Master Subscription Agreement (MSA) — postal.ID
Effective date: [DATE] This Master Subscription Agreement ("Agreement") is between [POSTAL.ID LEGAL NAME] ([DIFC ENTITY / LICENSE NO.]), [DIFC REGISTERED ADDRESS] ("postal.ID") and the customer identified in an Order Form ("Customer").
1. Key concept: roles (Controller/Processor)
For Verification Subject Data processed in connection with Customer's use of the verification service:
- Customer is the Controller; and
- postal.ID is the Processor, processing only on Customer's documented instructions.
For postal.ID's own Website/Admin/Billing Data, postal.ID is a Controller (see Privacy Notice — Website & Customer Admin Users).
2. Definitions
- Services: postal.ID platform, portals, APIs, and verification workflows.
- Verification: address verification via postal mail code/QR and optional digital factors (email/SMS OTP), and optional KYC/AML add-ons if enabled.
- Case: a verification request created by Customer.
- Subject: the individual being verified.
- Evidence Pack: generated artifacts and logs for a Case.
- Assurance Level: Digital Verified / Postal Verified / Digital+Postal Verified (defined in Verification Services Terms).
3. Subscription and access
postal.ID grants Customer a non-exclusive, non-transferable right to access and use the Services during the Term, subject to this Agreement, the AUP, and the Order Form.
4. Customer responsibilities
Customer will:
- ensure it has a lawful basis to provide Subject data and initiate verification;
- provide required notices/consents (especially for SMS/email where required);
- configure policies responsibly (assurance levels, expiry, reminders);
- keep credentials secure and use RBAC appropriately.
5. Verification results; no guarantee
postal.ID provides evidence-backed events and artifacts. Customer remains responsible for its onboarding/compliance decisions. postal.ID does not guarantee prevention of fraud or confirm legal residency.
6. Fees and payment
Fees, billing periods, and usage limits are in the Order Form. Taxes are Customer's responsibility unless required by law.
7. Confidentiality
Each party will protect the other's Confidential Information using reasonable care.
8. Data protection
The DPA forms part of this Agreement. Customer instructions are set in the Service configuration, API calls, and documented support tickets.
9. Security
postal.ID will maintain appropriate technical and organizational measures per the Security Addendum.
10. Intellectual property
postal.ID retains all IP in the Services. Customer retains IP in its data.
11. Acceptable use; suspension
postal.ID may suspend access for AUP violations, security threats, suspected fraud, or legal compliance.
12. Term and termination
Term is as stated in the Order Form. Either party may terminate for material breach not cured within [30] days. On termination, data return/deletion occurs per DPA and retention settings.
13. Warranties and disclaimers
Except as expressly stated, Services are provided "as is". postal.ID disclaims implied warranties to the maximum extent permitted by law.
14. Limitation of liability
Liability caps and exclusions apply as specified in the Order Form. Common structure:
- cap = fees paid in the [12] months preceding the claim;
- exclude indirect/consequential damages;
- carve-outs for IP infringement and breach of confidentiality as negotiated.
15. Indemnities
- postal.ID indemnifies Customer for third-party IP infringement claims regarding the Services.
- Customer indemnifies postal.ID for claims arising from Customer data, instructions, or unlawful use.
16. Changes
postal.ID may update Service features. Material changes to legal terms will be notified with reasonable advance notice.
17. Governing law and jurisdiction
This Agreement is governed by DIFC laws and subject to exclusive jurisdiction of the DIFC Courts.
18. Order of precedence
Order Form → DPA/Transfer Addendum → Security Addendum → this Agreement → policies (AUP, etc.).
19. Contact
Legal notices: [LEGAL@POSTAL.ID]