Terms of Service (TOS)
Cridenty Platform
Current version: V1
English translation provided for convenience. In case of discrepancy, the French version (“CGS”) shall prevail.
1. Purpose
These Terms of Service (the “TOS”) define the terms and conditions under which professional customers may access and use the Cridenty platform, published by 96t (Cridenty) SASU.
Cridenty provides a trusted evidence platform to secure critical operations, including in particular:
- strong authentication mechanisms,
- validation workflows,
- and cryptographically signed, timestamped proofs to verify the integrity of a message or an action.
2. Service provider
Company: 96t (Cridenty) – SASU
SIRET: 898 234 463 00013
Registered office: 231 rue Saint-Honoré, 75001 Paris – France
Contact email: contact@cridenty.com
3. Scope
These TOS apply exclusively:
- to professional customers (B2B),
- to any use of the Cridenty platform, its web interfaces, APIs and related applications.
Any use of the service implies full acceptance of these TOS.
4. Service description
Cridenty provides a platform enabling:
- authentication and validation of sensitive actions,
- generation of cryptographic proofs associated with content or an operation,
- independent verification of these proofs via short identifiers or stable references,
- logging and audit of critical events.
4.1 Nature of the service
Cridenty acts as an evidence service provider.
Cridenty:
- does not transport messages,
- does not participate in their delivery,
- does not store messages in clear text.
Submitted content is processed strictly for technical and transient purposes, exclusively to generate a cryptographic proof, without semantic analysis, without indexing, and without storing the message in clear text.
5. Access to the service
Access to the service is subject to:
- the creation of a customer account (tenant),
- the assignment of credentials and/or access keys,
- compliance with the security rules defined by Cridenty.
Cridenty reserves the right to refuse or suspend access in case of non-compliance with these TOS.
6. Customer obligations
The customer undertakes to:
- use the service in accordance with its intended purpose,
- keep credentials and keys confidential,
- not divert the service for fraudulent, illegal or abusive purposes,
- comply with applicable laws and regulations.
The customer remains solely responsible for:
- the content submitted to the platform,
- the use of generated proofs,
- the compliance of its own business processes.
When the customer deploys Cridenty Guard or Agent Guard in its environment, the customer remains responsible for:
- deployment on its workstations, servers or technical environments,
- configuration of policies and authorized scopes,
- information provided to the users or employees concerned,
- determination of the legal basis applicable to its own context,
- compliance with its employment-related, contractual and regulatory obligations,
- definition of retention periods applicable to its uses.
7. Prohibited uses
The following are strictly prohibited:
- any fraudulent use or attempt to bypass security measures,
- use of the service for illegal or misleading activities,
- any attempt to compromise the integrity, availability or security of the platform.
8. Suspension and termination
8.1 Immediate suspension
In the event of:
- suspected fraud,
- non-compliant use,
- attack on the security or integrity of the service,
Cridenty reserves the right to suspend access immediately, without prior notice and without refund.
8.2 Termination
Cridenty may terminate the contract:
- as of right,
- without compensation,
- in case of serious or repeated breach by the customer.
Except in case of security urgency, obvious fraud or legal impossibility, Cridenty sends the customer a formal notice or reasonable prior notification allowing, where possible, remediation of the identified breach.
9. Service availability (indicative SLA)
Cridenty uses reasonable efforts to ensure service availability.
An availability target may be communicated for information purposes only, without guarantee of results and without financial penalties.
The service may be temporarily unavailable due to:
- maintenance,
- updates,
- incidents outside of Cridenty’s control.
10. Security
Cridenty implements security measures consistent with industry best practices, including in particular:
- strong authentication (FIDO/WebAuthn),
- step-up mechanisms,
- secrets protection,
- logging of critical events.
However, Cridenty is bound by an obligation of means, not of result, meaning that Cridenty undertakes to use commercially reasonable efforts without warranting a specific result.
11. Data and proofs
Cridenty does not store any direct personal data in its exportable proofs.
Messages in clear text are not stored.
When a critical operation requires a technical target identifier to be executed securely, Cridenty applies a minimization strategy: a reduced readable representation for internal audit and notifications, and a hashed verifiable representation for exportable proofs.
Cryptographic proofs are retained for 120 months (10 years).
Production data is hosted within the European Union, unless a specific contractual agreement is made with the customer.
When the customer requires enhanced localization, France-based hosting or a dedicated instance may be contractually agreed.
Upon expiration or termination of the contract, Cridenty returns to the customer, upon request made within thirty (30) days following the end of the contract, the available exportable cryptographic proofs and technical identifiers in a usable format enabling independent verification. After that period, and subject to applicable legal, contractual or evidentiary obligations, data is deleted or anonymized in accordance with the Data Retention Policy.
12. Liability
Cridenty’s liability is strictly limited.
Cridenty shall not be liable for:
- indirect damages,
- loss of business,
- commercial losses,
- the customer’s use of generated proofs.
In any event, Cridenty’s total liability is capped at the amount actually paid by the customer during the preceding twelve (12) months.
This limitation does not apply in cases of gross negligence or willful misconduct, bodily injury, breach by Cridenty of its personal data protection obligations governed by the applicable DPA, or any mandatory liability that the law does not allow to be capped.
13. Intellectual property
The platform, APIs, interfaces and proof/security mechanisms are the exclusive property of Cridenty. No transfer of rights is granted to the customer, except for the strictly necessary right of use.
14. Changes to the TOS
Cridenty reserves the right to amend these TOS to reflect changes to the service, security requirements or regulatory requirements. Substantial changes are communicated with reasonable notice where possible.
Purely technical, editorial, customer-favorable or legally required changes may apply as of their publication.
15. Governing law and jurisdiction
These TOS are governed by French law.
Any dispute shall fall under the exclusive jurisdiction of the courts of Paris, unless otherwise required by mandatory law.