Terms of Service
Last updated: January 24, 2026
1. Introduction and Purpose
These Terms of Service and Platform Responsibility Policy (the "Agreement") govern your access to and use of the KYCProtect platform.
KYCProtect is operated by Novalis Solutions AB, registration number 559562-1912, with its registered office in Stockholm, Sweden ("KYCProtect", "we", "us", or "our").
KYCProtect provides a cloud-based platform designed to support businesses in managing Anti-Money Laundering (AML) and Know Your Customer (KYC) compliance workflows. These Terms clarify the scope of the Services and the allocation of responsibility between KYCProtect and its users.
By accessing or using the Services, you agree to be bound by this Agreement.
2. Scope and Intended Users
KYCProtect is designed primarily for participants in the art and luxury market, as well as other businesses that are subject to AML and KYC obligations under applicable European Union, United Kingdom, United States, and other national legislation.
The Services are intended for business users only and are not directed at consumers.
3. Scope of Services
KYCProtect provides a technology platform that may include:
- tools to generate internal AML and KYC policy documentation based on user-provided information and predefined templates;
- workflow tools to support AML and KYC processes;
- secure storage of compliance-related records and documentation; and
- access to automated screening and identity verification services provided by integrated third-party service providers.
Any documentation generated through the Services is provided for internal use by the user's business. Responsibility for reviewing, approving, implementing, and maintaining any generated documentation rests solely with the user.
4. Third-Party Services
Certain screening and due diligence functions made available through the Services, including sanctions screening, politically exposed person (PEP) checks, adverse media screening, and similar assessments, are performed through integrated third-party service providers and data sources.
KYCProtect does not control the underlying source data used by such providers, which may include sanctions lists and data derived from authorities such as the European Union, United Nations, Office of Foreign Assets Control (OFAC), and other recognised national or international bodies, as well as commercial data providers. Results made available through the Services, including any automated 'risk scores' or status indicators, are provided to support the user's compliance processes. The absence of a 'flag' or a 'low risk' status does not constitute a guarantee of compliance or the absence of risk. Responsibility for final verification, interpreting results, and acting upon them remains 100% with the user.
5. What KYCProtect Does Not Do
KYCProtect does not:
- provide legal or regulatory advice;
- act as a compliance officer, regulator, or supervisory authority;
- guarantee, certify, or ensure that a user's business is compliant with AML or KYC laws;
- make final risk determinations or compliance decisions on behalf of users; or
- submit suspicious activity or regulatory reports to authorities on behalf of users; or
- guarantee the accuracy of AI-driven document analysis or rule-based flags; these are tools for guidance only and are prone to false positives or false negatives.
All compliance decisions and obligations remain the responsibility of the user's business.
The Services are a compliance support tool only and do not replace professional legal, regulatory, or compliance advice.
6. User Responsibilities
You remain fully responsible for:
- determining your obligations under applicable AML and KYC laws in all jurisdictions relevant to your business operations;
- ensuring that any AML or KYC policies generated or stored using the Services are accurate and appropriate for your business;
- implementing and following your own AML and KYC policies and procedures in practice;
- ensuring that all information provided to KYCProtect is accurate, complete, and up to date; and
- taking any operational steps required to comply with applicable laws prior to an audit or regulatory review.
Use of the Services does not replace the need for appropriate internal controls, staff training, or professional advice where required.
7. Subscription, Fees, and Payment
7.1 Subscription Term
The Agreement commences on the date you first access the Services and continues for the subscription term selected by you, unless terminated earlier in accordance with this Agreement.
Subscriptions automatically renew for successive terms unless terminated by either party with at least thirty (30) days' written notice prior to the end of the applicable subscription period.
7.2 Pricing and Changes to Services
Subject to our obligation to provide the Services at the prices agreed for the applicable subscription period, we reserve the right to amend pricing and to modify the scope or availability of the Services from time to time.
Any change to pricing shall take effect only upon the commencement of a new subscription period. Prices applicable to a current subscription term shall not change during that term.
Where practicable, we will provide reasonable advance notice of any material changes to pricing or the range of Services.
7.3 Trial and Demo Access
KYCProtect may, at its discretion, offer trial or demo access to the Services for evaluation purposes.
Trial or demo access is limited to one instance per legal entity and/or business domain. Multiple trial or demo registrations by the same company, group, individual, or email domain are not permitted.
We reserve the right, at our sole discretion, to refuse, suspend, or terminate trial or demo access where we reasonably believe that such access is being misused, duplicated, or obtained in circumvention of these limitations.
7.4 Late Payment
If you fail to make any payment by the due date, we may, without prejudice to any other rights or remedies:
- suspend or terminate access to the Services;
- apply any payments received to outstanding amounts at our discretion; and
- charge interest on overdue amounts at a rate of 1.5% per month (18% per annum), or the maximum rate permitted by applicable law if lower, calculated from the due date until payment is made in full.
8. Permitted Use of the Services
The Services are provided solely for business-to-business use and may not be used for personal, household, or consumer purposes.
You agree to use the Services only in accordance with this Agreement and your selected subscription plan.
You shall ensure that:
- access to the Services is limited to authorised users under your subscription;
- user credentials are kept confidential;
- any suspected unauthorised use is reported to info@kycprotect.com without undue delay;
- the Services are not used to create competing products or services; and
- the Services are not made available to unauthorised third parties.
We reserve the right to audit your use of the Services on reasonable notice to verify compliance with your subscription plan.
9. Intellectual Property Rights
All intellectual property rights in the Services, including the platform software, interfaces, and underlying systems, are owned by or licensed to KYCProtect.
You retain ownership of all intellectual property rights in information and materials you submit to the Services. You are granted a limited, non-exclusive, non-transferable right to use the Services during the subscription term in accordance with this Agreement.
You shall not copy, modify, reverse engineer, or otherwise attempt to extract the source code or underlying structure of the Services.
10. Indemnity
If you breach this Agreement and any claim is brought against KYCProtect as a result, you shall indemnify and hold KYCProtect harmless against all losses, damages, costs, and expenses arising from such claim.
Subject to the limitations of liability set out below, KYCProtect shall indemnify you against third-party claims alleging that the Services infringe intellectual property rights, provided that you promptly notify us of the claim and allow us sole control of the defence and settlement.
11. Limitation of Liability
Nothing in this Agreement limits liability for death or personal injury caused by negligence, fraud, or any liability that cannot be excluded by law.
To the maximum extent permitted by law, KYCProtect's aggregate liability under this Agreement shall not exceed the total fees paid by you during the twelve (12) months preceding the event giving rise to the claim.
KYCProtect shall not be liable for indirect, incidental, consequential, or economic losses, including loss of profits, business, data, or reputation.
Outputs generated through the Services, including AI analysis and automated screening, depend on the accuracy of provided data and third-party sources. KYCProtect shall not be liable for any regulatory fines, penalties, or losses resulting from the user's reliance on platform indicators. The user acknowledges that the software is a support tool and does not replace the user's ultimate legal obligation to manually control and verify all documentation.
12. Data Protection and Confidentiality
12.1 Data Protection Roles and Regulatory Compliance
Each party shall comply with all applicable data protection laws and regulations, including, where applicable, the EU General Data Protection Regulation (GDPR) and the UK GDPR. In connection with the provision of the Services, KYCProtect acts as a data processor and you act as data controller in relation to personal data processed through the platform. This structure ensures that you, as the controller, retain paramount authority over how personal data is processed, including the scope and purpose of processing activities carried out on your behalf. KYCProtect processes such data solely in accordance with your documented instructions and applicable law, as further described in our Privacy Policy. KYCProtect actively monitors developments in data protection regulation and privacy-enhancing technologies — including emerging frameworks such as future AMLA (Anti-Money Laundering Authority) guidelines — to ensure the Services continue to support your compliance needs responsibly and in accordance with evolving legal and technical standards.
12.2 Technical and Organisational Security Measures
KYCProtect implements and maintains a robust suite of technical and organisational measures to protect personal data processed through the Services, designed in accordance with the principles of privacy by design and by default. These measures include:
- Row-Level Security (RLS): enforced at the database level to ensure strict logical isolation between customer accounts in our multi-tenant architecture, so that no customer can access another's data;
- Encryption: all data is encrypted both at rest and in transit using strong, industry-standard cryptographic protocols, ensuring confidentiality and integrity throughout;
- Role-based access controls: enforced at both application and infrastructure layers, limiting access to personal data strictly to authorised personnel for the minimum purposes necessary;
- Secure document handling: uploaded identity and compliance documents are stored in private object storage and accessed exclusively via time-limited, cryptographically signed URLs, preventing persistent or unauthorised access;
- Secure processing of verified attributes: our compliance workflows are designed to validate the necessary identity attributes to fulfil AML obligations while minimising the exposure and retention of raw personal data where operationally feasible;
- Dynamic data lifecycle management: personal data is subject to purpose-limited retention and secure, auditable deletion once legal and compliance retention obligations have been fulfilled, consistent with data minimisation principles under applicable law;
- Audit logging: all material actions within the platform are recorded in immutable audit logs to support compliance oversight, accountability, and incident response; and
- Trusted third-party partners: where verification or screening services are provided through integrated third-party providers, we select partners who demonstrate strong commitments to data security and privacy by design, and who may employ advanced privacy-enhancing verification techniques within their own pipelines.
Further details regarding our security architecture and practices are set out in our Privacy Policy and are available upon reasonable request.
12.3 Data Retention
KYCProtect applies a structured data lifecycle management approach. Personal data processed through the Services is retained in accordance with applicable AML legislation — typically for five (5) years following the end of a business relationship or transaction — and is securely deleted thereafter in a controlled and auditable manner. Data that is no longer necessary for its original compliance purpose is deleted or anonymised promptly, consistent with data minimisation obligations under applicable law. Customers retain authority, as data controllers, to define additional retention parameters within the bounds of applicable law.
12.4 Confidentiality
Each party shall keep confidential all non-public information received from the other party in connection with this Agreement and shall not disclose such information to any third party without prior written consent, except as required by applicable law or regulation. This obligation of confidentiality shall survive termination of the Agreement.
13. Anti-Bribery and Anti-Corruption
Each party shall comply with all applicable anti-bribery and anti-corruption laws and regulations, including those applicable in Sweden, the European Union, the United Kingdom, and the United States.
KYCProtect maintains policies and procedures designed to prevent bribery and corruption and takes reasonable steps to ensure compliance by persons associated with its business.
14. Force Majeure
Neither party shall be liable for failure or delay in performance caused by events beyond its reasonable control.
15. Governing Law and Jurisdiction
This Agreement shall be governed by and construed in accordance with the laws of Sweden. The courts of Sweden shall have exclusive jurisdiction.
16. Amendments and Variations
16.1. KYCProtect reserves the right to amend these Terms at any time to reflect changes in law, regulatory requirements, or platform functionality.
16.2. We will notify you of any material changes by posting the updated Terms on our website or via email at least thirty (30) days before the changes take effect.
16.3. Your continued use of the Services after the effective date of any amendment constitutes your acceptance of the revised Terms. If you do not agree to the amendments, your sole remedy is to terminate your subscription prior to the effective date.
17. Contact Information
For questions regarding the Services or this Agreement, please contact:
Email: info@kycprotect.com
Website: https://kycprotect.com/
End of Agreement
