All systems operational
00:00:00:00
ONEKYC // Legal
DOC_TYPE: USER_AGREEMENT

User Agreement

Version: 1.0Revision: 2026-08-14Effective: 2026-08-14Language: EN

This User Agreement governs the use of the ONEKYC KYC platform (SaaS) for business and constitutes a public offer of Finext Technology Ltd.

00

General Provisions

Version dated August 14, 2026 The Agreement constitutes the contractual terms of use of the Platform as published by the Operator. Any person who registers on the Platform, confirms their registration, clicks the button to accept the terms, subscribes, or otherwise begins actively using the Platform, thereby accepts the Agreement and enters into a contract with the Operator on the terms set forth below. The Platform is intended primarily for legal entities, sole proprietors, and other persons using it in connection with their business, professional, or occupational activities. Use of the Platform by an individual for personal, family, or household purposes is permitted only with the express prior consent of the Operator. The Agreement shall be governed by the laws of the DIFC, including the Contract Law, DIFC Law No. 6 of 2004 (as amended), the Electronic Transactions Law, DIFC Law No. 2 of 2017 (as amended), the Intellectual Property Law, DIFC Law No. 4 of 2019 (as amended), the Data Protection Law, DIFC Law No. 5 of 2020 and the relevant Data Protection Regulations, as well as any other mandatory provisions of the laws of the United Arab Emirates applicable within the DIFC and to the relevant relationships.

00

Terms And Definitions

Acceptance

the User's full and unconditional acceptance of the terms of the Agreement by performing actions expressly provided for by the Agreement, including registration, confirmation of consent through the interface, subscribing, or actual use of the Platform.

User Data

any information, documents, images, data, and other materials that the User, their employees, representatives, or systems integrated by the User upload, transmit, input, or otherwise provide through the Platform.

Counterparty

an individual, a legal entity, a sole proprietor, a beneficial owner, a representative, or any other person subject to verification by the User through the Platform.

Personal Account

a secured section of the Platform designed for User identification, account management, settings, Services, subscriptions, verification results, and integrations.

Operator

Finext Technology Ltd, registration no. 14021, incorporated in the Dubai International Financial Centre (DIFC), Dubai, UAE.

Platform / Software Suite

The OneKYC KYC platform (SaaS) for businesses, including the web interface, API, software modules, and other technical means provided by the Operator; functionality may include document verification, selfie/face matching, liveness checks, AML/sanctions screening, external source checks, manual review, and other features described on the website https://onekyc.io and/or within the Personal Account.

Policy

Personal Data Processing Policy of Finext Technology Ltd, published on the website https://onekyc.io, as currently in effect.

User

A legal entity, sole proprietor, or individual acting in connection with entrepreneurial, professional, or official activities who has entered into the Agreement through Acceptance. Where access is granted to an employee or representative of an organization, the organization itself shall be deemed the User, and the actions of its authorized representative shall be deemed the actions of the User.

Registration

A set of actions required to create an account and gain access to the Personal Account.

Access credentials

a login, password, OTP code, API key, token, authentication key, multi-factor authentication method, or any other identifier that provides access to the Platform.

Service

a distinct feature or set of features of the Platform available to the User in accordance with a pricing plan, order, subscription, or separate agreement.

Communication Tools

Personal account, email, online chat, feedback forms, phone, messaging apps, and other electronic communication channels agreed upon by the Parties.

Third-party sources

Government and commercial registries, sanctions lists, databases, and providers of identity verification, AML/KYC, information, cloud, and other services from which the Platform retrieves or against which it cross-references data.

Governing Law

DIFC law and the mandatory provisions of UAE legislation applicable to the Operator, the User, the Platform, or a specific transaction.

01

Subject Matter

1.1. The Operator grants the User a limited, non-exclusive, non-transferable, and non-sublicensable right to access the Platform and use the available Services for the duration of the Agreement and within the scope of the selected tariff, subscription, order, or separate contract.

1.2. The right to use the Platform is granted solely for the User's internal lawful business purposes, including, without limitation, KYC/KYB checks, identity verification, document verification, fraud prevention, compliance risk management, and other permissible due diligence procedures.

1.3. This Agreement does not entail the transfer of any exclusive rights to the Operator's or its licensors' software, databases, designs, documentation, trademarks, algorithms, models, source code, or any other intellectual property to the User.

1.4. The specific composition of the Services, limits, pricing, payment terms, SLA, and additional conditions may be governed by a tariff plan, commercial proposal, order, invoice, separate agreement, Data Processing Agreement (DPA), or any other document agreed upon by the Parties. In the event of a conflict between a specific document and the Agreement, the specific document shall prevail with respect to its relevant subject matter.

02

Platform Terms OF Use

2.1. The Platform is a technological tool and may generate verification results, matches, risk indicators, scores, statuses, and other conclusions based on User Data, verification settings, and information obtained from Third-Party sources.

2.2. The Platform's results do not constitute a legal opinion, nor a guarantee of the Counterparty's identity, solvency, good faith, or the legality of its activities, and shall not substitute the User's independent assessment of the requirements of applicable law, internal policies, and risk appetite.

2.3. The User independently determines whether the information obtained is sufficient to make a decision to initiate, continue, restrict, or terminate a relationship with a Counterparty. Unless expressly provided otherwise by a separate agreement, the Operator does not make final decisions on behalf of the User regarding client onboarding, AML/KYC, sanctions compliance, refusal of service, or the establishment of business relationships.

2.4. The User is obligated to use the Platform in accordance with Applicable Law, the Agreement, the Policy, and the Operator's documentation and technical guidelines.

2.5. The description of Services and technical requirements may be updated by the Operator in accordance with the development of the Platform, changes in Third-Party sources, security requirements, and applicable legislation.

2.6. The Operator may impose quantitative, technical, time-based, and territorial restrictions on the use of certain features, APIs, or Services where such restrictions are stipulated by the applicable pricing plan, required for security purposes, mandated by data provider requirements, or prescribed by Applicable Law.

2.7. To ensure proper functionality, the User is required to use supported browsers, operating systems, authentication tools, and other technical means. The Operator does not guarantee proper functionality when outdated, modified, or incompatible software is used.

03

Registration ON The Platform

3.1. To access features that require User identification, the User shall complete Registration and provide the requested information. The Operator may make limited functionality available without Registration.

3.2. The User is required to provide complete, accurate, up-to-date, and non-misleading information. Submitting forged documents, details of a non-existent person, someone else's contact information, or any other knowingly false information is prohibited.

3.3. When registering via email, verification may be carried out through a link, a code, or another form of electronic confirmation. When registering via phone number, the Operator may use a one-time password (OTP code).

3.4. The Operator may request additional information and documents regarding the User, their representatives, beneficial owners, the nature of their activities, and the source and anticipated scope of Platform usage, where such information is necessary for security purposes, risk management, compliance with Applicable Law, or obligations under agreements with Third-Party sources.

3.5. The Operator reserves the right to deny Registration or activation of individual Services if there are reasonable grounds to believe that use of the Platform may violate Applicable Law, sanctions restrictions, third-party rights, or information security requirements, or may create an unacceptable risk to the Operator, the Platform, or other users.

04

Personal Account And Access Security

4.1. The User has the right to create employee and representative accounts within the available functionality and is responsible for assigning them the appropriate roles and access rights.

4.2. All actions performed through the User's account using valid Access Credentials shall be deemed to have been performed by the User or a person authorized by the User, unless the User has notified the Operator of the compromise of the Access Credentials and unless otherwise determined as a result of an incident investigation.

4.3. The User shall maintain the confidentiality of Access Credentials, apply reasonable information security measures, refrain from sharing individual accounts with third parties, and enable multi-factor authentication where such a feature is available or required.

4.4. The User shall promptly notify the Operator of any suspected unauthorized access, compromise of Access Credentials, API key leakage, unusual activity, malicious interference, or any other incident related to the Platform.

4.5. The Operator reserves the right to temporarily suspend Access Credentials, forcibly terminate active sessions, require a password change, revoke API keys, or take other security measures if there are signs of compromise or a threat to the Platform.

05

Representations And Obligations OF The Parties

5.1. The Operator warrants that it holds the necessary rights to grant the User access to the Platform to the extent set forth in the Agreement, or that it uses the relevant components on a lawful basis.

5.2. The User represents and warrants that the individual accepting on behalf of the organization has the requisite authority and is duly authorized to bind the User to the terms of the Agreement.

5.3. The User confirms that they have familiarized themselves with the purpose and core functional characteristics of the Platform, and that use of the Platform is consistent with their business objectives.

5.4. If the User provides Data belonging to Counterparties or other third parties, the User warrants that there is a lawful basis for obtaining, using, transferring to the Operator, and otherwise processing such Data, and that any notification obligations owed to the relevant individuals have been fulfilled where required by law.

5.5. When submitting photographs, selfies, video recordings, liveness/face matching data, identity documents, or any other data that may constitute special categories of personal data, the User is obliged to ensure that an appropriate legal basis exists and that all requirements applicable to such processing are met.

5.6. The User shall ensure that their personal data processing instructions, verification settings, source data inputs, and subsequent use of the Platform's outputs are lawful.

5.7. The User is solely responsible for ensuring compliance with the laws and internal requirements applicable to its operations, including AML/CFT requirements, sanctions compliance, personal data protection, non-discrimination, and labor, financial, and industry regulations.

06

Prohibited Actions

The User is prohibited from:

6.1. use the Platform for unlawful purposes or to facilitate fraud, sanctions evasion, money laundering, terrorist financing, unlawful surveillance, harassment, or any other illegal activity;

6.2. to obtain or process information about individuals without the required legal basis, including uploading personal data that is not relevant to the legitimate purpose of the verification;

6.3. to transfer individual Access Credentials to unauthorized persons, grant access to the Platform to third parties outside the agreed usage model, or resell access without the Operator's prior written consent;

6.4. engage in web scraping, parsing, automated data extraction, bulk copying of results, or any other actions that go beyond the documented API or functionality expressly authorized in writing by the Operator;

6.5. circumvent technical limits, authentication mechanisms, rate restrictions, geographic restrictions, security protection measures, or monitoring systems;

6.6. introduce malicious code, generate excessive load, conduct unauthorized vulnerability scanning, penetration testing, DoS/DDoS attacks, or any other actions that may disrupt the operation of the Platform;

6.7. decompile, disassemble, reverse engineer, attempt to obtain the source code, copy, or create derivative works based on the Platform, except where such right cannot be expressly restricted under Applicable Law;

6.8. to impersonate another person, use forged documents, falsify verification results, manipulate liveness check procedures, or otherwise deceive the Platform, the Operator, or any third parties;

6.9. use VPN, proxy, or any tools designed to conceal or spoof network parameters for the purpose of circumventing security requirements, geographic restrictions, or any other control measures established by the Operator;

6.10. remove or alter copyright notices, trademarks, database rights, or any other proprietary rights designations;

6.11. use the trademarks, trade name, logos, or other means of identification of the Operator without authorization, except as expressly permitted by law;

6.12. use the Platform's outputs as the sole basis for decisions that could significantly affect the rights of an individual, where such practice is prohibited by applicable law or requires additional safeguards, human oversight, or an appeals process.

07

Liability

7.1. Each Party shall be liable for any breach of the Agreement in accordance with its terms and Applicable Law.

7.2. In the event that the User violates the requirements of Section 6, intellectual property rights, security rules, or data protection obligations, the Operator shall be entitled, depending on the nature of the violation, to restrict or suspend access, demand that the violation cease, require the removal of unlawfully obtained materials, seek compensation for documented losses and expenses, and pursue any other legal remedies available under Applicable Law.

7.3. The User agrees to indemnify the Operator for any reasonable, documented losses, expenses, and third-party claims arising directly from the User's unlawful instructions, unlawful transfer of personal data, violation of third-party rights, or use of the Platform in breach of the Agreement, provided that such losses are not attributable to any breach on the part of the Operator.

7.4. The Operator shall not be liable for any decisions made by the User based on the results generated by the Platform, unless the relevant result was distorted as a consequence of a proven breach of the Operator's contractual obligations.

7.5. Nothing in the Agreement shall exclude or limit liability for fraud, willful misconduct, or any other liability to the extent that its exclusion or limitation is not permitted under Applicable Law.

08

Limitation OF Liability And Warranties

8.1. Unless expressly stated otherwise in a separate agreement, the Platform is provided on an "as is" and "as available" basis. The Operator takes reasonable measures to maintain the performance and security of the Platform; however, it does not guarantee uninterrupted or error-free operation, or the availability of any Third-Party Source at any given time.

8.2. The Operator does not guarantee the absolute accuracy, completeness, or currency of data obtained from Third-Party sources, nor does it guarantee the absence of false positive or false negative matches in automated checks. The User is obligated to take into account the nature of the source and, where necessary, conduct additional verification.

8.3. The Operator does not guarantee that the use of the Platform, in and of itself, will ensure the User's full compliance with all AML/KYC requirements, sanctions regulations, industry-specific regulations, or any other regulatory requirements applicable in a particular jurisdiction.

8.4. To the maximum extent permitted by Applicable Law, the Operator shall not be liable for any indirect, special, consequential, or punitive damages, or any loss of profits, revenue, business opportunity, anticipated savings, or goodwill, arising out of or in connection with the use of or inability to use the Platform.

8.5. Unless otherwise provided by a separate agreement, the Operator's total liability for all claims arising during any consecutive twelve-month period in connection with the Agreement shall be limited to the amount of fees actually paid by the User to the Operator for the Platform during the twelve months immediately preceding the event giving rise to liability.

8.6. The Operator shall not be liable for failures, limitations, or disruptions affecting communication networks, equipment, software, cloud infrastructure, data providers, or any other third parties beyond the Operator's reasonable control.

8.7. The Parties shall be released from liability for failure to perform their obligations due to circumstances beyond the reasonable control of the respective Party, including natural disasters, war, acts of terrorism, civil unrest, epidemics, widespread communications outages, large-scale cyberattacks, actions of governmental authorities, sanctions restrictions, or other force majeure events, provided that reasonable measures have been taken to mitigate the consequences thereof.

09

Suspension OF Access And Deletion OF Personal Account

9.1. The Operator reserves the right to temporarily restrict or suspend access to the Platform, in whole or in part, in the event of a breach of the Agreement, overdue payment, a security threat, suspected fraud or unlawful use, a requirement issued by a competent authority, the application of sanctions, or the need to prevent harm to the Platform or third parties.

9.2. If the violation can be remedied and immediate suspension is not required for security or legal reasons, the Operator may grant the User up to 3 (three) business days, or such other reasonable period, to remedy the violation.

9.3. The Operator reserves the right to terminate access and delete the Personal Account in the event of a material or repeated breach of the Agreement, failure to remedy the breach within the provided timeframe, expiration of a paid subscription, inability to lawfully continue providing the Services, or upon the User's request.

9.4. The termination or deletion of a Personal Account does not imply the unconditional and immediate destruction of all data. Data is deleted, returned, anonymized, or retained in accordance with the Policy, the terms of the DPA, retention requirements, applicable law, security needs, and the protection of legitimate claims.

9.5. If a data export feature is available, the User is responsible for downloading any materials they need prior to the termination of access. The Operator is not obligated to retain data beyond the established retention period unless otherwise required by law or a separate agreement.

9.6. Provisions that by their nature are intended to survive the termination of the Agreement, including those relating to intellectual property, confidentiality, liability, limitation of liability, data protection, and dispute resolution, shall remain in full force and effect following termination.

10

Electronic Document Management And Communications

10.1. The Parties recognize the legal validity of electronic documents, electronic messages, Personal Account records, confirmations via link, OTP code, electronic signature, and other electronic means, to the extent permitted by the Electronic Transactions Law, DIFC Law No. 2 of 2017, and any other Applicable Law.

Acceptance of the Agreement, order confirmation, modification of settings, submission of a request, provision of an instruction, or any other action performed in the Personal Account using Access Credentials may be used as evidence of the intent of the respective Party.

10.3. The Parties may exchange documents and information through the Personal Account and Communication Tools. Scanned copies and electronic versions of documents may be used prior to the submission of originals, where an original is required by law or under a separate agreement.

10.4. The User is obligated to ensure the security of the email addresses, phone numbers, messenger accounts, and any other communication channels they have registered for the purpose of contacting the Operator.

10.5. A message from the Operator shall be deemed received by the User upon its posting in the Personal Account, or upon dispatch to the User's last provided email address or other agreed communication channel, unless the Operator receives an automated non-delivery notification.

10.6. The Operator may send service and legally significant notifications related to the account, security, changes to terms, or Services. Marketing communications are sent in accordance with applicable requirements and the opt-out settings available to the User.

11

Personal Data And Counterparty Data

11.1. The Operator processes personal data in accordance with the DIFC Data Protection Law, DIFC Law No. 5 of 2020, the Data Protection Regulations, and the Policy, and, where applicable, in compliance with any other mandatory data protection requirements.

11.2. With respect to registration, contact, payment, contractual, technical, and other data relating to the User, their representatives, and employees — where the Operator determines the purposes and means of processing for the administration of the relationship, security, billing, support, and legal compliance — the Operator acts as a Controller within the meaning of DIFC data protection legislation.

11.3. With respect to the personal data of Counterparties and other third parties that the User submits to the Platform for verification purposes in accordance with the User's instructions, the User generally determines the purposes of such processing and acts as the Controller, while the Operator processes such data as a Processor on behalf of the User, unless a different role expressly follows from the nature of a specific operation, applicable law, or a separate agreement.

11.4. The User shall ensure that a lawful basis exists for the transfer and processing of Counterparty data, provide the necessary notices to data subjects, comply with the principles of data minimization and purpose limitation, and refrain from instructing the Operator to carry out any processing that violates Applicable Law.

11.5. Where necessary, the Parties shall enter into a separate DPA setting out the subject matter, duration, nature, and purposes of processing, the categories of data and data subjects, security measures, procedures for engaging subprocessors, assistance in the exercise of data subject rights, incident notification procedures, data return and deletion procedures, and any other mandatory provisions.

11.6. The Operator may engage providers of cloud infrastructure, communications, identity, AML/KYC, analytics, and other services as processors/subprocessors in accordance with the Policy, DPA, and Applicable Law.

11.7. Cross-border transfers of data outside the DIFC are carried out in accordance with the requirements of the DIFC Data Protection Law, including applicable adequacy mechanisms, contractual safeguards, and other permitted grounds.

11.8. The User acknowledges that identity verification may involve the processing of facial images, selfies, videos, liveness checks/face matching, and other biometric indicators. To the extent that such data qualifies as Special Category Personal Data or is used to uniquely identify an individual, the Parties are required to comply with the additional obligations set forth under Applicable Law.

11.9. The procedures for storage, deletion, international transfer, exercise of data subject rights, use of cookies, and incident response are set out in detail in the Policy and, where applicable, the DPA.

12

Procedure For Handling Requests

12.1. For any questions regarding the functioning of the Platform, the User may contact the Operator by email at info@onekyc.io or through the available feedback form.

12.2. The Operator reserves the right to request information necessary to identify the User and verify their authority, as well as any information, logs, screenshots, or documents required to address a technical, contractual, or compliance matter.

12.3. Requests are handled within a reasonable timeframe, taking into account their complexity, priority, the need to engage with Third-Party sources, and the overall volume of incoming requests. A specific SLA applies only if it has been expressly agreed upon by the Parties.

12.4. The Operator reserves the right not to provide a substantive response to repeated inquiries for which a comprehensive reply has already been given and no new circumstances have arisen, to messages containing knowingly false information, malicious content, threats, or offensive language, as well as to requests that fall outside the Operator's scope of competence.

12.5. Requests from data subjects are handled on a case-by-case basis in the manner and within the timeframes established by applicable data protection legislation and the Policy.

13

Governing Law And Dispute Resolution

13.1. This Agreement, its formation, validity, interpretation, performance, termination, and any non-contractual obligations arising out of or in connection with it shall be governed by the laws of the Dubai International Financial Centre (DIFC), without regard to its conflict of laws rules that would result in the application of the laws of any other jurisdiction.

13.2. Prior to initiating court proceedings, a Party shall submit a written claim to the other Party. The Party receiving the claim shall have the right to provide a response within 10 (ten) business days, unless a longer period is objectively required to investigate the circumstances.

13.3. Any dispute, disagreement, claim, or demand arising out of or in connection with the Agreement, including any questions relating to its existence, validity, interpretation, performance, breach, termination, and available remedies, shall be subject to the exclusive jurisdiction of the Courts of the Dubai International Financial Centre (DIFC Courts).

13.4. Nothing in this Section shall limit the Operator's right to seek urgent interim or injunctive relief from a court of competent jurisdiction where necessary to protect the Operator's confidential information, intellectual property, data, or the security of the Platform.

14

Term And Amendment OF The Agreement

14.1. The Agreement enters into force upon Acceptance and remains in effect until terminated by the User or the Operator in accordance with its terms.

14.2. A User who does not agree to the terms of the Agreement is not permitted to use the Platform and must discontinue its use. For a registered User, discontinuing use does not in itself cancel any payment, contractual, or other obligations that have already arisen.

14.3. The Operator reserves the right to amend the Agreement in connection with the development of the Platform, changes to the business model, security requirements, Third-Party Sources, or applicable legislation. The Operator shall notify users of any material changes via the Platform, by email, or through any other reasonable means.

14.4. If a change is required to comply with applicable law, address a security threat, prevent abuse, or fulfill a binding requirement of a competent authority, it may take effect immediately. In all other cases, material changes shall take effect on the date specified by the Operator in the notice or updated version.

14.5. Continued use of the Platform after the changes take effect constitutes the User's acceptance of the updated terms. If the User does not agree with the changes, they must discontinue use of the Platform and, if a subscription is active, submit a termination notice in accordance with the applicable pricing plan or separate agreement.

14.6. The invalidity or unenforceability of any individual provision of the Agreement shall not affect the validity of the remaining provisions. Any invalid provision shall, to the maximum extent permitted, be interpreted or replaced in a manner that most closely achieves the original commercial intent of the Parties.

15

Final Provisions

15.1. The Operator reserves the right to modify the domain name, interface, architecture, and individual components of the Platform while preserving the core functionality of the paid-for Services, unless otherwise stipulated by a separate agreement.

15.2. The Operator reserves the right to carry out scheduled and unscheduled maintenance work. Where possible, the Operator will provide advance notice of any work that may significantly affect the availability of paid-for Services.

15.3. This Agreement does not create between the Parties any partnership, joint venture, agency, employment, or fiduciary relationship, except as expressly established by a separate written agreement.

15.4. The User may not assign this Agreement or transfer access rights to any third party without the prior written consent of the Operator. The Operator may assign this Agreement to an affiliate, successor, or acquirer of the relevant business or assets, provided that applicable data protection requirements are met and the User is notified where such notification is required.

15.5. The failure to exercise or any delay in exercising any right under the Agreement shall not constitute a waiver of such right.

15.6. This Agreement, together with the Policy, the applicable tariff, the order, the DPA, and any other expressly incorporated documents, constitutes the entire understanding of the Parties with respect to the subject matter of the use of the Platform and supersedes all prior understandings relating to the same subject matter, unless otherwise provided by a separately executed agreement.

15.7. Any matters not governed by the Agreement shall be resolved in accordance with the Applicable Law.

15.8. The current version of the Agreement is available at https://onekyc.io or in any other section of the Platform as designated by the Operator.

16

Operator Details

Name: Finext Technology Ltd

Registration number: 14021

Registered Address: IH-00-01-02-OF-01, Level 2, Innovation One, Dubai International Financial Centre (DIFC), Dubai, United Arab Emirates

It looks like you've shared a website URL, but haven't provided any text to translate. Could you please paste the specific text you'd like translated into English? I'll get right on it!

Email: info@onekyc.io

[ End of document · REV 2026-08-14 ]