# Trapets

Last updated: 18/09/2023
Current version effective from: 18/09/2023

# 1 Service description

The Signicat Services are integrated with services from the following Identity Provider: Trapets AB ("Trapets") / "InstantWatch KYC and AML Portfolio screening" ("Trapets Services"). InstantWatch KYC contains certain "KYC-Data", meaning any data distributed from, contained in, or originated from the Trapets Services.

# 2 The Customer's obligations

The Customer is granted a non-exclusive, non-transferable right to use KYC-Data. The Customer may only use the KYC-Data in its internal work to prevent money laundering and terrorism financing. KYC-Data is confidential and will be handled in accordance with the confidentiality provisions of the Agreement.

The Customer is not entitled to resell or transfer the KYC-Data to third parties. The Customer shall not disclose, evaluate, make available or allow the use of KYC-Data from or to a third party. Nor does the Customer have the right to convey the results of screenings where KYC-Data is used to third parties without Trapets written permission. Except as permitted in accordance with imperative legislation, the Customer may not modify, decompile or investigate the source code or data contents from the Trapets Services.

The Customer shall ensure that the agreement with its customers stipulates that such customers are not entitled to resell, transfer, disclose, evaluate, make available or allow the use of the data content from the Trapets Services to any third parties.

In the event that Signicat notifies the Customer that the agreement with Trapets has been terminated, the Customer shall immediately delete all instances of data content from the Trapets Services, and confirm in writing to Signicat when such deletion has been completed.

The Customer shall comply with all applicable laws in its use of KYC-Data and shall be responsible for obtaining all permits, licenses and approvals required for managing KYC-Data.

In the event of deficiencies in the KYC-Data, the Customer shall report such deficiencies to Signicat.

# 3 Security requirements

The Customer undertakes to maintain a high standard of IT security to prevent unauthorised access to the data contents of the Trapets Services.

In the event unauthorised access to the KYC-Data has been obtained by a third party, such unauthorised access shall be reported to Signicat.

# 4 Audit

In the event of a concrete suspicion that the Customer has been involved or implicated in unauthorised disclosure of KYC-Data contrary to the Agreement, Trapets has the right to perform an audit of the Customer, unless it is contrary to the applicable laws and regulations. The Customer shall ensure the full cooperation of its employees and representatives. The Customer shall make available to Trapets the materials required to make such examination. In the event of such a review reveals that the unauthorised disclosure of KYC-Data has occurred, Trapets through Signicat may take the necessary actions, including without limitation a termination of the part of this Agreement pertaining to the Trapets Services.

Last updated: 28/09/2023 13:52 UTC