Terms and Conditions
These Terms and Conditions (“Terms”) govern access to and use of the Idvizer.com AI face verification API and associated services (the “API”, “Service”) operated by Idvizer SASU, a company registered in France (“Idvizer”, “we”, “us”, “our”). By executing an Order Form, accessing the API, or integrating the Service into your systems, you (“Client”, “you”) agree to be bound by these Terms on behalf of the legal entity you represent.
The Service is provided exclusively to business clients (B2B). These Terms do not apply to or create any relationship with the individual end-users whose biometric data may be processed through the API. Clients are solely responsible for their obligations towards such individuals as Data Controllers under applicable law.
1. Definitions
“API” means the Idvizer.com RESTful application programming interface through which the Service is delivered, including all endpoints, authentication mechanisms, and associated technical documentation.
“Service” means the AI-powered face verification and identity matching functionality provided by Idvizer via the API on a zero-retention, ephemeral processing basis.
“Client” means the business entity that has entered into an agreement with Idvizer to access the API under these Terms.
“End-User” means any natural person whose biometric data or facial image is submitted to the API by the Client or on the Client's behalf.
“Biometric Data” has the meaning given in Article 4(14) GDPR — personal data resulting from specific technical processing relating to the physical characteristics of a natural person which allows or confirms the unique identification of that person.
“Ephemeral Processing” means the processing of data solely in volatile memory (RAM) for the duration of a single API call, with no writing to disk, no persistent storage, no logging of biometric payload, and automatic purging upon completion of the request.
“Zero-Retention Architecture” means Idvizer's technical and organisational design whereby no biometric data, facial images, or derived templates submitted via the API are stored, retained, or persisted on any Idvizer infrastructure.
“Order Form” means the commercial document executed between Idvizer and the Client specifying the subscribed API tier, rate limits, fees, and any special conditions.
“Documentation” means the technical API reference, integration guides, and compliance materials available at https://docs.idvizer.com.
“High-Risk AI System” has the meaning given in Article 6 and Annex III of the EU AI Act (Regulation (EU) 2024/1689).
2. Nature of the Service
2.1 API-Only Delivery
The Service is delivered exclusively via API. Idvizer does not provide a consumer-facing web application, portal, or interface for End-Users. All integration, user-facing flows, consent mechanisms, and data subject communications are the sole responsibility of the Client.
2.2 Zero-Retention Architecture
Idvizer's infrastructure is designed and operated on a zero-retention basis. When the Client submits a face verification request to the API:
- Facial image data and biometric payload are processed exclusively in volatile memory (RAM);
- No biometric data, images, facial templates, or derived identifiers are written to disk or any persistent storage medium;
- No biometric payload is included in server-side logs or audit records;
- All data in memory is purged automatically and irrecoverably upon completion of the API response;
- Idvizer retains only non-biometric transactional metadata (API call timestamp, Client ID, endpoint called, response code, and latency) strictly for billing and operational monitoring purposes.
The Client acknowledges that this architecture means Idvizer is technically unable to retrieve, replay, or restore any biometric data submitted via the API after the API response has been returned.
2.3 AI Act Classification
The Service constitutes a High-Risk AI System under Annex III(1) of Regulation (EU) 2024/1689 (the “EU AI Act”) as it involves biometric identification of natural persons. Idvizer, as Provider of the AI system, and the Client, as Deployer, each bear distinct and complementary obligations under the AI Act, as set out in Section 14 of these Terms.
3. Eligibility and Account Access
3.1 B2B Only
The Service is available exclusively to legal entities acting in a commercial or professional capacity. Natural persons acting as consumers may not subscribe to or use the API. By accepting these Terms, you represent and warrant that you are duly incorporated, have full authority to bind your organisation, and are not acting as a consumer.
3.2 API Credentials
Idvizer will issue API keys and authentication credentials to the Client upon execution of an Order Form. The Client is solely responsible for:
- Maintaining the confidentiality and security of all API credentials;
- Ensuring that credentials are not shared with unauthorised parties or embedded insecurely in client-side code;
- Immediately notifying Idvizer at security@idvizer.com upon actual or suspected compromise of any credential;
- All API calls made using its credentials, whether authorised or not.
3.3 Permitted Use
API access is granted solely for integration into the Client's own products and services in accordance with the Documentation and the permitted use cases specified in the Order Form. Any use outside the scope of the Order Form requires prior written approval from Idvizer.
4. Client Obligations as Data Controller
4.1 Data Controller Responsibility
The Client is and remains the Data Controller within the meaning of Article 4(7) GDPR for all personal data, including Biometric Data, submitted to the API. The Client is solely responsible for:
- Establishing and documenting a valid legal basis under Article 6 GDPR and, where applicable, an explicit derogation under Article 9(2) GDPR for the processing of Biometric Data;
- Obtaining, recording, and managing the explicit, freely given, specific, informed, and unambiguous consent of each End-User prior to submitting their biometric data to the API, unless another Article 9(2) derogation applies;
- Providing End-Users with a lawful, transparent, and complete privacy notice meeting the requirements of Articles 13 and 14 GDPR before any biometric data is collected;
- Responding to data subject rights requests (access, erasure, portability, objection, restriction) from End-Users within statutory timeframes;
- Conducting and maintaining a Data Protection Impact Assessment (DPIA) as required under Article 35 GDPR prior to deploying any face verification processing;
- Notifying the competent supervisory authority and affected data subjects of any personal data breach in accordance with Articles 33 and 34 GDPR;
- Ensuring that its use of the Service does not violate applicable anti-discrimination law, employment law, or any sector-specific regulation.
4.2 Prohibited Use Cases
The Client must not use the Service for any of the following purposes:
- Real-time remote biometric identification in publicly accessible spaces, as prohibited under Article 5(1)(d) of the EU AI Act (subject to the narrow law enforcement exceptions therein, which do not apply to private operators);
- Emotion recognition or inference of sensitive attributes (race, ethnicity, political opinion, health status) from facial data;
- Social scoring or any system that evaluates or classifies natural persons based on their behaviour or personal characteristics in a manner that causes detrimental treatment;
- Processing of biometric data of persons under the age of 18 without specific legal authority and appropriate safeguards;
- Any purpose that constitutes an unacceptable risk AI practice prohibited under Article 5 of the EU AI Act;
- Any purpose that is unlawful under applicable French, EU, or international law.
5. Data Processing Agreement
To the extent that Idvizer processes any personal data on behalf of the Client in providing the Service, the parties are subject to a Data Processing Agreement (“DPA”) pursuant to Article 28 GDPR. The Idvizer standard DPA is incorporated into these Terms by reference and is available at https://www.idvizer.com/dpa or upon request at legal@idvizer.com.
The DPA governs, among other matters, the subject matter and duration of processing, the categories of data processed, the obligations and rights of the Client as Data Controller, Idvizer's sub-processor arrangements, security measures, and breach notification procedures.
Given Idvizer's Zero-Retention Architecture, the parties acknowledge that the volume and duration of personal data processing by Idvizer is limited to the ephemeral duration of each API call, and that no biometric data persists on Idvizer systems following the return of an API response.
6. Subscription, API Access Tiers, and Fees
6.1 API Tiers
Access to the API is subject to a subscription to one of the available API tiers as set out in the applicable Order Form. Tiers are differentiated by monthly API call volume, rate limits, SLA commitments, and support levels.
6.2 Fees and Payment
Fees are invoiced in Euros (EUR) exclusive of applicable VAT, on a monthly or annual basis as agreed in the Order Form. Payment is due within 30 days of invoice date. Idvizer reserves the right to suspend API access if payment is not received within 15 days of a payment reminder, and to charge statutory late payment interest pursuant to EU Directive 2011/7/EU.
6.3 Usage Overages
Where the Client exceeds the API call volume included in its tier, Idvizer will charge overage fees at the rates specified in the Order Form. Idvizer will endeavour to provide reasonable advance notice of significant overage before invoicing.
6.4 No Refunds
As the Service is a B2B API service delivered to commercial entities, the 14-day consumer right of withdrawal under Directive 2011/83/EU does not apply. Fees paid are non-refundable except in the case of material Service unavailability attributable to Idvizer in excess of the SLA threshold set out in Section 9.
7. Intellectual Property
7.1 Idvizer IP
All intellectual property rights in the API, AI models, algorithms, software, Documentation, and associated technology (“Idvizer IP”) are and remain the exclusive property of Idvizer SASU or its licensors. These Terms grant the Client a limited, non-exclusive, non-transferable, non-sublicensable licence to access and use the API solely for the purposes permitted under the Order Form during the subscription term.
7.2 Client Data
The Client retains all rights in the data it submits to the API. Idvizer does not acquire any ownership or intellectual property rights in such data. Given the Zero-Retention Architecture, Idvizer does not retain any Client data beyond the ephemeral processing window of each API call.
7.3 Model Training Prohibition
Idvizer will not use any data submitted by the Client via the API to train, fine-tune, or improve its AI models or any third-party models without the Client's prior explicit written consent. The Zero-Retention Architecture is the primary technical guarantee of this commitment.
7.4 Feedback
Where the Client provides feedback or suggestions relating to the API or Service, Idvizer may use such feedback freely to improve its products without obligation or compensation to the Client.
8. Confidentiality
Each party agrees to treat as strictly confidential all non-public information disclosed by the other party in connection with these Terms, including API keys, technical architecture details, pricing, and business information. Each party will use Confidential Information solely for the purposes of performing its obligations under these Terms and will apply at least reasonable care in protecting it. These obligations survive termination for 5 years. Disclosures required by law or a competent authority are permitted provided the disclosing party notifies the other party promptly and cooperates to seek appropriate protection.
9. Service Levels and Availability
Idvizer will use commercially reasonable efforts to maintain API availability of 99.5% measured on a monthly basis (“Uptime SLA”), excluding scheduled maintenance (notified with at least 48 hours' advance notice) and events beyond Idvizer's reasonable control.
In the event of API unavailability attributable to Idvizer exceeding the SLA threshold in a given calendar month, the Client may request a service credit as specified in the Order Form. Service credits are the Client's sole and exclusive remedy for service unavailability, subject to the limitation of liability in Section 11.
Idvizer provides technical support in accordance with the support tier included in the Order Form. Support requests should be directed to support@idvizer.com.
10. Warranties and Disclaimers
10.1 Idvizer Warranties
Idvizer warrants that: (a) it has full right and authority to provide the Service and grant the licences set out in these Terms; (b) the Service will be provided with reasonable care and skill; (c) it will comply with applicable EU and French data protection law in performing the Service; and (d) its Zero-Retention Architecture operates as described in Section 2.2 and the Documentation.
10.2 AI Performance Disclaimer
The Client acknowledges that the Service is an AI system and that, like all AI-based biometric systems, it does not guarantee 100% accuracy. Verification results are probabilistic in nature. Idvizer makes no warranty as to the accuracy, completeness, or fitness for any particular purpose of the verification output. The Client is solely responsible for determining the appropriate confidence thresholds for its use case and for implementing human oversight mechanisms as required by the EU AI Act for High-Risk AI Systems.
10.3 General Disclaimer
Except as expressly stated in Section 10.1, the API is provided on an “as is” and “as available” basis. Idvizer disclaims all implied warranties to the fullest extent permitted by applicable law. The Service does not constitute legal, identity, or regulatory compliance advice.
11. Limitation of Liability
To the maximum extent permitted by applicable law:
- Idvizer's aggregate liability to the Client for all claims arising under or in connection with these Terms in any 12-month period will not exceed the total fees paid by the Client to Idvizer during that same 12-month period.
- Idvizer will not be liable for any indirect, consequential, special, incidental, or punitive damages, including loss of revenue, loss of data, loss of business, or reputational harm, even if advised of the possibility of such damages.
- Idvizer will not be liable for any claim arising from the Client's failure to obtain valid consent from End-Users, failure to comply with GDPR or the EU AI Act, or use of the Service in a manner prohibited by these Terms.
- Nothing in these Terms limits liability for death or personal injury caused by negligence, fraud or fraudulent misrepresentation, or any other liability that cannot be lawfully excluded under French or EU law.
12. Indemnification
The Client agrees to indemnify, defend, and hold harmless Idvizer SASU, its officers, directors, employees, and agents against any third-party claims, regulatory enforcement actions, fines, penalties, liabilities, damages, and costs (including reasonable legal fees) arising from: (a) the Client's breach of these Terms; (b) the Client's failure to comply with GDPR, the EU AI Act, or any applicable law in connection with its use of the Service; (c) the Client's failure to obtain valid End-User consent; (d) the Client's use of the Service for a prohibited purpose; or (e) any claim by an End-User arising from the Client's deployment of the Service.
13. Force Majeure
Neither party will be in breach of these Terms or liable for delay or failure to perform any obligation to the extent caused by circumstances beyond that party's reasonable control, including natural disasters, cyberattacks attributable to state actors, pandemics, government action, or failures of third-party cloud infrastructure providers. The affected party will promptly notify the other and use reasonable efforts to resume performance.
14. EU AI Act Obligations
14.1 Idvizer as Provider
As Provider of a High-Risk AI System under Annex III of the EU AI Act, Idvizer undertakes to:
- Establish and maintain a quality management system for the AI system in accordance with Article 17;
- Maintain technical documentation as required by Article 11 and Annex IV;
- Ensure the AI system undergoes the applicable conformity assessment procedure before being placed on the market or put into service, and affix the CE marking where required;
- Register the AI system in the EU database for high-risk AI systems pursuant to Article 71;
- Implement and maintain logging capabilities at the API level to record the operational parameters of each verification call (excluding biometric payload) to the extent required by Article 12;
- Provide the Client with the information necessary to fulfil its obligations as Deployer, including the instructions for use required by Article 13.
14.2 Client as Deployer
As Deployer of a High-Risk AI System, the Client undertakes to:
- Use the Service only in accordance with the instructions for use provided by Idvizer pursuant to Article 26(1);
- Assign human oversight to the verification process and ensure that output decisions are subject to meaningful human review prior to producing legal or similarly significant effects on End-Users, pursuant to Article 26(2);
- Conduct a fundamental rights impact assessment prior to deploying the Service in contexts that may affect the rights of natural persons, pursuant to Article 27;
- Not modify or retrain the AI model without Idvizer's written consent;
- Report to Idvizer any serious incidents or malfunctions of the AI system that may constitute a risk within the meaning of Article 73;
- Maintain logs of its own use of the Service for the period required by Article 26(6).
15. Term and Termination
15.1 Term
These Terms take effect upon execution of the Order Form and continue for the subscription term specified therein, renewing automatically unless either party gives 30 days' written notice of non-renewal before the end of the then-current term.
15.2 Termination for Cause
Either party may terminate these Terms immediately upon written notice if the other party materially breaches these Terms and fails to remedy such breach within 14 days of written notice, or becomes insolvent or subject to insolvency proceedings.
15.3 Termination for Regulatory Cause
Idvizer may terminate or suspend the Service immediately upon written notice if continued provision would, in Idvizer's reasonable opinion, expose Idvizer to violation of applicable EU or French law, regulatory sanction, or enforcement action, including under the EU AI Act or GDPR.
15.4 Effect of Termination
Upon termination, the Client's API access credentials will be revoked. Given the Zero-Retention Architecture, there is no Client biometric data held by Idvizer to return or delete. Non-biometric transactional metadata will be retained by Idvizer for the period required by applicable accounting and tax law. Accrued payment obligations, confidentiality, IP, liability, indemnification, and governing law provisions survive termination.
16. Modifications to These Terms
Idvizer may update these Terms to reflect changes in applicable law (including the EU AI Act implementing acts), regulatory guidance, or its business operations. Idvizer will provide at least 30 days' written notice of material changes. If the Client does not accept the updated Terms, it may terminate the subscription before the changes take effect. Continued use of the API after the effective date constitutes acceptance.
17. Governing Law and Dispute Resolution
These Terms are governed by the laws of France. In the event of a dispute, the parties will attempt to resolve it amicably within 30 days of written notice. If unresolved, the courts of Paris, France (Tribunal de Commerce de Paris) shall have exclusive jurisdiction.
18. General Provisions
- Entire Agreement: These Terms, together with the Order Form, DPA, and Documentation, constitute the entire agreement between the parties and supersede all prior agreements.
- Severability: If any provision is held unenforceable, it will be modified to the minimum extent necessary and the remainder will continue in force.
- No Waiver: Failure to enforce any provision does not constitute a waiver of future enforcement rights.
- Assignment: The Client may not assign these Terms without Idvizer's prior written consent. Idvizer may assign in connection with a corporate reorganisation or acquisition.
- Notices: Legal notices must be sent to legal@idvizer.com and will be effective upon confirmed receipt.
- Language: These Terms are drafted in English. A French version may be provided for convenience; the English version prevails in case of conflict.
19. Contact
Idvizer SASU | Registered in France
Legal: legal@idvizer.com
Security: security@idvizer.com
Support: support@idvizer.com
DPA requests: legal@idvizer.com
Website: https://www.idvizer.com
By accessing the Idvizer API, the Client confirms it has read, understood, and agrees to these Terms and Conditions.