Legal

Terms of Service

These Terms of Service govern the use of the Legichain website, platform (panel, API and SDK) and services. For customers who have a separately signed service agreement with Legichain, the signed agreement and its annexes take precedence over these terms (see Section 1.3). Last updated: 9 September 2026.

1. Parties, scope and order of documents

1.1 Parties. The service provider is Legichain. Address and tax details are stated in customer agreements and provided on request. The organisation that opens an account, places an order or uses the service is the “Customer”.

1.2 Scope. Legichain provides only the services included in the selected plan or order, within the purpose of use, region, credit, capacity and term limits stated there. A feature that is not selected, a paid extension of a supported feature or a roadmap feature is not automatically in scope. Resale to the Customer's affiliates or to its own customers is permitted only where agreed in writing.

1.3 Precedence of a signed custom agreement. Where the Customer and Legichain have signed an Enterprise Service Agreement and its annexes (commercial terms, service scope, processing of personal data, retention and deletion, service level), the provisions of the signed agreement apply in every matter where they conflict with these terms. A unilateral update on the website, the pricing page, a presentation or the panel does not change a signed price, credit tariff, data-use purpose, retention period or liability limit. In matters not regulated by the signed agreement, these terms apply as a supplement. Mandatory law is reserved in all cases.

1.4 Technical documentation. The technical documentation published by Legichain governs integration.

2. Key definitions

Service: the selected API, panel, SDK, screening, verification, reporting and retention functions. End User: the natural person whose data is processed. Customer Data: the inputs transferred by the Customer or, on its behalf, by an End User, together with the customer-specific results and records linked to them; independent third-party databases are not included in this definition as to ownership.

Credit: the billing unit; it is not money, electronic money, a crypto-asset or a payment instrument. API Request: a technical call sent to an endpoint. Credits, requests, screened records and verified persons are not interchangeable.

KYC Session: a verification process opened with a single application identifier. Retry: an additional attempt permitted within the same session; a process started with a new application identifier is a new session. Result: an accept, reject, review-required, match, risk-indicator or technical-status notification. A technically successful operation does not mean the person has been accepted.

3. Nature and limits of the service

3.1 Identity verification. Document, OCR/MRZ, NFC, liveness and face-matching checks are separate features; which of them apply is defined in the selected scope. Integrity and signature checks of an NFC chip do not by themselves prove the real-time presence of the person presenting the chip, that they are the person on the document, or their legal authority to transact. A check that is switched off is never presented as if it had been performed.

3.2 AML screening. Sanctions, PEP and, where included, adverse media screening is limited to the defined source and update scope. Similar names, missing attributes, transliteration and source errors can produce false positives or false negatives. A match is not, on its own, a conclusive finding of crime, of the application of sanctions or of customer rejection; the absence of a match does not show that a person is risk-free. The Customer performs its own risk-based review and, where needed, human assessment; Legichain investigates reported technical or matching errors and corrects those attributable to it.

3.3 Blockchain address screening. Scope is limited to the supported network, address format, dataset and relationship depth. Screening an address does not verify control of the private key, the beneficial owner, the full transaction history or the lawful origin of assets. Live chain monitoring, transaction monitoring, multi-hop fund tracing, Travel Rule, asset custody and transfer execution are in scope only where expressly purchased separately. An unsupported network or a failed query cannot be read as a “clean” result.

3.4 Reports and audit trail. Reports reflect the inputs, selected checks and accessible results at the time they were produced; unless continuous monitoring is selected, an old report is not updated automatically. Record-integrity mechanisms that support change detection do not replace a qualified electronic signature, an official time stamp or notarisation.

3.5 Regulatory boundary. The service provides technical decision support. The Customer's regulatory status, customer acceptance decision, risk appetite, suspicious transaction reporting, application of sanctions and statutory record-keeping obligations remain with the Customer. No regulatory approval or guarantee of full sectoral compliance is deemed given unless verified documents and scope are stated in writing.

4. Legichain's commitments

4.1 Legichain provides the service with reasonable professional care, in line with the agreed scope, security measures and documentation, and applies technical and organisational measures proportionate to the risk for Customer Data. No absolute guarantee is given of uninterrupted service, prevention of every attack, detection of every fraud or the accuracy of every external source.

4.2 Legichain notifies the Customer of known material defects, security incidents, source outages or loss of scope together with their impact, and does the work necessary to correct the error, mitigate harm and prevent recurrence. Where a result cannot be produced reliably, an error, pending or review state is used; a service failure is never presented as a positive verification.

4.3 Legichain makes understandable usage and credit records, integration documentation, a support channel and methods for the Customer to access its own data available. Final billing rests on auditable transaction records.

4.4 Legichain investigates a reported breach with the available evidence and, for a breach attributable to it, first provides correction, an equivalent workaround or free re-performance of the affected operation. No double remedy arises for the same loss; financial claims are subject to Section 14.

5. Customer obligations and integration

5.1 Lawfulness. The Customer uses the service for lawful purposes; establishes the processing condition required for the data it transfers, informs End Users properly and, where required, obtains valid explicit consent and keeps it provable. Acceptance of these terms or signature of an enterprise agreement does not constitute the End User's explicit consent. The service is not used for special-category data, children or vulnerable persons unless the applicable additional obligations are met. Where legally required, the Customer provides the ability to contest an automated result and obtain human re-assessment; Legichain makes the available findings and reasons accessible to support that review.

5.2 Access security. The Customer protects access keys and secrets; server keys are never placed in mobile applications, browsers or public repositories. The Customer defines permissions at minimum scope, validates user/session/application matching in its own backend, reports suspicious access without delay and rotates affected keys. Ordinary transaction fees for unauthorised use caused by a breach of the Customer's own systems, staff or integrator are borne by the Customer; Legichain's fault or failure to take reasonable measures after notification reduces this outcome in proportion to its contribution.

5.3 Integration. The Customer provides network and device compatibility, native NFC components and its own software according to the agreed division of tasks. Provision of an SDK does not mean that every operating system and device combination or a third-party NFC engine is included.

5.4 Webhooks. A Customer receiving webhooks verifies the signature and timestamp on the raw request body, prevents duplicate processing using delivery/event identifiers, returns a successful HTTP response only after durably recording the notification, and reconciles the final state with the authoritative status query. Exactly-once, ordered or guaranteed delivery is not promised; a notification failure does not invalidate the existing query result.

5.5 Own archive. The Customer lawfully exports the data it needs into its own systems before the retention period expires and determines its own statutory retention needs. Unless a separate archiving or recovery service is expressly purchased, Legichain is not the Customer's statutory archive or backup; agreed lawful deletion does not by itself constitute a breach by Legichain.

6. Acceptable use and licence

6.1 The Customer is granted the right, for the term, to use the selected service for its own authorised business purpose and, to the extent the licence terms permit, to integrate the SDK into its own application and distribute it to End Users. This licence does not grant the right to resell the API or to reproduce a third-party database in bulk.

6.2 The Customer may not use the service for unlawful discrimination, unauthorised surveillance, phishing, fraud, unauthorised bulk data extraction or to exceed a data-source licence; may not circumvent security controls or quota limits; and may not artificially increase the plan's total entitlement through multiple keys or accounts. Security testing is coordinated in writing in advance.

6.3 The Customer may not give third parties approvals, conclusive results or additional service-level commitments on Legichain's behalf. Use of the Customer's name or logo as a reference requires separate written permission.

7. Credits, fees, taxes and disputes

7.1 Plan, term, price, currency, tax treatment, payment due date, renewal, additional credit and overage conditions are determined by the selected plan or the signed agreement. Credit-consuming events and credits per check are published on the Pricing page; a service without a defined price is not opened as a paid service in production.

7.2 A credit is consumed when the chargeable operation takes place. In the model where creating a session is chargeable, rejection, abandonment or expiry of the session is not by itself a ground for refund. Credits are corrected for duplicate charges or paid operations not delivered due to Legichain's fault. Re-submission of the same operation under idempotency does not create a new charge. Switching a biometric check off does not automatically lower the same session tariff.

7.3 Unless agreed otherwise, plans are prepaid. Credits are valid for one year; they do not renew automatically, cannot be transferred to another account and are not converted to cash at the end of the term. Additional credit availability depends on the plan; where no overage entitlement is defined, overage is closed and no debt or additional package arises automatically.

7.4 The Customer pays the undisputed amount of an invoice when due. A technical consumption dispute is reported with transaction identifiers within 30 days of becoming known; Legichain provides a review response and record summary within 10 business days. The service is not suspended solely because of a portion disputed in good faith while it is under review. Statutory commercial default rules apply to late payment; taxes, exchange rates and payment arrangements follow mandatory law.

8. Capacity and rate limits

8.1 The requests-per-second limit (RPS) is the account's acceptance limit and, unless stated otherwise, is shared across the keys linked to the same account. RPS is not a guarantee that a verification completes within the same second or of continuous processing at that rate.

8.2 The daily quota resets in the stated time zone; unused capacity does not carry over to the next day. A limit-related 429 response and a 5xx response caused by a provider capacity problem are assessed separately.

8.3 The Customer uses back-off, jitter and queues for retries and, where possible, shares expected volume spikes 5 business days in advance. Increased limits or reserved capacity are agreed in writing with their price and activation date.

9. Changes, versions and maintenance

9.1 Legichain may develop the service, but may not materially reduce the core function, security level or data protection purchased for the term.

9.2 At least 90 days' notice, a migration document and a reasonable testing opportunity are provided before a backwards-incompatible API or SDK removal. Changes that cannot wait because of a security vulnerability or binding law may be made in a narrow scope with notice given without delay. The Customer applies reasonable security updates.

9.3 If a material part of the scope is permanently reduced because of the loss of a third-party source or a change in law, Legichain proposes a substantially equivalent alternative or transition solution within a reasonable time; if none can be provided, the affected service may be terminated without penalty and Section 13.4 applies only to the undelivered part. External source cost increases are not passed on unilaterally to the current term's price.

10. Confidentiality, data rights and intellectual property

10.1 Non-public technical, commercial and personal information, secrets, keys and contract terms are confidential and are disclosed only to persons who need to know them for performance and are bound by confidentiality. Legally required disclosure is made in the minimum scope. The confidentiality obligation continues for 5 years after the relationship ends and, for trade secrets and personal data, for as long as the relevant protection obligation lasts.

10.2 The Customer's rights in Customer Data and the rights of data subjects are preserved. Legichain obtains only the limited right of use necessary to perform the service and to carry out lawful documented instructions. The Customer may lawfully share its results and reports within its own compliance process, with its advisers and with competent authorities; bulk redistribution of a source database is not included in this right.

10.3 Legichain's software, algorithms and pre-existing intellectual property remain with Legichain. Customer Data may not be used for advertising, data sale, re-use of identities for another customer or model training. Only irreversibly anonymised aggregate statistics may be used for quality and capacity analysis; a hash or pseudonym alone is not anonymity.

11. Personal data, security and retention

11.1 Roles, security measures, use of sub-services, transfers, breach notification and retention in the processing of personal data are governed by the Privacy Notice and, where one exists, the data processing annexes of the Customer's signed agreement. Where Legichain notices an unlawful instruction, it reports this with reasons and stops processing the unlawful part.

11.2 Identity verification content and screening data are processed and stored in the selected region; the operation of account, permission and billing management in a separate control system is not a permission to copy End User data to another region.

11.3 When Legichain becomes aware of a personal data breach, it gives the Customer initial information without delay and at the latest within 24 hours, completes missing details in stages and takes the necessary measures; the Customer manages notification to authorities and data subjects, with Legichain's support.

11.4 Service Data is deleted from active systems at the end of the retention period defined in the selected plan or agreement; backup copies are destroyed within the regular backup cycle. Anonymous audit records that contain no personal data, and invoices, agreements and mandatory accounting records, are kept for the statutory period; this exception is not a general permission to retain raw identity content.

12. Suspension

12.1 Legichain may temporarily suspend the service, to the extent necessary and proportionate, because of a concrete security threat, clearly unlawful use, a binding authority decision or a material breach. For non-urgent breaches, the reasons and remediation steps are notified in writing and at least 10 business days are given. For payment breaches, this right is used only for overdue undisputed receivables and after a proper formal notice.

12.2 In an emergency a narrow suspension may be applied first; unless legally prohibited, the reason, impact and reopening condition are notified without delay. Once the threat ends, the service is reopened without undue delay. During suspension, secure data export and the exercise of statutory data rights continue as far as possible; a payment dispute does not create a lien over data.

12.3 A proportionate suspension based on objective and documentable grounds is not by itself a breach. During a justified suspension the plan term continues to run; in an unjustified or excessively long suspension, access and the right of use are restored first.

13. Term, termination and exit

13.1 Term and renewal. The plan term and credit validity are stated in the selected plan or agreement. Automatic renewal applies only where expressly selected; in that case notice of non-renewal may be given at least 30 days in advance, and a price increase is proposed at least 60 days in advance and is not binding for the new term unless accepted.

13.2 Material breach. In the event of a material breach, the other party notifies the breach and its remediation expectation in writing; if the breach is not remedied within 30 days, the affected service may be terminated. A remedied minor error or a single negative result is not automatically a material breach. Mandatory rights of immediate termination are reserved.

13.3 Discontinuation. If Legichain permanently discontinues a service by commercial decision, it gives 90 days' notice unless binding law or an urgent security requirement prevents this, provides a reasonable transition opportunity and refunds the undelivered part under Section 13.4.

13.4 Refunds. In the event of Legichain's unremedied material breach, discontinuation or a legally mandatory refund, only the net amount actually paid for the undelivered part of the ended service is refunded. No refund arises for delivered service, completed set-up or custom development, consumed credits, promotions or free credits. A refund that is due is made within 30 days of termination; the same amount is never paid twice.

13.5 Exit. On termination, where data has not yet been lawfully destroyed, free export in a standard format is available for 30 days; this period does not extend the retention period. Custom conversion, migration and consultancy are subject to a written work order.

14. Liability and third-party claims

14.1 Basis. Legichain is liable only for proven direct damage in an adequate causal link with a breach of contract attributable to it, within the applicable fault and evidence rules. The inherent limits of the selected checks, a false positive or false negative on its own, the Customer's customer-acceptance or payment decision, or a third party's fraud do not create a no-fault guarantee of compensation. The Customer's unlawful or incomplete input, its choice of a lower control profile, bypassing of security controls, its own system or integrator errors and failure to mitigate are taken into account in proportion to their contribution. Unavailability or inaccuracy of an independent external source does not give rise to compensation to the extent Legichain has not breached its selection, update, warning and reasonable mitigation obligations.

14.2 Aggregate cap. Subject to Section 14.4, the total of all limitable compensation, costs, defence expenses, service credits and recourse obligations of Legichain arising in a contract year is limited to 25% of the net fees actually paid by the Customer for the affected services in that year. Claims arising from the same or a connected root cause are attributed to the year of the first event; different events, claimants or legal grounds do not multiply the annual cap.

14.3 Customer cap. The annual aggregate cap of the Customer's limitable compensation and recourse obligations arising from its own breach is 100% of the total net service fees agreed for the relevant contract year. The obligation to pay service fees is not a compensation cap; third-party claims arising from the Customer's unlawful data or instructions or unauthorised resale are not subject to this cap.

14.4 Mandatory exceptions. The exclusion, damage-type and cap provisions do not apply to intent, gross negligence, fraud or other liabilities that cannot be limited by law. The statutory rights of data subjects, public authorities and third parties are not limited. Service fee payment obligations, refunds under Section 13.4 and corrections of erroneous or duplicate charges are not included in the compensation cap.

14.5 Third-party claims. Where software developed by Legichain and used unmodified within the authorised scope infringes a third party's intellectual property right, Legichain covers, within the Section 14.2 cap, the amount arising from a final judgment or a settlement it approved in advance and reasonable defence costs; the part caused by Customer input, unauthorised modification or out-of-scope use is excluded. The Customer covers, to the extent of its own breach, claims made against Legichain because of the Customer's unlawful data or instructions, failure to establish the required processing condition or information, unauthorised resale or unauthorised commitments on Legichain's behalf. Claims are notified without delay; a settlement made without written approval does not bind the other party.

14.6 Scope of damage. Subject to Section 14.4, the parties are not liable to each other for indirect damage, pure loss of profit or turnover, loss of business opportunity, customers or reputation, or punitive damages. Payment, credit or crypto-assets that the Customer gives an End User by its own commercial decision are not damage guaranteed by Legichain merely because the service result was relied on. The addressee of an administrative fine is determined by law; criminal liability is not transferable. No double recovery is made for the same damage.

15. Force majeure

Events beyond a party's reasonable control that cannot be prevented with due care even if foreseen and that prevent performance, such as earthquake, war, a binding public measure or a widespread infrastructure outage, may constitute force majeure to the extent of their concrete effects. The affected party notifies the event, the affected function and the estimated duration without delay and continues mitigation measures. Not every cyber attack or supplier failure is force majeure by itself; ordinary lack of capacity, financing difficulties or a known vulnerability left unaddressed are not excuses. If the impediment exceeds 30 days, either party may end the affected service without penalty. Mandatory data security and notification obligations continue.

16. Audit and regulatory cooperation

16.1 Each party meets its own statutory obligations and cooperates as necessary with lawful information and audit requests from competent authorities. Customer-specific sectoral requirements (BDDK, CMB, CBRT, MASAK, DORA or other outsourcing requirements) are defined in the signed agreement; not all of these regimes are deemed to apply to every Customer.

16.2 The Customer may have an audit carried out once a year with at least 30 days' notice, subject to confidentiality and without disrupting the service; a document review is performed first and other customers' data is not disclosed. Legichain bears the cost of remedying its own breach; the Customer's external auditor and adviser costs do not pass to Legichain automatically.

17. Notices, assignment and disputes

17.1 Operational notices are made through the registered email addresses and the support channel ([email protected]). Applicable formal requirements for default, termination and rescission notices are reserved; where required, a notary, registered mail or a secure electronically signed registered email (KEP) is used. Publication in the panel alone does not replace a legally required notice.

17.2 The agreement may not be assigned without the other party's written consent, which is not withheld without reasonable cause. In a merger or business transfer the transferee assumes all obligations and the security and data-transfer conditions are preserved. Use of sub-services is not an assignment.

17.3 These terms are governed by the laws of the Republic of Türkiye. The parties first attempt to resolve a dispute at the level of authorised representatives within 15 business days; mandatory mediation and statutory rules on jurisdiction and competence are reserved. Where a signed agreement selects a competent court, that selection applies; otherwise statutory jurisdiction rules apply.

18. Final provisions

18.1 The invalidity of one provision does not invalidate the remaining provisions; an invalid provision is replaced in line with mandatory law and the intended balance. Failure to exercise a right is not a waiver. The parties are independent contractors; no partnership, agency or employment relationship is created.

18.2 Technical records and transaction identifiers may be assessed together with other evidence; Legichain's records are not unilateral and conclusive evidence. A wet signature or a secure electronic signature recognised by applicable law may be used.

18.3 Legichain may update these terms; the current text and effective date are published on this page and Platform Users are informed separately of material changes. Updates do not alter rights purchased within a term or signed agreements, in accordance with Section 1.3. Questions: [email protected].