Platform terms

Terms of Use

Fraudcheck (Pty) Ltd — Effective 01 July 2026

These Terms govern access to and use of the Fraudcheck Platform and Services. By accessing the Platform or using any Services, the User is deemed to have accepted these Terms in their entirety.

Important Notice

These Terms are published by Fraudcheck and take effect from the Effective Date.

These Terms govern access to and use of the Platform and Services.

By accessing the Platform or using any Services, the User is deemed to have accepted these Terms in their entirety.

No separate signature or tick-box confirmation is required.


01

Definitions

  • 1.1In these Terms, unless the context indicates a contrary intention, the following words bear the meanings assigned to them, and cognate expressions bear corresponding meanings:
  • 1.1.1"Account" means the User profile, login credentials and associated configuration used to access the Platform;
  • 1.1.2"Additional Services" means any new products, checks, verification services or data offerings introduced by Fraudcheck from time to time, beyond the Services described at registration;
  • 1.1.3"AML" means anti-money laundering as regulated under FICA and related legislation;
  • 1.1.4"API" means an application programming interface made available by Fraudcheck to allow system integration with the Platform;
  • 1.1.5"Applicable Laws" means all laws, regulations, regulatory directives, codes of practice, court orders and legally binding requirements applicable to the use of the Services, including without limitation the NCA, POPIA, FICA, the ECT Act, the Consumer Protection Act 68 of 2008, the Financial Sector Regulation Act 9 of 2017, and all regulations promulgated thereunder, as amended from time to time;
  • 1.1.6"Authorised Prescribed Purpose" means a Prescribed Purpose assigned to and activated on a User's Account by Fraudcheck at onboarding or subsequently, as further described in clause 10.2;
  • 1.1.7"Biometric Data" means personal information relating to the physical, physiological or behavioural characteristics of a Data Subject that allows for the unique identification of that person, including facial geometry, facial images processed for Liveness Detection, fingerprints, voice patterns and other biometric identifiers Processed through the Platform;
  • 1.1.8"Business Client" has the meaning assigned to it in clause 5.1;
  • 1.1.9"Business Day" means any day that is not a Saturday, Sunday or public holiday in South Africa;
  • 1.1.10"Confidential Information" means any non-public information disclosed by the Disclosing Party to the Receiving Party in connection with the Platform or Services, whether in written, electronic, oral or other form, including without limitation technical information, software, algorithms, system architecture, pricing, business information, security procedures, Personal Information, User Data, Outputs, Consumer Credit Information, trade secrets, methodologies, customer lists, contractual terms and any information relating to the Platform or Services that is by its nature confidential or ought reasonably to be regarded as confidential;
  • 1.1.11"Consumer Credit Information" bears the meaning set out in section 70(1)(a) to (d) of the NCA and Regulation 18(6), and includes consumer information supplied as part of the Credit Bureau Services;
  • 1.1.12"Consumer Redress Process" means the process described in clause 12 for consumers who dispute the accuracy, currency or fairness of Consumer Credit Information;
  • 1.1.13"Credit Bureau Association" means the industry body established to represent registered credit bureaux in South Africa;
  • 1.1.14"Credit Bureau Services" means the provision of Consumer Credit Information by a credit bureau for the purpose of enabling the evaluation of a consumer's credit profile, including their credit history, repayment conduct, and financial obligations, which are subject to the additional due diligence requirements in clause 15;
  • 1.1.15"Credit Regulatory Framework" means all legislation and law applicable to credit bureaux, credit providers, Consumer Credit Information and Personal Information, including without limitation the NCA, the regulations thereunder, the requirements of the Credit Bureau Association, the Credit Ombud, the South African Credit and Risk Reporting Association, POPIA, and any other legislation enacted or amended from time to time;
  • 1.1.16"Data Subject" means the natural or juristic person whose Personal Information is Processed through the Services;
  • 1.1.17"Disclosing Party" means the Party disclosing Confidential Information to the Receiving Party;
  • 1.1.18"ECT Act" means the Electronic Communications and Transactions Act 25 of 2002;
  • 1.1.19"Enterprise Client" has the meaning assigned to it in clause 5.2;
  • 1.1.20"Existing Account" has the meaning assigned to it in clause 6.2;
  • 1.1.21"Existing Commercial Terms" has the meaning assigned to it in clause 3.3;
  • 1.1.22"FIC" means the Financial Intelligence Centre established under FICA;
  • 1.1.23"FICA" means the Financial Intelligence Centre Act 38 of 2001, as amended;
  • 1.1.24"Force Majeure Event" has the meaning assigned to it in clause 33.1;
  • 1.1.25"Fraudcheck" means Fraudcheck Proprietary Limited (registration number 2013/031750/07), a private company incorporated under the laws of South Africa and a Tier 2 registered credit bureau (NCR registration number: NCRCB65);
  • 1.1.26"Information Officer" means the person designated by Fraudcheck as its Information Officer under POPIA, as further described in clause 8;
  • 1.1.27"Information Regulator" means the Information Regulator established under POPIA;
  • 1.1.28"Intellectual Property" means all intellectual property rights including without limitation patents, inventions, copyright, trade marks, service marks, trade names, domain names, designs, rights in computer software, database rights, know-how, trade secrets and all other intellectual property rights, whether registered or unregistered, and all applications and renewals thereof;
  • 1.1.29"KYC" means know-your-customer processes including identity verification, document verification, Liveness Detection, biometric matching, sanctions screening and related compliance checks;
  • 1.1.30"Liveness Detection" means automated or assisted processes used to verify that a selfie or video is of a live person and not a photograph, mask or other spoofing attempt;
  • 1.1.31"NCA" means the National Credit Act 34 of 2005, as amended, and all regulations promulgated thereunder;
  • 1.1.32"NCR" means the National Credit Regulator established under the NCA;
  • 1.1.33"New Account" has the meaning assigned to it in clause 6.1;
  • 1.1.34"Operator" means a person who Processes Personal Information on behalf of a Responsible Party, as defined in POPIA;
  • 1.1.35"Outputs" means verification results, Credit Bureau Services reports, KYC reports, identity verification results, screening results, compliance checks, background verification results or other information made available through the Services, which may include information obtained from Third-Party Providers;
  • 1.1.36"Parties" means Fraudcheck and the User collectively, and "Party" means either one of them as the context indicates;
  • 1.1.37"Personal Information" means personal information as defined in POPIA, and includes any information relating to an identifiable, living natural person and, where applicable, an identifiable juristic person;
  • 1.1.38"Platform" means Fraudcheck's web application, portal, APIs, mobile interfaces and related systems through which the Services are delivered;
  • 1.1.39"Platform Availability" has the meaning assigned to it in Annexure A;
  • 1.1.40"POPIA" means the Protection of Personal Information Act 4 of 2013, as amended;
  • 1.1.41"Primary User" means, where the User is an entity, the individual designated by that entity from time to time as the primary representative responsible for managing the Account on its behalf;
  • 1.1.42"Prime Rate" means the prime overdraft rate of interest quoted by the major South African commercial banks from time to time;
  • 1.1.43"Prescribed Purpose" means a purpose for which a User is authorised to use Consumer Credit Information as set out in Regulation 18(4), Regulation 23A or the Credit Regulatory Framework;
  • 1.1.44"Processing" or "Process" has the meaning assigned in POPIA and includes any operation or set of operations concerning Personal Information, whether automated or not;
  • 1.1.45"Receiving Party" means the Party receiving Confidential Information from the Disclosing Party;
  • 1.1.46"Responsible Party" means a public or private body or any other person that, alone or in conjunction with others, determines the purpose of and means for Processing Personal Information, as defined in POPIA;
  • 1.1.47"Services" means the information and verification services provided by Fraudcheck through the Platform, as further described in clause 7. All Services are accessible upon registration, save that Credit Bureau Services are subject to the additional requirements in clause 15;
  • 1.1.48"South Africa" means the Republic of South Africa;
  • 1.1.49"Terms" means these Platform Terms of Use, together with all annexures and schedules, as updated from time to time;
  • 1.1.50"Third-Party Providers" means all external entities engaged by Fraudcheck from time to time to support the delivery of the Services, including without limitation registered credit bureaux, authorised identity verification and biometric processing providers, government databases, telecommunications providers and other external data sources. The identity of Third-Party Providers is available on written request where required by Applicable Laws;
  • 1.1.51"Unscheduled Downtime" has the meaning assigned to it in Annexure A;
  • 1.1.52"User" means the entity or individual that registers for and uses an Account. Where the User is an entity, the Primary User manages the Account on its behalf and all actions taken through the Account are binding on the entity;
  • 1.1.53"User Data" means all data and information (including Personal Information) submitted to or made available to Fraudcheck by or on behalf of the User in connection with the Services;
  • 1.1.54"VAT" means value-added tax as defined in the Value-Added Tax Act 89 of 1991.

02

Interpretation

  • 2.1In these Terms:
  • 2.1.1clause headings are for convenience only and do not affect interpretation;
  • 2.1.2references to the singular include the plural and vice versa;
  • 2.1.3references to a gender include all genders;
  • 2.1.4references to natural persons include juristic persons and vice versa;
  • 2.1.5the word "including" is not to be construed so as to limit the ambit of the provision concerned;
  • 2.1.6all amounts are exclusive of VAT unless stated otherwise;
  • 2.1.7a reference to any statute includes that statute as amended or re-enacted from time to time;
  • 2.1.8the contra proferentem rule shall not apply;
  • 2.1.9the eiusdem generis rule shall not apply; and
  • 2.1.10in the event of any conflict between these Terms and any annexure, the terms of the applicable annexure shall prevail in respect of the specific subject matter of that annexure, and these Terms shall prevail in respect of all other matters.

03

Application and Supersession of Prior Agreements

  • 3.1These Terms govern access to and use of the Platform and Services by all Users and constitute the entire and exclusive agreement between Fraudcheck and the User in respect of the subject matter hereof.
  • 3.2These Terms expressly supersede, replace and extinguish all prior versions of Fraudcheck’s terms of use, agreements, terms of service, service level agreements, data use or processing agreements, subscriber agreements, commercial arrangements, memoranda of understanding and all other written or oral understandings between the Parties relating in any way to the Platform or Services ("Prior Agreements"). No Prior Agreement that is not expressly preserved under clause 3.3 or incorporated in these Terms shall have any force or effect as between the Parties.
  • 3.3Notwithstanding clause 3.2, where an Existing Account has a documented and agreed commercial arrangement with Fraudcheck that was in effect prior to the Effective Date ("Existing Commercial Terms"), those Existing Commercial Terms shall continue to apply to that Existing Account solely in respect of the agreed transaction volumes, pricing and payment terms, and are not superseded by these Terms. All other aspects of the prior relationship between the Parties are superseded. For the avoidance of doubt, any undocumented, unsigned or unconfirmed arrangements do not constitute Existing Commercial Terms for the purposes of this clause.

04

Acceptance of Terms

  • 4.1These Terms are accepted without a separate signature or tick-box. By taking any of the following actions, a User is conclusively deemed to have read, understood and accepted these Terms in their entirety:
  • 4.1.1proceeding with or completing the Account registration process (including the enterprise registration pathway);
  • 4.1.2clicking any link sent by Fraudcheck to finalise, activate or migrate an Account;
  • 4.1.3accessing or using the Platform or Services in any manner; or
  • 4.1.4integrating with the Platform via API.
  • 4.2Users with Existing Accounts who receive a migration link are required to accept these Terms as a condition of continued access. Proceeding with migration or accessing the updated Platform constitutes acceptance.

05

Account Types

  • 5.1A Business Client accesses the Platform on Fraudcheck's standard commercial terms. Fees are charged on a per-transaction basis at Fraudcheck's standard rates, as notified to the User in a pricing addendum or other commercial documentation provided at or following registration. The standard payment terms and the service levels set out in these Terms, including Annexure A, apply to Business Clients and are not subject to negotiation. Fraudcheck may revise the standard rates from time to time in accordance with clause 20.
  • 5.2An Enterprise Client registers through the enterprise registration pathway. Enterprise Clients operate on negotiated transaction volumes, pricing and payment terms, which are agreed separately between the Parties. Upon completion of the registration process, Fraudcheck will contact the Enterprise Client to agree the applicable commercial terms, following which Fraudcheck will send a link to finalise registration and activate the Account. If the Parties fail to agree the applicable commercial terms within 30 (thirty) calendar days of the completion of the registration process, the registration shall lapse and Fraudcheck shall have no obligation to activate the Account. Fraudcheck shall notify the User in writing if the registration lapses. Enterprise commercial terms may vary the standard provisions of these Terms to the extent expressly agreed in writing between the Parties, including without limitation committed transaction volumes or minimum spend, payment terms, service levels (which may enhance the standard service levels in Annexure A), pricing, data residency or processing location, and bespoke integration or configuration arrangements.
  • 5.3Save for fees and provisions expressly applicable to a specific Account type, all provisions of these Terms apply equally to Business Clients and Enterprise Clients.

06

Account Registration and Access

  • 6.1A User opening a New Account must complete the Account registration process on the Platform, submit accurate information and supporting documentation as requested, designate an Primary User (where the User is an entity), and accept these Terms. Fraudcheck conducts a manual review and approval of all New Account applications. A New Account is only activated when Fraudcheck sends the User a link to finalise the Account, which the User must follow to complete access.
  • 6.2Users with Existing Accounts will receive a link from Fraudcheck to migrate to the updated Platform. Access to the updated Platform is activated by following that link.
  • 6.3The User must provide accurate, current and complete information and must maintain the accuracy of such information at all times.
  • 6.4The User is responsible for maintaining the confidentiality of its Account credentials and for all activity conducted through the Account, including activity undertaken by its employees, contractors, agents or system integrations.
  • 6.5The User must notify Fraudcheck immediately upon becoming aware of any unauthorised access to or use of its Account.
  • 6.6The User must implement access controls and internal procedures to restrict access to the Platform to authorised personnel and integrations only.
  • 6.7Where the User integrates the Platform via API:
  • 6.7.1API credentials are issued subject to Account creation and acceptance of these Terms;
  • 6.7.2every API call made using those credentials constitutes ongoing acceptance of and compliance with these Terms;
  • 6.7.3the User must maintain records of all API credentials issued, restrict access on a need-to-know basis, and rotate credentials in accordance with good security practice;
  • 6.7.4the User is responsible for all activity conducted through its API credentials, including activity by any system, application or third party to whom the User has granted access; and
  • 6.7.5Fraudcheck may revoke API credentials at any time where misuse, a security risk, or a breach of these Terms is suspected.
  • 6.8Either Party may request deletion of the User's Account by providing written notice to the other. Account deletion shall take effect 30 (thirty) calendar days after such notice is given (the "Deletion Period"). During the Deletion Period, Fraudcheck shall continue to provide the Services and the User shall continue to be bound by these Terms. The Deletion Period is required to enable Fraudcheck to comply with its regulatory and compliance obligations, including records management and audit requirements under Applicable Laws. Deletion of the Account does not affect any accrued rights or obligations of either Party.

07

Services

  • 7.1Fraudcheck provides the following Services through the Platform:
  • 7.1.1identity verification;
  • 7.1.2Credit Bureau Services and Consumer Credit Information;
  • 7.1.3compliance screening, including sanctions, PEP and adverse media screening;
  • 7.1.4background verification;
  • 7.1.5fraud detection and prevention Services;
  • 7.1.6KYC and AML compliance tools;
  • 7.1.7document verification;
  • 7.1.8biometric verification and Liveness Detection;
  • 7.1.9affordability assessments; and
  • 7.1.10related compliance workflows and reporting tools.
  • 7.2Upon activation of an Account, the User has access to all Services, subject to the additional due diligence requirements applicable to Credit Bureau Services set out in clause 15.
  • 7.3The specific checks, products, turnaround times and applicable regulatory classifications are as communicated to the User through the Platform or in the applicable commercial documentation.
  • 7.4Fraudcheck may update, improve, modify or enhance the Services from time to time. Fraudcheck will provide reasonable prior notice where any such change materially reduces the core functionality of the Services.
  • 7.5Additional Services shall only be made available on a mutually agreed commercial basis, recorded in writing between authorised representatives of the Parties.
  • 7.6Fraudcheck reserves the right to modify, suspend or discontinue any aspect of the Services where reasonably necessary for operational, regulatory or security reasons, and shall provide reasonable prior notice where practicable.
  • 7.7Fraudcheck acts as an authorised reseller of Consumer Credit Information obtained from registered credit bureaux, in its capacity as a Tier 2 registered credit bureau. Certain Services are subject to regulatory restrictions arising from Fraudcheck's obligations under the NCA.

08

Information Officer

  • 8.1Fraudcheck has designated an Information Officer as required under POPIA. The Information Officer is responsible for ensuring Fraudcheck's compliance with POPIA and for managing Data Subject rights requests.
  • 8.2Data Subjects who wish to access, correct or delete their Personal Information held by Fraudcheck, or who wish to lodge a complaint in connection with Fraudcheck's Processing of Personal Information, may contact the Information Officer at the address set out in clause 35.1.1.
  • 8.3The Information Officer may be contacted for any POPIA-related matters arising out of or in connection with Fraudcheck's Processing of Personal Information.

09

Regulatory Status and Compliance

  • 9.1Fraudcheck is a Tier 2 registered credit bureau under the NCA (NCR registration number: NCRCB65) and an authorised reseller of Consumer Credit Information.
  • 9.2Access to Credit Bureau Services is restricted by the Credit Regulatory Framework. The User acknowledges that use of Credit Bureau Services is subject to the requirements of the NCA and the regulations promulgated thereunder.
  • 9.3Fraudcheck may monitor usage of the Services and may request information, supporting evidence or documentation from the User where reasonably necessary to verify compliance with Applicable Laws.
  • 9.4The User shall cooperate with Fraudcheck in responding to any regulatory enquiries, investigations or audits relating to the User's use of the Services.
  • 9.5The User shall immediately notify Fraudcheck in writing if it becomes aware of: (a) any investigation, complaint or inquiry by the NCR, the Information Regulator or any other regulatory authority relating to the User's use of the Services; (b) any data breach or security incident involving User Data or Personal Information Processed through the Platform; or (c) any complaint from a Data Subject in connection with information obtained through the Services.
  • 9.6The User warrants that it is, and shall at all times remain, compliant with all Applicable Laws governing its use of the Services, including without limitation the NCA, POPIA, FICA and the ECT Act.
  • 9.7Nothing in these Terms limits Fraudcheck's independent statutory obligations as a registered credit bureau, and no provision hereof shall be construed to require Fraudcheck to act contrary to any such obligation.

10

Prescribed Purpose and Consumer Credit Information

  • 10.1Consumer Credit Information may only be accessed for lawful Prescribed Purposes as contemplated in section 70 of the NCA, Regulation 18 and the Credit Regulatory Framework.
  • 10.2Fraudcheck assigns one or more Authorised Prescribed Purposes to each User's Account based on its regulatory and compliance assessment of the User's business and the information provided from time to time. Where more than one Authorised Prescribed Purpose has been assigned, the available Authorised Prescribed Purposes will be displayed to the User through the Platform, and the User must select the applicable Authorised Prescribed Purpose for each check run. Where only one Authorised Prescribed Purpose has been assigned, it will apply automatically. The User does not control the assignment of Authorised Prescribed Purposes, which remains solely within Fraudcheck's discretion. The Prescribed Purposes available through the Platform are set out in Annexure B.
  • 10.3The User warrants that each time it accesses Consumer Credit Information through the Platform, it does so only for a purpose corresponding to an Authorised Prescribed Purpose activated on its Account, and that it has obtained all consents required by the Credit Regulatory Framework prior to each request.
  • 10.4Fraudcheck may, in its sole discretion, add to, withdraw or decline to make available any Authorised Prescribed Purpose on written notice to the User.
  • 10.5The User acknowledges that misuse of Consumer Credit Information constitutes an offence under the NCA and may expose the User to civil, regulatory and criminal liability.
  • 10.6Fraudcheck may immediately suspend or terminate access to Credit Bureau Services where misuse, unlawful access or non-compliance with this clause is suspected, in accordance with clause 30 and without prejudice to any other rights or remedies.

11

Acceptable Use of the Platform and Consumer Credit Information

  • 11.1The User may not:
  • 11.1.1access the Platform for any unlawful purpose or in a manner contrary to Applicable Laws;
  • 11.1.2access Consumer Credit Information without a lawful Authorised Prescribed Purpose or without obtaining required consents;
  • 11.1.3access Consumer Credit Information for the purpose of marketing to consumers;
  • 11.1.4on-sell, redistribute or otherwise make available any Consumer Credit Information to any third party without Fraudcheck's prior written consent;
  • 11.1.5transfer Consumer Credit Information to any person not authorised under the Credit Regulatory Framework to receive, view or access such information;
  • 11.1.6attempt to scrape, harvest or extract bulk data from the Platform by automated or other means;
  • 11.1.7reverse engineer, decompile, disassemble or otherwise attempt to derive the source code, algorithms or methodologies of the Platform;
  • 11.1.8copy, reproduce, aggregate, store, use, resell, redistribute or commercially exploit Outputs without express written authorisation from Fraudcheck;
  • 11.1.9attempt to interfere with, disrupt or circumvent the security or access controls of the Platform;
  • 11.1.10submit malicious code, viruses, denial-of-service attacks or other harmful content to the Platform;
  • 11.1.11submit inaccurate, fraudulent or misleading data to the Platform;
  • 11.1.12use the Platform to facilitate fraud, identity theft or any other criminal activity;
  • 11.1.13permit any unauthorised third party to access or use the Platform through the User's Account or API credentials; or
  • 11.1.14take any action that would impose a disproportionate or unreasonable load on Fraudcheck's infrastructure.
  • 11.2The User is responsible for ensuring that its employees, contractors and agents comply with this clause. A breach by any such person shall be treated as a breach by the User.
  • 11.3The User shall cooperate with Fraudcheck and the NCR in respect of any matter relating to the Credit Regulatory Framework.

12

Consumer Redress

  • 12.1Where a consumer disputes the accuracy, currency or fairness of any Consumer Credit Information contained in an Output, the User shall direct the consumer to contact Fraudcheck, who will escalate the dispute to the relevant primary credit bureau together with the required supporting documentation.
  • 12.2If the consumer remains dissatisfied, they may approach:
OrganisationContact numberEmailWebsite
Credit Ombud (the services of the Credit Ombud are free to consumers)086 166 2837ombud@creditombud.org.zawww.creditombud.org.za
National Credit Regulator087 234 7822complaints@ncr.org.za

13

Employment Certifications

  • 13.1This clause applies only where the User's Authorised Prescribed Purposes include the consideration of a candidate for employment in a position that requires honesty in dealing with cash or finances (Regulation 18(4)(c)).
  • 13.2The User warrants and certifies that:
  • 13.2.1it has obtained the required consumer consent before each credit record is requested, in accordance with Regulation 18(5);
  • 13.2.2the position in respect of which the Consumer Credit Information is requested requires honesty in dealing with cash or finances, and the relevant job description is clearly documented; and
  • 13.2.3all information supplied to Fraudcheck in connection with such request is, to the best of its knowledge, true and correct.
  • 13.3Fraudcheck may, on reasonable notice, require the User to produce the consumer consent, the certification and the relevant job description in respect of any request under this clause.

14

Compliance Assessment and Audit Trail

  • 14.1Fraudcheck or its authorised representative may conduct compliance assessments - either off-site or, on reasonable prior notice, at the User's premises - to determine whether the User complies with the restrictions governing the use of Consumer Credit Information, uses the Services for a lawful purpose, obtains and retains required consents, and otherwise complies with these Terms and the Credit Regulatory Framework.
  • 14.2The User shall implement an effective audit trail in respect of each transaction performed using the Services, recording at minimum:
  • 14.2.1the date and time of the request;
  • 14.2.2the identity of the requesting user;
  • 14.2.3the Authorised Prescribed Purpose relied upon; and
  • 14.2.4the consumer's consent reference, where applicable.
  • 14.3The audit trail shall be implemented within 1 (one) month of the date of registration or the Effective Date, whichever is later, and shall be made available to Fraudcheck within 14 (fourteen) Business Days of written request.
  • 14.4Information disclosed in the course of a compliance assessment shall be treated as Confidential Information in accordance with clause 24.
  • 14.5Fraudcheck retains credit reports for a maximum of 72 (seventy-two) hours from the date of generation, in accordance with its conditions of registration with the NCR. The User is solely responsible for storing, retaining and handling any Consumer Credit Information it wishes to retain beyond that period, in accordance with Applicable Laws and the Credit Regulatory Framework.

15

Credit Bureau Services – Additional Due Diligence

  • 15.1Although all Services are accessible upon activation of a User's Account, access to Credit Bureau Services is gated and requires the completion of additional due diligence by Fraudcheck prior to activation of this functionality.
  • 15.2The additional due diligence may include, without limitation, verification of the User's regulatory status, business purpose, identity of representatives, and any other information or documentation that Fraudcheck considers necessary in its sole discretion.
  • 15.3Fraudcheck reserves the right to decline to activate Credit Bureau Services for any User where, in its reasonable assessment, the User does not satisfy the requirements of the Credit Regulatory Framework or Fraudcheck's internal compliance standards.
  • 15.4Activation of Credit Bureau Services is not automatic and does not follow from Account registration alone. Fraudcheck will notify the User once Credit Bureau Services have been activated on its Account.

16

Data Protection and Privacy (POPIA)

  • 16.1Fraudcheck Processes Personal Information in accordance with POPIA and its obligations as a Responsible Party and, where applicable, as an Operator.
  • 16.2As between the Parties:
  • 16.2.1the User acts as the Responsible Party in respect of Personal Information relating to the User's own customers, end users and other Data Subjects that is submitted to the Platform;
  • 16.2.2Fraudcheck acts as the Operator in respect of such Personal Information, Processing it solely for the purposes of providing the Services; and
  • 16.2.3Fraudcheck acts as the Responsible Party in respect of Personal Information it Processes for its own regulatory compliance, audit, fraud prevention and Credit Bureau Services obligations.
  • 16.3The User, as Responsible Party, remains responsible for:
  • 16.3.1determining the lawful basis for Processing Personal Information through the Services;
  • 16.3.2ensuring that all Personal Information submitted to the Platform has been lawfully obtained and that Data Subjects have been notified as required by POPIA;
  • 16.3.3ensuring that Processing complies with Applicable Laws; and
  • 16.3.4obtaining and retaining all required consents prior to submitting any Personal Information, including Biometric Data, to the Platform.
  • 16.4Fraudcheck shall, in its capacity as Operator:
  • 16.4.1Process Personal Information only as necessary to provide the Services and in accordance with the User's documented instructions, except where required by Applicable Laws;
  • 16.4.2implement and maintain appropriate technical and organisational security measures to protect Personal Information;
  • 16.4.3ensure that any Third-Party Provider engaged to Process Personal Information in connection with the Services does so under appropriate written arrangements and in accordance with POPIA
  • 16.4.4assist the User in responding to Data Subject access requests and exercising Data Subject rights, to the extent reasonably practicable; and
  • 16.4.5notify the User without undue delay upon becoming aware of a Personal Information breach involving User Data.
  • 16.5The subject matter, duration, nature and purpose of Fraudcheck's Processing of Personal Information as Operator are further described in Annexure C, which constitutes the written mandate contemplated by section 21 of POPIA.
  • 16.6The User warrants that it has determined a lawful basis for Processing each category of Personal Information submitted to the Platform, that all such Personal Information has been lawfully obtained, and that Data Subjects have been notified as required by POPIA prior to submission.
  • 16.7Fraudcheck may retain records and Personal Information for periods required by Applicable Laws, regulatory directives, NCR requirements or legitimate operational purposes. Statutory retention obligations override any instruction to delete records prior to the expiry of the legally prescribed retention period.
  • 16.8Fraudcheck's Processing of Personal Information is further described in its Privacy Policy, available on the Platform. The Privacy Policy is governed by its own terms and should be read in conjunction with these Terms. The Privacy Policy does not form part of these Terms, and in the event of any conflict between the Privacy Policy and these Terms, these Terms shall prevail.
  • 16.9The User indemnifies Fraudcheck against any regulatory action, fine, penalty, claim or liability arising from the User's failure to comply with its obligations as Responsible Party under this clause or under POPIA.

17

Third-Party Providers

  • 17.1Certain Outputs made available through the Platform are derived from information supplied by Third-Party Providers.
  • 17.2Fraudcheck acts as an intermediary in facilitating access to information supplied by Third-Party Providers. Fraudcheck does not originate or independently verify such information and makes no representation or warranty regarding its accuracy, completeness, currency or fitness for any particular purpose.
  • 17.3The User acknowledges that:
  • 17.3.1Fraudcheck does not control Third-Party Providers and cannot guarantee the availability, accuracy or timeliness of data supplied by them;
  • 17.3.2Outputs derived from Third-Party Providers reflect the data held by those providers at the time of the query and may not reflect subsequent changes;
  • 17.3.3Fraudcheck is not liable for any error, omission, delay or unavailability of data attributable to a Third-Party Provider; and
  • 17.3.4Platform Availability and turnaround times may be affected by the availability and response times of Third-Party Providers' systems.
  • 17.4The User shall not contact Third-Party Providers directly in relation to disputes or issues arising from Consumer Credit Information obtained through the Platform. All such matters must be directed to Fraudcheck in the first instance, following which the Consumer Redress Process shall apply.
  • 17.5Fraudcheck shall use commercially reasonable efforts to ensure that its contracts with Third-Party Providers include appropriate data protection and security obligations consistent with Applicable Laws.

18

Biometric Data and KYC Services

  • 18.1Certain Services, including identity verification, document verification and Liveness Detection, involve the Processing of Biometric Data. Fraudcheck provides these capabilities through its own Platform and, where appropriate, through Third-Party Providers engaged under appropriate data processing arrangements.
  • 18.2The User, as Responsible Party, must:
  • 18.2.1prior to submitting any Biometric Data to the Platform, obtain informed, written consent from the relevant Data Subject for the collection and Processing of their Biometric Data;
  • 18.2.2inform the Data Subject of the categories of Biometric Data to be Processed, the purpose of Processing, and the Data Subject's right to withdraw consent;
  • 18.2.3retain auditable evidence of such consent; and
  • 18.2.4comply with all requirements under POPIA and any other Applicable Laws governing the Processing of Biometric Data.
  • 18.3The User warrants that prior to submitting any Biometric Data to the Platform, it has obtained informed written consent from the relevant Data Subject for the collection and Processing of their Biometric Data, and that it holds auditable evidence of such consent.
  • 18.4Fraudcheck shall Process Biometric Data solely for the purposes of identity verification and fraud prevention. Biometric Data shall not be used for any other purpose without the Data Subject's consent.
  • 18.5The User acknowledges that:
  • 18.5.1Biometric Data may be Processed in jurisdictions outside South Africa where operationally required, subject to appropriate cross-border data transfer safeguards in accordance with POPIA;
  • 18.5.2Biometric Data shall be retained only for the period required to fulfil the purpose of Processing and in accordance with Applicable Laws;
  • 18.5.3Fraudcheck is not liable for errors or inaccuracies in identity verification Outputs that result from the quality, accuracy or completeness of Biometric Data submitted by the User; and
  • 18.5.4a list of Third-Party Providers engaged in Biometric Data Processing is available on written request where required by Applicable Laws.
  • 18.6Identity verification Outputs, including biometric match scores, are probabilistic in nature and are not a guarantee of identity. The User remains responsible for evaluating these Outputs and must not use them as the sole basis for any high-stakes decision without applying appropriate human review where required by law or by the nature of the decision.
  • 18.7Where Applicable Laws (including POPIA section 57) restrict or require safeguards for automated decision-making based on Personal Information, the User is responsible for ensuring compliance and for providing Data Subjects with information about automated decisions that affect them.
  • 18.8The User may withdraw consent to the Processing of Biometric Data for a specific Data Subject at any time by written notice to Fraudcheck. Withdrawal of consent does not affect the lawfulness of Processing carried out prior to withdrawal and does not obligate Fraudcheck to delete records it is required to retain under Applicable Laws.

19

Anti-Money Laundering and Financial Crime Compliance

  • 19.1Where the User uses the Services in connection with its obligations under FICA, the User acknowledges that it remains solely responsible for:
  • 19.1.1conducting customer due diligence and enhanced due diligence in accordance with FICA;
  • 19.1.2determining risk ratings and applying appropriate monitoring measures;
  • 19.1.3filing suspicious transaction reports and cash threshold reports with the FIC as required;
  • 19.1.4maintaining records as required by FICA; and
  • 19.1.5ensuring compliance with all obligations under FICA applicable to it as an accountable institution or reporting institution.
  • 19.2Outputs obtained through the Services, including sanctions screening results, PEP screening results and adverse media results, are provided for informational purposes only and do not constitute legal or compliance advice. The User must apply its own judgment and, where necessary, seek independent legal advice before acting on such Outputs.
  • 19.3Fraudcheck does not act as the User's compliance officer, money laundering reporting officer or legal adviser, and nothing in these Terms or in the Services shall be construed as creating such a relationship.
  • 19.4The User indemnifies Fraudcheck against any regulatory penalty, fine, liability or reputational damage arising from the User's failure to comply with its obligations under FICA or any other financial crime legislation.
  • 19.5The User warrants that it has identified and understands its obligations as an accountable institution or reporting institution under FICA, and that it shall comply with all such obligations independently of the Services provided by Fraudcheck.

20

Fees, Billing and Payment

  • 20.1Fees for Business Clients, including applicable payment terms, are charged at Fraudcheck's standard rates as recorded in a pricing addendum or other commercial documentation provided to the User. Fraudcheck may revise such fees in accordance with this clause 20.
  • 20.2Fraudcheck may revise the standard rates payable by a Business Client from time to time on no less than 30 (thirty) calendar days' prior written notice to the User. Where the revision increases the fees payable by the Business Client, and the increase is not an adjustment of the kind contemplated in clause 20.3, the Business Client may, before the revision takes effect, terminate these Terms by written notice to Fraudcheck, in which event the revision shall not apply to the Business Client prior to termination. If the Business Client does not so terminate, continued use of the Services after the effective date of the revision constitutes acceptance of the revised fees.
  • 20.3Where a third party engaged by Fraudcheck to support the provision of a Service increases its charges or changes the basis on which it supplies the information or service necessary for that Service, such that Fraudcheck incurs additional costs in continuing to provide that Service, Fraudcheck may, in respect of that Service only, increase the fees payable by the User by the amount of such additional costs on written notice to the User. An adjustment under this clause 20.3 does not give rise to a right of termination under clause 20.2.
  • 20.4A pricing addendum or other commercial documentation agreed between the Parties forms part of these Terms. In the event of any conflict between such pricing addendum or commercial documentation and these Terms, the pricing addendum or commercial documentation shall prevail, but only in respect of fees and payment terms, and these Terms shall prevail in respect of all other matters. A revision of fees made in accordance with this clause 20 does not constitute an amendment to these Terms for the purposes of clause 38.
  • 20.5Fees for Enterprise Clients are governed by the commercial documentation agreed between the Parties.
  • 20.6Transaction volumes and usage of the Services shall be measured in accordance with Fraudcheck's system records, which shall constitute prima facie proof of usage in the absence of manifest error.
  • 20.7All invoices are payable by the due date set out in the applicable invoice or commercial documentation. Overdue undisputed amounts shall bear interest at the Prime Rate plus 3% per annum, calculated daily from the due date to the date of payment. Failure to pay undisputed amounts by the due date may result in suspension of access to the Services in accordance with clause 30.
  • 20.8Where the User disputes any invoice, it must notify Fraudcheck in writing within 15 (fifteen) Business Days of receipt, specifying the disputed amount and the basis of the dispute. The User must pay the undisputed portion by the due date. Unresolved disputes shall be resolved in good faith, failing which either Party shall be entitled to refer the dispute to determination by an independent auditor agreed between the Parties, or failing agreement within 5 (five) days, appointed by the President of South African Institute of Chartered Accountants (“SAICA”). The auditor's determination shall be final and binding and the costs thereof shall be borne by the unsuccessful Party.

21

Platform Availability and Service Levels

  • 21.1Fraudcheck shall use commercially reasonable efforts to maintain Platform Availability in accordance with the service levels set out in Annexure A.
  • 21.2Fraudcheck shall, upon written request from the User, provide a monthly availability report for the preceding calendar month, setting out total minutes, Unscheduled Downtime (if any) and the calculated Platform Availability percentage.
  • 21.3Fraudcheck does not warrant turnaround times for Services that are dependent upon Third-Party Providers, governmental databases or telecommunications infrastructure.

22

Intellectual Property

  • 22.1Fraudcheck retains all rights, title and interest in and to the Platform, the Services, and all Intellectual Property associated with them, including the software, algorithms, databases, system architecture, methodologies and related technology used to provide the Services.
  • 22.2The User retains ownership of User Data submitted to the Platform.
  • 22.3Fraudcheck does not claim ownership of the underlying data supplied by Third-Party Providers, but the manner in which such data is presented, Processed and delivered through the Platform constitutes Fraudcheck's Intellectual Property.
  • 22.4Service Data, meaning anonymised and aggregated data derived from the provision of the Services (including transaction patterns, verification outcomes, fraud signals and usage data), remains the property of Fraudcheck. Fraudcheck may use such Service Data for any lawful purpose, including fraud model development, risk scoring and analytics, benchmarking, product development, training and improving automated systems, and related operational and commercial purposes, subject to the condition that the data cannot reasonably be used to identify the User, any Data Subject or any specific User Data. Fraudcheck may not use raw Personal Information or User Data for model training or cross-User purposes without a separate lawful basis under POPIA.
  • 22.5Subject to these Terms, the User is granted a limited, non-exclusive, non-transferable and revocable licence to access and use the Platform and the Outputs made available through the Services for the User's own lawful business purposes during the term of these Terms.
  • 22.6The User shall not sub-licence, assign, transfer or otherwise dispose of any rights granted under clause 22.5 without Fraudcheck's prior written consent.

23

Outputs and No Advisory Role

  • 23.1Outputs are provided for informational purposes only. Fraudcheck does not provide legal, financial, credit, compliance or regulatory advice through the Platform or otherwise.
  • 23.2The User remains solely responsible for:
  • 23.2.1evaluating the Outputs and determining whether additional verification, investigation or advice is required;
  • 23.2.2all decisions made using Outputs; and
  • 23.2.3ensuring that decisions based on Outputs comply with Applicable Laws, including laws governing automated decision-making.
  • 23.3Fraudcheck does not guarantee that Outputs are accurate, complete, current or suitable for any particular purpose. Outputs reflect data available from Third-Party Providers at the time of the query and may not reflect changes that have occurred since the data was last updated.
  • 23.4The User may use Outputs in the ordinary course of its business, including for providing services to its own customers, subject to compliance with Applicable Laws and these Terms. The User may not commercially resell or redistribute Outputs except with Fraudcheck's prior written consent.

24

Confidentiality

  • 24.1Each Receiving Party acknowledges the importance of the Confidential Information of the Disclosing Party and undertakes:
  • 24.1.1not to disclose or publish the Disclosing Party's Confidential Information in any manner or for any purpose without the Disclosing Party's prior written consent, except as permitted by these Terms;
  • 24.1.2not to use the Disclosing Party's Confidential Information for any purpose other than the performance of the Parties' obligations under these Terms;
  • 24.1.3to restrict dissemination of Confidential Information to those of its personnel, employees, contractors and advisers who need access to it for the purposes of these Terms, on a strict need-to-know basis; and
  • 24.1.4to take all reasonable steps to prevent unauthorised disclosure of Confidential Information by its personnel.
  • 24.2The Receiving Party shall protect the Disclosing Party's Confidential Information with at least the same degree of care it applies to its own confidential information, and in no event with less than reasonable care.
  • 24.3The obligations in this clause do not apply to information that:
  • 24.3.1is or becomes publicly available other than through a breach of these Terms;
  • 24.3.2was lawfully known to the Receiving Party prior to disclosure by the Disclosing Party;
  • 24.3.3is independently developed by the Receiving Party without use of the Disclosing Party's Confidential Information; or
  • 24.3.4is required to be disclosed by law, court order or regulatory authority, provided that the Receiving Party gives the Disclosing Party reasonable prior notice where permitted.
  • 24.4Fraudcheck may retain Confidential Information to the extent required by and for the duration of its obligations under Applicable Laws, NCR directives and POPIA retention requirements.
  • 24.5Upon termination of these Terms, or at the Disclosing Party's written request, the Receiving Party shall promptly return or destroy the Disclosing Party's Confidential Information, subject to any statutory retention obligations, and shall confirm such return or destruction in writing within 7 (seven) Business Days.
  • 24.6The obligations in this clause survive termination or expiry of these Terms for so long as the relevant information remains confidential in nature.
  • 24.7Each Party acknowledges that a breach of this clause may cause irreparable harm for which monetary damages would be an inadequate remedy, and that the Disclosing Party is entitled to seek urgent injunctive or other equitable relief without the need to post security.

25

Warranties

  • 25.1Each Party warrants to the other that:
  • 25.1.1it has the legal capacity and has taken all necessary action required to authorise it to enter into and perform its obligations under these Terms;
  • 25.1.2these Terms constitute a valid and binding obligation on it, enforceable against it in accordance with its terms;
  • 25.1.3the execution of these Terms and the performance of its obligations hereunder does not and shall not, to the best of its knowledge and belief:
  • 25.1.3.1contravene any Applicable Laws;
  • 25.1.3.2where applicable, contravene any provision of its constitutional documents; or
  • 25.1.3.3conflict with or constitute a breach of any other agreement or obligation binding on it;
  • 25.1.4to the best of its knowledge and belief, it is not aware of any fact or circumstance that may impair its ability to comply with its obligations under these Terms; and
  • 25.1.5the individual accepting these Terms on its behalf is duly authorised to do so.
  • 25.2Each warranty in clause 25.1 is a separate warranty, is not limited by any other warranty, and shall continue in force notwithstanding completion of the transactions contemplated in these Terms. Each warranty shall prima facie be deemed material and to be a material representation inducing the other Party to enter into these Terms.
  • 25.3Fraudcheck further warrants that:
  • 25.3.1it is duly registered as a Tier 2 credit bureau under the NCA (NCR registration number: NCRCB65) and shall maintain such registration for as long as Credit Bureau Services are provided;
  • 25.3.2it shall provide the Services with due skill, care and diligence and in accordance with Applicable Laws.

26

Disclaimers

  • 26.1Except as expressly set out in these Terms:
  • 26.1.1the Services and Platform are provided on an "as is" and "as available" basis;
  • 26.1.2Fraudcheck makes no warranty that the Services will be uninterrupted, error-free or free from viruses or other harmful components;
  • 26.1.3Fraudcheck makes no warranty regarding information sourced from Third-Party Providers and is not responsible for errors, omissions or delays in such data; and
  • 26.1.4all implied warranties, conditions and representations, including as to merchantability, fitness for a particular purpose, non-infringement and satisfactory quality, are excluded to the fullest extent permitted by Applicable Laws.

27

Limitation of Liability

  • 27.1To the fullest extent permitted by Applicable Laws, Fraudcheck shall not be liable for:
  • 27.1.1indirect, consequential, incidental, special or punitive damages;
  • 27.1.2loss of profits, revenue, business, goodwill, anticipated savings or data;
  • 27.1.3loss arising from inaccuracies, omissions or delays in information supplied by Third-Party Providers;
  • 27.1.4loss arising from the User's failure to comply with its obligations under these Terms or Applicable Laws;
  • 27.1.5loss arising from the User's reliance on Outputs without appropriate independent verification; or
  • 27.1.6loss arising from a Force Majeure Event.
  • 27.2Fraudcheck's total aggregate liability to the User for all claims arising under or in connection with these Terms shall not exceed the total fees paid by the User to Fraudcheck in the 6 (six) calendar months immediately preceding the event giving rise to the claim.
  • 27.3Nothing in these Terms limits or excludes liability for: (a) fraud or wilful misconduct; (b) death or personal injury caused by negligence; or (c) any other liability that cannot be excluded or limited by Applicable Laws.
  • 27.4The limitations in this clause reflect a fair allocation of risk between commercially sophisticated Parties. The User acknowledges that these limitations are reasonable having regard to this allocation.
  • 27.5Nothing in this clause limits the User's liability for regulatory breaches, unlawful use of Consumer Credit Information or Biometric Data, or indemnity obligations under these Terms.

28

Indemnity

  • 28.1The User indemnifies and holds Fraudcheck harmless from and against all claims, losses, liabilities, costs, expenses, regulatory actions, fines, penalties and damages (including legal costs on an attorney-and-own-client scale) arising from or in connection with the User's breach of:
  • 28.1.1Applicable Laws in connection with the User's use of the Services and/or Platform; or
  • 28.1.2these Terms.
  • 28.2The indemnity in clause 28.1 shall not apply to the extent that the relevant loss was directly caused by Fraudcheck's own fraud, wilful misconduct or gross negligence.

29

Data Security and Retention

  • 29.1Fraudcheck warrants that it shall implement and maintain appropriate technical and organisational security measures to protect Personal Information and User Data against unauthorised access, loss, destruction, misuse or disclosure, having regard to the requirements of POPIA, the NCA and applicable regulatory standards, including where appropriate: access controls, encryption, system monitoring, secure hosting environments and internal information security policies.
  • 29.2The User shall implement and maintain its own appropriate technical and organisational security measures to protect Personal Information Processed in connection with its use of the Services, and shall ensure that its systems and networks through which it accesses the Platform are adequately secured.
  • 29.3Fraudcheck shall retain records relating to Credit Bureau Services, including access logs and bureau requests, for the minimum period required under the NCA, NCR directives and other Applicable Laws, subject to clause 14.5.
  • 29.4Fraudcheck may disclose information, including User Data and Outputs, to the NCR, the Information Regulator, the FIC or any other competent regulatory or supervisory authority where required by law or regulatory directive. Such disclosure shall not constitute a breach of confidentiality.
  • 29.5In the event of a suspected or actual Personal Information breach involving User Data, Fraudcheck shall notify the User within a reasonable time after becoming aware of the breach and shall provide such information as is reasonably available to assist the User in discharging its notification obligations under POPIA.
  • 29.6Upon termination of these Terms, Fraudcheck shall, upon written request by the User and subject to payment of all outstanding amounts, provide the User with a copy of User Data held by Fraudcheck in a reasonably accessible electronic format. Fraudcheck is not required to delete records it is obliged to retain under Applicable Laws.

30

Suspension

  • 30.1Fraudcheck may suspend the User's access to the Platform or Services, with or without notice, in any of the following circumstances:
  • 30.1.1failure to pay undisputed invoices within the agreed payment period;
  • 30.1.2material or suspected breach of these Terms or Applicable Laws;
  • 30.1.3receipt of a regulatory directive from the NCR, the Information Regulator, the FIC or any other competent authority;
  • 30.1.4security risks, system integrity concerns or suspected unauthorised access;
  • 30.1.5where required to protect the interests of third parties, including Data Subjects; or
  • 30.1.6any other circumstance in which Fraudcheck reasonably considers suspension necessary to protect its interests or the integrity of the Platform.
  • 30.2Where the grounds for suspension are remediable, Fraudcheck shall, where reasonably practicable, notify the User of the grounds for suspension and provide a reasonable period within which to remedy the issue before suspension takes effect.
  • 30.3Suspension shall not relieve the User of its obligation to pay accrued fees or its liability for any breach.
  • 30.4Fraudcheck shall lift the suspension promptly upon satisfaction that the grounds for suspension have been remedied, subject to any regulatory restrictions.
  • 30.5Suspension does not preclude Fraudcheck from exercising its right to terminate these Terms in accordance with clause 31.

31

Breach and Remedies

  • 31.1If either Party ("Defaulting Party") commits a material breach of these Terms and fails to remedy such breach within 7 (seven) Business Days of written notice from the other Party ("Aggrieved Party") requiring the breach to be remedied, the Aggrieved Party shall be entitled, at its election:
  • 31.1.1to claim immediate specific performance of the Defaulting Party's obligations, with or without claiming damages; or
  • 31.1.2to cancel these Terms and claim damages.
  • 31.2Notwithstanding clause 31.1, Fraudcheck may terminate these Terms immediately upon written notice to the User without providing a cure period in the following circumstances:
  • 31.2.1the User's unlawful use of Consumer Credit Information or Biometric Data;
  • 31.2.2the User's fraudulent conduct or wilful misconduct;
  • 31.2.3a regulatory directive requiring Fraudcheck to cease providing Services to the User;
  • 31.2.4where the User is an entity, the liquidation or winding-up of the User or the commencement of business rescue proceedings in respect of the User, to the extent that termination on this ground is not precluded by the moratorium provisions of the Companies Act 71 of 2008; or

where the User is a natural person, the sequestration of the User's estate.

  • 31.2.5any other breach that, by its nature, is incapable of remedy.
  • 31.3Any costs awarded shall be recoverable on an attorney-and-own-client scale.
  • 31.4Remedies under this clause are cumulative and are not in substitution for any other remedy available at law or in equity.

32

Termination and Consequences

  • 32.1The User may terminate these Terms by requesting deletion of its Account in accordance with clause 6.8. Cessation of use of the Platform does not, on its own, constitute notice of termination and does not relieve the User of liability for fees accrued prior to cessation.
  • 32.2Fraudcheck may terminate the User's access to the Platform and Services on 30 (thirty) calendar days' written notice, without cause. Fraudcheck may terminate immediately, without notice, in the circumstances set out in clause 31.2.
  • 32.3Upon termination or expiry of these Terms for any reason:
  • 32.3.1the User's right to access and use the Services and the Platform shall immediately cease;
  • 32.3.2all outstanding undisputed fees accrued up to the date of termination shall immediately become due and payable;
  • 32.3.3each Party shall promptly return or destroy the other Party's Confidential Information, subject to statutory retention obligations;
  • 32.3.4Fraudcheck shall, upon written request and subject to payment of all outstanding amounts, provide the User with a copy of User Data in a reasonably accessible electronic format;
  • 32.3.5Fraudcheck shall not be required to delete or return any records it is required to retain under Applicable Laws; and
  • 32.3.6Fraudcheck shall not be obliged to transfer any Intellectual Property, Service Data, methodologies or internal systems configurations.
  • 32.4Termination shall not affect any accrued rights or obligations of either Party.
  • 32.5Any provision of these Terms that by its nature is intended to survive termination or expiry shall do so, including without limitation provisions relating to definitions, intellectual property, confidentiality, limitation of liability, indemnity, dispute resolution and general provisions.

33

Force Majeure

  • 33.1For purposes of this clause, "Force Majeure Event" means any event beyond the reasonable control of the affected Party, including acts of God; natural disasters; flood, fire, earthquake or storm; war, armed conflict, terrorism or civil unrest, whether or not formally declared; pandemic or epidemic; labour disputes or industrial action; failure or disruption of telecommunications networks, internet infrastructure or electricity supply; failure or unavailability of Third-Party Providers or governmental systems; governmental actions, regulatory directives or sanctions; or power outages.
  • 33.2Neither Party shall be in breach of its obligations under these Terms, or incur any liability, where it is prevented from carrying out those obligations by a Force Majeure Event, provided that:
  • 33.2.1the affected Party notifies the other Party in writing as soon as reasonably practicable after the occurrence of the Force Majeure Event;
  • 33.2.2the affected Party uses all reasonable endeavours to mitigate the effect of the Force Majeure Event and to resume performance as soon as reasonably practicable; and
  • 33.2.3the Force Majeure Event is not caused by or attributable to the affected Party's own fault or negligence.
  • 33.3The affected Party is not excused from performance of those of its obligations that are not affected by the Force Majeure Event.
  • 33.4If a Force Majeure Event prevents the affected Party from performing any material obligation under these Terms for a continuous period of 30 (thirty) calendar days or more, either Party may terminate these Terms by written notice without liability, other than for fees accrued prior to termination.

34

Dispute Resolution

  • 34.1A dispute shall arise for purposes of this clause when one Party communicates the dispute and its particularity in writing to the other Party.
  • 34.2The Parties shall endeavour to resolve any dispute through good faith negotiation between senior representatives within 5 (five) Business Days of the notice referred to in clause 34.1. If the dispute is not resolved within that period, either Party may refer it directly to arbitration under clause 34.3.
  • 34.3All disputes shall be finally resolved by arbitration under the expedited rules of AFSA. The arbitration shall be held in Sandton, Johannesburg. The arbitrator shall be agreed upon by the Parties or, failing agreement within 3 (three) Business Days, appointed by the Chairman of the Johannesburg Bar Council (for legal disputes) or the President of SAICA (for accounting disputes).
  • 34.4The arbitrator's award shall be final and binding, shall be given within 30 (thirty) calendar days of finalisation of proceedings, and may be made an order of court. There shall be no right of appeal except in the case of manifest error.
  • 34.5Nothing in this clause prevents either Party from applying to a South African court for urgent or interim relief at any time.
  • 34.6This clause is separate and divisible from the rest of these Terms and remains in effect even if these Terms are terminated, cancelled or found to be void.

35

Notices and Domicilium

  • 35.1The Parties choose as their domicilia citandi et executandi ("domicilium") the following addresses:
  • 35.1.1Fraudcheck:

Physical: Fraudcheck Pty Ltd, Freestone Office Park, 135 Patricia Rd, Sandown, Sandton, 2196

Email: spencerl@fraudcheck.co.za

Attention: Spencer Luck (Information Officer)

  • 35.1.2User: The physical address and email address provided by the User at onboarding, as updated Fraudcheck from time to time.
  • 35.2Any notice delivered by hand to a responsible person at the physical domicilium during business hours shall be deemed received on the day of delivery, unless the contrary is proved.
  • 35.3Any notice sent by email at the email domicilium shall be deemed received on the date of successful transmission, or the next Business Day if transmitted outside of business hours, unless the contrary is proved.
  • 35.4Either Party may change its domicilium by written notice, with effect from the 7th (seventh) Business Day after deemed receipt of that notice.
  • 35.5Any notice or other communication to be given to any of the Parties in terms of these Terms shall be valid only if it is given in writing, provided that any notice given by email shall be regarded for this purpose as having been given in writing.
  • 35.6This clause 35 does not operate so as to invalidate the giving or receipt of any written notice which is actually received by the addressee other than by a method referred to in this clause 35.
  • 35.7The User undertakes to immediately notify Fraudcheck in writing of any change in its physical address, email address or Primary User for the purposes of these Terms. This obligation includes notifying Fraudcheck where the designated Primary User leaves the User's employ or is otherwise no longer authorised to act on the User's behalf. Failure to do so shall not invalidate any notice served by Fraudcheck in accordance with the last known details on record.

36

Electronic Communications and Contracting

  • 36.1These Terms are accepted electronically through the Platform in accordance with the ECT Act. Electronic acceptance, including by proceeding with registration, following a link sent by Fraudcheck, accessing or using the Platform, or integrating via API, constitutes a legally binding agreement, as set out in clause 4.
  • 36.2Communications between the Parties may be conducted electronically, including through the Platform, email or other agreed digital communication channels.
  • 36.3The Parties agree that electronic acceptance shall be valid and binding to the same extent as a wet-ink signature, except where a specific provision requires a written signature.

37

Governing Law and Jurisdiction

  • 37.1These Terms are governed by and construed in accordance with the laws of South Africa.
  • 37.2The Parties irrevocably submit to the non-exclusive jurisdiction of the High Court of South Africa, Gauteng Division, Johannesburg, for purposes of seeking urgent or interim relief and for any matters not subject to the dispute resolution process in clause 34.

38

Amendments to Terms

  • 38.1Fraudcheck may update these Terms from time to time to reflect changes in Applicable Laws, regulatory requirements, the Services or operational needs.
  • 38.2Updated Terms will be published on the Platform. Fraudcheck shall provide at least 30 (thirty) calendar days' prior written notice of any material change and at least 10 (ten) calendar days' prior written notice of any non-material change, except where a change is required urgently by law or regulatory directive, in which case it takes effect on publication.
  • 38.3Continued use of the Services after the effective date of any update constitutes acceptance of the updated Terms. No separate tick-box or confirmation is required.
  • 38.4If the User does not accept the updated Terms, it must cease using the Services from the Effective Date and notify Fraudcheck in writing as soon as reasonably practicable thereafter.

39

General Provisions

  • 39.1These Terms, together with all annexures, constitute the entire agreement between the Parties in relation to the subject matter hereof and supersede all prior discussions, negotiations, understandings and agreements between the Parties relating to the Services, subject to clause 3.3.
  • 39.2The Parties shall act in good faith in performing their obligations under these Terms and shall do all things reasonably necessary to give effect to the intent and purpose of these Terms.
  • 39.3If any provision of these Terms is held to be invalid, unlawful or unenforceable, such provision shall be deemed severed, and the remaining provisions shall continue in full force and effect.
  • 39.4No failure or delay by either Party in exercising any right or remedy shall constitute a waiver of that right or remedy. A waiver shall only be effective if made in writing and shall not constitute a waiver of any subsequent breach or default.
  • 39.5The User may not assign, transfer or otherwise dispose of any of its rights or obligations under these Terms without Fraudcheck's prior written consent. Fraudcheck may assign or transfer its rights and obligations under these Terms to an affiliate or as part of a merger, acquisition, corporate restructuring or sale of business, provided that the User's rights are not materially prejudiced.
  • 39.6No partnership or agency: Nothing in these Terms creates a partnership, joint venture, employment or agency relationship between the Parties. Neither Party has authority to bind the other.
  • 39.7Unless these Terms provide otherwise, each Party shall bear its own legal costs in connection with the preparation and negotiation of these Terms.
  • 39.8These Terms are entered into for the benefit of the Parties only and do not create any rights in favour of any third party.

Annexure A – Service Level Agreement

Platform Availability

Platform Availability = (Total minutes in the calendar month – Unscheduled Downtime) ÷ Total minutes in the calendar month

Where "Unscheduled Downtime" means periods during which the Platform is unavailable to the User, excluding the following:

  • scheduled maintenance windows of up to 4 (four) hours per calendar month, notified to the User at least 48 (forty-eight) hours in advance where reasonably practicable;
  • emergency maintenance required to protect the security or integrity of the Platform;
  • Force Majeure Events;
  • downtime attributable to Third-Party Providers, governmental systems, telecommunications networks or internet service providers; and
  • downtime attributable to the User's systems, configurations, equipment or connectivity.

Fraudcheck shall use commercially reasonable efforts to achieve and maintain Platform Availability of at least 99.5% per calendar month.

Maintenance windows

Scheduled maintenance windows shall not exceed 4 (four) hours per calendar month.

Where reasonably practicable, scheduled maintenance shall be:

  • scheduled during off-peak hours (typically between 22:00 and 06:00 SAST); and
  • notified to the User at least 48 (forty-eight) hours in advance.

Support hours

Support LevelHoursNotes
General Support08:00 – 17:00 (Monday to Friday)Excludes public holidays
Technical Support08:00 – 17:00 (Monday to Friday)Excludes public holidays
Priority / Emergency Support24 hours / 7 daysFor critical incidents only

Incident response times

SeverityImpactTime to AcknowledgementTarget Resolution Time
CriticalPlatform completely unavailable or core Services non-functionalImmediateUnder 1 hour
HighMaterial degradation of core ServicesImmediateUnder 2 hours
MediumPartial degradation; workaround availableImmediate4 – 6 hours
LowMinor issue; no material impact on core ServicesNext Business DayNext Business Day

Resolution times are targets only and do not constitute a guarantee.

Times are measured from when Fraudcheck becomes aware of or is notified of the incident.


Annexure B – Prescribed Purposes

The following table sets out the Prescribed Purposes available through the Platform under the Credit Regulatory Framework:

Regulation / SectionPrescribed or Contemplated PurposeConsumer Consent Required
Reg 18(4)(b)Fraud detection and fraud prevention Services, provided that any subscriber performing these Services has been approved by Fraudcheck.No
Reg 18(4)(c)Considering a candidate for employment in a position that requires honesty in dealing with cash or finances (subject to clause 13).Yes
Reg 18(4)(d)An assessment of the debtors book of a business for the purposes of: (a) the sale of the business or debtors book; or (b) any other transaction dependent upon determining the value of the business or debtors book.No
Reg 18(4)(g)Verifying educational qualifications and employment by an Employment Agency or Employer.Yes
Reg 18(4)(h)Obtaining consumer information to distribute unclaimed funds, including pension funds and insurance claims, by an Insurance Company or its Agent.No
Reg 18(4)(i)Tracing a consumer by a Credit Provider (or agent) in respect of a credit agreement. Tracing by non-credit collectors requires consumer consent (Reg 18(6)(d)).No
Reg 18(4)(j)Developing a credit scoring system by a Credit Provider or credit bureau.No
Sec 68(1)(b)(ii)(aa) / Reg 18(6)(d)As directed by the consumer or prospective consumer; or any other purpose not related to and not intended for providing consumer credit.Yes
Reg 23AConducting an affordability assessment by a Credit Provider, excluding incidental Credit Providers and Education Institutions. Non-registered Credit Providers require consent (Reg 18(6)(d)).No
Contemplated PurposeAccount management for an existing base (positive or negative credit worthiness assessment) under a credit agreement by a Credit Provider, including incidental credit.Yes
Sec 81Assessing the debt repayment history of a consumer under their credit agreements (enquiries for credit assessment at the time of application) under a credit agreement by a Credit Provider, including incidental credit.No
Sec 68(1)(b)(i)Consumer credit information requested in terms of other national legislation by a person stated therein.Dependent on legislation

Annexure C – Data Processing Schedule

This schedule records the written mandate under which Fraudcheck Processes Personal Information as Operator on behalf of the User as Responsible Party, as contemplated by section 21 of POPIA.

Subject matter

The Processing of Personal Information submitted by the User to the Platform in connection with identity verification, credit bureau enquiries, KYC and AML compliance checks, biometric verification and related Services.

Duration

For the duration of these Terms and for such further period as Fraudcheck is required to retain records under Applicable Laws.

Nature of Processing

Collection, storage, retrieval, use, transmission to Third-Party Providers and deletion of Personal Information as necessary to provide the Services.

Purpose of Processing

To enable Fraudcheck to deliver the Services to the User, including facilitating access to Consumer Credit Information, conducting identity verification and biometric checks, performing compliance screening, and fulfilling Fraudcheck's regulatory obligations as a registered credit bureau.

Categories of Personal Information Processed

Identity information (name, identity number, date of birth, nationality); contact information (address, email, telephone number); financial information (credit history, payment profile, affordability data); biometric information (facial geometry, liveness detection data, fingerprints where applicable); employment information where relevant to an Authorised Prescribed Purpose.

Categories of Data Subjects

The User's customers, employees, prospective employees and other individuals in respect of whom the User submits Personal Information to the Platform.

Operator obligations

Fraudcheck shall Process Personal Information only in accordance with the documented instructions of the User as set out in these Terms, except where required to do otherwise by Applicable Laws. Fraudcheck's obligations as Operator are set out in clause 16.4 of these Terms.