1. Introduction and Acceptance of Terms
These Terms of Service, Privacy Policy, and Data Use Agreement (collectively, the "Agreement") govern access to and use of the ASGARD identity verification and participation monitoring platform (the "Platform" or "Service").
This Agreement is entered into between ASGARD ("Company," "we," "us," or "our") and the organization that has engaged the Company's services ("Client"). Individuals accessing or using the Platform through a Client deployment ("Participants" or "Users") are also subject to the terms and conditions set forth in this Agreement.
The Client is responsible for ensuring that its Participants are informed of and consent to the applicable provisions of this Agreement where required by law.
This Agreement is designed to comply with applicable privacy and data protection laws globally, including but not limited to GDPR, PIPEDA, CCPA/CPRA, BIPA, FERPA, HIPAA, and other applicable privacy laws.
2. Description of the Platform and Services
The Platform is a browser-based Software-as-a-Service (SaaS) application that provides identity verification and participation monitoring for online training sessions.
The Platform:
- Verifies the identity of Participants using government-issued identification documents
- Monitors Participant engagement during training sessions
- Generates a digital record attesting to verified participation and completion
- Restricts access to training content in the event of detected non-compliance
The Platform operates entirely through a web browser and does not install software or modify user device configurations.
3. Identity Verification
Participants are required to present a valid government-issued photo identification document during onboarding.
The Company utilizes automated AI-powered identity verification technology and proprietary biometric matching methodologies for identity validation.
Government-issued ID images are processed in real time and are not retained after verification processing is complete.
The Company does not sell, trade, or commercially exploit biometric data.
4. Data Collection and Use
The Platform may collect and process:
- Full name
- Email address
- Training completion information
- Participation timestamps
- Proprietary biometric matching data
- A photo of the Participant's face
The Platform does not retain government-issued ID images or raw biometric measurements.
Data is collected solely for:
- Identity verification
- Participation monitoring
- Training completion verification
- Client compliance and recordkeeping obligations
5. Data Storage, Security, and Retention
All data is stored within Amazon Web Services (AWS) infrastructure in regions selected by the Client.
The Company utilizes commercially reasonable security measures including:
- Encryption in transit and at rest
- Access controls
- Security monitoring
- Incident response procedures
Retention periods are controlled by the Client unless otherwise required by law.
6. Data Sharing and Third Parties
The Company does not sell or share Participant data for advertising or marketing purposes.
Data may only be disclosed:
- Upon Client instruction
- To contracted infrastructure providers
- Where legally required
7. Acceptable and Lawful Use
The Platform may only be used for lawful purposes.
The Company may suspend or terminate access where use:
- Violates applicable laws
- Compromises Platform security or integrity
- Involves fraudulent or unlawful activity
8. Service Availability, Support Commitments, and Service Credits
8.1 Service Availability Commitment
ASGARD shall use commercially reasonable efforts to maintain Platform availability of 99.99% uptime measured on a monthly basis.
The Company maintains redundant infrastructure, failover systems, and operational safeguards designed to minimize or eliminate disruption to Client operations.
8.2 Maintenance and Operational Architecture
The Platform has been architected and deployed in a manner intended to allow maintenance, updates, upgrades, patches, security enhancements, infrastructure modifications, and operational improvements to occur without interruption to Client access or Platform availability.
The Company utilizes redundant systems, failover infrastructure, rolling deployment methodologies, and operational redundancies intended to permit maintenance and operational changes to be performed while the Platform remains operational.
Where maintenance activities are anticipated to materially impact Platform availability, the Company shall use commercially reasonable efforts to provide advance notice to affected Clients.
8.3 Exclusions from Uptime Calculations
The following events shall not be considered downtime:
- Force majeure events
- AWS or third-party infrastructure outages
- Internet service provider failures
- Client-caused interruptions
- Cybersecurity attacks or denial-of-service events
- Security preservation activities
- Beta or testing environments
8.4 Service Credits for Downtime
If the Company fails to meet the Availability Commitment during a calendar month, the Client shall receive service credits in the form of additional licenses.
Credits shall be calculated using:
- The Client's rolling twelve (12) month average license consumption; and
- The duration of verified downtime.
The average license utilization rate shall be calculated by dividing total license consumption during the previous twelve months by the total number of minutes during that same period.
The resulting average per-minute utilization rate shall be multiplied by the verified downtime duration to determine the number of additional licenses to be added to the Client account.
Service credits:
- Shall be fully proportional to downtime duration
- Shall not be subject to a monthly cap
- Shall constitute the sole remedy for uptime claims
8.5 Support Response Expectations
Severity Level 1 — Critical Service Impact
Target Initial Response Time: Within one (1) hour
Severity Level 2 — Major Functional Impact
Target Initial Response Time: Within four (4) business hours
Severity Level 3 — Minor Functional Impact
Target Initial Response Time: Within one (1) business day
Response times are targets only and are not guarantees of resolution within a specific timeframe.
9. Educational Records and FERPA
Where deployed within educational environments, the Company acts as a school official with legitimate educational interest under FERPA.
Client institutions remain responsible for FERPA compliance obligations.
10. Healthcare Contexts and HIPAA
The Company does not intentionally collect Protected Health Information (PHI).
Healthcare-sector Clients remain responsible for ensuring HIPAA-compliant deployment and use.
11. Informed Consent
Participants are required to provide informed consent prior to the commencement of identity verification and participation monitoring activities.
12. Limitation of Liability
To the maximum extent permitted by law, the Company shall not be liable for indirect, incidental, special, consequential, or punitive damages arising from use of the Platform.
Total cumulative liability shall not exceed amounts paid by the Client during the preceding twelve months.
13. Changes to This Agreement
The Company reserves the right to modify this Agreement. Material changes will be communicated to Clients in advance where commercially reasonable.
14. Governing Law and Dispute Resolution
This Agreement shall be governed by the laws of the applicable governing jurisdiction specified by the Company and Client agreement.