Legal

Acceptable Use Policy

Effective Date: 2026-03-01

Company: Asteria Limited (HK)

This Acceptable Use Policy describes the permitted and prohibited uses of the ASTERIA KYC website, platform, APIs, SDKs, dashboards, verification workflows, compliance tools, and related services. It is designed to protect ASTERIA KYC, Customers, End Users, infrastructure, data, and the integrity of identity verification and compliance-support processes.

This policy applies to all Customers, administrators, developers, integration partners, contractors, agents, users, and any party accessing or using ASTERIA KYC services.

1. General Standard of Use

You must use ASTERIA KYC lawfully, responsibly, securely, and in accordance with applicable agreements, documentation, technical instructions, and policies.

You must not use ASTERIA KYC in a way that creates unreasonable legal, regulatory, security, operational, reputational, or human rights risk.

You are responsible for all activity conducted through your account, credentials, API keys, dashboard access, integrations, and authorized users.

2. Lawful Basis and User Notice

You must ensure that you have a lawful basis to submit personal data, identity documents, biometric-related information, images, videos, device signals, risk information, or other data to ASTERIA KYC.

Where required by law, you must provide End Users with clear notice and obtain valid consent before processing identity, document, biometric, liveness, screening, or risk data.

You must not submit data that you are not legally authorized to collect, process, disclose, or transfer.

3. Prohibited Illegal Use

You may not use ASTERIA KYC to facilitate, support, conceal, or enable:

  • money laundering
  • terrorist financing
  • sanctions evasion
  • fraud
  • identity theft
  • document forgery
  • synthetic identity creation
  • trafficking
  • scams
  • illegal gambling
  • unauthorized financial services
  • unlawful surveillance
  • cybercrime
  • market manipulation
  • corruption or bribery
  • tax evasion
  • other unlawful activity

4. Prohibited Harmful Use

You may not use ASTERIA KYC to:

  • target individuals unlawfully or unfairly
  • discriminate unlawfully based on protected characteristics
  • make high-impact decisions without required human review
  • process biometric-related data without required notice or consent
  • harass, intimidate, exploit, or harm individuals
  • conduct unauthorized background checks
  • create exclusionary or abusive verification practices
  • use results outside the stated purpose of the verification workflow
  • misrepresent verification results as official government decisions
  • present ASTERIA KYC outputs as legal certification, regulatory approval, or proof of innocence or wrongdoing

5. Data Submission Rules

You must not upload, submit, or transmit:

  • data you are not authorized to process
  • malicious code
  • corrupted files
  • unlawful content
  • fake documents created for fraudulent purposes
  • stolen identity data
  • data obtained through phishing or deception
  • excessive or irrelevant personal data
  • special category or sensitive data not required for the configured workflow
  • data relating to minors unless you have a valid legal basis and appropriate safeguards

6. Security Requirements

You must:

  • protect account credentials and API keys
  • restrict access to authorized personnel only
  • use strong authentication where available
  • maintain secure systems and networks
  • validate webhooks and callbacks securely
  • avoid exposing secrets in public repositories or client-side code
  • promptly rotate compromised credentials
  • notify ASTERIA KYC of suspected unauthorized access
  • implement reasonable logging and access controls
  • follow integration security documentation

7. Prohibited Technical Abuse

You may not:

  • reverse engineer the Services
  • bypass access controls
  • scrape, harvest, or extract data at scale
  • interfere with service operation
  • overload infrastructure
  • perform unauthorized scanning or penetration testing
  • introduce malware
  • exploit vulnerabilities
  • attempt privilege escalation
  • use bots or automation in a way that harms service stability
  • tamper with verification workflows
  • manipulate liveness or biometric checks
  • submit injection attacks, deepfake attacks, replay attacks, or synthetic media for abusive purposes

8. API and SDK Restrictions

You must use ASTERIA KYC APIs and SDKs only for legitimate, authorized, and documented purposes.

You must not:

  • expose API keys in public
  • share access with unauthorized parties
  • resell API access without authorization
  • submit excessive requests beyond permitted limits
  • circumvent rate limits
  • disable security checks
  • alter SDK behavior to mislead End Users
  • remove required notices or consent screens where applicable
  • misroute or manipulate verification results

9. Prohibited Misrepresentation

You must not claim that ASTERIA KYC has:

  • approved your business
  • certified your compliance program
  • granted regulatory permission
  • endorsed your platform
  • guaranteed user legitimacy
  • guaranteed fraud prevention
  • cleared a user from all legal risk
  • made a final onboarding or rejection decision
  • issued a government-equivalent identity result

10. High-Risk Use Cases

Certain use cases may require additional review, contractual controls, configuration restrictions, or refusal.

High-risk use cases may include regulated financial services, virtual assets, gambling, payment services, age-restricted products, high-value transfers, cross-border onboarding, politically exposed persons, sanctions-exposed jurisdictions, high-fraud regions, and sensitive biometric workflows.

ASTERIA KYC may request additional information, impose conditions, restrict features, or decline service for high-risk use cases.

11. Monitoring and Enforcement

ASTERIA KYC may monitor use of the Services for security, abuse prevention, operational integrity, legal compliance, and policy enforcement.

If we believe this policy has been violated, we may:

  • issue a warning
  • request remediation
  • restrict features
  • suspend access
  • terminate access
  • disable API keys
  • remove or quarantine content
  • notify affected parties where appropriate
  • cooperate with legal authorities where required by law

12. Customer Responsibility for Authorized Users

Customers are responsible for employees, contractors, agents, affiliates, developers, and third parties who access ASTERIA KYC through the Customer’s account or integration.

Customers must ensure authorized users are trained, supervised, and restricted to appropriate roles.

13. Reporting Misuse

If you become aware of misuse, suspected abuse, unauthorized access, data compromise, exposed credentials, or security risk involving ASTERIA KYC, you must notify us promptly through the official contact channel provided on the website.

14. Updates to This Policy

We may update this Acceptable Use Policy from time to time. Continued use of the Services after publication of an updated policy indicates acceptance of the revised policy.

Inquiry

Need clarification regarding this policy?

If you have questions about this policy, ASTERIA KYC services, data handling, compliance workflows, or documentation, please contact Asteria through the official contact channel on the website.

Acceptable Use Policy | ASTERIA KYC