DEVICE INTELLIGENCE - CONSORTIUM | ID NUMBER 202521
1. Scope of Additional Terms
1.1. These Additional Terms are applicable where any of Dataset IDs listed above are used, and is referred to within these Additional Terms as the “Service”. These Additional Terms supplement the Agreement and any applicable data processing agreement (“DPA”).
1.2. The Service enables End User to collect and evaluate device, browser, behavioral, network, location, malware, and session-integrity identifiers (“Online Identifiers”)through End User’s implementation of the Service, including the Web SDK/JavaScript, to support End User’s fraud prevention, authentication, security, identity verification, and risk assessment workflows. GBG processes such data on End User’s behalf and returns risk signals, scores, indicators, or other outputs for End User’s use. End User controls the deployment, configuration, consumer experience, notices, permissions, and downstream use of the Service and Results.
2. Definitions
Capitalised terms not defined in these Additional Terms have the meanings given in the Agreement or applicable DPA. The following terms apply to the Service:
“Consumer Choice Signal” means any opt-out, objection, consent withdrawal, limitation request, rejection of non-essential tracking, global privacy control, universal opt-out mechanism, browser or device permission setting, or equivalent preference or rights signal required to be honored under Applicable Data Protection Law.
“Sensitive Personal Data” shall have the meaning set forth under Applicable Data Protection Law.
“Results” means any risk signals, scores, indicators, flags, confidence levels, device or session attributes, and any other outputs returned by the Service.
3. Roles of the Parties
For purposes of the Service, GBG processes personal data on behalf of End User as a service provider, processor, or equivalent role under Applicable Data Protection Law, and End User is responsible for determining the lawful basis, purposes, means, implementation, configuration, consumer disclosures, and downstream use of the Service and Results.
4. Authorised Purposes and End User Responsibility
4.1 End User shall use the Service and Results only for the permitted fraud prevention, authentication, security, service integrity, risk assessment, and identity verification purposes described in the applicable order form, statement of work, service notice, or other written agreement between the parties (“Authorised Purposes”).
4.2 End User may use the Service only for the Authorised Purposes, unless otherwise expressly agreed in a written and signed amendment by GBG.
4.3 End User is responsible for selecting, enabling, disabling, configuring, and maintaining the Service features, Web SDK/JavaScript implementation, data fields, workflows, thresholds, retention settings, consumer permissions, and downstream decisioning logic applicable to End User’s use case.
4.4 End User shall ensure that End User’s use of the Service is lawful, necessary, proportionate, and consistent with End User’s consumer-facing notices, consents, permissions, authorizations, privacy policies, internal policies, and obligations under Applicable Data Protection Law.
4.5 The End User is responsible for maintaining its own back-ups of all Results.
5. Notice, Consent, and Permissions at Collection
5.1 Because the Service collects or processes Personal Data through End User-controlled websites, applications, software, SDK implementations, or digital properties, End User is solely responsible for providing all legally required notices and obtaining all legally required consents, permissions, authorizations, or other approvals at or before the point of collection for processing provided under the Service, including the contribution of the Online Identifiers to the Shared Device Intelligence Network and their use to develop and operate the Shared Network Model for the benefit of participating GBG customers.
5.2 To enable End User to draft any required notices and disclosures, GBG has prepared the following Device Intelligence Services GBG Processing Notice, available here: https://www.gbgplc.com/legal-and-regulatory/products-services-privacy-policy/device-intelligence-processing-notice/
5.3 Without limiting the foregoing, End User shall, where required and in accordance with Applicable Data Protection Law:
a. provide clear and conspicuous notice or disclosures of the processing to enable GBG to perform the Service, which may include any legally required just-in-time, behavioral biometric, or geolocation disclosures or notices;
b. implement and maintain any required cookie banner, consent-management platform, preference center, device permission prompt, or equivalent mechanism;
c. obtain opt-in consent, explicit consent, written release, authorization, or equivalent permission;
d. maintain records of notices presented, consents or authorizations obtained, Consumer Choice Signals received, and preference changes applied; and
e. ensure that End User’s use of the Service remains consistent with End User’s consumer-facing privacy notices, product disclosures, terms of use, and applicable sectoral or regulatory disclosure requirements.
6. Consumer Opt-Outs, Limitation Requests, and Preference Signals
6.1 End User is solely responsible for implementing, detecting, recording, and honoring all Consumer Choice Signals applicable to End User’s use of the Service, including any “Do Not Sell or Share,” profiling, sensitive data limitations, precise geolocation, biometric, cookie/tracker, global privacy control, universal opt-out mechanisms, browser or device permission settings, or equivalent requests or signals required under Applicable Data Protection Law.
6.2 End User shall not enable, transmit, make available, or otherwise cause GBG to process Personal Data through the Service where the consumer has exercised an applicable opt-out, withdrawn consent, refused or revoked permission, objected to processing, limited the use or disclosure of Sensitive Personal Data, rejected non-essential tracking, or submitted another legally effective Consumer Choice Signal, unless End User has determined and documented that the processing remains permitted under Applicable Data Protection Law.
6.3 End User shall configure the Service and any End User-controlled websites, applications, SDK implementations, tags, scripts, consent-management tools, and workflows to prevent, restrict, or cease collection and processing through the Service in accordance with Consumer Choice Signals and Applicable Data Protection Law.
7. End User Responsibility for Final Decisions
7.1 Results are not intended to constitute, and shall not be treated as, automated decisions that independently approve, deny, restrict, or otherwise determine access to a product, service, account, benefit, transaction, or opportunity.
7.2 End User remains solely responsible for making any final determination regarding the use of the Result. The End User must apply its own policies, procedures, meaningful human review by a qualified reviewer with the authority to override the Result where appropriate, and legal compliance assessment before taking any action that may produce a legal or similarly significant effect on an individual.
8. Retention and Deletion
8.1 GBG will retain Results for up to twelve (12) months, after which it will be automatically deleted, unless a shorter retention period is requested by End User or configurable within the Service. Upon termination or expiration of the applicable agreement, GBG will delete personal data processed on End User’s behalf within ninety (90) days, unless a longer retention period is required by applicable law or otherwise permitted under the agreement. Where End User submits a verified deletion request on behalf of a consumer, GBG will provide reasonable assistance by deleting applicable Personal Data from production systems within a reasonable timeframe after receiving sufficient information from End User to identify the relevant data. GBG will also direct applicable subprocessors to delete such personal data and will confirm completion to End User in accordance with the DPA.
9. Device Intelligence Network
9.1 Description of Processing. The Service allows End Users to contribute their data subjects’ Online Identifiers to a shared network to generate risk scores and indicators for fraud prevention and identity verification purposes (“Shared Device Intelligence Network”). The Shared Device Intelligence Network is composed of and utilises the Online Identifiers that are collected from End Users who are utilising this Service. End User acknowledges that Online Identifiers contributed by End User may therefore inform outputs provided in connection with transactions submitted by other participating GBG customers who are also using the Shared Device Intelligence Network. All Online Identifiers are encrypted in transit and at rest, and are not disclosed or otherwise made available to any other End User. Customer understands the description of processing in this clause 9.1, and instructs GBG and its subprocessors to contribute and utilise the Online Identifiers in the Shared Device Intelligence Network for the purposes described in clause 9.3.
9.2 Role of the Parties. GBG acts as a Processor on behalf of Customer, and may Process the Online Identifiers as reasonably necessary and proportionate to achieve the purpose of processing set forth in paragraph 9.3 below.
9.3 Purpose of Processing. GBG shall process the Online Identifiers in accordance with Customer’s documented instructions under the Agreement, the Data Processing Agreement and these Additional Terms, and solely for the limited and specified purposes of security-integrity, identity verification, and fraud prevention in connection with End User’s use of the Service.
9.4 Retention and Deletion. The Online Identifiers will be retained for a period of twelve (12) months, and then deleted.
10. Artificial Intelligence
10.1 Customer instructs GBG to use the data contributed into the Shared Device Intelligence Network to train, retrain, validate, test, calibrate, and operate the Shared Device Intelligence Network’s learning model (“Shared Network Model”), solely for security-integrity, identity verification, and fraud prevention purposes described in clause 9.3. End User acknowledges and agrees that, as part of the direct business relationship established by this Agreement, the Shared Network Model may be used to provide the Services to End User and other participating GBG customers using the Shared Device Intelligence Network. End User Data shall not be used for general model training, improvement or development.
11. No FCRA Permissible Purpose Use
11.1 The End User acknowledges that: (i) the Service is not a “consumer report” as defined under the U.S. Fair Credit Reporting Act, 15 U.S.C. §1681 et seq. (“FCRA”), (ii) GBG is not acting as a “consumer reporting agency” as defined under the FCRA, and (iii) the Service is provided only for fraud risk assessment in the context of identity verification.
11.2 The End User shall not use the Service or Results for any purpose requiring a permissible purpose under the Fair Credit Reporting Act (FCRA), including credit eligibility, employment eligibility, insurance eligibility, tenant screening, or any other FCRA-regulated eligibility determination.