Terms of Service

Last updated: October 1st, 2026

INTRODUCTION

A. These Terms of Service. These Terms of Service (“Terms of Service”) govern the Services that SEON provides to business customers. A customer agrees to these Terms of Service either (i) by signing an Order Form that refers to them, or (ii) by accepting them online, for example by ticking a box or clicking to accept when creating an account, starting a trial, or ordering Services through SEON’s website or the Admin Panel. “Customer” means the business entity named in the Order Form or on whose behalf these Terms of Service are accepted online, and the individual who accepts online on behalf of Customer represents that they are authorized to bind Customer. “SEON” means the SEON entity named in the Order Form or, where Customer accepts these Terms of Service online, SEON Technologies Kft. These Terms of Service, each Order Form and Online Order, and the terms incorporated by reference in them together form the agreement between SEON and Customer (the “Agreement”), and references below to “this Agreement” mean the Agreement. The “Effective Date” is the earlier of the date on which the first Order Form has been signed by both parties and the date on which Customer first accepts these Terms of Service online.

B. Signed agreements take priority. Where SEON and Customer have signed a separate subscription services agreement or other written agreement for the Services, that agreement governs the Services ordered under it, and these Terms of Service do not apply to those Services. Any terms on this page that such an agreement refers to continue to apply as that agreement provides.

C. Incorporated terms. The following terms, set out further down this page, form part of the Agreement:

(1) Acceptable Use Policy;

(2) Support Terms;

(3) Service Level Commitment;

(4) Data Processing Agreement; and

(5) Professional Services Agreement, where Customer orders Professional Services.

D. Online orders. Where Customer orders Services online rather than under a signed Order Form, the plan, pricing, usage limits and other order details that SEON presents and Customer accepts online (an “Online Order”) are treated as an Order Form for all purposes of this Agreement, and accepting online is a valid means of accepting this Agreement and each Online Order. For Online Orders:

(1) Customer authorizes SEON and its payment service providers to charge the payment method Customer provides for all fees when due, including recurring fees;

(2) where the Online Order does not state a fixed term, it continues until Customer terminates it, which Customer may do at any time with immediate effect by email to [email protected] or by any method SEON makes available online, or until SEON terminates it on thirty (30) days’ notice;

(3) the fee increase on automatic renewal in Section 4.1 does not apply. SEON may instead change its fees on thirty (30) days’ notice, with effect as stated in the notice, and if Customer does not agree to the change, Customer may terminate the Online Order with immediate effect; and

(4) notices to Customer under Section 16.1 may also be sent to the email address of the administrator User of Customer’s account.

E. Free trials and evaluations. Where SEON makes Services available free of charge, including for a trial, evaluation or proof of concept, SEON determines their scope and duration and may end them at any time. Such Services are provided “as is”, and the Services Warranty in Section 9.2 and the Service Level Commitment do not apply to them. Where Customer has not paid and does not owe any fees under this Agreement, the limit on each party’s aggregate liability in Section 10.2 is one hundred euros (EUR 100), subject to Section 10.3.

F. AWS Marketplace. Where Customer procures access to the Cloud Services through AWS Marketplace, an accepted AWS Marketplace offer that refers to these Terms of Service is treated as an Order Form. Such procurement is solely a commercial transaction enabling Customer to arrange for the payment for SEON’s services via the AWS Marketplace platform. The Cloud Services and all related rights and obligations are governed exclusively by this Agreement and the specific terms of any accepted AWS Marketplace offer, and no other general AWS Marketplace terms shall modify, supersede, or form part of this Agreement with respect to the items addressed in this Agreement unless expressly agreed in writing by SEON.

G. Business customers only. The Services are intended solely for use by businesses. Customer may not order or use the Services in a consumer capacity.

H. Updates. Section 2.5 applies to these Terms of Service in the same way as to the other terms referenced by URL in this Agreement. The date of the most recent update is shown at the top of this page, and earlier versions are available on request from [email protected].

I. Earlier versions. A customer that accepted an earlier version of these Terms of Service continues under that version until it accepts this version, whether by signing a new Order Form that refers to these Terms of Service or by accepting them online.

J. SEON entities and service provider information. SEON provides the Services through the following entities:

SEON Technologies US Inc., a Delaware corporation, 310 Comal Street, Suite 270, Austin, TX 78702, United States;

SEON Technologies Kft., a Hungarian limited liability company, Szabadság tér 7., Platina Tower, Floors 8 & 9, 1054 Budapest, Hungary; company registration number 01-09-292732 (Company Registry Court of Budapest Capital Regional Court); tax number 25854071-2-42;

SEON Technologies Brazil LTDA, a Brazilian sociedade limitada, Av. Marquês de São Vicente, 230, Conj. 1218, Sala 15, Várzea da Barra Funda, São Paulo – SP, CEP 01139-000, Brazil.

SEON’s hosting provider is Amazon Web Services EMEA SARL (38, Avenue John F. Kennedy, L-1855 Luxembourg; aws.amazon.com/contact-us). Elasticsearch B.V. (Keizersgracht 281, 1016 ED Amsterdam, the Netherlands; www.elastic.co) is a main provider that supports the functioning of the Services. These Terms of Service are available in English.

1. Definitions

“Acceptable Use Policy” means SEON’s policy governing the permitted and prohibited uses of the Cloud Services, available at https://seon.io/legal-and-security/legal/#h-acceptable-use-policy.

“Admin Panel” means the web-based dashboard/UI application provided as part of the Cloud Services through which SEON and the Customer communicate, and the Customer or its Users submit, manage and process requests and configure and operate the products provided as part of the Cloud Services.

“Affiliate” means any entity that directly or indirectly controls, is controlled by, or is under common control with a party to this Agreement. For the purposes of this definition “control” shall mean the ownership, directly or indirectly, of more than fifty percent (50%) of the voting securities or other ownership interests of such entity, or the ability to direct the management and policies of such entity, whether through ownership, by contract, or otherwise.

“API” means application programming interface.

“Applicant” means the end user (whether natural person or legal entity) providing documents, images, and other input data with respect to which SEON performs Services.

“Cloud Services” means the hosted software-as-a-service platform and any optional modules or components that SEON makes available to Customer under an Order Form, as updated from time to time. The Cloud Services may be accessed or used through the Admin Panel, APIs, SDKs, SEON’s MCP connector, or any other means SEON makes available, together with their associated client-side or offline components, where applicable. Cloud Services exclude Beta Services, Third-Party Applications, Support Services, and Professional Services.

“Customer Data” means all electronic data, including personal data as defined in the DPA, or information submitted to and stored in the Cloud Services by the Customer or its Users, as well as data collected from Applicants or other end users on Customer’s behalf through the Cloud Services (including through SDKs).

“DPA” means a data processing agreement executed by the parties, if applicable. If the parties have not signed a separate data processing agreement, then SEON’s DPA made available at https://seon.io/legal-and-security/legal/#h-data-processing-agreement, or such other URL as specified by SEON, shall be deemed the data processing agreement between the parties.

“MCP” means Model Context Protocol.

“Order Form” means a SEON quote or order form in the name of and executed by Customer and accepted by SEON which specifies the Cloud Services, and any Support Services and/or Professional Services to be provided by SEON subject to the terms of this Agreement.

“Professional Services” means the optional, expert-led advisory and operational services that SEON offers in addition to the Cloud Services and its standard onboarding, implementation and Support Services. Professional Services are provided pursuant to the terms of this Agreement and the additional terms available at https://seon.io/legal-and-security/legal/#h-professional-services-agreement or such other URL as specified by SEON.

“SDK” means software development kit.

“Support Services” means the supplemental, free or fee-based technical support services to be provided to Customer for the Cloud Services pursuant to the terms hereof and the additional terms for Support Services available at https://seon.io/legal-and-security/legal/#h-support-terms or such other URL as specified by SEON.

“Third-Party Applications” means applications, integrations, services, or implementation, customization and other consulting services related thereto, provided by a party other than SEON that interoperate with the Cloud Services.

“User Guides” means SEON’s online user guides and technical documentation for the Services, currently available at https://docs.seon.io, as updated from time to time.

“Users” means individuals authorized by Customer to use the Cloud Services pursuant to this Agreement for whom subscriptions to the Cloud Services have been procured. Users may include but are not limited to Customer and Customer’s Affiliates, employees, consultants, contractors, and agents.

2. Services

2.1 Grant of Rights. Subject to the terms and conditions of this Agreement, Customer shall have the non-exclusive, worldwide, limited right to use the Cloud Services, Support Services, Professional Services, and Beta Services ordered by Customer (collectively, the “Services”) during the applicable period set forth in the applicable Order Form. Customer may use the Services and their outputs for its internal business operations, including within Customer’s own products and services, to screen Customer’s own Applicants, transactions, and Users. To the extent that Customer allows its Users to use the Services, Customer remains responsible for their compliance with this Agreement and the applicable Order Form. Customer may not resell the Services or provide any third party with direct access to the Services.

The Services may be used for lawful purposes, including fraud detection and prevention, internal risk management, due diligence, compliance with anti-money laundering (AML) and countering the financing of terrorism (CFT) requirements, remote identity verification (IDV), and other related legitimate activities. Please note, however, that SEON is not a consumer reporting agency and the Services are not a “consumer report.” SEON’s system and services should not be used without the Customer’s active control and human oversight to determine: (a) an individual’s eligibility for credit, loans, or other financial products; (b) an individual’s eligibility for insurance, housing, or employment; or (c) any decision requiring compliance with the Fair Credit Reporting Act (FCRA) or equivalent legislation in other jurisdictions.

SEON’s Services and their outputs are designed solely to assist in risk management and related prevention, detection, verification, authentication or reporting processes. The outputs provided by the Cloud Services or any results of the Professional Services are based on data provided by third-party sources, public records, and user-submitted information, and may be subject to inaccuracies, delays, or errors. Risk scores, fraud signals, and screening results are probabilistic, and SEON does not guarantee that the Services will detect or prevent all fraud or illicit activity. Customer remains solely responsible for its own AML, CFT, and fraud-prevention programs, risk assessments, and regulatory reporting, which the Services support but do not replace.

2.2 Performance of Services. SEON may perform the Services, in whole or in part, itself or through one or more of its Affiliates or subcontractors, provided that SEON remains responsible for performance of the Services in accordance with this Agreement.

2.3 Support Services. As part of the Cloud Services, SEON will provide Customer with documentation (including User Guides), direct communication with Users and/or authorized representatives of Customer, and other online resources to assist Customer in its use of the Cloud Services. SEON may also offer optional additional Support Services and Professional Services for a fee.

2.4 Service Level. During the Term, the Cloud Services will meet the service level specified in the “Service Level Commitment,” available at https://seon.io/legal-and-security/legal/#h-service-level-commitment or such other URL as specified by SEON. If the Cloud Services fail to achieve the service level, then the Customer will be entitled, as its sole and exclusive remedy, to a credit for the Cloud Services in accordance with the terms set forth in the Service Level Commitment. Current service availability and incident status are published at https://status.seon.io/, and the status of data enrichment is published at https://status-enrichment.seon.io/ (or such other URLs as specified by SEON), for information only; service credits are determined under the Service Level Commitment.

2.5 Updates. During the Term, SEON may update the Services, the terms referenced by URL in this Agreement and the User Guides to reflect changes in, among other things, laws, regulations, rules, technology, industry practices, patterns of system use, and availability of Third-Party Applications. The terms of this Agreement also apply to any updates and upgrades SEON provides for the Cloud Services, which SEON hosts and may update in functionality, interface, usability, and related documentation from time to time in its sole discretion, in accordance with this Agreement, as part of its ongoing efforts to improve the Services. Such updates and upgrades will not materially reduce the level of performance, functionality, security or availability of the Services during the term of this Agreement.

2.6 Third-Party Applications

(a) Customer acknowledges and agrees that SEON may enable interoperability of the Services with Third-Party Applications, including via APIs, connectors, integrations, or similar technologies (including, without limitation, MCP servers or integrations with large language models or other AI systems) (collectively, “Integrations”). Any procurement, access, or use of Third-Party Applications by Customer via such Integrations is solely the responsibility of Customer and/or the applicable third-party provider.

(b) To the extent Customer enables or uses any Integrations, Customer instructs SEON to transmit, make available, or otherwise permit access to Customer Data to such Third-Party Applications. Customer acknowledges that any Customer Data transferred to, accessed by, or processed within Third-Party Applications is no longer under SEON’s control and will be subject to the terms, conditions, and data processing practices of the applicable third-party provider.

(c) SEON shall have no responsibility or liability for, and disclaims any warranty with respect to, (i) the processing, use, disclosure, modification, or deletion of Customer Data by any Third-Party Applications, including any large language models or AI systems; (ii) the security, integrity, or confidentiality of Customer Data once transmitted to or accessed by such Third-Party Applications; or (iii) any acts or omissions of the providers of such Third-Party Applications.

(d) Customer is solely responsible for (i) evaluating and selecting Third-Party Applications; (ii) ensuring that its use of such Third-Party Applications complies with applicable laws and regulations, including all applicable data protection laws; and (iii) obtaining all necessary rights, consents, and other legal bases required for the transfer and processing of Customer Data by such Third-Party Applications.

(e) Except as otherwise provided in the Chargeback Management section of this Agreement (where applicable), these provisions do not apply to any applications or services provided by third parties and integrated into the Services by SEON, as opposed to Customer, for which SEON retains responsibility.

2.7 Beta Services

(a) From time to time, SEON may offer access to services that are being provided prior to general release and are therefore classified as “Beta Services.”

(b) SEON (i) makes no warranties and representations that a Beta Service will ever be made generally available; (ii) reserves the right to discontinue or modify a Beta Service at any time without prior notice; and (iii) is not obliged to provide technical support in connection with the Beta Service.

(c) Beta Services are provided “AS-IS” and by their nature, may be incomplete, contain bugs, errors or other defects. Customer’s use of the Beta Services is solely at the Customer’s risk.

(d) To the extent permitted by applicable law, SEON disclaims any liability, warranties, indemnities, and conditions, whether express, implied, statutory or otherwise in connection with a Beta Service.

(e) For the Beta Services only, the terms of this clause 2.7 supersede any conflicting terms and conditions in this Agreement.

3. Ordering, Fees, and Taxes

3.1 Ordering. The Services shall be ordered by Customer pursuant to Order Forms. Each Order Form shall include a listing of the Cloud Services and any Support Services and/or Professional Services being ordered and the associated fees. Except as otherwise provided on the Order Form or this Agreement, once signed, each Order Form is non-cancellable and all sums paid are non-refundable.

3.2 Affiliate Orders. Any of the Customer’s majority owned subsidiaries or affiliates under its control may also order Services under this Agreement by entering into an Order Form, signed by such subsidiary and SEON, and agreeing to be bound by the terms of this Agreement and such Order Form. For the purposes of such Order Form, “Customer” as used in such Order Form and this Agreement, shall be deemed to refer to the majority owned subsidiary or controlled affiliate executing such Order Form.

3.3 Entitlement to Products and Features

(a) “Entitled Products” refer exclusively to those SEON services, modules, features, or functionalities that are explicitly listed in the applicable Order Form executed between SEON and Customer. Any products or services not listed therein shall be deemed “Off-Contract Products.”

(b) Access and Consumption. Customer acknowledges that the Cloud Services may permit technical access to Off-Contract Products. The provision of such access shall not constitute a waiver of SEON’s rights to invoice for usage of those Off-Contract Products.

(c) Invoicing of Off-Contract Products. Notwithstanding anything contained in this Agreement or any Order Form, SEON shall have the right to invoice Customer for any use of Off-Contract Products at the then-current list price applicable at the time of consumption, unless otherwise agreed in writing by the parties. Failure by SEON to detect or immediately invoice for the use of any Off-Contract Product shall not constitute a waiver of its right to do so, provided that SEON invoices for such use no later than the next invoicing cycle following the invoicing cycle in which the use occurred. SEON waives its right to invoice for any use of an Off-Contract Product not invoiced within that period. Customer’s initiation or use of any Off-Contract Product, including via the Admin Panel or other means, constitutes Customer’s acceptance of the fees and terms applicable to such Off-Contract Products, as specified in the Admin Panel or otherwise provided by SEON. SEON may rely on system logs, access data, and consumption records to determine the scope of usage and related billing obligations.

(d) Unintentional Use. Notwithstanding the foregoing, if Customer promptly notifies SEON that its use of an Off-Contract Product was unintentional and ceases such use promptly after becoming aware of it, Customer will not be liable for fees arising from that use. This exception does not apply to any continued use of the Off-Contract Product after Customer becomes aware of it.

3.4 Fees and Payment.

(a) Unless the applicable Order Form provides otherwise, SEON invoices fees in advance. All fees payable are due within 30 days from the invoice date unless otherwise specified in the applicable Order Form. Any amounts not paid by the due date will accrue interest at the rate of one and one-half percent (1.5%) per month or the maximum amount permitted by law, whichever is lower.

(b) The fees and term of use for additional Users, modules, features or other items procured during an existing subscription term will co-terminate with, and be prorated through, the end date of the then-current subscription term for the applicable Cloud Services, unless otherwise agreed in the applicable Order Form.

(c) Where Customer subscribes to the Cloud Services via AWS Marketplace, invoicing will be handled by AWS Marketplace directly as the invoicing entity. The Customer hereby acknowledges and agrees that payments for services rendered under the applicable Order Form or this Agreement will be processed through and managed by the designated payment system of AWS Marketplace in accordance with their prescribed procedures, with this section 3.4 and with any quotation set out in the applicable Order Form.

3.5 Contractual Commitments

(a) Customer acknowledges that SEON’s pricing reflects, among other things, the costs SEON incurs in acquiring customers and in dedicating resources and personnel to implementing, making available, and supporting the Services, and is set so that SEON recovers the full value of Customer’s minimum contractual commitments over the Term.

(b) Any delay or failure to configure, deploy, or use the Services that is not attributable to SEON does not entitle Customer to withhold, defer, reduce, or offset any fees or to modify its contractual commitments.

(c) SEON may, in its sole discretion, consider a request to revise Customer’s contractual commitments only where: (i) Customer is current on all fees then owed; (ii) circumstances beyond Customer’s reasonable control and not reasonably foreseeable (excluding, for clarity, revenue or profitability shortfalls) have materially changed Customer’s ability to use or pay for the Services; and (iii) the proposed modification still allows SEON to realize the full anticipated value of the original agreement. Nothing in this Section requires SEON to agree to any modification.

3.6 Taxes. SEON fees do not include any local, state, federal or foreign taxes, levies or duties of any nature, including value-added, sales use or withholding taxes (“Taxes”). Customer is responsible for paying all Taxes, excluding taxes based on SEON’s net income. If SEON has the legal obligation to pay or collect Taxes for which Customer is responsible under this Section, the appropriate amount shall be invoiced to and paid by Customer unless Customer provides SEON with a valid tax exemption certificate authorized by the appropriate taxing authority.

4. Term and Termination

4.1 Term. The term of this Agreement shall commence on the Effective Date and shall continue for the length of time referenced in all Order Forms for the Services (the “Term”). The initial subscription term of the Services procured by Customer shall continue for the term applicable to such Services specified in the applicable Order Form. If Customer has not entered into an Order Form with SEON regarding renewal of the Services prior to the expiration of the initial term or then-current renewal term of such Services, then the subscription term for such Services shall be automatically renewed for an additional term of equal length to the Term unless either party provides written notice of non-renewal to the other at least sixty (60) days before the expiration of the applicable Term. Upon each automatic renewal, the fees for the renewed Services increase by five percent (5%) over the fees payable during the immediately preceding Term, unless otherwise agreed in the applicable Order Form. For the avoidance of doubt, neither party is obligated to renew, and either party may prevent automatic renewal by giving the notice described above.

Where Customer procures the Cloud Services through AWS Marketplace, renewal of the subscription will be handled through AWS Marketplace rather than as set out above. The subscription will automatically renew for a term equal to the then-current term, at fees five percent (5%) higher than the fees payable during the immediately preceding term, unless Customer opts out of renewal through AWS Marketplace at least sixty (60) days before the end of the then-current term. The applicable renewal schedule and uplift will be set out in the AWS Marketplace private offer accepted by Customer.

4.2 Suspension for Delinquent Account. If any invoice remains unpaid more than thirty (30) days after its due date, SEON may suspend Customer’s access to and/or use of the Services, without any notice other than the invoice-related notices already provided. SEON will not suspend the Services based on non-payment of amounts that Customer is disputing in good faith, provided that Customer: (a) notifies SEON of the disputed amount and the basis for the dispute on or before the due date, (b) pays all undisputed amounts when due, and (c) reasonably cooperates with SEON to resolve the dispute. SEON will restore access promptly after Customer pays all invoiced amounts then due (other than amounts disputed in good faith in accordance with this Section). Suspension does not relieve Customer of its payment obligations, and SEON shall not be liable to Customer or any third party for any direct or indirect consequences of any suspension made in accordance with this Section.

4.3 Suspension for Ongoing Harm. SEON may suspend Customer’s or User’s access to, or use of, the Services, if SEON reasonably determines, in good faith and based on objective evidence, that (a) there is a significant threat to the functionality, security, integrity, or availability of the Services or any content, data, or applications in the Services; (b) Customer or Users are accessing or using the Services to commit an illegal act; or (c) there is a violation of the Acceptable Use Policy. When reasonably practicable and lawfully permitted, SEON will provide Customer with advance notice of any such suspension. SEON will use reasonable efforts to re-establish the Services promptly after SEON determines that the issue causing the suspension has been resolved. During any suspension period, SEON will make Customer Data (as it existed on the suspension date) available to Customer. Any suspension under this section shall not excuse Customer from Customer’s obligation to make payments under this Agreement.

4.4 Suspension and Termination for Legal and Reputational Reasons. SEON reserves the right to temporarily suspend Customer’s access to the Services and/or terminate this Agreement with immediate effect and without any liability, in each case where SEON, acting in good faith and based on objective evidence to the extent practicable, determines that: (a) Legal and Regulatory Breach: the Customer (including any of its Affiliates, as well as any director, officer, agent, or employee of the Customer or any of its Affiliates) is in breach of any applicable laws and regulations or is subject to any local or international sanctions (including, but not limited to, those administered or enforced by the U.S. government or the U.S. Department of State, the United Nations Security Council, the European Union, His Majesty’s Treasury, or any other relevant sanctions authority) or restrictions; (b) the Customer is infringing upon the intellectual property rights of SEON, its Affiliates, or its licensors; or (c) the Customer’s activities or the provision of the Services to the Customer may be detrimental to the interests or business reputation of SEON, its Affiliates, or its licensors. If SEON terminates this Agreement under clause (c), SEON will nonetheless refund to Customer any fees prepaid for the terminated Services that are allocable to the period after the effective date of termination.

4.5 Termination for Cause. If either Customer or SEON breaches a material term of this Agreement or any Order Form and fails to correct the breach within 30 days of written specification of the breach, then the breaching party is in default and the non-breaching party may terminate (a) in the case of breach of any Order Form, the Order Form under which the breach occurred; or (b) in the case of breach of the Agreement, the Agreement and all Order Forms that have been placed under the Agreement. If SEON terminates any orders as specified in the preceding sentence, Customer must pay within 30 days all amounts that have accrued prior to such termination, as well as sums remaining unpaid for the Services under such Order Forms plus related taxes and expenses. If Customer terminates this Agreement or any Order Form as a result of SEON’s uncured material breach, SEON will refund to Customer any fees prepaid for the terminated Services that are allocable to the period after the effective date of termination. Except for nonpayment of fees, the non-breaching party may agree in its sole discretion to extend the 30-day period for so long as the breaching party continues reasonable efforts to cure the breach. Customer agrees that if it is in default under this Agreement, Customer may not use those Services ordered.

4.6 Termination for Insolvency. Either party may terminate this Agreement immediately upon written notice if the other party becomes insolvent, is unable to pay its debts as they fall due, makes a general assignment for the benefit of creditors, or becomes the subject of any bankruptcy, insolvency, receivership, administration, liquidation, or similar proceeding that is not dismissed within sixty (60) days.

4.7 Effect of Termination. Upon expiration or termination of this Agreement or an applicable Order Form: (a) Customer’s rights to access and use the affected Services will immediately cease and Customer must stop using them; (b) all amounts accrued or payable by Customer up to the effective date of termination will become immediately due; (c) each party will, at the other party’s request, return or destroy the other party’s Confidential Information in its possession or control, subject to applicable legal retention requirements; (d) for at least thirty (30) days following the effective date of termination or expiration, SEON will make Customer Data available for Customer to retrieve and export, after which SEON will return or delete Customer Data in accordance with the DPA; and (e) any provision that by its nature should survive termination, including provisions governing accrued fees, proprietary rights, confidentiality, warranty disclaimers, limitation of liability, indemnification, and governing law and dispute resolution, will survive.

5. Customer Obligations and Acceptable Use

5.1 General Restrictions

(a) Customer will comply with the Acceptable Use Policy. In response to any violation, SEON may take remedial action it considers necessary, including removing or disabling access to offending material, in addition to its other rights under this Agreement or the applicable Order Form.

(b) Customer may not, and may not cause or permit others to: (i) use the Cloud Services to violate the rights of any person (including privacy or intellectual property rights), to transmit unlawful, infringing, or malicious material, or otherwise in violation of applicable laws or regulations; (ii) perform or disclose any benchmarking, availability or performance testing of the Cloud Services; or (iii) perform or disclose any vulnerability or penetration testing of the Cloud Services, including network discovery, port and service identification, vulnerability scanning, password cracking, or remote access testing, in each case without SEON’s prior written approval.

(c) Customer may not, and may not cause or permit others to: (i) modify, make derivative works of, disassemble, decompile, reverse engineer, reproduce, republish, download, or copy any part of the Services (including any data structures or similar materials produced by the Services); (ii) access or use the Services to build or support, directly or indirectly, any product or service competitive with SEON; or (iii) license, sell, transfer, assign, distribute, outsource, permit timesharing or service bureau use of, commercially exploit, or make the Services available to any third party except as permitted by this Agreement or the applicable Order Form.

(d) Customer will use the Cloud Services and their outputs only as a tool to support its own decision-making, within decision processes that operate under Customer’s human oversight. Customer is solely responsible for designing, configuring, and supervising those processes (including any rules or thresholds Customer configures in the Services), for decisions made using the Services, and for complying with applicable laws governing such decisions and its use of AI-enabled tools, including laws on automated decision-making and artificial intelligence, such as Article 22 of the GDPR and UK GDPR, the EU Artificial Intelligence Act (Regulation (EU) 2024/1689), and any equivalent laws in other jurisdictions where Customer operates or affected individuals are located. SEON has no liability for decisions Customer makes on the basis of outputs from the Services.

5.2 Users, Passwords, Access and Notification. Customer will assign unique usernames and passwords to the number of Users procured on the applicable Order Form. User logins are for a single designated User and may not be shared, but may be permanently reassigned to another User as needed. Customer is responsible for maintaining the confidentiality of its Users’ passwords, tokens, credentials, and usernames, and for all activity and electronic communications made under Customer’s account, including any business, account, financial, or other information entered through the Cloud Services. SEON may treat any electronic communication made under Customer’s credentials or account as having been sent by Customer. Customer will use commercially reasonable efforts to prevent unauthorized access to or use of the Cloud Services, and will promptly notify SEON of any unauthorized access or use, or any loss, theft, or unauthorized use of any credentials or account.

5.3 AI Tools. Customer may connect AI agents, assistants, and other automated tools provided by a party other than SEON (“AI Tools”) to the Cloud Services through the APIs, SEON’s MCP connector, or other means SEON makes available, subject to this Agreement, the Acceptable Use Policy, and the User Guides (including any rate or usage limits). Any request submitted through an AI Tool using credentials, API keys, or tokens issued to or created by Customer or a User is treated as made by that User on Customer’s behalf and as Customer’s instruction to SEON. Those requests are use of the Services under the applicable Order Form (including for purposes of Section 3.3), and fees arising from them are payable by Customer.

6. Proprietary Rights

6.1 SEON Intellectual Property Rights.

(a) All rights, title and interest in and to the Services (including without limitation all intellectual property rights therein and all modifications, extensions, customizations, scripts or other derivative works of the Services provided or developed by SEON) and anything developed or delivered by or on behalf of SEON under this Agreement are owned exclusively by SEON or its licensors. Except as provided in this Agreement, the rights granted to Customer do not convey any rights in the Services, express or implied, or ownership in the Services or any intellectual property rights thereto.

(b) Customer grants SEON a royalty free, worldwide, perpetual, irrevocable, transferable right to use, modify, distribute and incorporate into the Services (without attribution of any kind) any suggestions, enhancement requests, recommendations, proposals, correction or other feedback or information provided by Customer or any Users related to the operation or functionality of the Services. SEON will not distribute or license Customer’s feedback to any third party as a standalone product or in any manner that identifies Customer or discloses Customer’s Confidential Information.

(c) Any rights in the Services or SEON’s intellectual property not expressly granted herein by SEON are reserved by SEON. SEON service marks, logos and product and service names are marks of SEON (the “SEON Marks”). Customer agrees not to display or use the SEON Marks in any manner without SEON’s express prior written permission.

(d) The trademarks, logos and service marks of Third-Party Application providers (“Marks”) are the property of such third parties. Customer is not permitted to use these Marks without the prior written consent of such third parties which may own the Mark.

6.2 Ownership of Customer Data. As between SEON and Customer, all title and intellectual property rights in and to Customer Data are owned exclusively by Customer. Customer grants SEON the right to host, store, use, process, enrich, display, and transmit Customer Data to provide the Services in accordance with this Agreement, the DPA, and the applicable Order Form. SEON’s platform gives customers direct control over the retention and deletion of their data, and SEON will retain, return, and delete Customer Data in accordance with Customer’s instructions, subject to the DPA. Customer has sole responsibility for the accuracy, quality, integrity, legality, reliability, and appropriateness of Customer Data, and for obtaining all rights and consents required for SEON to process Customer Data and perform the Services, including such consents as are necessary in various jurisdictions where Customer is subject to regulation and for particular services, including but not limited to IDV and other biometric identification services.

6.3 Ownership of Service-related Data. “Service-related Data” means data that SEON derives or generates from the operation and use of the Services and from its processing of Customer Data, excluding Customer Data itself. As between the parties, SEON exclusively owns all Service-related Data, and to the extent any Service-related Data would otherwise vest in Customer, Customer assigns it to SEON. SEON’s processing of any personal data contained in Service-related Data is governed by the DPA.

6.4 SEON’s Use of Data

(a) SEON may use Customer Data and Service-related Data to provide, secure, and operate the Services and to continuously improve the operation and performance of its risk assessments, including to: (i) monitor, measure, and bill usage; (ii) detect, investigate, and prevent fraud, security threats, and other illicit or high-risk activity; (iii) develop, train, and test its fraud-detection, identity verification, and risk-assessment models; and (iv) produce aggregated and anonymized statistics, analyses, benchmarks, and research.

(b) When developing or improving cross-customer models or fraud intelligence, SEON uses Customer Data only in aggregated or anonymized form that does not identify Customer or any individual. SEON’s ability to derive and analyze signals across its customer base in aggregated and anonymized form is central to the fraud-prevention, KYC, and AML functionality that SEON provides to all of its customers.

(c) SEON does not use Customer Data or Service-related Data for its own benefit separate and apart from developing, operating, and improving the Services provided to SEON’s customers, and does not sell or otherwise make available any such data to any third party, except (i) to subprocessors designated and disclosed in the DPA, and (ii) to data sources and Integrations to the extent necessary to provide the Services, such as submitting identifiers to obtain enrichment, verification, or screening results, as described in the DPA and the User Guides.

(d) Unless the DPA provides otherwise, SEON processes personal data within Customer Data as Customer’s processor in accordance with the DPA, and any data SEON uses across its customer base or retains beyond its provision of the Services to Customer is aggregated or anonymized so that it does not identify, and cannot reasonably be used to re-identify, Customer or any individual. The DPA governs SEON’s processing of personal data and controls in the event of any conflict with this Section.

6.5 Artificial Intelligence and Machine Learning. The Services include artificial intelligence and machine-learning features that SEON uses to detect and prevent fraud and to support KYC and AML compliance. Customer-specific risk-assessment models are trained on the relevant Customer’s own data and operate solely within that Customer’s account, so that one customer’s data does not determine outcomes for another. SEON’s cross-customer base models and fraud-intelligence signals are built only from sanitized, aggregated, or anonymized data that does not identify Customer or any individual, and SEON does not use Customer Data to train any third-party artificial intelligence model. Additional information about these features, and the controls and opt-outs available to Customer, is set out in the User Guides and in SEON’s AI disclaimer available at seon.io/legal-and-security/ai-disclaimer.

7. Data Protection and Security

7.1 Data Protection

(a) Unless the DPA provides otherwise, SEON will act as a data processor, and will act on Customer instructions concerning the treatment of Customer Data residing in the Cloud Services environment, as specified in this Agreement, the DPA and the applicable Order Form.

(b) The DPA, which is available at https://seon.io/legal-and-security/legal/#h-data-processing-agreement or such other URL as specified by SEON, sets forth the detailed terms and conditions for the processing of Customer Data by SEON as a data processor and, unless executed by the parties, may be updated by SEON from time to time. By using the Cloud Services, Customer agrees to be bound by the terms of the DPA, and in the event of any conflict between the DPA and this Agreement, the DPA shall prevail with respect to data processing activities.

(c) Changes to the DPA by SEON will not result in a material reduction in the level of protection provided for Customer’s personal data during the term of the applicable Order Form. This Section 7.1(c) does not apply to a DPA executed by the parties, which may be amended only in a writing signed by both parties.

(d) Customer acknowledges that it is responsible for obtaining all necessary consents and permissions from data subjects and complying with applicable data protection laws and regulations with respect to the collection, use, processing, transfer, and disclosure of personal data, and for providing any notices required in relation to the use of the Cloud Services. This includes providing notices to, and obtaining any required consent from, Applicants and other end users for the collection of device, browser, and similar signals through SDKs or other client-side components of the Cloud Services. Failure to comply renders the Customer solely liable for any resulting breach of applicable data protection legislation.

(e) SEON hosts the Cloud Services and stores Customer Data on Amazon Web Services (AWS) infrastructure or on that of another cloud infrastructure provider that SEON engages as a subprocessor under the DPA. Customer may select the geographic region in which SEON processes and stores Customer Data from the processing locations (for example, AWS regions) SEON makes available for the applicable Cloud Services, as specified during implementation. SEON will process and store Customer Data in the selected region, provided that SEON and its subprocessors may access Customer Data from other locations solely as necessary to provide, secure, and support the Services and as described in the DPA. Any cross-border transfer of personal data is governed by the DPA.

7.2 Security. SEON maintains administrative, physical, and technical safeguards designed to protect the confidentiality, integrity, and availability of Customer Data, as further described in the DPA. SEON maintains an information-security program that is independently certified or audited against recognized standards, including ISO/IEC 27001 and ISO/IEC 27017, and has in place effective SOC 2 Type II controls. SEON acknowledges that certain Customers are financial entities or other regulated entities subject to sector-specific operational-resilience or cybersecurity requirements applicable to their information and communications technology service providers, such as Regulation (EU) 2022/2554 (DORA) and the New York Department of Financial Services Cybersecurity Regulation (23 NYCRR Part 500). SEON maintains ICT risk-management, operational-resilience, and incident-notification measures designed to support such Customers’ compliance with those requirements, and, where a Customer is subject to such a regime, the parties, upon Customer’s request, may enter into a supplementary addendum reflecting the specific provisions it requires.

7.3 Service Monitoring. SEON continuously monitors the Cloud Services to operate them, to help resolve Customer service requests, to detect and address threats to the functionality, security, integrity, and availability of the Cloud Services and any content, data, or applications in the Services, and to detect and address illegal acts or violations of the Acceptable Use Policy. SEON’s monitoring tools do not collect or store Customer Data residing in the Cloud Services except as needed for these purposes. SEON does not monitor, and is not responsible for, non-SEON software provided by Customer or its Users that is stored in, or run on or through, the Cloud Services. Information collected by SEON’s monitoring tools, excluding Customer Data, may also be used to manage SEON’s product and service portfolio, to address deficiencies in its offerings, and for license management.

7.4 Transmission of Data. Customer is responsible for obtaining and maintaining the network access and equipment necessary to use the Cloud Services. Customer consents to SEON’s transmission, processing, and storage of Customer Data as necessary to provide the Services. Customer acknowledges that data transmitted over the Internet and other networks not operated by SEON may be accessed by unauthorized parties, and, without limiting SEON’s obligations under the Security and Confidentiality Sections of this Agreement, SEON is not responsible for Customer Data that is lost, altered, intercepted, or delayed in transit across networks not owned or operated by SEON.

8. Confidentiality

8.1 Confidential Information. By virtue of this Agreement, the parties may disclose to each other information that is confidential (“Confidential Information”). Confidential Information includes, without limitation, the pricing and other terms of Customer’s Order Forms, Customer Data residing in the Cloud Services, and any other non-public information disclosed by a party (the “Disclosing Party”) to the other (the “Receiving Party”) that is identified as confidential or that a reasonable person would understand to be confidential given its nature or the circumstances of disclosure, whether or not marked as confidential.

8.2 Exclusions. A party’s Confidential Information shall not include information that: (a) is or becomes a part of the public domain through no act or omission of the other party; (b) was in the other party’s lawful possession prior to the disclosure and had not been obtained by the other party either directly or indirectly from the Disclosing Party; (c) is lawfully disclosed to the other party by a third party without restriction on the disclosure; (d) is independently developed by the other party; or (e) is approved for release in writing by the Disclosing Party.

8.3 Non-Disclosure. Each party will not disclose the other party’s Confidential Information except as permitted in this Section, and will use the other party’s Confidential Information only as necessary to exercise its rights and perform its obligations under this Agreement. SEON will protect the confidentiality of Customer Data residing in the Services in accordance with Section 7 (Data Protection and Security) and the DPA for as long as such Customer Data resides in the Services.

8.4 Permitted Disclosures. The parties agree that Confidential Information may be disclosed to its employees, agents, subcontractors, and professional advisors as needed to further the purpose of this Agreement to the extent that the Persons to whom such disclosure is made will be informed of the confidential nature of such information, instructed to keep such Information confidential and will have agreed in writing (or in the case of professional advisors are otherwise bound) to keep confidentiality no less restrictive than those contained herein. The Receiving Party will ensure that those persons: (a) use such Confidential Information only to exercise rights and fulfill obligations under this Agreement; and (b) keep such Confidential Information confidential. The Receiving Party shall remain liable for any act or omission by its employees and/or professional advisors. Either party may also disclose the terms of this Agreement and any Order Form to its actual or prospective investors, acquirers, lenders, and other financing sources, and to their professional advisors, in connection with a bona fide financing, merger, acquisition, or similar transaction, provided that such recipients are bound by confidentiality obligations no less protective than those contained in this Section. Additionally, where the Customer was referred to SEON by a third party (e.g., a referral partner of SEON), SEON shall be allowed to disclose the contents of this Agreement (including without limitation the price list and other pricing terms and conditions applicable between the Customer and SEON) to that third party to the extent necessary for SEON to fulfill its obligations under its respective commercial agreement with that third party.

8.5 Compelled Disclosure. The Receiving Party may also disclose Confidential Information when required by law after giving reasonable notice to the Disclosing Party (if permitted by applicable laws and regulations).

8.6 Return or Destruction. If so requested by the Disclosing Party at any time by written notice to the Receiving Party, the Receiving Party shall promptly: (a) destroy or return to the Disclosing Party all documents and materials (and any copies thereof) containing, reflecting, incorporating, or based on the Disclosing Party’s Confidential Information; (b) erase all Confidential Information from its own computer and communications systems, devices, and other means of electronic storage; (c) erase all Confidential Information stored in electronic form in systems and data storage services owned by third parties; and (d) certify in writing to the Disclosing Party that it has complied with the requirements of this clause 8.6. Notwithstanding the foregoing, the Receiving Party may retain copies of Confidential Information (i) created by routine automated back-up procedures and not readily accessible in the ordinary course of business, or (ii) required to be retained by applicable law, in each case subject to the confidentiality obligations of this Section for so long as retained. The retention, return, and deletion of Customer Data are governed by Section 6.2 and the DPA rather than this Section 8.6.

8.7 Injunctive Relief. Without affecting any other rights and remedies that the Disclosing Party may have, the Receiving Party hereby agrees that damages would not be an adequate remedy for any breach by the Receiving Party of the provisions of this Agreement, and that the Disclosing Party shall be entitled to remedies of injunction, specific performance, and other equitable relief for any threatened or actual breach of the provisions of this Agreement.

8.8 Survival. Notwithstanding anything to the contrary, the obligations in this Section 8 shall survive for three (3) years after this Agreement is terminated for any reason, except that Confidential Information that constitutes a trade secret shall remain protected for as long as it qualifies as a trade secret under applicable law.

9. Warranties, Disclaimers and Exclusive Remedies

9.1 Mutual Representations. Each party represents, warrants, and covenants that: (a) it is duly incorporated, organized, and validly existing under the applicable law; (b) it has the good and sufficient capacity, power, authority, and right to enter into, execute, and deliver this Agreement and perform its obligations thereunder; and (c) each Order Form is signed or accepted on its behalf by a duly authorized representative in accordance with its corporate documents and applicable laws.

9.2 SEON’s Warranties. SEON warrants that during the Term, SEON will perform (i) the Cloud Services using commercially reasonable care and skill in all material respects as described in any User Guides, (ii) any Support Services in a commercially reasonable manner; and (iii) any Professional Services in a professional manner consistent with industry standards (the warranties described by the foregoing clauses (i), (ii), and (iii), collectively, the “Services Warranty”). If the Services provided to Customer are not performed as warranted, Customer must promptly provide SEON with a written notice that describes the deficiency in the Services (including, as applicable, the record of notifying SEON of the initial deficiency in the Services).

9.3 Customer’s Warranties and Covenants. The Customer warrants, represents, and covenants that it will not: (a) use the Services to discriminate against any Applicant or in a manner that causes damage or injury to any person or property; (b) use the Services in a manner that could reasonably be expected to bring SEON into disrepute or otherwise harm its reputation; (c) act or omit to act in a way that interferes with or compromises the integrity or security of the Services; (d) make the Services available, or otherwise use the Services, in any jurisdiction where the Services are not permitted by applicable law; or (e) provide or use Customer Data that breaches any applicable law or infringes the rights of any third party, including intellectual property, privacy, or publicity rights.

9.4 Warranty Limitations. SEON does not warrant that the Services, including Professional Services, will be performed error-free or uninterrupted, that SEON will correct all Services errors, or that the Services will meet Customer’s requirements or expectations. SEON is not responsible for any issues related to the performance, operation, or security of the Services that arise from Customer Data or from Third-Party Applications or services provided by third parties. The Services are not intended to be used as the sole basis for any business decision, including any decision concerning an Applicant. SEON has no liability for any inaccuracy, incompleteness, or other error in the Services arising from data provided by Customer, an Applicant, or any third party, including where a Service is limited, suspended, or discontinued due to a deficiency or unavailability of data submitted by an external third-party source SEON engages to provide the relevant Service.

9.5 Exclusive Remedy. For any breach of the Services Warranty, Customer’s exclusive remedy and SEON’s entire liability shall be the correction of the deficient Services that caused the breach of warranty, or, if SEON cannot substantially correct the deficiency in a commercially reasonable manner, Customer may end the deficient Services and SEON will refund to Customer the fees for the terminated Services that Customer prepaid to SEON for the period following the effective date of termination.

9.6 Disclaimer of Implied Warranties. Except as expressly provided under Section 9.2 and to the extent not prohibited by law, these warranties are exclusive and there are no other express or implied warranties or conditions, including for software, hardware, systems, networks, or environments, or for merchantability, satisfactory quality, or fitness for a particular purpose.

9.7 Professional Services Disclaimer. The Customer acknowledges that any Professional Services are provided strictly on an advisory basis. SEON does not guarantee that the Professional Services will achieve any specific business results or that they will be error-free or uninterrupted. Where SEON, if requested by Customer, performs manual reviews and makes any decisions as part of its Professional Services, Customer remains solely responsible for the implementation and consequences of such decisions within its systems. SEON, to the extent permitted by applicable laws, disclaims any liability for any decisions made by the Customer, or by SEON on behalf of the Customer, based on SEON’s Professional Services, or any actions or omissions arising from Customer’s reliance on SEON’s recommendations or direct decision-making actions.

10. Limitation of Liability

10.1 Exclusion of Indirect Damages. In no event will either party or its Affiliates be liable for any indirect, consequential, incidental, special, punitive, or exemplary damages, or for any loss of revenue, profits, sales, data, data use, goodwill, or reputation, arising out of or related to this Agreement, however caused and under any theory of liability. This Section does not limit either party’s obligation to pay amounts properly due under this Agreement.

10.2 Liability Cap. Except as provided in Section 10.3, the aggregate liability of each party and its Affiliates arising out of or related to this Agreement or an Order Form, whether in contract, tort, or otherwise, will not exceed the total amounts paid or payable under the applicable Order Form for the Services giving rise to the liability during the twelve (12) months immediately preceding the event giving rise to the liability. The DPA governs the limitation of liability for the processing of personal data.

10.3 Exclusions from the Cap. Nothing in this Agreement limits or excludes either party’s liability for: (a) fraud or fraudulent misrepresentation; (b) death or personal injury caused by its negligence; (c) a party’s obligation to pay amounts properly due under this Agreement; (d) Customer’s obligations under Section 11.2 (Customer Indemnity); or (e) any liability that cannot be limited or excluded under applicable law.

11. Indemnification

11.1 Infringement Indemnity. If a third party makes a claim against either Customer or SEON (the “Recipient,” which may refer to Customer or SEON depending on which party received the Material) that any information, design, specification, instruction, software, service, data, hardware, or material (collectively, “Material”) furnished by the other party (the “Provider,” which may refer to Customer or SEON depending on which party provided the Material) and used by the Recipient infringes that third party’s intellectual property rights, the Provider will, at its sole cost and expense, defend the Recipient against the claim and indemnify the Recipient from the damages, liabilities, costs, and expenses awarded by a court to the third party or agreed in settlement by the Provider, subject to Section 11.3.

11.2 Customer Indemnity. Customer will, at its sole cost and expense, defend SEON and its Affiliates against any third-party claim arising from (a) Customer Data, including any claim that Customer Data, or SEON’s processing of it in accordance with this Agreement, infringes or misappropriates any intellectual property or other right, violates applicable law, or was provided without the rights, permissions, or consents required (including any consent required for biometric or similarly regulated data); (b) Customer’s use of the Services in violation of this Agreement or applicable law; or (c) Customer’s breach of Section 5 (Customer Obligations and Acceptable Use) or its warranties in Section 9.3; and will indemnify SEON and its Affiliates from the damages, liabilities, costs, and expenses awarded by a court to the third party or agreed in settlement by Customer, subject to Section 11.3.

11.3 Indemnification Procedure. The indemnified party must: (a) notify the indemnifying party in writing of the claim not later than 30 days after receiving notice of it (or sooner if required by applicable law); (b) give the indemnifying party sole control of the defense and settlement of the claim, provided that the indemnifying party will not settle any claim in a manner that imposes any liability or obligation on, or requires any admission by, the indemnified party without the indemnified party’s prior written consent, not to be unreasonably withheld; and (c) provide the information, authority, and assistance reasonably needed to defend or settle the claim. A party’s failure to comply with the foregoing relieves the indemnifying party of its obligations only to the extent it is prejudiced by the failure.

11.4 Mitigation. If the Provider believes, or it is determined, that any Material may infringe a third party’s intellectual property rights, the Provider may, at its option, (a) modify the Material to be non-infringing while substantially preserving its utility or functionality, (b) obtain a license permitting continued use, or, if neither alternative is commercially reasonable, (c) end the license for, and require the return of, the applicable Material and refund any unused, prepaid fees paid for that Material. If such return materially affects SEON’s ability to meet its obligations under the relevant Order Form, SEON may, on 30 days’ prior written notice, terminate the applicable Order Form. If the Material is third-party technology and the applicable third-party license does not permit SEON to terminate it, SEON may, on 30 days’ prior written notice, end the Services associated with that Material and refund any unused, prepaid fees for those Services.

11.5 Exclusions. The Provider will not indemnify the Recipient to the extent a claim arises from (a) the Recipient’s alteration of the Material or use of it outside the scope described in the Provider’s documentation or the User Guides; (b) the Recipient’s use of a superseded version of the Material where the claim could have been avoided by using the current version made available to the Recipient; or (c) any Material not furnished by the Provider. SEON will not indemnify Customer to the extent a claim is based on a Third-Party Application or any Material from a third-party portal or other external source accessible or made available to Customer within or by the Services (for example, a social media post from a third-party blog or forum, a third-party web page accessed via hyperlink, or marketing data from third-party data providers).

11.6 Limitation; Exclusive Remedy. Except for Customer’s obligations under Section 11.2 (Customer Indemnity), which are not subject to the cap in Section 10.2, each party’s liability under this Section 11 is subject to Section 10. Sections 11.1 and 11.3 through 11.5 state the parties’ sole and exclusive remedy for third-party claims of intellectual property infringement.

12. Non-Solicitation

12.1 Restriction. During the term of this Agreement and for 12 months following its termination or expiration, neither party will, without the other party’s prior written consent, directly or indirectly solicit for employment or engagement any employee or contractor of the other party who participated in the negotiation, management, or provision or receipt of the Services. This restriction does not prohibit (a) general solicitations not specifically directed at the other party’s personnel (including job postings and searches by recruiters not instructed to target them), or (b) hiring any person who responds to such a general solicitation or who approaches a party on their own initiative.

12.2 Reasonableness. The parties agree and acknowledge that this restriction is reasonable and necessary to protect the value of their respective legitimate business interests, including in their employment and contractor relationships, goodwill, confidential and proprietary information, and relationships with their respective customers. The parties further agree and acknowledge that this restriction does not impose any unreasonable burden on any particular employee or contractor and does not materially prevent any such person from seeking and obtaining employment or a contractual relationship in the market for persons with similar credentials and experience.

12.3 Injunctive Relief. Without limiting any other rights and remedies they may have, the parties agree that a breach of this restriction may cause irreparable harm for which monetary or liquidated damages would not be an adequate remedy for any breach of this restriction, and that an aggrieved party is entitled to seek an injunction or such other equitable relief as may be reasonable and necessary in the event of any threatened or actual breach of the restriction.

12.4 Reformation. In the event that this restriction or any portion thereof is deemed by any judicial or regulatory authority to violate applicable law, regulation, or public policy, the parties agree to modify the restriction as necessary to preserve its enforceability to the fullest extent practicable.

12.5 No Third-Party Rights. This restriction is not intended to amend or otherwise alter the terms of any agreement between either party and any of its employees or contractors, or create any third-party rights or beneficiary interests in this Agreement.

13. Governing Law and Dispute Resolution

13.1 Governing Law. This Agreement shall be governed by and construed in accordance with the laws of the region where the Customer has its registered seat, as specified below:

Registered Seat of Customer (Region)Governing LawSeat of ArbitrationLanguageNumber of arbitratorsApplicable rules
AMER (the United States, Canada, Mexico, Central America, the Caribbean and South America, except Brazil)The laws of the State of Delaware (US)Austin (TX)EnglishOne (1)International Arbitration Rules of the International Centre for Dispute Resolution (ICDR)
BrazilThe laws of the Federative Republic of BrazilSão PauloPortugueseOne (1)Arbitration Rules of the Center for Arbitration and Mediation of the Chamber of Commerce Brazil-Canada (CAM-CCBC)
APAC (Asia-Pacific)The laws of SingaporeSingaporeEnglishOne (1)Singapore International Arbitration Centre (SIAC Rules)
Europe (except the United Kingdom)The laws of AustriaViennaEnglishOne (1)Rules of Arbitration and Mediation of the Vienna International Arbitral Centre (VIAC) of the Austrian Federal Economic Chamber (Vienna Rules)
United KingdomThe laws of England and WalesLondonEnglishOne (1)London Court of International Arbitration Rules
META (Middle East, Turkey and Africa)The laws of England and WalesDubai, United Arab EmiratesEnglishOne (1)Arbitration Rules of the Dubai International Arbitration Centre (DIAC Arbitration Rules 2022)

13.2 Arbitration Rules. Any dispute, controversy, or claim arising out of or relating to this Agreement, its interpretation, performance, breach, termination, or validity, shall be resolved under the applicable arbitration rules specified above.

13.3 Interim and Injunctive Relief. Notwithstanding the arbitration provisions of this Section, either party may seek interim, provisional, or injunctive relief from any court of competent jurisdiction to protect its intellectual property, Confidential Information, or other rights pending resolution of the dispute in arbitration, and such application will not constitute a waiver of the agreement to arbitrate.

13.4 Collection of Fees. Notwithstanding the arbitration provisions of this Section and any restriction on assignment in this Agreement, SEON may, at its option, either commence arbitration or bring an action in any court of competent jurisdiction to collect fees that are due and not disputed in good faith. SEON may engage third-party collection agencies and other providers to collect such amounts and, for that purpose, may disclose to them, and refer or assign to them the right to collect, the information reasonably necessary to do so, including Customer’s identity and contact details, the applicable invoices, and the amounts due. Customer will reimburse SEON for the reasonable costs of collecting undisputed overdue amounts, including collection agency fees and reasonable attorneys’ fees. SEON’s processing of any personal data in connection with such collection is governed by the DPA and applicable law.

13.5 Confidentiality. Except as required by law, the existence, content, and results of any arbitration conducted pursuant to this Agreement shall be kept confidential by all parties involved, and no party or its representatives shall disclose any information related to the arbitration without the prior written consent of all parties.

13.6 Final and Binding. The arbitration award shall be final and binding on both parties, and judgment upon the award rendered by the arbitrator(s) may be entered in any court having jurisdiction thereof.

13.7 Severability. If any provision of this Governing Law and Dispute Resolution section is found to be invalid or unenforceable, such provision shall be severed from the Agreement, and the remainder of this Agreement shall remain in full force and effect.

14. Chargeback Management

14.1 Third-Party Services Related to Chargeback Management. This section applies only where Customer has subscribed to SEON’s Chargeback Management services. As part of the chargeback management services provided through SEON’s Services, SEON utilizes third-party services from ChargeFlow. Customer’s use of these services is subject to ChargeFlow’s Privacy Notice and Terms, which are incorporated by reference and form a condition of Customer’s use of SEON’s services.

By using SEON’s chargeback management services, Customer acknowledges and agrees to comply with ChargeFlow’s Privacy Notice and Terms, available at:

• Privacy Notice: https://www.chargeflow.io/terms-of-service#privacy

• Terms of Service: https://www.chargeflow.io/terms-of-service

SEON is not responsible for the content, accuracy, or updates of ChargeFlow’s Privacy Notice or Terms. It is Customer’s sole responsibility to review and understand these policies. Any questions or concerns about the ChargeFlow’s policies should be directed to ChargeFlow. ChargeFlow may update its Privacy Notice or Terms from time to time, which Customer acknowledges. SEON disclaims any liability arising from ChargeFlow’s terms or practices.

14.2 Provision of Accurate and Timely Information. The Customer agrees to provide accurate, complete, and timely information, documentation, and access to transaction data necessary for the performance of chargeback management services, where subscribed to by Customer, including but not limited to transaction details, customer communications, and supporting evidence for disputes.

14.3 Compliance with Applicable Rules. The Customer shall ensure compliance with all applicable rules, regulations, and terms, including but not limited to (a) Card Network Rules (e.g., Visa, Mastercard regulations); (b) Payment Processor Terms and Conditions as required for chargeback dispute processes; and (c) any relevant local, national, or international laws and regulatory obligations governing the Customer’s business operations or payment processing activities.

14.4 Failure to Provide Information. The Customer acknowledges that any delay, inaccuracy, or failure to provide the required information or comply with applicable rules may adversely impact the performance of the chargeback management services (where applicable), and SEON shall not be held liable for any resulting losses, penalties, or unfavorable dispute outcomes.

14.5 Indemnification. The Customer Indemnity in Section 11.2 applies to any third-party claim arising from Customer’s non-compliance with its obligations under this Section 14, including non-compliance with card network rules or regulatory requirements, and is subject to Section 11.3.

15. Marketing Cooperation

15.1 Marketing Cooperation. During the Term, Customer will reasonably cooperate with SEON in marketing, public relations, and promotional activities relating to Customer’s use of the Services. Customer grants SEON a non-exclusive, worldwide, royalty-free license to use Customer’s name, logo, and trademarks (“Customer Marks”) to identify Customer as a SEON customer in SEON’s website, customer lists, and similar marketing and promotional materials, provided that such use complies with any brand guidelines Customer makes available to SEON. Customer may revoke this license or request that SEON cease a particular use on reasonable notice, and SEON will comply within a commercially reasonable period. Marketing activities that are more prominent or significant than identifying Customer as a SEON customer, including those described below, are subject to Customer’s review and approval, not to be unreasonably withheld or delayed.

15.2 Example Marketing Activities. From time to time, SEON may propose, and Customer agrees to consider in good faith, marketing activities relating to Customer’s use of the Services. Each such activity is subject to Customer’s prior review and written approval, not to be unreasonably withheld or delayed. Examples of activities the parties may pursue include: (a) a partnership announcement or press release, including a Customer quote; (b) a joint webinar, panel discussion, or other speaking engagement; (c) a case study or success story; (d) video testimonials; and (e) participation in reference calls with prospective customers, investors, industry analysts, or media.

15.3 Marketing Materials. In developing, planning, or distributing any such materials, the parties will work together in good faith so that published materials accurately reflect Customer’s experience with the Services and align with Customer’s preferences regarding confidentiality and publicity. Customer may request reasonable modifications to, or removal of, any marketing materials referencing Customer that become outdated, inaccurate, or inconsistent with Customer’s branding or corporate policies, and SEON will make commercially reasonable efforts to comply in a timely manner.

16. General Provisions

16.1 Notice. All notices under this Agreement shall be given in writing by email and are effective upon delivery. Notices to SEON shall be sent to [email protected], and notices to Customer to the notice email address specified in the applicable Order Form or, if none is specified, the business contact email address specified in Customer’s most recent Order Form. Each party shall promptly acknowledge receipt of any notice sent by email.

16.2 Export Compliance. Customer acknowledges that the Services are designed with capabilities for the Customer and Customer Users to access the Services without regard to geographic location and to transfer or otherwise move Customer Data between the Services and other locations such as User workstations. Customer is solely responsible for the authorization and management of User accounts across geographic locations, as well as export control and geographic transfer of Customer Data.

16.3 Entire Agreement

(a) This Agreement incorporates by reference all terms referenced by URL in this Agreement (as applicable), Exhibits and Order Forms, and this Agreement, together with such referenced items, constitute the entire understanding between the Customer and SEON and are intended to be the final and entire expression of their agreement. The parties expressly disclaim any reliance on any and all prior discussions, emails, RFPs and/or agreements between the parties. There are no other verbal agreements, representations, warranties, undertakings or other agreements between the parties.

(b) Under no circumstances will the terms, conditions or provisions of any purchase order, invoice or other administrative document issued by Customer in connection to this Agreement be deemed to modify, alter or expand the rights, duties or obligations of the parties under, or otherwise modify, this Agreement, regardless of any failure of SEON to object to such terms, provisions, or conditions. In the event of any inconsistencies between the terms of an Order Form and the Agreement, the Order Form shall take precedence; however, unless expressly stated otherwise in an Order Form, the terms of the DPA shall take precedence over any inconsistent terms in an Order Form.

16.4 Other General Provisions

(a) This Agreement will inure to the benefit of and bind the parties and their successors and permitted assigns. Neither party may assign this Agreement without the other party’s written consent, except that either party may assign this Agreement, without consent, to an Affiliate or to a successor of all or substantially all of its business or assets to which this Agreement relates. There are no third-party beneficiaries to this Agreement.

(b) This Agreement does not create any joint venture, partnership, agency, or employment relationship between the parties.

(c) If any provision is held by a court of competent jurisdiction to be contrary to law, such provision shall be eliminated or limited to the minimum extent necessary so that this Agreement shall otherwise remain in full force and effect. A waiver of any breach under this Agreement shall not constitute a waiver of any other breach or future breach.

(d) Electronic signature. The parties agree that electronic signature (verified using the DocuSign electronic signature platform or other similar electronic signature platform) by the authorized representative of each party, will be valid and will fully reflect the consent of that party to each Order Form and to this Agreement.

(e) Force Majeure. Neither party shall be liable for loss, delay, nonperformance (including failure to meet the service level commitment but excluding payment obligations) to the extent resulting from any force majeure event, including, but not limited to, acts of God, strike, riot, fire, explosion, flood, earthquake, natural disaster, terrorism, act of war, civil unrest, criminal acts of third parties, failure of the internet, governmental acts or orders or restrictions, failure of suppliers, labor stoppage or dispute (other than those involving SEON employees), or shortage of materials, provided that such party uses reasonable efforts, under the circumstances, to notify the other party of the circumstances causing the delay and to resume performance as soon as possible and any delivery date shall be extended accordingly. If a force majeure event continues for more than thirty (30) consecutive days, either party may terminate this Agreement upon written notice without liability. If either party terminates this Agreement under this Section, SEON will refund to Customer any fees prepaid for the terminated Services that are allocable to the period after the effective date of termination.

(f) Non-Impediment. Nothing in this Agreement shall be construed as precluding or limiting in any way the right of SEON to provide consulting, development, or other services of any kind to any individual or entity (including without limitation performing services or developing materials which are similar to and/or competitive with the Professional Services and/or deliverables hereunder).

Acceptable Use Policy

1.1. This Acceptable Use Policy forms part of the agreement between SEON and Customer under which Customer uses the Services, whether SEON’s Terms of Service or a signed subscription services agreement or other agreement (the “Agreement”). Capitalized terms not defined in this Acceptable Use Policy have the meanings given in the Agreement, and “Website” means seon.io and its subdomains. Any issues not regulated by this Acceptable Use Policy shall be governed by the provisions of the Agreement. In case of conflict between this Acceptable Use Policy and the Agreement, the Agreement prevails.

1.2. Customer must at all times use the Website and the Services in accordance with SEON’s acceptable use standards, including but not limited to:

1.2.1. Respecting the law. Customer may use the Website and the Services for lawful purposes only. Customer may not use the Website and the Services in any way that breaches any applicable local, national, or international laws, regulations, and codes. Customer may not use the Website and the Services in any way that is unlawful, fraudulent, or has any unlawful or fraudulent purpose or effect.

1.2.2. Respecting intellectual property. Customer may not attempt to copy, reproduce, duplicate, modify, create derivative works from or distribute all or any portion of the Website and the Services (including any functions, graphics, features, ideas). Customer may not modify the paper or digital copies of any materials of SEON or third parties the Customer has printed off or downloaded in any way, and Customer may not use any illustrations, photographs, video or audio sequences or any graphics separately from any accompanying text. Customer may not remove any ownership, authorship, or brand notices on the Website and the Services.

1.2.3. No competitors. Customer may not access all or any part of the Website and the Services in order to build a website, a product or service which competes with the Website and/or the Services. Customer is specifically not allowed to use the Website and the Services to create a competitor or facilitate the design of any or all of a competitor service. Competitors of SEON, and any individuals or entities acting on behalf or in the guise of any competitor of SEON, may only create an account with the prior written consent of SEON.

1.2.4. Services Security. Customer may not interfere with, damage or disrupt any part of the Website and the Services or any software used in the provision of the Website and the Services, or any equipment or network on which the Website or the Services are stored. Customer may not attempt to gain unauthorized access or assist third parties in obtaining unauthorized access to the Website and Services, the server on which the Website or the Services are stored or any server, computer or database connected to the Website and the Services. Customer may not defeat, avoid, bypass, remove, deactivate, or otherwise circumvent any software protection or monitoring mechanisms of the Website and the Services, the server on which the Website and the Services are stored or any server, computer or database connected to the Website and the Services. Customer must not attack the Website or the Services via brute-force attacks, a denial-of-service attack, or a distributed denial-of-service attack. Customer may not attempt to undertake any security testing of the Website and the Services without the prior written consent of SEON.

1.2.5. Account security. Customer must use strong passwords that are created and maintained in compliance with the applicable industry standards and SEON’s password policy. Customer expressly agrees that SEON may refuse the creation of an account if the chosen password does not fulfil SEON’s password policy requirements. Customer shall ensure that account login credentials are managed in accordance with industry-standard password management requirements.

1.2.6. No crypto-mining, or other malicious use of the Services. Customer may not attempt to use the Website and/or the Services (or any portion thereof) to undertake the mining of cryptocurrencies, or to perform any other resource intensive tasks not related to the purpose of the Services.

1.2.7. No reverse engineering. Outside the extent it is allowed by applicable laws, no one is allowed to reverse engineer, or attempt to reverse engineer, decompile, hack, disable, interfere with, disassemble, modify, copy, translate, or disrupt the features, functionality, integrity, or performance of the Website and the Services.

1.2.8. No Data Harvesting. No one is allowed to collect or harvest any personal data from the Website or the Services, except through Customer’s use of the Services as permitted by the Agreement.

1.2.9. No scraping. No one is allowed to access, search the Website and the Services by any means other than SEON’s publicly supported user interfaces (e.g. it is prohibited to access, search the Website and the Services via web scraping or web crawling). No one is allowed to access the Services through any technology or means other than as SEON may explicitly designate for this purpose.

1.2.10. No automated registration. Accounts registered via automated methods are prohibited except if expressly permitted and/or intentionally enabled by SEON.

1.2.11. No trial fraud. One Customer may not participate in more than one trial period. It is prohibited to apply for or use multiple or consecutive trial plans.

1.2.12. No spam. Customer may not use the Website and the Services to transmit, or procure the sending of, any unsolicited or unauthorised advertising or promotional material or any other form of similar solicitation.

1.2.13. No viruses. Customer may not use the Website and the Services to knowingly transmit or introduce any data, send or upload any material that contains viruses, Trojan horses, worms, time-bombs, keystroke loggers, spyware, adware or any other harmful programs, materials or similar computer code designed to adversely affect the operation of any computer software or hardware.

1.2.14. No commercial distribution. Customer may only use the Website and the Services for its internal business operations as permitted by the Agreement, unless otherwise authorized by SEON in writing. Except as permitted by the Agreement, Customer may not distribute any part of the Website or the Services, including but not limited to any data or content featured on the Website, in any medium without SEON’s prior written authorization.

1.2.15. Users and third parties. Customer may not authorize, permit, enable, induce or encourage any User or any third party to perform any activities regarding the Website and the Services that are in breach of this Acceptable Use Policy or the Agreement.

1.2.16. No consumers. Customer may not use the Website and the Services in a consumer capacity. The Website and the Services are intended for use solely by businesses.

1.2.17. Sanctions. Customer, and any individual or legal entity (including their Affiliates, and their executive officers, employees, owners and ultimate beneficial owners), that is subject to any local or international sanctions or restrictions, including those administered or enforced by the U.S. government or the U.S. Department of State, the United Nations Security Council, the European Union, His Majesty’s Treasury, or any other relevant sanctions authority, is expressly prohibited from accessing and using the Website and the Services.

1.2.18. Compliance with AI regulations.

The Customer acknowledges and agrees that certain Services provided by SEON may incorporate Artificial Intelligence (“AI”) functionalities. The Customer shall, at all times, use the Services in strict compliance with all applicable laws and regulations governing the use of AI, including but not limited to Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 March 2024 laying down harmonised rules on artificial intelligence (the “EU AI Act”), as amended or replaced from time to time.

In circumstances where the EU AI Act is applicable to the Customer’s use of the Services, whether directly or indirectly, and insofar as such use gives rise to obligations under the EU AI Act, the Customer represents, covenants and warrants that it will not use the Services in any manner that:

  1. results in the Customer being classified as a ‘provider’ or ‘deployer’ of a prohibited AI system under the EU AI Act;
  2. causes the Customer to use the Services in a way that would breach any obligations relating to high-risk AI systems, unless the Customer ensures full compliance with the EU AI Act requirements, including but not limited to data governance, transparency, human oversight, and conformity assessment obligations;
  3. circumvents, disables, or interferes with any safeguards, monitoring tools, or compliance features embedded in the Services;
  4. contributes to any unlawful or unethical use of AI technologies.

1.2.19. Social Security Number (SSN) Handling Limitation.

If the Services provided by SEON to the Customer include access to, or processing of, US Social Security Numbers (SSNs) or equivalent government-issued identifiers in the course of fraud prevention or identity verification checks, the following restrictions shall apply:

  1. Permitted Use. Customer may only access, use, and process such data strictly for the purposes of fraud prevention and identity verification, and solely within the scope of the Services provided by SEON.
  2. Restrictions. Customer shall not store, retain, cache, or transfer any SSN data except as strictly required under applicable law (e.g., AML, BSA, or equivalent compliance obligations), and only where such data is:
    • stored in encrypted form, and
    • not further transferred, sublicensed, or resold.
  3. Disclosure Limitations. Customer shall not disclose SSN data to its end users or any third party, except where a limited disclosure is strictly necessary (for example, confirming that the last four digits of an SSN matched), and only within a permissible fraud prevention or identity verification use case, in strict compliance with this Acceptable Use Policy and the Agreement.
  4. Legal Compliance. All handling of SSN data shall comply with applicable privacy, data protection, and information security laws and standards.

SUPPORT TERMS

Subject to your procurement of Support Services (as defined herein), these Support Services terms (the “Support Terms”) describe SEON’s provision of Support Services to you (“Customer”) pursuant to the terms of the Agreement and the terms hereof in accordance with the level of Support Services that you have procured or are otherwise entitled to. In case of conflict between these Support Terms and the Agreement, the Agreement prevails.

1. DEFINITIONS

“Agreement” means the applicable agreement(s) that provide you with access to Services, whether SEON’s Terms of Service or a signed subscription services agreement or other agreement.

“Alternative Solution” means a solution or correction to an incident that allows the Service to function substantially in accordance with the User Guides.

“Authorized Contacts” means the named Customer employees or authorized agents who: (i) have sufficient technical expertise, training and/or experience with the Service to perform the Customer’s obligations under these Support Terms; (ii) are responsible for all communications with SEON regarding these Support Terms, including case submission and Incident reports; and (iii) who are authorized by Customer to request and receive Support Services for the Service on behalf of the Customer.

“Basic Support” is SEON’s basic Support Services described herein, which is included in a current subscription to the Service.

“Business Days” are Monday to Friday during Normal Support Hours, excluding SEON company holidays.

“Enhancement Request” means a request by Customer to add functionality or enhance performance beyond the specifications of the Service and are not included as part of Support Services.

“Incident” means a single support question or reproducible failure of the Service to substantially conform to the functions and/or specifications as described in User Guides and reported by an Authorized Contact.

“Normal Support Hours” are defined as 02:00 UTC on Monday to 22:00 UTC on Friday, with the exception of public holidays.

“Premium Support” means SEON’s Premium Support Services, which provide 24/7 access to dedicated SEON resources and are a paid service in addition to SEON’s standard Support Services (Basic Support).

“Response Time” means the targeted time period within which SEON will use commercially reasonable efforts to contact Customer to acknowledge receipt of an Incident report and to engage an appropriately skilled support resource, commencing from the time that SEON receives all required information as specified in Section 4.2. Response Times are measured during Normal Support Hours.

“Service” means the Cloud Services (as defined in the Agreement) to which Customer subscribes.

“Severity” means the Severity Levels 1-3 as defined below:

“Severity 1 or S1 (Critical)” means an Incident where Customer’s production use of the Service is stopped or so severely impacted that the Customer cannot reasonably continue business operations through the use of the Service. It may result in a material and immediate interruption of Customer’s business operations that may cause a loss of data and/or restrict availability to such data and/or cause significant financial impact.

“Severity 2 or S2 (Less Critical)” means an Incident where one or more important functions of the Service are unavailable with no acceptable Alternative Solution. Customer’s implementation or production use of the Service is continuing but not stopped; however, there is a serious impact on the Customer’s business operations.

“Severity 3 or S3 (Minimal)” means an Incident that has a minimal impact on business use or basic functionality of the Service, or an Incident where Service features are unavailable, but an Alternative Solution is available.

“Support Services” means the support services for the Service provided by SEON under the terms set forth herein and as further defined in the Agreement, but do not include Enhancement Requests. Support Service levels include Basic and Premium. Customer’s level of Support Services shall be determined by the level of Support Services that such Customer has procured or is otherwise entitled to. Support Services are provided in the English language. Support Services may be provided in other languages, when available at SEON’s sole discretion.

“Test Case” means Customer’s instructions that allow SEON to reproduce an Incident.

2. SCOPE OF THE SUPPORT TERMS

2.1. Subject to the terms contained herein, SEON shall address all Incidents which may arise from Customer’s use of the Service in accordance with Sections 4 and 5 below.

2.2. SEON shall not have any obligation to provide Support Services with respect to any adaptations, configurations or modifications of the Service made by the Customer or any third party.

2.3. SEON may offer Professional Services to help resolve issues that fall outside the scope of the Support Services. Professional Services are ordered under an Order Form and are provided under the Agreement and SEON’s Professional Services Agreement.

3. TERMINATION

3.1. Notwithstanding anything to the contrary herein or in the applicable Agreement, these Support Terms shall terminate upon the expiration or termination of the Agreement or expiration or termination of Customer’s right to access the applicable Service.

4. INCIDENT REPORTING & RESPONSE TIMES

4.1. Authorized Contacts. All reports of Incidents must be made to SEON by the Authorized Contact(s). The primary method for a Customer to report an Incident is via admin.seon.io/support. The foregoing notwithstanding, Customer may notify SEON of S1 and S2 Incidents via email at [email protected] if Customer’s access to admin.seon.io/support is unavailable. The Customer may substitute Authorized Contact(s) from time to time by giving SEON prior written notice, including the relevant contact information for any new Authorized Contact.

4.2. Required Information. All Incident reports must, if applicable, include the following: a) The Customer’s identification number or business name b) A reproducible Test Case that demonstrates the specific usage that causes the Incident being reported. c) Exact wording of all related error messages. d) A full description of the Incident and expected results. e) Any special circumstances surrounding the discovery of the Incident. f) For S1 Incidents, please provide an additional point of contact.

4.3. Severity Levels. SEON will work with Customer and will assign the appropriate severity level to all Incidents according to the Severity Level definitions. Severity Levels are assigned to allow prioritization of incoming Incidents. SEON may reclassify Incidents based on the current impact on the Service and business operations as described in the Severity Level definitions. In the event SEON determines that an Incident is in fact an Enhancement Request, it shall not be addressed under these Support Terms.

4.4. SEON’s Obligations. SEON will make available Support Services access during Normal Support Hours for the Customer to report Incidents and receive assistance. On receipt of an Incident report, SEON shall establish whether there is an Incident for which the Customer is entitled to Support Services under these Support Terms and, if so, shall: a) Confirm receipt of the Incident report and notify Customer of the Incident case number that both parties must then use in any communications about the Incident. b) Work with Customer to set a severity level for the Incident based on the criteria set forth herein. c) Analyze the Incident and verify the existence of the problem. d) Give the Customer direction and assistance in resolving the Incident pursuant to the terms described herein.

4.5. Response Time Goals.

Severity LevelResponse Time Goals
Severity 11 Hour
Severity 2Same Business Day
Severity 3Next Business Day

4.6. Customer’s Obligations. SEON’s obligation to provide Support Services under these Support Terms is conditioned upon the Customer: (a) paying all applicable fees for Support Services prior to the date the Incident is reported; (b) having valid access to the Service; (c) providing SEON with all reasonable assistance and providing SEON with data, information and materials that are reasonably necessary; (d) procuring, installing and maintaining all equipment, telephone lines, communication interfaces and other hardware and software necessary to access the Service; (e) providing appropriate contact information for all Authorized Contact(s); (f) utilizing the admin.seon.io/support incident reporting portal to log all incident cases.

5. EXCLUSIONS FROM SUPPORT SERVICES

5.1. SEON will not be required to correct any Incident caused by (i) integration of any feature, program or device to the Service or any part thereof; (ii) any non-conformance caused by unauthorized misuse, alteration, modification or enhancement of the Service; or (iii) use of the Service that is not in compliance with the Agreement.

SERVICE LEVEL COMMITMENT

This Service Level Commitment forms part of the agreement between SEON and Customer under which Customer uses the Cloud Services, whether SEON’s Terms of Service or a signed subscription services agreement or other agreement (the “Agreement”), and applies to the Cloud Services. Capitalized terms not defined in this Service Level Commitment have the meanings given in the Agreement. In case of conflict between this Service Level Commitment and the Agreement, the Agreement prevails.

1. Web-based Services

SEON commits to provide 99.5% uptime for Web-based services with respect to the Cloud Services to which Customer subscribes during each calendar month of the Term, excluding regularly scheduled maintenance times. Web based services include all services that are available via a web user interface.

Downtime for web-based services means any period of time during which the web-based services are not accessible.

2. API-based Services

SEON commits to provide 99.9% uptime for API-based services with respect to the Cloud Services to which Customer subscribes during each calendar month of the Term, excluding regularly scheduled maintenance times. API-based services include all services that are available via an Application Programming Interface and documented in the SEON API reference documentation.

Downtime for API-based services means any period of time during which the API-based services are unable to answer any of the incoming API requests.

SEON determines the downtime of its Services by continuously checking the availability of its own Services from an independent, globally distributed infrastructure. Results are communicated real time on status.seon.io.

3. Credit Request

In order to receive a credit under this Service Level Commitment, Customer must request it via the standard support channels, within thirty (30) days of the availability event. If Customer submits a credit request and does not receive a prompt automated response indicating that the request was received, Customer must resubmit the request because the submission was not properly received and will not result in a credit.

Customers who are past due or in default with respect to any payment or any material contractual obligations to SEON are not eligible for any credit under this Service Level Commitment. The service credit will automatically be applied to the Customer’s next invoice or billing.

SEON shall calculate any service level downtime using SEON’s system logs and other records.

4. Downtime Credits

Service credits under this Service Level Commitment are Customer’s sole and exclusive remedy, and SEON’s entire liability, in connection with the availability of the Cloud Services. SEON will credit the Customer 5% of the fees for the affected Cloud Services attributable to the relevant month for each period of 60 or more cumulative minutes of downtime.

If in any calendar month SEON’s uptime commitment is not met by SEON and Customer was negatively impacted, SEON shall provide downtime credits, as the sole and exclusive remedy.

Credit shall not be cumulative beyond a total of credits for 20% of the fees for the affected Cloud Services attributable to that calendar month in any event.

5. Scheduled Maintenance

Scheduled maintenance time does not count as downtime. Maintenance time is regularly scheduled if it is communicated in accordance with Section 6 below at least 14 calendar days in advance of the maintenance time.

5.1. Exemptions

Uptime calculation shall exclude any period of time under which the Services are not available due to

a.) scheduled maintenance;

b.) maintenance requested by Customer;

c.) Customer’s failure to perform its obligations under the Agreement or any Order Form that directly impacts the performance of the Cloud Services;

d.) force majeure events as described in the Agreement;

e.) the disturbance in the performance of a third party outside of SEON’s control – provided that SEON supplies the Customer with any relevant evidence proving that the only cause of not meeting uptime commitments was the performance of third party and SEON made all reasonable efforts to avoid cascading failures (these third parties include but are not limited to Amazon Web Services, Social Media Platforms, Public Databases, Caller Name Delivery (CNAM), and Home Location Register (HLR));

f.) unforeseen capacity increases based on material changes in Customer’s business operations, processes or methodology that adversely impact the Services, provided SEON notifies Customer immediately of such adverse impact on the Services;

g.) misconfiguration of the Cloud Services by Customer; Any downtime resulting from the customization of the Cloud Services to meet specific Customer requirements shall not be considered in the downtime calculation. Customer understands that tailoring the Cloud Services to the Customer’s needs may require temporary suspension of certain functionalities, and such customization efforts shall not be penalized under this Service Level Commitment.

h.) termination, suspension of the Services or any blocking of the Services in accordance with the Agreement (including the Acceptable Use Policy) (e.g. for suspected account takeover of the Customer) unless such event occurred due to SEON’s negligence.

6. Updates/Notice

This Service Level Commitment may be amended by SEON at its discretion but only after providing thirty days advance notice. Notices will be sufficient if provided to a user designated as an administrator of your applicable account either: (a) as a note on the screen presented immediately after completion of the log in authentication credentials at the log in screen, or (b) by email to the registered email address provided for the administrator(s) for Customer’s account.

DATA PROCESSING AGREEMENT


This Data Processing Agreement (“DPA”) forms part of the agreement under which the SEON entity named in the applicable Order Form or online order (“SEON” or “Processor”) provides Services to its customer (“Customer” or “Controller”), including SEON’s Subscription Services Agreement or SEON’s online terms of service, together with the Order Forms entered into under it (the “Agreement”). This DPA sets out the terms on which SEON processes personal data in providing the Services.

1. Definitions

Capitalized terms used but not defined in this DPA (including Admin Panel, Affiliate, Applicant, Confidential Information, Customer Data, Order Form, Services, Third-Party Application, User Guides, and Users) have the meanings given in the Agreement, and any of them that the Agreement does not define has its ordinary meaning. If the Agreement does not define “Services,” the term means the services SEON provides to Customer under the Agreement or for an Evaluation. If the Agreement does not define “User Guides,” the term means SEON’s online user guides and technical documentation for the Services, currently available at https://docs.seon.io, as updated from time to time. In this DPA:

“Anonymized” means altered so that the data does not identify, and cannot reasonably be used to re-identify, Customer or any individual, taking into account all means reasonably likely to be used; “Anonymize” has a corresponding meaning. Anonymized data is not personal data or Customer Personal Data.

“Applicant Information” means Customer Personal Data relating to an Applicant, including any risk score or risk level, tags of approval, rejection, and resubmission, and related log information.

“Controller’s Email Address” means the email address of Customer’s Designated POC under Section 15.1 and any email address associated with an administrator-role User account for the Services or, if Customer has no such account, any email address SEON has on file for Customer. A notice sent to at least one of Controller’s Email Addresses is sufficient.

“Customer Personal Data” means personal data contained in Customer Data, or otherwise provided by or for Customer to SEON in connection with the Services or an Evaluation, that SEON processes on Customer’s behalf as processor under the Agreement or during an Evaluation.

“Data Protection Legislation” means all data protection and privacy laws applicable to the processing of Customer Personal Data under the Agreement, including, as applicable: (a) Regulation (EU) 2016/679 (the “GDPR”) and laws implementing or supplementing it; (b) the GDPR as it forms part of the law of the United Kingdom (the “UK GDPR”) and the UK Data Protection Act 2018; (c) the Swiss Federal Act on Data Protection; (d) the laws of the United States and its states relating to privacy, security, or data protection (“US Data Protection Legislation”); and (e) Brazil’s General Data Protection Law (Lei No. 13,709/2018) (“LGPD”) and the regulations and resolutions of Brazil’s National Data Protection Authority; in each case as amended or replaced.

“EEA” means the European Economic Area, consisting of the member states of the European Union (“EU Member States”) and Iceland, Liechtenstein, and Norway.

“Evaluation” means a batch test, proof of concept, pilot, sandbox, or similar period in which Customer tests or assesses the Services before entering into an agreement for them, whether or not fees are payable. A trial period or Beta Services under an agreement for the Services is not an Evaluation.

“Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data transmitted, stored, or otherwise processed by SEON or its Subprocessors.

“Subprocessor” means any processor, including an Affiliate of SEON, that Processor engages to process Customer Personal Data on Customer’s behalf.

The terms “controller,” “processor,” “data subject,” “personal data,” “processing,” and “supervisory authority” have the meanings given in the GDPR and include the equivalent terms under other Data Protection Legislation (such as “business,” “service provider,” and “personal information” under US Data Protection Legislation, and “controlador” and “operador” under the LGPD).

2. Scope and Application

2.1 Application. This DPA applies to SEON’s processing of Customer Personal Data in providing the Services, as described in Appendix 1. It forms part of the Agreement and applies where the parties sign it, where it is attached to or referenced in the Agreement or an Order Form, or where the Agreement incorporates it by reference, including by URL. SEON also processes Customer Data that is not personal data, and Service-related Data (as defined in the Agreement), in providing, securing, and improving the Services; that processing is governed by the Agreement. Matters not addressed in this DPA are governed by the Agreement.

2.2 Purpose. This DPA is intended to meet the requirements of Data Protection Legislation for a written contract between a controller and a processor, including Article 28 of the GDPR.

2.3 Appendices. The following Appendices form part of this DPA: Appendix 1 (Details of Processing); Appendix 2 (Subprocessors); and Appendix 3 (Consent and Privacy Notice Wording). The jurisdiction-specific Schedules that follow the Appendices also form part of this DPA: Schedule A (European Economic Area, United Kingdom, and Switzerland), Schedule B (United States), and Schedule C (Brazil). References to this DPA include its Appendices and Schedules.

2.4 Interpretation. References to Controller and Processor are to Customer and SEON in those capacities, and where Customer acts as a processor on behalf of a third-party controller (Section 3.2), references to Controller are to Customer in that capacity. Where SEON acts as an independent controller, this DPA refers to it as SEON. “Including” means including without limitation. Headings are for convenience only.

2.5 Evaluations. This DPA also applies where SEON processes Customer Personal Data for an Evaluation, which takes place under an agreement between the parties (such as the online terms, a non-disclosure agreement, or a proof-of-concept agreement) that is the Agreement for that Evaluation. An Evaluation ends at the end of the evaluation period agreed by the parties or, if earlier, when either party notifies the other in writing that it is ending the Evaluation. Customer is responsible under Section 11 for the data it submits for an Evaluation, including historical data. SEON will delete Customer Personal Data processed for an Evaluation as set out in Appendix 1, Section 5. If the parties enter into an agreement for the Services, this DPA continues to apply to the Services provided under it.

3. Roles of the Parties

3.1 Controller and Processor. For Customer Personal Data, Customer is the Controller and SEON is the Processor. Controller determines the purposes and means of the processing and remains responsible for complying with its obligations under Data Protection Legislation and for the instructions it gives Processor. Except as described in Sections 3.5 and 3.7, Processor will process Customer Personal Data only on Controller’s documented instructions, which consist of the Agreement, this DPA, Controller’s configuration and use of the Services (including the settings Controller selects in the Admin Panel), and any other written instructions that Processor acknowledges as instructions for the purposes of this DPA.

3.2 Customer as Processor. Where Customer acts as a processor on behalf of a third-party controller, SEON acts as a further processor engaged by Customer, and Customer warrants that its instructions to SEON, including its appointment of SEON and its authorization of the processing described in this DPA, have been authorized by that controller. Customer is SEON’s sole point of contact for that controller unless Data Protection Legislation requires otherwise.

3.3 Risk Scoring and Applicant Information. Where applicable, Processor stores Applicant Information tagged with the risk level Controller assigns. Controller, for its fraud-prevention purposes, instructs Processor to generate and assign risk scores and related insights to Applicant Information as part of the Services.

3.4 Service-related Data. To the extent data that Processor derives or generates from the operation and use of the Services and from its processing of Customer Data (“Service-related Data,” as further defined in the Agreement where applicable) contains personal data relating to Applicants or other data subjects, Processor processes that personal data as Customer Personal Data under this DPA, except as described in Sections 3.5 and 3.7.

3.5 Independent Controller Processing. To develop, improve, and secure the Services and to detect and prevent fraud and other illicit activity, SEON may process certain Customer Personal Data, alone or in combination with data from other sources (including data providers and other customers), as an independent controller. This may include using artificial intelligence and machine-learning techniques, identifying patterns indicative of fraud or other illicit activity, generating risk scores and alerts, and maintaining audit logs. SEON undertakes this processing only for purposes compatible with those for which Customer provided the Customer Personal Data, and relies on the legitimate interests of SEON, its customers, and third parties in preventing fraud and other illicit activity and in securing and improving the Services (and, where applicable, on compliance with its legal obligations) as the legal basis for it. Any data that SEON uses across its customers, or retains for its own purposes beyond providing the Services to Customer, is aggregated or Anonymized so that it does not identify, and cannot reasonably be used to re-identify, Customer or any individual, and SEON does not share Customer-identifiable personal data with, or use it for the benefit of, any other customer. SEON does not use Customer Personal Data to train any third-party artificial intelligence model. Customer authorizes the processing described in this Section 3.5, including profiling for these purposes.

3.6 Exclusion Where Required by Law. Where a law or regulation that governs Customer’s business (for example, banking-secrecy or equivalent obligations applicable to a regulated financial institution) requires Customer to restrict the processing described in Section 3.5, Customer may, by written notice to SEON, require SEON to exclude Customer Personal Data from that processing. SEON will implement the exclusion within a reasonable period after receiving the notice and will inform Customer of any resulting effect on the performance of the Services. SEON will continue to process Customer Personal Data as processor to provide the Services, including through Customer-specific models that are trained on Customer’s own data and operate solely within Customer’s account. SEON is not responsible for any reduction in the performance of the Services resulting from the exclusion. This Section 3.6 is in addition to any controls and opt-outs available in the Services as described in the User Guides.

3.7 Retention After the Agreement Ends. After the Agreement ends, SEON may retain aggregated or Anonymized data derived from Customer Personal Data for the purposes described in Section 3.5. SEON may retain identifiable personal data after that point, as an independent controller, only to the extent, and for so long as, it has a specific lawful basis to do so, such as compliance with a legal obligation, the establishment, exercise, or defense of legal claims, or the enforcement of this DPA or the Agreement. This Section 3.7 applies in the same way when an Evaluation ends.

3.8 SEON Account Data. SEON processes business contact and account information about Customer’s Users and personnel (such as names, business email addresses, and login and usage records) to administer Customer’s account, invoice Customer, communicate with Customer, and secure and improve the Services, as an independent controller and in accordance with SEON’s privacy notice. That information is not Customer Personal Data and is covered by SEON’s privacy notice available at https://seon.io/legal-and-security/privacy/.

3.9 Independent Controllers. Where SEON acts as an independent controller under this Section 3, each party is separately responsible for its own processing and for its own compliance with Data Protection Legislation.

4. Processor’s Obligations

4.1 Processor’s Undertakings. Processor will:

(a) process Customer Personal Data in accordance with Data Protection Legislation and Controller’s documented instructions under Section 3.1;

(b) inform Controller before processing if applicable law requires Processor to process Customer Personal Data other than on Controller’s instructions, unless that law prohibits Processor from doing so on important grounds of public interest;

(c) immediately inform Controller if, in Processor’s opinion, an instruction infringes Data Protection Legislation, in which case Processor need not follow the instruction until the parties resolve the matter in good faith;

(d) keep Customer Personal Data confidential and ensure that persons authorized to process it have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;

(e) implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as required by Data Protection Legislation and as described in Appendix 1, Section 6, and not materially reduce the overall security of the processing during the term of the Agreement;

(f) taking into account the nature of the processing, assist Controller by appropriate technical and organizational measures, insofar as possible, in responding to requests from data subjects exercising their rights under Data Protection Legislation (including requests concerning decisions based on automated processing, by providing information reasonably available to Processor about the main factors underlying the relevant outputs of the Services, to the extent technically feasible and subject to the protection of Processor’s trade secrets); notify Controller without undue delay if Processor receives such a request relating to Customer Personal Data, by email to Controller’s Email Address unless Controller instructs otherwise; and reasonably cooperate with Controller in addressing the request. Processor is not responsible for responding to data subjects on Controller’s behalf;

(g) taking into account the nature of the processing and the information available to Processor, assist Controller in ensuring compliance with its obligations regarding security of processing, notification of Personal Data Breaches to supervisory authorities and data subjects, data protection impact assessments, and prior consultation with supervisory authorities, and make available to Controller the information necessary to demonstrate compliance with this DPA, to the extent Controller does not otherwise have access to it. Except for negligible costs, Processor may charge Controller its reasonable costs of providing assistance under this DPA;

(h) inform and consult with Controller without undue delay if a supervisory authority initiates or takes any action in relation to Processor concerning the processing of Customer Personal Data, unless the law prohibits it; and

(i) process Customer Personal Data only for as long as necessary to provide the Services and in any case no longer than the Data Retention Period set out in Appendix 1, Section 5 or configured by Controller, after which Processor will delete or Anonymize it, unless applicable law requires Processor to retain it for longer, and subject to Sections 3.5, 3.7, and 9.

5. Audit

5.1 Certifications and Reports. Processor will satisfy Controller’s audit requests by providing its current ISO/IEC 27001 certificate, SOC 2 Type II report, and penetration-test summary, and by responding to reasonable security questionnaires once per year. These materials are available through SEON’s Trust Center at https://trust.seon.io and are Processor’s Confidential Information.

5.2 Audits. Processor will allow for and contribute to an audit, including an inspection, by Controller or an independent auditor Controller appoints (i) where the materials under Section 5.1 do not reasonably address a specific concern about Processor’s compliance with this DPA, (ii) following a Personal Data Breach, or (iii) where a supervisory authority with jurisdiction over Controller requires it, in each case on these conditions:

(a) the auditor is a well-regarded professional firm that is not a competitor of Processor and is bound by confidentiality obligations to Processor before the audit begins;

(b) Controller gives at least thirty (30) days’ written notice, and the parties agree the scope, timing, and duration of the audit in advance, with Processor’s agreement not to be unreasonably withheld;

(c) audits take place no more than once in any twelve (12) month period, except where required by a supervisory authority or following a Personal Data Breach;

(d) audits take place during business hours without unreasonably disrupting Processor’s operations and do not give access to other customers’ data or to Processor’s source code; and

(e) Controller bears its own costs and the costs of its auditor.

6. Subprocessors

6.1 General Authorization. Controller gives Processor general authorization to engage Subprocessors, including Processor’s Affiliates, in accordance with this Section 6.

6.2 Subprocessor List. Processor’s current Subprocessors are listed in Appendix 2 (the “Subprocessor List”). Controller authorizes Processor to use the Subprocessors on the Subprocessor List.

6.3 Changes and Objections. Processor will inform Controller of any intended addition or replacement of a Subprocessor by updating the Subprocessor List at least fourteen (14) days before the new Subprocessor begins processing Customer Personal Data. Controller may object to the change on reasonable grounds relating to data protection by email to Processor’s Designated POC within that period. Processor will make reasonable efforts to address the objection, which may include reviewing whether an equivalent alternative Subprocessor is commercially reasonable. Processor will also update the Subprocessor List when it removes a Subprocessor.

6.4 Subprocessor Obligations. Processor will engage each Subprocessor under a written agreement that imposes data protection obligations substantially equivalent to those in this DPA, to the extent applicable to the services the Subprocessor provides, and Processor remains responsible to Controller for the performance of each Subprocessor’s obligations.

7. International Transfers and Data Location

7.1 Data Location. Processor processes and stores Customer Personal Data in the geographic region Controller selects under the Agreement from the processing locations Processor makes available or, absent a selection, in the region Processor designates. Processor and its Subprocessors may access Customer Personal Data from other locations solely as necessary to provide, secure, and support the Services, subject to this Section 7.

7.2 Transfer Safeguards. Processor will transfer Customer Personal Data across borders, including to Subprocessors, only in compliance with Data Protection Legislation. Where a transfer by Processor to a Subprocessor requires an appropriate safeguard, Processor will put in place a valid transfer mechanism, such as standard contractual clauses approved by the competent authority or the Subprocessor’s certification under an applicable adequacy framework.

7.3 Transfer Mechanisms. Where a transfer of personal data between Customer and SEON under the Agreement requires a transfer mechanism under Data Protection Legislation, the mechanism set out in the applicable Schedule applies. Where the Data Protection Legislation of a jurisdiction not covered by a Schedule requires a specific transfer mechanism, the parties will cooperate in good faith to put that mechanism in place.

8. Data Sources and Third-Party Applications

8.1 Data Sources. Processor uses data sources to provide the Services, including public databases and publicly available information (including from social media providers), and enrichment, verification, and screening sources such as telecommunications, credit bureau, official registry, electronic identity, payment card verification, and sanctions, politically exposed person, watchlist, and adverse media data providers, as described in the User Guides. Controller authorizes Processor to submit identifiers from Customer Personal Data to these sources, including public database providers (such as DNSBL and data breach database providers) and social media providers established within or outside the EEA, as necessary to provide the Services and to receive the results. These providers are third parties that process the identifiers they receive under their own terms. Processor does not engage them to process Customer Personal Data on Controller’s behalf. A provider that does so is a Subprocessor under Section 6.

8.2 Integrations Enabled by Controller. Where Controller enables or uses an integration with a Third-Party Application (including through an application programming interface, connector, SEON’s Model Context Protocol (MCP) connector, another MCP server, or large language model integration), Controller instructs Processor to transmit Customer Personal Data to, or permit access by, that Third-Party Application. The provider of the Third-Party Application is not Processor’s Subprocessor, and its processing of Customer Personal Data is governed by its own terms and Controller’s arrangements with it, as described in the Agreement. This Section 8.2 does not apply to third-party services that Processor itself integrates into the Services, which Processor engages as Subprocessors where they process Customer Personal Data on Processor’s behalf, except as the Agreement otherwise provides for chargeback management services.

9. Return and Deletion

9.1 Access and Export. During the term of the Agreement, Controller may retrieve and export Customer Personal Data using the functionality of the Services. At Controller’s written request, Processor will provide Controller with a copy of, or access to, Customer Personal Data in Processor’s possession or control in a commonly used, machine-readable format, to the extent Controller cannot retrieve it through the Services.

9.2 Deletion on Instruction. On Controller’s written instruction, Processor will cease processing and promptly delete or return all or the specified Customer Personal Data, including (a) as Controller instructs in connection with the Services, and (b) on Controller’s written request in connection with the termination or expiry of the Agreement for any reason. Controller may also delete Customer Personal Data directly through the retention settings and deletion functionality of the Services described in the User Guides. Sections 9.2 and 9.3 do not apply to aggregated or Anonymized data, or to personal data that Processor retains as an independent controller as permitted by Section 3.7.

9.3 Deletion After the Agreement Ends. Within thirty (30) days after the end of the period during which the Agreement allows Controller to retrieve Customer Data following termination or expiry of the Agreement (or, if the Agreement provides no such period, after its termination or expiry), Processor will delete or Anonymize all Customer Personal Data, or return it to Controller if Controller so instructs, and delete or Anonymize existing copies, unless applicable law requires Processor to retain it. When an Evaluation ends, the deletion period in Appendix 1, Section 5 applies.

9.4 Legally Required Retention. If applicable law, regulation, or a governmental or regulatory authority requires Processor to retain Customer Personal Data that it would otherwise be required to return or delete under this DPA, Processor will promptly notify Controller in writing, specifying the legal basis for the retention, the data to be retained, and the timeline for deletion once the requirement ceases to apply. Processor will continue to protect the retained data in accordance with this DPA and process it only for the purpose of the retention.

9.5 Certification. At Controller’s written request, Processor will confirm in writing, within thirty (30) days after completing a deletion under Section 9.2 or 9.3, that the relevant Customer Personal Data has been deleted.

10. Personal Data Breach

10.1 Notification. Processor will notify Controller without undue delay after becoming aware of a Personal Data Breach and will cooperate reasonably with Controller to remedy it. The notification will include the information then available to Processor that Controller reasonably needs to meet its obligations under Data Protection Legislation, such as the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Processor will provide further information as it becomes available.

10.2 Method. Processor will send notifications under this Section 10 to Controller’s Email Address.

10.3 Notifications to Authorities and Data Subjects. Controller is responsible for notifying supervisory authorities and affected data subjects where Data Protection Legislation requires it. Processor will not notify them on Controller’s behalf unless required by law or agreed in writing.

10.4 No Admission. Processor’s notification of, or response to, a Personal Data Breach is not an acknowledgment of fault or liability.

11. Controller’s Responsibilities

11.1 Customer Personal Data. Controller is solely responsible for the accuracy, quality, and legality of Customer Personal Data, the means by which Controller acquired it, and all other obligations imposed on controllers by Data Protection Legislation.

11.2 Controller’s Measures. Taking into account the nature, scope, context, and purposes of the processing and the risks of varying likelihood and severity for the rights and freedoms of natural persons, Controller will implement appropriate technical and organizational measures to ensure, and to be able to demonstrate, that its processing is performed in accordance with Data Protection Legislation, including appropriate data protection policies where proportionate, and will review and update those measures where necessary.

11.3 Notices and Legal Basis. Controller will provide data subjects with all notices required by Data Protection Legislation (including, where applicable, the information required by Articles 13 and 14 of the GDPR), obtain all necessary permissions, authorizations, and consents, and ensure that it has a valid legal basis under Data Protection Legislation for the processing of Customer Personal Data under the Agreement, including the processing described in Section 3.5.

11.4 Biometric and Similarly Regulated Data. Where Controller uses the Services to process biometric data or similarly regulated categories of personal data, Controller will ensure, before the processing begins, that data subjects are adequately informed of the processing and have given, where required, valid, explicit, and informed consent to it. In particular, Controller will:

(a) incorporate, or otherwise make available to data subjects, the notice and consent language set out in Appendix 3, and ensure that its notices and consents are consistent with Appendix 3;

(b) give data subjects direct access (by hyperlink or otherwise) to SEON’s privacy notice; and

(c) implement the technical or API-based mechanisms described in Appendix 3 to capture and record that data subjects have been presented with, and agreed to, the foregoing.

Controller is solely liable for any breach of Data Protection Legislation resulting from its failure to comply with this Section 11.4.

11.5 Automated Decisions and Human Oversight. Controller will use the Services and their outputs only to support decision processes that operate under Controller’s human oversight, as described in the Agreement, and is solely responsible for the decisions it makes using the Services and its use of AI-enabled tools and for complying with applicable laws governing automated decision-making and artificial intelligence, such as Article 22 of the GDPR and UK GDPR, the EU Artificial Intelligence Act (Regulation (EU) 2024/1689), and any equivalent laws in other jurisdictions where Customer operates or affected individuals are located.

11.6 Lawful Instructions. Controller will ensure that its instructions comply with Data Protection Legislation and that Processor’s processing in accordance with them will not cause Processor to breach Data Protection Legislation.

12. Jurisdiction-Specific Terms

12.1 Application. Each Schedule to this DPA applies, in addition to the rest of this DPA, to the processing of personal data that is subject to the laws of the jurisdiction the Schedule covers.

12.2 Precedence. For processing subject to the laws of a jurisdiction covered by a Schedule, that Schedule prevails over the rest of this DPA to the extent of any conflict.

12.3 Additional Jurisdictions. SEON may add a Schedule for a jurisdiction not covered by the existing Schedules in accordance with Section 15.3.

13. Limitation of Liability

13.1 Exclusion of Indirect Damages. In no event will either party or its Affiliates be liable under or in connection with this DPA for any indirect, consequential, incidental, special, punitive, or exemplary damages, or for any loss of revenue, profits, sales, data, data use, goodwill, or reputation, however caused and under any theory of liability.

13.2 Liability Cap. Except as provided in Section 13.3, the aggregate liability of each party and its Affiliates arising out of or related to this DPA or the processing of personal data under the Agreement, whether in contract, tort, or otherwise, will not exceed the total amounts paid or payable under the applicable Order Form for the Services giving rise to the liability during the twelve (12) months immediately preceding the event giving rise to the liability. This Section 13 is the limitation of liability for the processing of personal data referred to in the Agreement. The cap in this Section 13.2 and the liability cap in the Agreement are a single aggregate cap and not cumulative, and any amount paid under either reduces the amount available under the other.

13.3 Exclusions from the Cap. Nothing in this DPA limits or excludes: (a) either party’s liability for fraud or fraudulent misrepresentation, or for death or personal injury caused by its negligence; (b) Customer’s obligation to pay amounts properly due under the Agreement; (c) Customer’s obligations under the Customer indemnity in the Agreement; or (d) any liability that cannot be limited or excluded under applicable law, including under any transfer mechanism incorporated under a Schedule or under Data Protection Legislation.

13.4 Negotiated Terms. Where a signed Agreement or Order Form expressly sets a different limitation of liability for data protection obligations or for this DPA, that limitation applies in place of Section 13.2 to the extent it states. For an Evaluation, a limitation of liability in the Agreement for that Evaluation likewise applies in place of Section 13.2.

14. Term and Termination

14.1 Term. This DPA takes effect on the earlier of (a) the date it is signed or otherwise becomes part of the Agreement and (b) the date Processor first processes Customer Personal Data under the Agreement or the Evaluation, and it continues for as long as Processor or any Subprocessor processes Customer Personal Data.

14.2 No Separate Termination. This DPA cannot be terminated separately from the Agreement while SEON processes Customer Personal Data, except that an Evaluation may be ended under Section 2.5. If the parties replace this DPA with another data processing agreement, the replacement governs from its effective date.

14.3 Survival. Any provision of this DPA that by its nature should survive its termination survives, including Sections 1 (Definitions), 3.7 (Retention After the Agreement Ends), 3.9 (Independent Controllers), 9 (Return and Deletion), 11 (Controller’s Responsibilities), 12 (Jurisdiction-Specific Terms), 13 (Limitation of Liability), 14 (Term and Termination), 15 (General Provisions), and the Schedules.

15. General Provisions

15.1 Designated Contacts and Notices. Each party designates a point of contact for data protection and urgent security matters (a “Designated POC”). SEON’s Designated POC is [email protected]. If Customer has not designated a Designated POC, Customer’s Designated POC is the notices email address stated in the Agreement or the applicable Order Form or, if none, Controller’s Email Address. Operational notices under this DPA may be sent by email to the other party’s Designated POC. Legal notices are given as the Agreement provides.

15.2 Governing Law and Dispute Resolution. This DPA is governed by the law that governs the Agreement or, if the Agreement does not specify a governing law, by the laws of Hungary. Where Data Protection Legislation requires this DPA to be governed by the law of an EU Member State and the law governing the Agreement is not such a law, this DPA is governed by the laws of Hungary or, if Data Protection Legislation requires the law of a particular EU Member State, by the law of that Member State. In all cases, Section 13 is governed by the law that governs the Agreement. Any dispute arising out of or in connection with this DPA will be resolved in accordance with the dispute resolution provisions of the Agreement. Any standard contractual clauses incorporated under a Schedule are governed by the law, and subject to the forum, specified in them or in that Schedule.

15.3 Amendments. Where this DPA forms part of the Agreement by reference (including by URL), SEON may change it by giving Customer reasonable prior notice through the same channel by which the Agreement is communicated to Customer, and no change will result in a material reduction in the level of protection provided for Customer Personal Data during the term of the applicable Order Form. A DPA signed by the parties, or attached to an Agreement or Order Form signed by both parties, may be amended only in a writing signed by both parties.

15.4 Order of Precedence. In the event of a conflict: (a) any standard contractual clauses or other transfer mechanism incorporated under a Schedule prevail over this DPA and the Agreement where they apply; (b) a Schedule prevails over the rest of this DPA as provided in Section 12.2; (c) this DPA prevails over the Agreement and any Order Form with respect to the processing of personal data, unless an Order Form expressly states otherwise; and (d) within this DPA, the body of this DPA prevails over Appendices 1, 2, and 3.

15.5 Severability. If any provision of this DPA is invalid or unenforceable, the remainder of this DPA remains valid and in force, and the invalid or unenforceable provision will be (a) amended as necessary to make it valid and enforceable while preserving the parties’ intentions as closely as possible or, if that is not possible, (b) construed as if the invalid or unenforceable part had never been included.

15.6 Entire Agreement. This DPA, together with the Agreement, constitutes the parties’ entire agreement on its subject matter and supersedes any prior data processing agreement between them relating to the Services provided under the Agreement. This includes any data processing agreement for an Evaluation, and Customer Personal Data processed under it becomes subject to this DPA.

15.7 Electronic Signature. Where this DPA is signed, it may be signed electronically (including through DocuSign, Juro, or a similar electronic signature platform) and in counterparts, each of which is an original and all of which together are one instrument.

Appendix 1: Details of Processing

1. Subject Matter

SEON’s provision of the Services to Customer under the Agreement or for an Evaluation.

2. Nature and Purpose of the Processing

SEON processes Customer Personal Data to provide the Services Customer uses, as described below and in the User Guides, including IT support, troubleshooting, and debugging (for example, during beta testing or integration assistance), and as described in Sections 3.3 and 3.4 of the DPA. SEON’s processing as an independent controller is described in Sections 3.5 and 3.7 of the DPA.

SEON provides a platform for fraud prevention and anti-money laundering (AML) compliance. Customer accesses the Services through application programming interfaces (APIs), software development kits (SDKs) for web and mobile applications, webhooks, and the Admin Panel. Customer sends data to SEON from its own systems or through SDKs integrated into its websites and apps, and SEON returns scores, enriched data, and decisions in real time or near real time. Depending on the exact scope of Services, the activities may include (without limitation): using real-time data signals to enrich customer profiles, flag suspicious behavior, and provide signals and scores aimed at detecting and preventing fraud and assessing risk, including by analyzing device and behavioral signals; verifying the identity of individuals, including their documents, addresses, and biometric characteristics; screening individuals and entities against sanctions, politically exposed person, watchlist, crime list, and adverse media sources and monitoring payments and transactions; supporting Customer’s investigations, case handling, workflows, and regulatory reporting, including through SEON’s AI-assisted features (for example, detecting connected fraud networks, suggesting rules, and drafting report narratives); making SEON’s data available to Customer’s own AI tools through SEON’s Model Context Protocol (MCP) connector, where Customer enables it, as described in Section 8.2 of the DPA.

The purpose is to enable Customer to prevent fraud and financial crime and to meet its customer due diligence, know-your-customer, and anti-money laundering and counter-terrorist financing obligations.

For an Evaluation, the nature of the processing is the same as for the Services being evaluated, and the purpose is to enable Customer to test and assess the suitability of those Services (for example, by sending historical data in a batch test or by running a proof of concept).

3. Categories of Data Subjects

Applicants and other individuals whose personal data Customer submits to the Services or collected from them through the Services, including Customer’s customers, prospective customers, users, and transaction counterparties, and individuals whose data is returned in screening or verification results.

The same categories apply to an Evaluation, limited to the Services being evaluated, and Evaluation data may include historical or test data that Customer submits (for example, in files).

4. Categories of Personal Data

The following is a non-exhaustive summary of the categories of personal data that SEON may process in connection with the Services. The categories processed depend on (i) the Services Customer uses, (ii) Customer’s configuration and customization choices, and (iii) the data Customer provides to SEON. The User Guides contain the complete list.

4.1 Fraud Prevention Services (where applicable): contact and identification data, including name, username, user ID, date and place of birth, email address, phone number, and physical or mailing address (including billing and shipping addresses); financial and payment data, including bank account details, payment card data (for example, card BIN, card hash, last digits, cardholder name, and expiry date) and payment authentication results; online and technical data, including IP address, device information (including device and browser fingerprints, operating system, browser version, and unique device identifiers), session information (for example, session IDs and timestamps), and metadata about the method and context of access to Customer’s system or site (for example, referral URL); behavioral and transactional data, including transaction details (for example, time, amount, and payment method) and user behavior patterns on Customer’s platform (for example, frequency or timing of transactions or account logins); order and counterparty data (for example, items purchased and the name, date of birth, and bank details of a payment receiver); location data, including geolocation information; enrichment data returned for email addresses, phone numbers, IP addresses, and physical addresses (for example, age, validity, and carrier or line type; online profiles and account registrations; data-breach exposure; domain registration details; proxy and VPN indicators; and verified or standardized address data); self-exclusion data, where Customer uses that functionality (for example, name, date of birth, email address, phone number, and postal code); derived or machine-generated data, including risk scores and analytical insights generated by SEON’s systems (for example, fraud risk assessments or flags); and any other data that Customer chooses to send (for example, in custom fields).

4.2 Identity Verification Services (where applicable): (i) personal data on, or extracted from, the identification document, such as name, sex, personal identification number or national equivalent, date of birth, estimated age, legal capacity, nationality, citizenship, eye color, weight and height, and address, as well as historic data of the Applicant that SEON may have stored during previous interactions within the retention periods and at all times within the scope of Customer’s account; (ii) contact data, such as address, email address, telephone numbers, IP address and, if relevant, the type of document presented (for example, bank statement or utility bill); (iii) bank account number; (iv) details of the identification document, such as the name of the document, issuing country, document number, expiration date, data encoded in the document barcodes (which may vary by document type), data read from the document’s electronic chip where chip reading is enabled (for example, the chip photo, name, document number, date of birth, nationality, and expiry date), and security features; (v) identity verification data, such as images (photographs) and recordings (videos) of the Applicant and their identification document, video recordings of the verification process, and the results of the verification checks; (vi) biometric identifiers, being data generated by measurements of the Applicant’s biological characteristics, such as face scans (scans of face geometry), face embeddings and other biometric templates (including those stored for duplicate detection and re-authentication), retina or iris scans, and other measurements extracted from an image (for example, a selfie) or a video and used to verify the Applicant or compare their face to the identity document photo through facial recognition or similar technologies; biometric information, being information based on a biometric identifier that can be used to identify the Applicant; and any personal data resulting from specific technical processing relating to the physical, physiological, or behavioral characteristics of a natural person that allow or confirm the unique identification of that person, such as facial images or dactyloscopic data (Article 4(14) of the GDPR), some of which may be biometric data under Data Protection Legislation (“Biometric Personal Data”); (vii) technical data, including the date, time, and the Applicant’s activity within the Services, IP address and domain name, software and hardware information, and general geographic location (for example, city, state, or country); (viii) session metadata, such as login and device information; (ix) attributes returned by an electronic identity provider, where electronic identity verification is used; (x) data returned by official, credit bureau, telecommunications, and other third-party sources for database (eKYC) checks, including national identification numbers and matched name, date of birth, address, phone, and email details and, depending on the check and country, additional attributes such as address history, relatives, or credit-file indicators; (xi) for payment card verification, the cardholder name and the result of the check (SEON does not receive full card numbers or card verification codes for this purpose); and (xii) documents and information that Customer requests for evidence collection (for example, proof of address and source-of-funds documents) and the data they contain.

4.3 AML Services (where applicable): general personal data (full name, date of birth, place of birth, photo ID number, nationality and residency data, unique user identifier, affiliation with organizations, and adverse media information, which may include negative news or reports identifying potential reputational risks related to financial crime or illegal activity); organization data for entity screening (organization names and their directors, beneficial owners, and representatives); identification document data (document type, issuing country, ID number, expiry date, machine-readable zone (MRZ), information embedded in document barcodes, and security features); relevant publicly available data (such as whether a person is a politically exposed person or is included in sanctions, watch, or crime lists); data from country-specific official registries and lists, where Customer enables them; payment screening data (sender and receiver names, bank names, account numbers or IBANs, SWIFT or BIC codes, and cryptocurrency wallet addresses); transaction data used for monitoring (for example, amounts, currencies, dates, payment methods, and counterparties); and screening outputs (for example, match scores, ongoing-monitoring alerts, and review decisions).

4.4 Case Management, Workflows, and AI-assisted Features (where applicable): alert and case records, including notes, decisions, and attachments relating to individuals; labels, tags, and custom lists (for example, blocklists and allowlists) that Customer applies; workflow run records; regulatory-report content; and the outputs of AI-assisted features (for example, summaries, risk explanations, and rule suggestions) based on Customer Personal Data.

4.5 Special categories of personal data: Biometric Personal Data processed for the purpose of uniquely identifying a natural person, where Customer uses the Identity Verification Services. The safeguards in Section 11.4 of the DPA, Appendix 3, and Section 6 of this Appendix 1 apply. Where Customer uses the AML Services, the personal data processed may include personal data relating to criminal convictions and offences (Article 10 of the GDPR), such as information in crime lists and adverse media. Other special categories of personal data may appear incidentally in documents and images submitted by Customer, in adverse-media sources, or in screening results.

5. Duration of Processing and Data Retention

SEON processes Customer Personal Data for the term of the Agreement or the Evaluation, subject to Sections 4.1(i) and 9 of the DPA. The default data retention period is:

  • for the Fraud Prevention Services, one (1) year from the completion of the relevant query;
  • for the AML Services, five (5) years from the completion of the relevant query; and
  • for the Identity Verification Services, three (3) years from the completion of the verification session

(each, a “Data Retention Period”). Customer may request SEON to configure different Data Retention Periods for each SEON domain or product, as available in the Services, and is responsible for ensuring that the Data Retention Periods it configures comply with Data Protection Legislation and for updating its retention settings as necessary.

Where SEON processes Customer Personal Data in connection with an Evaluation, SEON will delete all Customer Personal Data processed for the Evaluation within thirty (30) days after the Evaluation ends, unless Customer instructs SEON in writing to keep it (for example, where the parties enter into an agreement for the Services) or applicable law requires SEON to keep it.

This section does not apply to data processed by SEON as an independent controller, in accordance with Section 3.5 of the DPA, or to personal data that SEON retains as permitted by Section 3.7 of the DPA.

6. Technical and Organizational Security Measures

SEON maintains an information-security program that is independently certified or audited against recognized standards, including ISO/IEC 27001 and ISO/IEC 27017, and has in place effective SOC 2 Type II controls. SEON’s technical and organizational measures include:

  • encryption of Customer Personal Data in transit and at rest;
  • role-based access controls, least-privilege access, multi-factor authentication for personnel, and single sign-on support for Admin Panel access;
  • logging and monitoring of access to systems that process Customer Personal Data;
  • vulnerability management, including regular vulnerability scanning and at least annual third-party penetration testing;
  • backups, business continuity, and disaster recovery measures;
  • confidentiality commitments and security and privacy training for personnel;
  • security and data protection review of Subprocessors;
  • logical separation of Customer Personal Data from other customers’ data;
  • network security controls, including network segmentation, firewalls, and intrusion detection;
  • secure software development and change-management practices;
  • an incident response process; and
  • data minimization and retention controls, including the configurable Data Retention Periods described in Section 5 of this Appendix 1.

Further information about SEON’s security program and privacy practices is available through SEON’s Trust Center at https://trust.seon.io.

Appendix 2: Subprocessors

SEON’s current Subprocessor List is available through SEON’s Trust Center at https://trust.seon.io, or at such other URL as SEON specifies.

1. Requirement to Obtain Consent

Where required under Data Protection Legislation (including applicable US law), Customer must obtain each data subject’s valid, explicit, and informed consent to the processing of Biometric Personal Data by both parties as described in this DPA and the Agreement, by complying with the requirements below.

2. Notice and Consent Language

The following notice and consent text (or a functionally equivalent version) must be integrated into Customer’s user interface for any individual using Customer’s services where SEON’s technology and Services are deployed, before the data subject is redirected to proceed with onboarding:

Consent to Biometric and Other Personal Data Processing

“I understand and voluntarily agree that my personally identifiable information (“Personal Data”), including biometric information, may be processed by:

(i) the organization for which I am undergoing the identity verification process (the “Company”), and

(ii) Any member of the SEON Group (“SEON” or the “Service Provider”), each acting in accordance with applicable privacy and data protection laws.

For more information about SEON and how it processes my Personal Data, including its company and contact details, please refer to SEON’s Privacy Notice available at https://seon.io/legal-and-security/privacy/identity-verification-services/.

I acknowledge and agree that:

(i) (Categories of Biometric Data) my biometric data (including facial features or facial scans) may be processed to confirm my identity and/or verify that the identity document presented is legitimately owned by me;

(ii) (Purposes of Biometric Data Processing) my biometric data will be processed for the Company’s purposes, which may include compliance with anti-money laundering and counter-terrorist financing (AML/CFT) regulations, fraud prevention, age verification, and related legal obligations or business requirements;

(iii) (Purposes of Biometric Data Processing) SEON may independently process biometric data for compatible purposes, such as service development, fraud and criminal activity prevention, litigation holds, and other legal or regulatory requirements, as further described in SEON’s Privacy Notice available at https://seon.io/legal-and-security/privacy/identity-verification-services/;

(iv) (Automated decision-making) the Company and SEON may process my biometric data using automated techniques, such as facial scans, liveness checks, video selfies, face matching with identity documents, and related technologies, to verify my identity, detect the use of multiple or fraudulent identities, and help prevent illegal and fraudulent activity;

(v) (Disclosure of Personal Data) my Personal Data, including biometric data, may be shared with SEON’s affiliated entities where necessary to achieve the purposes set out above, and SEON uses Amazon Web Services (AWS) as its subprocessor to store biometric data; and

(vi) (Retention period) my Personal Data, including biometric data, will be retained by the Company and SEON only for as long as necessary to fulfill the purposes for which it was collected or to comply with applicable laws, and biometric data will be permanently destroyed once it is no longer required or the applicable legal retention period expires:

  • for residents of Texas, within one (1) year from the date the purpose of collecting the data ends;
  • for residents of Illinois, within three (3) years from the date the data was initially provided to SEON; and
  • in all other cases, no later than five (5) years after SEON’s receipt of the data, or earlier if required by law or on the Company’s instructions. Additional information about data deletion and destruction is provided in SEON’s Privacy Notice available at https://seon.io/legal-and-security/privacy/identity-verification-services/.”

Acknowledgment and Consent

“I confirm that I have read, understand, and voluntarily agree to the above terms, and I consent to the processing of my biometric data and other Personal Data by the Company and SEON for the purposes described above.”

3. Hyperlinks to SEON’s Privacy Notice

Customer must ensure that the notice and consent include direct hyperlinks to SEON’s Privacy Notice, available at https://seon.io/legal-and-security/privacy/identity-verification-services/.

4. Additional Requirements in Customer Documentation

In addition to incorporating the notice and consent wording above, Customer must ensure that its own policies, notices, and agreements with data subjects contain any further terms required by Data Protection Legislation, addressing, among other matters:

  • the processing of personal data, including biometric data, at the point of facial capture;
  • the specific purposes for which biometric data is processed;
  • Customer’s use of third-party service providers (such as SEON) to perform identity verification and related services; and
  • storage, retention periods, international transfers (if applicable), and any other legally required disclosures.

5. API Consent Parameter

Where Customer uses an API integration under the Agreement, Customer must implement an API consent parameter, such as privacy_notices_read_consent_given (or a similar parameter specified by SEON), to allow SEON to record and confirm that data subjects have been presented with, and agreed to, the provisions described in this Appendix 3.

Schedules: Jurisdiction-Specific Terms

Each of the following Schedules applies to the processing of personal data that is subject to the laws of the jurisdiction it covers, as provided in Section 12 of the DPA. Schedule A covers the European Economic Area, the United Kingdom, and Switzerland; Schedule B covers the United States; and Schedule C covers Brazil.

Schedule A: European Economic Area, United Kingdom, and Switzerland

1. Application

This Schedule A applies to the processing of personal data that is subject to the GDPR, the UK GDPR, or the Swiss Federal Act on Data Protection (the “FADP”).

2. Definitions

“Standard Contractual Clauses” or “SCCs” means the standard contractual clauses for the transfer of personal data to third countries adopted by Commission Implementing Decision (EU) 2021/914 of 4 June 2021, as amended or replaced.

“UK Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner under section 119A of the UK Data Protection Act 2018, as amended or replaced.

3. Transfer Mechanisms

Where a transfer of personal data between Customer and SEON under the Agreement is a restricted transfer under Data Protection Legislation and no other valid transfer mechanism applies, the SCCs, completed as set out in Section 6 of this Schedule A, apply as follows:

(a) Module One, for personal data that SEON processes as an independent controller under Sections 3.5 and 3.7 of the DPA;

(b) Module Two, where Customer, as controller, transfers Customer Personal Data to SEON as processor;

(c) Module Three, where Customer, as processor, transfers Customer Personal Data to SEON as a further processor; and

(d) Module Four, where SEON, as a processor established in the EEA, transfers Customer Personal Data to Customer as controller outside the EEA, in which case Clauses 14 and 15 of the SCCs apply only if SEON combines the Customer Personal Data received from Customer with personal data collected by SEON in the EEA.

4. United Kingdom and Switzerland

For restricted transfers subject to the UK GDPR, the SCCs apply as supplemented by the UK Addendum, completed as set out in Section 6 of this Schedule A. For transfers subject to the FADP, the SCCs apply with these adaptations: (a) the Swiss Federal Data Protection and Information Commissioner is the competent supervisory authority; (b) references to “Member State” in Clause 18(c) include Switzerland, so that data subjects in Switzerland may bring claims in their place of habitual residence; and (c) references to the GDPR include the FADP.

5. Precedence

Where the SCCs or the UK Addendum apply, this DPA supplements them to the extent permitted, and the SCCs and the UK Addendum, as completed in Section 6 of this Schedule A, prevail over any conflicting provision of this DPA or the Agreement.

6. Completion of the SCCs and the UK Addendum

Where Section 3 or 4 of this Schedule A provides that the SCCs or the UK Addendum apply, they are incorporated into the DPA by reference and completed as set out below. By entering into the Agreement or this DPA, each party is deemed to have signed the SCCs and the UK Addendum, including their Annexes, in the role described in Section 3 of this Schedule A and Annex I below.

SCC ClauseEU SCCsUK Addendum
ModulesModule One (controller to controller), Module Two (controller to processor), Module Three (processor to processor), and Module Four (processor to controller), as set out in Section 3 of this Schedule A.As for the EU SCCs.
Clause 7 (Docking clause)Applies.Applies.
Clause 9(a) (Use of sub-processors)Option 2 (general written authorization) applies. The data importer will inform the data exporter of any intended changes to the list of sub-processors at least fourteen (14) days in advance, in accordance with Section 6.3 of the DPA.As for the EU SCCs.
Clause 11(a) (Redress)The optional language does not apply.As for the EU SCCs.
Clause 13 and Annex I.C (Competent supervisory authority)For Modules One, Two, and Three, the supervisory authority determined in accordance with Clause 13 (for a data exporter established in an EU Member State, the supervisory authority of that Member State).The UK Information Commissioner.
Clause 17 (Governing law)Option 1 applies: the law of Hungary.The laws of England and Wales.
Clause 18 (Choice of forum and jurisdiction)The courts of Hungary.The courts of England and Wales.
Annex I.A (List of parties)See Annex I.A below.Table 1: see Annex I.A below.
Annex I.B (Description of transfer)See Annex I.B below and Appendix 1.Table 3: see Annex I.B below and Appendix 1.
Annex II (Technical and organizational measures)Appendix 1, Section 6.Table 3: Appendix 1, Section 6.
Annex III (List of sub-processors)Appendix 2 (the Subprocessor List).Table 3: Appendix 2.
Ending the UK Addendum when the Approved Addendum changesNot applicable.Table 4: either the data importer or the data exporter may end the UK Addendum as set out in its Section 19.

Annex I to Schedule A

A. List of Parties

Customer. Name and address: as stated in the DPA or the Agreement. Contact person’s name, position, and contact details: Customer’s Designated POC or Controller’s Email Address. Activities relevant to the data transferred: receipt of the Services described in Appendix 1. Role: controller (or processor, under Module Three); data exporter under Modules One, Two, and Three and data importer under Module Four. Signature and date: by entering into the Agreement or this DPA, as described in Section 2.1 of the DPA.

SEON. Name and address: the SEON entity that is party to the DPA, at the address stated in the DPA or the Agreement. Contact person’s name, position, and contact details: Data Protection Officer, [email protected]. Activities relevant to the data transferred: provision of the Services described in Appendix 1. Role: processor (or further processor, under Module Three) and, under Module One, controller for the processing described in Sections 3.5 and 3.7 of the DPA; data importer under Modules One, Two, and Three and data exporter under Module Four. Signature and date: by entering into the Agreement or this DPA, as described in Section 2.1 of the DPA.

B. Description of Transfer

Categories of data subjects whose personal data is transferredAs specified in Section 3 of Appendix 1.
Categories of personal data transferredAs specified in Section 4 of Appendix 1.
Sensitive data transferred, and the restrictions or safeguards appliedBiometric Personal Data processed for the purpose of uniquely identifying a natural person, where Customer uses the Identity Verification Services. Safeguards: Section 11.4 of the DPA, Appendix 3, the measures in Section 6 of Appendix 1, and the retention limits in Section 5 of Appendix 1.
Frequency of the transferContinuous, for the term of the Agreement.
Nature and purpose of the data transfer and further processingAs specified in Section 2 of Appendix 1 and, for Module One, the purposes described in Sections 3.5 and 3.7 of the DPA.
Period for which the personal data will be retained, or the criteria used to determine that periodAs specified in Section 5 of Appendix 1.
Transfers to sub-processors: subject matter, nature, and duration of the processingAs described in Section 6 of the DPA and Appendix 2, for the duration of the Agreement.

Schedule B: United States

1. Application

This Schedule B applies to the processing of Customer Personal Data that is subject to US Data Protection Legislation.

2. Definitions

“US Data Protection Legislation” means the laws of the United States and its states relating to privacy, security, or data protection that apply to the processing of Customer Personal Data, including, as applicable, the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA”), other US state consumer privacy laws, the Illinois Biometric Information Privacy Act, the Texas Capture or Use of Biometric Identifier Act, and Washington’s biometric identifiers law (RCW 19.375).

“Business Purposes” means providing, securing, and supporting the Services for Customer under the Agreement and the purposes described in Appendix 1, together with the purposes described in Section 3.5 of the DPA to the extent US Data Protection Legislation permits a service provider or processor to process personal information for them (including to detect security incidents, to protect against fraudulent or illegal activity, and to build or improve the quality of the Services).

3. Service Provider

To the extent US Data Protection Legislation applies, Processor acts as Controller’s “service provider” or “processor” (as those terms are defined in the applicable law) with respect to Customer Personal Data, and Controller discloses Customer Personal Data to Processor solely for the Business Purposes.

4. Restrictions

Except as permitted by US Data Protection Legislation, Processor will not:

(a) sell or share Customer Personal Data (as “sell” and “share” are defined in the CCPA);

(b) retain, use, or disclose Customer Personal Data for any purpose other than the Business Purposes, including for any commercial purpose outside the direct business relationship between Controller and Processor; or

(c) combine Customer Personal Data with personal information that Processor receives from or on behalf of another person or collects from its own interactions with consumers, except to perform the Business Purposes, including to detect security incidents, to protect against fraudulent or illegal activity, and to build or improve the quality of the Services, in each case as permitted by US Data Protection Legislation.

5. Compliance

Processor will comply with the obligations that apply to it as a service provider or processor under US Data Protection Legislation, provide the level of privacy protection that US Data Protection Legislation requires, and notify Controller if it determines that it can no longer meet those obligations. Controller may, on notice to Processor, take reasonable and appropriate steps to stop and remediate any unauthorized use of Customer Personal Data.

6. Deidentified Data

Where Processor uses deidentified data derived from Customer Personal Data, Processor will take reasonable measures to ensure that the data cannot be associated with a consumer or household, publicly commit to maintain and use the data only in deidentified form and not to attempt to re-identify it, and contractually require any recipient of the data to do the same.

Schedule C: Brazil

1. Application and Precedence

This Schedule C applies to the processing of personal data that is subject to the LGPD, including where the processing takes place in Brazil, where it relates to individuals located in Brazil in connection with the offering of goods or services, or where the personal data was collected in Brazil. For that processing, this Schedule C prevails over the rest of this DPA to the extent of any conflict.

2. Definitions

“ANPD” means Brazil’s National Data Protection Authority (Autoridade Nacional de Proteção de Dados). “International Transfer Regulation” means ANPD Resolution CD/ANPD No. 19/2024. “ANPD SCCs” means the standard contractual clauses approved by the ANPD in Annex II to the International Transfer Regulation. For the purposes of the LGPD, Controller acts as “controlador” and Processor acts as “operador.”

3. Legal Bases

3.1 Processing as Processor. Controller determines the legal basis for the processing of Customer Personal Data under Article 7 or, for sensitive personal data, Article 11 of the LGPD, and represents that it has identified and documented a valid legal basis for each processing activity it instructs Processor to carry out.

3.2 SEON’s Processing as Independent Controller. SEON’s processing as an independent controller under Sections 3.5 and 3.7 of the DPA relies, as applicable to each processing activity, on (a) the legitimate interests of SEON or third parties, under Articles 7(IX) and 10 of the LGPD; (b) the protection of credit, under Article 7(X) of the LGPD, where the processing is aimed at preventing or detecting fraud in connection with credit or financial transactions; or (c) compliance with a legal or regulatory obligation, under Article 7(II) of the LGPD. For sensitive personal data, including biometric data, SEON relies on the applicable bases in Article 11 of the LGPD, including the prevention of fraud and the security of the data subject in identification and authentication processes under Article 11(II)(g).

3.3 Legitimate Interest Assessments. SEON documents a legitimate interest assessment for each processing activity that relies on legitimate interest, taking into account the ANPD’s guidance, and will provide Controller with a summary of the relevant assessment on reasonable written request.

4. Retention After the Agreement Ends

For personal data subject to the LGPD that SEON retains under Section 3.7 of the DPA, SEON will (a) set a documented retention period for each category of retained data that is proportionate to the purpose of the retention, consistent with the principles of purpose and necessity in Article 6(I) and (III) of the LGPD; (b) delete or anonymize the data when that period expires, in accordance with Article 16 of the LGPD; and (c) where the retention relies on legitimate interest, provide Controller with a summary of the corresponding balancing assessment on reasonable written request.

5. Automated Decisions

5.1 Notices. Controller will ensure that data subjects receive, in Portuguese, the information required by Articles 9, 18, and 20 of the LGPD, including (a) the existence of automated decision-making, including profiling and risk scoring; (b) the criteria and procedures used for automated decisions that affect their interests, subject to commercial and industrial secrecy; and (c) how to request review of those decisions.

5.2 Controller’s Responsibility. Where Controller uses risk scores, fraud flags, or transaction recommendations from the Services in decisions that produce legal or similarly significant effects on data subjects (including decisions about access to financial products or services), Controller is primarily responsible for informing data subjects of their right to request review under Article 20 of the LGPD and for receiving and handling those requests, and will promptly notify Processor in writing when it needs Processor’s support with a request.

5.3 Processor’s Support. On Controller’s written request, and to the extent technically feasible and subject to commercial and industrial secrecy, Processor will (a) describe the logic, main parameters, and relevant factors underlying the risk scores, fraud flags, and transaction recommendations (such as approve, review, or decline) generated for a specific data subject; (b) maintain up-to-date technical documentation of automated processing that directly or decisively influences outcomes for data subjects; and (c) provide a reasoned response, within a reasonable time, to review requests that Controller refers to it. Processor’s role under this Section 5 is limited to providing technical support and information, and responding to data subjects remains Controller’s responsibility.

6. Data Subject Rights

Data subjects may exercise their rights under Articles 17 to 22 of the LGPD free of charge. Controller is responsible for responding within the timeframes required by the LGPD and the ANPD, including by providing a simplified response immediately or a complete response within fifteen (15) days of the request, and Processor will assist Controller as provided in Section 4.1(f) of the DPA.

7. International Transfers

7.1 Framework. International transfers of personal data subject to the LGPD are governed by Articles 33 to 36 of the LGPD and the International Transfer Regulation, and require both a legal basis under Article 7 or 11 of the LGPD and a valid transfer mechanism.

7.2 ANPD Standard Contractual Clauses. Where Customer Personal Data subject to the LGPD is transferred between Controller and Processor, or by Processor to a Subprocessor, to a country that the ANPD has not recognized as providing an adequate level of protection, and no other valid mechanism under Article 33 of the LGPD applies, the parties adopt the ANPD SCCs, which are incorporated into this DPA in full and without modification. The party that transfers the personal data acts as exporter and the party that receives it acts as importer, and the information needed to complete the ANPD SCCs is set out in Annex I to Schedule A and in Appendices 1 and 2, applied with the necessary changes. The ANPD SCCs prevail over the rest of this DPA and the Agreement to the extent of any conflict.

7.3 Processor’s Transfer Obligations. For transfers of personal data subject to the LGPD, Processor will (a) assess whether each processing operation involves an international transfer subject to the LGPD and, if so, confirm that it has a valid legal basis and transfer mechanism; (b) limit transfers to the personal data needed for their purposes; (c) apply technical and administrative security measures appropriate to the risk and to the transfer mechanism used; (d) require Subprocessors that receive the data to provide safeguards at least equivalent to those in this Schedule C and in the applicable transfer mechanism; (e) on Controller’s written request, provide within fifteen (15) days a copy of the transfer mechanism used and documentation of the safeguards in place, so that Controller can meet its transparency obligations under the International Transfer Regulation; and (f) notify Controller without undue delay of any change in the law of a destination country that prevents Processor from complying with the applicable transfer mechanism.

8. Data Protection Officer (Encarregado)

SEON’s data protection officer (encarregado) for the purposes of the LGPD is currently Nauman Abuzar, who can be contacted at [email protected]. SEON ensures that communications with data subjects and the ANPD can be handled in Portuguese.

9. Supervisory Authority

The ANPD is the competent supervisory authority for processing subject to the LGPD, and references in this DPA to supervisory authorities include the ANPD for that processing.

10. Cross-Customer Fraud Intelligence

Where personal data of data subjects in Brazil is used in SEON’s cross-customer fraud intelligence under Section 3.5 of the DPA, including consortium features, SEON will (a) ensure that the use is compatible with the purpose for which the data was collected, in accordance with Article 6(I) of the LGPD; (b) document a necessity and proportionality analysis for that use; and (c) apply de-identification measures so that data used across customers is aggregated or anonymized and cannot reasonably be re-identified, consistent with Article 12 of the LGPD. Controller will inform data subjects in its privacy notice, to the extent the LGPD requires, that their data may be used in shared fraud intelligence mechanisms.

11. Biometric Data and Consent Wording

11.1 Application of Appendix 3. For biometric data of data subjects in Brazil, Appendix 3 applies with the changes in this Section 11.

11.2 Language and Form of Consent. Controller will present the notice and consent language in Portuguese. Where consent is the legal basis, Controller will obtain it in a specific and highlighted manner for the purposes described, as required by Article 11(I) of the LGPD, and will obtain a separate consent for SEON’s independent processing described in item (iii) of the consent language.

11.3 Additional Consent Language. Controller will add the following to the consent language in Appendix 3:

“(vii) (Review of automated decisions) I may request review of decisions made solely on the basis of automated processing of my personal data that affect my interests, as provided in Article 20 of the LGPD, by contacting the Company or SEON’s data protection officer (encarregado) at [email protected].”

“☐ I specifically consent to SEON independently processing my biometric data for the compatible purposes described in item (iii) above.”

11.4 Controller’s Own Legal Basis. Where Controller relies on Article 11(II)(g) of the LGPD rather than consent for its own processing, Controller remains responsible for the notices the LGPD requires, and the separate consent for item (iii) remains required for SEON’s independent processing.

11.5 Privacy Notice. For data subjects in Brazil, Controller will link to the Portuguese version of SEON’s privacy notice.

PROFESSIONAL SERVICES AGREEMENT


1. OBJECTIVE AND APPLICATION

1.1 This PSA forms part of, and complements the provisions of, the Agreement between SEON and Customer and governs SEON’s provision to Customer of the optional, expert-led advisory and operational services that SEON offers in addition to the Cloud Services and its standard onboarding, implementation and Support Services, such as custom implementation, configuration, integration, customization, training, consulting, or other technical or advisory services (“Professional Services”). Any issues not regulated by this PSA shall be governed by the provisions of the Agreement. By signing this PSA or clicking through the click-through mechanism implemented by SEON at seon.io or by expressing its agreement otherwise, Customer agrees to this PSA and this PSA becomes a binding commitment between Customer and SEON.

1.2 This PSA is incorporated into the Agreement. Interpretations and defined terms set forth in the Agreement apply to the interpretation of this PSA. The terms of this PSA are cumulative with those set forth in the Agreement and other agreements ancillary thereto, and are not intended and shall not be construed to expand either party’s obligations or limit either party’s rights with regard to the subject matter thereof except as expressly set forth herein with regard to any Professional Services provided by SEON to Customer. In case of conflict between this PSA and the Agreement, the Agreement prevails.

1.3 For purposes of clarification and not limitation, unless expressly otherwise agreed, the terms and conditions of the parties’ Agreement (whether a signed subscription services agreement or SEON’s Terms of Service), governing payment terms, term and termination, and confidentiality apply to and govern SEON’s provision of Professional Services hereunder.

2. SEON PROFESSIONAL SERVICES

2.1 SEON shall provide to Customer any Professional Services: (a) in accordance with the terms and subject to the conditions set forth in this PSA, the Agreement and the applicable Order Form or statement of work (“SOW”) setting forth the services to be provided, and deliverables thereunder, whether in the form of advice, specific systems or processes (“Tools”), or any other means (collectively, “Deliverables”); and (b) in a professional manner consistent with industry standards.

2.2 SEON will perform the Professional Services in accordance with the DPA and applicable data protection laws and regulations, as referenced in the Agreement.

3. CUSTOMER OBLIGATIONS

3.1 Customer shall: (a) pay any fees associated with the Professional Services as stated in the applicable Order Form or SOW; (b) cooperate with SEON in all matters relating to the Professional Services; (c) provide such access to Customer’s systems as may reasonably be requested by SEON for the purposes of performing the Professional Services; (d) respond promptly to any SEON request to provide direction, information, approvals, authorizations, or decisions that are reasonably necessary for SEON to perform the Professional Services in accordance with the requirements of this PSA; (e) ensure that all Customer systems are in good working order and suitable for the purposes for which they are used in relation to the Professional Services; and (f) obtain and maintain all necessary licenses and consents and comply with all applicable law in relation to the Professional Services.

3.2 If SEON’s performance of its obligations under this PSA is prevented or delayed by any act or omission of Customer or its agents, subcontractors, consultants, or employees, SEON shall not be deemed in breach of its obligations under this PSA or the Agreement or otherwise liable for any costs, charges, or losses sustained or incurred by Customer, in each case, to the extent arising directly or indirectly from such prevention or delay.

3.3 Customer remains responsible for ensuring that any data provided to SEON for the purpose of Professional Services complies with the DPA and all applicable data protection laws and regulations.

4. CONFIDENTIALITY

4.1 Notwithstanding that the form and content of the Deliverables under this PSA may be distinct and of a different nature than the Services provided under the parties’ Agreement, the confidentiality obligations of the Agreement apply with equal force to the Deliverables and any content contained therein or derived therefrom.

5. INTELLECTUAL PROPERTY RIGHTS

5.1 The parties agree that the Professional Services, and the Deliverables provided in connection therewith, constitute Confidential Information under the terms of the Agreement. Ownership of the Professional Services and the Deliverables, and Customer’s right to use them, are governed by the Agreement.

6. LIMITATION OF WARRANTIES

6.1 EXCEPT AS EXPRESSLY SET FORTH IN THIS PSA OR THE AGREEMENT, SEON HEREBY DISCLAIMS ALL WARRANTIES, EITHER EXPRESS, IMPLIED, STATUTORY, OR OTHERWISE UNDER THIS PSA AND SPECIFICALLY DISCLAIMS ALL IMPLIED WARRANTIES OF TITLE AND NON-INFRINGEMENT WITH RESPECT TO THE PROFESSIONAL SERVICES.

7. INDEMNIFICATION

7.1 Indemnification in connection with the Professional Services is governed by the Agreement.

8. LIMITATION OF LIABILITY

8.1 IN NO EVENT WILL EITHER PARTY BE LIABLE TO THE OTHER OR TO ANY THIRD PARTY FOR ANY LOSS OF USE, REVENUE, OR PROFIT OR LOSS OF DATA OR FOR ANY CONSEQUENTIAL, INCIDENTAL, INDIRECT, EXEMPLARY, SPECIAL, OR PUNITIVE DAMAGES WHETHER ARISING OUT OF BREACH OF CONTRACT, TORT (INCLUDING NEGLIGENCE), OR OTHERWISE, RESULTING FROM THE PROVISION OF THE PROFESSIONAL SERVICES, REGARDLESS OF WHETHER SUCH DAMAGE WAS FORESEEABLE AND WHETHER OR NOT SUCH PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.

9. GOVERNING LAW AND JURISDICTION

9.1 The PSA is governed by, and the parties agree to resolve disputes under, the terms, conditions, and processes specified, including binding arbitration, as set forth in their Agreement.