Online ConnectID Beneficiary Terms

Last material update: September 17, 2026

These terms govern the ConnectID services provided by the entity identified in your Participation Agreement (“Company”), acting as your Representative, to the business identified there (“Beneficiary” or “you”). You and Company accept these terms by entering into the ConnectID Participation Agreement.

1. Definitions

1.1ConnectID Operator” means ConnectID Pty Ltd trading as ConnectID.

1.2ConnectID” means its digital identity network.

1.3Network Documentation” means the rules, procedures, specifications and agreements governing Company’s participation with the ConnectID Operator and other Participants.

1.4Representative” means an entity approved by the ConnectID Operator to perform transactions for a Beneficiary.

1.5Participant” means another person participating in ConnectID.

1.6Data Provider” means an identity or attribute provider supplying End User Data through ConnectID.

1.7Participation Agreement” means the ConnectID Participation Agreement accepted by you and Company.

1.8Approved Use” means a use recorded there as authorized for your arrangement.

1.9End User” means your customer, member, client, service recipient or other individual identity owner in a transaction performed for your benefit.

1.10End User Data” means information collected, processed, transmitted, stored or returned in connection with the Identity Service that identifies or relates to an End User, including identity attributes, verifications and assertions. It excludes anonymized and aggregated data that cannot identify an End User.

1.11Personal Information” includes personal or sensitive information under the Privacy Act or comparable privacy law received in connection with this agreement or a transaction, and always includes End User Data.

1.12Privacy Act” means the Privacy Act 1988 (Cth).

1.13Privacy Law” means applicable laws, principles, industry codes, guidelines and policies concerning collection, use, disclosure, storage, protection or access to Personal Information, including the Privacy Act and applicable state or territory privacy laws. References to processing include access, collection, use, disclosure, transfer, storage and other handling.

1.14ConnectID Usage Data” means automatically generated ConnectID transaction records, including timestamps, identities of Company and the relevant Data Provider, proofing level and types of End User Data supplied, but excludes End User Data and metadata about End User Data, such as an attribute’s validation level or last update.

1.15High Risk Attributes” means government-related identifiers under the Privacy Act, including passport, driver license and Medicare details, and attributes designated high risk by ConnectID.

1.16Sanctioned Jurisdiction” means a jurisdiction subject to sanctions or restricted export laws applicable to a Participant, or identified by FATF or AUSTRAC as high risk, under increased monitoring, subject to a call for action, a prescribed foreign country, or a substantially similar or replacement category.

1.17Fraud Incident” means an event or circumstance where fraud is reasonably suspected on an account and Data Provider End User Data assisted in enabling it, or other fraudulent activity connected with the Identity Service.

1.18Security Incident” means an actual or suspected breach of applicable confidentiality, privacy or security requirements, or unauthorized, accidental or unlawful access, use, disclosure, modification, loss or damage affecting Personal Information or End User Data connected with the Identity Service. It includes an eligible data breach under the Privacy Act and incidents notified or required to be notified to a regulator, or potentially compromising the stability, security, reliability, performance or integrity of the Identity Service or ConnectID.

2. Representative Services

2.1 Identity Service. Company agrees to act as your Representative and perform transactions and obtain services through ConnectID for your benefit (the “Identity Service”), subject to completion of the conditions in Section 3. The Identity Service will not begin until ConnectID Pty Ltd approves Company to act as your Representative. You must not transfer the benefit of Company’s Representative services or use the Identity Service for another entity’s benefit, including as a service bureau.

2.2 Main Agreement. If you and Company have an MSA or other services agreement covering the Identity Service (the “Main Agreement”), these terms supplement it solely for the Identity Service. Otherwise, these terms, the ConnectID Participation Agreement, and any mutually executed commercial order form between you and Company (an “Order Form”) govern Company’s Representative services for you.

2.3 Operator Interface. Company acts as the interface between you, the ConnectID Operator and Data Providers. You must provide information, reports, notices and assistance reasonably required for Company to comply with ConnectID requirements or requested by the ConnectID Operator, and consent to their identified disclosure as permitted by Section 7. You must reasonably cooperate with Company and the ConnectID Operator in monitoring, auditing and investigating participation. If you reasonably believe a matter adversely affecting ConnectID’s stability, security, reliability, performance, integrity or reputation will not adequately reach the ConnectID Operator through Company, including because of urgency or sensitivity, you may notify the ConnectID Operator directly.

2.4 Network Rights. You have no rights or powers under the Network Documentation. TO THE EXTENT PERMITTED BY LAW, YOU MUST NOT BRING A CLAIM IN CONNECTION WITH THE NETWORK DOCUMENTATION OR CONNECTID, INCLUDING A CONNECTID TRANSACTION, AGAINST THE CONNECTID OPERATOR OR ANY PARTICIPANT OTHER THAN COMPANY IN ITS CAPACITY AS YOUR REPRESENTATIVE. Your right of action for loss connected with the Identity Service is through Company. Company may seek to enforce the Network Documentation for your benefit, subject to its exclusions and limitations. Company holds the exclusions and limitations in this Section, and the other rights and benefits granted to the ConnectID Operator under these terms, on trust for the ConnectID Operator, which may rely on them although it is not a party.

3. Eligibility, Scope and Certification

3.1 Eligibility. You must at all times: (a) be incorporated, formed or created in or under Australian law and hold a current Australian Business Number, Australian Company Number or Australian Registered Body Number; (b) pass Company’s probity checks; and (c) need to collect End User Data for a purpose reasonably necessary for one or more of your functions or activities. You must comply with applicable conditions imposed by the ConnectID Operator and notified to you. Any exceptions to eligibility must be approved in writing by the ConnectID Operator and apply only to the extent, for the period, and for the entities, expressly stated in that exception.

3.2 Approved Use. You may use the Identity Service only for the approved uses and identified essential or voluntary attributes recorded in the Participation Agreement, and only for your existing or prospective End Users. You must not circumvent controls implementing those restrictions. Changes requiring approval or certification must be completed before the changed use begins.

3.3 Onboarding. The Identity Service starts only after successful completion of all applicable onboarding and certification. You must participate and assist as reasonably required by Company or the ConnectID Operator. The ConnectID Operator determines whether certification requirements have been met.

3.4 Continuing Information. You must keep your participation information accurate and promptly notify Company of a loss of eligibility, breach of these terms, an event requiring suspension under applicable ConnectID requirements notified to you, cessation of participation or other change affecting the arrangement. You must notify Company as soon as possible, and no later than 14 days after becoming aware of an impending or actual change of control or sale of a business participating under the arrangement; where confidentiality obligations prevent disclosure of an impending transaction, notice is required when it occurs. You must provide the Beneficiary-specific records and assistance reasonably required for Company’s annual compliance certification and other required reporting.

4. Operational and End-User Obligations

4.1 Network Conduct. You must not adversely affect ConnectID’s stability, security, reliability, performance or integrity or bring ConnectID or the ConnectID Operator into disrepute. You must maintain effective measures to identify, mitigate and protect against operational risks, including fraud, and appropriate security and data protection processes, policies and controls protecting End User Data and ConnectID Usage Data. You must comply with laws applicable to your performance and valid directions, determinations, requests, conditions and requirements imposed under the Network Documentation and notified by Company or the ConnectID Operator. You must promptly notify and consult Company if a regulatory authority contacts, audits or investigates you in connection with participation.

4.2 Fraud. Except to the extent prohibited by law, you must immediately alert Company on becoming aware of a Fraud Incident and provide further information reasonably requested. You must take reasonable steps to minimize further fraud, monitor affected accounts, delete End User Data obtained in connection with the Fraud Incident, and assist Company and the ConnectID Operator with required investigation and reporting. The immediate alert obligation is separate from the security-incident deadline in Section 6.

4.3 End-User Terms. Before an End User’s first transaction, you must enter into an agreement with that End User using either: (a) Company’s ConnectID End-User Terms, with you identified as Beneficiary in the verification journey; or (b) the completed Annex 1 to the ConnectID PST, published on your website as a standalone ConnectID end-user terms page. The agreement must identify and bind both you and Company, be presented for the End User’s affirmative acceptance, and be accompanied by links to both parties’ privacy policies. Company must present the agreement and record the End User’s acceptance and the version accepted when Company hosts the acceptance screen; when you or your intermediary hosts that screen, you must do so or contractually require your intermediary to do so. The same process applies before the next affected transaction whenever a material change requires renewed agreement. You authorize Company to enter into the agreed end-user terms in your name, and Company authorizes you to do so in its name, solely using the agreed text and completed particulars. You must take reasonable steps to ensure End Users comply. In addition to obtaining agreement to those terms, you must obtain the End User’s express consent for each transaction under Section 5.2.

4.4 Support and Charges. You must promptly respond to and use reasonable efforts to investigate and resolve End User complaints, disputes, enquiries and support requests concerning the Identity Service, and keep the End User adequately informed of progress. You must not charge End Users for your use of the Identity Service. You must not make a warranty or representation about ConnectID, the ConnectID Operator or a Participant in connection with your goods, services or the Identity Service.

4.5 Subcontractors. If you engage a person, including your intermediary, to perform an Identity Service obligation, you must bind it to the obligations applicable to its functions and remain responsible for your own obligations. You must provide the relevant arrangements and reasonable assistance needed for Company to meet its subcontractor obligations to ConnectID, including reasonable cooperation with direct Operator communications. Any recipient of or person permitted access to End User Data must have contractual obligations at least as protective of that information and End User privacy as these terms, including compliance with the Privacy Act and Australian Privacy Principles as if subject to them, purpose limitations, and applicable overseas-disclosure requirements under Australian Privacy Principle 8.

5. Privacy, Consent and Data Restrictions

5.1 Privacy Compliance. You must comply with the Privacy Act as if subject to it and, if permitted, opt in and remain on the OAIC opt-in register. You must not cause Company, the ConnectID Operator or a Data Provider to breach Privacy Law. Except where prohibited by law, you must promptly notify Company of a formal or material privacy complaint and follow its reasonable directions concerning the Identity Service. You must maintain a public privacy policy expressly covering your participation, use of the Identity Service and End User Data.

5.2 Minimum Data and Choice. You may request only the minimum End User Data reasonably necessary for the Approved Use. If an End User does not consent, you must provide an alternative process for receiving your service without the Identity Service. You warrant and represent for the Data Provider’s benefit that any consent wording you supply for presentation is current and accurate and accurately describes your primary collection purpose, consistent with the Approved Use and these terms. Each transaction requires the End User’s express consent to the disclosed purpose, requested data and recipients; a previous transaction does not authorize another transfer.

5.3 End User Data Purposes and Retention. Subject to Sections 5.4–5.6, you may store, retain and use End User Data for the primary purpose disclosed in the transaction consent, and store, retain, use and disclose it for secondary purposes only consistently with Privacy Law, your privacy policy and these terms. Retention, destruction and de-identification must comply with applicable law. Company must delete End User Data after delivering the agreed data or result unless you or your intermediary have configured a retention period for your service. Any configured retention must be permitted by ConnectID, documented in the service configuration made available to you, and end no later than the configured period, or earlier if ConnectID or applicable law requires. Company may retain the minimum End User Data required by applicable law or by ConnectID for audit or compliance, solely for the required period and purpose, and must delete it when the requirement ends.

5.4 ConnectID Usage Data. You may use or disclose ConnectID Usage Data only for the Identity Service, legal compliance, or fraud identification or prevention. You must not use or disclose it to analyze, evaluate, predict or attempt to analyze, evaluate or predict a person’s personal or behavioral characteristics, or otherwise profile a person, including for credit scoring, risk assessment, refusal of services or differential pricing. Company is subject to the corresponding Network Documentation restrictions, including the limited permission for aggregated insights used only for governance of and participation in ConnectID.

5.5 Prohibited Activities. Regardless of consent, you must not: (a) sell, hire out or assign rights in End User Data; (b) use it for analytical or statistical purposes unless de-identified so it no longer contains End User Personal Information; (c) use it in a manner intended or likely to adversely affect the End User, Company, the ConnectID Operator, ConnectID, the Identity Service, a Participant or Beneficiary, without limiting use in disputes, debt recovery, court proceedings or enforcement of rights; or (d) use it to analyze, evaluate, predict or attempt to analyze, evaluate or predict a person’s personal or behavioral characteristics or otherwise profile a person, including for credit scoring, risk assessment, refusal of services or differential pricing, except as expressly permitted by the ConnectID Procedures for fraud management.

5.6 Overseas Handling. You may disclose, transfer, store or permit access to End User Data outside Australia only in compliance with Privacy Law and Australian Privacy Principle 8 as if subject to it, and never in or from a Sanctioned Jurisdiction. If a location becomes prohibited, or data has otherwise been handled there, you must promptly stop that handling, relocate the data and take reasonable steps to ensure it is no longer processed or retained there.

5.7 Higher Privacy Standard. To the extent these terms, the Main Agreement, an applicable data processing agreement or applicable Privacy Law conflict, the provision providing the higher or more stringent privacy protection applies to End User Data and ConnectID Usage Data. The parties must still comply with mandatory requirements of applicable law and standard contractual clauses.

6. Security Incidents

6.1 Notification and Response. Except to the extent prohibited by law, when you become aware of reasonable grounds to believe or suspect a Security Incident, you must promptly, and within 24 hours, notify Company through the security contact in the Participation Agreement. You must provide information, cooperation and assistance reasonably required, including the nature and extent, affected data types and affected Participants; expeditiously investigate its nature, extent and cause; promptly take reasonable steps to stop and mitigate loss, interference and harm; remediate weaknesses to prevent recurrence; and keep Company informed of assessment and remediation status and outcomes. Company acts as the interface with the ConnectID Operator and affected Participants, without preventing agreed direct interaction.

6.2 High Risk Attributes. Except where prohibited by law, if High Risk Attributes are compromised you must provide Company with details of each affected End User and compromised attribute types for delivery to the relevant Data Provider solely to prevent or respond to cybersecurity incidents, fraud, scams or identity theft. You must reasonably assist affected Data Providers, through Company or agreed direct contact, with identity protection and restoration.

6.3 Required Notices. You and Company will agree responsibility for legally required notifications; generally you are responsible if your system is directly involved. Neither party is prevented from meeting its own legal duties. Where required by applicable ConnectID rules, you must apply the Notifiable Data Breaches Scheme as if subject to it notwithstanding a different state or territory privacy regime. Where Rules Section 14.3(d) applies, you must also notify the relevant State or Territory privacy or information commissioner at the same time as any required notification to the OAIC.

6.4 Other Participants and Operator Incidents. If another Participant’s incident may affect you, Company may notify you and you must reasonably assist the impact assessment. If Company becomes aware of reasonable grounds to believe or suspect an incident involving your supplied Personal Information held by the ConnectID Operator, Company will promptly notify you and relay relevant information it receives. In relation to such an incident involving Personal Information supplied by you and held by the ConnectID Operator, you must not make an announcement or notify a regulator or affected person identifying ConnectID or the ConnectID Operator without Company’s prior written consent, and must give the ConnectID Operator an opportunity to review and comment on required statements or notices. Nothing here prevents a legally required notification. Incident information supplied for response must be used and disclosed only as permitted by applicable law and ConnectID requirements.

7. Information and Confidentiality

7.1 Permitted Information Sharing. Company may provide information about you, End Users and this agreement, including Personal Information and confidential information, to the ConnectID Operator and other Participants as permitted by the Network Documentation, including for incidents and fraud. You consent and must make necessary disclosures and obtain relevant consents and approvals enabling those recipients to process, publish and hold the information in connection with their business and ConnectID as permitted by law and the Network Documentation. This includes Operator analytics and developing, improving and supporting ConnectID and its related bodies corporate’s products and services, including fraud prevention, risk management and response to incidents and scams. This clause does not authorize disclosure of End User Data to the ConnectID Operator or Personal Information in ConnectID Usage Data, or override any other Network Documentation restriction on information provided to it or a Governing Body.

7.2 Protected Information. You may receive confidential information of Company, the ConnectID Operator, another Participant or another person in connection with ConnectID (each a “Disclosing Party”), including Network Documentation. You acknowledge its value, must keep it confidential, may use it only to perform obligations or exercise rights under this agreement, and may disclose it only as permitted by this agreement or required by law. Where lawful, you must notify Company before a legally compelled disclosure and limit it to what is required. You may disclose to a subcontractor only as necessary for its authorized functions and under equivalent confidentiality obligations. You may disclose Confidential Information to your personnel and professional advisers who need to know it for this agreement, provided they have agreed to confidentiality obligations no less protective than this Section. This Section does not restrict any use or disclosure of End User Data disclosed to you by Company that is otherwise permitted under Section 5.

7.3Confidential Information” includes information in any form, whether disclosed before or after this agreement, that is confidential by nature, designated confidential or reasonably understood to be confidential. It excludes information that enters the public domain without breach, is obtained from a third party without a confidentiality obligation, or is independently developed or obtained without breach.

8. ConnectID Materials and Marks

8.1 Materials. Ownership of the ConnectID platform, Network Documentation and other documentation, data or information provided by the ConnectID Operator, including modifications, improvements and derivative works (together, “ConnectID Materials”), remains with the ConnectID Operator. You assign to Company for assignment to the ConnectID Operator any rights you have or obtain in those materials immediately on creation, including by future assignment of copyright. You receive a nonexclusive, revocable, royalty-free, nontransferable license to use the documentation solely to perform this agreement during its term. This assignment does not extend to your separate technology or data merely because it interfaces with ConnectID.

8.2 Licensed Marks. Company grants you nonexclusive, revocable, royalty-free, nontransferable licenses to use marks made available to you: (a) ConnectID Operator marks solely to advertise participation in and promote ConnectID in connection with this agreement; (b) Data Provider names and main trading logos solely to identify them as potential providers for a proposed transaction; and (c) Company’s marks solely for this agreement. Each use must follow this agreement and the relevant communicated brand guidance.

8.3 Beneficiary Marks. You grant Company a nonexclusive, revocable, royalty-free, nontransferable license to use your name and main trading logos for the Identity Service and to sublicense them to Data Providers solely to identify you to the End User for a proposed transaction for your benefit, and to the ConnectID Operator for administration, operation and promotion of ConnectID. You consent to the Operator using your name and main trading logo in customer and participant lists and promotional activities associated with ConnectID.

8.4 Sublicensing. You may sublicense licensed marks only to a subcontractor solely to provide services to you under this agreement; no further sublicensing is permitted. You must take all reasonable steps and use best endeavors to ensure permitted use, prevent onward unauthorized use, and ensure use ceases when the sublicense is no longer permitted, and take appropriate steps to prevent unauthorized or inappropriate use.

8.5 Restrictions and Cessation. You must not adopt ConnectID or an Operator mark as your business name or apply it to your goods or services. Neither you nor a sublicensee may use licensed marks in a manner likely to imply that your goods or services are endorsed, produced, offered or sold by the Operator or a Data Provider, violate law, or adversely affect their reputation or the marks’ value or validity. All licenses to documentation and marks cease immediately on termination. You must cease use, cause sublicensees to cease use, and destroy materials bearing the licensed marks as soon as practicable as required for offboarding.

9. Monitoring and Audit

9.1 Operator Rights. You permit the ConnectID Operator or its nominee to monitor, audit, access, inspect and copy your performance of the applicable ConnectID obligations and relevant agreements, arrangements and undertakings with Company or subcontractors to verify compliance or meet applicable law, accreditation requirements or supervisory requests. This right does not include the separate general audit of Resources in ConnectID Rules Section 12(a)(ii). You must fully cooperate and provide the assistance, access to premises and personnel, information and documents reasonably requested in the exercise of Operator monitoring, compliance, investigation and fraud-management rights under Rules Sections 12, 17.1, 17.3 and 18.2 and Procedures Section 2.4, as applied to Beneficiaries by Rules Section 6.4 and subject to the applicable source protections, including Section 9.2 for audits.

9.2 Audit Protections. Ordinary audits require at least 14 days’ notice and reasonable endeavors to occur during normal business or operating hours. They occur no more than once a year unless noncompliance is reasonably suspected or likely, or a prior audit revealed material noncompliance. These notice and frequency restrictions do not apply to an audit connected with a Security Incident or required for law, accreditation or supervisory requirements. Access or disclosure prohibited by law is not required. The Operator or nominee must follow reasonable security and workplace safety policies and use reasonable endeavors to minimize disruption. Each bears its own costs, except that you must reimburse Operator audit costs, including auditor fees, if noncompliance found is not trivial or immaterial. These specific rights apply independently of ordinary audit limits in a Main Agreement.

9.3 Insurance Information. Company is required to maintain insurance coverage in connection with its participation in ConnectID and its performance of the Representative services, including coverage that may vary based on the nature and scale of its activities as a Representative and the number of Beneficiaries it supports. On Company’s reasonable request, and in any event no less than annually, you must provide Company with information reasonably necessary for Company to assess and maintain that insurance coverage, including your expected or actual ConnectID transaction volumes, the types of End User Data or Attributes requested under your Approved Use (including any High Risk Attributes), and annual turnover figures where applicable. You must promptly notify Company of any material change to that information between requests.

10. Changes, Suspension and Offboarding

10.1 Required Updates. Company may update these terms to reflect changes required by the Network Documentation and the services, features or functionality used in the Representative arrangement. Company will provide the updated terms and notice through the designated notice contact at least 30 days before they take effect unless ConnectID or law requires a shorter period. The notice must identify the change and effective date. Continued affected use after that date constitutes acceptance. If you do not accept, you may stop the Identity Service before that date; Company may not continue the affected Representative arrangement on noncompliant terms. Commercial consequences under a separate services agreement remain governed by it.

10.2 Suspension or Termination. Company may suspend or terminate the affected Identity Service and Representative arrangement, including immediately, when the ConnectID Operator exercises its rights against Company or you, or when Company must cease the arrangement under ConnectID requirements, including loss of eligibility or a noncompliant arrangement. Company will promptly notify you. A suspended Beneficiary may not participate in ConnectID in any capacity until suspension is revoked. Company will enable resumption after the Operator’s applicable reinstatement requirements are satisfied. Re-entry after termination requires the applicable eligibility and onboarding process unless the Operator agrees otherwise.

10.3 Offboarding. On cessation you must stop affected transactions and access, including access by personnel and subcontractors, cease representations of current participation, and cooperate with Company’s required offboarding, records and notifications. Sections 5–7 continue to govern retained information; no general backup or archival exception expands a permitted retention period. Accrued rights and liabilities and provisions needed to address an earlier breach or protect retained information survive. Either party may end the Representative arrangement by written agreement or through an applicable termination right under the Main Agreement or Participation Agreement.

11. Contract Administration

11.1 Administration. Where there is a Main Agreement, its notices, governing law and general contract-administration terms continue to apply, subject to these terms and mandatory law. Otherwise, notices go to the contacts in the Participation Agreement; electronic signatures and counterparts are effective; and these terms, the Participation Agreement and any applicable Order Form constitute the entire agreement solely for the Representative arrangement. A waiver must be in writing; an unenforceable provision is severed to the extent necessary without affecting the remainder.

11.2 Governing Law Without a Main Agreement. If no Main Agreement applies, the laws of the State of Delaware govern these terms, without reference to its choice-of-law rules, and the parties submit to the exclusive jurisdiction of the state or federal courts in Delaware. This choice does not displace mandatory Australian privacy or other applicable legal requirements.