Comms.ID Relying Party Agreement

Last Updated: 14 July 2026 Version: 1.0.3

This Relying Party Agreement ("Agreement") is a binding legal contract between Comms.ID Pty Ltd (ACN: 686 963 904), a company incorporated in Queensland, Australia ("Comms.ID," "we," "us," "our"), and the entity registering to use the Comms.ID platform as a Relying Party ("Relying Party," "you," "your").

For identity services that may involve the Australian Government's Document Verification Service (DVS), a Relying Party is an ID Service Client.

By registering a client, integrating with our platform, or using the Comms.ID Services, you agree to be bound by the terms and conditions of this Agreement.

1. The Comms.ID Ecosystem and Our Commitment

Comms.ID provides a secure digital identity platform ("Platform" or "Services") designed to combat fraud and build digital trust. Our Platform operates in alignment with the Australian Government Digital ID System (AGDIS).

1.1. Voluntary Alignment with AGDIS: AGDIS is a voluntary accreditation scheme. While Comms.ID is on the journey to achieve formal accreditation, we have built our Platform from the ground up to adopt and conform to all relevant aspects of the AGDIS framework, including the Digital ID Act 2024, associated Rules, Data Standards, and the Privacy Act 1988. We aim to meet and exceed the best practices and legal requirements of the AGDIS framework. Our commitment to these standards is unwavering regardless of our accreditation status.

1.2. Interoperability and Separation of Roles: The AGDIS framework is designed for interoperability. This separation of roles (Identity Service Provider, Attribute Service Provider, Identity Exchange) is a fundamental requirement of the system's design to enhance privacy and security. While Comms.ID currently provides an integrated ecosystem, our architecture anticipates future interoperability with other accredited providers. This Agreement governs your use of our Platform within this framework.

2. Registration and Onboarding

2.1. Dynamic Client Registration (DCR): You may register to use the Services through our automated DCR process. You warrant that all information provided during registration is true, accurate, and complete.

2.2. ID Service Client Eligibility: You warrant at registration and throughout your use of the Services that:

(a) You are a legal entity whose identity has been established by Comms.ID.

(b) You carry on business in Australia or New Zealand and are subject to Australian or New Zealand civil and criminal laws.

(c) You are subject to the Privacy Act 1988 (Cth), the Privacy Act 2020 (New Zealand), or a prescribed Australian state or territory privacy law. If you are not subject to one of those laws, you agree to comply with the Australian Privacy Principles as though you were an APP entity.

(d) You use the Services on your own behalf only and not as an agent for another person.

(e) You meet and will continue to comply with all DVS access criteria applicable to an ID Service Client.

(f) You will promptly notify Comms.ID of any change to your legal identity, business status, applicable privacy-law coverage, authority to act only on your own behalf, DVS eligibility, or the verified identity or authority of relevant representatives.

2.3. Vetting and Approval: We reserve the right to vet any Relying Party and verify its continuing eligibility. For certain high-risk scopes, such as aml/ctf, registration will result in a "Pending Review" status. We may require you to provide additional information, including evidence of your compliance with applicable laws (such as your Anti-Money Laundering and Counter-Terrorism Financing Program). We retain the absolute discretion to approve, reject, suspend, or revoke your access to any or all Services to protect the integrity of our Platform and its users and to comply with DVS requirements.

2.4. ID Service Client Register: Where your use of the Services may involve the DVS, you authorise Comms.ID to include your legal identity, business details, and the verified identity and authority of relevant representatives in its current register of ID Service Clients and to provide that information to the Gateway Service Provider or Framework Administrator for DVS access management, compliance, and audit purposes.

3. Your Obligations as a Relying Party

3.1. Compliance with Laws: You warrant that you will use the Services in full compliance with all applicable laws, including applicable privacy law and, where applicable, the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (AML/CTF Act). Where section 2.2(c) requires you to comply contractually with the Australian Privacy Principles, that obligation applies as though you were an APP entity.

3.2. Data Handling and User Consent: You acknowledge and agree that:

(a) You may request only personal information and consents that are reasonably necessary to deliver your service. Every consent you request must be required for that service; you must not request optional additional information. An individual may accept all required consents or decline them and not receive your service.

(b) Where "Access Only" applies, relevant Comms.ID identity-system records remain within the Comms.ID ecosystem and may be viewed only through the controlled environment provided for authorised manual review or compliance activity. You must not scrape, copy, or otherwise store those records. "Access and Duplicate" is limited to information needed to personalise your application—commonly the individual's name and avatar or profile image—not Comms.ID identity-system records.

(c) You are solely responsible for how you handle, store, and secure any personal information that a user consents to duplicate to your systems, and you must do so in accordance with the Privacy Act.

(d) Where an identity service may involve the Document Verification Service, you authorise Comms.ID to provide the required DVS disclosures and obtain and retain the individual's specific, one-off express consent for each DVS transaction on behalf of both Comms.ID and you as the ID Service Client. The consent record maintained by Comms.ID is the record for both parties. You must not bypass, suppress, alter, or treat any other consent as satisfying this DVS consent process.

(e) Identification Information collected for a DVS transaction may be used or disclosed only for that DVS check, the requested identity service, and applicable legal obligations. You must not use or disclose it for profiling or behavioural tracking, offering, advertising or promoting goods or services, enabling another person to do those things, or market research. This restriction does not prevent you from using Comms.ID's Identity Opinion or separately consented attributes to deliver your service.

(f) You must describe any result supplied to you only as Comms.ID's Identity Opinion or verification or authentication outcome. You must not represent it as a DVS match, pass, or result, imply that you have direct access to the DVS, attempt to infer the underlying DVS result, or enable another person to do so.

3.3. Security and Incident Notification: You are responsible for securely managing your client credentials, API keys, and access to the Platform. You must immediately notify Comms.ID of any known or suspected unauthorised access to or use of the Services or relevant systems, or any loss, modification, disclosure, or compromise of information relating to the identity service. You must preserve relevant evidence and cooperate with containment, investigation, notification, and remediation.

3.4. Fair Use Policy: You agree to abide by our Fair Use Policy. We reserve the right to monitor usage and suspend or limit your access if your use is deemed fraudulent, malicious, or so excessive that it degrades the performance and availability of the Platform for other users.

3.5. DVS Compliance Audits: You must cooperate with audits or verification activities conducted by Comms.ID, the Gateway Service Provider, the Framework Administrator, or their authorised auditors to verify compliance with DVS requirements. On request, you must provide prompt access to records, systems, premises, and facilities relevant to your use of the identity service. Audit access must be limited to what is relevant to DVS compliance and may be provided through controlled evidence, supervised access, or a dedicated auditor view. Where Comms.ID provides auditor access, the auditor must verify their identity and authority and comply with applicable auditor-access terms.

3.6. DVS Point of Contact: You must direct all questions, complaints, and incidents relating to the Comms.ID identity service or its use of the DVS to Comms.ID as the sole point of contact. You must not seek to involve the Gateway Service Provider or Framework Administrator on an individual's behalf unless directed by Comms.ID, required for an authorised audit, or required by law.

4. Fees and Payment (For Subscribed Services)

4.1. Basic Service: Access to our core identity verification services may be provided free of charge, at our discretion.

4.2. Subscribed Services: Access to certain features and scopes (e.g., aml/ctf compliance solutions) requires a paid subscription ("Subscribed Services"). Fees for Subscribed Services will be based on your chosen subscription tier and are payable monthly in advance.

4.3. Payment Terms: You agree to pay all applicable fees in a timely manner. We reserve the right to suspend access to Subscribed Services for non-payment. Fees are non-refundable except as required by law.

5. Intellectual Property

We grant you a limited, non-exclusive, non-transferable, revocable license to access and use our Platform and integrate with our APIs solely for the purpose of receiving the Services as permitted by this Agreement. We retain all right, title, and interest in and to the Comms.ID Platform.

6. Confidentiality

You may have access to confidential information relating to our Platform. You agree to keep such information confidential and not disclose it to any third party without our prior written consent, except as required by law.

7. Disclaimer and Limitation of Liability

7.1. Disclaimer: Except as expressly stated in this Agreement, the Services are provided "as is" and "as available." We make no warranties, whether express, implied, or statutory, regarding the Services.

7.2. Limitation of Liability: To the fullest extent permitted by law, Comms.ID's total aggregate liability to you for any and all claims arising out of or in connection with this Agreement or the use of the Services shall not exceed:

(a) For the Basic Service (free of charge), the amount of one hundred Australian dollars (AUD $100.00).

(b) For Subscribed Services, the total fees paid by you to us in the twelve (12) months immediately preceding the event giving rise to the claim.

7.3. Exclusion of Damages: In no event will Comms.ID be liable for any lost profits, revenue, or data, or for any indirect, special, consequential, or punitive damages.

7.4. Framework Administrator Benefit: The disclaimers, exclusions, and limitations of liability in this Agreement are also for the benefit of the Australian Government entity responsible for administering the DVS (the "Framework Administrator"). They may be directly enforced by the Framework Administrator or by Comms.ID on its behalf.

8. Term and Termination

8.1. Term: This Agreement commences on the date you first use the Services and continues until terminated.

8.2. Termination: We may suspend or terminate this Agreement and your access to the Services immediately if you breach any term of this Agreement. You may terminate this Agreement at any time by ceasing all use of the Services and de-registering your client.

8.3. Survival: Provisions of this Agreement that by their nature should survive termination will remain in effect, including sections on Confidentiality, Intellectual Property, Limitation of Liability, and Governing Law.

9. General

9.1. Governing Law: This Agreement is governed by the laws of Queensland, Australia. Both parties agree to submit to the exclusive jurisdiction of the courts of Queensland.

9.2. Future Services: We may introduce new services or features (such as configurable AI agents). Your use of such new services may be subject to additional terms and fees, which you must agree to before use.

9.3. Entire Agreement: This Agreement constitutes the entire agreement between you and Comms.ID regarding your use of the Services as a Relying Party and supersedes all prior agreements.

Document integrity hash:

34db1028e535f24ec29259b8f2b8f15860a99202b80ad8a71219a41e11a5c8d7