The agreement
These terms govern access to Regulated, a product operated by InsurSystems Limited (company number 17254443). They apply to the website, hosted platform, developer portal, APIs, webhooks, screening certificates and related services.
If your organisation has an order, accepted commercial proposal, data-processing agreement or enterprise agreement, those documents form part of the contract and take priority where they expressly conflict with these terms. By creating an account or using the service, you confirm that you have authority to act for your organisation.
The service
Regulated provides tools for company and individual screening, regulatory monitoring, sanctions and PEP checks, ownership analysis, adverse-media review, alerts, investigations, evidence provenance, certificates, reporting and workflow automation. Available features, sources, limits and environments depend on the customer’s plan and approved entitlements.
Test access is for integration and evaluation. Live access may require onboarding approval, successful testing, accepted agreements and valid payment arrangements.
Accounts and security
Customers must provide accurate information, maintain authorised users and roles, enforce appropriate authentication, protect passwords and API credentials, and promptly revoke access that is no longer needed. Credentials must not be shared between organisations or embedded in public code.
You must notify us promptly of suspected compromise, unauthorised access or incorrect tenant access. We may require password resets, key rotation, MFA or other proportionate security steps.
Permitted and prohibited use
You may use Regulated for lawful business compliance, onboarding, due-diligence, risk and monitoring purposes within your agreed limits. You must have a lawful basis for personal-data processing and provide required notices.
You must not use the service to harass, discriminate unlawfully, make unsupported allegations, conduct indiscriminate surveillance, breach sanctions or export controls, evade security controls, scrape the service, resell data without permission, reverse engineer restricted components, upload malicious content or interfere with other tenants.
Screening results and decisions
Matches, risk scores, confidence values, alerts and automated rules are decision-support signals. They are not legal advice, regulatory approval, a guarantee of identity, or proof that a person or organisation is sanctioned, politically exposed, unsuitable or engaged in wrongdoing.
Customers remain responsible for human review, identity resolution, source verification, proportionality, documented rationale and final decisions. A “clear” result means no match was identified in the sources checked at that time; it is not a guarantee about information outside those sources.
Customer data and privacy
Customers retain their rights in data submitted to the service and authorise us to process it to provide, secure and support Regulated. Each party must comply with applicable data-protection law. Where we process customer personal data as processor, the data-processing agreement applies.
Customers must minimise personal data, avoid unnecessary full dates of birth or sensitive information, configure appropriate retention, respond to data-subject requests and ensure their integrations and users only access information they are authorised to receive.
Third-party sources and integrations
Regulated depends on public registers, regulators, sanctions authorities, news publishers, data providers, payment processors and infrastructure services. Source availability, coverage, licensing, formats and update frequency can change without our control.
We may replace or discontinue a source where necessary and will seek to communicate material reductions in service. Third-party content remains subject to its source terms and intellectual-property rights.
Plans, credits and payment
Fees, included credits, usage costs, overages, top-ups, commitment periods and renewal terms are shown in the selected plan or commercial proposal. Unless stated otherwise, fees exclude VAT and are charged through the configured billing provider.
Usage is measured by Regulated’s service records. Credits have no cash value, cannot be transferred between tenants and expire only as stated in the applicable offer. Completed screening or provider costs are generally non-refundable. Billing disputes must be raised promptly with the relevant evidence.
Failed payment may restrict paid features or live API access. Cancellation takes effect according to the applicable plan, commitment and notice period; it does not cancel amounts already due.
Availability and changes
We aim to provide a reliable service but do not promise uninterrupted or error-free operation. Maintenance, incidents, provider outages, rate limits and legal restrictions may affect availability. Any specific service level applies only where agreed in writing.
We may update the service to improve security, compliance, performance or functionality. We will give reasonable notice of a material change that significantly reduces contracted functionality where practicable.
Intellectual property
Regulated, its software, design, models, documentation and service-generated structure are owned by or licensed to InsurSystems Limited. Customers receive a limited, non-exclusive, non-transferable right to use the service during the contract.
Customers may retain and use their exported records and valid screening certificates for internal compliance, policy and audit purposes. Feedback may be used to improve the service without identifying confidential customer information.
Confidentiality
Each party must protect the other’s confidential information using reasonable care and use it only for the contract. This does not cover information that is public without breach, already lawfully known, independently developed or lawfully received from another source. A party may disclose information where legally required, where permitted giving notice when lawful.
Responsibility and liability
Nothing in these terms excludes liability that cannot lawfully be excluded, including liability for death or personal injury caused by negligence, fraud or fraudulent misrepresentation.
Subject to that, neither party is responsible for indirect or consequential loss, or loss of profit, revenue, goodwill or anticipated savings. Our aggregate liability is limited to the fees paid or payable for the affected service during the 12 months before the event, unless a signed agreement states a different cap.
Customers are responsible for losses arising from unlawful instructions, unsupported decisions, misuse of credentials, unauthorised integrations or data they had no right to submit.
Suspension and termination
We may suspend access where reasonably necessary to address security risk, illegality, sanctions exposure, material misuse, non-payment or a serious breach. Where appropriate, we will explain the reason and steps required to restore access.
On termination, access ends and outstanding amounts become due. Customers should export required records before termination. We will return or delete customer data in accordance with the contract, retention requirements and backup cycle.
General terms
Neither party is liable for delay caused by events beyond its reasonable control. A failure to enforce a right is not a waiver. If part of the agreement is unenforceable, the remainder continues. Customers may not transfer the agreement without consent; we may transfer it as part of a corporate reorganisation or sale where customer protections are not materially reduced.
We may update these public terms for legal, security or service reasons. Material changes affecting an active paid contract will be notified and apply as stated in that notice or at renewal, unless earlier application is required by law.
Governing law and contact
These terms and any non-contractual dispute are governed by the laws of England and Wales. The courts of England and Wales have exclusive jurisdiction, unless a signed agreement provides otherwise.
InsurSystems Limited is registered at 21 Bryn Eglur Road, Morriston, Swansea, SA6 7PG. Service questions can be sent to [email protected]; privacy enquiries to [email protected].