DEEPXL AS
API TERMS
EVALUATION PERIOD AND PRODUCTION
Version 1.0 | Effective from 14 September 2026
Published at deepxl.ai, in the legal section — prior versions archived in the same place
BUSINESS USE ONLY. NOT FOR CONSUMERS.
These Terms have two states, and one thing decides which one you are in: whether an Order Form is in force. Until you and we sign an Order Form you are in the Evaluation Period: you may test and demonstrate the Services and build an integration, but you must not use them in production and you must not rely on any Output. That is true whether you use the Playground interface or call the API directly, in whatever endpoint or mode, at whatever volume — the interface you choose changes nothing. When an Order Form takes effect, Schedule 4 (Production Terms) applies and replaces the clauses listed in it, and you may use the Services live on the prices and volumes the Order Form states. Your API credentials are the same throughout and are not permission for either state.
READ THESE FOUR THINGS BEFORE YOU ACCEPT. (1) Clause 5: personal data may be submitted, but only synthetic files, files relating to yourself, or files relating to a person who has consented or for whom you hold another documented lawful basis — and you carry the whole of the responsibility for every file you send. (2) Clauses 2.3, 2.10 and 6: during the Evaluation Period Outputs must not be relied on at all, and going live requires a signed Order Form — a working API key is not permission. In production Outputs are still never a determination of authenticity or identity, must never be the sole or determinative basis for a decision about a person, and require human review under P5 of Schedule 4. (3) Clause 8: we are a Norwegian company subject to the GDPR, and all files are processed and stored on cloud infrastructure operated by our sub-processors in the locations stated in our published sub-processor list — at the date of this version, the United States — wherever in the world you are located; we are the exporter of that data and clause 8.4 states the safeguards. (4) Clause 11: where Evaluation use is without charge we exclude our liability in full; where you have paid a charge it is capped at what you have consumed, with a floor of EUR 500. In production, clause P8 of Schedule 4 applies instead.
CLAUSE 16 PROVIDES FOR NORWEGIAN LAW AND ARBITRATION IN OSLO. DISPUTES ARE RESOLVED INDIVIDUALLY.
These API Terms (the “Terms”) are entered into between DeepXL AS, a Norwegian private limited company, org. no. 932 269 570, Bjørnveien 87B, 0773 Oslo, Norway (“DeepXL”, “we”, “us”) and the legal entity that registers for access, following an invitation from us or, where we make open registration available, directly (the “Customer”, “you”). Contact for legal notices: legal@deepxl.ai.
These Terms apply to Customers established anywhere in the world. There is no country-specific or regional version, and no version is selected at registration. The Data Processing Addendum in Schedule 2 contains a region-specific module whose paragraphs apply automatically according to the law applicable to you.
1. INVITATION, ELIGIBILITY AND ACCEPTANCE
1.1 How access is granted. Access is granted either on invitation from us or, where we make open registration available, by registering directly. We decide which route applies, may operate both at once, may switch between them at any time, and may require an invitation from some or all applicants without giving reasons. An invitation is personal to the invited organisation, is not transferable, and may be withdrawn by us at any time before or after registration. We are not obliged to issue an invitation or to grant access, and we are not obliged to give reasons for declining or withdrawing either. Where an invitation is issued it states the access period, the number of Calls made available and whether any charge applies (an “Invitation”), and it forms part of these Terms and is incorporated into them. Where no Invitation is issued, those matters are as stated at registration and in your account.
1.2 Formation. These Terms become binding when you complete registration in the Playground sign-up flow in the manner described in clause 1.6, or, if earlier, when you make your first Call. That date is the “Effective Date”. These Terms,
together with their Schedules, are the entire agreement between us in respect of the Services. No purchase order, order form or separate signature is required, and none is created by these Terms.
1.3 Business use only; no consumers. The Services are offered exclusively to legal entities and to natural persons acting for purposes relating to their trade, business, craft or profession. You represent and warrant that you are not acting as a consumer. If we determine that an account has been registered by a consumer, or that a statement made under clause 1.4 is false or misleading, we may terminate access with immediate effect. Nothing in these Terms is intended to limit a right that a person has under mandatory consumer protection law; if such a right applies notwithstanding this clause, these Terms apply only to the extent that law permits.
1.4 Registration information. At registration you will provide, accurately and completely, only the following: your registered legal name; your registered or principal business address; a business e-mail address for notices; and the name, job title and business e-mail address of the individual accepting these Terms. You will keep that information current. Nothing further is required of you at registration, and no annex, schedule or form has to be completed by either party: as Schedule 3 explains, these four items identify the contracting entity for notices, for our record of processing under Article 30(2) of the GDPR and, where the Standard Contractual Clauses apply between us under clause 9.4 of Schedule 2, for Part A of Annex I to those Clauses, which is why they are asked for. Your company registration number and VAT or tax identification number are not required at registration; we will ask for them before we invoice any charge to you and they are stated in an Order Form under clause 2.10.
1.5 Authority. The individual accepting these Terms represents and warrants that they are at least 18 years old and duly authorised to bind the Customer. The account is the Customer’s account, not that individual’s, irrespective of who any invitation was addressed to.
1.6 Acceptance by registration. No checkbox is used. You accept these Terms by completing registration. The final step of the registration form is a single button whose label states that acceptance (for example “Register and accept the Terms”), and immediately above it, on the same screen and without scrolling, the flow displays the following statement, with the named document as a conspicuous hyperlink and with a link to download it as a PDF: “By registering you accept the API Terms, and you confirm that you are authorised to do so on behalf of the organisation named above.” Clicking the button is your affirmative acceptance of these Terms, including Schedules 1 to 4, and of the representations in clauses 1.3, 1.4 and 1.5, whether or not each of those representations appears on screen. No separate signature, order form or confirmation is required.
1.7 Availability and retention. The links required by clause 1.6 open the current version and allow it to be downloaded as a PDF; the text need not be reproduced in the sign-up flow. We do not send you a copy of these Terms when you register, and we are not obliged to. You are responsible for downloading and retaining a copy if you want one. Where we send you any e-mail about your registration, it will identify the version number and effective date of the version you accepted and link to that version in the archive; where your account displays that information, that display serves the same purpose. When an Order Form is signed we confirm it by e-mail, identifying the version number and effective date of the version then in force and either linking to it or attaching a copy, at our option. Making these Terms available by link and download at the moment of acceptance is how we make them available in a form you can store and reproduce, and to the extent sections 11 and 12 of the Norwegian E-Commerce Act (ehandelsloven) would otherwise require more, or would require anything during the Evaluation Period, the parties agree, as that Act permits between parties who are not consumers, that they do not apply. Every version carries a version number and an effective date, and every version, current and superseded, remains available at the archive on our website for as long as a claim under it could be brought; that archive is how you can see what changed and when, and it is what clause 14.1 relies on. Publishing a new version at that URL does not by itself change these Terms as they apply to you: clause 14.1 is the only way these Terms are amended.
1.8 Evidence of acceptance. We record, for each registration, the version number of the Terms displayed, the date and time of acceptance, the exact wording and links displayed immediately above the registration button, the label of that button, the registration information submitted and the IP address and user agent used. That record, read with the archived version bearing that version number, is evidence of the agreement between us, and is sufficient for that purpose whether or not we have sent you anything and whether or not your account displays the version you accepted. Neither any e-mail nor any display in your account is the point at which the agreement is formed, and a failure to send, receive or display either does not affect the agreement.
1.9 Order of precedence. If there is a conflict, the following order applies: (a) the Standard Contractual Clauses, where they apply between the parties under clause 9.4 of Schedule 2, to the extent of the conflict; (b) Schedule 2 (Data
Processing Addendum); (c) an Order Form signed under clause 2.10, in respect of the matters it covers; (d) Schedule 4 (Production Terms), where it applies; (e) the Invitation, in respect of the access period, the number of Calls and any charge only; (f) these Terms; (g) Schedule 1 (Acceptable Use Policy); (h) the Documentation.
2. THE PLAYGROUND, THE EVALUATION PERIOD AND PRODUCTION
2.1 Definitions. “Evaluation Period” means the period from the Effective Date until an Order Form takes effect under clause 2.10 or these Terms terminate, whichever is earlier. “Playground” means the non-production environment, interface and Documentation we make available for use during the Evaluation Period; the Services may equally be accessed by direct calls to the API during the Evaluation Period, and both are Evaluation use. “Services” means the analysis services described in clause 2.2, however accessed. “Call” means a single request to the API submitting one file for analysis, and includes an Analysis Call (document or object analysis) and a Parsing Call (extraction of structured data from a document); an Order Form may price the two types differently. “Order Form” means a document signed by both parties under clause 2.10 setting the commercial terms for production use. “Customer Content” means the files, images and data you submit. “Output” means the analysis result returned in response to a Call. “Documentation” means the technical documentation we make available.
2.2 Scope of the Services. The Services comprise Document Analysis, Object Analysis and Parsing, in each case with the coverage described in clause 6.6. The Services do not include, and you must not attempt to use them for, biometric processing of any kind, including face comparison, face matching, liveness detection or the generation or comparison of any biometric template. Nor do they include identity verification against any register or database, watchlist or sanctions screening, or credit or affordability assessment. This clause applies both during the Evaluation Period and in production; Schedule 4 does not vary it, and any addition to scope requires a written amendment to these Terms or an express provision in an Order Form.
2.3 Evaluation use only, and what determines which terms apply. During the Evaluation Period you may use the Services only to evaluate them, to demonstrate them internally within your own organisation, and to develop and test a technical integration. You must not use the Services, or any Output, in production, for live traffic, for any real customer or applicant, or to make, support, inform or document any decision about any person, transaction, application, account or claim. The only thing that determines which terms apply to your use is whether an Order Form is in force. It makes no difference whether you access the Services through the Playground interface, by direct calls to the API, through an endpoint or mode described as test or as production, or by any other means; nor does it make any difference what volume you send, in what environment you deploy, or how you or we describe your use. Until an Order Form takes effect under clause 2.10, all use of the Services is Evaluation use and is governed by these Terms without Schedule 4; from that date it is production use and Schedule 4 applies.
2.4 Length of the Evaluation Period. Access is granted for sixty (60) days from the Effective Date, unless an Invitation or your account states a different period, in which case that period applies. We may extend it in writing, including by e-mail. Access terminates automatically at the end of the period unless extended or unless an Order Form has taken effect. Either party may terminate these Terms at any time, for any reason and with immediate effect, by notice to the other; we may also suspend or revoke access immediately and without notice or reason. Where you have paid a charge under clause 10 and we terminate or revoke for convenience rather than for cause, clause 10.4 applies.
2.5 Volume limit and credits during the Evaluation Period. Use is limited to the number of Calls made available to you, being the number stated in your Invitation or, where no Invitation is issued or it states no number, the standard allowance we make available at registration as stated in your account or the Documentation. We may set, vary and withdraw the standard allowance at any time, it may differ between recipients, and a change to it does not affect an allowance already stated in an Invitation. We may increase your allowance in writing at any time, and may reduce it only prospectively and only where you have breached these Terms. The allowance may be presented in your account as a number of credits, in which case one credit corresponds to one Call; credits have no monetary value, are not property, are not transferable and are not redeemable or refundable. The limit applies per Customer and, where two or more accounts are held by affiliated entities or operated by the same persons, across those accounts in aggregate. Clauses 2.15 and 2.16 govern which Calls count against the limit. Calls in excess of the limit return an error and are not processed, and no entitlement to exceed it arises otherwise than in writing from us.
2.6 Credentials, Administrator and Authorised Users. API credentials are issued to the Customer, not to any individual, and are confidential. The individual who completed registration is the initial Administrator. The Administrator may designate another Authorised User as Administrator and may invite further individuals to the account as
Authorised Users. An Authorised User may be an employee of the Customer, or an individual contractor working under the Customer’s direction and control, and may be no one else: in particular you must not invite an individual who is employed or engaged by, or who is acting for, any other legal entity, including a group company, an affiliate, an agent, an adviser, a prospective customer or a customer of yours. The number of Authorised Users does not affect the allowance under clause 2.5. Each Authorised User must use their own login and must not share it; the account-level API credentials remain yours and must not be disclosed to, or used by, any person or organisation other than an Authorised User acting for the purposes in clause 2.3. You will keep the list of Authorised Users current and will withdraw an individual’s access without undue delay once they cease to be eligible. Anything done in the account by the Administrator or by an Authorised User is done by you and binds you, including an invitation, a designation of a new Administrator, a configuration change, a request to increase the allowance, a retention election under clause 8.3 and an instruction for the purposes of clause 2.1 of Schedule 2, and we may act on it without further verification. You are responsible for all activity conducted using the account and the credentials, whoever conducts it. Clause 2.9 governs what the credentials do and do not permit. You will notify us without undue delay at legal@deepxl.ai if you become aware that credentials or a login have been disclosed or compromised, or that a person who is not an Authorised User has had access.
2.7 No service level, no support commitment. During the Evaluation Period the Services are provided on an as-available basis. We give no availability commitment, no service level, no response or resolution time and no support commitment, and service credits are not available. We may take the Playground or the API offline, change it, reset it or delete its contents at any time without notice. Any assistance we choose to give is given without obligation.
2.8 The same analysis; the surrounding functionality may change. The analysis the Services perform is the same during the Evaluation Period and in production; what differs is the terms on which it is provided, not the analysis itself. Everything around that analysis may differ and may change: the Playground, the console, the interface, the tooling, the configuration and filtering options, the reporting and any other feature we make available. We may add, change, withdraw or discontinue any such feature at any time, and a feature may be available during the Evaluation Period and not in production, or in production and not during the Evaluation Period. That a feature is available to you at one time, or in one phase, is not a commitment that it will remain available, become available or be priced in any particular way. From time to time we may make a pre-release model version, threshold, configuration or feature available, and we will say so where we do; otherwise you are using the current production models. Where you are in production and a change is likely to have a material adverse effect on your use of the Services, P4.3 of Schedule 4 applies.
2.9 Credentials and credits confer no further right. Your API credentials and your Call allowance or credits are the technical means by which we control access; they are not a licence beyond clause 3.1 and they do not enlarge the purposes permitted by clause 2.3. The same credentials are used during the Evaluation Period and in production, and as clause 2.3 provides, it is the Order Form and nothing else that determines which terms apply. An increase in your allowance, however granted, including automatically, on request or by our error, does not permit production use, does not vary clause 2.3 or 6.2 and is not a waiver of either; nor does any demonstration, technical assistance or indicative pricing given during the Evaluation Period.
2.10 Moving to production. Production use begins only when both parties have signed an Order Form. An Order Form is a document issued by us that identifies these Terms and their version number and states at least: (a) your registered legal name, country of establishment, company registration or VAT/tax number, registered or principal business address and notice e-mail address; (b) the account or API credential reference; (c) the date from which production use begins; (d) the Services elected and the price for each Call type; (e) the currency; (f) the initial prepayment amount and any minimum top-up; (g) the initial term and renewal, where different from P3.1 of Schedule 4; (h) any rate or concurrency limits, where different from the Documentation; (i) the retention election under clause 8.3, where shorter than twelve months; (j) anything permitted under P2.2 of Schedule 4 that would otherwise be prohibited; and (k) whether the DORA Addendum referred to in P9 of Schedule 4 applies. We maintain the form of the Order Form ourselves and may change it at any time; a change to the form is not a change to these Terms.
2.11 Effect of an Order Form, and what is not one. From the date stated in the Order Form: (a) Schedule 4 (Production Terms) applies and replaces the clauses listed in P1.1 of that Schedule, and the rest of these Terms continues in force unchanged; (b) the Order Form governs the matters it covers; and (c) the Evaluation Period allowance under clause 2.5 ceases to apply and is not carried over, converted or credited. Your API credentials do not change. Neither party is obliged to sign an Order Form, neither has any exclusivity, and any price discussed, quoted or displayed before an Order Form is signed is indicative only and does not bind us. No Order Form arises from an e-
mail exchange, a quotation, a proposal, a purchase order, a vendor-portal submission or any click-through. Terms printed on or referred to in a purchase order, vendor registration form, procurement portal or similar document have no effect, whether or not we sign or acknowledge that document.
2.12 These Terms are offered on a standard basis. We do not negotiate them for Evaluation Period access, and no variation of them, and no additional or different term, is effective unless we agree it in writing. A customer whose requirements are not met by these Terms as they stand — whether as to processing locations, contractual terms or anything else — may ask for a negotiated enterprise agreement under clause 2.14, which we may offer or decline at our discretion and which is priced separately; that route, and not a variation of these Terms, is how such requirements are met. Access to the Playground and the signing of an Order Form are at our discretion, and we may decline either, or withdraw the Order Form route, without giving reasons. Where we do agree separate written arrangements with you, they govern use of the Services from the date stated in them and, unless they provide otherwise, replace these Terms in respect of that use; these Terms and Schedule 2 continue to apply to Customer Content submitted before that date until it is deleted under clause 8.3, and the clauses listed in clause 12.3 survive.
2.13 Unauthorised production use. If you use the Services in production, or otherwise in breach of clause 2.3 or clause 6.2, before an Order Form has taken effect, that is a material breach entitling us to suspend or terminate immediately under clause 12.1. You will stop that use on becoming aware of it, notify us at legal@deepxl.ai without undue delay, and cease to rely on any Output already obtained. Your liability for that breach is not subject to any limit under clause 11, and your indemnity under clause 5.6 applies to it, including to any claim by a person affected by a decision you made using an Output. Where the Invitation states a rate for the Services, you will in addition pay us that rate for every Call made in the course of that use, payable on demand against invoice, as a charge for services actually received. We may treat sustained volume, traffic patterns, submission rates or data characteristics that are inconsistent with evaluation as evidence of production use, and clause 3.6 applies.
2.14 Where you also have a negotiated agreement with us. If a reseller, distribution, enterprise or other negotiated agreement between you and us covering the Services is in force, or comes into force, then that agreement prevails over these Terms in respect of all use of the Services falling within its scope, and these Terms govern only Evaluation Period access that the negotiated agreement does not cover. No Order Form may be signed, and Schedule 4 does not apply, while such an agreement is in force. Where the negotiated agreement contains its own data protection terms, those terms apply to processing within its scope in place of Schedule 2. You will tell us before registering if such an agreement is in force or under negotiation, and we may make Evaluation Period access conditional on terms stated in the Invitation.
2.15 When a Call is counted. A Call is counted, and draws down your allowance under clause 2.5 or your Balance under P7 of Schedule 4, when we accept it for processing. A Call is counted whether or not the result is useful to you. In particular, the following are counted: a Call that returns an Output of any kind, including an inconclusive, low-confidence or negative result; a Call analysed under General Coverage; a Call we reject after acceptance because the file does not meet the technical or quality requirements stated in the Documentation, for example because it is unreadable, corrupt, password-protected, of an unsupported format or size, or has the wrong number of pages; a Call whose Output you disagree with; and a repeated submission of a file you have submitted before.
2.16 When a Call is not counted. The following are not counted: a Call refused before acceptance because it would exceed your allowance under clause 2.5 or the rate or concurrency limits under P4.1 of Schedule 4; a Call refused because your credentials are invalid or your access is suspended; a Call refused because your Balance is exhausted; and a Call that fails solely because of a fault, error or unavailability on our side. Where a Call has been counted and then fails solely for that reason, we will re-credit it to your allowance or Balance on your request, made within thirty (30) days of the Call; we may also re-credit it without a request but are not obliged to identify such Calls ourselves. Where we reject a Call under clause 2.15 we will return an error identifying the reason, so that you can correct the file and resubmit; the technical and quality requirements are stated in the Documentation and it is for you to check a file against them before submitting it. Our records of Calls counted are conclusive absent manifest error, and you may query them within thirty days.
2.17 New features and feature-specific terms. We release new features from time to time. Unless we state otherwise, a new feature forms part of the Services and is governed by these Terms as they stand, and clause 2.8 applies to it. Where a feature needs terms specific to it — because it changes who decides something, introduces a new data flow, or carries a different allocation of risk — we will publish those terms in the Documentation, identified as feature-specific terms, and they apply to your use of that feature from the first time you use it. Feature-specific
terms supplement these Terms and, in respect of that feature only, prevail over them. Using a feature after such terms are published is your acceptance of them, and you may simply not use the feature. Feature-specific terms may not reduce your rights under clause 8 or Schedule 2, widen the limits in clause 13.2A of Schedule 2, or vary clause 2.2, 6.1, 6.4 or 11; any of those requires an amendment under clause 14.1.
3. LICENCE AND RESTRICTIONS
3.1 Licence. We grant you a non-exclusive, non-transferable, non-sublicensable, revocable licence, for the term of these Terms only, to access and use the Services, whether through the Playground or by direct calls to the API, and the Documentation, for the purposes set out in clause 2.3 or, once an Order Form takes effect, in P2 of Schedule 4.
3.2 Own use only. The Services are for your own use. You must not:
-
(a) resell, sublicense, rent, lend or otherwise make the Services, the Playground, the API or any Output available to any third party;
-
(b) white-label the Services or present them, or any Output, as your own product or capability, or under any name other than DeepXL;
-
(c) embed or expose the Services, directly or indirectly, in any product, application, interface or service used by your own customers or end users;
-
(d) submit Calls on behalf of, at the request of, or for the benefit of any third party, including any group company, agent, adviser, consultant or prospective customer of yours; or
-
(e) demonstrate the Services to any person outside your organisation without our prior written consent. Consent may be given in the Invitation, and is given for any demonstration expressly permitted by a negotiated agreement referred to in clause 2.14.
3.3 No benchmarking or publication. You must not use the Services to conduct any competitive analysis or benchmarking exercise, and you must not publish, disclose or otherwise make available to any third party any Output, test result, accuracy figure, error rate, latency measurement or other performance information relating to the Playground or the Services, without our prior written consent. This restriction survives termination.
3.4 No reverse engineering. You must not reverse engineer, decompile, disassemble or otherwise attempt to derive the source code, model architecture, model weights, training data, thresholds, features or decision logic of the Services, nor use the Services, the Playground, the API or any Output to train, fine-tune, validate, distil or develop any machine learning model, algorithm or competing service. Where mandatory law confers a right to decompile that cannot be excluded, this clause applies only to the extent that law permits, and you will notify us in advance and give us a reasonable opportunity to provide the information you require.
3.5 Acceptable Use Policy. Your use of the Services is subject to the Acceptable Use Policy in Schedule 1, which forms part of these Terms.
3.6 Monitoring. We may monitor your use of the Services, including Call volumes, patterns, file characteristics and metadata, to verify compliance with these Terms, to protect the security and integrity of our systems and to detect misuse. Where we sample Customer Content for that purpose, we do so in accordance with clause 8 and Schedule 2.
3.7 Reservation of rights. All rights in the Services, the Playground, the models, the training data, the Documentation, the Outputs in their aggregated and de-identified form, and all improvements to any of them, are and remain ours or our licensors’. You acquire no right, title or interest in any of them other than the licence expressly granted in clause 3.1. No rights are granted by implication, estoppel or otherwise.
3.8 Feedback. If you give us feedback, suggestions, bug reports, ratings, corrections or ideas relating to the Playground, the console, the Documentation, the Services or any Output — whether given through a feedback function in the account, by rating a Call, or otherwise — you assign to us all rights in that feedback, to the extent assignable, and otherwise grant us a perpetual, irrevocable, worldwide, royalty-free and sublicensable licence to use it for any purpose without restriction or compensation. That includes using it to evaluate and improve detection quality, to identify and correct error in an Output, and to inform the fraud-prevention layer described in clause 4.4, subject to the limits in clause 13 of Schedule 2. Your feedback is not Customer Content, and clause 4.6 does not restrict our use of it. You must not include Customer Content, or personal data relating to any person, in feedback. Feedback given through the account is associated automatically with the Call it concerns, so there is no need to describe or
identify the file, the document or any person in order to be understood: say what was good or poor about the result. Where feedback nonetheless contains personal data, that personal data is treated as Customer Content, is not assigned to us under this clause, is governed by clause 5 and Schedule 2, and is deleted with the Call it relates to under clause 8.3; and we may redact or delete it from the feedback at any time without notice, retaining the rating or assessment itself. Where moral rights or other rights cannot be assigned or waived under applicable law, you agree not to assert them against us or our licensees.
4. YOUR CONTENT
4.1 Ownership. You retain all right, title and interest in Customer Content. We claim no ownership of it.
4.2 Licence to us. You grant us a non-exclusive, worldwide, royalty-free licence to host, store, transmit, process, analyse and create derived data from Customer Content for the purposes of providing and securing the Services, verifying compliance with these Terms, the purposes stated in clause 8 and Schedule 2, and the fraud-prevention purpose in clause 4.4, and for no other purpose.
4.3 Derived data. Outputs, risk signals, feature values, hashes, fingerprints and technical metadata derived from Customer Content, in a form that does not identify you, are ours, and we may use them to operate, secure and improve the Services and for the purpose in clause 4.4.
4.4 Cross-customer fraud prevention. Document and object fraud is committed against many organisations using the same artefacts and the same forgery templates, so the Services would be materially less effective if each customer’s data were sealed off from every other. We therefore maintain a fraud-prevention layer in which we store, for each file submitted, technical signals derived from it — fingerprints, template and tamper signatures and derived risk signals, and not the file, a copy or image of it, or the content of any field in it — and we match new submissions against it across all customers. Clause 13.2 of Schedule 2 states what the layer holds, and clause 13.2A sets the limits on it, which we cannot widen without amending these Terms. Where a match is found, the Output may indicate that the same file, or a file matching the same forgery template or tamper pattern, has been submitted to us before. We will not disclose to you the identity of any other customer, when or how often a file was submitted, or any other information from which another customer, its business or its end users could be identified or inferred, and we will not disclose your identity or your submissions to any other customer. You must not attempt to identify, and must not use an Output to identify or draw any inference about, any other customer of ours or any other submitter of a file.
4.5 Your part in clause 4.4. You acknowledge that we act as an independent controller for the fraud-prevention layer, on the basis and subject to the safeguards in clause 13 of Schedule 2, and that this processing is not carried out on your instructions and is outside the processor relationship described in clause 8.1. Your disclosure of Customer Content to us for that layer is your own processing, for which you rely on your legitimate interest, and that of the persons harmed by document fraud, in preventing fraud (recital 47 to the GDPR) or on another lawful basis available to you. You will ensure that the privacy notice or equivalent disclosure you give to the persons whose data appears in Customer Content states that files may be submitted to a third-party fraud-prevention service which retains fingerprints and derived signals for fraud-prevention purposes and refers them to section 3 of our Privacy Policy, published in the legal section of our website at deepxl.ai, and you will not submit a file where the law applicable to you does not permit that. That notice is the means by which the persons concerned are directed to the information we publish under Article 14(5)(b) of the GDPR. Clause 13 of Schedule 2 states what the layer contains, how long it is kept and how a person may exercise their rights in respect of it.
4.6 No training on Customer Content. We do not use Customer Content to train, fine-tune, validate or evaluate any machine learning model, and we do not use it to develop any product or service otherwise than by operating the Services for you. The only material derived from Customer Content that we use to improve the Services is the de-identified derived data described in clause 4.3, which does not identify you, and the fraud-prevention signals described in clause 4.4, which are pseudonymised and are held and used only within the limits in clauses 13.2A and 13.6A of Schedule 2. This clause applies during the Evaluation Period and in production alike; Schedule 4 does not vary it, and clause 2.2(c) of Schedule 2 states the same limit for the purposes of our processing on your instructions.
5. FILES YOU MAY SUBMIT — YOUR SOLE RESPONSIBILITY
This is the most important clause in these Terms. The Services are intended for synthetic files and for files relating to you or to a person who has agreed to it, or for whom you hold another documented lawful basis. Personal data may be submitted, and this clause 5 and Schedule 2 govern it. Whatever you submit, you carry the whole of the responsibility and the whole of the risk for it.
5.1 Permitted files. You may submit only:
-
(a) synthetic, specimen or wholly fictitious files that contain no personal data relating to any living person;
-
(b) files relating only to the individual submitting them; or
-
(c) files containing personal data relating to another person, where that person has given consent to the submission in advance in accordance with clause 5.2 or, where consent is not the appropriate lawful basis in your circumstances, where you have identified and documented another lawful basis on which you rely and can produce that documentation to us on request.
5.2 Consent. Consent for the purposes of clause 5.1(c) must be freely given, specific, informed and unambiguous, must be given by a clear affirmative act, must be recorded by you in a form you can produce to us on request, must be capable of being withdrawn at any time without detriment, and must cover the submission of the file to us for the analysis requested and its retention for the period in clause 8.3. Consent is not the mechanism for the transfer described in clause 8.3, which is ours and is made under clause 8.4; but the person must have been informed, in your privacy notice or otherwise as Data Protection Law requires, that the file is processed on infrastructure located outside the EEA under the safeguards described in clause 8.4 and in section 3 of our Privacy Policy. Consent is not freely given where the person could not have refused without disadvantage. You are responsible for assessing whether consent is a valid lawful basis in the circumstances; where it is not, you must not submit the file unless the second limb of clause 5.1(c) applies. If consent is withdrawn, or a lawful basis ceases to apply, you will notify us at legal@deepxl.ai and we will delete the file on request.
5.3 Prohibited files. We do not analyse, extract, infer or index special categories of personal data as such, and we do not use Customer Content to derive any characteristic of a person beyond the authenticity and parsing signals described in clause 2.2. You must not submit any file containing:
-
(a) special categories of personal data, or personal data relating to criminal convictions and offences, where the file is submitted in order to reveal, analyse, extract or act on such data, or where such data is the subject matter of the file rather than incidental to it. Such data appearing incidentally in a document submitted for authenticity analysis or parsing does not breach this clause, provided that clause 5.4(d) is satisfied. Examples of incidental appearance are a transaction in a bank statement that reveals a religious, political, health-related or trade-union connection, and a place of birth, nationality or photograph appearing in an identity document;
-
(b) genetic data, or biometric data processed for the purpose of uniquely identifying a person, in either case whether incidental or not;
-
(c) personal data relating to a person under the age of 18, where the file is submitted in order to process that person’s data for a purpose other than verifying a document or object connected with a product, service, application, account or claim to which that person, or their parent or guardian, is or seeks to be a party. Where such data is present because that person is the subject of, or a party to, the matter being verified, the submission does not breach this clause provided that clause 5.4(e) is satisfied. You must not in any event use the Services or any Output to profile a person under the age of 18, to market to them, or to assess them for a purpose unconnected with such a product, service, application, account or claim;
-
(d) data obtained unlawfully, held in breach of a duty of confidence, or subject to legal privilege;
-
(e) data whose disclosure to us would breach any law, regulation, contract, professional obligation or obligation you owe to any person; or
-
(f) malicious code, or any file crafted to exploit, overload or interfere with our systems.
5.4 Your representations. You represent and warrant, on each Call, that:
-
(a) the file complies with clauses 5.1 and 5.3, and you hold the consent required by clause 5.2 or the documented lawful basis permitted by clause 5.1(c);
-
(b) you hold every other right, notice, authorisation and lawful basis necessary for the submission of the file, for its processing and storage on the infrastructure described in clause 8.3, and for its retention and use as described in clause 8 and Schedule 2, and clause 13.3 of these Terms does not apply to you;
-
(c) the submission infringes no intellectual property, privacy or publicity right and breaches no law, contract, duty of confidence or professional obligation, and you have taken reasonable steps to satisfy yourself that the file contains no malicious code;
-
(d) where special categories of personal data, or personal data relating to criminal convictions and offences, appear incidentally in the file, you have identified and can document a condition under Article 9(2) or Article 10 of the GDPR (as defined in Schedule 2), or the equivalent under the Data Protection Law applicable to you — for example explicit consent, or a national-law basis available to an obliged entity under anti-money-laundering legislation — that permits the processing, and our processing on your instructions falls within it; and
-
(e) where personal data relating to a person under the age of 18 is present, you have a lawful basis for the submission, you have taken account of the additional protection that children’s personal data requires under the Data Protection Law applicable to you, you hold any parental or guardian authorisation that law requires, and you have carried out any data protection impact assessment that law requires; that assessment is yours and not ours.
5.5 Sole responsibility. You are solely responsible for Customer Content, for the lawfulness of its collection and submission and for all consequences of its submission, including any claim, complaint, request, investigation, enforcement action, penalty, order or loss arising from it. We do not review, screen, validate or approve Customer Content before processing, we are under no duty to do so, and any monitoring under clause 3.6 does not constitute review or approval and creates no duty of care. Our willingness to process a file, and the fact that the Services accept it, is not an assessment or confirmation that its submission was lawful. Where you are a controller, the assessment of lawful basis, purpose compatibility, necessity and proportionality is yours alone; where you are a processor, operador, encargado or equivalent for another person, we are your sub-processor and it is your responsibility, not ours, to hold the authorisations, instructions and transfer mechanism your own arrangements require.
5.6 Indemnity. You will indemnify, defend and hold harmless DeepXL and its officers, employees and sub-processors against all claims, demands, proceedings, investigations, fines, penalties, damages, losses, costs and expenses (including reasonable legal fees) arising out of or in connection with (a) any breach of clause 5.1, 5.2, 5.3 or 5.4, (b) any Customer Content, (c) any use of or reliance on any Output in breach of clause 2.3 or clause 6, and (d) any breach of clause 2.3, 3.2, 3.3 or 3.4. This indemnity is not subject to the limits in clause 11.
5.7 Our remedies. We may reject, refuse to process, quarantine or delete any file at any time, without notice and without liability, and we may suspend or terminate your access under clause 12 if we reasonably suspect a breach of this clause 5. If you become aware that a prohibited file has been submitted, you will notify us without undue delay at legal@deepxl.ai and we will delete it on request; deletion at your request does not limit your liability under clause 5.6.
6. OUTPUTS — NO RELIANCE
6.1 Nature of Outputs. Outputs are probabilistic risk signals generated by machine learning models. They are statistical indications only. They are not, and must not be treated as, a finding of fact, a determination of authenticity, genuineness, validity or identity, a legal or regulatory conclusion, professional advice, a consumer report, a credit assessment, or a recommendation. This clause applies during the Evaluation Period and in production alike, and P1.1 of Schedule 4 does not replace it.
6.2 No reliance during the Evaluation Period. You must not rely on any Output obtained during the Evaluation Period. Such Outputs must not be used, alone or together with any other information, as the basis for, or as a contribution to, any decision about any person, transaction, application, account, claim or entitlement, and must not be recorded in, or referred to in, any decision, file, report or communication concerning any person. If you wish to use Outputs operationally you must first sign an Order Form under clause 2.10. The stricter rule in this clause applies only during the Evaluation Period, but it does not follow that Outputs may be relied on without qualification once an
Order Form is in force: clause 6.1 continues to apply in production, and P5 of Schedule 4 sets out the rules that then govern.
6.3 False results. False positives and false negatives occur, in the Evaluation Period and in production alike. Detection performance depends on the quality, format and type of the file submitted, on whether the type and market have Specialist Coverage under clause 6.6, and on the thresholds, decision rules and escalation procedures you apply, which are yours to set and yours to monitor for their effect on your own outcomes. We do not warrant any detection rate, accuracy level or error rate, and no figure given in the Documentation or in any proposal or evaluation is a warranty. Results you obtain during the Evaluation Period come from the same models you would use in production, but they are not a warranty or a prediction of the performance you will see on your own live traffic, which depends on your data, your document mix and your configuration.
6.4 Prohibited regulated uses. We are not a credit reference agency, credit bureau, consumer reporting agency or background screening provider in any jurisdiction; we do not assemble or evaluate information about natural persons for the purpose of furnishing credit references, consumer reports or screening reports; and the Services and the Outputs are not, and must not be used as, a credit reference, consumer report, credit score or creditworthiness assessment. You must not use the Services or any Output (a) to evaluate the creditworthiness of a natural person or to establish their credit score, or as the basis for a decision that a person is or is not eligible for credit, insurance, employment, housing, a licence or a public benefit; (b) for any purpose regulated by consumer-reporting, credit-reporting or background-screening law, including, where they apply to you, the United States Fair Credit Reporting Act, 15 U.S.C. § 1681 et seq., the Equal Credit Opportunity Act, the Driver’s Privacy Protection Act and the Illinois Biometric Information Privacy Act, or any equivalent or successor law; or (c) in a manner that would make us the provider of an AI system intended for a purpose listed in point 5(b) of Annex III to the AI Act. Using an Output, in production and with the human review required by P5 of Schedule 4, as one indication among others of whether a document or object submitted to you is genuine is not prohibited by this clause; using it to assess a person is. You must not describe us, or permit any person to describe us, as a credit reference agency, consumer reporting agency or equivalent. Where you are subject to obligations concerning automated decision-making, adverse action, fairness, explainability or human review, including under Article 22 of the GDPR as interpreted by the Court of Justice in Case C-634/21 (SCHUFA), those obligations are yours alone. This clause applies during the Evaluation Period and in production alike. Breach of it is a material breach and you will indemnify us for it under clause 5.6.
6.5 AI regulation. “AI Act” means Regulation (EU) 2024/1689 as amended from time to time, including by Regulation (EU) 2026/1744. As between the parties we are the provider of the Services as an AI system and you are the deployer; your obligations as a deployer, including under Articles 4 and 26 of the AI Act where they apply to you, are yours alone. The intended purpose of the Services is the authenticity analysis of documents and of images of physical objects and the extraction of structured data from documents. The Services are not designed, documented or conformity-assessed as a high-risk AI system and are not intended for any purpose listed in Annex III to the AI Act; they do not perform biometric identification, biometric verification or biometric categorisation (clause 2.2) and are therefore outside point 1 of Annex III; and they detect synthetic or manipulated content rather than generating or manipulating it, so the marking obligations in Article 50(2) do not apply to us in respect of the Outputs. You must not use the Services as, or as a component of, an AI system intended for a purpose listed in Annex III, or as a safety component of a product covered by Annex I, without our prior written consent, which we may give or decline at our discretion and may give subject to additional terms, documentation and fees. Where we consent, or where you do so notwithstanding this clause: (a) you are the provider of that system and the obligations of a provider are yours; (b) we will make available the supplier information package described in the Documentation, which is the written specification of information, capabilities, technical access and assistance for the purposes of Article 25(4) of the AI Act, and that package, not any open-ended obligation, discharges our duties under that Article; and (c) you will not represent that the Services have been assessed for that purpose. Clause 3.2 prohibits you from placing the Services on the market under your own name or trademark; if you do so notwithstanding that prohibition, or substantially modify them or change their intended purpose, you are the provider of the resulting AI system under Article 25(1) of the AI Act, assume the corresponding obligations and indemnify us under clause 5.6. The obligations in this clause are assumed as a matter of contract from the Effective Date, and apply irrespective of the application dates in Article 113 of the AI Act and irrespective of whether and when the AI Act is incorporated into the EEA Agreement or brought into force in Norway.
6.6 Specialist and general coverage. For some document and object types, and for some issuing countries or markets, we have built type-specific expertise into the Services: dedicated checks, references and thresholds for that type as
issued in that market (“Specialist Coverage”). Where a submitted file is of a type and market with Specialist Coverage, the Output is materially more accurate than it would otherwise be. Where it is not, the file is analysed under our general method and reported in the “Other” category (“General Coverage”): the analysis is type-agnostic, it applies no type-specific reference or check, and materially lower detection performance is to be expected and you should treat the Output accordingly.
6.7 The coverage list. The document and object types and markets that have Specialist Coverage at any time are listed in the Documentation. That list is maintained by us and is updated from time to time; we may add a type or market and we may withdraw one, and a change to the list is not a change to these Terms and does not require notice under clause 14.1. You can determine which coverage was applied to a Call by comparing the type reported in the Output with the list. It is for you to check the list before relying on the Services for a type, and we give no warranty, and make no representation, that any type or market is covered, will be added, or will remain covered. Where we withdraw Specialist Coverage for a type you have been submitting in volume, P4.3 of Schedule 4 applies to that change once an Order Form is in force.
6.8 Charging is unaffected. A Call is charged, and draws down your allowance or Balance, whether it is analysed under Specialist Coverage or General Coverage, unless an Order Form provides otherwise. Submitting a file of a type without Specialist Coverage is not a failure of the Services and gives rise to no claim under P8.1 of Schedule 4.
6.9 Customer Configuration. We may make available features that let you depart from our standard weighting, thresholds, signal treatment or decision rules, in whole or in part, in whatever respects the feature allows (a “Customer Configuration”). What may be configured is whatever we make configurable from time to time and is described in the Documentation; nothing in these Terms limits it to any particular finding, signal or setting, and any example given is illustrative only — so, for instance, you might choose to treat a document with missing pages as more or less significant than we do by default. A Customer Configuration is optional. Our standard settings apply unless and until you configure otherwise, and you may revert to them at any time. Our standard settings reflect our own assessment of what a finding indicates; a Customer Configuration replaces that assessment to the extent you configure it. An Output produced under a Customer Configuration is produced on your instructions and to your specification. You are responsible for the configuration, for testing it before you rely on it, for monitoring its effect on your own outcomes, and for the consequences of it. Detection performance under a Customer Configuration may be materially worse than under our standard settings, and any figure we publish or discuss relates to our standard settings only. The warranty in P8.1 of Schedule 4 does not apply to an Output to the extent it is affected by a Customer Configuration, and clause 7.2 applies to such an Output without qualification: our warranty goes to the manner in which we perform, not to a configuration we did not choose. Clauses 6.6 to 6.8 are unaffected, and a Customer Configuration does not extend Specialist Coverage to a type that does not have it. Using only the configuration options we make available is use in accordance with the intended purpose of the Services and is not a substantial modification for the purposes of clause 6.5. Clause 2.8 applies to configuration options, which we may add, change, limit or withdraw at any time. The configuration itself is yours; clause 4.3 applies to de-identified data about configurations in the aggregate.
7. WARRANTIES AND DISCLAIMER
7.1 Mutual warranty. Each party warrants that it has the legal capacity and authority to enter into these Terms.
7.2 Disclaimer. Except as expressly stated in clause 7.1, and to the fullest extent permitted by applicable law, the Services, the Playground, the API, the Documentation and all Outputs are provided “as is” and “as available”, without warranty, condition, representation or term of any kind, whether express, implied, statutory or otherwise. We specifically disclaim any warranty of merchantability, satisfactory quality, fitness for a particular purpose, non-infringement, accuracy, completeness, reliability, availability, security, uninterrupted or error-free operation, and any warranty arising from course of dealing, usage or trade practice. We do not warrant that the Services will detect any fraudulent, altered, forged or synthetic document or object, or that any Output is correct.
7.3 Effect of payment. Where use during the Evaluation Period is without charge, no warranty, condition or term implied by law in respect of goods, digital content or services supplied for consideration applies to it. Where you have paid a charge under clause 10, clause 7.2 continues to apply to the fullest extent permitted by applicable law, and payment does not give rise to any warranty of accuracy, availability, performance or fitness for purpose. Where mandatory law implies a term that cannot be excluded, our liability for its breach is limited as set out in clause 11.
8. DATA PROTECTION AND PROCESSING LOCATION
8.1 Roles. To the extent that Customer Content contains personal data, you are the controller (controlador, responsable, business or equivalent) and we are the processor (operador, encargado, service provider or equivalent), acting only on your documented instructions. Where you are yourself a processor for a third party, we are a sub-processor.
8.2 Data Processing Addendum. The Data Processing Addendum in Schedule 2 governs that processing. It forms part of these Terms, and it is accepted by the same act and at the same time as these Terms. It applies to all personal data in Customer Content, whether submitted in accordance with clause 5.1 or in breach of clause 5.3. Schedule 2 is intended to satisfy the requirements of Article 28(3) of the GDPR and the equivalent provisions of the other laws identified in Schedule 2, Schedule B.
8.3 Processing location. All Customer Content is processed and stored on servers located in the United States, irrespective of where you are established, where the Services are accessed from, or where any data subject is located. There is no regional, local or in-country processing option, and none can be requested. We are the exporter of that data and clause 8.4 and clause 9 of Schedule 2 govern the transfer. By accepting these Terms and by each Call you give the documented instruction and authorisation for that transfer that clause 9.2 of Schedule 2 records, and you confirm that the information you give to the persons concerned under clause 5.2 describes it. Retention. Customer Content submitted to the Services is deleted twelve (12) months after the Call, on a rolling basis, applying the same standard retention period as our other services. That period continues to run irrespective of termination of access. It is applied for the purposes stated in clause 2.2 of Schedule 2, including quality assurance, and is enforced automatically by scheduled processes in our own systems with failure alerting, not by manual routine. Because those processes run periodically, deletion occurs within twelve months plus a short operational margin. A submitted file is not recoverable once deleted. Entries in our database, being the derived signals and the fraud-prevention layer, remain technically restorable through the database platform’s point-in-time restore for up to seven (7) days after deletion, after which they are permanently gone. Where a processing operation fails, content from a submitted file may also appear in error logs, which are held in the same cloud subscription and region and are deleted after thirty (30) days. You may at any time (a) request a shorter standard retention period for your account, down to thirty (30) days, or (b) request deletion of all Customer Content in your account, or of a particular file identified by its Call reference, in each case by writing to legal@deepxl.ai; clause 11 of Schedule 2 governs how we do that. Derived Outputs, technical metadata and logs are retained for the periods stated in Schedule 2, Schedule A.
8.4 International transfers. We are established in Norway. Where you are established in the European Economic Area, the United Kingdom or Switzerland, your submission of Customer Content to us is not a transfer to a third country. The onward transfer by us to sub-processors outside the EEA is a transfer under Chapter V of the GDPR for which we are the data exporter, and it is made under the mechanisms in clause 9 of Schedule 2: the EU–US Data Privacy Framework where the sub-processor is certified under it and the transfer falls within its certification, and otherwise, and automatically as a fallback where they are available with that sub-processor, the Standard Contractual Clauses (Module Three) supported by our transfer impact assessment; clause 9.3 of Schedule 2 states the position where they are not available. Where you are established outside the EEA, the United Kingdom and Switzerland, our return of Customer Content and Outputs to you is itself a transfer by us to a third country, and Module Four of the Standard Contractual Clauses applies between us as set out in clause 9.4 of Schedule 2, with Part A of Annex I completed from your registration information as described in Schedule 3. Any requirement that the law applicable to you imposes on your own disclosure of Customer Content to us is yours to satisfy, as Schedule B to Schedule 2 explains.
8.5 Security and personal data breaches. We maintain the technical and organisational measures described in Schedule 2, Schedule C. We will notify you without undue delay after becoming aware of a personal data breach affecting Customer Content, in the manner and with the information described in clause 10 of Schedule 2 and in a way that enables you to meet your own obligation under Article 33(1) of the GDPR; our obligation as processor is that in Article 33(2), and the seventy-two-hour period in Article 33(1) is yours.
8.6 Our own processing. Our processing of your business contact and account data as a controller in our own right — for account administration, billing, security, legal compliance and communications — is described in our Privacy Policy, published in the legal section of our website at deepxl.ai, as is the fraud-prevention layer for which we are controller under clause 4.4.
9. CONFIDENTIALITY
9.1 Obligation. Each party will keep the other’s Confidential Information confidential, will use it only for the purposes of these Terms, and will disclose it only to those of its personnel and advisers who need it and who are bound by obligations no less protective than these. “Confidential Information” means information disclosed by or on behalf of a party that is identified as confidential or that a reasonable recipient would understand to be confidential.
9.2 Our Confidential Information expressly includes. The existence and content of the invitation; the Documentation; the API structure, endpoints, request and response schemas, parameters and error codes; model behaviour, thresholds, scores, feature names and decision logic; Outputs; and all performance, accuracy, latency and error information relating to the Playground and the Services.
9.3 Exclusions. The obligation does not apply to information that is or becomes public without breach of these Terms, was lawfully known to the recipient without obligation of confidence before disclosure, is independently developed without use of the other’s Confidential Information, or is lawfully received from a third party without restriction.
9.4 Compelled disclosure. A party may disclose Confidential Information where required by law, regulation or a competent authority or court, provided that, where lawful and practicable, it notifies the other party in advance and limits the disclosure to what is required.
9.5 Duration and remedies. This clause survives termination for five (5) years, and indefinitely in respect of trade secrets. Damages may not be an adequate remedy for breach, and each party may seek injunctive or other interim relief without proving actual damage and without posting security.
9.6 Publicity. Neither party will issue any public statement referring to the other or to these Terms without the other’s prior written consent. In particular, you must not state or imply that you are a customer, partner, reseller or integrator of DeepXL, or that the Services are or will be part of your product, on the basis of Evaluation Period access.
10. FEES AND INVOICING
10.1 Charges. Use during the Evaluation Period is without charge unless an Invitation states a charge, which is agreed with you before the Invitation is issued; where no Invitation is issued, use during the Evaluation Period is without charge. A charge may be expressed as a fixed evaluation fee for the period, as a price per Call, or as a combination of the two; the Invitation states which, and where it states a price per Call it also states the included allowance, if any, and the rate for Calls above it. No charge arises, and no charge may be introduced, during the Evaluation Period other than by a written variation of the Invitation signed or confirmed by e-mail by both parties, or by a written agreement where no Invitation was issued. There is no payment card, no subscription, no prepaid credit and no automatic charging during the Evaluation Period, and no obligation on you to make any purchase during or after it.
10.2 Payment in advance. All amounts are payable in advance. Where the Invitation states a charge, we issue an invoice for it and access begins when payment is received in cleared funds; we are not obliged to give access before then. Payment is made in the currency stated in the Invitation, by bank transfer to the account stated on the invoice, without set-off, deduction or withholding. Amounts are exclusive of value added tax and any other tax, duty or levy, which you will pay in addition where applicable. Where the reverse charge or an equivalent mechanism applies, you will account for the tax in your own jurisdiction and you will provide your VAT or tax identification number on request; if you do not, we may charge Norwegian value added tax. If any deduction or withholding for or on account of tax is required by law, you will pay such additional amount as is necessary for us to receive and retain the amount we would have received had none been required, and will provide the official withholding certificate within thirty days. This clause applies to amounts payable under clause 10 and, subject to P7 of Schedule 4, to Fees payable in production.
10.3 No credit. We do not extend credit. Where an amount is invoiced but not paid, we may withhold or suspend access until payment is received, and any amount that becomes overdue bears interest at the rate set under the Norwegian Late Payment Interest Act (forsinkelsesrenteloven) from the due date until payment.
10.4 Refunds. Amounts paid in advance are non-refundable, except that where we terminate or revoke access for convenience under clause 2.4, or discontinue the Services, before the end of the period paid for, we will refund the unused portion on a pro rata daily basis. No refund is due where access is terminated or revoked for cause under clause 12.1, where you terminate, or in respect of Calls already made. Nothing in this clause limits a refund required by mandatory law.
10.5 Effect on liability. Where you have paid us nothing, clause 11.2 applies; where you have paid a charge, clause 11.3 applies instead.
10.6 Payment does not change the nature of Evaluation use. A charge under this clause is consideration for access to a non-production evaluation environment and nothing more. Payment does not permit production use, does not vary clause 2.3, 2.9 or 6.2, does not create any service level, availability commitment or support obligation, does not affect clause 2.7 or 2.8, and does not entitle you to an Order Form under clause 2.10 or oblige us to offer one.
11. LIMITATION OF LIABILITY
11.1 Basis of this clause. During the Evaluation Period the Services are provided for evaluation only, with no availability or performance commitment and no reliance permitted on any Output, and without charge unless the Invitation states a modest evaluation charge set on the basis of this clause. The exclusions and limits in this clause are a fundamental basis on which access is made available at all. The parties are professionals, each has had the opportunity to take independent legal advice, and a customer that requires a different allocation of risk may seek a negotiated enterprise agreement under clause 2.14 in which that allocation is priced; on that basis the parties agree that the exclusions and limits in this clause are reasonable in the context of these Terms.
11.2 Exclusion of our liability where no charge is paid. Where use during the Evaluation Period is without charge to you, and subject only to clauses 11.3 and 11.4, we exclude all liability to you arising out of or in connection with these Terms, the Services, the Playground, the Documentation, any Output and any Customer Content, whether in contract, tort (including negligence), breach of statutory duty, restitution or otherwise, to the fullest extent permitted by applicable law. Without limiting that exclusion, we have no liability for: the Services or the Playground being unavailable, suspended, withdrawn, reset, changed or discontinued; any error, inaccuracy, false positive or false negative in an Output; any decision, act or omission based on an Output; the loss, deletion, corruption or non-availability of Customer Content; any failure to detect any fraudulent, altered, forged or synthetic document or object; or any delay in performance.
11.3 Cap where a charge is paid, and where exclusion is not permitted. Clause 11.2 does not apply, and this clause applies instead, where either (a) you have paid us any amount under clause 10, or (b) applicable law does not permit the exclusion in clause 11.2 in a particular case. In either case our total aggregate liability arising out of or in connection with these Terms, however arising, is limited to the charges you have paid us under clause 10 for use in the twelve months preceding the event giving rise to the liability — for a fixed charge, the part of it attributable to that period; for per-Call charges, those for Calls actually made — and where that amount is less than five hundred euro (EUR 500), to five hundred euro (EUR 500) in aggregate for all claims. An amount you have paid in advance for a period that has not yet run, or for Calls not yet made, is not taken into account. A single cap applies to all claims, including a claim arising from a personal data breach; clause 12.1 of Schedule 2 preserves the position that it does not apply to the extent Data Protection Law or the Standard Contractual Clauses do not permit it.
11.4 Liability that can never be limited. Nothing in these Terms limits or excludes either party’s liability for death or personal injury caused by its negligence, for fraud or fraudulent misrepresentation, for gross negligence or wilful misconduct, or for any other liability that cannot lawfully be limited or excluded under the law applicable to these Terms.
11.5 Excluded heads of loss. In any event, and in addition to clauses 11.2 and 11.3, neither party is liable to the other for loss of profit, loss of revenue, loss of anticipated savings, loss of business or business opportunity, loss of goodwill or reputation, loss of or corruption of data, wasted expenditure, regulatory fines imposed on the other party, or any indirect or consequential loss, in each case however arising and whether or not foreseeable.
11.6 Your obligations are not limited; and how data claims are characterised. Clauses 11.2, 11.3 and 11.5 limit our liability only. They do not limit your obligations to pay amounts due under clause 10, your obligation to pay for unauthorised production use under clause 2.13, your indemnity under clause 5.6, or your liability for breach of clause 2.3, 3.2, 3.3, 3.4, 5.1, 5.2, 5.3, 6.2 or 9, none of which is subject to any cap. We are not liable for any loss to the extent it arises from a Customer Configuration under clause 6.9, from your own thresholds or decision rules, or from your use of a feature contrary to feature-specific terms published under clause 2.17. A claim against us arising from unauthorised disclosure of, failure to protect, or other mishandling of personal data contained in Customer Content is governed exclusively by clause 8, Schedule 2 and clauses 11.2 and 11.3, and is not a breach of clause 9 (confidentiality) for the purposes of this clause.
11.7 Time limit. Any claim against us must be brought within twelve months of the date on which the claimant first became aware, or ought reasonably to have become aware, of the circumstances giving rise to it, failing which it is barred, save where applicable law does not permit that limitation.
11.8 No exclusion of your own compliance. Nothing in these Terms transfers to us, or relieves you of, any obligation you owe under data protection, consumer protection, financial services, anti-money-laundering or any other law in respect of your own activities.
12. SUSPENSION, TERMINATION AND EFFECT
12.1 Termination and suspension. In addition to clause 2.4, we may suspend or terminate access immediately, without notice and without liability, where we reasonably suspect a breach of clause 3, 5, 6 or 9, where required by law or by a competent authority, where continued access presents a security, legal, regulatory or reputational risk, or where an invoice is overdue.
12.2 Effect of termination. On termination: the licence in clause 3.1 ends immediately; you will cease all use of the Services, delete all API credentials, and delete all copies of the Documentation and any Output in your possession; and Customer Content continues to be deleted in accordance with clause 8.3 and clause 11 of Schedule 2.
12.3 Survival. Clauses 1.8, 2.9 to 2.17, 3.3, 3.4, 3.7, 3.8, 4.3 to 4.6, 5.5, 5.6, 6, 7, 9, 10, 11, 12.2, 12.3, 15 and 16, and Schedule 2 to the extent processing continues, survive termination.
12.4 No transition right. Termination or expiry of access creates no right to continued access, to production access, to an Order Form, or to any migration, export or transition assistance. Clauses 2.10 and 2.12 govern any move to production, and nothing in the Evaluation Period obliges either party to sign an Order Form or to agree any particular commercial term.
13. SANCTIONS, EXPORT CONTROL AND TERRITORIES WE DO NOT SERVE
13.1 Your representation. You represent and warrant, on the Effective Date and on each Call, that neither you, nor any entity controlling or controlled by you, nor any of your directors, officers or beneficial owners, is a person designated on any sanctions list maintained by the United Nations, the European Union, the Kingdom of Norway, the United Kingdom or the United States, or is established, resident or located in, or acting for the benefit of any person in, a Restricted Territory.
13.2 Restricted Territories — self-defining. “Restricted Territory” means any country, territory or region that is, at the relevant time, (a) subject to comprehensive, territory-wide or embargo-level sanctions or restrictive measures imposed by the United Nations, the European Union, the Kingdom of Norway, the United Kingdom or the United States, or (b) notified by us to you in writing, or identified as a Restricted Territory on any page we publish for that purpose, as a Restricted Territory. Limb (a) applies of its own force and does not depend on any list maintained by us; a territory that ceases to be so sanctioned ceases to be a Restricted Territory without any act of either party. We may add a territory under limb (b) at any time and for any reason, including the reasons in clause 13.3, and may block access from any territory, including by geolocation.
13.3 Territories we do not serve for data protection reasons. You must not register for or use the Services, and we may block or terminate access without liability, where the law applicable to you requires, as a condition of the transfer and processing described in clause 8.3, any of the following that we do not hold: a filing, registration, approval, licence, security assessment or certification with or from a public authority; the use of a standard contract or transfer instrument prescribed by that authority in place of the Standard Contractual Clauses incorporated under clause 9 of Schedule 2; or the localisation of the personal data within your jurisdiction. This clause applies of its own force to any jurisdiction whose law imposes such a requirement, whether or not it is named anywhere in these Terms, and whether the requirement exists at the Effective Date or is introduced later. Mainland China is presently such a jurisdiction, because the Personal Information Protection Law requires a filed standard contract, a security assessment or certification which the Standard Contractual Clauses do not satisfy. It is for you, not us, to determine whether this clause applies to you, and your representations in clause 5.4 cover that determination.
13.4 No local obligations for us. You will not use the Services in a way that requires us to appoint a local representative or data protection officer, to register or notify a supervisory or other authority, to obtain a licence or authorisation, to hold data within a particular territory, or to make any filing, in your jurisdiction or in the jurisdiction of any data
subject. If we determine that your use has or would have that effect, we may block or terminate access on notice, and clause 10.4 applies to any fixed fee you have paid.
13.5 Screening and information. We may screen you, your beneficial owners and your intended use before issuing an invitation, before granting access on registration, and at any time afterwards. You will provide the information we reasonably request for that purpose, including ownership and control information and a description of your intended use, without undue delay, and we may suspend or withhold access until you do. Failure to provide it is a material breach.
13.6 Export control. You will not export, re-export or make the Services, the Documentation or any Output available in breach of any applicable export control or sanctions law. Nothing in this clause 13 requires either party to act, or to refrain from acting, in a manner that would cause it to breach Council Regulation (EC) No 2271/96 or any equivalent blocking measure applicable to it, and either party may suspend performance to the extent necessary to comply with a sanctions measure. Breach of this clause 13 is a material breach and entitles us to terminate with immediate effect.
14. CHANGES
14.1 Changes to these Terms. We may amend these Terms by publishing a new version at the URL on the cover page, bearing a new version number and an effective date. A new version applies immediately to anyone registering after it is published. For you, if you registered before it was published, we will give notice of the new version, identifying what has changed, by e-mail to your notice e-mail address and, where we make such a notice available, also by a notice displayed to an Authorised User in the account. The version you accepted continues to apply for thirty (30) days after notice is given, and the new version applies to your use from the end of that period. The thirty-day period runs from the e-mail; where we receive a delivery failure notification, clause 15.1 applies and the period runs from the notice displayed in the account, which is given when it is first made available whether or not an Authorised User signs in. Publication alone does not start that period; the notice does. Every version, current and superseded, remains available at that URL so that you can compare them. You may terminate under clause 2.4 at any time, including during that period. Where a new version materially reduces your rights or materially increases your obligations, and you terminate before it takes effect, we will refund any unexpired unused Balance and any unused portion of a fixed charge as if we had terminated for convenience under clause 10.4 or P7.3 of Schedule 4. Where a change is required by law or is necessary to address a security or legal risk, it takes effect on publication and we will give the notice as soon as practicable afterwards.
14.2 Changes to the Services. Clause 2.7 applies. We may change or discontinue the Services, the Playground or the API, in whole or in part, at any time.
15. GENERAL
15.1 Notices. Notices to us must be sent to legal@deepxl.ai. Notices to you are sent to the notice e-mail address in your registration information. You will ensure that address is valid, that it is monitored, and that it is kept current; a notice sent to it is effective whether or not we have verified it, whether or not it is monitored, and whether or not anyone reads it. A notice sent by e-mail is deemed received on the next business day in Oslo after sending, unless the sender receives a delivery failure notification. Where we receive a delivery failure notification for a notice under clause 14.1, we may instead give that notice by any other means reasonably likely to bring it to your attention, including a notice in your account.
15.2 Assignment. You may not assign or transfer these Terms or any right under them, including by operation of law or on a change of control, without our prior written consent. We may assign these Terms to an affiliate or in connection with a merger, reorganisation or sale of all or substantially all of our assets.
15.3 Subcontracting. We may perform our obligations through sub-processors and subcontractors in accordance with clause 8 of Schedule 2, and remain responsible for their performance.
15.4 No partnership, agency or exclusivity. These Terms create no partnership, joint venture, agency, employment, franchise, distributorship or fiduciary relationship, and no exclusivity. Neither party may bind the other. Nothing in these Terms restricts either party from dealing with any third party, including a competitor of the other.
15.5 Entire agreement. These Terms and their Schedules are the entire agreement between the parties in respect of the Services and supersede all prior discussions, proposals, representations and understandings relating to it, save for
the Invitation, which forms part of these Terms as provided in clause 1.1. Neither party has relied on any statement not set out in these Terms. This clause does not limit liability for fraudulent misrepresentation. Any non-disclosure agreement in force between the parties continues to apply, and where its terms conflict with clause 9, the terms more protective of the disclosing party prevail.
15.6 No waiver; severability. A failure or delay in exercising a right is not a waiver of it. If a provision is held invalid or unenforceable, it will be modified to the minimum extent necessary to make it enforceable, or, if that is not possible, severed, and the remaining provisions continue in force.
15.7 Force majeure. Neither party is liable for a failure or delay caused by an event beyond its reasonable control, provided it notifies the other and uses reasonable efforts to mitigate. This does not excuse an obligation to pay.
15.8 Third parties. These Terms confer no right on any person other than the parties, save that our sub-processors and personnel may rely on clause 5.6.
15.9 Language. These Terms are made in English. Any translation is for convenience only and the English text prevails, except where mandatory local law provides otherwise. Where the law of your jurisdiction requires that a standard-form contract be made available in another language before it binds you, we will provide a translation on request to legal@deepxl.ai, and by registering you confirm that you have had the opportunity to request one and have chosen to be bound by the English text to the extent that law permits.
16. GOVERNING LAW AND DISPUTES
16.1 Governing law. These Terms and any dispute arising out of or in connection with them, including their formation, validity and termination, are governed by Norwegian law, excluding its conflict-of-laws rules and excluding the United Nations Convention on Contracts for the International Sale of Goods.
16.2 Escalation. Before commencing arbitration, a party will give the other written notice describing the dispute, and the parties will attempt in good faith to resolve it within thirty days. This clause does not prevent an application for interim or injunctive relief.
16.3 Arbitration. Any dispute not resolved under clause 16.2 will be finally settled by arbitration in Oslo, Norway, under the Norwegian Arbitration Act (voldgiftsloven), before a single arbitrator, in the English language. The award is final and binding, and is enforceable in the courts of the parties’ respective jurisdictions under the New York Convention on the Recognition and Enforcement of Foreign Arbitral Awards. The parties will keep the arbitration and the award confidential, save as required by law or to enforce the award.
16.4 Costs of arbitration. The arbitrator allocates the costs of the arbitration between the parties in accordance with chapter 8 of the Norwegian Arbitration Act, the starting point being that the unsuccessful party bears the fees and expenses of the arbitrator and the reasonable legal costs of the successful party, save to the extent the arbitrator apportions them differently having regard to the outcome and the conduct of the parties. Nothing in these Terms limits the parties’ liability to the arbitrator for the arbitrator’s remuneration and expenses under that Act, or the arbitrator’s power to require security for them; as between the parties, a party that discharges more than the share allocated to it may recover the excess from the other. As between the parties, neither is obliged to advance any part of the other’s share of a deposit or security the arbitrator requires: where a party fails to advance a sum the arbitrator has requested within the time the arbitrator sets, the other party may apply to the arbitrator to stay or terminate the proceedings, and does not breach this clause 16 by declining to advance that sum on the defaulting party’s behalf. Neither party is required to provide security for the other party’s legal costs as a condition of commencing or continuing proceedings.
16.5 Interim relief. Either party may apply to any court of competent jurisdiction for interim, protective or injunctive relief, including to protect Confidential Information or intellectual property, without that application being a waiver of this clause 16.
16.6 Claims that need not go to arbitration. Notwithstanding clauses 16.3 and 16.7, and in each case as an alternative to arbitration at the claimant’s election, (a) either party may bring before Oslo tingrett a claim not exceeding EUR 10,000 or its equivalent, and (b) we may bring before Oslo tingrett any claim for payment of an amount due under clause 10 or clause 2.13 or under P7 of Schedule 4, together with interest and costs, whatever its value. The parties
accept Oslo tingrett as the agreed venue for such claims and waive any objection to that venue. Bringing such a claim is not a waiver of clause 16.3 in respect of any other dispute.
16.7 Individual proceedings. Each dispute is resolved individually between the parties to it. Claims of two or more customers may not be joined or consolidated, and no representative, collective or group proceeding may be brought, in arbitration under this clause 16 without the written consent of all parties concerned; the arbitrator has no authority to conduct such a proceeding, to certify a group, or to award relief to anyone other than a party to the arbitration. Where mandatory law nonetheless permits a group action before a court in respect of a particular claim, that claim alone is excluded from arbitration and is brought before Oslo tingrett, and the remainder of this clause 16 continues to apply to all other claims; that consequence is intended, because the parties prefer a collective claim to be heard by a court rather than by an arbitrator.
16.8 Mandatory rules of other laws. Clause 16.1 governs these Terms in full, and nothing in this clause 16.8 is a submission to any other law or forum or an agreement that any other law applies to these Terms. This clause 16.8 records only what is true in any event: a choice of Norwegian law does not switch off a rule of another legal system that applies of its own force notwithstanding the parties’ choice of law. That includes, in particular, data protection, sanctions, export control, competition, financial services and other regulatory law applying to your own activities in your own jurisdiction, and any rule that makes an arbitration agreement unenforceable against you. Where such a rule applies, it applies only to the extent it requires and only in respect of the claim or obligation it concerns, the remainder of these Terms and of this clause 16 continuing in force; and where it makes clause 16.3 unenforceable against you in respect of a claim, that claim alone may be brought before a court having jurisdiction under that rule. This clause confers no right on you beyond what such a rule itself requires.
SCHEDULE 1
ACCEPTABLE USE POLICY
This Acceptable Use Policy forms part of the Terms. Breach of it is a material breach and entitles DeepXL to suspend or terminate access with immediate effect under clause 12.1.
1. PROHIBITED PURPOSES
You must not use the Services:
-
during the Evaluation Period, for any production, live or operational purpose, or otherwise in breach of clause 2.3 or clause 6.2 of the Terms, whether or not your API credentials or credit allowance technically permit it — going live requires a signed Order Form under clause 2.10, and clause 2.13 makes unauthorised production use a material breach with uncapped liability;
-
during the Evaluation Period, to make, support, inform or document any decision about any person; and in production, to use an Output as the sole or determinative basis for any such decision, or without the human review required by P5 of Schedule 4, including any decision to grant, refuse, restrict, price, suspend or terminate a product, service, account, application, benefit, employment or entitlement;
-
to evaluate the creditworthiness of a natural person, to establish a credit score, or for any consumer- reporting, credit-reporting or background-screening purpose, including any purpose regulated by the United States Fair Credit Reporting Act, the Equal Credit Opportunity Act, the Driver’s Privacy Protection Act or the Illinois Biometric Information Privacy Act where they apply to you, or any equivalent or successor law (clause 6.4 of the Terms);
-
in connection with any activity that is unlawful in Norway, in your country of establishment or in the country where the subject of a file is located;
-
to test, probe or develop a means of defeating, evading or degrading document or object fraud detection, including to evaluate whether a forged, altered or synthetic artefact would pass detection;
-
to produce, refine or validate forged, counterfeit, altered or synthetic identity documents, credentials, certificates or objects;
-
for surveillance, monitoring, profiling, tracking or investigation of any individual, or for any purpose relating to law enforcement, intelligence, immigration enforcement or military use, without our prior written consent;
-
to assess, categorise or score any individual by reference to race, ethnic origin, nationality, religion, political opinion, trade union membership, health, disability, sexual orientation, gender identity or any other protected characteristic;
-
for the biometric identification or biometric categorisation of natural persons, for the creation, population or expansion of any facial-image or biometric database, for emotion recognition, or for any practice prohibited by Article 5 of the AI Act. These uses are prohibited absolutely and are not capable of authorisation by consent, ours or anyone else’s;
-
for migration, asylum or border control management, or as a safety component of a product, without our prior written consent (clause 6.5 of the Terms); or
-
in any manner that would cause us to breach any law, regulation, sanctions measure or obligation to which we are subject.
2. PROHIBITED CONTENT
You must not submit:
-
personal data relating to a person who has not consented under clause 5.2 of the Terms and for whom you hold no other documented lawful basis under clause 5.1(c) or, in production, P6.1 of Schedule 4;
-
a file prohibited by clause 5.3 of the Terms: genetic data or biometric data processed to identify a person uniquely, in any circumstances; and special categories of personal data, data relating to criminal convictions and offences, or personal data relating to a person under the age of 18, where the file is
submitted in order to analyse or act on that data rather than to verify a document or object as clause 5.3 permits;
-
material that is obtained unlawfully, held in breach of a duty of confidence or subject to legal privilege;
-
material depicting child sexual abuse, or content that is obscene, abusive, harassing or that incites violence or hatred; or
-
malicious code, or any file crafted to exploit, overload or interfere with our systems.
3. PROHIBITED TECHNICAL CONDUCT
You must not:
-
circumvent or attempt to circumvent any authentication, rate limit, volume limit, quota, credit allowance or access control, including by registering additional accounts or by obtaining allowance increases under a false description of your intended use;
-
conduct any penetration test, vulnerability scan, load test or stress test against our systems without our prior written consent;
-
scrape, crawl, mirror or systematically extract the Documentation, the API or any Output;
-
interfere with or disrupt the integrity, performance or security of the Services or the data of any other user; or
-
breach clause 3.3 (benchmarking and publication) or clause 3.4 (reverse engineering) of the Terms.
4. REPORTING
Report suspected misuse, security vulnerabilities or breaches of this Policy to legal@deepxl.ai. We investigate reports but give no undertaking as to the outcome or timing of an investigation.
SCHEDULE 2
DATA PROCESSING ADDENDUM
This Data Processing Addendum (the “DPA”) forms part of the Terms and is accepted by the same act and at the same time. It applies to all processing of personal data by DeepXL on the Customer’s behalf in connection with the Playground, whether that personal data was submitted in accordance with clause 5.1 of the Terms or in breach of clause 5.3. It applies to Customers established anywhere in the world; the paragraphs of Schedule B apply automatically according to the law applicable to the Customer, and no country-specific version need be selected. DeepXL is established in Norway and processes Customer Content on infrastructure operated by its sub-processors in the locations stated in the published sub-processor list, at the date of this version the United States; clause 9 governs the resulting transfers.
1. DEFINITIONS AND ROLES
1.1 “Data Protection Law” means each law relating to the protection of personal data applicable to the processing, including Regulation (EU) 2016/679 (the “GDPR”) as it applies in the European Union and, as incorporated by the Norwegian Personal Data Act of 15 June 2018 (personopplysningsloven), in Norway; the UK GDPR and the Data Protection Act 2018; the Swiss Federal Act on Data Protection; the California Consumer Privacy Act as amended (“CCPA”); other United States state privacy laws; PIPEDA (Canada); Lei nº 13.709/2018 (“LGPD”, Brazil); and the Ley Federal de Protección de Datos Personales en Posesión de los Particulares (“LFPDPPP”, Mexico). Terms such as controller, processor, personal data, processing, data subject and personal data breach have the meanings given in the applicable Data Protection Law.
1.2 Roles. The Customer is the controller (controlador, responsable, business) and DeepXL is the processor (operador, encargado, service provider) in respect of Customer Content. Where the Customer is itself a processor for a third party, DeepXL is a sub-processor and the Customer warrants that it has the authorisations and instructions necessary to appoint DeepXL on these terms.
1.3 Roles outside this DPA. DeepXL does not process Customer Content as a controller in its own right, does not sell or share personal data within the meaning of the CCPA, and does not use Customer Content for cross-context behavioural advertising, save that DeepXL is an independent controller for the fraud-prevention layer described in clause 4.4 of the Terms, on the terms set out in clause 13 below. DeepXL’s processing of the Customer’s business contact and account data as a controller in its own right is outside this DPA and is described in the Privacy Policy.
2. SCOPE AND INSTRUCTIONS
2.1 Documented instructions. The Terms, this DPA and the Customer’s use of the Services in accordance with the Documentation constitute the Customer’s complete documented instructions. DeepXL processes Customer Content only on those instructions and for the purposes in clause 3, and not for any other purpose.
2.2 Permitted processing. Those purposes are:
-
(a) performing the analysis requested by a Call and returning the Output;
-
(b) operating, securing, monitoring and troubleshooting the Services and the Playground, including the compliance monitoring described in clause 3.6 of the Terms;
-
(c) quality assurance, including limited human review of a sample of submissions and Outputs by authorised personnel, solely to verify the correctness of Outputs returned to the Customer and to detect and correct systematic error in the Services; Customer Content is not used to train, fine-tune, validate or evaluate any model, and only the de-identified derived signals described in clause 4.3 of the Terms are used to improve the Services, as clause 4.6 of the Terms also provides; and
-
(d) complying with a legal obligation to which DeepXL is subject.
2.3 Unlawful instruction. DeepXL will inform the Customer without undue delay if, in its opinion, an instruction infringes Data Protection Law, and may suspend performance of that instruction until it is amended or confirmed. DeepXL is not obliged to carry out a legal review of the Customer’s instructions and gives no advice on the lawfulness of the Customer’s processing.
2.4 Customer responsibilities. The Customer is responsible for the lawfulness of the collection and submission of Customer Content, for having a lawful basis, for providing any required notice or privacy notice (including any aviso de
privacidad), for obtaining and recording the consent required by clause 5.2 of the Terms, or documenting the lawful basis permitted by clause 5.1(c) or, in production, by clause P6.1 of Schedule 4, for assessing whether consent is a valid lawful basis in its circumstances, for handling any withdrawal of consent, and for the accuracy and relevance of Customer Content. The prohibitions in clause 5.3 of the Terms, and the Article 9(2) and Article 10 warranty in clause 5.4(d), apply in addition to and not instead of these obligations.
3. CONFIDENTIALITY OF PERSONNEL
3.1 DeepXL ensures that persons authorised to process Customer Content are bound by an obligation of confidentiality, are informed of the confidential nature of the data, are subject to appropriate access controls, receive appropriate training, and have access only to the extent necessary for the purposes in clause 2.2.
4. SECURITY
4.1 DeepXL implements and maintains appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing. Those measures are described in Schedule C and in the security documentation published in the legal section of our website at deepxl.ai.
4.2 DeepXL may update its measures provided that the level of protection is not materially reduced.
4.3 The Customer is responsible for the security of its own systems, its API credentials and its use of the Services, and for its decision that the Services are appropriate for the data it chooses to submit.
5. SUB-PROCESSORS
5.1 General authorisation. The Customer gives DeepXL general written authorisation to engage sub-processors. The current sub-processors, the processing each carries out, the country in which each processes and, where DeepXL relies on it, the sub-processor’s certification under the EU–US Data Privacy Framework, are listed in the legal section of our website at deepxl.ai. That page carries a date of last update, each version is archived and remains retrievable, and it completes Annex III to the Standard Contractual Clauses where they apply.
5.2 New sub-processors. DeepXL will notify the Customer of an intended addition or replacement of a sub-processor at least fifteen (15) days in advance, or thirty (30) days while an Order Form is in force, either by e-mail to the notice address in the Customer’s registration information or Order Form or by a notice displayed to the Administrator in the account, and will update the published list at the same time. Notification of a sub-processor change is given individually because Article 28(2) of the GDPR requires the Customer to be informed and given the opportunity to object; the passive publication mechanism in clause 14.1 of the Terms does not apply to it. The Customer may object on reasonable data-protection grounds within that period; if the parties cannot resolve the objection, the Customer may terminate under clause 2.4 of the Terms or P3.1 of Schedule 4. Continued use of the Services after the notice period constitutes acceptance.
5.3 Flow-down and responsibility. DeepXL imposes on each sub-processor data protection obligations no less protective than those in this DPA, and remains responsible to the Customer for the performance of each sub-processor’s obligations.
6. DATA SUBJECT RIGHTS
6.1 DeepXL will not respond to a data subject request relating to Customer Content itself, unless legally required. It will refer the request to the Customer without undue delay.
6.2 Taking into account the nature of the processing, DeepXL will provide reasonable assistance to enable the Customer to respond to requests for access, rectification, erasure, restriction, portability, objection, and the exercise of ARCO rights under the LFPDPPP or equivalent rights under any other Data Protection Law. The assistance available is principally confirmation of whether a file identified by its Call reference is held, provision of a copy, and deletion under clause 11.2; DeepXL cannot rectify the content of a submitted file, only delete it, and cannot identify a data subject across files.
7. ASSISTANCE AND RECORDS
7.1 DeepXL will provide the Customer with reasonable assistance in carrying out a data protection impact assessment, and in any prior consultation with a supervisory authority, in each case in relation to the Services and to the extent the Customer does not otherwise have the information. Clause 7.4 applies to the cost of that assistance.
7.2 DeepXL maintains the record of processing carried out on the Customer’s behalf required by Article 30(2) of the GDPR and will make relevant extracts available on reasonable request.
7.3 DeepXL will notify the Customer without undue delay of a legally binding request by a public authority for disclosure of Customer Content, unless prohibited by law, and will challenge such a request where it has reasonable grounds to consider it unlawful.
7.4 Cost of assistance. DeepXL provides the following free of charge: the information necessary to demonstrate compliance with this DPA under clause 8.1, including its security documentation and transfer impact assessment; standard extracts of its record of processing under clause 7.2; the notification and challenge of a public-authority request under clause 7.3; and the incident information under clause 10. Where the Customer requests assistance under clause 6.2 or clause 7.1 that goes beyond the standard documentation, or requests a bespoke extract, a completed security or privacy questionnaire, a bespoke security review, a meeting or workshop, or evidence prepared specifically for the Customer, DeepXL may charge for the time spent at the rate it notifies to the Customer before the work begins. DeepXL will provide an estimate and will not incur a charge without the Customer’s written approval. Nothing in this clause permits DeepXL to make the provision of assistance conditional on payment where Data Protection Law does not permit that, and clause 8.2 continues to govern the cost of an audit.
8. AUDIT
8.1 DeepXL will make available the information necessary to demonstrate compliance with this DPA, including its current security documentation and the transfer impact assessment referred to in clause 9.7. DeepXL does not presently hold a third-party security certification or audit report such as ISO/IEC 27001 or a SOC 2 report; where it obtains one it will make the certificate or report available under this clause, and it will not state or imply that it holds one until it does.
8.2 Audit. Article 28(3)(h) of the GDPR (and, where the SCCs apply between the parties, clause 8.9 of the SCCs) requires DeepXL to allow for and contribute to audits, and this clause sets out how that is done rather than excluding it. Where the information in clause 8.1 is not sufficient, the Customer may audit DeepXL’s compliance with this DPA, limited to the processing of the Customer’s own personal data, no more than once in any twelve-month period, on at least thirty days’ written notice and during business hours. An additional audit may be conducted within that period only where a supervisory authority requires it or where there has been a personal data breach affecting the Customer’s Customer Content. An audit is conducted remotely, by document review, interview and evidence of configuration, where that is sufficient to answer the Customer’s questions; an on-site inspection may be conducted only where remote means are demonstrably insufficient. DeepXL may require that an audit be conducted by an independent third-party auditor who is not a competitor of DeepXL and who is acceptable to both parties, and that the auditor sign a confidentiality undertaking directly with DeepXL. An audit confers no right of access to the personal data or Customer Content of any other customer, to DeepXL’s source code, model architecture, model weights or training data, or to information whose disclosure would breach a duty DeepXL owes to a third party. The Customer bears its own costs and DeepXL’s reasonable costs of supporting the audit, including where the Services are provided without charge. This clause satisfies Article 28(3)(h) of the GDPR; it does not contain the audit, access and inspection rights that Regulation (EU) 2022/2554 (DORA) or equivalent outsourcing rules require a financial entity to obtain for ICT services supporting critical or important functions, which are available only under the DORA Addendum referred to in P9 of Schedule 4.
9. INTERNATIONAL TRANSFERS
9.1 Establishment and roles. DeepXL is established in Norway and its processing of Customer Content is subject to the GDPR under Article 3(1), wherever the Customer, the data subjects or the infrastructure are located. Customer Content is processed on infrastructure in the countries stated in the published sub-processor list, which at the date of this version is the United States for all Customer Content. The transmission of Customer Content by DeepXL to a sub-processor in a third country is a transfer under Chapter V of the GDPR for which DeepXL is the data exporter and
the sub-processor is the data importer. Where the Customer is established in the EEA, the United Kingdom or Switzerland, the Customer’s submission of Customer Content to DeepXL is not a transfer to a third country, and no transfer mechanism is required between the parties for it.
9.2 Instruction and authorisation. The Customer instructs and authorises DeepXL to transfer Customer Content to the sub-processors on the published list, in the countries stated there, on the mechanisms in this clause 9. That authorisation is a documented instruction for the purposes of Article 28(3)(a) of the GDPR and clause 2.1, and the Customer is responsible for describing the transfer in the information it gives to data subjects.
9.3 Primary and fallback mechanism. For each transfer to a sub-processor in the United States, DeepXL relies on the European Commission’s adequacy decision for the EU–US Data Privacy Framework (Commission Implementing Decision (EU) 2023/1795, incorporated into the EEA Agreement so that it applies to transfers from Norway), where the sub-processor is certified under the Framework and the transfer falls within its certification; DeepXL verifies the certification before engaging the sub-processor and periodically thereafter, and states it in the published list. Where a sub-processor is not so certified, the Standard Contractual Clauses (Module Three, processor to processor) apply instead, and DeepXL has concluded them with that sub-processor. If that decision or the certification is annulled, suspended, amended, withdrawn or ceases to cover a transfer, DeepXL will suspend the affected processing or move it to a mechanism that validly covers it within sixty (60) days, and may suspend the affected processing in the meantime. DeepXL maintains the transfer impact assessment in clause 9.7 for every transfer under this clause. The parties intend that there be no period in which a transfer lacks a valid mechanism. If DeepXL concludes that no mechanism in this clause validly covers a transfer, it will inform the Customer without undue delay and the Customer may terminate under clause 2.4 of the Terms or P3.1 of Schedule 4.
9.4 Customers outside the EEA, the United Kingdom and Switzerland. Where the Customer is established outside those territories, DeepXL’s return of Customer Content and Outputs to the Customer, and any other disclosure of personal data by DeepXL to the Customer, is a transfer by DeepXL to a third country. For that transfer the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914 (the “SCCs”) are incorporated into this DPA by reference and apply between DeepXL as data exporter and the Customer as data importer: Module Four (processor to controller) where the Customer is a controller, and Module Three (processor to processor) where the Customer is itself a processor for a third party. Nothing in this clause makes DeepXL responsible for any requirement that the law applicable to the Customer imposes on the Customer’s own disclosure of Customer Content to DeepXL; Schedule B governs that.
9.5 SCC elections. For the purposes of the SCCs where they apply between the parties: the optional docking clause (clause 7) does not apply; in clause 11, the optional independent dispute resolution body does not apply; in clause 13 and Annex I Part C, the competent supervisory authority is the Norwegian Data Protection Authority (Datatilsynet); in clause 17, the governing law is the law of Norway; in clause 18(b), the forum is the courts of Norway. Annexes I and II are completed by Schedule A and Schedule C, and Part A of Annex I as set out in Schedule 3 to the Terms. Where the SCCs apply between DeepXL and a sub-processor under clause 9.3, DeepXL makes the corresponding elections and will provide a copy of the concluded clauses, with commercial information redacted, on request under clause 8.1.
9.6 UK and Switzerland. Norway is recognised by the United Kingdom and by Switzerland as providing adequate protection for personal data, so the Customer’s submission of Customer Content to DeepXL requires no transfer mechanism under the UK GDPR or the Swiss Federal Act on Data Protection. The onward transfer by DeepXL to sub-processors in the United States is made under clause 9.3, and DeepXL’s transfer impact assessment addresses the requirements of the UK GDPR and the Swiss Federal Act on Data Protection to the extent they apply to it. References to a supervisory authority include the Information Commissioner’s Office and the Federal Data Protection and Information Commissioner respectively.
9.7 Transfer impact assessment. DeepXL maintains a transfer impact assessment for transfers to the United States, covering the legal regime applicable to the importer and the supplementary technical, organisational and contractual measures in place, and will make it available to the Customer on request under clause 8.1. DeepXL reviews it at least annually and where a material change in law or practice occurs, including any decision of the Court of Justice of the European Union concerning the Data Privacy Framework.
9.8 Precedence. Where the SCCs apply between the parties and conflict with this DPA or the Terms, the SCCs prevail to the extent of the conflict.
10. PERSONAL DATA BREACH
10.1 DeepXL will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Content, and in any event in a manner and within a time that enables the Customer to meet its own obligation under Article 33(1) of the GDPR. DeepXL’s obligation is that of a processor under Article 33(2); the seventy-two-hour period in Article 33(1) runs against the Customer, not DeepXL.
10.2 The notification will describe, to the extent known and as it becomes known: the nature of the breach; the categories and approximate volume of personal data and data subjects concerned; the likely consequences; the measures taken or proposed to address it and mitigate its effects; and a contact point. Information may be provided in phases.
10.3 DeepXL will take reasonable steps to contain and remediate the breach and will provide reasonable assistance to enable the Customer to meet its own notification obligations to supervisory authorities and data subjects. DeepXL bears its own costs of that assistance.
10.4 DeepXL will not notify a supervisory authority or any data subject on the Customer’s behalf unless required by law or requested by the Customer in writing. An initial notification is not an admission of fault or liability.
11. RETURN AND DELETION
11.1 Automatic deletion. Customer Content is deleted in accordance with clause 8.3 of the Terms and Schedule A, on a rolling basis and irrespective of termination of access. That deletion is automatic and requires no request from the Customer. On termination DeepXL retains no Customer Content other than for the remainder of the retention period, or to the extent it is required to retain a copy by law, in which case it will continue to protect it under this DPA and will process it only for that purpose.
11.2 Deletion on request. In addition to clause 11.1:
-
(a) the Customer may at any time request deletion of all Customer Content in the account, and DeepXL will give effect to that request without undue delay;
-
(b) the Customer may request a shorter standard retention period for the account, which DeepXL will apply prospectively; and
-
(c) where the Customer needs a particular file deleted before the retention period expires — including to give effect to a data subject’s erasure request or a supervisory authority’s order, or because consent relied on under clause 5.2 of the Terms has been withdrawn or a lawful basis relied on under clause 5.1(c) or P6.1 of Schedule 4 has ceased to apply — the Customer will identify the file by its Call reference, and DeepXL will delete it without undue delay after receiving that reference.
11.3 Limits on deletion on request. DeepXL is not obliged to search for, identify or match a file, to identify a data subject across files, or to reconstruct which Call relates to which person; the account holds the Call references and the Customer is best placed to use them. Clause 7.4 applies where a request requires work beyond deleting identified Calls or the account. Deletion under clause 11.2 does not extend the retention period for anything else and does not affect clause 11.1.
11.4 DeepXL will certify deletion to the Customer in writing on request, and, where the SCCs apply between the parties, as clause 8.5 of the SCCs requires. Deletion from backups occurs in the ordinary course of the backup cycle, and in any event within ninety (90) days.
11.5 Aggregated and de-identified data that cannot reasonably be used to identify any person or the Customer is not Customer Content and is not subject to this clause.
12. LIABILITY AND PRECEDENCE
12.1 Liability under this DPA is subject to clause 11 of the Terms, save to the extent that Data Protection Law or the SCCs do not permit that limitation. Nothing in this DPA limits a data subject’s rights under the SCCs or under Data Protection Law.
12.2 This DPA prevails over the Terms in the event of conflict in respect of the processing of personal data. Clause 1.9 of the Terms sets out the full order of precedence.
13. CROSS-CUSTOMER FRAUD PREVENTION — DEEPXL AS CONTROLLER
13.1 Scope and role. This clause governs the fraud-prevention layer described in clause 4.4 of the Terms. DeepXL is an independent controller for it. The processing is not carried out on the Customer’s instructions, and clauses 2 to 12 of this DPA do not apply to it, save that clauses 3 (confidentiality of personnel), 4 (security) and 10 (personal data breach) apply to it as they apply to Customer Content.
13.2 What the layer holds. The layer holds technical signals derived from each file submitted. These include, without limitation, cryptographic and perceptual fingerprints of the file and of regions within it; template, layout, font, structural and metadata signatures; tamper and manipulation signals; the derived risk signals produced by the analysis; and such other derived technical signals as we develop from time to time for the purpose in clause 4.4 of the Terms. A signal may be computed from content appearing in the file, including an identifier, in which case clause 13.3 applies to it. We describe the categories of signal held in the security documentation referred to in clause 4.1, and may update that description at any time; the limits in clause 13.2A apply to it and cannot be widened by it.
13.2A Limits on the layer. The following limits govern the layer. Neither the security documentation nor anything else we publish can widen them.
-
(a) Purpose and necessity. The layer holds only what is necessary to recognise a file, a forgery template or a tamper pattern again. It is not a store of documents or of their content.
-
(b) No reconstruction. The layer does not contain the file, or a copy, reproduction or image of it, and no signal in it is designed or intended to permit the file, or the content of any field in it, to be reconstructed or reproduced.
-
(c) Limited linkability. The layer holds a reference to the Call that produced each entry, and no other identifier: no customer identifier, no account identifier and no API credential identifier. That reference can be matched to the Call in your call history for as long as that history exists, so an entry is capable of being traced to the Customer that submitted the file. We hold no other means of attribution, we do not use the reference for attribution except as clause 13.6A permits, and we may remove the reference or replace it with a one-way value at any time.
-
(d) No sensitive processing as such. We do not hold, extract, derive, index or match on special categories of personal data, personal data relating to criminal convictions and offences, genetic data or biometric data as such, and no biometric template is generated or held. Where such data is present in a submitted file it is not the subject of the processing, and clause 5.3(a) of the Terms governs its presence.
-
(e) Changes. We may change what the layer holds, and how, within these limits and without notice, as the Services develop. A change that would exceed limit (a), (b) or (c) requires an amendment to these Terms under clause 14.1, and is a change materially reducing your rights for the purposes of that clause.
13.3 Status of the layer. Because of the Call reference described in clause 13.2A(c), an entry in the layer is pseudonymised rather than anonymous: it can be linked to a Call and, through the call history, to a Customer and to the individual whose document was submitted. DeepXL therefore treats the layer as personal data in full, and this clause 13 applies to it in full. DeepXL does not rely on Article 11 of the GDPR in respect of the layer.
13.4 Lawful basis. DeepXL relies on its legitimate interests and those of its customers and of the persons affected by document fraud, under Article 6(1)(f) of the GDPR, in preventing and detecting fraud — a purpose expressly recognised in recital 47 to the GDPR. DeepXL maintains a legitimate interests assessment covering the necessity of the processing, the limits in clause 13.2A, the linkability described in clause 13.2A(c) and the restrictions on its use in clause 13.6A, and the safeguards in this clause, and will make it available on request under clause 8.1.
13.4A Impact assessment and information to data subjects. DeepXL maintains a data protection impact assessment for the layer under Article 35 of the GDPR and reviews it with the legitimate interests assessment. The layer holds no contact details, and the Call reference in clause 13.2A(c) cannot identify a person without records that only the Customer holds, so individual notification of the persons concerned by DeepXL is impossible or would involve disproportionate effort; DeepXL provides the information required by Article 14 of the GDPR by making it publicly available in section 3 of its Privacy Policy, as Article 14(5)(b) permits, and the Customer’s notice under clause 4.5 of the Terms directs the persons concerned to it.
13.5 Retention. Entries in the layer are retained for sixty (60) months from the Call that created them, and are then deleted by an automatic scheduled process in DeepXL’s own systems with failure alerting. Deleted entries remain technically restorable through the database platform’s point-in-time restore for up to seven (7) days, after which they are permanently gone. That period is longer than the period in clause 8.3 of the Terms because a forgery template remains in circulation for years; it applies only to the signals described in clause 13.2 and does not extend the retention of any Customer Content. DeepXL reviews the period at least annually.
13.6 Confidentiality between customers. DeepXL will not disclose to any customer the identity of another customer, the timing, frequency or volume of another customer’s submissions, or any information from which another customer, its business or its end users could be identified or inferred. An Output derived from the layer states only that a matching file, template or tamper pattern has been seen before.
13.6A Use of the Call reference. DeepXL may use the Call reference in clause 13.2A(c) only to investigate a suspected error or malfunction in the layer, to respond to a request from a person under clause 13.7 or from the Customer under clause 11.2, and to investigate a security incident or suspected breach of the Terms. It will not be used to disclose anything to another customer, to compare customers with one another, to construct a view of a customer’s volumes or outcomes, or for any commercial or marketing purpose. Access to the reference is restricted to authorised personnel under clause 3, and each use is logged. The call history is retained for twelve months under Schedule A; after that, the reference is no longer capable of attribution, so an entry is traceable for twelve of the sixty months for which it is held.
13.7 Rights of persons. A person may exercise the rights available to them in respect of the layer, including the right to object under Article 21 of the GDPR, by contacting legal@deepxl.ai. DeepXL will respond directly and will not require the person to approach the Customer. Where DeepXL upholds an objection or erasure request it will delete the entries concerned. The Customer will pass on to DeepXL, without undue delay, any such request it receives that concerns the layer.
13.8 Transfers and no onward disclosure. The layer is held on infrastructure in the United States. DeepXL, as controller, transfers it to its sub-processors under the Data Privacy Framework or, as fallback, Module Two of the SCCs, on the basis and with the safeguards described in clause 9.3 and 9.7, DeepXL acting as data exporter in its own right. DeepXL will not sell, licence, publish or otherwise make the layer or any part of it available to any third party, will not use it for any purpose other than fraud prevention and the improvement of the Services’ detection capability, and will not use it to build a profile of, or draw any inference about, any identified person beyond the authenticity of the artefacts submitted.
SCHEDULE A — DETAILS OF PROCESSING (ARTICLE 28(3) GDPR; SCC ANNEX I, PARTS A AND B, WHERE THE SCCs APPLY BETWEEN THE PARTIES)
| Item | Detail |
|---|---|
| Controller (and data importer where clause 9.4 of this DPA applies) | The Customer, as identified by the registration information described in Schedule 3 to the Terms, or by the Order Form where one is in force. Where the Customer is itself a processor for a third party, the Customer acts as processor and DeepXL as sub-processor. |
| Processor (and data exporter where clause 9.4 of this DPA applies) | DeepXL AS, org. no. 932 269 570, Bjørnveien 87B, 0773 Oslo, Norway. Contact: legal@deepxl.ai. Activities: analysis of files submitted through the Services, during the Evaluation Period and in production. |
| Subject matter | Automated analysis of files submitted for indications of manipulation, tampering, forgery or synthetic generation, and extraction of structured data from submitted documents. |
| Nature of processing | Collection, storage, automated analysis, extraction of structured data from documents (Parsing), generation of derived signals, limited human quality-assurance review, logging, deletion. No biometric processing, template generation or face comparison is performed. Customer Content is not used to train, fine-tune, validate or evaluate any model. |
| Purposes | The purposes in clause 2.2 of this DPA. The fraud-prevention layer in clause 13 is processed by DeepXL as controller and is outside this Annex. |
| Duration | The access period under clause 2.4 of the Terms and, where an Order Form takes effect under clause 2.10, the term of the Order Form, plus the retention periods below. This DPA continues to apply to |
| Item | Detail |
|---|---|
| Customer Content until it is deleted. | |
| Categories of data subject | The individual submitting a file; any other individual who has given consent under clause 5.2 of the Terms or for whom the Customer holds a documented lawful basis under clause 5.1(c) or P6.1 of Schedule 4. May include a person under the age of 18 where clause 5.3(c) of the Terms permits it, that is where the person is the subject of or a party to the matter being verified and the Customer has warranted the matters in clause 5.4(e). |
| Categories of personal data | Data appearing in or derived from a submitted file, which may include name, date of birth, document or reference number, issuing authority, address, photograph, signature, transaction data and file metadata. See the row below as to special categories. No biometric template is generated or stored, and no biometric comparison is performed. |
| Sensitive data | Special categories of personal data, and personal data relating to criminal convictions and offences, are not the subject matter of the processing and are never analysed, extracted, inferred or indexed as such. They may nonetheless appear incidentally in a submitted document — for example a transaction in a bank statement that reveals a religious, political, health-related or trade-union connection, or a place of birth, nationality or photograph in an identity document — and are then processed only as part of the document image or text for the purpose of the Call, subject to the Article 9(2) or Article 10 condition warranted by the Customer under clause 5.4(d) of the Terms. Genetic data and biometric data processed for the purpose of uniquely identifying a person are prohibited absolutely (clause 5.3(b)). No biometric template is generated or stored. Restrictions applied: the measures in Schedule C, the retention period in this Schedule, and access limited to authorised personnel under clause 3. |
| Frequency | On each Call. Occasional and low volume during the Evaluation Period, subject to the allowance under clause 2.5 of the Terms; continuous in production. |
| Recipients | DeepXL personnel bound by clause 3; the sub-processors on the published list. |
| Processing location | Infrastructure operated by the sub-processors on the published list, in the country stated there for each — at the date of this version, the United States for all Customer Content (clause 9.1). |
| Retention — submitted files | Deleted 12 months after the Call, on a rolling basis, irrespective of termination of access, by an automatic scheduled process in DeepXL’s own systems with failure alerting. The process runs periodically, so deletion occurs within twelve months plus a short operational margin. Soft delete is not enabled on the storage account and blob versioning is off, so a submitted file is not recoverable once deleted. Applied for the purposes in clause 2.2, including quality assurance. Reducible to 30 days on the Customer's request, and any file or the whole account deleted on request (clause 8.3 of the Terms, clause 11.2 of this DPA). |
| Retention — Outputs and derived signals | Retained in a form not identifying any person for the purposes in clause 4.3 of the Terms. Held in the database, where a deleted entry remains restorable through point-in-time restore for up to 7 days before permanent removal. |
| Retention — usage and Call records; platform logs | Usage and Call records: 12 months, for billing, security, abuse detection and compliance monitoring. That is also the period for which a Call reference in the fraud-prevention layer remains capable of attribution under clause 13.6A. Platform security, access and error logs: 30 days. Where a processing operation fails, content from a submitted file may appear in an error log held in the same cloud subscription and region, and is deleted after 30 days. |
| Retention — acceptance record (clause 1.8) | Retained for the limitation period applicable to claims under the Terms. |
| Transfers by DeepXL | To the sub-processors on the published list, in the countries stated there, under the Data Privacy Framework or, as fallback, Module Three of the SCCs, with DeepXL as data exporter (clause 9.3). Where the Customer is established outside the EEA, the United Kingdom and Switzerland, the return of Customer Content and Outputs to the Customer under Module Four (or Module Three) of the SCCs, with DeepXL as data exporter (clause 9.4). |
SCHEDULE B — REGION-SPECIFIC TERMS
Each paragraph of this Schedule applies of its own force where the law it concerns applies to the processing. No selection is required and none is made at registration.
B.1 Norway and the European Economic Area
This DPA is intended to satisfy Article 28(3) of the GDPR and the Norwegian Personal Data Act. DeepXL is established in Norway, and its processing is therefore subject to the GDPR under Article 3(1) irrespective of where the Customer, the data subjects or the infrastructure are located. Coverage of local law alone is not sufficient and does not displace this Schedule. The Customer’s submission of Customer Content to DeepXL is not a transfer to a third country. The onward transfer by DeepXL to sub-processors in the United States is governed by clause 9, and the fallback in clause 9.3 means that the outcome of any challenge to the Data Privacy Framework adequacy decision does not require an amendment to this DPA. Where the Customer is a Norwegian financial institution, P9 of Schedule 4 addresses the information it needs for any notification to Finanstilsynet.
B.2 United Kingdom
This DPA is intended to satisfy Article 28(3) of the UK GDPR. Norway is covered by the United Kingdom’s adequacy regulations, so the Customer’s submission of Customer Content to DeepXL is not a restricted transfer; clause 9.6 governs the onward transfer by DeepXL. References to a supervisory authority include the Information Commissioner’s Office.
B.3 Switzerland
Norway is recognised by Switzerland as providing adequate protection, so the Customer’s submission of Customer Content to DeepXL requires no transfer mechanism; clause 9.6 governs the onward transfer by DeepXL. References to a supervisory authority include the Federal Data Protection and Information Commissioner. This DPA applies equally to personal data relating to legal entities where Swiss law so requires.
B.4 California
DeepXL is a service provider in respect of Customer Content. It does not sell or share personal information, does not retain, use or disclose personal information except for the business purposes in clause 2.2 and the fraud-prevention purpose in clause 13, does not combine it with personal information received from another source except for that fraud-prevention purpose, which the CCPA permits as a business purpose of helping to prevent, detect and investigate fraud, and does not use it for cross-context behavioural advertising. DeepXL will comply with applicable obligations under the CCPA, will provide the assistance in clauses 6 and 7 in respect of consumer requests, and will notify the Customer if it determines it can no longer meet its obligations as a service provider. The Customer may take reasonable and appropriate steps under clause 8 to verify compliance.
B.5 Other United States state privacy laws
Where the Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Connecticut Data Privacy Act, the Utah Consumer Privacy Act, the Texas Data Privacy and Security Act or any other United States state privacy law imposing obligations on processors applies, DeepXL acts as a processor, processes personal data only on the Customer’s instructions, is bound by the duty of confidentiality in clause 3, engages sub-processors under clause 5, assists with data protection assessments under clause 7, deletes or returns personal data under clause 11, and makes available the information necessary to demonstrate compliance under clause 8. This paragraph applies to any such law now in force or enacted in future without the need for a new version of this DPA.
B.6 Canada
DeepXL processes personal information as a service provider on the Customer’s behalf, maintains protections comparable to those required under PIPEDA and applicable provincial law, and confirms that personal information is stored and processed in the United States and may be accessible to United States authorities under the law of that country. The Customer is responsible for informing individuals of that transfer where required.
B.7 Brazil
The Customer is controlador and DeepXL is operador. DeepXL processes personal data only on the Customer’s instructions and in accordance with Article 39 of the LGPD, maintains security measures under Article 46, notifies incidents under clause 10 to enable the Customer’s communication to the ANPD and to data subjects under Article 48, and assists with data subject
rights under Articles 18 and 19. International transfers rely on the standard contractual clauses adopted by the ANPD where applicable and, in addition, on the SCCs incorporated under clause 9. The Customer is responsible for the legal basis under Articles 7 or 11 and for any required consent.
B.8 Mexico
The Customer is responsable and DeepXL is encargado. DeepXL processes personal data only under the Customer’s instructions and in accordance with the LFPDPPP, does not transfer it except to the sub-processors on the published list, maintains security measures, and returns or deletes personal data under clause 11. The Customer is responsible for the aviso de privacidad, for any required consent — including express written consent where datos sensibles or financial data are concerned — and for handling ARCO requests, in respect of which DeepXL assists under clause 6.
B.9 Any other jurisdiction
This paragraph applies where the Customer is established in, or the relevant data subjects are located in, a country not named above. DeepXL acts as processor, service provider, data intermediary or equivalent, processes personal data only on the Customer’s instructions, and undertakes the obligations that the applicable privacy law imposes on a party in that role, including as to confidentiality, security, sub-processing, assistance with data subject rights, incident notification and deletion, in each case as set out in this DPA. DeepXL’s return of Customer Content and Outputs to the Customer is made under Module Four (or Module Three) of the SCCs under clause 9.4. Where the law applicable to the Customer restricts the Customer’s own transfer of personal data out of its country, the SCCs so incorporated also apply as a matter of contract between the parties in respect of that transfer, so that a contractual safeguard is in place irrespective of whether that law recognises the instrument.
Exporter-side requirements are the Customer’s. Several privacy laws place the operative cross-border requirement on the exporting party rather than on the importer: examples include a consent or equivalent-standards assessment under the Japanese APPI, consent and disclosure under the Korean PIPA, explicit consent or an approved undertaking under the Turkish KVKK, notice under Australian APP 8, and a section 72 assessment under the South African POPIA. The Customer is responsible for determining whether the law applicable to it permits the transfer described in clause 9.1 and clause 8.3 of the Terms, and for obtaining and recording any consent, notice, filing, approval, registration or assessment that law requires. DeepXL gives no assurance that its processing satisfies any exporter-side requirement, and the Customer’s representations in clause 5.4 of the Terms cover this.
China. The Personal Information Protection Law requires a filed standard contract, a security assessment or certification before personal information may be transferred out of the mainland, and the SCCs incorporated under clause 9.4 do not satisfy that requirement. Clause 13.3 of the Terms therefore prohibits registration and use by a Customer to which such a requirement applies, of its own force and without China or any other jurisdiction needing to be listed, and permits DeepXL to block or terminate access. This paragraph does not create a transfer mechanism where clause 13.3 applies.
SCHEDULE C — TECHNICAL AND ORGANISATIONAL MEASURES (SCC ANNEX II)
The measures listed below are the minimum. They are the contractual floor for the purposes of Annex II to the Standard Contractual Clauses and cannot be reduced by anything published elsewhere. The security documentation published in the legal section of our website at deepxl.ai forms part of this Schedule and is incorporated by reference, and sets out the current measures in detail; where it is more specific than this Schedule it prevails, but where it would provide less than this Schedule, this Schedule prevails. That page carries a version number and a date of last update, each version is archived and remains retrievable, and the version in force when the Customer accepted the Terms, or when an Order Form took effect, is the version incorporated until DeepXL notifies a change under clause 4.2.
-
Customer Content is encrypted in transit using TLS 1.2 or above and at rest using AES-256 or equivalent.
-
Role-based access on the principle of least privilege; unique named accounts; multi-factor authentication for administrative access; access to production systems restricted to a minimum number of named individuals; access reviewed periodically and revoked promptly on role change or departure.
-
Quality-assurance review under clause 2.2(c) is carried out on the minimum sample necessary by authorised personnel only. Derived signals under clause 4.3 are retained in a form that does not identify any person; the fraud-prevention signals under clause 4.4 are retained within the limits in clauses 13.2A and 13.6A, which permit a Call reference and prohibit any other identifier.
-
Segmented network architecture; firewalling; hardened configurations; timely patching; malware protection; secrets management.
-
Security and access logging with alerting on anomalous activity; logs protected against unauthorised alteration.
-
Encrypted backups; documented restoration procedures; capacity monitoring. No availability commitment is given during the Evaluation Period (clause 2.7 of the Terms); P4.2 of Schedule 4 applies in production.
-
Code review; separation of development, test and production environments; dependency management.
-
Automated enforcement of the retention periods in Schedule A; secure deletion of media.
-
Confidentiality undertakings; security awareness training; background screening where lawful.
-
Due diligence before engagement, including verification of Data Privacy Framework certification where relied on; contractual flow-down under clause 5.3 and conclusion of the SCCs under clause 9.3; periodic review.
-
Documented incident response plan with defined roles, containment steps and the notification process in clause 10.
SCHEDULE 3
REGISTRATION INFORMATION, PROCESSING RECORDS AND COMPLETION OF SCC ANNEX I, PART A
This Schedule exists so that the identity of the parties is formally recorded for the purposes of Article 28 and Article 30 of the GDPR in every customer relationship, and so that the Standard Contractual Clauses, where they apply between the parties under clause 9.4 of Schedule 2, are complete without either party completing a table by hand.
1 The registration information the Customer provides under clause 1.4 of the Terms — registered legal name, registered or principal business address, notice e-mail address, and the name, job title and business e-mail address of the individual accepting the Terms — identifies the Customer as controller (or processor) for the purposes of Schedule 2 and of DeepXL’s record of processing under Article 30(2) of the GDPR, and, where clause 9.4 of Schedule 2 applies, constitutes and is incorporated as the data importer’s details in Part A of Annex I to the SCCs.
2 DeepXL’s details are as stated in Schedule A of Schedule 2. Where clause 9.4 of Schedule 2 applies, they are the data exporter’s details in Part A of Annex I.
3 The contact person for data protection enquiries on the Customer’s side is the individual whose details are given as the notice contact, unless the Customer notifies a different contact in writing to legal@deepxl.ai.
4 The activities relevant to the processing are the Customer’s use of the Services as described in the Terms. The role of the Customer is controller, or processor where clause 1.2 of Schedule 2 applies.
5 Any signature and date required by Annex I are supplied by the Customer’s acceptance of the Terms by completing registration under clause 1.6 and by the record kept under clause 1.8. That record sets out the registration information as submitted and is the completed Annex I where it applies; the Customer may obtain it, and the version of the Terms it relates to, from its account or on request to legal@deepxl.ai.
6 If the Customer’s registration information changes, the Customer will update it in the account or notify DeepXL, and this Schedule is treated as updated accordingly with effect from that date.
End of Schedule 3.
SCHEDULE 4
PRODUCTION TERMS
This Schedule applies only from the date stated in an Order Form signed by both parties under clause 2.10 of the Terms. Until then it has no effect, and all use of the Services is Evaluation use under clause 2.3 of the Terms whatever interface, endpoint or mode is used.
P1. APPLICATION
P1.1 From the date an Order Form takes effect the Evaluation Period ends and the following clauses of the Terms are replaced by the corresponding provisions of this Schedule: clause 2.3 by P2; clauses 2.4 and 12.1 by P3; clauses 2.5 and 2.7 by P4; clause 6.2 by P5; clause 5.2 by P6; clause 10.1 by P7; and clause 7.3 and clauses 11.1 to 11.3 by P8. P9 and P10 apply in addition. Every other clause of the Terms applies in production exactly as it applies during the Evaluation Period.
P1.2 In particular the following continue to apply unchanged and are not varied by this Schedule: clause 2.2 (scope, and the exclusion of biometric processing), clause 2.8, clauses 2.15 to 2.17 (Call counting and new features), clause 3, clauses 5.1, 5.3 to 5.7, clauses 6.1, 6.3 and 6.4, clauses 6.6 to 6.9 (coverage and Customer Configuration), clauses 7.1 and 7.2, clauses 8 and Schedule 2 (data protection, including the retention period in clause 8.3), clause 9, clauses 10.2 to 10.6, clauses 11.4 to 11.8, and clauses 13 to 16. Where an Order Form conflicts with this Schedule, the Order Form prevails in respect of the matters it covers.
P2. PERMITTED USE
P2.1 You may use the Services in the ordinary operation of your own business, to assess documents and objects submitted to you for indications of manipulation, tampering, forgery or synthetic generation, and to extract structured data from documents by means of Parsing Calls.
P2.2 Clause 3.2 of the Terms continues to apply. The Services remain for your own use: no resale, sublicensing, white-labelling, or embedding or exposing the Services in any product, application, interface or service used by your own customers or end users, and no Calls on behalf of or for the benefit of any third party, unless the Order Form expressly permits it and states the terms on which it is permitted. Each legal entity requires its own Order Form; affiliates are not covered unless named in it.
P3. TERM, SUSPENSION AND TERMINATION
P3.1 The initial term is stated in the Order Form and, unless it provides otherwise, the Order Form then renews automatically for successive periods of one month. Either party may terminate for convenience on thirty (30) days’ written notice expiring at the end of a calendar month. There is no minimum commitment and no early termination charge unless the Order Form states one.
P3.2 Either party may terminate immediately for material breach not remedied within thirty days of written notice, or on the other’s insolvency, liquidation, administration or equivalent proceeding.
P3.3 We may suspend the Services immediately, with notice as soon as practicable, where required by law or by a competent authority, where we reasonably suspect a breach of clause 3, 5, 9, 13 or Schedule 1, where continued access presents a security, legal or regulatory risk, or where an amount invoiced to you under P7 or clause 2.13 is unpaid. Calls are in any event refused when your Balance is exhausted, which is not a suspension. The right in clause 12.1 of the Terms to suspend or revoke without notice or reason does not apply while an Order Form is in force.
P3.4 On termination or expiry, clause 12.2 of the Terms applies and all accrued Fees become payable.
P4. VOLUMES, RATE LIMITS AND AVAILABILITY
P4.1 There is no monthly volume ceiling; your consumption is limited only by your Balance under P7. Your account is subject to the rate and concurrency limits stated in the Order Form or, where it is silent, published in the Documentation, and we may throttle, queue or suspend Calls that exceed them or that in our reasonable judgement threaten the stability, security or integrity of the Services. Evaluation allowances and credits have no application in production.
P4.2 We will use commercially reasonable efforts to achieve 99.5% monthly availability of the production API, excluding scheduled maintenance, force majeure, third-party network failures, your own systems and connectivity, and any suspension permitted under P3.3. Service credits and contractual service levels are not available.
P4.3 Production Calls are served by the current production model versions. We may change models, thresholds, configurations and features; where a change is likely to have a material adverse effect on your use of the Services we will give thirty (30) days’ written notice, and you may terminate on notice given before it takes effect.
P5. OUTPUTS
P5.1 Clause 6.1 of the Terms continues to apply in production: an Output is a probabilistic signal and is never a finding of fact or a determination of authenticity, genuineness, validity or identity. An Output must not be the sole or determinative basis for any decision about a person. Where you use an Output in connection with such a decision you will apply human review that is capable of changing the outcome and is not a formality, by a person competent to assess the Output and authorised to reach a different conclusion, you will take account of other information available to you, and you will retain a record of the review. You will inform the persons concerned, as the law applicable to you requires, that documents they submit are checked by an automated fraud-detection service, and you will give them a means to contest a decision and to obtain human intervention, so that the decision is not one based solely on automated processing within Article 22 of the GDPR. You will not represent to any person, and will not permit any person to represent, that an Output establishes that a document or object is authentic or genuine, that a person is who they claim to be, or that any fact has been verified.
P5.2 Clause 6.3 of the Terms continues to apply, and nothing in P8.1 qualifies it: the warranty in P8.1 is as to the manner of performance, not as to the correctness of any Output.
P5.3 Suitability is yours to assess. You acknowledge that you had the opportunity to evaluate the Services during the Evaluation Period, that you have satisfied yourself as to their suitability for your intended use, and that we have made no representation as to their suitability for that use, for your sector, for any document or object type, or for any jurisdiction. Where we have discussed your intended use with you, that discussion is not advice and is not a representation.
P6. FILES AND LAWFUL BASIS
P6.1 Clause 5.2 of the Terms is replaced by this P6. Consent is one lawful basis and is not required where another applies: you may submit files containing personal data relating to another person where you have identified and can document a lawful basis for the submission under applicable law and have given any notice that law requires. Clause 5.1, clauses 5.3 to 5.7 and the warranties in clause 5.4(d) and 5.4(e) continue to apply unchanged; in particular clause 5.3(c) governs personal data relating to a person under the age of 18 in production exactly as it does during the Evaluation Period. Clause 2.2 of the Terms is unaffected: no biometric processing is within scope, and the prohibitions in clause 5.3(b) are absolute.
P7. PREPAYMENT AND FEES
P7.1 Prepayment. The Services are supplied on a prepaid basis only. You pay us in advance the amount stated in the Order Form, and that amount, as increased by any later top-up, is your “Balance”. Each Call reduces the Balance by the price for that Call type stated in the Order Form. There is no subscription, no minimum commitment and no set-up fee, and you pay only for Calls actually made in the sense that unused Balance is not consumed.
P7.2 Operation of the Balance. We invoice the prepayment and each top-up in advance, and the Balance is credited when payment is received in cleared funds. Calls are refused once the Balance is exhausted, and we are not obliged to extend credit or to process Calls against a negative Balance. You may top up at any time, subject to any minimum top-up stated in the Order Form. Clauses 2.15 and 2.16 of the Terms govern which Calls draw down the Balance. Consumption is calculated on our own Call records, which are conclusive absent manifest error; you may query a statement within thirty days and may access your usage and Balance through the account at any time. Clauses 10.2 to 10.6 of the Terms continue to apply, including payment in advance, the no-credit rule, the tax and withholding provisions, the refund rule in clause 10.4 and the effect of payment in clause 10.6.
P7.3 Expiry, refunds and price changes. Unused Balance expires twelve (12) months after the payment that created it, and expired Balance is not refundable, transferable or restorable. Unused Balance is otherwise non-refundable, except
that where we terminate for convenience under P3.1, discontinue the Services, or the Order Form expires without our having offered renewal, we will refund the unexpired unused Balance. No refund is due where you terminate or where we terminate under P3.2 or P3.3. We may change the prices on sixty (60) days’ written notice taking effect at the start of a calendar month and applying only to Balance consumed after that date; if you do not accept the change you may terminate on notice given before it takes effect, and P7.3 applies to the unused Balance as if we had terminated for convenience.
P8. WARRANTY AND LIABILITY
P8.1 Warranty. Clause 7.3 of the Terms does not apply once an Order Form is in force. We warrant that we will perform the Services with reasonable skill and care and in accordance with the Documentation in all material respects. Your exclusive remedy for breach of this warranty is that we will re-perform the affected Calls or, if we cannot do so within a reasonable period, refund the Fees consumed for them. To claim under this warranty you must notify us at legal@deepxl.ai within thirty (30) days of the affected Call, describing the failure in reasonable detail; a claim notified later is barred. The warranty does not apply to use during the Evaluation Period, to a Call whose submission did not meet the technical and quality requirements in the Documentation, to a Call analysed under General Coverage as described in clause 6.6 of the Terms, or to a failure arising from Customer Content, from your systems or connectivity, or from your own thresholds, decision rules or configuration. Clauses 7.1 and 7.2 of the Terms continue to apply, including the disclaimer of any warranty of accuracy, completeness or detection performance.
P8.2 Our total aggregate liability arising out of or in connection with the Terms and any Order Form, whether in contract, tort (including negligence), breach of statutory duty or otherwise, is limited to the Fees consumed from your Balance in respect of Calls actually made in the twelve months preceding the event giving rise to the liability or, where that amount is less than five thousand euro (EUR 5,000), to that figure, so that a limit applies from the start of the production relationship. Balance paid in advance but not yet consumed is not taken into account, and any charge paid in respect of the Evaluation Period is disregarded.
P8.3 A single cap applies to all claims. The limit in P8.2 is not increased, doubled or disapplied for any category of claim, including a claim arising from a personal data breach or from breach of clause 8 of the Terms or of Schedule 2, and clause 11.6 of the Terms applies so that such a claim is not a breach of clause 9 (confidentiality) for the purposes of the uncapped matters. Clause 12.1 of Schedule 2 preserves the position that the limit does not apply to the extent Data Protection Law or the Standard Contractual Clauses do not permit it, and clause 11.4 of the Terms preserves liability that can never be limited.
P8.4 We are not liable for any loss to the extent it arises from your failure to comply with P5.1, from your use of an Output as the sole or determinative basis for a decision, from your use of an Output without the review required by P5.1 or with a review that was a formality, from any representation you made about an Output, from Customer Content, or from your own thresholds, decision rules or configuration.
P9. REGULATED CUSTOMERS, DORA AND OUTSOURCING
P9.1 These Production Terms do not contain the contractual provisions that Regulation (EU) 2022/2554 (DORA), as implemented in Norway by the Act of 27 May 2025 on digital operational resilience in the financial sector, or equivalent outsourcing rules applicable to financial entities, require for ICT services supporting critical or important functions — in particular unrestricted rights of access, inspection and audit for the entity and its competent authorities, exit strategies and transition periods, subcontracting conditions, and incident and threat-led penetration testing cooperation. A Customer that is a financial entity will determine, before production use, whether the Services support a critical or important function and whether those provisions are required by the law applicable to it; where they are, the parties will enter into our DORA Addendum before production use, the Order Form will say so under clause 2.10(k), and until it is signed the Services may not be used to support such a function.
P9.2 Whether or not the DORA Addendum applies, we will provide on request the information reasonably required for the Customer’s register of information under Article 28(3) of DORA and for any notification the Customer must make to its supervisory authority in respect of its use of the Services, including under section 13-4 of the Norwegian Financial Institutions Act (finansforetaksloven), and clause 7.4 of Schedule 2 governs the cost of anything beyond our standard documentation.
P10. SWITCHING AND EXIT
P10.1 Notwithstanding clause 12.4 of the Terms, for the purposes of Chapter VI of Regulation (EU) 2023/2854 (the Data Act), to the extent it applies to the Services, and in any event as a matter of contract: (a) you may terminate under P3.1 on thirty (30) days’ notice and no switching charge or early termination charge applies unless the Order Form states one; (b) during the term, and for thirty (30) days after termination or expiry, you may retrieve through the API and the account the Outputs and usage records relating to your Calls in the machine-readable format in which they were returned; (c) Customer Content itself is not exported, because you hold the originals and we delete it under clause 8.3 of the Terms; (d) we will give reasonable cooperation, without charge, with your migration to another provider or to your own systems, limited to the information and formats described in the Documentation; and (e) the retention and deletion rules in clause 8.3 of the Terms and clause 11 of Schedule 2 apply after retrieval.