Trustform wallet Terms of Use

Interim soft-launch working version v1.1 · 11 September 2026

Effective Date: 11.09.2026

Last Updated: 11.09.2026

Please read these Terms carefully. They set out what the Trustform Wallet does and, importantly, what it does not do. Sections 25 and 26 limit our liability and allocate risk. Section 10 explains that we do not determine beneficial owners. Section 11 explains that a credential, once issued, cannot be recalled from a person who already holds it. Section 14 explains your responsibilities where you enter information about other people. If you are a consumer, Annex 1 sets out rights you have that these Terms cannot reduce.

1. About these Terms and who you are contracting with

1.1 These Terms of Use (the "Terms") govern your access to and use of the Trustform Wallet and the related websites, web applications, mobile applications, application programming interfaces, software, features and services made available in connection with it (together, the "Service").

1.2 Which Trustform entity you contract with. The Trustform entity that contracts with you is determined by your location, as set out in Schedule B (Country Schedule):
(a) if you are located in the United Kingdom, or in another country allocated to Trustform UK in Schedule B, your contract is with Trustform UK Ltd, a company incorporated in England and Wales with company number 16485941 and registered office at Fourth Floor, 11 Berkeley Street, London, England, W1J 8DS ("Trustform UK");

(b) if you are located in the European Economic Area and the Service is made available to you by the EEA contracting entity identified in Schedule B, your contract is with Truvity B.V., a private limited liability company incorporated in the Netherlands, registered with the Dutch Chamber of Commerce under number 64246728 and having its registered address at Nieuwezijds Voorburgwal 162, 1012 SJ Amsterdam, the Netherlands ("Trustform EU"); and

(c) if you are located elsewhere, your contract is with Trustform UK unless Schedule B expressly identifies another contracting entity for your country.

References to "Trustform", "we", "us" and "our" are to whichever of those entities contracts with you. The governing law, the forum for disputes, the consumer-law variations that apply to you and the dispute-resolution routes available to you are those stated for your country in Schedule B.

1.3 Your location. Your location is determined at the time you accept these Terms, by reference to the country of residence or, for an Organisation, the country of establishment that you provide to us. If you move, or if the information you gave was incorrect, we may update the contracting entity applicable to you on notice; a change of contracting entity does not reduce any right you have already accrued and does not reduce mandatory consumer rights.

1.4 Acceptance. By creating an Account, clicking to accept these Terms, downloading or installing a Trustform mobile application, or otherwise accessing or using the Service, you confirm that you have read and understood these Terms and agree to be bound by them. If you do not agree, you must not access or use the Service.

1.5 Acting for an Organisation. If you access or use the Service on behalf of a company, partnership, trust, foundation, association or other organisation, you represent and warrant that you have authority to bind that organisation, and Schedule A applies. In that case "you" and "your" refer to both you and that organisation, except where the context requires otherwise.

1.6 Who these Terms do not bind.
(a) A Certifier, in their capacity as a Certifier, is bound by the Trustform Certifier Terms of Use and not by these Terms. Where a Certifier also holds a Wallet as a user, these Terms govern that use only.

(b) A Recipient is bound by the conditions of access presented to and accepted by them at the point of access (the "Verification Page Notice"), and not by these Terms.

1.7 Order of precedence. Where there is a conflict between documents, the following order applies, higher prevailing over lower to the extent of the conflict:

  1. Annex 1 (Consumer Rights), where you are a consumer;

  2. Schedule B (Country Schedule), as to contracting entity, governing law, forum and jurisdiction-specific requirements;

  3. any Master SaaS Agreement or other signed written agreement between Trustform and your

  4. Organisation covering the Service;

  5. any order form, subscription confirmation or Billing Terms applicable to a paid plan you have purchased;

  6. the Certification Terms, as to the subject matter of a Certification Request;
    Schedule A (Business Accounts);

  7. these Core Terms;

  8. Annex 3 (Acceptable Use Policy) and any other annex or product-specific notice.

The Privacy Notice is not in this hierarchy: it describes how we process personal data and does not vary these Terms.

1.8 Documents incorporated. The documents incorporated into these Terms by reference are, and are limited to: Schedules A and B; Annexes 1 to 3; the Certification Terms where you submit a Certification Request; and any checkout terms, subscription confirmation or order form applicable to a paid plan you have purchased. The Privacy Notice and any just-in-time privacy notice are transparency documents and do not form contractual terms. No other document forms part of these Terms unless we expressly say so in writing.


2. Definitions and interpretation

2.1 In these Terms:

Account means an account used to access the Service, whether established for an individual or for an Organisation.

Affiliate means, in relation to a party, any entity that directly or indirectly controls, is controlled by, or is under common control with that party, where "control" means the ownership of more than 50% of the voting rights or the ability to direct the management of the entity.

Authorised User means an individual whom an Organisation permits to access or use a Business Wallet on its behalf.

Business Wallet means a Wallet established for or used by an Organisation, including the information, documents, relationships, permissions and activity records associated with it. Referred to in the Service as an enterprise or organisation wallet.

Certification Request means a request submitted through the Service asking a Certifier to review and, if the Certifier is satisfied, certify a document, copy, fact, statement, signature, identity attribute or other information.

Certification Terms means the Trustform Certification Terms, accepted in-flow at the point a Certification Request is raised, which govern the subject matter of that request.

Certifier means a professional — including a lawyer, notary, court interpreter or legal translator — whom Trustform has admitted to the Service as a Certifier following the verification described in clause 12.4, and whose authority to certify through the Service is limited to the scope recorded on their Certifier profile.

Credential means a verifiable credential issued through the Service following a Certification Request, held in a Wallet, presentable to a Recipient and verifiable independently of Trustform, the holder and the Certifier.

Extraction Output means a value, field, relationship or other item of data proposed by the Service from a document you upload, using optical character recognition, artificial intelligence or other automated means, before you confirm it.

Free Tier means access to the Service, or to a feature of it, made available to you without payment.

Identity Provider means a third party that provides identity verification, authentication, biometric, liveness, registry, screening, data validation or similar services integrated with or made accessible through the Service.

Partner Sign-In means a branded sign-in method made available by Trustform that allows you to create, link or access a Wallet account using identity credentials or authentication assertions supplied through an approved partner's identity or self-sovereign identity (SSI) infrastructure.

Key Person means an individual whom the Service lists as appearing to have significant involvement in an Organisation's ownership, control or management, for the purpose described in clause 10.

Organisation means any company, partnership, trust, foundation, association, public body or other legal or organisational entity.

Profile means the structured record of an individual or an Organisation maintained in a Wallet, including its identity attributes, relationships, ownership and control data, documents and Credentials.

Recipient means a person or Organisation to whom Wallet Content is sent, disclosed, made accessible or otherwise made available through or in connection with the Service.

Structure Version means the state of an Organisation's Profile — its entities, relationships, percentages and rights answers — at a given point in time, as recorded by the Service. Any change creates a new Structure Version, and earlier versions are retained.

User or you means a person who holds or uses an Account, and an Organisation on whose behalf an Account is held. It does not include a Certifier acting as a Certifier, or a Recipient.

Verification Page means the public page on which a Credential may be verified, showing the request provenance and the Certifier's name, occupation, business, regulatory body, licence number, licence expiry and status.

Wallet means the individual or Business Wallet made available to you through the Service.

Wallet Content means information, records, documents, images, Credentials, attributes, statements, relationships, certifications, metadata and other content submitted to, generated through, stored in, received by or shared from the Service.

2.2 References to "including" or "includes" mean "including without limitation". Headings are for convenience only and do not affect interpretation. A reference to applicable law includes legislation, regulations, binding regulatory requirements and professional rules applicable to the relevant person or activity. A reference to a "consumer" means an individual acting wholly or mainly outside their trade, business, craft or profession.


3. Eligibility and authority

3.1 You may use the Service only if you have legal capacity to enter into a binding agreement and are at least 18 years old, or the age of legal majority in your jurisdiction if higher.

3.2 How we apply the age requirement. We require you to confirm your date of birth at registration. Where you complete electronic identity verification under clause 8, your date of birth is verified against your identity document. We may suspend or close an Account where we have reasonable grounds to believe the holder is under 18. We do not knowingly provide the Service to anyone under 18 and no feature of the Service is directed at children.

3.3 You may not use the Service if you are prohibited from doing so under applicable law, are subject to sanctions or trade restrictions that prevent us from providing the Service to you, or were previously removed from the Service for material breach, unless we have expressly authorised your return.

3.4 You are responsible for ensuring that your use of the Service, and any instruction you give through it, is lawful and within the scope of your authority. If you act for another person or an Organisation, you must have and maintain all mandates, appointments, consents and permissions necessary to do so.

3.5 Partner Sign-In. Trustform may allow you to create, link or access your Account using Partner Sign-In, including a branded option such as "Log in with Investors Europe" where that option is made available to you. When you use Partner Sign-In, the relevant partner may authenticate you and provide Trustform with the identifiers, credentials, attributes or authentication result needed to establish or confirm your access to the Wallet. Trustform uses that information only as described in these Terms and the Privacy Notice. Using Partner Sign-In does not give the partner ownership or control of your Wallet Content and does not authorise Trustform to share Wallet Content with the partner unless you separately choose to share it or another lawful basis applies.

4. What the Wallet is

4.1 The Wallet is a business identity wallet. It lets you build and maintain a structured record of who you are, or who an Organisation is — including who owns and controls it and the documents evidencing that — and then reuse that record with counterparties instead of re-submitting the same information each time.

4.2 Depending on the features made available to you, the Service may enable you to: create an individual or Business Wallet; verify your identity electronically or by uploading documents; build an Organisation's Profile, including its ownership, management and appointment relationships; upload, organise and maintain documents; request certification of documents from a Certifier and hold the resulting Credentials; share selected Wallet Content with Recipients and revoke future access; manage roles, permissions and approvals; maintain activity records; and use integrations with other Trustform products or third-party services.

4.3 The Profile is yours to maintain. The Profile is a record that you control and keep current. It is not a submission that Trustform holds, checks, endorses or certifies. Section 7 sets out your obligation to keep it accurate and current, and what we do and do not do about currency.

5. What Trustform does not do

This section is important. It states expressly what the Service is not, and it applies throughout these Terms.

5.1 Trustform does not verify the truth of information you provide. Except where the Service performs a specific automated check and tells you the result, we do not investigate, corroborate or confirm that Wallet Content is true, complete or current.

5.2 Trustform does not determine beneficial owners, and the Service does not perform a beneficial ownership determination or a compliance assessment. Section 10 explains this in full.

5.3 Trustform does not provide legal, notarial, accounting, tax, investment, compliance or regulatory advice, and is not acting as your lawyer, notary, auditor, corporate service provider, compliance officer, fiduciary, certifying officer or identity issuer. This remains the case notwithstanding that lawyers, notaries and other professionals operate on the Service as Certifiers.

5.4 Trustform is not a certifying authority. Where a Certification Request is made, the certification is the act of the Certifier, performed on their own professional authority and responsibility. Section 12 explains what Trustform does and does not do in relation to Certifiers.

5.5 Trustform does not warrant that any counterparty will accept a Profile or a Credential. No bank, registry, authority, court, employer or other Recipient is obliged to accept anything issued through or shared from the Service, and acceptance may depend on their own requirements, applicable law and the process used.

5.6 Trustform is not a qualified trust service provider under Regulation (EU) No 910/2014 or its UK equivalent, is not an EUDI wallet provider, and does not issue qualified electronic signatures or qualified electronic seals. A Credential and the Certifier's digital stamp are what these Terms and the Certification Terms describe them to be, and nothing more.

5.7 Trustform does not carry out regulated activity on its own account in relation to your compliance obligations. We provide software to the people who carry those obligations; we do not discharge them for you.

6. Wallet Content: ownership, our licence, and what we do not do with it

6.1 Ownership. As between you and Trustform, and subject to rights held by third parties, you retain all right, title and interest in Wallet Content you submit. These Terms do not transfer ownership of it to us.

6.2 The licence you grant us. You grant Trustform and its Affiliates a non-exclusive, worldwide, royalty-free licence to host, store, reproduce, format, organise, transmit, display and otherwise process Wallet Content, solely to: operate, secure, support, maintain and provide the Service to you; carry out your instructions; perform the automated processing described in clauses 8, 9 and 10; prevent and detect fraud and misuse; enforce these Terms; and comply with our legal obligations. The licence lasts for as long as reasonably necessary for those purposes, including applicable backup, audit and retention periods.

6.3 What we do not do with your Wallet Content — artificial intelligence.

(a) We do not use Wallet Content to train, fine-tune or improve general-purpose or foundation artificial intelligence models, whether our own or a third party's.

(b) We do not disclose Wallet Content to a provider of a general-purpose model for that provider's own training purposes. Where we use a third-party model to provide a feature to you, we do so under contractual terms that prohibit the provider from retaining or using your Wallet Content to train its models.

(c) We may use Wallet Content to train, evaluate and improve our own document-extraction, classification and data-quality models, but only where the content has been aggregated or de-identified so that it no longer relates to an identifiable person or Organisation, or where you have separately and specifically consented to the use of identified content for that purpose. Consent given for that purpose is not a condition of using the Service and may be withdrawn.

(d) We may use aggregated, de-identified statistical information about use of the Service for any lawful purpose, provided it cannot reasonably be used to identify you, your Organisation or any individual.

6.4 Your rights in what you submit. You represent and warrant that you have all rights, permissions, notices, consents and lawful bases necessary to submit, store, use, request, receive and share Wallet Content through the Service, including where it relates to another individual or Organisation. Section 14 deals specifically with information about other people.

6.5 We do not pre-screen. We are not obliged to review Wallet Content before it is stored or transmitted. We may remove, restrict or preserve access to content where reasonably necessary to protect users, comply with law, enforce these Terms or preserve evidence.

6.6 Third-party sources. Where the Service displays information obtained from a registry, an Identity Provider, a Certifier or another third party, that information may be incomplete, delayed, unavailable or subject to conditions imposed by the source. You should independently confirm material information before relying on it.

6.7 Export. You may export your Profile and your Wallet Content at any time while your Account is active, and for 30 days after it closes, in a structured, commonly used, machine-readable format covering: your Profile and its current Structure Version; the documents you have uploaded; the Credentials you hold; and your sharing and activity history. This right is in addition to any right of data portability you have under data protection law, and it extends to Profile data that is not personal data. We may apply reasonable technical limits to very large or repeated exports, and we may charge a reasonable fee for an export requested more than once in any 30-day period.

7. Accuracy, and the living Profile

7.1 You must provide complete, accurate and current information, and you are responsible for the accuracy, legality, completeness and appropriateness of Wallet Content you provide or confirm.

7.2 Your obligation to keep it current. The Profile is designed to be a living record, and counterparties may rely on it as current. You must therefore keep your Profile current, and must update it without undue delay where a change occurs that makes it inaccurate or incomplete — including a change of address or identity document, a change of directors or officers, a transfer of shares or other change of ownership, a change in control or in the rights recorded under clause 10.2, and the expiry or replacement of a document held in the Wallet.

7.3 What we do not do about currency. Trustform does not monitor your Profile for changes, does not verify that it remains accurate, and does not notify Recipients if it ceases to be. The Service may prompt you to review or refresh information, and may display when information was last confirmed, but a prompt is not a check and the absence of a prompt is not a confirmation that your Profile is current.

8. Electronic identity verification

8.1 Certain features allow or require electronic identity verification, authentication, screening or data validation. These may be performed by one or more Identity Providers acting under their own technical methods and legal responsibilities. Our Identity Providers are named in the Privacy Notice.

8.2 By initiating or consenting to identity verification, you instruct us to transmit the information and documents necessary to the relevant Identity Provider, and to receive, display, store and otherwise process the resulting data, status, evidence or credential in accordance with the Privacy Notice and the selections you make.

8.3 Biometric and other special category data. Electronic identity verification inherently involves the processing of biometric data — for example, a facial image compared against the image on your identity document, and liveness signals. We do not process biometric data for that purpose unless you have given explicit consent at the point of verification, separately from your acceptance of these Terms. Accepting these Terms is not consent to biometric processing. If you do not consent, you may still verify your identity through the document-upload route in clause 9, though some features and some counterparties may require the electronic route. You may withdraw consent at any time; withdrawal does not affect the validity of a verification already completed, and the Privacy Notice explains what is retained and for how long.

8.4 What a verification result means. A verification result indicates only that specified checks were completed and produced a particular result at a particular time. It is not a guarantee that a person is who they claim to be, that the information remains current, that fraud is impossible, or that you satisfy any Recipient's legal, risk or compliance requirements.

8.5 Failed or inconclusive checks. We do not guarantee that an Identity Provider will be available, will complete a check, or will produce a particular outcome. Where a check fails, is inconclusive or expires, we will tell you the outcome and, where we are permitted to do so, the general reason. You may retry, provide additional evidence, or use the document-upload route. A failed check does not by itself mean your Account will be closed, but we may restrict features that depend on a verified identity. Where a check fails for reasons connected with fraud prevention or financial crime, we may be unable to give reasons.

9. Document upload and automated extraction

This section allocates responsibility between what the Service proposes and what you confirm. It matters, because most data in a Profile arrives this way.

9.1 How it works. Where you upload a document, the Service may read it using optical character recognition, artificial intelligence and other automated means, and propose values, fields and relationships for your Profile. The same applies to information elicited through a guided or conversational interface in the Service.

9.2 Extraction Output is a proposal, not a finding. An Extraction Output is a proposal presented to you for review. It is not Trustform's finding, determination or verification of anything. Extraction may be incomplete, may misread a document, may attribute a value to the wrong field or person, and may miss information entirely — including on documents that are handwritten, low quality, in an unexpected format or in a language or script the Service handles imperfectly.

9.3 Confirmation makes it yours. When you confirm an Extraction Output, the confirmed value becomes your own representation as to that information, in the same way as if you had entered it yourself, and clauses 6.4 and 7.1 apply to it. It ceases to be a proposal.

9.4 You must check before you confirm. You must review each Extraction Output against the source document before confirming it, and you must not confirm a value you have not checked. The Service will show you what it proposes and the document it came from. Where you confirm in bulk, you are confirming each value in the batch.

9.5 Nothing in this section makes Trustform responsible for the content of a document you upload, for the accuracy of a value you confirm, or for a consequence of your having confirmed a value without checking it. Nothing in this section limits our own obligations in relation to the operation of the extraction feature itself.

10. Organisation Profiles, ownership and control, and Key Persons

This section describes the most carefully designed part of the Service, and the part most often misunderstood. Read it before you rely on anything the Service shows you about who owns or controls an Organisation.

10.1 How the Service records structure. An Organisation's Profile records relationships in three groups: Ownership relationships, which carry a percentage; Management relationships — directors, officers and signatories — which do not carry a percentage and are deliberately excluded from the ownership calculation; and Appointments — such as trustees, protectors, settlors and fund managers — which do not carry a percentage but may be material to questions of control.

10.2 Rights questions. The Service also asks you plain-language questions about rights over the Organisation, including who may appoint or remove directors, who holds a veto, whether a shareholders' agreement exists, and whether shareholders vote together. Your answers are your own representations and are recorded against the Structure Version to which they relate.

10.3 What the Key Person list is. The Service runs tests over the structure you have entered and lists individuals who, on the information you have provided, appear to have significant involvement. It labels them Key Persons.

10.4 What the Key Person list is not. For the avoidance of any doubt:

(a) the Key Person list is not a beneficial ownership determination, and Trustform does not determine beneficial owners;

(b) it is not a compliance assessment, a risk assessment, a due diligence conclusion, or advice of any kind;

(c) it is not a statement that any listed person is, or is not, a beneficial owner, a controlling person, a person of significant control, or anything else under any law, regulation or institution's policy;

(d) no threshold, test or criterion is represented by it, none is displayed to you, and none should be inferred from the fact that a person is or is not listed; and

(e) the absence of a person from the list is not a statement that they do not matter, whether for a regulatory purpose or any other purpose.

10.5 Your confirmation. You are asked to confirm the Key Person list, and to add or remove individuals with a reason. When you do:

(a) your confirmation is your own representation that, to the best of your knowledge and belief, the list as confirmed is complete and accurate as regards the individuals having significant involvement in the Organisation;

(b) your confirmation, your additions, your removals and your reasons are recorded against the specific Structure Version in force at the time; and

(c) your confirmation does not transfer any responsibility to Trustform, and does not make the confirmed list a determination by Trustform.

10.6 Your own obligations remain yours. You remain solely responsible for: identifying your beneficial owners and controlling persons for any purpose for which you are required to do so; complying with your own regulatory, registry, tax and reporting obligations; and the accuracy and completeness of anything you declare to a bank, registry, authority or other institution. You must not represent to any third party that Trustform has determined, verified or approved the beneficial ownership or control of any Organisation, or that a Key Person list constitutes such a determination.

10.7 Where a Trustform determination is made. Where Trustform, acting as a service provider to a regulated institution under a separate agreement, makes a determination about beneficial ownership, it does so under that agreement and for that institution — not for you, and not under these Terms. Nothing in the Service tells you that such a determination has been made, and you may not rely on one.

10.8 Profiling depth and technical limits. The Service may apply limits to the depth, type or complexity of ownership and control structures it can represent. Any material limit applicable to the feature you are using will be shown in the Service or Documentation. You are responsible for determining whether your structure is fully represented, and a complete-looking Profile is not a statement that every ownership, control or appointment relationship has been captured.

11. Credentials: issuance, holding, presentation, revocation — and immutability

11.1 What a Credential is. A Credential is a verifiable credential issued following a Certification Request. It is not a stamped PDF. It is held in your Wallet, may be presented repeatedly, and may be verified by a Recipient without contacting Trustform, you or the Certifier. It is signed with the Certifier's own decentralised identifier and carries the Certifier's digital stamp.

11.2 Immutability — read this before you issue. A Credential is issued on infrastructure designed so that it cannot be silently altered. This has consequences you should understand before a Credential is issued:

(a) a change does not overwrite a Credential — it produces a new recorded version, and the earlier version remains recorded;

(b) once a Credential has been presented to or accessed by a Recipient, it cannot be recalled, edited, unissued or withdrawn from that Recipient's hands, whether by you, by the Certifier or by Trustform;

(c) revoking a Credential, or withdrawing sharing under clause 13, changes or restricts its future status or availability through the Service. Revocation does not erase the Credential, retrieve a copy already held by a Recipient, or make the historical issuance event disappear. A Recipient may still be able to verify that a Credential was issued and has since been revoked; and

(d) closing your Account does not withdraw Credentials already issued and already held by Recipients. Clause 11.5 explains what happens on closure.

11.3 Correcting an error. Where a Credential contains an error, the route is to issue a corrected Credential and, where appropriate, revoke the earlier one. Trustform can record the revocation status and facilitate issuance of a new version at the Certifier's instruction; neither Trustform nor the Certifier can silently alter the historical Credential that was already issued. Where the error is in the certification itself, the Certification Terms and the Certifier's own complaints procedure apply.

11.4 Erasure and immutability. Data protection law gives you rights of erasure and rectification in relation to personal data, and immutability is in tension with them. Our position, described in full in the Privacy Notice, is that:

(a) the personal data within a Credential is stored so that it can be deleted, and what is recorded immutably is a cryptographic representation of it, which does not by itself reveal the underlying data;

(b) on a valid erasure request, we delete the Credential and related personal data.

(c) we may retain what we are permitted or required to retain under Article 17(3) of the UK GDPR and the EU GDPR and their equivalents — including for the establishment, exercise or defence of legal claims, and to comply with a legal obligation — and we retain the audit and security records described in clause 21.5.

We cannot delete a copy of a Credential already held by a Recipient, and a request to us cannot achieve that.

11.5 Account closure and issued Credentials. On closure of your Account: Credentials already issued and held by Recipients remain valid and verifiable unless revoked; the Verification Page for those Credentials continues to operate, showing the Certifier's details and the request provenance; your ability to present, manage or revoke Credentials through the Service ends; and you should exercise clause 6.7 to export your Credentials before closing. Where a Certifier's status becomes Inactive, Credentials they have issued remain verifiable and their record is preserved for audit purposes, as described in the Certifier Terms.

12. Certification Requests

The Certification Terms, accepted in-flow when you raise a Certification Request, govern that request. This section states the position between you and Trustform. Where the two differ on the subject matter of a request, the Certification Terms prevail (clause 1.7).

12.1 What the Service does. The Service enables you to select and communicate with a Certifier, provide documents and information to them, and receive the resulting Credential. Trustform provides the environment in which that happens, and the governance described in clause 12.4.

12.2 Who contracts with whom. Unless expressly agreed otherwise in writing, the professional relationship arising from a Certification Request is between you and the Certifier. Trustform is not a party to it, does not direct the Certifier's professional judgement, and does not itself certify anything.

12.3 Your authorisation. By submitting a Certification Request you authorise Trustform to disclose the selected Wallet Content and related information to the chosen Certifier, and to facilitate communications, status updates, payment information where applicable, and delivery of any resulting Credential.

12.4 What Trustform verifies about a Certifier, and what that means. Before a professional may certify anything through the Service, Trustform verifies:

(a) their identity;

(b) their practising licence or professional authorisation;

(c) the regulatory or professional body that licenses or authorises them;

(d) the jurisdiction granting that authority; and

(e) the scope of what they are authorised to certify.

Certification is enabled on their account only after those checks are completed, and we re-verify licence status on the cadence stated on the Verification Page. The Verification Page displays the Certifier's name, occupation, business, regulatory body, licence number, licence expiry and status.

What that verification does not mean. Verification is as at the time it was performed, and:

(f) it is not a guarantee of the Certifier's competence, nor of the quality, correctness or legal sufficiency of any particular certification;

(g) it is not a warranty that the licence remains valid between checks, or that the Certifier has notified us of a change as they are required to do;

(h) it is not a recommendation of any Certifier for your purpose, and you remain responsible for choosing a Certifier suitable for it;

(i) it does not make Trustform a party to the certification, a certifying authority, or responsible for the legal act; and

(j) it does not extend to matters outside those listed in (a) to (e) — in particular it is not a check of the Certifier's insurance position, disciplinary history beyond licence status, or professional record.

What Trustform stands behind is the governance of who is permitted to act and the integrity of the record. The legal act, and the liability for it, remain with the Certifier.

12.5 The Certifier's decisions. A Certifier alone determines whether they are authorised to accept a request, what evidence or procedure is required, whether the applicable legal or professional standard is met, and whether to issue, refuse, qualify, withdraw or revoke a certification. A Certifier may require additional evidence, an interview, an original document, an in-person step, a prescribed form or payment of fees, and may refuse a request in their discretion or where law or professional obligations require.

12.6 Your warranties on a request. You represent and warrant that every document and item of information you submit is genuine, complete and not misleading; that you are entitled to submit it; that you hold it lawfully; and that you are not seeking certification for an unlawful, fraudulent or deceptive purpose.

12.7 No warranty of acceptance. No Recipient, bank, registry, authority or court is obliged to accept a Credential. We tell you this before you pay for or rely on a certification, and we repeat it here.

12.8 Apostille and legalisation are outside the Service. Where a document is intended for government use, or for use in a country that is not a party to the Hague Apostille Convention, an apostille, consular legalisation or other formality may additionally be required. The Service asks you for the intended use and destination country and shows a notice where this is likely, but:

(a) apostille and legalisation are not part of the Service;

(b) whether a formality is required, and obtaining it, are your responsibility; and

(c) the notice the Service shows is general information based on what you have told us. It is not advice, and its absence is not a statement that no formality is required.

12.9 Declined, cancelled and re-certified requests. Where a request is declined by the Certifier, cancelled by you before the Certifier begins work, or cancelled by the Certifier, the Service will tell you the outcome and what happens to any fee. Fee treatment is set out in the Certification Terms and, once fees are live, in the Billing Terms; where you are a consumer, Annex 1 applies and prevails.

12.10 Fees for certification. Where a fee is payable for a certification, the price and the identity of the person supplying the certification service will be shown before you commit to pay. Unless the checkout screen states otherwise, the Certifier supplies the professional certification service and Trustform collects the fee as the Certifier's disclosed collection agent. The Certifier remains responsible for the professional service and its own tax and professional obligations; Trustform is responsible for operating the payment collection mechanism and for any obligation that applicable law places on Trustform in that role.

12.11 Immutability acknowledgement. You acknowledge clause 11.2 before a Credential is issued at your request.

13. Sharing, permissions and Recipients

13.1 Selective disclosure. The Service is designed to let you disclose selectively. You may be able to choose particular documents, attributes, Credentials or data fields, identify a Recipient, set an access period and purpose, and revoke future access where the technical design permits.

13.2 Your instruction. When you approve or initiate a share, you instruct and authorise Trustform to make the selected Wallet Content available to the designated Recipient in accordance with the settings shown to you at the time. You are responsible for checking the identity of the Recipient, the scope of what you have selected and any stated purpose before you confirm.

13.3 Revocation. Revocation prevents future access through the Service. It does not retrieve, erase or invalidate copies already downloaded, exported, recorded, printed, transmitted onward or otherwise retained by a Recipient, and a Recipient may have a legal obligation or independent lawful basis to retain what it has received. Clause 11.2 applies to Credentials.

13.4 Recipients act independently. Unless the Service expressly states otherwise, a Recipient acts independently of Trustform and is responsible for its own collection, use, disclosure, storage, security, retention and deletion of what it receives. We do not control a Recipient's systems or its subsequent conduct.

13.5 Verification Page conditions. A Verification Page displays a short Verification Page Notice explaining the provenance and status of the information, the limits of Trustform's role and the lawful-use conditions that apply to access through that page. Where the product requires an affirmative acceptance step before access, those conditions form the access terms accepted by the Recipient. Where no acceptance step is used, the Notice operates as a notice and does not by itself make the Recipient a party to these Terms. Trustform does not guarantee a Recipient's compliance with any condition or notice.

13.6 Sharing into the Trustform Platform. Where a Recipient is an institution operating the Trustform Platform, a Profile you share may flow into that institution's own compliance workflow, where it is processed by and for that institution under its own arrangements. From the point at which it enters that workflow, the institution determines how it is used and Trustform acts on that institution's instructions. The Privacy Notice sets out the point at which that change occurs and who answers a data subject request at each stage.

13.7 Records of sharing. The Service may record evidence of a sharing event, including the sender, Recipient, time, scope, status and permissions. Those records support auditability. They do not prove that every legal requirement applicable to a particular disclosure has been satisfied.

14. Information about other people

This section deals with the directors, shareholders, beneficial owners, officers, employees and family members whose information you enter into a Profile. They are not parties to these Terms, and many of them will not know their information is in your Wallet.

14.1 Your authority. Where you submit, store, confirm or share information about another individual, you must have all rights, lawful bases, authority, consents and permissions necessary to do so. The fact that information is held in a Business Wallet does not by itself establish authority to disclose it.

14.2 Your transparency obligation. Where you are the controller of information about another individual — which will normally be the case for information you enter about the people connected with your Organisation — you are responsible for giving that individual the information data protection law requires, including that their data is held in a Trustform Wallet, why, with whom it may be shared, and how they may exercise their rights. A warranty to us does not discharge that obligation.

14.3 What we provide to help you. Trustform may provide template transparency wording in the Service or Help Centre that an Organisation can use as a starting point when informing individuals whose data it enters into a Business Wallet. The Organisation remains responsible for adapting that wording to its own purposes, lawful basis, disclosures and retention, and for giving any notice required by applicable law.

14.4 Roles under data protection law. The Privacy Notice sets out our position on who is controller and who is processor at each stage, including for information about third parties, and the point at which a role changes when a Profile is shared into an institution's workflow. Those roles are determined by the relevant facts and by any applicable data processing agreement, and the Privacy Notice describes them; they are not determined by these Terms alone.

14.5 Requests from individuals. Where an individual contacts Trustform about information held in your Wallet and we are not the controller of it, we will tell them so, tell them how to contact you where we may lawfully do so, and pass the request to you. You must respond to it as the controller, and you must not obstruct the exercise of a right. We may act on our own account where we are the controller, where we are required to by law, or where an individual's rights are being frustrated.

15. Integrations and third-party services

15.1 The Service may interoperate with other Trustform products and with third-party websites, applications, registries, Identity Providers, storage services, payment providers, communications services and other systems ("Third-Party Services").

15.2 Your use of a Third-Party Service is governed by that third party's terms and privacy information. Trustform does not control and is not responsible for the operation, availability, accuracy, security, legality or content of a Third-Party Service.

15.3 If you enable an integration, you authorise Trustform to exchange data with the relevant Third-Party Service as necessary to perform it. You are responsible for configuring it correctly and for ensuring the exchange is authorised.

15.4 A Third-Party Service may change or discontinue its interface without notice to us. We may suspend or remove an integration where necessary for security, legal, technical or commercial reasons.

15.5 Links to third-party sites are provided for convenience and do not imply endorsement.

15.6 Partner authentication. Partner Sign-In is an authentication method for the Trustform Wallet and may be available across both the web and mobile applications. The partner provides the authentication or SSI-based identity assertion used to sign you in; Trustform remains responsible for the Wallet Service. Your relationship with the partner, including the partner's own processing of personal data, is governed by the partner's terms and privacy information.

15.7 Availability and continuity. A Partner Sign-In option may depend on the continued availability of the relevant partner's authentication or SSI infrastructure. If that method becomes unavailable, Trustform may provide another supported way for you to access the same Wallet Account, subject to appropriate identity and security checks.

16. Acceptable use

16.1 You must use the Service lawfully and honestly, and in a way that does not harm Trustform, other users or third parties. Annex 3 (Acceptable Use Policy) sets out what is prohibited and the enforcement steps we may take. It is part of these Terms.

16.2 We may update Annex 3 from time to time to address new forms of misuse. We will give notice of a change in accordance with section 28, and a change to Annex 3 that does not reduce your rights or expand your obligations beyond conduct that is already unlawful or already prohibited in substance takes effect on notice.

16.3 We may investigate suspected misuse, and may preserve or disclose information where reasonably necessary to comply with law, protect rights or safety, respond to a lawful request or enforce these Terms.

17. The Free Tier

17.1 What is free. The core Wallet is currently made available at no charge. What the Free Tier includes is described on our website and in the Service, and includes creating and maintaining an individual or Business Wallet, building a Profile, uploading and organising documents, sharing and revoking access, and holding Credentials. Certification, and any feature identified as a paid feature, may carry a fee.

17.2 No service level. No availability commitment, service level, support commitment or response time applies to the Free Tier. Section 22 applies.

17.3 Withdrawing or reducing free features. We may withdraw the Free Tier, or materially reduce what it includes, on not less than 60 days' notice to you. We may act on shorter notice only where a shorter period is required for legal, regulatory or security reasons, and then only to the extent required.

17.4 What you get if we do. Where we give notice under clause 17.3, you may export your Wallet Content under clause 6.7 at any time during the notice period and for 90 days after it expires, and we will not delete your Wallet Content during that period other than in accordance with an erasure request or a legal obligation. Credentials already issued are unaffected as described in clause 11.5. If you have paid in advance for a feature that we withdraw before the end of the paid period, we will provide the refund or other remedy required by the checkout terms and applicable law, including Annex 1 where you are a consumer.

18. Fees, subscriptions and taxes

18.1 Some features are free and others may require payment, a subscription, a transaction fee or a separate order. Before you commit to pay, the checkout screen or order form will show the total price, taxes where applicable, billing frequency, included usage, subscription term, renewal mechanism and cancellation method. Those purchase-specific details form part of these Terms for that purchase.

18.2 You authorise us and our payment providers to charge the payment method you provide for amounts due. Unless stated otherwise, fees exclude taxes and duties, which you are responsible for except taxes on our net income.

18.3 If a subscription renews automatically, we will tell you clearly before purchase, show the renewal interval and price (or how it is calculated), provide an accessible cancellation method, and send any renewal or reminder notice required by applicable law. Cancellation stops future renewals but does not by itself reverse charges already properly incurred, subject to Annex 1 and mandatory law.

18.4 Refunds and cancellation. Except where law requires otherwise or the checkout terms expressly state otherwise, fees for a completed one-off transaction are non-refundable and recurring subscription fees are refundable only to the extent required by applicable law or where Trustform terminates a paid feature without cause before the end of the paid period. If you are a consumer, this clause is subject to Annex 1, including any applicable cancellation or withdrawal right. Fees payable for a Certifier's professional service are also subject to the Certification Terms and mandatory consumer law.

18.5 We may change pricing on reasonable notice. A price change will not apply retrospectively and will generally take effect at your next renewal or purchase. Section 28 applies to a price change, and where you are a consumer Annex 1 applies.

19. Mobile applications

19.1 Subject to these Terms, Trustform grants you a limited, personal, non-exclusive, non-transferable, revocable licence to install and use the Trustform Wallet mobile application on devices you own or control, solely for permitted use of the Service.

19.2 Annex 2 (App Store Terms) applies where you obtain the application from the Apple App Store or Google Play, and sets out the additional terms those providers require, including the account-deletion route available in the application.

19.3 You are responsible for maintaining a compatible device, operating system, network connection and security settings. Some functionality may be unavailable on an unsupported, jailbroken, rooted or otherwise compromised device.

19.4 Partner Sign-In on mobile. Where Partner Sign-In is offered in the mobile application, it is the mobile presentation of the same Wallet authentication feature available through the Service generally. It is used to authenticate or link access to a Trustform Wallet Account; it does not transfer responsibility for the Trustform application to the partner and does not, by itself, provide access to third-party content, subscriptions or purchases through the application.

20. Intellectual property

20.1 Trustform and its licensors own all right, title and interest in the Service, including its software, interfaces, workflows, designs, databases, documentation and trademarks, excluding Wallet Content owned by you or a third party.

20.2 Except for the limited right to use the Service under these Terms, no licence is granted to you by implication or otherwise. You must not remove proprietary notices, or use Trustform's names, logos or marks without prior written permission.

20.3 If you give us feedback or suggestions about the Service, you grant us a perpetual, irrevocable, worldwide, transferable, sublicensable, royalty-free right to use it without restriction, provided we do not identify you publicly as its source without your permission. This clause does not apply to Wallet Content and gives us no right to it.

21. Privacy, confidentiality and security

21.1 Our processing of personal data is described in the Privacy Notice, which also identifies our sub-processors, the legal basis for each purpose, our retention periods, our international transfer mechanisms, and our position on automated processing including the extraction described in clause 9 and the Key Person logic described in clause 10.

21.2 You must treat non-public Wallet Content you receive from another user as confidential, protect it with reasonable measures, and disclose it only as authorised, as required by law, or as reasonably necessary for the purpose for which it was shared.

21.3 We maintain technical and organisational measures designed to protect the confidentiality, integrity and availability of the Service. A summary is made available in the Trustform Trust Centre or, for enterprise customers, in the applicable security schedule. No system is completely secure, and we do not guarantee that unauthorised access, loss or disruption will never occur.

21.4 Sensitive data. Some features are designed for identity documents and other sensitive information, and you may use them for that purpose. Outside those features, you must not upload special-category data, criminal-offence data or other highly sensitive or regulated data unless the relevant feature is intended for it and you are authorised to submit it. Clause 8.3 governs biometric data processed in electronic identity verification, which is not data you choose to upload.

21.5 Audit and security records. The Service maintains audit and security records of access, sharing, certification, verification, approvals, configuration changes and other activity. We may retain those records for security, compliance, dispute resolution, fraud prevention and legal purposes after particular Wallet Content is deleted, where retention is lawful and proportionate. Retention periods are in the Privacy Notice.

22. Availability, changes and beta features

22.1 We aim to make the Service reliably available but do not guarantee uninterrupted, error-free or continuous operation. Availability may be affected by maintenance, updates, telecommunications failures, third-party services, security incidents, legal requirements and events beyond our reasonable control. No service level applies unless a paid plan or a signed agreement states one.

22.2 We may impose reasonable technical, rate, storage or usage limits to protect the Service and its users.

22.3 We may add, modify, suspend or discontinue features. Where a change materially and adversely reduces core functionality you use, we will give reasonable advance notice and, where you are a consumer or where the change affects a paid plan, section 28 and Annex 1 apply. Clause 17.3 applies to withdrawal of the Free Tier.

22.4 A feature identified as beta, pilot, preview or experimental is provided for evaluation, may be incomplete, may change or be withdrawn, and may carry additional limitations stated in the product. Unless a signed enterprise agreement expressly says otherwise, you must not use or rely on a beta feature as the sole means of satisfying a legal, regulatory, filing, identity-verification or compliance obligation.

23. Suspension, termination and what happens to your data

23.1 You may stop using the Service at any time, and may close your Account in the Service settings — including in the mobile application, as described in Annex 2 — or by contacting us. Closure is subject to any payment obligation, any legal retention requirement, and any Organisation control over a Business Wallet.

23.2 We may suspend, restrict or terminate access immediately where reasonably necessary to address a security threat, suspected fraud, unlawful activity, sanctions risk, material breach of these Terms or Annex 3, non-payment, harm to other users, a lawful request, or a risk to the integrity of the Service.

23.3 Where practicable we will give notice and an opportunity to remedy a remediable breach before terminating. We need not do so where delay could cause harm, compromise security, breach law or frustrate an investigation. Where we suspend or terminate your access we will tell you, and give reasons unless we are prevented from doing so by law or by a financial-crime obligation.

23.4 Your data on exit. On termination or closure, your right to use the Service ends. You may export your Wallet Content under clause 6.7 for 30 days afterwards. After that we may delete or de-identify Wallet Content in accordance with the retention periods in the Privacy Notice, and we may retain what we are required or permitted to retain by law, what is necessary to protect legal rights, what clause 21.5 covers, and what remains in backups pending ordinary deletion cycles. Clause 11.5 governs Credentials already issued.

23.5 Survival. Termination does not affect accrued rights, payment obligations, or provisions intended by their nature to survive — including clauses 6.1, 6.3, 10.6, 11.2, 11.5, 14, 20, 21.2, 21.5, 24, 25, 26 and 29, and clause 6.7 to the extent stated in clause 23.4.

24. Disclaimers

24.1 Where you use the Service for business or professional purposes. To the maximum extent permitted by law, the Service is provided "as is" and "as available", and Trustform disclaims all warranties, representations and conditions, express, implied or statutory, including implied warranties of merchantability, satisfactory quality, fitness for a particular purpose, title, non-infringement and accuracy. Without limiting that, we do not warrant that the Service will meet every requirement, be uninterrupted, secure or error-free, prevent all fraud or misuse, produce accurate or complete results in every case, or remain compatible with every device, system, legal regime or third-party service.

24.2 Where you are a consumer. Clause 24.1 does not apply to you. Instead: we will provide the Service with reasonable care and skill; the Service will match any description we have given of it; and you keep every right you have under consumer law that cannot be excluded or limited, which is summarised in Annex 1. Nothing in these Terms affects those rights.

24.3 Third parties. Trustform is not responsible for the decisions, acts or omissions of users, Organisations, Certifiers, Identity Providers, Recipients or other third parties. We do not endorse or guarantee any person, professional, service, document, certification, Credential or transaction merely because it appears in, or is facilitated through, the Service. This clause does not affect what clause 12.4 says we do.

25. Limitation of liability

Read this section with section 24 and, if you are a consumer, with Annex 1.

25.1 What is never limited. Nothing in these Terms limits or excludes liability for fraud or fraudulent misrepresentation, death or personal injury caused by negligence, wilful misconduct, or any other liability that cannot lawfully be limited or excluded.

25.2 If you are a consumer. Clauses 25.3 to 25.5 do not apply to you. We are responsible for loss or damage you suffer that is a foreseeable result of our breach of these Terms or our failure to use reasonable care and skill. We are not responsible for loss or damage that was not foreseeable or that you could reasonably have avoided. Nothing in these Terms affects your statutory rights as a consumer. Annex 1 sets out the position in more detail and prevails over this section.

25.3 If you use the Service for business or professional purposes. Subject to clause 25.1 and to the maximum extent permitted by law, we will not be liable under these Terms for any loss of profit, revenue, business, contracts, anticipated savings, goodwill, reputation or business opportunity, or for any indirect or consequential loss.

25.4 Self-service business users. If you purchase or use the Service for business or professional purposes other than through an Organisation that has entered into an Enterprise SaaS Agreement or other negotiated written agreement with Trustform, our total aggregate liability to you arising out of or in connection with these Terms will not exceed the greater of the fees paid by you to Trustform in the 12 months before the event giving rise to the claim and EUR 10,000, except for liability that cannot lawfully be limited.

Interim soft-launch position: the self-service business-user cap in clause 25.4 is retained as a temporary launch position and must be confirmed against Trustform's cyber/professional indemnity insurance and intended self-service pricing before broader public release.

25.5 Enterprise authorised users. If you access the Service as an Authorised User of an Organisation that has entered into an Enterprise SaaS Agreement or other negotiated written agreement with Trustform, that agreement governs Trustform's liability to the Organisation in connection with the enterprise service and workspace. These Terms do not give you personally any additional right to recover losses suffered by the Organisation, and do not make you personally responsible for the Organisation's payment or other commercial obligations.

25.6 Data protection rights. Nothing in these Terms limits your rights as a data subject or any liability to a data subject that cannot lawfully be limited under applicable data protection law.

26. Indemnity

26.1 This section applies only where you use the Service for business or professional purposes. It does not apply to you if you are a consumer.

26.2 To the extent permitted by law, you will indemnify, defend and hold harmless Trustform, its Affiliates and their respective officers, employees and agents against third-party claims, losses, liabilities, damages, penalties, costs and reasonable legal fees arising from: Wallet Content you submit or confirm; your breach of these Terms or Annex 3; your unlawful or unauthorised use of the Service; your infringement of another person's rights; your breach of clause 14 in relation to information about another individual; a representation you make to a third party in breach of clause 10.6; and, if you are an Organisation, the acts and omissions of your Authorised Users, personnel and representatives.

26.3 We will give you reasonable notice of a claim and let you control the defence and settlement, provided you may not settle in a way that admits liability by Trustform, imposes an obligation on Trustform, or fails to provide an unconditional release, without our prior written consent. We may participate with our own counsel at our own expense.

26.4 The indemnity survives termination.

27. Compliance, sanctions and export controls

27.1 You must comply with all laws applicable to your use of the Service, including data protection, professional, anti-fraud, anti-money laundering, sanctions, export-control and consumer-protection laws.

27.2 You represent that you are not subject to sanctions and are not located in a territory where providing the Service would be prohibited, and you must not use the Service for the benefit of a prohibited person or in connection with a prohibited transaction.

27.3 We may conduct screening, request information, restrict functionality or refuse service where reasonably necessary to comply with a legal or financial-crime obligation or a requirement of our service providers.

28. Changes to these Terms

28.1 When we may change them. We may amend these Terms, and the documents incorporated into them, for a valid reason — namely: a change to the Service or the features we offer; a change to law, regulation, a regulator's requirement or a court decision; a change required for security, fraud prevention or the integrity of the Service; a change in a third-party requirement, including an app-store rule or an Identity Provider's terms; a change to our costs of providing a paid feature; or to correct an error or ambiguity.

28.2 Notice. We will give you not less than 30 days' advance notice of a change that is material, by email to the address associated with your Account and in the Service. The notice will say what is changing, why, and when it takes effect. We may act on shorter notice only where a change is required urgently for legal, regulatory or security reasons, or where the change is wholly to your benefit.

28.3 Your right to walk away. If you do not accept a material change, you may terminate these Terms and close your Account at any time before it takes effect, and for 30 days afterwards, without penalty, charge or notice period. On terminating for that reason you may export your Wallet Content under clause 6.7, and where you have paid for a period extending beyond termination we will refund the unused portion on a pro-rata basis.

28.4 Express consent for significant changes. Where a change significantly alters the balance of these Terms — in particular a change that expands the purposes for which we process Wallet Content, reduces the protection in clause 6.3, reduces our liability, or introduces a charge for something previously included in your plan — we will ask for your express consent and will not apply it to you without it. If you do not consent, clause 28.3 applies and we may, on notice, restrict the affected feature rather than your Account as a whole.

28.5 Continued use. For a change that is neither material nor significant — such as a correction, a clarification, or a change to Annex 3 within clause 16.2 — your continued use of the Service after the change takes effect indicates your acceptance of it. Continued use is never treated as acceptance of a change falling under clause 28.2 or 28.4.

28.6 Consumers. Where you are a consumer, this section is subject to Annex 1, and nothing in it permits a change that a consumer-protection law would treat as unfair.

29. Governing law and disputes

29.1 Talk to us first. Before starting formal proceedings, each of us will make reasonable efforts to resolve the dispute by contacting the other, describing the issue and the remedy sought. Our complaints route is in clause 30.10 and, for consumers, in Annex 1.

29.2 Governing law. These Terms, and any non-contractual obligation arising out of or in connection with them, are governed by the law stated for your country in Schedule B. Where you are a consumer, this does not deprive you of the protection of the mandatory law of your country of residence.

29.3 Jurisdiction — business and professional users. Where you use the Service for business or professional purposes, the courts stated for your country in Schedule B have exclusive jurisdiction over any dispute arising out of or in connection with these Terms.

29.4 Jurisdiction — consumers. Where you are a consumer:

(a) you may bring proceedings against us in the courts of your country of residence, or in the courts stated for your country in Schedule B; and

(b) we may bring proceedings against you only in the courts of your country of residence.

29.5 Alternative dispute resolution. Annex 1 and Schedule B set out the alternative dispute resolution and complaint-handling routes available to you.

30. General provisions

30.1 Notices. We may give notice through the Service, by email to the address associated with your Account, or by another reasonable electronic means. Where a notice is material — a change under section 28, a suspension or termination, or a withdrawal of the Free Tier — we will use email as well as in-Service notice. You must keep your contact details current, and a notice sent to the details associated with your Account is treated as properly delivered unless law requires otherwise. Notices to Trustform must be sent to the address in Schedule B for the entity you contract with, copied to legal@trustform.io.

30.2 Assignment. You may not assign or transfer these Terms or an Account without our prior written consent. We may assign these Terms to an Affiliate, or in connection with a merger, reorganisation, financing, sale of assets or transfer of the relevant business, provided the assignment does not reduce your rights under these Terms or your mandatory consumer rights, and we will notify you.

30.3 No partnership or agency. These Terms do not create a partnership, joint venture, employment, fiduciary or agency relationship between you and Trustform, except as clause 12.10 states in relation to the collection of Certifier fees. No user, Certifier, Identity Provider or Recipient may bind Trustform unless expressly authorised in writing.

30.4 Third-party rights. Except for an app-store provider identified in Annex 2 and Trustform Affiliates entitled to rely on protections in these Terms, a person who is not a party has no right to enforce them.

30.5 Force majeure. Neither party is liable for delay or failure caused by an event beyond its reasonable control, excluding payment obligations. This clause does not reduce a consumer's statutory remedies.

30.6 Severability. If a provision is held unlawful or unenforceable, it will be enforced to the maximum extent permitted and the remainder of these Terms will continue in effect.

30.7 Waiver. A failure or delay in enforcing a right is not a waiver. A waiver is effective only in writing and only for the circumstances stated.

30.8 Entire agreement. These Terms, together with the documents listed in clause 1.8, constitute the entire agreement between us concerning the Service and supersede prior discussions and agreements on that subject. This clause does not exclude liability for fraudulent misrepresentation, does not affect a consumer's rights in respect of a pre-contractual statement, and does not exclude a statement we have made about the Service on which you were entitled to rely.

30.9 Language. These Terms may be translated. Unless prohibited by law, the English version prevails in the event of inconsistency. Where you are a consumer and we have provided a translation in the language in which we marketed the Service to you, that version prevails for you.

30.10 Contact and complaints. Questions about these Terms may be sent to legal@trustform.io or to the postal address in Schedule B. Support requests should be submitted through the in-app Help & Support channel or support@trustform.io. A complaint may be submitted to complaints@trustform.io; we will acknowledge it within 5 business days and aim to respond substantively within 30 days. Consumers have the additional routes in Annex 1.

30.11 Our data protection officer may be contacted at dpo@trustform.io. Any representative required under Article 27 of the UK GDPR or EU GDPR will be identified in Schedule B or the Privacy Notice before the relevant territorial offering is enabled.

SCHEDULE A — BUSINESS ACCOUNTS

This Schedule applies where a Wallet is held by or for an Organisation. It adds to the Core Terms and, where it conflicts with them, prevails over them (clause 1.7).

A1. Authority to accept

A1.1 The individual who accepts these Terms for an Organisation represents and warrants that they are authorised to bind it, and that they will remain authorised or will ensure that another authorised individual assumes the role of administrator.

A1.2 Trustform is entitled to rely on that representation. If it proves to be untrue, the individual who made it is personally responsible to Trustform for loss caused by the reliance, to the extent permitted by law.

A1.3 Where an Organisation subsequently confirms, ratifies or takes the benefit of the Account, it is bound by these Terms from the date they were accepted.

A2. Seats, roles and administrators

A2.1 The Organisation must designate at least one administrator, and should designate at least two. An administrator may invite and remove Authorised Users, assign roles, configure permissions, approve requests, manage integrations, access records and change other material settings.

A2.2 The Organisation is responsible for selecting appropriate administrators, for reviewing their access at reasonable intervals, and for promptly removing or changing access when an individual changes role or ceases to be authorised.

A2.3 Where a paid plan limits the number of seats or Authorised Users, the Organisation must not exceed it or share credentials between individuals. Each Authorised User must have their own credentials.

A2.4 Loss of administrator access. Where an Organisation loses access to every administrator account, we may restore access to a person who satisfies our verification requirements and demonstrates authority to act for the Organisation. We may decline where we are not reasonably satisfied, and we are not liable for declining in that case.

A3. Reliance on instructions

A3.1 Trustform may rely on an instruction given through a Business Wallet by a person using valid credentials and holding the permissions shown in the Service, unless we have actual knowledge that the instruction is unauthorised or law requires us to investigate further.

A3.2 The Organisation is responsible for the acts and omissions of its Authorised Users in relation to the Business Wallet, for maintaining appropriate internal governance and approval processes, and for the consequences of a permission it has configured.

A4. Delegation and representative access

A4.1 The Organisation may permit a professional adviser, corporate service provider or other representative to access its Business Wallet. The Organisation remains responsible for that access and for what the representative does with it.

A4.2 Where a representative holds Wallets for several clients, it must not merge or cross-use their content, and must have the authority of each client for what it does.

A5. Accuracy of entity and ownership data

A5.1 The Organisation is responsible for the accuracy and completeness of its entity, ownership, control and appointment data, and for keeping it current under clause 7.2. Clause 10 applies in full, and the Organisation acknowledges clause 10.4 and clause 10.6 in particular.

A5.2 Confirmation of a Key Person list by an administrator or Authorised User is the Organisation's own representation, and is recorded against the Structure Version in force at the time.

A6. Authority to share, and information about individuals

A6.1 The Organisation warrants that it has authority, and the necessary lawful basis, to submit and to share personal data of its officers, employees, shareholders, beneficial owners, representatives and their family members, and that it has given those individuals the information required under clause 14.2.

A6.2 Clause 14 applies to the Organisation in full, and the Organisation may not rely on the fact that data sits in its Business Wallet as establishing authority to disclose it.

A7. Authorised Users' position

A7.1 An Authorised User acknowledges that the Organisation controls the Business Wallet, may access information and activity associated with the Authorised User's use of it, and may remove or restrict access. Information in a Business Wallet may remain under the Organisation's control after an Authorised User leaves.

A7.2 Where an individual Wallet is linked to a Business Wallet, the individual may provide or refresh selected information from their individual Wallet. The individual retains control of future disclosures from their individual Wallet, but information the Organisation has already lawfully received remains subject to the Organisation's own legal duties and retention periods.

A7.3 An Authorised User acting outside the Business Wallet, in their own individual Wallet, does so under the Core Terms as a user in their own right.

A8. Lawful use of a Business Wallet

A8.1 The Organisation must not use a Business Wallet to centralise, retain or disclose personal data in a way that is unlawful, excessive or inconsistent with the notices it has given to the relevant individuals. Trustform does not determine the Organisation's lawful basis, retention obligations or internal authorisation rules.

A9. Liability, indemnity and consumer rights

9.1 The Organisation uses the Service for business purposes. Accordingly clause 24.1, clause 25.3 and section 26 apply to it, and Annex 1 (Consumer Rights) does not apply to an Organisation or to an Authorised User acting on its behalf. Clause 25.4 applies only where the Organisation is using the Service on a self-service basis and has not entered into an Enterprise SaaS Agreement or other negotiated written agreement with Trustform.

A9.2 Nothing in this Schedule affects the rights of an individual who is a consumer in relation to their own individual Wallet.

A9.3 Where the Organisation has entered into an Enterprise SaaS Agreement or other negotiated written agreement with Trustform covering the Service, the liability regime in that agreement governs Trustform's liability to the Organisation and prevails over section 25 to the extent of any inconsistency (clause 1.7).

SCHEDULE B — COUNTRY SCHEDULE

Interim soft-launch territorial position. Self-service consumer availability should be enabled only for the territories expressly approved below. Enterprise users may be invited under a signed enterprise agreement subject to its territorial and regulatory terms. Any expansion of self-service consumer availability requires a country-law and language review before launch.

Part 1 — Trustform UK Ltd

Contracting entity: Trustform UK Ltd, company number 16485941, registered office Fourth Floor, 11 Berkeley Street, London, England, W1J 8DS. Applies to users located in the United Kingdom and, for business/professional use only, other countries not allocated to Trustform EU where the Service is lawfully offered. Governing law: England and Wales. Courts: England and Wales, subject to clause 29.4 for consumers. Notices: legal@trustform.io and the registered office above. EU representative: not required for the current UK consumer soft-launch scope; this must be reassessed before Trustform UK directly offers the Service to EEA consumers.

Part 2 — Trustform EU

Contracting entity: Truvity B.V., Dutch Chamber of Commerce number 64246728, registered address Nieuwezijds Voorburgwal 162, 1012 SJ Amsterdam, the Netherlands. Interim allocation: EEA business/professional users where Trustform expressly enables access or where access is provided under an enterprise arrangement. Governing law: the Netherlands, without prejudice to clause 29.2 for consumers. Courts: Amsterdam, the Netherlands, subject to clause 29.4 for consumers. Notices: legal@trustform.io and the registered address above. Self-service consumer access through Trustform EU is not enabled for this interim soft launch. The lead-supervisory-authority and Article 27 analysis must be completed before any consumer offering through Trustform EU or any UK-facing offering by Trustform EU is enabled.

Part 3 — Rest of world

Contracting entity: Trustform UK Ltd unless Trustform expressly identifies another entity before acceptance. Governing law and courts: as Part 1 for business/professional users, subject always to mandatory local law. Self-service consumer access outside the United Kingdom is not approved for the interim soft launch unless a country entry below expressly says otherwise.

Part 4 — Country-specific variations

For each country in which the Service is offered, this Part states: the contracting entity; governing law; courts; the consumer-protection variations that apply; the alternative dispute resolution or ombudsman body available to consumers; the local-language requirements, if any; and any local restriction on the Service.


United Kingdom

Entity

Trustform UK Ltd

Governing law

England and Wales

Courts

England and Wales

Consumer variations

Consumer Rights Act 2015; Consumer Contracts (Information, Cancellation and Additional Charges) Regulations 2013; Digital Markets, Competition and Consumers Act 2024 provisions in force from time to time

ADR body

No voluntary ADR scheme currently designated; mandatory ADR rights, if any, remain unaffected

Notes

Approved self-service consumer soft-launch territory


Netherlands / EEA

Entity

Truvity B.V.

Governing law

Netherlands

Courts

Amsterdam, subject to consumer mandatory forum rights

Consumer variations

Mandatory consumer law of the user’s country of residence applies where the user is a consumer

ADR body

Any ADR entity that Trustform is legally obliged or agrees to use will be identified in the complaint response and/or pre-contract information

Notes

INTERIM: business/professional or enterprise-invite access only unless country consumer rollout is separately approved


Other EEA states

Entity

Truvity B.V.

Governing law

Netherlands

Courts

Amsterdam, subject to consumer mandatory forum rights

Consumer variations

Local mandatory consumer law applies

ADR body

As required by local law

Notes

INTERIM: no self-service consumer launch; enterprise/business access only


Rest of world

Entity

Trustform UK Ltd

CGoverning law

England and Wales

Courts

England and Wales for business/professional users

Consumer variations

Mandatory local consumer law, if applicable, cannot be excluded

ADR body

As required by local law

Notes

INTERIM: business/professional access only unless country rollout is approved


Standing entries for all EEA countries: Directive 2011/83/EU (Consumer Rights) as implemented locally; Directive 93/13/EEC (Unfair Terms) as implemented locally; Directive (EU) 2019/770 (Digital Content and Services) as implemented locally; Regulation (EU) 2017/2394; and the local ADR body notified under Directive 2013/11/EU.

ANNEX 1 — CONSUMER RIGHTS

This Annex applies to you if you are a consumer — that is, an individual using the Service wholly or mainly outside your trade, business, craft or profession. It prevails over anything in the Core Terms that conflicts with it (clause 1.7). If you use the Service for your business, or on behalf of an Organisation, this Annex does not apply to you.

Nothing in these Terms affects the rights you have under the consumer law of your country of residence. Where the law of your country gives you more than this Annex does, that law applies.

Who you are contracting with

The Trustform entity identified for your country in Schedule B, with its registered address, company number and registered office as stated there

What we provide

The Trustform Wallet, as described in section 4 of the Core Terms — a digital wallet in which you build and hold a record of your identity and, where relevant, of an organisation, together with documents and certified credentials, and from which you may share selected information with others

How it is provided

As digital content and a digital service, online and through our mobile applications, for as long as your Account is open

What it costs

The core Wallet is currently free. Where a feature carries a fee, the total price including taxes, and any delivery or transaction charge, is shown to you before you commit to pay. There are no hidden charges

Duration and how to end it

Open-ended, with no minimum term for the Free Tier. You may close your Account at any time, in the Service or in the app (Annex 2), or by writing to us. Where you buy a subscription, its duration and renewal terms are shown before purchase

What you need to use it

An internet connection and a currently supported browser or mobile device and operating system. Current compatibility and interoperability information is provided in the Service, app-store listing or Help Centre before installation or where a material requirement changes.

Complaints

complaints@trustform.io — see paragraph 6

How to contact us

legal@trustform.io, support@trustform.io, the in-app Help & Support channel, and the postal address in Schedule B

2. Your 14-day right to change your mind

2.1 Where you buy a paid feature, plan or certification from us, you have 14 days from the day the contract is concluded to withdraw from it, without giving a reason and without penalty.

2.2 How to withdraw. Tell us using the in-Service cancellation or account-closure control, the in-app Help & Support channel, or any clear statement sent to support@trustform.io or legal@trustform.io. You may use the model withdrawal form at the end of this Annex but you do not have to.

2.3 Your refund. We will refund everything you have paid, using the same payment method, within 14 days of being told, subject to paragraph 2.5.

2.4 If you want us to start immediately. Where you ask us to start providing a paid service before the 14 days are up, we will ask you to confirm two things at the point of purchase: that you want us to begin immediately, and that you understand you will lose your right to withdraw once the service has been fully performed. We will not begin before you confirm.

2.5 What happens if we have started. Where you asked us to begin immediately and then withdraw:

(a) if the service has been fully performed with your prior express consent and your acknowledgement that you would lose the right to withdraw, the right is lost; and

(b) if it has been partly performed, you may still withdraw, and you pay an amount proportionate to what was supplied before you told us, calculated against the total contract price.

2.6 Certifications. A certification is fully performed when the Credential is issued. If you withdraw before the Certifier begins work you will be refunded in full. If you withdraw after the Certifier has begun but before the Credential is issued, paragraph 2.5(b) applies. Once a Credential has been issued, the right to withdraw is lost — and clause 11.2 of the Core Terms explains why a Credential cannot be recalled. We will tell you this before you pay.

2.7 Clause 18.4 of the Core Terms (fees non-refundable once a period has begun) does not apply to you until this right has expired or been lost.

3. Your rights if something goes wrong

3.1 We must supply the Service with reasonable care and skill, as described, and fit for the purpose you made known to us. Where we supply digital content or a digital service, it must be of satisfactory quality, fit for purpose and as described, and it must continue to conform for as long as we supply it.

3.2 If the Service does not conform, you may require us to bring it into conformity, and if we cannot or do not do so within a reasonable time and without significant inconvenience to you, you may claim a price reduction or, where the failure is not minor, end the contract and claim a refund.

3.3 You may also claim compensation for loss you suffer as a foreseeable result of our breaking these Terms or failing to use reasonable care and skill. We are not liable for loss that was not foreseeable, or that you could reasonably have avoided.

3.4 The self-service business cap in clause 25.4 of the Core Terms does not apply to you. Neither does the exclusion in clause 25.3. Nothing in these Terms limits our liability to you below the level required by law, and nothing limits our liability for death or personal injury caused by negligence, fraud, or any other matter that cannot lawfully be limited.

3.5 The indemnity in section 26 does not apply to you.

3.6 The "as is" disclaimer in clause 24.1 does not apply to you.

4. Changes to these Terms and to the Service

4.1 We will give you at least 30 days' notice of a material change to these Terms, by email and in the Service, saying what is changing and why (clause 28.2).

4.2 If you do not accept it, you may end this contract without penalty at any time before it takes effect and for 30 days afterwards, export everything you hold, and receive a pro-rata refund of anything you have paid for a period after termination (clause 28.3).

4.3 We will not treat your continued use of the Service as acceptance of a material or significant change (clause 28.5).

4.4 Where a change significantly alters the balance of these Terms, we will ask for your express consent and will not apply it to you without it (clause 28.4).

4.5 Where we change the Service itself in a way that materially and adversely affects your use of it, and the change is not required by law or security, you may end the contract and receive a pro-rata refund of anything you have paid for the period after termination. Where we withdraw the Free Tier, clause 17.3 gives you 60 days' notice and clause 17.4 gives you 90 days to export what you hold.

5. Your data

5.1 Nothing in these Terms limits your rights under data protection law, including your rights of access, rectification, erasure, restriction, objection and portability. The Privacy Notice explains how to exercise them, and clause 11.4 of the Core Terms explains how erasure works where a Credential has been issued.

5.2 Your right to export your Wallet Content under clause 6.7 is in addition to your right of data portability, and covers data that is not personal data.

5.3 Biometric processing in electronic identity verification requires your explicit consent, given separately at the point of verification and never bundled into your acceptance of these Terms (clause 8.3). You may withdraw it at any time.

6. Complaints and alternative dispute resolution

6.1 Complain to us first. Write to complaints@trustform.io. We will acknowledge within 5 business days and aim to give you a substantive response within 30 days. If we cannot resolve it in that time we will tell you why and when we expect to.

6.2 Alternative dispute resolution. If applicable law requires Trustform to participate in an alternative dispute resolution scheme, or if Trustform agrees to do so for a particular dispute, we will give you the name and contact details of the relevant approved body and explain whether its decision is binding. We do not commit to a voluntary ADR scheme unless we expressly identify one to you before or during the complaint process.

6.3 EEA consumer redress information. The former EU Online Dispute Resolution platform was discontinued on 20 July 2025. If you are resident in the EEA, information about recognised consumer dispute-resolution bodies is available through the European Commission's Consumer Redress resources. This clause does not create an obligation on Trustform to participate in a scheme where applicable law does not require it.

6.4 Courts. You may bring proceedings in the courts of your country of residence, and we may bring proceedings against you only there (clause 29.4). ADR is optional and does not affect your right to go to court.

6.5 Regulators. You may complain to the consumer-protection authority in your country, and to your data protection authority about how we handle your personal data. Contact details are in Schedule B and in the Privacy Notice.

7. Model withdrawal form

To: Trustform UK Ltd, Fourth Floor, 11 Berkeley Street, London, England, W1J 8DS; legal@trustform.io (or the EEA contracting entity identified in Schedule B, where applicable)

I hereby give notice that I withdraw from my contract for the following service: ______________

Ordered on / received on: ______________ Name: ______________ Address: ______________ Signature (only if sent on paper): ______________ Date: ______________

ANNEX 2 — APP STORE TERMS

This Annex applies where you obtain a Trustform Wallet application from an app store. It adds to section 19 of the Core Terms.

Part 1 — Apple App Store

Where you obtain the application from the Apple App Store, the following applies and, in the event of conflict with the Core Terms as regards the application, prevails.

1.1 The agreement is with us, not Apple. These Terms are between you and Trustform only, not Apple Inc. or its subsidiaries ("Apple"). Trustform, not Apple, is solely responsible for the application and its content.

1.2 Scope of licence. The licence granted in clause 19.1 is a non-transferable licence to use the application on any Apple-branded product that you own or control, as permitted by the Usage Rules in the Apple Media Services Terms and Conditions, except that the application may be accessed by other accounts associated with you via Family Sharing or volume purchasing.

1.3 Maintenance and support. Trustform is solely responsible for maintenance and support of the application. Apple has no obligation to provide any maintenance or support.

1.4 Warranty. In the event of a failure of the application to conform to any applicable warranty, you may notify Apple, and Apple will refund the purchase price (if any) to you. To the maximum extent permitted by law, Apple has no other warranty obligation with respect to the application. Any other claim, loss, liability, damage, cost or expense attributable to a failure to conform to a warranty is Trustform's sole responsibility.

1.5 Product claims. Trustform, not Apple, is responsible for addressing any claim by you or a third party relating to the application or your possession or use of it, including product liability claims, claims that the application fails to conform to a legal or regulatory requirement, and claims under consumer protection, privacy or similar legislation, including in connection with the application's use of the HealthKit or HomeKit frameworks if applicable.

1.6 Intellectual property claims. In the event of a third-party claim that the application or your possession and use of it infringes that third party's intellectual property rights, Trustform, not Apple, is solely responsible for the investigation, defence, settlement and discharge of that claim.

1.7 Legal compliance. You represent and warrant that you are not located in a country subject to a U.S. Government embargo or designated as a "terrorist supporting" country, and that you are not listed on any U.S. Government list of prohibited or restricted parties.

1.8 Developer contact. Questions, complaints and claims about the application should be directed to Trustform through the in-app Help & Support channel, support@trustform.io or legal@trustform.io, and to the postal address in Schedule B.

1.9 Third-party terms. You must comply with applicable third-party terms of agreement when using the application.

1.10 Apple as third-party beneficiary. Apple and its subsidiaries are third-party beneficiaries of this Part 1, and have the right — and are deemed to have accepted the right — to enforce it against you as a third-party beneficiary.

1.11 Partner Sign-In. If the application displays a branded Partner Sign-In option, including "Log in with Investors Europe", that option is an authentication method for the Trustform Wallet. Trustform, not the partner, provides and is responsible for the application and Wallet Service. The Partner Sign-In option is not a mechanism for purchasing or subscribing to third-party digital content or services through the application.

Part 2 — Google Play

2.1 Where you obtain the application from Google Play, your use is additionally subject to the Google Play Terms of Service. Google is not a party to these Terms and is not responsible for the application.

2.2 Trustform, not Google, is responsible for the application, for support and maintenance, and for any claim relating to it.

2.3 Refunds for purchases made through Google Play are handled in accordance with Google Play's policies, without prejudice to your rights under Annex 1.

Part 3 — Account deletion from within the application

3.1 You may delete your Account from within the mobile application, without contacting us and without leaving the application. For the interim release, the intended route is Settings > Account > Delete account. If the production navigation differs, use the deletion control shown in the application; Trustform must update this wording to the production path before broader public release.

3.2 Deletion from within the application initiates closure of your Account and deletion of your Wallet Content, subject to clause 23.4 and to the retention periods in the Privacy Notice. Before you confirm, the application will tell you what will be deleted, what will be retained and why, and will offer you the export in clause 6.7.

3.3 Where your Account is an Authorised User account on a Business Wallet, deletion removes your access and your individual Wallet. It does not delete the Organisation's Business Wallet or the content the Organisation controls (clause A7.1).

3.4 Clause 11.5 governs Credentials already issued to and held by Recipients. Deleting your Account does not withdraw them.

ANNEX 3 — ACCEPTABLE USE POLICY

This Annex forms part of these Terms. Clause 16.2 governs how it may be updated.

1. Documents, identity and credentials

You must not:

1.1 submit, confirm or share information or a document that is false, forged, altered, fabricated, stolen or unlawfully obtained;

1.2 impersonate another person or Organisation, or misrepresent your identity, authority, role, qualifications, licence or status;

1.3 create an Account in another person's name, or an Account for an Organisation without authority;

1.4 seek certification of a document you know or suspect to be false, altered or unlawfully held, or for an unlawful, fraudulent or deceptive purpose;

1.5 misrepresent the provenance, scope, status or legal effect of a Credential, or present a revoked or superseded Credential as current;

1.6 represent that Trustform has certified, verified, determined or approved anything it has not — including that Trustform has determined beneficial ownership or performed a compliance assessment (clause 10.6);

1.7 represent that a Credential or digital stamp is a qualified electronic signature or qualified electronic seal, or that Trustform is a qualified trust service provider (clause 5.6);

1.8 use, copy, present or share another person's Credential or decentralised identifier as your own, or interfere with a decentralised identifier or key material.

2. Financial crime and unlawful conduct

You must not use the Service to facilitate fraud, money laundering, terrorist financing, sanctions evasion, identity theft, tax evasion, bribery, human trafficking, harassment or any other unlawful conduct; to conceal beneficial ownership or control from a person entitled to know it; or in breach of any sanctions, export-control or anti-money-laundering law.

3. Other people's data

You must not submit, retain or share personal data about another individual without the rights, authority and lawful basis required by clause 14; use the Service to build a dossier on an individual for a purpose unrelated to a legitimate identity, onboarding, compliance or corporate purpose; or use special-category or criminal-offence data outside a feature intended for it (clause 21.4).

4. Security and integrity

You must not:

4.1 access or attempt to access data, an Account or functionality without authority;

4.2 probe, scan or test the vulnerability of the Service, or breach or circumvent a security or authentication measure, except under a written authorisation from us or in accordance with a published vulnerability disclosure policy;

4.3 introduce malware or other harmful code;

4.4 interfere with the integrity, availability or performance of the Service, or place an unreasonable load on it, including through automated means;

4.5 scrape, harvest, index or extract data other than through functionality we provide for that purpose;

4.6 reverse engineer, decompile or disassemble the Service, or attempt to derive its source code, except to the extent that restriction is prohibited by law;

4.7 circumvent a usage limit, seat limit, access restriction or paywall;

4.8 resell, sublicense or make the Service available to a third party except under an agreement with us that permits it.

5. Artificial intelligence

You must not use Wallet Content to train or improve an artificial intelligence model without every right and permission required by law and any condition imposed by the person whose content it is. Clause 6.3 states what Trustform does and does not do.

6. Enforcement

6.1 Where we identify or reasonably suspect a breach, we may take one or more of the following steps, proportionate to the breach and to the risk: ask you for an explanation; issue a warning; restrict or suspend the affected feature; restrict or suspend the Account; remove or restrict access to specific Wallet Content; revoke a share; terminate the Account under clause 23.2; and report the matter to a law enforcement agency, regulator, professional body or affected third party where we are required or permitted to do so.

6.2 We will normally begin with the least severe step that addresses the risk, and will tell you what we have done and why, unless we are prevented from doing so by law or by a financial-crime obligation. Where the breach is remediable we will normally give you the opportunity to remedy it. We may act immediately, and without notice, where there is a risk of harm to another person, to the integrity of the Service or of evidence, or where law requires it.

6.3 Where we suspend or restrict your access and you consider we have got it wrong, you may ask us to review the decision at complaints@trustform.io, and a person not involved in the original decision will review it.

CONFIRMATION REGISTER — ORANGE ITEMS

The following points are intentionally highlighted because they depend on Trustform facts, technical architecture, insurance, tax treatment or launch configuration. They do not prevent the controlled UK soft launch where the relevant feature is disabled or operated as stated below.

C-1 — EEA contracting / privacy role
Truvity B.V. details are populated. For this interim release, no self-service EEA consumer launch is approved. Confirm the lead-supervisory-authority and any Article 27 representative analysis before enabling a consumer offering through Trustform EU or a UK-facing offering by Trustform EU.

C-2 — Credential erasure architecture
Confirm that the architecture described in clause 11.4 is accurate: personal-data payloads can be deleted and the immutable record is only a cryptographic representation that does not itself reveal the underlying personal data. If not confirmed, do not enable credential issuance in the soft launch.

C-3 — AI use
Confirm clause 6.3 matches production and vendor contracts, including no general-purpose model training on Wallet Content and no provider training/retention for its own purposes.

C-4 — Biometric verification
Confirm the identity-verification flow obtains separate explicit biometric consent and offers the non-biometric document-upload route described in clause 8.3. If not, disable biometric verification until aligned.

C-5 — Certification commercial model
Confirm clause 12.10: the Certifier supplies the professional service and Trustform collects as disclosed collection agent unless checkout says otherwise. Obtain tax/VAT confirmation before paid certification is enabled.

C-6 — Certifier governance
Confirm all checks stated in clause 12.4 are performed before certification is enabled and insert the actual re-verification cadence in the Verification Page / certifier materials.

C-7 — Verification Page
Confirm whether the production Verification Page uses affirmative acceptance. Clause 13.5 now accommodates either model; the interface and notice must match it.

C-8 — Liability and insurance
Confirm the self-service business-user cap in clause 25.4 against current cyber/professional indemnity insurance and intended self-service pricing. Enterprise customer liability is deliberately left to the applicable Enterprise SaaS Agreement and is not duplicated in these end-user Terms.

C-9 — Privacy / retention
Publish the Wallet Privacy Notice before onboarding live users. Confirm its retention schedule, sub-processors, controller/processor handoff and identity-document/eIDV retention periods match production.

C-10 — Operational contacts and deletion path
Confirm legal@trustform.io, support@trustform.io, complaints@trustform.io and dpo@trustform.io are live and monitored, and confirm the production in-app deletion path. The current intended path is Settings > Account > Delete account.