ConnectID End-User Terms

Last material update: September 14, 2026

These terms govern the Identity Service provided to you as an individual customer, member, client or service recipient and are between you, Trinsic Technologies, Inc. (“Company”), and the business identified as the recipient in your ConnectID verification journey (the “Beneficiary”). Company is the Beneficiary’s Representative, authorized to perform ConnectID transactions on its behalf.

1. The Identity Service

1.1 Service and Data. Company participates in ConnectID, a digital identity network that lets you ask organizations with which you have a relationship (“ID Providers”) to provide identity or attribute information, or a verification or assertion about you (“End User Data”), to Company. With your authorization, Company supplies the verification result identified in your journey, including End User Data, to the Beneficiary to support the purpose shown there (the “Identity Service”).

1.2 Transfer. ConnectID facilitates a bilateral transfer from the selected ID Provider to Company (a “Digital Identity Transaction”). ConnectID Pty Ltd or its related bodies corporate within the meaning of the Corporations Act 2001 (Cth) (the “ConnectID Operator”) does not access or hold your End User Data. Company receives the data and delivers the agreed data or result to the Beneficiary, where applicable, through Company’s or Beneficiary’s service providers identified in the respective privacy policy.

1.3 Your Choice. Each Digital Identity Transaction requires your express consent. If you do not consent, the transaction will not occur and the Beneficiary will offer an alternative way to provide the required information or verify your identity without ConnectID. Each approved transaction is a one-off transfer; any additional transactions, even from the same ID Provider, require new consent and a new transaction.

1.4 Availability and Eligibility. The Identity Service must be enabled for the relevant product or service and the ID Provider must hold valid ConnectID accreditation. You must have an enabled digital account with that ID Provider, have verified your identity and core information with it within the previous five years, and meet its minimum age requirements for ConnectID.

2. Your Acknowledgments and Consent

2.1 Reviewing the Data. These terms govern your Identity Service transactions. The ID Provider will ask you to review the End User Data for accuracy and expressly consent to its transfer to Company. When you consent, you also authorize Company to provide the data or result to the identified Beneficiary as described in your journey and these terms.

2.2 Beneficiary Handling. The Beneficiary may collect, use and disclose End User Data for the purpose you consent to in the Identity Service. It may use it for secondary purposes only where you give further consent or applicable Australian privacy legislation, including the Privacy Act 1988 (Cth) and applicable state or territory privacy laws (“Privacy Law”), permits, consistently with its terms, privacy policy and ConnectID restrictions. Those restrictions include limits on sale, profiling, overseas handling and use of ConnectID usage records; consent does not remove them.

2.3 Company Handling. Company uses End User Data to provide the Identity Service to the Beneficiary. Company may retain the minimum End User Data required by applicable law or by ConnectID for audit or compliance, solely for the required period and purpose, and deletes it when such requirement ends. Company will not use your End User Data for any unrelated secondary purposes.

2.4 Responsibility After Transfer. After transfer to Company and the Beneficiary, the ID Provider no longer controls or bears responsibility for the recipients’ security or handling of End User Data. Each recipient’s handling is governed by these terms and its own privacy policy.

2.5 Incident Information. If Company or the Beneficiary experiences a security or data incident affecting your End User Data, you consent to Company collecting incident information from the Beneficiary where applicable and providing information about the incident, including your affected personal information under Privacy Law (“Personal Information”) and End User Data, to the relevant ID Provider. That provider may use it solely to seek to prevent or respond to cybersecurity incidents, fraud, scams or identity theft.

2.6 ID Providers. Company, the Beneficiary, and the ConnectID Operator do not endorse, represent or recommend ID Providers, including the suitability of their security or privacy practices. TO THE MAXIMUM EXTENT PERMITTED BY LAW, COMPANY, THE BENEFICIARY AND THE CONNECTID OPERATOR EXCLUDE LIABILITY FOR ACTS OR OMISSIONS OF AN ID PROVIDER. Company holds the Operator’s exclusions on trust for it, so it may rely on them without being a party. Nothing in these terms excludes a right or remedy that cannot lawfully be excluded.

2.7 Consumer Data Right. These transactions operate separately from requests under the Consumer Data Right scheme. The Identity Service does not make a Consumer Data Right request; any such service offered by the Beneficiary is accessed through its separate Consumer Data Right process.

3. Withholding the Service

Company or the Beneficiary may withdraw or suspend the Identity Service. They or the relevant ID Provider may be unable to process a transaction, including because: (a) the underlying transaction is outside the permitted use; (b) you do not meet eligibility requirements or the ID Provider cannot supply the data; (c) there are reasonable suspicions of fraud or a security incident; (d) Company’s or the Beneficiary’s ConnectID participation is suspended or terminated; or (e) the transaction requires intervention, including because it concerns you as a vulnerable person.

4. Fees

Company and the Beneficiary will not charge you for a Digital Identity Transaction performed in relation to you.

5. Access, Corrections and Fraud

5.1 Your Information. You may request access to or correction of Personal Information held by Company or the Beneficiary using the procedures in its privacy policy. Company’s policy is available at Company Privacy Policy. The Beneficiary’s privacy policy and contact details are identified in your verification journey.

5.2 Separate Records. Updating information with Company or the Beneficiary does not update the ID Provider’s records. Contact the ID Provider separately to update the information it holds.

5.3 Suspected Fraud. If you suspect fraud involving your identity, account or a transaction or Identity Service you did not authorize, notify Company or the Beneficiary as soon as possible using the contacts below.

6. Complaints and Contact

Contact Company at support@trinsic.id, or the Beneficiary at the contact shown in your verification journey, with complaints, disputes or suspected fraud concerning the Identity Service. If the matter concerns an ID Provider’s activities, Company or the Beneficiary may direct you to that provider.