Legal
Terms and Conditions
These terms define how DecentraTrust may be accessed, purchased, configured, and used for high-trust document verification workflows.
1. Agreement and order of precedence
These Terms and Conditions govern access to and use of DecentraTrust, a document verification, audit evidence, and credential trust system provided by Cardoholding Digitalized Solutions. They apply to public website use, evaluation access, subscriptions, implementations, support, and related services unless a signed agreement, AWS Marketplace private offer, order form, data processing addendum, or other written contract expressly states different terms.
If the product is purchased through AWS Marketplace, AWS Marketplace purchase, billing, tax, renewal, cancellation, and marketplace account terms may also apply. If there is a conflict between these Terms and a fully executed marketplace private offer, order form, or enterprise agreement, the more specific transaction document controls for that transaction.
2. Product scope
DecentraTrust helps organizations register trusted document records, capture verification metadata, generate tamper-evident proof artifacts, manage issuer and credential context, and support independent review of submitted files. The system may include document hashing, metadata capture, audit events, status checks, automated analysis signals, QR or verification links, proof packages, dashboards, APIs, and administrative controls.
DecentraTrust is a trust and verification workflow tool. It does not by itself create legal validity, replace professional judgment, guarantee that a document is lawful or enforceable, or prove facts outside the records, files, metadata, issuer status, and verification events available to the system.
3. Accounts and authorized users
Customers are responsible for all activity under their accounts, administrator profiles, API credentials, integrations, and authorized users. Customers must keep credentials confidential, apply appropriate access controls, promptly remove users who no longer need access, and notify Cardoholding Digitalized Solutions of suspected unauthorized access.
Customers may use DecentraTrust only for their internal business operations and permitted verification workflows, unless resale, managed-service use, or external distribution is expressly authorized in an order document.
4. Customer data and document content
Customers retain ownership of documents, metadata, issuer data, holder data, verification records, proof packages, configuration data, and other content submitted to the service. Customers grant Cardoholding Digitalized Solutions the limited rights needed to host, process, secure, transmit, analyze, verify, support, and operate the service.
Customers are responsible for ensuring they have the rights, notices, consents, legal bases, and authority needed to upload, process, verify, share, or disclose document content and personal data through DecentraTrust. Customers should not submit prohibited data or regulated data unless the applicable order, security controls, and data processing terms permit that use.
5. Security and shared responsibility
Cardoholding Digitalized Solutions will use commercially reasonable administrative, technical, and organizational safeguards designed to protect the service and customer data. These safeguards may include access controls, encryption, logging, backup controls, least-privilege practices, monitoring, and incident response procedures appropriate to the subscribed service tier.
Security is a shared responsibility. Cardoholding Digitalized Solutions is responsible for the controls it operates for the service. Customers are responsible for their own users, endpoints, credentials, permissions, network settings, input data, third-party integrations, exported files, and downstream use of verification results.
6. Acceptable use
- Do not use the service for unlawful, deceptive, infringing, harmful, abusive, or high-risk activity.
- Do not upload malware, intentionally corrupted files, unauthorized confidential data, or content that violates third-party rights.
- Do not attempt to bypass authentication, probe or attack the service, scrape at abusive scale, interfere with operations, or reverse engineer non-public components except where law expressly permits.
- Do not represent a verification result as a guarantee of identity, legal enforceability, regulatory approval, employment eligibility, educational standing, or fraud-free status where the underlying evidence does not support that claim.
- Do not use the service to make automated decisions about individuals where applicable law requires human review, notice, consent, or other safeguards unless the customer has implemented those safeguards.
7. Verification results and audit evidence
Verification results depend on the submitted file, registered reference records, issuer configuration, credential status, metadata quality, available audit events, and selected verification rules. A match, mismatch, warning, or status result should be interpreted within the customer workflow and evidence available at the time of review.
Audit logs, hashes, ledger-style events, Merkle proofs, and proof packages are designed to support tamper-evident review. They are not a substitute for independent legal, compliance, security, identity, educational, licensing, or professional review where such review is required.
8. Subscriptions, fees, taxes, and AWS Marketplace
Fees, subscription terms, usage limits, renewal periods, cancellation rights, refund eligibility, and support entitlements are stated in the applicable order, product listing, private offer, marketplace transaction, invoice, or written agreement.
Where AWS Marketplace is used, billing and collection may be handled through AWS Marketplace according to the buyer account and selected offer. Customers are responsible for taxes, marketplace account permissions, procurement approvals, and usage charges associated with their subscription unless the applicable transaction document states otherwise.
9. Availability, support, and changes
Cardoholding Digitalized Solutions may maintain, update, improve, suspend, or modify the service to improve reliability, security, performance, compliance, or product functionality. Material changes that substantially reduce subscribed core functionality will be handled according to the applicable order or support terms.
Support channels, response targets, service levels, maintenance windows, and escalation processes apply only if included in the subscribed plan, private offer, support policy, or written agreement.
10. Confidentiality
Each party may receive non-public business, technical, security, product, pricing, or operational information from the other party. The receiving party must use reasonable care to protect confidential information and use it only for purposes related to the service, except where disclosure is required by law or permitted by the disclosing party.
11. Intellectual property
Cardoholding Digitalized Solutions and its licensors retain all rights in the service, software, workflows, designs, documentation, templates, product names, and related technology. Customers receive only the limited right to use the service during the applicable subscription term.
Feedback may be used to improve the service without obligation, provided it does not require disclosure of customer confidential information or customer data.
12. Third-party services and integrations
The service may interoperate with cloud providers, identity providers, email services, storage systems, marketplace services, analytics, payment systems, APIs, or other third-party tools. Customer use of third-party services is governed by the applicable third-party terms, and customers are responsible for configuring those integrations securely.
13. Suspension and termination
Cardoholding Digitalized Solutions may suspend access where necessary to address security risk, unlawful use, non-payment, account compromise, abuse, or violation of these Terms. Upon termination or expiration, customer access may end and data export or deletion will be handled according to the applicable order, retention policy, data processing terms, and legal obligations.
14. Disclaimers and limitation of liability
Except for commitments expressly stated in an applicable signed agreement, the service is provided on an as-is and as-available basis to the maximum extent permitted by law. Cardoholding Digitalized Solutions does not warrant that verification results will be error-free, that every altered or fraudulent document will be detected, or that the service will satisfy every legal or regulatory requirement for every customer workflow.
To the maximum extent permitted by law, neither party will be liable for indirect, incidental, special, consequential, exemplary, or punitive damages, or for lost profits, lost revenue, loss of goodwill, or business interruption. Any aggregate liability cap will be the cap stated in the applicable order or agreement, or if none is stated, the amount paid for the service during the twelve months before the event giving rise to the claim.
15. Compliance, export, and restricted use
Each party must comply with laws applicable to its performance and use of the service, including data protection, anti-corruption, export control, sanctions, procurement, and sector-specific obligations. Customers must not use the service where prohibited by sanctions, export restrictions, or applicable law.
16. Governing law and disputes
The governing law, venue, dispute process, and notice addresses are those stated in the applicable order, private offer, marketplace agreement, or signed contract. If no specific terms are stated, disputes will be handled under the laws and courts applicable to the seller principal place of business, without regard to conflict-of-law rules.
17. Updates and contact
Cardoholding Digitalized Solutions may update these Terms from time to time. Updated terms will be posted on this page with a revised effective date. For legal, security, privacy, or product terms questions, contact hello@cardoholding.com.