are not responsible for them.
10. Fees and payment
You will pay the fees in your order form. [Invoicing, payment terms, late payment interest] Fees exclude taxes, which you will pay except for taxes on our income. [Renewal and price change terms]
11. Confidentiality
Each party will keep the other’s confidential information confidential. It will use that information only to perform this agreement and disclose it only to people who need to know it and are bound by similar duties. This does not apply to information that is public, already known to the recipient, independently developed, or lawfully received from someone else. Either party may disclose confidential information where the law or a regulator requires, giving notice where it lawfully can.
12. Suspension
We may suspend access, where possible only for the users or features concerned, if we reasonably believe:
- your use breaches section 6;
- your use creates a security risk to the Service or other customers;
- suspension is required by law; or
- undisputed fees are more than [30] days overdue after we have given notice.
We will tell you, and restore access once the issue is resolved.
13. Term and termination
These Terms apply for the subscription term in your order form. [Renewal terms] Either party may terminate for the other’s material breach if it is not remedied within [30] days of notice, or if the other party becomes insolvent.
On termination, your right to use the Service ends. You may export your Customer Data for [30] days. After that we delete it as the DPA describes, unless the law requires us to keep it. You remain responsible for keeping any records your own regulatory obligations require.
14. Warranties and disclaimers
We warrant that the Service will perform materially as described in its documentation, and that we will provide it with reasonable skill and care. If it does not, we will use reasonable efforts to correct the problem. If we cannot, either party may terminate the affected module, and we will refund prepaid fees for the remaining term. [Service levels, if any]
Except as expressly stated in these Terms, and to the extent the law allows, the Service and Output are provided without other warranties, express or implied. This includes warranties of merchantability, fitness for a particular purpose, and that the Service will detect all financial crime or fraud, or be uninterrupted or error-free.
15. Indemnities
[Mutual indemnities to be agreed: for example, ChrysoSure for third-party claims that the Service infringes intellectual property rights; Customer for claims arising from Customer Data, its lack of a lawful basis or notice, or its breach of section 6]
16. Limitation of liability
Nothing in these Terms limits liability that cannot be limited by law, including liability for death or personal injury caused by negligence, or for fraud.
Subject to that, neither party is liable for:
- loss of profits, revenue, goodwill or anticipated savings;
- indirect or consequential loss;
- fines or penalties imposed on the other party by a regulator for that party’s own non-compliance.
Each party’s total liability under or in connection with these Terms in any 12-month period is limited to [the fees paid or payable in the 12 months before the claim]. [Any separate cap for data protection, confidentiality and indemnity claims]
17. Intellectual property
We and our licensors own the Service, including its software, models, documentation and everything we develop in providing it. No rights are granted except as expressly set out in these Terms. If you give us feedback, we may use it without restriction or obligation.
18. Export controls and sanctions
Each party will comply with the export control and sanctions laws that apply to it. You confirm that you are not a sanctioned person and are not owned or controlled by one, and that you will not give access to the Service to anyone who is.
19. Governing law and disputes
These Terms and any dispute arising from them are governed by the laws of [governing law]. The courts of [jurisdiction] have exclusive jurisdiction. [Arbitration or escalation procedure, if any]
20. General
- Assignment. Neither party may assign these Terms without the other’s consent, except to a successor of all or substantially all of its business on notice.
- Force majeure. Neither party is liable for delay or failure caused by events beyond its reasonable control.
- Independence. The parties are independent contractors.
- No third-party rights. No one other than the parties has rights under these Terms.
- Waiver and severability. A waiver must be in writing. If a provision is found unenforceable, the rest of the Terms remain in effect.
- Entire agreement. These Terms, the order form and the DPA are the entire agreement between the parties on their subject matter.
- Changes. We may update these Terms by giving you at least [30] days’ notice. Changes will not apply to a subscription term already under way unless you agree.
- Notices. Legal notices to us must be sent to [notice address], with a copy to compliance@chrysosureai.com.
21. Contact
- Sales and contracts: sales@chrysosureai.com
- Support: support@chrysosureai.com
- Security: security@chrysosureai.com
- Privacy: privacy@chrysosureai.com