Vaulth Logo
Back to Overview
Legal

Terms of Service

Last Updated: April 30, 2026

These Terms of Service (the "Terms") govern the access to and use of the Application Programming Interface (API) infrastructure and legal vault services provided by ModelBoard / vAulth.one (the "Provider", "we", "us", or "our") to the client entity (the "Client", "you").

By integrating our API or using our services, the Client agrees to be bound by these Terms, as well as by our Data Processing Agreement (DPA).

1.Service Description and Role of the Parties

ModelBoard provides a B2B Regulatory Technology (RegTech) infrastructure enabling identity verification (KYC), biometric validation, and secure, immutable record storage to assist the Client in complying with legal obligations, notably 18 U.S.C. § 2257 (the "Service").

The Client acts as the Data Controller and Content Publisher. The Client is solely responsible for the content published on its platform and for obtaining explicit consent from its end-users (Creators/Performers) for the collection of their biometric and identity data.

ModelBoard acts as a Data Processor and Custodian of Records. ModelBoard does not host, produce, distribute, or monetize any content related to the entertainment or adult industry.

2.Security Infrastructure & "Cold Vault" (18 U.S.C. § 2257)

To ensure the security and insurability of sensitive data, ModelBoard deploys a "Zero-Trust" architecture:

  • Ephemeral Processing: Biometric verifications are processed entirely in Random Access Memory (RAM).
  • WORM Storage: Identity documents required for legal purposes are encrypted (AES-256 via hardware KMS) and transferred into an isolated digital vault (the "Cold Vault").
  • Legal Retention: Documents deposited into the Cold Vault are subject to an Object Lock Compliance hold for a standard duration of seven (7) years. This renders them mathematically impossible to delete or modify by anyone, including the Provider and the Client, ensuring strict compliance with federal requirements.

3.Right to be Forgotten (GDPR / CCPA) Resolution

If an end-user exercises their right to erasure with the Client:

  • The Client shall use the ModelBoard API to order the purge of active data.
  • ModelBoard agrees to break the cryptographic link (anonymization) between the user's public identity on the Client's platform and their legal record.
  • However, the Client expressly acknowledges and agrees that sealed archives within the Cold Vault will not be destroyed prior to the expiration of the applicable statutory limitation period (e.g., 2257), in accordance with the legal exceptions provided under the GDPR (compliance with a legal obligation and establishment/defense of legal claims).

4.Client Obligations

The Client agrees to:

  • Never transmit identity data directly from its own servers in clear text. The Client must exclusively use the Hosted URLs or secure Software Development Kits (SDKs) provided by ModelBoard.
  • Never use the ModelBoard API to verify the identity of individuals involved in illegal activities or human trafficking.
  • Maintain the accuracy of its internal metadata (Reference IDs) to ensure the integrity of generated audit reports.

5.Service Level Agreement (SLA)

ModelBoard commits to providing an API Uptime of 99.9% per calendar month.

  • If the Uptime falls between 99.0% and 99.89%, the Client shall be entitled to a Service Credit of 10% applied to their next monthly invoice.
  • If the Uptime falls below 99.0%, the Service Credit shall be 25%.

Limitation: These Service Credits constitute the Client's sole and exclusive remedy for any service outage. No cash refunds will be issued. Interruptions due to scheduled maintenance (notified 48 hours in advance) and force majeure events are excluded from Uptime calculations.

6.Fees and Payment Terms

The Client agrees to pay the applicable fees as outlined in the executed pricing quote, which generally includes:

  • Setup Fee: A one-time technical integration fee.
  • Pay-per-Verification: Transactional fees billed monthly based on API call volume.
  • Custodian Fee: A recurring monthly (or annual) fee for the immutable maintenance and securing of records within the Cold Vault.

In the event of a payment delay exceeding 30 days, ModelBoard reserves the right to suspend access to the verification API without deleting the legal archives from the Cold Vault (Custodian Fees will continue to accrue).

7.Limitation of Liability

TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, IN NO EVENT SHALL MODELBOARD BE LIABLE FOR ANY INDIRECT, PUNITIVE, INCIDENTAL, OR SPECIAL DAMAGES, INCLUDING LOSS OF REVENUE OR PROFITS, ARISING OUT OF A SERVICE OUTAGE OR A GOVERNMENTAL INSPECTION OF THE CLIENT.

Liability Cap: ModelBoard's total and cumulative liability, regardless of the cause of action (breach of contract, negligence, or otherwise), shall in no event exceed the total amount paid by the Client to ModelBoard during the twelve (12) months immediately preceding the event giving rise to the claim.

8.Indemnification

The Client agrees to indemnify, defend, and hold harmless ModelBoard, its officers, directors, and employees from and against any claims, fines, federal inspections (e.g., FBI/DOJ), or legal actions brought by third parties or authorities arising out of:

  • The publication of illicit content by the Client;
  • The Client's failure to properly use the ModelBoard API to verify a user's age;
  • The Client's violation of any data privacy law (GDPR, CCPA) outside the scope of the services provided by the API.

9.Term and Termination

These Terms remain in effect for as long as the Client uses the Services or ModelBoard retains records on behalf of the Client. Upon termination of the agreement:

  • The Client's access to the verification API will be immediately revoked.
  • The Client will continue to be billed for residual "Custodian Fees" until the legal WORM locks expire on the final documents stored in the Cold Vault. In the event of payment default on these residual fees, ModelBoard will provide the Client with an encrypted export of all their archives and proceed with the administrative closure of the account, thereby transferring the full responsibility of legal storage back to the Client.

Data Processing Agreement (DPA)

Addendum to the Terms of Service

This Data Processing Agreement ("DPA") forms part of the Terms of Service (the "Agreement") between ModelBoard / vAulth.one ("Processor", "we", "us") and the Client ("Controller", "you"). This DPA reflects the parties' agreement with regard to the processing of Personal Data in accordance with the requirements of Data Protection Laws, including the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).

1.Definitions

  • "Data Protection Laws" means all applicable worldwide privacy and data protection laws and regulations, including the EU GDPR, the UK GDPR, and the CCPA.
  • "Personal Data" means any information relating to an identified or identifiable natural person (the "Data Subject") processed by the Processor on behalf of the Controller.
  • "Sub-processor" means any third party engaged by the Processor to process Personal Data.

2.Scope, Nature, and Purpose of Processing

The Processor will process Personal Data solely to provide the RegTech infrastructure, identity verification (KYC), and legal vaulting services as described in the Terms of Service.

  • Categories of Data Subjects: The Controller's end-users (Creators/Performers).
  • Types of Personal Data: Government-issued identification documents (passports, driver's licenses), biometric data (facial geometry for Liveness checks), and internal reference IDs.
  • Duration of Processing: For the duration of the Agreement, plus any statutory retention period required by applicable law (e.g., 18 U.S.C. § 2257).

3.Processor Obligations

The Processor agrees to:

  • Process Personal Data only on documented instructions from the Controller, unless required to do otherwise by applicable law.
  • Ensure that persons authorized to process the Personal Data (e.g., employees) have committed themselves to strict confidentiality.
  • Assist the Controller in ensuring compliance with the obligations pursuant to security, data breach notifications, and data protection impact assessments.

4.Security Measures ("Zero-Trust" Architecture)

The Processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, specifically tailored to highly sensitive identity and biometric data:

  • Ephemeral Biometric Processing: All biometric comparisons and Liveness checks are processed in volatile memory (RAM) and are permanently purged from active processing environments immediately upon validation.
  • WORM Cold Vault: Identity documents are encrypted using AES-256 (via hardware-backed Key Management Service) and stored in a "Write-Once-Read-Many" (WORM) storage environment.
  • Immutability: Access to the Cold Vault is restricted by infrastructure-level Object Locks, preventing deletion, alteration, or tampering by any party, including the Processor's administrators or potential malicious actors.

5.Data Subject Rights & The "Right to Erasure" Exception

The Processor shall assist the Controller, insofar as possible, to fulfill the Controller's obligation to respond to requests for exercising Data Subject rights (such as access, rectification, or erasure).

Special Provision Regarding Erasure (GDPR Art. 17 / CCPA): If a Data Subject exercises their "Right to be Forgotten" or "Right to Erasure", the Processor will, upon the Controller's API instruction:

  • Purge the Data Subject's active tracking data from the hot database.
  • Permanently sever the cryptographic link between the Controller's public user profile and the secure legal record.

Statutory Retention Exemption: The Controller acknowledges that pursuant to GDPR Article 17(3)(b) (compliance with a legal obligation) and applicable U.S. Federal Laws (including 18 U.S.C. § 2257), the actual identity documents sealed within the Cold Vault cannot and will not be deleted prior to the expiration of the mandatory federal retention period (typically seven years). These locked records will remain strictly isolated and inaccessible for any purpose other than compliance with a lawful government subpoena or inspection.

6.Sub-processing

The Controller grants the Processor general authorization to engage Sub-processors to deliver the Service.

Primary Infrastructure Provider: The Controller explicitly approves the use of Amazon Web Services (AWS) as the primary underlying cloud infrastructure provider.

The Processor remains fully liable to the Controller for the performance of the Sub-processors' data protection obligations. The Processor will notify the Controller of any intended changes concerning the addition or replacement of Sub-processors, giving the Controller the opportunity to object.

7.Personal Data Breaches

In the event of a confirmed Personal Data breach affecting the Controller's data, the Processor shall notify the Controller without undue delay, and in any event within forty-eight (48) hours of becoming aware of the breach. The Processor will provide sufficient information to allow the Controller to meet any obligations to report the breach to supervisory authorities or Data Subjects.

8.International Data Transfers

If the processing involves the transfer of Personal Data from the European Economic Area (EEA), the UK, or Switzerland to a country outside of those areas (e.g., the United States) that is not recognized as providing an adequate level of protection, the parties agree to rely on the applicable Standard Contractual Clauses (SCCs) approved by the European Commission, which are hereby incorporated by reference into this DPA.

9.Deletion or Return of Personal Data

Upon termination of the Agreement, the Processor shall, at the choice of the Controller, delete or return all active Personal Data. Notwithstanding the foregoing, any Personal Data locked within the 18 U.S.C. § 2257 Cold Vault will be retained securely in its encrypted, immutable state until the expiration of the statutory limitation period, after which it will be permanently and automatically destroyed.