Enrich

Terms of Service

Effective 9 September 2026 · Version 2026-09-09

These Terms govern use of Enrich. Because the Service performs regulated checks on people and businesses at your instruction, much of what follows concerns the responsibilities that come with that: whose consent you need, which laws apply to which checks, how you may rely on what comes back, and — for customers who are themselves regulated — the audit, security and continuity commitments your compliance function will need from us.

1.The agreement

These Terms of Service (the Terms) are a binding agreement between Timble Technologies Private Limited (Enrich, we, us) and the organisation on whose behalf you create an account (you, the Customer). They govern access to and use of the Enrich platform, its web application, its programmatic API, its MCP endpoint and related services (together, the Service).

By creating an account, accepting these Terms at sign-up, or using the Service, you confirm that you have read and agree to these Terms and to our Privacy Policy, and that you are authorised to bind the Customer. If you are not, do not use the Service.

Where you and we have signed a master services agreement, order form, data processing agreement or information security schedule, that document prevails over these Terms to the extent of any conflict. Absent one, these Terms are the whole of the agreement between us.

2.What the Service does

Enrich is an agent that plans and performs verification work on your instruction. Given a subject — an individual or a business — and a stated purpose, it selects checks from a catalogue of licensed data sources and public registries, performs them in an order appropriate to that purpose, pauses for your approval where a human should decide, and assembles the results into a scored, sourced report with an audit trail. Checks are available for subjects in India, the United States, Canada and the United Arab Emirates, and the catalogue changes over time.

Results originate from third-party data providers, public records and government registries. We do not create those records, cannot alter them, and their accuracy, completeness and currency are determined by their sources. Section 8 governs the consequences of that for how you may rely on a report.

We may add, change, suspend or withdraw features, checks and data sources, including where a source withdraws access or a legal requirement changes. Where a change materially reduces a capability you rely on, we will give you reasonable notice unless a legal or security constraint prevents it. Features designated beta, preview or experimental are provided as-is.

3.Our regulatory status, and what we are not

Enrich is a technology and data services provider. Its role is to obtain, organise and present information that you have instructed it to obtain. Understanding what that is not is important to how you may use it.

We are not, and do not hold ourselves out as:

  • a bank, a non-banking financial company, or any other entity registered with or regulated by the Reserve Bank of India; we do not lend, accept deposits, hold client funds, or carry on any activity requiring authorisation as a financial institution;
  • a Credit Information Company under the Credit Information Companies (Regulation) Act 2005; we do not maintain a credit information database and do not issue credit information reports of our own;
  • a credit rating agency, a valuer, an insurer or an insurance intermediary;
  • a provider of legal, regulatory, tax, accounting, credit or investment advice. Nothing the Service produces is advice, and no relationship of adviser and client arises between us.

If you are a regulated entity — an NBFC, bank, insurer, payment operator, capital markets intermediary or similar — your engagement of the Service is an outsourcing of an information technology and data service. Your regulator’s rules on outsourcing continue to apply to you and are not displaced by anything we do: you remain responsible for your own compliance, for the decisions you take, and for supervising this arrangement. Sections 13, 14 and 15 exist so that you can meet those obligations, and you should tell us at onboarding that you are a regulated entity so that we apply the right controls and record-keeping from the outset.

4.Eligibility and your authorisations

The Service is offered to businesses and professionals only. You must be at least 18 years old and acting in a business or professional capacity, and we may restrict sign-up to approved email domains.

You represent, on each occasion you use the Service, that:

  • you hold every licence, registration, authorisation and approval that your use of the Service and your own business require, and will maintain them;
  • your use is within the scope of those authorisations and of the purposes you have told us about;
  • you are not subject to any sanction, debarment or regulatory direction that would prohibit us from providing the Service to you, and neither you nor your beneficial owners are on an applicable sanctions list;
  • the information you give us at onboarding — including your regulatory status, your intended use cases and your billing details — is accurate, and you will tell us promptly if it changes.

We may verify these matters before or during the relationship, may require written certification of your purpose or regulatory status before enabling a check, and may decline or withdraw any check for any customer.

5.Accounts, users and credentials

A workspace is created for the Customer at sign-up and the person who signs up becomes its first administrator. Administrators may invite further users and assign roles. You are responsible for everyone who uses the Service under your workspace (Authorised Users), for ensuring each complies with these Terms, and for all activity under your accounts and API keys, whether or not you authorised it.

You must: keep credentials, session tokens and API keys confidential; enable two-factor authentication where offered; grant each Authorised User only the access their role requires; withdraw access promptly when a person leaves or changes role; and notify us at support@timbletech.com without delay on discovering any actual or suspected compromise. API keys are displayed in full only once, at creation; we store them hashed and cannot recover a lost key, only issue a replacement.

We may suspend or close accounts we reasonably believe to be created with false information, used by a person other than the Customer, shared with an unauthorised third party, or compromised.

6.Your obligations: lawful basis and consent

The Service processes personal data about the people and businesses you instruct it to check (Verification Subjects). You decide whom to check and why. For that data you are the data controller — in India, the Data Fiduciary — and we act as your processor on your documented instructions. You are solely responsible for ensuring each check is lawful in every jurisdiction applicable to you, to us and to the subject.

You represent and warrant, for every check you run, that:

  • you have a lawful basis to process the subject’s personal data for that purpose — the subject’s free, specific, informed and unambiguous consent, or a legal obligation, contract or other basis the applicable law recognises;
  • where consent is that basis, you obtained it before the check, you can evidence it, you gave the notice the law requires, and you will honour a withdrawal;
  • the purpose is legitimate — customer due diligence, know-your-customer and know-your-business obligations, anti-money-laundering compliance, credit underwriting and monitoring, fraud prevention and investigation, employment or tenancy screening where permitted, or lawful debt recovery — and is not a prohibited use under Section 9;
  • you will use results only for that purpose and will not retain, disclose or repurpose them beyond what the purpose and the law allow.

Consent-first by default. Checks on individuals require the subject’s verifiable, explicit consent unless we have agreed otherwise in writing. Access to check individuals without per-subject consent (lawful-basis mode) is available only to organisations that have completed our compliance review, documented a lawful basis such as a statutory KYC, AML or fraud-prevention obligation, and signed an agreement covering it. Such access is scoped to the agreed purposes, logged, and auditable.

Every run is recorded against your workspace: what was requested, which checks ran, what was returned, and who approved it. Treat that record as part of your own compliance file; you may export it, and Section 14 governs access to it.

7.Rules for particular checks and jurisdictions

Certain checks are governed by specific statutes. The following apply in addition to Sections 6 and 9 and are conditions of access to those checks.

India

  • Aadhaar. You must comply with the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act 2016 and UIDAI regulations. No report the Service generates displays a full Aadhaar number: Aadhaar is always rendered masked to its last four digits. A small number of checks take an Aadhaar number as their input in order to run at all; where a check accepts a masked Aadhaar or a Virtual ID, you must use that instead, and you must not submit a full Aadhaar number where a masked form would serve. Do not store Aadhaar numbers obtained through the Service except as those regulations permit.
  • Credit information. Credit bureau data is governed by the Credit Information Companies (Regulation) Act 2005 and the rules under it. You may request it only for a purpose the Act permits, only with the subject’s consent, and may not disclose it onward.
  • Anti-money-laundering. Where you are a reporting entity under the Prevention of Money-Laundering Act 2002, you remain responsible for your own customer due diligence, record-keeping and reporting. Our output supports those obligations; it does not discharge them.
  • Personal data generally. The Digital Personal Data Protection Act 2023 applies. You are the Data Fiduciary for Verification Subjects and must give the notices, obtain the consents and honour the rights that Act requires.

United States

  • Social Security numbers and driver licence data are subject to the Gramm-Leach-Bliley Act and the Driver’s Privacy Protection Act respectively. Request them only for a purpose those statutes permit, and certify that purpose if we ask.

Canada

You must comply with the Personal Information Protection and Electronic Documents Act and any applicable provincial privacy legislation, including the requirement for meaningful consent before collecting an individual’s personal information.

United Arab Emirates

You must comply with Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data and, for Emirates ID and visa data, the requirements of the Federal Authority for Identity, Citizenship, Customs and Port Security. Certain checks are available only to entities licensed in the UAE.

8.Results are decision support, not decisions

A report is a structured account of what third-party sources returned, together with our assessment of how those findings bear on the purpose you stated. It is not advice, not a certification, and not a guarantee about any person or business.

You remain the decision-maker. You must not take any action producing legal effects or similarly significant effects for an individual — declining credit, refusing an application, terminating a relationship, commencing recovery, denying employment — solely on the basis of a report, without meaningful human review by a person competent to make that decision. The Service is built to pause for that review, and you agree to operate it that way.

Source data can be incomplete, stale or wrong; identities are matched probabilistically; a record may relate to a different person of the same name. Before acting adversely on a finding you must verify it and, where the law requires, notify the subject and afford an opportunity to dispute it. We will assist with disputes about how a result was assembled and will identify the source of any finding, but we cannot correct a source record; the subject’s remedy against an inaccurate source record lies with that source.

Where you deploy the Service in an automated decision workflow, you are responsible for the governance of that workflow, including any model risk management, fairness testing and explainability your regulator requires of you.

9.Prohibited uses

You must not, and must not permit any person to, use the Service:

  • to check any person without a lawful basis, or to profile a person for a purpose of which they have not been informed;
  • to stalk, harass, intimidate, discriminate against or cause harm to any person, or to locate a person who holds a protective order or comparable protection against you;
  • to make decisions about individuals on the basis of protected characteristics, or otherwise in breach of anti-discrimination law;
  • for coercive or abusive debt collection, or in breach of any applicable fair-practices code governing recovery;
  • as a factor in establishing an individual’s eligibility for credit, insurance, employment, tenancy or another benefit in any jurisdiction whose consumer-reporting or credit-reporting legislation would apply to that use, unless we have agreed to it in writing and you comply with every notice, certification and adverse-action requirement that legislation imposes;
  • to resell, sublicense, publish or otherwise supply results to third parties as a data product, or to construct a competing database or service from them;
  • to circumvent consent requirements, compliance review, rate limits, credit accounting or any other control;
  • to submit content that is unlawful or infringing, or documents belonging to others without authority;
  • to probe, scan, disrupt, or reverse-engineer the Service or its data sources, or to access them other than through the interfaces we provide;
  • in breach of any export control, sanctions, anti-bribery or anti-corruption law.

We may investigate suspected misuse, suspend access during an investigation, and report unlawful conduct to the relevant authorities. Where your use breaches this Section we may also notify a regulator if we are required or permitted to do so.

10.Credits, fees and payment

The Service is paid for with prepaid credits. Each check consumes the number of credits shown for it in the workspace at the time it runs; generating the report itself is free. You are charged for the checks a run actually performs — a run that halts early consumes only the credits of the checks it reached.

A credit balance is required to begin. Credits are purchased through our payment processor and by paying you also accept that processor’s terms. Prices are shown before payment and exclude taxes; applicable taxes, including GST, are added at checkout and stated on the invoice. You are responsible for supplying a correct billing profile, including any GSTIN to appear on invoices.

So that work in progress is not interrupted, a run that begins with a positive balance may be permitted to complete even if it takes the balance below zero. Any shortfall is a debt due to us, is set off against your next purchase, and we may suspend new runs until it is cleared.

Credits are not money, carry no interest, are not a deposit or stored-value instrument, cannot be transferred between workspaces, and are non-refundable except where the law requires, where we terminate other than for your breach, or as the payment processor’s rules require for a failed or duplicated charge. Credits expire twelve months after purchase, and expired credits are not refundable or reinstated; we will notify you before a material balance lapses. We may change credit prices and per-check costs on reasonable notice; changes do not affect credits already purchased or runs already begun.

11.Customer data and ownership

Customer Data means everything you or your Authorised Users submit to the Service and everything it produces for you — instructions, uploaded documents, check results, reports and audit records. As between us, you own it. You grant us a non-exclusive licence to host, process, transmit and display it solely to provide, secure and support the Service, to comply with law, and as the Privacy Policy describes.

We do not sell Customer Data, do not use it for advertising, and do not use Customer Data or Verification Subject data to train machine-learning models. Our model providers are engaged on terms prohibiting them from training on our inputs or outputs.

We may collect and use aggregated or de-identified operational information — which checks run how often, error rates, latency — to operate, secure and improve the Service, provided it cannot reasonably identify you, your Authorised Users or any Verification Subject.

Where you require a data processing agreement, we will enter into one on request.

12.Confidentiality

Each party will keep the other’s non-public information confidential, use it only for the purposes of this agreement, disclose it only to those of its personnel and advisers who need it and are bound by equivalent obligations, and protect it with at least reasonable care. This does not apply to information that is public otherwise than through the recipient’s breach, was already lawfully known to the recipient, is independently developed, or is required to be disclosed by law or by a regulator — in which case the recipient will, where lawful, give notice and disclose only what is required. Customer Data is your confidential information; the non-public workings of the Service are ours. These obligations survive termination.

13.Information security

We maintain technical and organisational measures appropriate to the sensitivity of the data the Service handles, including:

  • encryption of data in transit using current TLS, and encryption at rest for stored reports, credentials and secrets;
  • passwords stored only as salted hashes; API keys and third-party credentials stored hashed or encrypted; secrets held in a managed secrets store and never in source control;
  • role-based access control within workspaces, optional two-factor authentication, account lockout after repeated failed sign-ins, and bot protection on authentication pages;
  • least-privilege, logged and time-bound administrative access to production systems by our personnel, who are subject to background checks appropriate to their role, confidentiality obligations and security training;
  • audit logging of administrative and security-relevant events, retained for 365 days and held within India, meeting the log-retention requirement of the CERT-In directions of April 2022;
  • segregation of each customer’s data, and controls preventing one workspace from reaching another’s data;
  • a secure development lifecycle including code review, dependency monitoring and change control.

Incident notification. On confirming a security incident affecting your Customer Data we will notify you without undue delay and in any event within twenty-four hours, provide the information reasonably necessary for you to meet your own regulatory reporting obligations — including any six-hour reporting requirement applicable to you — and keep you informed as the investigation proceeds. We will cooperate with CERT-In and any other authority as required. A shorter notification window may be agreed in a signed agreement.

We maintain ISO/IEC 27001 and SOC 2. Certificates, scope statements and attestation reports are made available to customers under confidentiality rather than published, as those schemes intend. We will also complete customer security questionnaires and provide our current control documentation on request.

14.Audit, regulatory inspection and sub-contracting

Audit. Once in any twelve-month period, on at least thirty days’ written notice and at your cost, you may audit our compliance with these Terms so far as it concerns the Service provided to you. An audit will be conducted in business hours, will not unreasonably disrupt our operations, must not access another customer’s data, and any auditor must be bound by confidentiality and must not be our competitor. Additional audits may be conducted following a security incident affecting you or where a regulator directs one.

Regulatory inspection. Where you are a regulated entity, we acknowledge that your regulator — including the Reserve Bank of India where applicable — your statutory auditors and persons authorised by them may inspect, audit and obtain information about the Service, our books and records relating to it, and the premises and systems used to provide it, whether directly or through you. We will grant that access, cooperate fully and promptly, and will not treat the exercise of a regulator’s statutory powers as a breach of confidentiality. We will notify you promptly if a regulator approaches us directly about services provided to you, unless prohibited from doing so.

Records. We will maintain records of the Service provided to you — runs performed, checks executed, approvals given, access granted — sufficient to allow you to demonstrate your own compliance, and will retain them as Section 15 and the Privacy Policy describe. Where your regulatory obligations require longer retention or specific record formats, we will agree those in writing.

Sub-contracting. We use sub-processors to provide the Service. We remain fully responsible to you for their acts and omissions as if they were our own, engage each under written terms no less protective than these, and assess their security and regulatory suitability before engagement. The Privacy Policy describes the categories we use; the current list of named sub-processors is available to customers on request under confidentiality. We will give you reasonable prior notice of a new or replacement sub-processor that will process your Customer Data, and if you reasonably object on documented security or regulatory grounds we will work with you in good faith to find an alternative, failing which you may terminate the affected part of the Service without penalty. We will not sub-contract a material part of the Service to a provider outside India without your prior written consent where your regulator requires it.

15.Business continuity and exit

Continuity. We maintain backups of Customer Data and documented procedures for restoring the Service following a disruption, and test them periodically. Recovery objectives, and any commitment to availability, apply only as set out in a signed agreement with you. We will inform you of a disruption materially affecting the Service and of our expected recovery.

Exit. On termination, and for 30 days afterwards, you may export your reports, run records and audit trail in a machine-readable format through the Service. On request during that period we will provide reasonable transition assistance, at our then-current professional rates where the assistance goes beyond standard export, so that you can migrate without interruption to your own regulatory obligations. After that period we delete Customer Data in accordance with the Privacy Policy, and will confirm deletion in writing on request, save for records we are required by law to retain and backups that expire on their ordinary cycle.

16.Intellectual property

The Service — its software, models and prompts, interfaces, documentation, check catalogue and report designs — is owned by us and our licensors and protected by intellectual property law. We grant you a limited, non-exclusive, non-transferable, revocable licence to use it in accordance with these Terms for your internal business purposes. All rights not expressly granted are reserved.

Third-party data returned by the Service remains subject to the rights and terms of its source. Nothing here transfers any right in that data beyond the right to use results for the purpose for which you lawfully requested them.

If you send us feedback or suggestions, you grant us a perpetual, royalty-free licence to use them without obligation to you.

17.API and integrations

The API and MCP endpoint are part of the Service and subject to these Terms. API keys identify your workspace and carry its permissions and credit balance; you are responsible for their use. You must observe documented rate limits and idempotency rules, must not share keys with third parties other than your own service providers acting on your behalf and under equivalent obligations, and must ensure any integration you build enforces the consent and purpose requirements of Sections 6 and 7 before it calls us.

Webhook payloads are signed; verify signatures before acting on them. We may version, deprecate or change the API on reasonable notice, except where a security or legal issue requires an immediate change.

18.Availability and support

We aim to keep the Service available and will give notice of planned maintenance where we reasonably can, but we do not warrant uninterrupted or error-free operation, and third-party data sources may be unavailable for reasons outside our control. Support is available at support@timbletech.com. Any service-level commitment, including availability targets and support response times, applies only if set out in a signed agreement with you.

19.Disclaimers

Except as expressly stated in these Terms, the Service and all results are provided “as is” and “as available”, and we disclaim all warranties, express or implied, including of merchantability, fitness for a particular purpose, non-infringement, and of the accuracy, completeness, currency or reliability of any result. We do not warrant that any result will satisfy a legal or regulatory obligation applicable to you.

Nothing in these Terms excludes a warranty or right that cannot lawfully be excluded.

20.Limitation of liability

To the fullest extent the law allows, neither party is liable for any indirect, incidental, special, consequential or punitive loss, or for loss of profit, revenue, business, goodwill or data, however arising.

To the fullest extent the law allows, our total aggregate liability arising out of or in connection with the Service and these Terms, whether in contract, tort (including negligence), breach of statutory duty or otherwise, is limited to the fees you paid us in the twelve months preceding the event giving rise to the claim.

These limits do not apply to liability for death or personal injury caused by negligence, for fraud or wilful misconduct, for breach of confidentiality, for our breach of Section 13, to your payment obligations, or to your indemnity in Section 22 — nor to any liability that cannot lawfully be limited.

21.Indemnity

You will defend, indemnify and hold us harmless against any claim, fine, penalty, loss and expense (including reasonable legal fees) arising from: a check run without a lawful basis or in breach of Sections 6, 7 or 9; a decision taken about a person in breach of Section 8; Customer Data submitted without the right to do so; your use of the Service outside your own authorisations under Section 4; or your Authorised Users’ breach of these Terms. We will notify you promptly of any such claim and allow you to control its defence, provided you do not settle in a way admitting fault on our behalf without our consent.

22.Suspension and termination

You may close your workspace at any time from the admin console or by writing to support@timbletech.com. We may suspend or terminate access, in whole or part, immediately on your breach of these Terms, where required by law, by a regulator or by a data source, where your account presents a security risk, or where your balance remains negative after notice; and otherwise on thirty days’ notice.

Where we suspend rather than terminate, we will tell you why and what is needed to restore access, and will restore it promptly once the cause is resolved. On termination your right to use the Service ends and Section 15 governs export, transition and deletion. Unused credits are forfeited on termination for breach and otherwise handled as Section 10 provides. Sections 6 to 8, 11 to 16 and 19 to 24 survive termination.

23.Changes, governing law and general terms

Changes. We may update these Terms. The current version and its effective date appear at the head of this page, and we record which version each account accepted. For material changes we will give at least thirty days’ notice by email or in the product; continuing to use the Service after the effective date constitutes acceptance. If you do not accept, you may close your workspace before the change takes effect.

Governing law and disputes. These Terms are governed by the laws of India. The parties will first attempt to resolve any dispute in good faith through their senior representatives within thirty days of written notice. Failing that, the parties submit to the exclusive jurisdiction of the courts at New Delhi, India, without prejudice to either party’s right to seek injunctive relief in any court of competent jurisdiction.

General. These Terms and the Privacy Policy are the entire agreement between us on their subject matter and supersede prior discussions. If a provision is unenforceable the remainder stands. Failure to enforce a right is not a waiver. You may not assign without our written consent; we may assign to an affiliate or to a successor to our business, subject to any notification your regulator requires. Neither party is liable for delay caused by events beyond its reasonable control, provided it takes reasonable steps to mitigate. Nothing here creates a partnership, joint venture, agency or employment relationship. Notices to us go to support@timbletech.com; notices to you go to the email address on your account.

24.Grievance redressal and contact

Timble Technologies Private Limited
Pillar Number 181, Shop No. 2, 2nd Floor, Khasra No. 541 & 542, near Arjan Garh Metro Station, Aya Nagar, New Delhi, Delhi 110047
CIN: U80902DL2016PTC305288

First level — support. support@timbletech.com, for questions about the Service, your account or billing.

Second level — Grievance Officer, under the Digital Personal Data Protection Act 2023 and the Information Technology Rules. Write to support@timbletech.com marked for the attention of the Grievance Officer. We aim to acknowledge within 3 working days and to resolve within 30 days. If you are not satisfied with the outcome you may complain to the Data Protection Board of India.

Security reports and suspected incidents: support@timbletech.com.