Terms of Use
These Terms govern the public website, mobile application, administration tools, APIs, integrations, documentation, trials, and related MYID services.
Contents
- Agreement and precedence
- Definitions
- Access and license
- Required testing and approval
- Customer responsibilities
- Identity action risks
- Connected systems
- Automation and security decisions
- Acceptable use
- Data and privacy
- Availability and support
- Fees
- Ownership
- Confidentiality
- Warranty disclaimer
- Liability limit
- Indemnity
- Suspension and termination
- Disputes
- General terms
1. Agreement and precedence
These Terms form an agreement between Software Productivity Strategists, Inc., doing business through the MYID Self Verify product, and the person or entity using the Services. By accessing or using the Services, you represent that you have authority to bind the applicable organization and accept these Terms.
A signed master agreement, order, statement of work, service level agreement, data processing agreement, or other written contract controls to the extent it expressly conflicts with these public Terms. If no signed agreement applies, these Terms control.
If you do not accept these Terms, do not access or use the Services.
2. Definitions
Company means Software Productivity Strategists, Inc. Company Parties means Company, any parent, subsidiary, affiliate, licensor, supplier, service provider, and each of their owners, directors, officers, employees, contractors, agents, successors, and assigns.
Customer means the organization that purchases, evaluates, configures, authorizes, or makes the Services available. User means an employee, contractor, administrator, tester, or other authorized person. Customer Data means information submitted to or processed through the Services on behalf of a Customer. Services means the MYID website, applications, platform, APIs, administration tools, integrations, documentation, trials, previews, support, and related work.
3. Access and license
Subject to these Terms, the applicable order, and payment of fees, Company grants Customer a limited, revocable, nonexclusive, nontransferable right to use the Services for its internal authorized purposes during the applicable term.
Customer must limit access to authorized Users, protect administrator access, promptly remove access that is no longer required, and use the Services only within the approved tenant, scope, and environment.
4. Required testing and approval
Customer must test before use. Customer must evaluate the Services in a representative test environment before production approval. Customer must test every enabled identity action, provider connection, failure path, timeout, retry, audit event, notification, privacy flow, performance condition, and rollback procedure that is material to its use.
Customer must use approved test accounts and data, document results, correct configuration problems, train support personnel, preserve an independent recovery path, and obtain its own security, privacy, legal, labor, records, risk, and regulatory approvals.
A demonstration, preview, trial, test result, readiness screen, sample report, or successful action does not guarantee the same outcome for another account, provider, network, configuration, load, or time.
5. Customer responsibilities
Customer is responsible for its lawful basis, notices, instructions, user authorization, account lifecycle, identity proofing, data quality, provider licenses, permissions, network paths, secret management, backup, recovery, helpdesk, monitoring, records duties, and production approval.
Customer must enable only capabilities that are fully configured and tested for that tenant. Customer must not treat a cached, pending, unavailable, or degraded provider result as a verified live result. Customer must review logs and provider records before making a material decision when the result is uncertain.
Customer remains responsible for its employees, administrators, connected systems, and any action it authorizes through the Services.
6. Identity action risks
The Services can request password changes, password resets, account unlock, profile changes, MFA enrollment or removal, session action, incident response, notification, or other identity and security operations. These actions can affect access, authentication, investigations, records, and business operations.
Customer authorizes Company to transmit approved requests to connected systems. Customer must provide a separate recovery path and must verify the resulting provider state when an action times out, returns an uncertain result, or depends on eventual consistency.
7. Connected systems
The Services can depend on identity providers, directories, security platforms, endpoint tools, training services, messaging providers, mobile platforms, cloud services, customer networks, and other third party systems. Company does not control their availability, accuracy, permissions, changes, security, response time, pricing, data practices, or continued compatibility.
Company Parties are not responsible for an outage, delay, denial, duplicate action, inconsistent state, data loss, or security event caused by a connected system, Customer configuration, Customer instruction, network path, device, or provider change.
8. Automation and security decisions
Autopilot, recommendations, risk signals, security scores, and automated actions are decision support and workflow tools. They are not a substitute for qualified human judgment, Customer policy, an incident response program, or an independent security control.
Customer chooses the response window, allowed actions, consent behavior, provider permissions, and oversight. Customer must test automation, monitor results, maintain a manual recovery path, and disable a function that behaves unexpectedly.
No automated system detects every threat or avoids every false result. Company does not guarantee that an event will be detected, associated with the correct person, delivered, answered, or remediated.
9. Acceptable use
You must not access data or systems without authorization, interfere with security or audit controls, introduce malicious code, overload the Services, evade rate or access limits, reverse engineer protected portions, use the Services to build a competing product, test security without written permission, violate law, infringe rights, or submit secrets through a public form.
Company may investigate suspected misuse and may restrict access when reasonably necessary to protect people, systems, data, rights, or legal obligations.
10. Data and privacy
Customer retains its rights in Customer Data. Customer grants Company the rights needed to host, process, transmit, secure, support, and delete Customer Data according to the agreement and Customer instructions.
The Privacy Policy, Data Processing Agreement, and Customer contract describe applicable processing. Customer is responsible for providing required notices and instructions to Users.
11. Availability and support
Unless a signed service level agreement states otherwise, no uptime, response time, recovery time, recovery point, support time, performance, retention, compatibility, or remediation commitment applies. Maintenance, provider outages, security action, capacity, and events outside reasonable control can affect access.
Support does not include the Customer helpdesk, identity decision, provider administration, emergency access, or legal advice unless a signed agreement expressly includes it.
12. Fees
Fees, taxes, payment terms, term, renewal, usage limits, and service scope are stated in the applicable order. Except where law or a signed order requires otherwise, paid fees are nonrefundable and Customer may not withhold or offset payment.
13. Ownership
Company and its licensors retain all rights in the Services, software, designs, documentation, methods, configurations, improvements, and related intellectual property. No right is granted except the limited use right stated in these Terms.
Company may use feedback without restriction or payment, provided it does not identify Customer or disclose Customer Confidential Information.
14. Confidentiality
Each party must protect the other party’s nonpublic business, technical, security, and financial information using reasonable care, use it only for the agreement, and disclose it only to people who need it and are bound to protect it. Standard exceptions apply to information lawfully known, independently developed, publicly available without breach, received lawfully from another source, or required by law.
15. Warranty disclaimer
TO THE MAXIMUM EXTENT PERMITTED BY LAW, THE SERVICES ARE PROVIDED AS IS, AS AVAILABLE, AND WITH ALL FAULTS. COMPANY PARTIES DISCLAIM ALL EXPRESS, IMPLIED, STATUTORY, AND OTHER WARRANTIES, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, NONINTERFERENCE, NONINFRINGEMENT, ACCURACY, SECURITY, AVAILABILITY, QUIET ENJOYMENT, AND ANY WARRANTY ARISING FROM COURSE OF DEALING OR USAGE.
COMPANY PARTIES DO NOT WARRANT THAT THE SERVICES WILL BE ERROR FREE, UNINTERRUPTED, SECURE, COMPLETE, CURRENT, COMPATIBLE, OR COMPLIANT; THAT DATA WILL BE PRESERVED; THAT EVERY REQUEST OR RESPONSE WILL BE CAPTURED; OR THAT ANY IDENTITY OR SECURITY ACTION WILL SUCCEED.
Preview, beta, trial, evaluation, test, and unreleased functions can be changed, suspended, or removed at any time and must not be used for production or safety critical decisions unless expressly approved in writing.
16. Liability limit
TO THE MAXIMUM EXTENT PERMITTED BY LAW, COMPANY PARTIES WILL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, PUNITIVE, OR ENHANCED DAMAGES; LOST REVENUE, PROFITS, SAVINGS, GOODWILL, DATA, ACCESS, OR BUSINESS; BUSINESS INTERRUPTION; COST OF SUBSTITUTE SERVICES; SECURITY INCIDENT; IDENTITY ACTION; OR CLAIM BY ANOTHER PERSON, EVEN IF ADVISED OF THE POSSIBILITY.
TO THE MAXIMUM EXTENT PERMITTED BY LAW, COMPANY PARTIES HAVE NO LIABILITY ARISING FROM FREE, PREVIEW, BETA, TRIAL, EVALUATION, UNAPPROVED, OR UNTESTED USE.
IF LIABILITY CANNOT LAWFULLY BE EXCLUDED, THE TOTAL AGGREGATE LIABILITY OF ALL COMPANY PARTIES FOR ALL CLAIMS ARISING FROM OR RELATED TO THE SERVICES WILL NOT EXCEED THE AMOUNT CUSTOMER ACTUALLY PAID COMPANY FOR THE SPECIFIC AFFECTED SERVICE DURING THE THREE MONTHS BEFORE THE EVENT GIVING RISE TO THE FIRST CLAIM. FOR A FREE SERVICE, THE MAXIMUM AGGREGATE AMOUNT IS ONE HUNDRED UNITED STATES DOLLARS.
These limits apply regardless of legal theory and allocate risk between the parties. They do not limit liability that applicable law does not permit the parties to limit. A signed agreement may state a different exclusive limit.
17. Indemnity
Customer will defend, indemnify, and hold harmless the Company Parties from any claim, loss, penalty, damage, judgment, cost, and reasonable legal fee arising from Customer Data, Customer instructions, Customer configuration, Customer or User conduct, connected systems, failure to test, failure to obtain authorization or lawful basis, violation of these Terms, or violation of law or another person’s rights.
18. Suspension and termination
Company may suspend access when reasonably necessary to address nonpayment, misuse, a security threat, legal requirement, provider restriction, or material breach. Either party may terminate as stated in the applicable order or signed agreement.
On termination, access ends and data is handled under the applicable contract, Data Processing Agreement, retention need, and backup cycle. Terms that by their nature should survive will survive, including ownership, confidentiality, disclaimer, liability, indemnity, payment, and dispute terms.
19. Disputes
These Terms are governed by Maryland law without regard to conflict principles. Before filing a claim, the parties will attempt good faith resolution for thirty days after written notice.
Except for a claim eligible for small claims court or a request for urgent equitable relief, a dispute will be resolved by confidential binding arbitration administered by the American Arbitration Association under its applicable commercial rules in Montgomery County, Maryland. Each party waives trial by jury and participation in a class, collective, consolidated, or representative action to the extent permitted by law.
20. General terms
These Terms and applicable signed documents are the entire agreement for their subject. If a provision is unenforceable, it will be enforced to the maximum lawful extent and the remainder continues. Failure to enforce is not a waiver. Customer may not assign without written consent. Company may assign in connection with a reorganization, financing, sale, or transfer of the Services.
Company may update these Terms. Material changes will be posted with a new effective date and notice where required. Continued use after the effective date constitutes acceptance where permitted by law.
Legal notices to Company must be sent to legal@ext.myidselfverify.com and 2400 Research Blvd, Suite 115, Rockville, Maryland 20850.