Parties
This Services Agreement (the “Agreement”) is made on the Effective Date between:
(1) RISK LAB INNOVATION PTY LTD (ABN 52 695 286 287) trading as Detekta (“Detekta”, “Provider”, “we”, “us”); and
(2) [CUSTOMER LEGAL NAME] (ABN __________________) (the “Customer”, “you”).
(each a “Party” and together the “Parties”).
Background
(A) Detekta provides (i) AML/CTF compliance services and (ii) a Software-as-a-Service compliance platform delivering KYB, KYC, ultimate beneficial owner verification, document and biometric verification, transaction monitoring, and sanctions, PEP and adverse-media screening (the Platform).
(B) The Customer is a reporting entity (or is preparing to operate as a reporting entity) under the AML/CTF Laws and requires the Services to establish and operate its AML/CTF compliance obligations.
(C) The Services comprise two distinct modules — Compliance Services (Schedule A) and Platform Services (Schedule B) — provided on the commercial terms set out in Schedule C.
(D) The Parties agree to enter into this Agreement on the terms set out below.
1. Definitions and Interpretation
- In this Agreement, capitalised terms have the meanings given below or where defined in context:
Term | Meaning |
Affiliate | an entity that Controls, is Controlled by, or is under common Control with, a Party. |
AML/CTF Laws | the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth), the AML/CTF Rules, and any related or successor legislation and regulator instruments. |
Applicable Laws | all laws, regulations, rules, regulator policy and orders in force in the Territory that apply to a Party in performing this Agreement, including the AML/CTF Laws and Privacy Laws. |
Authorised Users | employees and contractors of the Customer or its Affiliates whom the Customer nominates and grants access to the Platform in accordance with this Agreement. |
Business Day | a day other than a Saturday, Sunday or public holiday in Sydney, New South Wales. |
Case | a single KYB, KYC, UBO, identity, document or screening verification event initiated through the Platform that consumes one (1) unit of an Included Allowance. Ongoing monitoring and automated periodic re-screening of an already-verified party do not consume a Case. |
Compliance Services | the AML/CTF compliance services described in Schedule A. |
Confidential Information | information of a confidential nature disclosed by one Party to the other, in any form, including the terms of this Agreement, Customer Data, the Platform, pricing and business information. |
Control | the power to direct the management or policies of an entity, whether through ownership of more than 50% of its voting securities, by contract or otherwise. |
Customer Data | all data, content and records (including Personal Data) that the Customer, its Authorised Users, its clients or its Affiliates submit to, generate within, or store on the Platform. |
Effective Date | the date set out on the cover page of this Agreement, or if none is stated, the date of last signature. |
Fees | the fees payable by the Customer as set out in Schedule C. |
GST | goods and services tax under the A New Tax System (Goods and Services Tax) Act 1999 (Cth). |
Included Allowance | the volume of Cases (stated separately for KYB and KYC) included in the Fees for the relevant period, as set out in Schedule C. |
Order Form | Schedule C to this Agreement, and any further order form the Parties agree in writing. |
Program Documents | the AML/CTF program, policies, procedures and customer risk-rating methodology in the final form delivered to the Customer under Schedule A. |
Initial Term | thirty-six (36) months from the Effective Date. |
MLRO | the Customer’s appointed AML/CTF Compliance Officer / Money Laundering Reporting Officer. |
Personal Data | has the meaning given to “personal information” in the Privacy Act 1988 (Cth). |
Platform Services | the Platform and related services described in Schedule B. |
Privacy Laws | the Privacy Act 1988 (Cth) and the Australian Privacy Principles, and any other applicable data-protection law in the Territory. |
Services | together, the Compliance Services and the Platform Services. |
SMR | a suspicious matter report under the AML/CTF Laws. |
Territory | Australia. |
Third Party Data Providers | third-party data sources, registries and identity providers used by Detekta to deliver the Platform Services, as listed in Schedule D. |
- Interpretation. Headings are for convenience only. A reference to a statute includes subordinate legislation and any amendment or replacement. The singular includes the plural and vice versa. A reference to a Schedule is to a Schedule to this Agreement, which forms part of it. If there is any inconsistency, the main body prevails over a Schedule except where a Schedule expressly states otherwise.
2. Structure of the Services
- The Services are provided in two distinct modules, each with its own scope, warranties and, where stated, service levels:
- Compliance Services (Schedule A) — professional AML/CTF compliance support; and
- Platform Services (Schedule B) — a subscription licence to the Platform.
- The Customer may take both modules or, where Schedule C so indicates, either module. The warranty standard and liability treatment applicable to each module are as set out in clauses 11 and 12 and the relevant Schedule.
- Detekta will provide the Services from the Effective Date in accordance with this Agreement and the Schedules. The Services are provided on a non-exclusive basis.
3. Customer Responsibilities and Regulatory Ownership
- The Customer will (a) provide the information, data, files, access and validations reasonably required for Detekta to perform the Services, accurately and on time; (b) ensure all data it submits is accurate, lawfully obtained and that it has the rights and consents to share it with Detekta; (c) use the Services only for lawful purposes; (d) be responsible for its Authorised Users; and (e) maintain reasonable security over access credentials.
- Regulatory ownership. The Customer is and remains the reporting entity under the AML/CTF Laws. The Customer is solely responsible for its compliance with the AML/CTF Laws, for adopting and applying its AML/CTF program, and for all regulatory decisions, determinations and lodgements. Detekta provides support, tooling and recommendations only; it does not assume the Customer’s regulatory obligations.
- No legal advice. The Compliance Services are compliance operational and advisory support and do not constitute legal advice. The Customer is responsible for obtaining its own legal advice on its obligations.
- Reliance on Customer inputs. Detekta’s outputs depend on the accuracy and completeness of the information, files and validations the Customer provides. Detekta is not responsible for outcomes arising from inaccurate, incomplete or late Customer inputs, or from the Customer’s decision not to act on a Detekta recommendation.
- The Customer must not (a) reverse engineer or attempt to derive the source of the Platform; (b) resell or make the Platform available to third parties except its Affiliates and its own clients receiving the Services as part of the Customer’s regulated activities; (c) circumvent usage limits; or (d) use the Platform to build a competing product.
4. Term and Renewal
- This Agreement commences on the Effective Date and continues for the Initial Term of thirty-six (36) months.
- After the Initial Term, this Agreement automatically renews for successive twelve (12) month terms unless either Party gives written notice of non-renewal at least sixty (60) days before the end of the then-current term.
- Because the Fees for the Initial Term are structured around a fixed monthly amount that absorbs front-loaded implementation and remediation effort, termination for convenience is not available during the Initial Term. Early termination is dealt with in clauses 13 and Schedule C (Early-termination true-up).
- Fees for any renewal term may be adjusted on no less than sixty (60) days’ written notice, by no more than the greater of (a) five per cent (5%) and (b) the annual CPI (All Groups, Sydney) plus two per cent (2%). Third-party cost pass-through is dealt with in Schedule C.
5. Fees and Payment
- The Customer will pay the Fees set out in Schedule C.
- Billing cycle. The monthly Fee is payable monthly in advance for the coming month. Detekta will issue a tax invoice at or before the start of each month, and payment is due within ten (10) days of the invoice date. The Customer may instead authorise automatic card debit, in which case Detekta will debit the monthly Fee (plus GST and any accrued overage) on or after the first day of the month to which it relates.
- Overage. Cases processed in excess of the applicable Included Allowance are charged at the overage rates in Schedule C and are invoiced (or debited) in arrears for the month in which they were processed. KYB and KYC allowances and overage are tracked separately.
- All Fees are exclusive of GST, which will be added where applicable. Fees are non-refundable except as expressly stated.
- If an amount is not paid when due, Detekta may charge interest on the overdue amount at the Reserve Bank of Australia cash rate plus four per cent (4%) per annum, calculated daily, and may exercise its rights under clause 13.2.
- The Customer may dispute an invoiced amount in good faith by written notice within ten (10) days of the invoice, with reasonable detail. Undisputed amounts remain payable. The Parties will resolve disputes promptly and in good faith.
6. Service Levels and Support
- Platform Services are provided to the availability and support targets in Schedule B (Service Levels). Where a service-credit regime is specified in Schedule B, service credits are the Customer’s sole and exclusive remedy for failure to meet an availability target.
- Compliance Services are provided in accordance with the timeframes and cadence in Schedule A and Schedule C, subject to the Customer meeting its input dependencies.
7. Data Protection and Privacy
- Each Party will comply with the Privacy Laws applicable to its activities under this Agreement.
- Where Detekta processes Personal Data on behalf of the Customer, the Parties’ respective obligations are set out in the Data Processing Addendum at Schedule D, which forms part of this Agreement.
- Detekta will host Customer Data in Australia and will not transfer Customer Data outside Australia except to the extent strictly necessary to process a verification request through a Third Party Data Provider, and in accordance with Schedule D.
- Detekta will maintain administrative, physical and technical safeguards appropriate to the sensitivity of the Customer Data, including encryption in transit and at rest, access controls and logging, as further described in Schedule D.
- Detekta will notify the Customer without undue delay after becoming aware of an eligible data breach affecting Customer Data, and will cooperate with the Customer in relation to its obligations under the Notifiable Data Breaches scheme.
8. Confidentiality
- Each Party will keep the other’s Confidential Information confidential, use it only for this Agreement, and disclose it only to personnel, advisers and subcontractors who need to know and are bound by equivalent obligations.
- The obligation does not apply to information that (a) is or becomes public other than by breach; (b) was already known without restriction; (c) is independently developed; or (d) is required to be disclosed by law or regulator, in which case the receiving Party will, where lawful, give prior notice.
- These obligations survive termination for five (5) years, except that they continue for trade secrets for so long as the information remains a trade secret.
9. Intellectual Property
- As between the Parties, Detekta owns all intellectual property in the Platform, the Services, and Detekta’s underlying templates, methodologies, know-how and pre-existing materials, and any modifications or derivative works of them.
- Program Documents belong to the Customer. On delivery and subject to payment of the Fees, the final Program Documents delivered to the Customer under Schedule A are the Customer’s property, and the Customer may use, modify, retain and rely on them for its own AML/CTF compliance, including after termination or expiry of this Agreement. Detekta retains ownership of the underlying templates, methodologies and know-how used to prepare them, and to the extent any such Detekta materials are embedded in the Program Documents, Detekta grants the Customer a perpetual, irrevocable, royalty-free licence to use them as part of the Program Documents.
- Subject to payment of the Fees, Detekta grants the Customer a non-exclusive, non-transferable, non-sublicensable licence during the term to access and use the Platform for its internal business purposes in the Territory.
- As between the Parties, the Customer owns its Customer Data. The Customer grants Detekta a non-exclusive licence to process Customer Data solely to provide and improve the Services and to comply with Applicable Laws.
- Detekta may use de-identified, aggregated data derived from Customer Data to operate, secure, improve and benchmark the Platform, provided it does not identify the Customer, its clients or any individual.
- Publicity. Detekta may identify the Customer as a customer and use the Customer’s name and logo in its marketing, with the Customer’s prior written approval (not to be unreasonably withheld).
10. Third Party Data Providers
- The Customer acknowledges that the Platform Services rely on Third Party Data Providers. Detekta will use reasonable endeavours to procure that they meet the standards required to deliver the Services, but does not warrant the accuracy, completeness or availability of third-party data beyond Detekta’s reasonable control.
- The Customer will comply with any Third Party Data Provider end-user terms notified to it. Detekta may add or replace Third Party Data Providers on reasonable notice, and may suspend a particular data source where required by its upstream provider.
11. Warranties
- Each Party warrants that it has the power and authority to enter into and perform this Agreement, and that its performance will comply with Applicable Laws.
- Compliance Services warranty. Detekta warrants that the Compliance Services will be performed with reasonable care and skill, in a professional manner consistent with a competent provider of AML/CTF compliance services. Detekta does NOT warrant that use of the Services will ensure the Customer’s compliance with the AML/CTF Laws or prevent any regulator finding, penalty or action; responsibility for compliance remains with the Customer under clause 3.
- Platform Services warranty. Detekta warrants that the Platform will, in all material respects, perform in accordance with its documentation, and will be provided with reasonable care and skill.
- To the maximum extent permitted by law, all other warranties, whether express or implied, are excluded. Where a warranty is implied by law and cannot be excluded, Detekta’s liability for breach is limited (where permitted) to re-supply of the relevant Services or the cost of re-supply.
12. Liability and Indemnity
- Subject to clauses 12.2 to 12.5, each Party’s aggregate liability under or in connection with this Agreement (whether in contract, tort, statute or otherwise) in any twelve (12) month period is limited to the Fees paid or payable by the Customer in the twelve (12) months preceding the event giving rise to the liability.
- Neither Party is liable for loss of profit, revenue, business, goodwill or anticipated savings, or for any indirect or consequential loss, however arising.
- Nothing in this clause limits liability that cannot be limited by law, a Party’s liability for breach of confidentiality or infringement of the other’s intellectual property, the indemnities in clause 12.5, or the Customer’s obligation to pay undisputed Fees.
- Compliance Services — causation. The Parties acknowledge that the Customer is the reporting entity and makes all regulatory decisions (clause 3). Detekta is not liable for any regulator penalty, fine or enforcement action, or for any loss arising from the Customer’s regulatory decisions, filings or omissions, except to the extent directly caused by Detekta’s breach of clause 11.2, and in any event subject to the cap in clause 12.1.
- Indemnities. Detekta indemnifies the Customer against third-party claims that the Platform infringes that party’s Australian intellectual property rights, provided the Customer promptly notifies Detekta, makes no admission without consent, and cooperates; and provided that on such a claim Detekta may at its option modify or replace the affected element, procure a licence, or terminate the affected Services and refund prepaid unused Fees. This indemnity excludes claims arising from Customer Data, Third Party Data Provider data, or combination of the Platform with the Customer’s systems, and Detekta’s aggregate liability under this indemnity is capped at two (2) times the Fees paid or payable by the Customer in the twelve (12) months preceding the claim. The Customer indemnifies Detekta against claims arising from the Customer’s breach of clause 3.5 or its instruction to process data in breach of Applicable Laws.
13. Suspension, Termination and Effect
- Either Party may terminate immediately by notice if the other (a) commits a material breach not remedied within thirty (30) days of written notice; or (b) becomes insolvent or subject to an insolvency process, to the extent permitted by law.
- Detekta may suspend the Services on seven (7) Business Days’ written notice if the Customer fails to pay an undisputed amount by its due date or fails to maintain a valid payment method, until the amount is paid.
- Early-termination true-up. If this Agreement is terminated before the end of the Initial Term other than for Detekta’s uncured material breach or insolvency, the Customer will pay, on termination, the difference between (a) the value of Services actually consumed to the date of termination re-rated at the pay-per-volume rates in Schedule C, plus any implementation, setup and integration fees not yet recovered through the Fees paid, and (b) the Fees already paid — if (a) exceeds (b). This reflects that the fixed monthly Fee absorbs front-loaded implementation, integration and remediation cost.
- On termination or expiry: (a) the Customer pays all Fees accrued to the effective date; (b) each Party returns or destroys the other’s Confidential Information, except where retention is required by Applicable Laws; (c) Detekta will, on or before the effective date of termination, and in any event on the Customer’s written request made within ninety (90) days, export the Customer Data and the Program Documents in a common machine-readable format and provide them to the Customer at no additional charge; and (d) Detekta will delete Customer Data from active production systems within sixty (60) days after the Customer confirms receipt of that export (or, if no export is requested, within ninety (90) days of termination), subject to the seven (7) year retention requirement under the AML/CTF Laws and to routine backup cycles that overwrite in the ordinary course.
14. Regulatory Compliance, Records and Audit
- Each Party will comply with Applicable Laws in performing this Agreement. Detekta acknowledges that the Customer is subject to oversight by AUSTRAC and other regulators in the Territory, and will reasonably cooperate with any regulator request or examination relating to the Services and provide records the regulator is entitled to receive.
- Detekta will retain records related to the Services for the period required by Applicable Laws, and in any event for not less than seven (7) years from the relevant transaction or verification.
- The Customer may, on reasonable prior written notice and not more than once per twelve (12) month period (or more frequently if required by a regulator or following a material breach), audit Detekta’s compliance with this Agreement, during business hours, without unreasonable disruption, and at the Customer’s cost. Detekta’s independent SOC 2 or equivalent report may be accepted in lieu of an on-site audit at the Customer’s option.
15. Force Majeure
- Neither Party is liable for delay or failure to perform (other than payment obligations) caused by events beyond its reasonable control, including natural disaster, act of government, war, terrorism, pandemic, telecommunications failure, or cyber attack not caused by that Party’s negligence. The affected Party will notify the other promptly and use reasonable endeavours to mitigate. If the event continues for more than sixty (60) consecutive days, either Party may terminate on written notice.
16. Dispute Resolution
- Before commencing proceedings (other than for urgent injunctive relief), the Parties will (a) raise the dispute in writing; (b) escalate within fifteen (15) Business Days to senior representatives who will meet in good faith; and (c) if unresolved within thirty (30) Business Days, refer the dispute to mediation in Sydney under the Resolution Institute Mediation Rules, costs shared equally.
- If mediation does not resolve the dispute within sixty (60) days of referral, either Party may commence proceedings in the courts of New South Wales.
17. General
- Governing law. This Agreement is governed by the laws of New South Wales, Australia, and the Parties submit to the exclusive jurisdiction of its courts.
- Entire agreement. This Agreement and its Schedules are the entire agreement and supersede all prior agreements and any Detekta standard online terms.
- Variation. No variation is effective unless in writing and signed by an authorised representative of each Party.
- Assignment. Neither Party may assign without the other’s prior written consent (not to be unreasonably withheld), except to an Affiliate or successor in a reorganisation, merger or sale of substantially all assets, on notice.
- Subcontracting. Detekta may subcontract the performance of the Services (including to Third Party Data Providers), but remains liable for the acts and omissions of its subcontractors as if they were its own.
- Notices. Notices must be in writing and sent to the contacts in Schedule C (or as updated by written notice), and may be given by email. A notice is deemed received when sent if sent on a Business Day before 5:00pm (Sydney), and otherwise on the next Business Day, unless the sender receives an automated delivery-failure message.
- Waiver. A failure or delay in exercising a right under this Agreement is not a waiver of it, and no waiver is effective unless in writing. A waiver of one breach does not waive any other.
- Relationship. Nothing creates a partnership, joint venture, employment or agency relationship.
- Survival. Clauses that by their nature should survive termination (including clauses 7, 8, 9, 12, 13.3, 13.4, 14, 16 and 17) survive.
- Severability. If a provision is invalid or unenforceable, the remainder continues in force.
- Counterparts. This Agreement may be executed in counterparts and by electronic signature, each of which is an original.
Execution
Executed as an agreement. Each company may sign in accordance with section 127 of the Corporations Act 2001 (Cth) — by two directors, a director and a company secretary, or (for a sole-director company) the sole director.
Signed for RISK LAB INNOVATION PTY LTD t/a DETEKTA (ABN 52 695 286 287): |
Signature of director: ______________________ | Signature of director/secretary: ________________ |
Name: __________________________ | Name: __________________________ |
Office held: ____________________ | Office held: ____________________ |
Date: __________________________ | Date: __________________________ |
Signed for [CUSTOMER LEGAL NAME] (ABN __________): |
Signature of director: ______________________ | Signature of director/secretary: ________________ |
Name: __________________________ | Name: __________________________ |
Office held: ____________________ | Office held: ____________________ |
Date: __________________________ | Date: __________________________ |
(If a Party is a sole-director company, only the sole director need sign; strike through the second signature block.)
Schedule A — Compliance Services
This Schedule describes the professional AML/CTF compliance module. It is subject to the warranty standard in clause 11.2 and the liability treatment in clause 12.4. Detekta prepares and supports; the Customer, as reporting entity, decides and files.
A1. AML/CTF Program & Policies
- ML/TF risk assessment of the Customer’s business, clients, channels and services.
- Drafting of the AML/CTF program, policies and procedures, and a customer risk-rating methodology, for the Customer’s adoption and board approval.
- Annual review and update of the program and policies.
A2. Back-book Remediation & Ongoing CDD
- Risk-rating of the existing client base and a remediation schedule paced across the relevant period.
- Management, tracking and evidencing of ongoing customer due diligence in accordance with the adopted program.
A3. Case Review & Outsourced Compliance Operations
- Review of onboarding cases, investigation of alerts, and preparation of case records and narratives.
- Maintenance of audit-ready records for the retention period required by the AML/CTF Laws.
A4. MLRO Support (division of responsibility)
The Customer appoints and maintains its own MLRO. Detekta supports the role but does not perform it. Specifically:
Activity | Responsibility |
Investigate alerts; gather evidence; draft SMRs and reports | Detekta (prepares) |
Review and approve reports and SMRs; decide whether to report | Customer’s MLRO (decides) |
Lodge SMRs and reports with AUSTRAC | Detekta, only on the MLRO’s express written approval and instruction |
Quarterly MLRO meeting (cases, filings, program health) | Detekta facilitates; Customer’s MLRO chairs |
A5. Learning & Development
- One (1) live video training session (approximately 45 minutes) for current staff who handle clients, client money or have Platform access.
- Online training modules for new employees, at no additional cost, with attendance records maintained as compliance evidence.
A6. External Audit Readiness
- Preparation of evidence and support for independent reviews or regulator audits of the Customer’s AML/CTF compliance.
A7. Customer dependencies
Detekta’s delivery of the Compliance Services depends on the Customer providing complete and accurate information, file extracts, validations and access, and reasonable personnel availability, as further described in Schedule C. Timeframes run from the Customer meeting these dependencies.
Schedule B — Platform Services
This Schedule describes the Platform (SaaS) module. It is subject to the warranty standard in clause 11.3.
B1. Platform capabilities
- KYB — company, ABN/ACN and UBO verification, directors and registry data, with continuous monitoring.
- KYC — document verification, biometric/liveness checks, identity verification, orchestrated across Detekta’s provider network.
- Sanctions, PEP and adverse-media screening, with ongoing re-screening.
- Transaction monitoring — rule-based and behavioural analytics, with case generation (data ingested by file extract unless otherwise agreed in Schedule C).
- Customer-branded onboarding portal and forms.
- Integrations and data flow to the Customer’s systems as specified in Schedule C.
- Operational and management reporting, dashboards and regulator-ready exports.
B2. Case definition and allowances
A Case is a single initiated KYB, KYC, UBO, identity, document or screening verification event. Ongoing monitoring and automated periodic re-screening of an already-verified party do NOT consume a Case. The fixed Fee covers the estimated KYB and KYC volumes set out in Schedule C; Cases above those volumes are billed monthly in arrears at the overage rates in Schedule C, stated separately for KYB and KYC as the rates differ.
B3. Service Levels
Element | Target |
Platform availability | 99.95% per calendar month (excl. scheduled maintenance, Force Majeure, Customer-side outages, and Third Party Data Provider unavailability outside Detekta’s control) |
Support hours | Business Hours (9:00am–6:00pm Sydney, Mon–Fri excl. public holidays); critical incidents 24/7 |
P1 (critical) — response / resolution | 30 minutes / 4 hours |
P2 (high) — response / resolution | 2 Business Hours / 1 Business Day |
Service credits | As set out below (Customer’s sole and exclusive remedy for failure to meet availability) |
Monthly availability | Service credit (% of monthly Platform Fee) |
< 99.95% and ≥ 99.0% | 5% |
< 99.0% | 10% |
Availability is measured on the Platform and excludes unavailability of Third Party Data Providers. This 99.95% commitment mirrors the service level Detekta receives from its primary orchestration provider.
B4. Hosting and security
Customer Data is hosted in Australia. Detekta maintains encryption in transit and at rest, role-based access control, multi-factor administrative authentication, logging and monitoring, vulnerability management, and documented business continuity and disaster recovery, as further described in Schedule D.
Schedule C — Commercial Terms (Order Form)
Complete the fields below per engagement. All amounts are in AUD and exclusive of GST unless stated otherwise.
C1. Parties and contacts
Customer legal name / ABN | ______________________________________________ |
Detekta contact | Ricardo Maifrino — ricardo@detekta.ai |
Customer primary contact | ______________________________________________ |
Customer billing contact | ______________________________________________ |
Customer MLRO | ______________________________________________ |
C2. Term and modules
Initial Term | Thirty-six (36) months from the Effective Date |
Modules included | ☐ Compliance Services (Schedule A) ☐ Platform Services (Schedule B) |
Territory | Australia |
C3. Fees
Fixed monthly Fee (covers all included modules and allowances):
Fee component | Basis | Amount (ex GST) |
Fixed monthly Fee | per month, in advance | ____________ |
— covering: program, remediation, case review, MLRO support, monitoring, training, integrations, and checks up to the estimated volumes in C4 | | included |
One-off and variable components (complete as applicable):
Category | Basis | Amount (ex GST) |
Implementation / setup | one-off | ____________ |
System integration — per system (e.g. Ignition, Xero) | one-off per system | ____________ |
KYB verification — overage | per Case | ____________ |
KYC verification — overage | per Case | ____________ |
Transaction monitoring (if priced separately) | per month | ____________ |
MLRO support (if priced separately) | per month | ____________ |
Additional / bespoke services | as quoted | ____________ |
C4. Included volumes and overage
The fixed monthly Fee covers the estimated check volumes below over the Initial Term. Cases above these volumes are billed monthly in arrears at the KYB and KYC overage rates in C3 — stated separately by check type, as the rates differ.
Check type | Estimated volume included (over the 36-month term) | Overage rate (ex GST) |
KYB Cases | ____________ | __________ |
KYC Cases | ____________ | __________ |
C5. Payment
Billing cycle | Monthly in advance |
Payment terms | Due within ten (10) days of invoice date, or by automatic card debit on/after the first of the month |
Payment method | ☐ EFT / bank transfer ☐ Automatic card debit (Stripe / Pin Payments / equivalent) |
Overage billing | In arrears, added to the following month’s invoice or debit |
C6. Third-party cost pass-through
Where a Third Party Data Provider increases the charges it imposes on Detekta, Detekta may pass through the increase (by no more than the same percentage) on thirty (30) days’ written notice. Otherwise Fees are fixed for the Initial Term save for the renewal adjustment in clause 4.4.
C7. Group and referral incentives (optional)
Group discount | ____% off each additional Customer-group entity onboarded |
Referral credit | ____% of each referred customer’s monthly fee, credited to the Customer for ____ months per successful referral (stacking) |
Schedule D — Data Processing Addendum (Australia)
This Addendum applies to Personal Data processed by Detekta on behalf of the Customer under the Privacy Act 1988 (Cth) and the Australian Privacy Principles. It forms part of the Agreement.
D1. Roles and processing
The Customer determines the purposes and means of processing Customer Data; Detekta processes it on the Customer’s behalf and on its documented instructions, except where required by Applicable Laws. Where the Customer processes data for its own clients who are the controllers, Detekta acts as a downstream processor.
Subject matter and purpose: KYB/KYC verification, sanctions/PEP/adverse-media screening, transaction monitoring, compliance reporting and related processing to support the Customer’s AML/CTF obligations. Duration: the term of the Agreement plus the 7-year AML/CTF retention period.
D2. Categories of data
Data subjects: the Customer’s clients (individuals and representatives of entities), Authorised Users, and other persons whose data is submitted. Categories: identification and contact data, identity-document details, biometric data (where used for liveness), financial and transactional data, KYB/KYC outcomes, screening results, and audit and access logs.
D3. Detekta obligations
- Process Personal Data only on the Customer’s documented instructions.
- Ensure personnel authorised to process Personal Data are bound by confidentiality.
- Implement the technical and organisational measures in D5.
- Assist the Customer, so far as reasonably possible, with data-subject requests and with its obligations to secure data and to notify eligible data breaches.
- On termination, delete or return Personal Data in accordance with clause 13.4.
- Make available information reasonably necessary to demonstrate compliance and allow audits under clause 14.3.
D4. Third Party Data Providers / sub-processors
Detekta uses the following Third Party Data Providers / sub-processors (complete per engagement; Australian domestic engagement shown as default). Detekta will notify the Customer of any addition or replacement on at least thirty (30) days’ notice; if the Customer reasonably objects on data-protection grounds, the Parties will work in good faith on an alternative.
Provider | Purpose | Location |
FrankieOne (Frankie Financial Pty Ltd) | KYB/KYC orchestration | Australia |
Australian registries / credit bureaus (as applicable) | Company, identity and credit data | Australia |
Amazon Web Services (Sydney) | Infrastructure hosting | Australia |
Supabase (AU region) | Application database, auth, functions | Australia |
__________________ | ________________ | __________ |
D5. Technical and organisational measures
- Encryption of Customer Data in transit (TLS 1.2+) and at rest (AES-256).
- Role-based access control with least-privilege; multi-factor authentication for administrative access.
- Centralised logging and monitoring; audit logs retained not less than seven (7) years.
- Vulnerability management with regular scanning and prompt patching of critical/high issues.
- Independent penetration testing at least annually.
- Secure development lifecycle with code review and dependency scanning.
- Personnel screening, security-awareness training and confidentiality obligations.
- Documented business continuity and disaster recovery, tested at least annually.
- Data hosted in Australia on AWS (Sydney) with multi-AZ redundancy; database and functions on Supabase (AU region).
D6. Breach notification
Detekta will notify the Customer without undue delay after becoming aware of an eligible data breach affecting Customer Data, providing the nature of the breach, the categories and approximate numbers of records affected, likely consequences, and measures taken or proposed — to enable the Customer to meet its Notifiable Data Breaches obligations.
— End of template —