IDFLOW
Back
IDFlow Secure™

Service Level Agreement (SLA)

Government Department — Identity Verification & Data Access Services

Effective Date: Upon Account Activation

Between: IDFlow Secure™ (the "Provider")
And: The Government Department named in the registration (the "Client")

1. Purpose & Scope

This Service Level Agreement ("SLA") governs the provision of identity verification, data access, and auto-form completion services (the "Services") by IDFlow Secure™ to the Client. The Client, being a government department, requires enhanced security, data sovereignty, audit compliance, and service availability guarantees.

2. Service Availability

The Provider guarantees 99.9% uptime for the Services, measured monthly. Scheduled maintenance windows will be communicated at least 72 hours in advance. Emergency maintenance may occur with 2 hours' notice. Downtime exceeding the guaranteed threshold entitles the Client to service credits as defined in the commercial agreement.

3. Data Sovereignty & Residency

All citizen data accessed, processed, or stored through the Services shall reside within the Client's national jurisdiction or as otherwise agreed in writing. The Provider shall not transfer, replicate, or back up citizen data to servers located outside the agreed jurisdiction without explicit written authorization from the Client.

4. Security & Encryption

All data in transit is encrypted using TLS 1.3 or higher. All data at rest is encrypted using AES-256. The Provider maintains ISO 27001 certification (or equivalent). Security incidents affecting government department data must be reported to the Client within 4 hours of detection.

5. Access Control & Authentication

All users accessing the Services on behalf of the Client must use multi-factor authentication (MFA). Role-based access control (RBAC) shall be configured according to the Client's organizational structure. The Provider shall maintain a complete audit log of all access events, retained for a minimum of 7 years.

6. Audit & Compliance

The Provider shall maintain comprehensive audit trails of all identity lookups, data accesses, form fills, and consent verifications. The Client may request audit reports at any time. The Provider shall cooperate fully with any regulatory audit, investigation, or compliance review initiated by the Client or its authorized representatives.

7. Consent Management

All citizen data access shall be consent-verified prior to disclosure. Emergency override provisions exist for life-threatening situations, logged permanently with full justification recorded. The Provider shall implement and maintain consent management systems compliant with applicable data protection legislation including POPIA, GDPR, and equivalent regulations.

8. Incident Response

The Provider shall maintain a documented incident response plan. For incidents affecting the Client's data or operations: Severity 1 (Critical) incidents require response within 15 minutes and resolution within 2 hours. Severity 2 (High) incidents require response within 1 hour and resolution within 8 hours. Severity 3 (Medium) incidents require response within 4 hours and resolution within 24 hours.

9. Support & Escalation

The Client shall have access to 24/7/365 priority support via a dedicated support channel. Support tickets raised by the Client shall receive initial response within 15 minutes. An escalation matrix with named contacts shall be provided to the Client upon activation.

10. Termination & Data Handover

Upon termination of the agreement, the Provider shall export all Client data in a standard, machine-readable format (CSV, JSON, or as agreed) within 30 calendar days. The Provider shall then permanently delete all Client data from its systems and provide a certificate of destruction within 60 calendar days.

11. Governing Law

This SLA shall be governed by and construed in accordance with the laws of the Client's country of registration. Any disputes arising under this SLA shall be resolved through good-faith negotiation first, followed by arbitration in the Client's jurisdiction if necessary.

12. Due Diligence & Verification

The Client acknowledges that access to the Services is contingent upon successful completion of the Provider's due diligence process. This includes verification of the Client's government department status, authorized representative credentials, and email domain validation. The Provider reserves the right to request additional documentation before activating the account.

This SLA is incorporated by reference into the Master Services Agreement between IDFlow Secure™ and the Client Government Department. By using the Services, the Client acknowledges acceptance of these terms.