1. Definitions
- Operator
- The party that runs the matching service and publishes these terms. That is us.
- Subject
- The person or entity an attestation is about. A Subject has no SealRelay account, no PIN, and no key file held by the operator.
- Part A
- A legal entity that learns a fact and publishes a signed attestation about a Subject. Part A publishes free.
- Part B
- A party that looks up whether a pairwise commitment exists for a given Subject, Part A, domain and epoch. Part B pays per live lookup.
- Customer
- Part A or Part B, as the context requires. Where a clause applies to only one of them, it says so.
- Attestation
- A signed statement published by Part A. The operator receives a sealed tag derived from it, never the underlying identity.
- Lookup
- A live matching response to a query from Part B. Section 5 states exactly what is and is not a lookup.
- Epoch
- The period a matching key is scoped to, per participant and domain. Opening a new epoch is how revocation works; there is no separate revocation list.
- Adapter
- The thin, domain-specific layer through which a customer uses the service. Domain rules live in the adapter, never in the matching core.
2. What the service does, and what it does not do
SealRelay is a matching service. It answers one narrow question: does a pairwise commitment exist for this Subject, this Part A, this domain, this epoch. The answer is yes or no.
The operator does not hold the Subject's raw identity, does not hold the underlying document or fact, and does not evaluate identifiers. Part A publishes a sealed tag; Part B asks whether a matching tag exists. The material truth stays with Part A.
The operator is not a register, not a credit bureau, not an adviser, and does not verify that what Part A attested is true. The service does not decide anything about a Subject and does not produce a score, a rating, or a recommendation.
Where a lookup returns no, the four subject-side no cases are deliberately indistinguishable from each other. That is a design property of the service, not a fault, and the operator does not undertake to explain which of them applies.
3. Accounts and authority
An account is opened by a legal entity, together with a named person who confirms that they are authorised to act for it. Whether a further authority check applies depends on the adapter, and the adapter's rules are part of these terms for customers using that adapter.
You are responsible for the accuracy of the entity details you give us, for keeping your credentials and signing keys under your control, and for the acts of anyone you allow to use your account.
You must tell us without undue delay if you believe your credentials or an operational signing key have been lost or compromised. What happens next is set out in section 7.
4. Publishing (Part A)
Part A publishes free. Part A warrants that it has a lawful basis for the attestation it publishes, that the legitimacy anchor it asserts is the one that actually applies, and that it will not publish an attestation it knows to be false.
Part A withdraws a consent at Part A, not at the operator. The operator receives a revoke signal; it does not hold a Subject account through which a Subject could withdraw. Opening a new epoch is the revocation mechanism.
History in the matching core is append-only. Participant status is an attested lifecycle event, never a deletion. Withdrawal stops future lookups; it does not erase the record that an earlier lookup happened.
5. Lookups and fees (Part B)
Part B pays per live lookup. A yes and a no cost the same, so the amount billed cannot leak the answer. There is a free first period; after it, fees are those stated in your order form.
These are not lookups and are not billed: a cached answer served while matching is down, the fail-closed no returned while matching is down, and any refusal of a malformed or unauthorised request.
Billing is blind: the operator's billing records cannot be joined to a Subject. This means the operator cannot produce a per-Subject breakdown of your invoice, and will not do so on request, because the data to build one does not exist.
Invoices are payable as stated in your order form. If an invoice is overdue, the operator may stop new lookups for that account. Stopping Part B never stops Part A and never stops a Subject's own discovery. An answer Part B already fetched stays valid on Part B's side; the operator cannot delete a copy Part B already holds.
6. Reliance — what a yes means, and what it does not
Reliance limit
A yes is a technical hit: it says a pairwise commitment exists. It is not a verification of the underlying fact, not a warranty about the Subject, and not a waiver of any duty you have.
Part B bears the reliance on Part A's facts. If you act on an answer, you act on Part A's attestation, and your own obligations — regulatory, contractual, or otherwise — are unaffected by having received it.
A hit is a timestamped fact. It says the commitment existed when it was fetched. Anything that needs to be true now needs a new lookup.
The operator does not promise that matching is free of error. If the operator's own matching produces a wrong answer, the position is the same one stated here, and the limits in section 11 apply.
7. No key recovery
Required clause — no key recovery
There is no key recovery. If the Subject loses their key, SealRelay cannot restore it, and no one at SealRelay can act on their behalf.
This is not a limitation on a service that could otherwise be offered. The operator has never held the key material, so there is nothing to restore. There is no recovery form, no support ticket that reinstates a key, no escrow copy, no backup key, no administrative override, and no operator action that puts a key back.
The remedy for a lost key is a fresh qualified eID signing at Part A, which establishes a new binding. That is structurally the same act that created the binding in the first place. Old tokens are not restored; a fresh consent supersedes an old one.
The same applies to a Part A or Part B operational signing key. A lost or compromised operational key is replaced by a new signing act by that organisation, recorded as an attested lifecycle event on that participant. It does not oblige the operator to open a new epoch for everyone else in the same scope, and an ordinary loss is not treated as a compromise of the matching service.
Do not agree to these terms if your operating model requires the operator to be able to reinstate a key for you. No support arrangement, priority tier, or side letter can create that ability.
8. Availability and support
The operator measures uptime and publishes what it measures. These terms contain no guaranteed availability percentage, no service credit, and no committed response time. Support is a channel, not a promise about how fast it answers.
While matching is down, the service may serve the last signed yes for up to 24 hours and never a cached no; after that it fails closed. A fail-closed no is not a lookup and is not billed.
9. Acceptable use
You must not: query the service to enumerate Subjects, probe for the existence of Subjects you have no legitimate reason to query, attempt to distinguish the four subject-side no cases from one another, attempt to correlate billing records with Subjects, circumvent rate budgets, or use the service to build a register of Subjects.
You must not publish an attestation you know to be false, or assert a legitimacy anchor that does not apply.
On suspected protocol abuse the operator may stop new lookups for the account immediately, without notice. Section 10 sets out what happens next.
10. Term and termination
Required clause — termination
The agreement runs month to month. Either party may terminate for convenience on 30 days' written notice, effective at the end of the notice period. No reason is required and no termination fee applies.
Immediate stop on suspected protocol abuse. If the operator suspects abuse of the protocol under section 9, it may stop new lookups for that account immediately and without prior notice. This is a suspension of new lookups, not a deletion of history. The operator will tell you the account has been stopped and, so far as it can without defeating the purpose of the measure, why.
Termination for cause. Either party may terminate with immediate effect on a material breach that is not remedied within 30 days of written notice, or immediately if the other party becomes insolvent.
Effect of termination. New lookups stop. Answers already fetched remain with the party that fetched them; the operator cannot recall or delete them. Fees accrued up to termination remain payable. The append-only log is not rewritten on termination — participant status is recorded as a lifecycle event, never as an erasure. Data held under the data processing agreement is handled as that agreement provides, including deletion by destruction of the relevant key.
Sections 6, 7, 11, 12 and any clause that by its nature should survive, survive termination.
11. Limitation of liability
Required clause — liability cap
Cap. Each party's total aggregate liability arising out of or in connection with the agreement, whether in contract, tort (including negligence) or otherwise, is limited to the total fees paid by the customer to the operator under the agreement in the 12 months immediately preceding the event giving rise to the claim.
Where no fees are paid. Part A publishes free. For a customer that has paid no fees in that period, the aggregate cap is a fixed sum to be stated here. The figure is deliberately left blank in this draft: setting it is a legal and commercial decision, and inventing a number would misrepresent it as decided.
Excluded loss. Neither party is liable for indirect or consequential loss, loss of profit, loss of revenue, loss of anticipated savings, loss of goodwill, or loss arising from a decision the customer took on the basis of a lookup answer.
What the cap does not cover. Nothing limits or excludes liability that cannot lawfully be limited or excluded — including death or personal injury caused by negligence, fraud or fraudulent misrepresentation, and wilful misconduct — nor the customer's obligation to pay fees due.
No availability warranty. Consistent with section 8, the operator gives no warranty of availability and no service credit, and the absence of such a remedy does not enlarge the cap.
12. Assignment and transfer
Required clause — assignment and transfer
The customer may not assign, novate, or otherwise transfer the agreement, in whole or in part, without the operator's prior written consent, which will not be unreasonably withheld.
The operator may. The operator may assign or novate the agreement, and transfer the intellectual property and operational responsibility behind the service, to a successor entity within the same ownership, or to an acquirer of all or substantially all of the assets to which the agreement relates, without the customer's consent. The operator will notify the customer in writing of any such transfer.
Why this clause exists. The service is expected to move from the entity that currently operates it to a dedicated operating company. That move must not require re-signing every customer agreement. A transfer changes who the counterparty is; it does not change these terms, the fees, or the technical behaviour of the service.
Not transferred by this clause. The transfer does not create any new access to customer data, and it does not create a key recovery ability that section 7 says does not exist. A successor operator inherits the same inability.
The named legal entities on both sides of any transfer are left out of this draft on purpose. Naming them is a decision for the operator and its lawyer, and the naming also interacts with how this site is allowed to be published.
13. Changes to these terms and to fees
The operator may change these terms on written notice. A change that materially reduces what the customer gets takes effect no earlier than 30 days after notice, and the customer may terminate under section 10 before it takes effect.
A new list price takes effect no earlier than 30 days after notice. No list price is stated in this draft.
14. Other terms
- Data protection. The operator's processing of personal data is described in the privacy notice, and, where the customer is a controller and the operator a processor, governed by the data processing agreement. Both are drafts on the same footing as this page.
- Confidentiality. Each party keeps the other's non-public information confidential and uses it only to perform the agreement.
- Intellectual property. The specification is open. The matching operations are the operator's. Nothing in the agreement transfers ownership of either party's intellectual property.
- No exclusivity. Nothing here is exclusive to any customer, sector, or territory.
- Entire agreement. The agreement is these terms, the order form, and the data processing agreement. In conflict, the order form prevails over these terms, and the data processing agreement prevails on matters of personal data.
- Severability. If a provision is unenforceable, the rest stands.
- Governing law and venue. To be stated. Left blank in this draft — see section 15.
15. Open in this draft
These items are deliberately not written here. Each needs a human decision or a lawyer, and inventing text for them would make this draft look more settled than it is.
- Legal review. Still outstanding, at minimum: the carve-out wording, the assignment clause, the liability cap, the termination rights, and the no-key-recovery clause.
- The liability cap figure for a customer that pays no fees (section 11).
- Governing law and venue (section 14).
- The named operator entity, and the named successor entity in the assignment clause (section 12).
- List price and the length of the free first period (section 5).
- Collections wording for unpaid invoices (section 5).
- Insurance — the decision is documented separately and is not a term of this agreement.
- A contact channel for notices. This page states no address.