Salt Edge Authenticator Terms of Service

Date Last Revised: July 4, 2019

Thank you for using Salt Edge Authenticator, the mobile authentication application for iOS and Android platforms (the "Authenticator"), which, inter alia, provides a solution for the requirements of strong customer authentication and dynamic linking set forth in the Payment Services Directive (EU) 2015/2366 (PSD2). These Terms of Service (the "Agreement") are a legal and binding agreement between Salt Edge Inc. including its respective licensors ("Salt Edge", "we", "our" or "us"), and you. This Agreement sets out the terms and conditions under which you may access and use the Authenticator and the Services (as defined below) provided by us via the Authenticator. By downloading and installing the Authenticator and using the Services, you agree to be bound by the terms and conditions of this Agreement. We recommend that you thoroughly review this Agreement, as the same may be updated from time to time, before accessing or starting to use the Services and during your use of the Services. You must not access and use the Authenticator and the Services if you don’t agree to all of the terms and provisions of this Agreement.


1. DEFINITIONS

In addition to the capitalized terms defined elsewhere in this Agreement, the following capitalized terms, when used in this Agreement, shall have the meanings given to them as follows:

1.1. "Authentication" means the process of your online authentication towards the Financial Institution and/or the authorization by you of Financial Account Actions, by means of Authentication Codes.

1.2 "Authentication Code" means a unique identifier made of a combination of letters, numbers or symbols, generated, encrypted and transmitted to you by the Financial Institution, that you must digitally sign and send from your mobile device to the Financial Institution for verification, for the purpose of authenticating yourself and/or authorizing a Financial Account Action.

1.3. "Financial Account" means an account accessible online held in your name by the respective Financial Institution. Financial Account includes but is not limited to Payment Account, current account, e-money account, credit card account, savings account, mortgage account, loan account.

1.4. "Financial Account Action" means any instance of providing access to and/or any action with respect to your Financial Account carried out through a remote channel, for whose execution the respective Financial Institution requires your preliminary authentication and/or authorization.

1.5. "Financial Institution" means a legal entity engaged in the business of dealing with financial transactions, including without limitation banks, payment system providers, loan companies, mortgage companies, investment companies, utilities/bills providers and other financial service providers located worldwide, that provides and maintains a Financial Account for you and that has engaged Salt Edge as third-party provider for the Authentication solution.

1.6. "Payment Account" means a Financial Account, which may be used for the execution of Payment Transactions.

1.7. "Payment Transaction" means an online act initiated by you or on your behalf of placing, transferring or withdrawing funds from your Payment Account.

1.8. "Services" means the functionality of the Authenticator aimed at enabling your Authentication, as described in more detail in Clause 3.1, as well as any content, features, tools or services as made available by Salt Edge from time to time in connection with the Authenticator.

1.9. "Third-Party Provider" means any financial service provider offering or intending to offer you services in relation to your Financial Account.


2. ACCEPTANCE OF AGREEMENT

2.1. By downloading and installing the Authenticator and by accessing and using the Services, you agree to be bound by the terms of this Agreement and also represent and warrant:

  1. in the event that you are an individual, that you are at least eighteen (18) years old, or of the legal age of majority in the jurisdiction in which you reside;
  2. that you have legal capacity to enter into this Agreement;
  3. in the event that you act on behalf of a company, corporation, organization or other legal entity ("Legal Entity"), that you have the authority to bind that Legal Entity to this Agreement; and
  4. that you have carefully reviewed the terms and conditions of this Agreement.

2.2. If this Agreement is entered into on behalf of a Legal Entity, then all references to "you" and "your" in this Agreement shall refer to such Legal Entity, unless the context indicates otherwise, and the provisions hereof shall be applicable to such Legal Entity except for the provisions limited by the context to individuals.


3. SERVICES

3.1. Services. During the term of this Agreement, Salt Edge shall provide the Services to you via the Authenticator, in accordance with, and subject to the terms and conditions of this Agreement. The Services include:

  1. the delivery of push notifications regarding the receipt of Authentication Codes;
  2. the display of Financial Account Action details and of the requests for your authentication and/or for the authorization of Financial Account Actions, as generated by your Financial Institution(s);
  3. the transmission of Authentication Codes between your mobile device and your Financial Institution.

3.2. Business Arrangements and Free of Charge. The provision to you of the Services in connection with your Financial Institution is subject, at any given time, to the existence of a functional business arrangement between Salt Edge and that Financial Institution. By virtue of such arrangement, the Services are provided to you free of charge, unless indicated otherwise in this Agreement.

3.3. License Grant. The Authenticator and the Services are protected by copyright, trade secret, and other intellectual property rights laws. Salt Edge hereby grants you a personal, limited, non-exclusive, non-transferable, revocable, non-sublicensable, royalty-free right and license to download and install the Authenticator on your mobile device for the sole purpose of enabling you to use and enjoy the benefit of the Services during the term of, and as permitted by, this Agreement. Except for the rights expressly granted to you in this Agreement, no other rights are granted by implication, estoppel or otherwise. You acknowledge that only Salt Edge shall have the right to maintain, enhance or otherwise modify the Authenticator and the Services, unless specific permissions are granted to you in a separate written agreement with Salt Edge.

3.4. License Restrictions. You shall use the Authenticator and the Services solely as permitted by, and contemplated in, this Agreement. Without limiting any other provision of this Agreement, you agree that you shall not (and will not allow any third party to), either directly or indirectly:

  • market, sell, license, sublicense, lease, transfer or distribute, any element of the Authenticator and/or the Services;
  • reverse engineer, decrypt, decompile, decode, disassemble the Authenticator or any part thereof;
  • modify, copy, translate, or create derivative works based on, the Authenticator;
  • breach, override or otherwise circumvent any authentication or security mechanisms, or any user limits or other use restrictions that are built into the Services;
  • remove or obliterate any proprietary notices, ownership labels, classified legends or marks from the Authenticator and the Services;
  • indulge in any actions with the Authenticator and/or Services that meddle with, disturb, destroy, or access in an unlawful way the server networks, connections, systems, records, or other assets, tools or services of Salt Edge or any related third party;
  • indulge in any actions with the Authenticator and/or the Services that could result in disruption of the Services;
  • transmit any worms, viruses, Trojan horses, or any other malware, disruptive or harmful software or data through your access to, and use of, the Authenticator and the Services;
  • access and use the Authenticator, Services or any part thereof for any unlawful or fraudulent purpose or otherwise in any way not permitted by this Agreement.

4. YOUR USE OF THE SERVICES

4.1. Authenticator Credentials. When installing the Authenticator on your mobile device, you will be required to establish an authentication procedure by means of providing your (or your authorized agent’s) biometric characteristics (a capture of facial image or fingerprint) or, alternatively, a PIN code (each and together, "Authenticator Credentials"). You will be required to provide the Authenticator Credentials each time you access the Authenticator.

4.2. Linking to Financial Accounts. In order to be able to enjoy the Services in relation to any of your Financial Accounts, you will be required to link the Authenticator to that Financial Account, by scanning a QR code provided online by the Financial Institution that holds that particular Financial Accountor or by accessing the deep link provided to you on the website of that Financial Institution. During the linking process you will be required by the respective Financial Institution to go through its own authentication flow. Following successful linking to the Financial Institution, you can start using the Authenticator and the Services in relation to the relevant Financial Account.

4.3. General Requirements. The Authenticator and the Services are available to you through a compatible mobile device and require internet access. You acknowledge and agree that you are solely responsible for the technical requirements relating to your access and use of the Services through your mobile device, including but not limited to: (i) any applicable charges, updates and/or additional fees of your telecommunications provider (internet service provider, mobile service provider and/or other data providers), and (ii) using the Services in compliance with the terms of your agreement with your telecommunications provider. You acknowledge and agree that Salt Edge makes no warranties or representations of any kind, express, statutory or implied, as to whether the telecommunications services from your provider will be available and accessible at any time or from any location. We expressly disclaim any liability or responsibility for any loss, damage or security intrusion, for which your telecommunications services provider is responsible, as well as for any failure of your telecommunications service provider to transmit any data, communications or settings in connection with your use of the Services. You are responsible for the security of your internet connection, including for the correct configuring of your information technology device and for using adequate virus protection software. You also acknowledge and agree that insofar as the Authenticator and the Services enable your interaction with the Financial Institution, Salt Edge disclaims any liability or responsibility for your inability to use the Services that is due to the actions, omissions, failure, inaccessibility or unavailability of the Financial Institution or of its services, websites, APIs, applications and other technology.

4.4. Acknowledgement. While Salt Edge will endeavor to ensure that the Services are available to you at any time during the term of this Agreement, we do not guarantee their continuous, uninterrupted or error-free operation and we shall not be liable to you if the Services are unavailable at any time for any reason. We may also temporarily restrict, suspend or deny access to the Services in case of: (i) emergency, Force Majeure, technical problems, system failure or degradation, scheduled or emergency maintenance, or an actual or suspected security incident; (ii) suspicious activity, fraud or other illegal actions with respect to the use of Authenticator and/or Services by you or attributable by you; or (iii) a request from your Financial Institution. The Services involve the Authenticator displaying and transmitting content that is not generated by Salt Edge, but is made available by the relevant Financial Institution. This content is the sole responsibility of the Financial Institution that makes it available.

4.5. Security Requirements. You are solely responsible for all activities and actions carried out from your mobile device via the Authenticator using the Authenticator Credentials. Any such activities and actions shall be deemed performed by you. You understand and acknowledge that, insofar as you use the Authenticator and the Services for the purpose of authenticating yourself towards your Financial Institution and/or authorizing Financial Account Actions, the security of your Financial Accounts relies, inter alia, on the safety of your Authenticator Credentials. You are solely responsible for maintaining the security of the Authenticator and Authenticator Credentials against any unauthorized access, use or disclosure. If you suspect that an unauthorized access to the Authenticator has occurred or that the Authenticator Credentials have been stolen, compromised or been made known to others, you must change them immediately.

4.6. Your Notification Obligations. You must immediately notify Salt Edge at authenticator@saltedge.com, if you suspect or become aware of an instance of unauthorized access to the Authenticator or of any loss, theft or unauthorized use or disclosure of your Authenticator Credentials. You should immediately notify of the same the respective Financial Institution(s) by means of the communication channels made available to you for such purpose. Salt Edge reserves the right to deny you access to the Services (or any part thereof) if Salt Edge reasonably believes that any loss, theft, or unauthorized use or disclosure of the foregoing information has occurred. Such denial of access may without limitation enable Salt Edge to investigate said loss, theft or unauthorized use or disclosure (including in cooperation with the law enforcement authorities).


5. NO PROCESSING OF PERSONAL DATA

In providing the Authenticator and the Services, Salt Edge does not collect, record, store, use, or otherwise process any of your personal data whatsoever, including without limitation any personal data available from your Financial Institution relating to your Financial Account. Any personal data involved in the provision of the Authenticator and the Services is either stored locally on your mobile device or transmitted by, or to, your Financial Institution, without it being accessed, retained or coming in any other manner into Salt Edge’s custody or control.


6. NO GUIDANCE OR PROFESSIONAL ADVICE

Any and all data, information and particulars regarding your Financial Account, Payment Transactions and any other Financial Account Actions made available to you through the Authenticator and/or the Services are provided by your Financial Institution. All such data and information is stored on your mobile device and transmitted by us as is, in encrypted form. Salt Edge does not generate, store, review, change, analyze or have control over such data and particulars, is not responsible for their completeness or accuracy and doesn’t, and does not profess to, offer guidance or induce you to act in a certain way in respect of the authorization requests received by you from the Financial Institution via the Authenticator. Any authentication, authorization, rejection or other action taken by you in the Authenticator with respect to the said requests is made at your sole risk and on your sole responsibility. Salt Edge is not authorized to give professional advice and is not in the business of providing legal, financial, accounting, taxation or other professional services or advice. You should independently verify and research, or take independent financial advice from a trusted and competent professional in connection with, any information or data contained in or made available through, or as a result of using, the Services and/or the Authenticator for the purpose of making any financial decisions or otherwise. Salt Edge expressly disclaims any liability, whether in contract, tort (including negligence) or otherwise, in respect of any damage, expense or other loss you may suffer arising out of such information or data, or any use of or reliance upon such information or data.


7. PROPRIETARY RIGHTS

All rights, title and interest in and to the Authenticator and the underlying technology, including all intellectual property rights therein, are and will remain with Salt Edge and its licensors. Salt Edge, Salt Edge Authenticator and all other trademarks, service marks, graphics and logos used in connection with the Authenticator and the Services are trademarks or registered trademarks of Salt Edge. Salt Edge does not grant you any right or license to use, copy or reproduce any intellectual property and trademarks of Salt Edge or the trademarks of any third party that may appear in the Authenticator and in connection with the Services.


8. FORCE MAJEURE

You hereby release Salt Edge from any liability arising from a delay in performance or non-performance by Salt Edge under this Agreement caused by Force Majeure. "Force Majeure" means any circumstances that are caused by acts or events beyond Salt Edge’s reasonable control, and could not be reasonably foreseen by Salt Edge, including without limitation acts of God, normative acts issued by state or government institutions, strikes, lock-outs, war or any kind of military operations, blockade, epidemics, acts or threats of terrorism, errors or outages of public or private telecommunications networks, etc.


9. CHANGES TO THE AGREEMENT AND SERVICES

9.1. Changes to the Agreement. Salt Edge reserves the right to change this Agreement at any time and from time to time to reflect changes in the applicable laws or regulations, technical or security requirements, the functionality of the Authenticator and/or the Services, or our business requirements. If we decide to change this Agreement in the future, we will post an appropriate notice at the top of this page. The changes to this Agreement will not apply retroactively and will take effect upon the expiry of fifteen (15) days from being posted, except that changes addressing new services or new functions of the Authenticator and changes made for legal reasons shall become effective immediately upon being posted. The date of the last update of this Agreement is set out at the top of this document. You acknowledge and agree that your continued access to and use of the Authenticator and the Services after the date of changes to this Agreement indicates your agreement to such changes.

9.2. Updates to the Services. Salt Edge may in its sole discretion and at any time update or modify the Authenticator and/or the Services, add or remove functions, discontinue, temporarily or permanently, providing the Services or any part thereof, including without limitation due to technical reasons, security issues, regulatory and legal requirements, or business reasons. Salt Edge may also perform maintenance of the Services from time to time which may result in interruptions, delays or errors in the Services. You acknowledge and agree that any maintenance, modification, suspension or termination of the Services may be effected without prior notice. You further acknowledge and agree that your continued use of the Services after the date of changes to the Services indicates your agreement to such changes.


10. TERM AND TERMINATION

10.1. This Agreement becomes effective when you install the Authenticator on your mobile device and remains in force until terminated by either party. We may terminate this Agreement at any time and for any reason by posting an appropriate notice at the top of this page, such termination to become effective upon the expiry of fifteen (15) days from being posted. You acknowledge and agree that Salt Edge in its sole discretion and without advance notice may immediately suspend or terminate this Agreement:

  1. if Salt Edge reasonably believes that you have breached any of the terms of this Agreement (including without limitation by using the Services to carry out fraud or other illegal or criminal activities). Depending on the type of your breach, we may take any and all actions as we reasonably deem appropriate and required or permitted by law, including without limitation notifying the competent law enforcement, government or regulatory bodies; or
  2. if we are required by applicable law or by a competent law enforcement, government or regulatory body.

10.2. You may terminate this Agreement at any time for any reason by deleting the Authenticator from your mobile device.

10.3. Upon termination of this Agreement: (i) you must cease all use of the Authenticator, the Services and any other activities or actions permitted under this Agreement, (ii) you must uninstall and delete the Authenticator from you mobile device; and (iii) all rights and licenses granted to you under this Agreement will be terminated.

10.4. Any termination of this Agreement (howsoever occasioned) shall not affect any accrued rights or liabilities of either party, nor shall it affect the coming into force or the continuance in force of any provision hereof which is expressly or by implication intended to come into or continue in force on or after such termination.


11. DISCLAIMER OF WARRANTIES

11.1. SUBJECT ALWAYS TO CLAUSE 11.2 AND CLAUSE 12.2, YOU ACKNOWLEDGE AND AGREE THAT TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAWS:

  1. SALT EDGE OFFERS THE AUTHENTICATOR AND THE SERVICES ON AN "AS IS" AND "AS AVAILABLE" BASIS AND DOES NOT ASSUME RESPONSIBILITY OR LIABILITY FOR ANY USE OF, OR RELIANCE ON, THE AUTHENTICATOR AND THE SERVICES, OR ANY INFORMATION PROVIDED THROUGH THE SERVICES, OR FOR THE RELIABILITY OF SUCH INFORMATION, OR FOR ANY DISRUPTIONS TO, OR DELAY IN, THE PROVISION OF THE SERVICES, OR FOR ANY PERFORMANCE OR NON-PERFORMANCE OF ANY OF YOUR FINANCIAL INSTITUTION’S WEBSITE, API OR SERVICES;
  2. SALT EDGE MAKES NO WARRANTIES OR REPRESENTATIONS, EXPRESS, STATUTORY OR IMPLIED, AS TO THE ACCURACY, TIMELINESS, COMPREHENSIVENESS, COMPLETENESS, QUALITY, FUNCTIONALITY, RELIABILITY, CURRENCY, ERROR-FREE NATURE, COMPATIBILITY, SECURITY, DATA LOSS, NON-INTERFERENCE WITH, OR NON-INFRINGEMENT OF, ANY INTELLECTUAL PROPERTY RIGHTS, OR FITNESS FOR A PARTICULAR PURPOSE OF THE AUTHENTICATOR AND THE SERVICES OR ANY INFORMATION PROVIDED THROUGH THE SERVICES; AND
  3. SALT EDGE DOES NOT GUARANTEE THE ADEQUACY OF THE SERVICES OR COMPATIBILITY AND SECURITY THEREOF TO YOUR COMPUTER EQUIPMENT AND DOES NOT WARRANT THAT THE SERVICES, THEIR INFRASTRUCTURE OR ANY COMMUNICATIONS TRANSMITTED VIA THE SERVICES WILL BE FREE OF VIRUSES OR SECURE AGAINST HACKING ATTACKS.

11.2. THE EXCLUSION OF THE WARRANTIES SET FORTH IN CLAUSE 11.1 SHALL APPLY TO THE MAXIMUM EXTENT ALLOWED BY THE APPLICABLE LAWS IN YOUR JURISDICTION.


12. LIMITATION OF LIABILITY

12.1. YOU ACKNOWLEDGE AND AGREE THAT, TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAWS, SALT EDGE SHALL NOT BE LIABLE, IN CONTRACT, TORT OR OTHERWISE, FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, PUNITIVE, RELIANCE, CONSEQUENTIAL OR EXEMPLARY DAMAGES, INCLUDING BUT NOT LIMITED TO DAMAGES FOR, RELATING TO OR ARISING FROM: (I) LOSS OF PROFITS, (II) LOSS OF USE; (III) DELAYS OR BUSINESS INTERRUPTIONS; (IV) FAILURE OF TELECOMMUNICATIONS, THE INTERNET, ELECTRONIC COMMUNICATIONS, (V) FAILURE OF ANY RELEVANT FINANCIAL INSTITUTION; (VI) LOSS OF BUSINESS REVENUE OR INVESTMENT, (VI) USE OF SOFTWARE OR HARDWARE THAT DOES NOT MEET SALT EDGE’S SYSTEM REQUIREMENTS, (VII) DAMAGE TO GOODWILL, REPUTATION, DATA OR OTHER INTANGIBLE LOSSES, AND/OR (VIII) THE USE OF, OR THE INABILITY TO USE, THE SERVICES. TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAWS, THE ABOVE LIMITATIONS APPLY EVEN IF SALT EDGE HAS BEEN ADVISED OF, OR SHOULD HAVE FORESEEN, OR HAD OTHER REASON TO KNOW, THE POSSIBILITY OF SUCH DAMAGES.

12.2. NOTHING IN THIS AGREEMENT IS INTENDED TO OR SHALL EXCLUDE OR LIMIT OUR LIABILITY: (I) FOR DEATH OF PERSONAL INJURY CAUSED BY OUR NEGLIGENCE, (II) FOR FRAUD AND/OR FRAUDULENT MISREPRESENTATION, (III) FOR OUR WILLFUL MISCONDUCT OR GROSS NEGLIGENCE, AND/OR (IV) WHICH CANNOT BE EXCLUDED, LIMITED, MODIFIED OR RESTRICTED UNDER THE APPLICABLE LAWS AND/OR REGULATIONS. ALL STATUTORY RIGHTS THAT ARE OR MAY BE AVAILABLE TO YOU RELATING TO THE PROVISION OF SERVICES UNDER THIS AGREEMENT SHALL NOT BE IMPAIRED OR AFFECTED.


13. INDEMNIFICATION

YOU AGREE TO INDEMNIFY, DEFEND AND HOLD SALT EDGE AND ITS OFFICERS, DIRECTORS, EMPLOYEES, AND SUPPLIERS HARMLESS FROM ALL LOSSES, DAMAGES, FINES, PENALTIES, COSTS AND EXPENSES (INCLUDING WITHOUT LIMITATION REASONABLE ATTORNEY’S FEES) INCURRED OR SUFFERED BY SALT EDGE AS A RESULT OF: (I) YOUR USE OF THE SERVICES, (II) A BREACH BY YOU OF ANY OF THE TERMS OF THIS AGREEMENT OR APPLICABLE LAWS, (III) YOUR INFRINGEMENT OF ANY INTELLECTUAL PROPERTY RIGHTS OR ANY OTHER RIGHTS OF THIRD PARTIES, AND/OR (IV) FRAUD COMMITTED OR FRAUDULENT MISREPRESENTATION MADE BY YOU.


14. LAWS AND JURISDICTION

This Agreement shall be governed by, and construed in accordance with, the laws of the Province of Ontario, and the federal laws of Canada, as applicable therein. Any dispute or claim arising out of, or in connection with, this Agreement and its existence, validity or termination (including non-contractual disputes or claims) shall be subject to the exclusive jurisdiction of the courts of the Province of Ontario.


15. GENERAL PROVISIONS

15.1. Entire Agreement. This Agreement constitutes the entire agreement and understanding between you and Salt Edge with respect to access to and use of the Authenticator and Services and replaces all prior understandings, communications and agreements, whether oral or written, regarding the subject matter hereof.

15.2. Severability. If any provision of this Agreement is held to be illegal, invalid, void or unenforceable, in whole or in part, by any court of competent jurisdiction, the remainder of the terms and provisions set forth herein shall remain in full force and effect and shall in no way be affected, impaired or invalidated thereby. Such illegal, invalid, void or unenforceable term or provision or part thereof shall be deemed modified to the extent required to render it enforceable in such jurisdiction, failing which, it shall be severed from this Agreement, which shall continue in full force and effect and be binding upon the parties hereof. The prohibition or unenforceability of a provision of this Agreement in any jurisdiction shall not invalidate such provision in any other jurisdiction.

15.3. Assignment. You cannot assign, sub-license or transfer any or all of your rights or obligations under this Agreement to anyone without Salt Edge’s prior written approval. However, Salt Edge in its sole discretion may assign or transfer this Agreement, in whole or in part, without your consent to a third party provided however that such assignment shall not affect your rights or our obligations to you under this Agreement.

15.4. Non-Waiver. No failure or delay on the part of either party in exercising any right, power or remedy under this Agreement shall operate as a waiver thereof, and no single or partial exercise of any such right, power or remedy shall preclude any other or further exercise thereof, or the exercise of any other right, power or remedy.

15.5. Third Parties. A person who is not a party to this Agreement cannot enforce or enjoy the benefit of any term or provision of this Agreement.

15.6. Headings. The headings and captions used in this Agreement are used for convenience only and are not to be considered in construing or interpreting this Agreement.


16. COMPLAINTS AND ENQUIRIES

In case of any questions or complaints regarding this Agreement, Authenticator or the Services, please contact our customer support team at authenticator@saltedge.com.