BankConnectorCustomer Agreement · v1.0

Customer Agreement

v1.0Last updated 8 July 2026. This version applies to Orders entered into on or after 8 July 2026. This Agreement governs a Company purchasing BankConnector for its own use. A software platform offering BankConnector to its own customers is instead governed by the BankConnector Platform Agreement, and its customers by the Connected Company Agreement.

BankConnector is a software service. BankConnector ApS, a Danish limited liability company ("BankConnector", "we"), provides software that converts payment instructions into bank-specific file formats, delivers them to banks over the Customer's own bank connections, and returns bank statements and payment status in one normalised format. BankConnector is not a bank, payment institution, or money services business. We never receive, hold, control, or transmit funds. We do not provide payment services within the meaning of Annex I of Directive (EU) 2015/2366 (PSD2) or the Danish Payments Act. All payments are executed by the Customer's banks under the Customer's own bank agreements and mandates; BankConnector acts solely as the Customer's technical agent and communication channel.

1Definitions

2The Services

2.1

Provision. We will provide the services identified in the Order, materially as described in the Service Description and Documentation, and in accordance with the SLA & Support Policy and Security Policy.

2.2

What the Services do. The Services (a) validate Payment Instructions against generic, bank-specific, and payment-type rules and report all issues found; (b) convert valid Payment Instructions into the applicable Bank's file format; (c) deliver converted files directly to the Bank over the Customer's active Bank Connection, subject to the Customer's approval workflows; (d) retrieve and normalise bank statements and payment status reports; and (e) provide the web portal, API, webhooks, journal, and audit trail described in the Service Description.

2.3

What the Services do not do. The Services do not (a) hold, receive, or transmit funds; (b) execute payments (execution is performed exclusively by the Customer's Bank); (c) guarantee that a Bank will accept, process, or execute any payment file; or (d) provide legal, tax, regulatory, or compliance advice. Validation reduces, but cannot eliminate, the risk of rejection by a Bank.

2.4

Delivery is direct-only. Converted, signed payment files are delivered by us directly to the Bank. We do not return signed payment files to the Customer or any third party. A Payment Instruction addressed to a Bank without an active Bank Connection and an applicable approval policy will be rejected.

2.5

Approval workflows. Release of a payment file to a Bank requires prior approval under the Customer's configured approval policy. The Customer is responsible for configuring approval policies appropriate to its risk profile. Approval policies are versioned; changes require dual co-signature by two distinct administrators, as described in the Documentation.

2.6

Limited Releases. Limited Releases are provided as-is, without warranty, indemnity, SLA, or support commitments, may be modified or discontinued at any time, and may not be covered by the retention and security commitments applicable to production services, as stated in the Service Description. Sandbox environments are available for the Order term; other Limited Releases may be time-limited. Our total aggregate liability arising out of Limited Releases is capped at EUR 500.

2.7

Changes to the Services. We may improve or modify the Services. We will give at least 30 days' notice of any change that materially reduces the core functionality the Customer has purchased, except where a shorter period is required for security or legal reasons.

3Account, Users, and Security

3.1

Registration. The Customer will provide accurate, current registration information and keep it updated. We may verify the Customer's identity and business information, including through third-party sources.

3.2

Users. The Customer provisions and manages its Users and their roles. The Customer is responsible for all Connection Activity performed through its User accounts and API keys, whether or not authorised, except to the extent caused by our breach of the Security Policy. The Customer will promptly disable access for departing personnel and will notify us without undue delay of any suspected credential compromise.

3.3

Security measures. Both parties will implement appropriate technical and organisational measures. Our commitments are stated in the Security Policy. The Customer will use the security controls provided (including multi-factor authentication for administrators and approvers, role separation, and approval policies) in a manner appropriate to its risk.

4Bank Connections and Authorisation

4.1

Customer authorisation. The Customer authorises BankConnector to access and operate its Bank Connections and to perform Connection Activity on the Customer's behalf, solely as necessary to provide the Services and solely as instructed through the Services.

4.2

Customer authority. The Customer represents and warrants that it is legally authorised to access each Bank Account and Bank Connection it uses with the Services, to issue payment instructions against those accounts, and to receive the associated statements and reports, in each case under its own agreements and mandates with the relevant Bank.

4.3

Bank Requirements. The Customer is solely responsible for its own Banks, bank agreements, mandates, and for satisfying all Bank Requirements. A Bank's delay or failure to onboard, accept, or process files does not relieve the Customer of its payment or other obligations under this Agreement.

4.4

Key custody. We generate and store Bank Connection credentials and key material on the Customer's behalf, encrypted at rest as described in the Security Policy. Key material is used solely to operate the Customer's Bank Connections. On termination, key material is destroyed in accordance with Section 9.6, except where a Bank Requirement or law requires otherwise.

4.5

Instruction content. As between the parties, the Customer is solely responsible for the accuracy, completeness, lawfulness, and timeliness of its Payment Instructions and for any transaction it directs or enables through the Services, including any resulting loss, fraud, or reversal, except to the extent caused by our failure to convert or deliver a valid, approved Payment Instruction in accordance with this Agreement.

5Customer Data and Privacy

5.1

Ownership. The Customer retains all rights in Customer Data. We process Customer Data solely to provide the Services and support, as instructed under the Agreement, or as required by law.

5.2

Data protection. The Data Processing Agreement (DPA) governs processing of personal data in Customer Data, with BankConnector acting as processor. For security telemetry, service improvement, and fraud/abuse prevention we act as an independent controller in respect of Usage Data only.

5.3

Permitted data. The Services are designed for business payment data, including: party names, addresses, account identifiers (IBAN/BBAN), remittance information, and, where required for approval workflows, approver identity data including national identity numbers, which are encrypted, masked, and never written to logs, as described in the Security Policy. The Customer must not submit special categories of personal data (Art. 9 GDPR), payment-card primary account numbers, or health data.

5.4

Usage Data. We may use Usage Data for operating, securing, and improving the Services, and may disclose it only in de-identified, aggregated form.

5.5

Export. The Customer may export its journal and documents at any time during the term using the export functions described in the Documentation.

6Customer Obligations and Compliance

6.1

Lawful use. The Customer will use the Services only for its own business purposes, in compliance with the Agreement, the Acceptable Use Policy, and all laws applicable to the Customer, including, without limitation, anti-money-laundering, counter-terrorist-financing, KYC, economic sanctions, and export control laws, and any payment scheme rules binding on the Customer.

6.2

Compliance allocation. The Customer acknowledges that BankConnector does not screen payments against sanctions or embargo lists, does not perform KYC/AML checks on the Customer's counterparties, and does not monitor transactions for financial-crime purposes, except for any screening features expressly described in the Service Description that the Customer has configured. Responsibility for financial-crime compliance rests with the Customer and its Banks.

6.3

Restrictions. The Customer will not (a) resell, sublicense, or provide the Services to third parties, or use them on behalf of third parties, except under a separate written agreement with us (the platform track); (b) use the Services to build a competing product; (c) reverse engineer any part of the Services except as permitted by mandatory law; (d) circumvent usage limits or security controls; (e) perform security testing without our prior written consent; (f) publish benchmarks of the Services without our consent; or (g) use the Services other than in accordance with the Documentation.

7Fees and Payment

7.1

Fees. Fees are stated in the Order. We invoice fees; we never deduct fees from payment flows (we have no access to funds). Invoices are payable within 30 days of the invoice date. Late amounts accrue interest in accordance with the Danish Interest Act (renteloven).

7.2

Taxes. Fees exclude VAT and similar taxes, which the Customer pays where applicable (other than taxes on our income).

7.3

Fee changes. Fee changes take effect at the next renewal, with at least 60 days' prior notice.

7.4

No set-off against Bank failures. Fees are not reduced or excused by a Bank's unavailability, delay, or rejection of files (see Section 4.3 and the SLA & Support Policy's third-party exclusions).

8Term and Renewal

8.1

The Agreement runs from the Order start date for the initial term stated in the Order, and renews for successive 12-month periods unless either party gives at least 30 days' notice of non-renewal before the end of the then-current term.

9Suspension and Termination

9.1

Suspension events. We may suspend the Services (in whole or part) if: (a) the Customer materially breaches Sections 3, 4, 6 or the Acceptable Use Policy; (b) we reasonably believe continued provision creates a material security risk, legal or regulatory exposure, or material harm to the Services or other customers; (c) undisputed fees are more than 30 days overdue after written reminder; or (d) usage limits are materially exceeded. Except where the risk is material and imminent, we will give notice and a reasonable opportunity to cure before suspending. We will restore the Services promptly once the cause is resolved. Fees continue to accrue during suspension caused by the Customer.

9.2

Termination for cause. Either party may terminate: (a) for material breach not cured within 30 days of written notice; or (b) upon the other party's insolvency. We may additionally terminate if required by law or a governmental or bank-imposed requirement, or if the Customer becomes subject to sanctions.

9.3

Effects of termination. Access ceases at the effective date, except as set out in Section 9.4. Accrued fees survive. Sections intended to survive (including 4.5, 5, 7, 10–14, 16) survive.

9.4

Wind-down and export. For 30 days after termination (other than termination for the Customer's material breach or unlawful use), we will keep the portal available in read-only mode so the Customer can export its journal, documents, and configuration. No new Payment Instructions may be submitted during wind-down. In-flight payment files at the termination date will be completed or cancelled per the Customer's instruction where technically possible.

9.5

Data deletion. After wind-down, Customer Data is deleted or anonymised in accordance with the DPA and our published retention schedule (journal documents 90 days; audit records 5 years; see the Service Description), subject to legal holds and statutory retention duties.

9.6

Key destruction. Bank Connection key material is destroyed on completion of wind-down. The Customer is responsible for notifying its Banks of the termination and revoking bank-side authorisations.

10Warranties and Disclaimers

10.1

Mutual. Each party warrants it is validly existing and has the authority to enter into the Agreement.

10.2

Our warranties. We warrant that (a) the production Services will operate materially as described in the Service Description and Documentation; (b) we will not materially reduce the overall functionality purchased during an Order term; and (c) we will provide the Services with reasonable skill and care, using appropriately qualified personnel.

10.3

Bank integrations (efforts only). We will use commercially reasonable efforts to maintain the availability and correctness of the Bank integrations used by the Customer. We do not warrant that any Bank will accept or process files, nor that a Bank will not change its requirements. Bank-side changes are addressed as maintenance under the SLA & Support Policy.

10.4

Third-Party Services. Banks, network providers, and other third-party services are outside our control. We are not liable for their acts, omissions, unavailability, or data handling. Bank unavailability never counts as our downtime under the SLA & Support Policy.

10.5

Warranty remedy. For breach of Section 10.2: we will re-perform or repair within 30 days of notice; failing that, the Customer may terminate the affected Order and receive a pro-rata refund of prepaid unused fees. This is the exclusive remedy for warranty breach, without limiting Section 11.

10.6

Disclaimer. Except as stated in this Agreement, the Services are provided without further warranties; we do not warrant uninterrupted or error-free operation.

11Liability

11.1

Exclusions. Neither party is liable for indirect or consequential loss, loss of profits, revenue, goodwill, or data (data loss as such; data-restoration obligations under the DPA remain unaffected).

11.2

Cap. Each party's total aggregate liability under the Agreement is limited to the fees paid or payable by the Customer in the 12 months preceding the first event giving rise to liability.

11.3

Carve-outs. The exclusions and cap do not apply to: (a) liability that cannot be excluded under mandatory law; (b) fraud, gross negligence, or wilful misconduct; (c) the Customer's breach of Section 6.3 (Restrictions) or the Acceptable Use Policy; (d) either party's indemnity obligations; or (e) the Customer's fee obligations.

11.4

No funds liability. For clarity: we never hold funds; nothing in the Agreement makes us liable for funds in transit between the Customer and its Banks. Our responsibility relates to the conversion, validation, delivery, and reporting of payment files as described in Section 2.

11.5

Claims bar. A claim under the Agreement must be brought within 12 months of the date the claiming party became aware, or ought reasonably to have become aware, of the facts giving rise to it.

12Indemnities

12.1

By the Customer. The Customer will defend and indemnify BankConnector against third-party claims arising from (a) Customer Data or Payment Instructions; (b) the Customer's breach of Sections 4, 6, or the Acceptable Use Policy; or (c) the Customer's business and its relationships with its Banks and counterparties.

12.2

By BankConnector. We will defend and indemnify the Customer against third-party claims that the Services, as provided by us and used in accordance with the Documentation, infringe a patent, copyright, trademark, or trade secret enforceable in the EEA or the United Kingdom. Remedies: we may procure the right to continue, modify or replace the infringing element, or terminate the affected Order with a pro-rata refund of prepaid unused fees. This states the exclusive remedy for infringement. Exclusions: modifications not made by us, combination with items not provided by us, use in breach of the Agreement, and Limited Releases.

12.3

Procedure. The indemnified party gives prompt notice; the indemnifying party controls the defence; the indemnified party cooperates reasonably. Late notice relieves the indemnifying party only to the extent of actual prejudice.

13Confidentiality

Each party will protect the other's confidential information with at least reasonable care, use it only for the purposes of the Agreement, and disclose it only to personnel and advisors bound by equivalent duties. Exclusions: information that is public, independently developed, rightfully received from a third party, or already known. Disclosure compelled by law is permitted with prior notice to the other party where lawful. These duties last 3 years after termination; for trade secrets and Customer Data, for as long as the information remains protected.

14Intellectual Property; Feedback; Publicity

14.1

Ownership. We retain all rights in the Services, the conversion engine, bank profiles, formats, validation rules, and Documentation. The Customer receives a non-exclusive, non-transferable right to use the Services during the term for its own business.

14.2

Feedback. The Customer grants us a non-exclusive, perpetual, royalty-free licence to use feedback and suggestions; feedback is not assigned.

14.3

Publicity. Neither party may issue announcements about the relationship without the other's consent. We may include the Customer's name and logo in our customer lists and on our website until the Customer revokes this in writing.

15Changes; Order of Precedence

15.1

Changes to the Agreement. We may update this Agreement with notice; changes take effect at the next renewal or new Order. If the Customer objects in writing within 30 days of notice, the then-current terms continue until the end of the then-current term.

15.2

Changes to Policies. We may update Policies with notice, effective on the date stated, provided changes do not materially reduce our overall obligations during a current Order term. Material Policy changes will be pre-announced with an effective date; the Customer may terminate without penalty before the effective date if a change is materially adverse.

15.3

Versioning. Superseded versions of this Agreement and the Policies remain available at dated URLs.

15.4

Precedence. In case of conflict: the DPA (for its subject matter), then the Order (where it expressly overrides), then this Agreement, then the Policies, then the Documentation. Terms on a Customer purchase order have no effect.

16General

16.1

Governing law and venue. The Agreement is governed by Danish law, excluding its conflict-of-law rules and the United Nations Convention on Contracts for the International Sale of Goods (CISG). Exclusive venue: the City Court of Copenhagen (Københavns Byret).

16.2

Escalation. Before commencing proceedings (except for interim relief), the parties will escalate a dispute to senior management for 30 days of good-faith discussion.

16.3

Notices. Operational and legal notices are given by email (to BankConnector at legal@bankconnector.com, and to the Customer at its registered administrator email) and may additionally be given by in-product notice. Notices are deemed received on the next business day.

16.4

Assignment. Neither party may assign the Agreement without the other's consent, except to an affiliate or in connection with a merger or a sale of substantially all assets. The Customer notes that Banks may require re-onboarding of an assignee under Bank Requirements.

16.5

Force majeure. Neither party is liable for failure caused by events beyond its reasonable control; fee obligations are not excused.

16.6

Miscellaneous. The Agreement is the entire agreement between the parties regarding its subject matter and supersedes prior discussions. If a provision is held unenforceable, it will be modified to the minimum extent necessary and the remainder stays in force. A failure to enforce is not a waiver. The parties are independent contractors. The Agreement is drawn up in English, and the English text controls.

16.7

Subcontracting. We may use subcontractors and affiliates in providing the Services (data subprocessors are governed by the DPA); we remain responsible for our overall performance.

BankConnector ApS · bankconnector.com/legalBC-LGL-CA-1.0