Subscriber Agreement
for
 

Certification Services

Version 1.0

January 2000

Copyright 2000 VillageMall Pty Ltd.
ALL RIGHTS RESERVED


Before, making an application for,  or using your Digital Certificate or private key associated with your Digital Certificate, you must read this Agreement carefully.  
This Agreement imposes security obligations on yourself and limits the liability of VillageMall Certification Authority to you. By using the Digital Certificate, you are agreeing to be bound by the terms of this Agreement. If, you do not agree to the terms of this Agreement do not apply for or use the VillageMall Digital Certificate, or Token. 

This  Certification Agreement ("Agreement") takes effect from the date (the "Commencement Date") on the Digital Certificate issued by VillageMall to the You as a subscriber to VillageMall Certification Authority.

1. Definitions:

Approved Manner means the manner of using a Digital Certificate which is set out in clause 4.

Certificate Revocation List ("CRL") means the list from time to time of information regarding the status of Digital Certificates or a facility which enables the status of a Digital Certificate to be checked.

Certification Authority ("CA") means VillageMall or any other entity expressly authorised by VillageMall to issue Digital Certificates.

Client Application Software means a computer software program which is designed to directly facilitate end user functions in computing environment in conjunction with or by interacting with VillageMall Server Application Software.

Token mans any token issued by to you or to any Additional Token Holder, for use with your VillageMall Account from time to time.

VillageMall Account mans any account issued by VillageMall to you, for use within the VillageMall network  from time to time.

Client Certificate means:

    (1) the set of electronic information consisting of a Public Key, information about the Subscriber [other information which is contained in the Digital Certificate] and an expiry date;

    2) which has been digitally signed by either VillageMall CA performing the signing cryptographic operation using a Private Key; and

    3) which is to be used in connection with Client Application Software.

    4) which must be used according to the VillageMall Certificate Policy.

Common Name means that field of information which:

    (5) is provided by the Subscriber when the Subscriber applies for a Digital Certificate; and

    (6) forms part of the information contained in the Digital Certificate.

Digital Certificate means an X.509 Client or Server certificate.

VillageMall CA means the CA which digitally signs a Digital Certificate.

Authentication Information means information provided by you as part of the process of applying for a Digital Certificate which may be used by the Subscriber to revoke a Digital Certificate.

Private Key means that cryptographic key of a matching cryptographic key pair which is to be kept private by you, and stored within a Token.

Public Key means that cryptographic key of a matching cryptographic key pair which is to be available publicly.

Server Application Software means a computer software program which is designed to host, route or distribute data in a networked computing environment in conjunction with or by interacting with Client Application Software.

Server Certificate means:

    (7) the set of electronic information consisting of a Public Key, information about the Subscriber [other information which is contained in the Digital Certificate] and an expiry date;

    (8) which has been digitally signed by VillageMall CA performing the signing cryptographic operation using a Private Key; and

    (9) which is to be used in connection with a Server Application Software.

Subscriber means You, the individual or organisation making an application for a Digital Certificate.

Token-holder means You , the individual or organisation

Validity Period means the time calculated in accordance with Clause 3.

2. Use of Digital Certificate

VillageMall authorises the Subscriber, during the Validity Period, to use the Digital Certificate in the Approved Manner.

3. Validity Period

The Validity Period of a Digital Certificate runs from the Commencement Date until the earliest of:

    (1) the date 1 (one) year after the Commencement Date;

    (2) the expiry date asserted within the Digital Certificate;

    (2) the revocation of the Digital Certificate; or

    (3) the giving, on reasonable grounds, of notice by VillageMall that the Subscriber is in breach of a material obligation under this Agreement.

4. Approved Manner

4.1 The Subscriber may only use the Digital Certificate:

    (1) Within the VillageMall network, and in relation to the Common Name and the Application Software for which the Digital Certificate is issued; and

    (2) if requested by VillageMall, in conjunction with a device mark or logo supplied by VillageMall on the website of the Subscriber which provides a hypertext link to a website controlled by VillageMall which provides information in relation to Digital Certificates issued by VillageMall or a CA.

4.2 The Subscriber may not use the Digital Certificate or any reference to VillageMall or the Issuing CA:

    (1) after the end of the Validity Period; or

    (2) in any manner which represents that VillageMall CA uses, approves, endorses or is associated in any way with the Subscriber or with any goods or services used or provided by the Subscriber.

    (3) for any purpose not directly connected with the VillageMall community.

5. Subscriber Responsibility for Security

The Subscriber:

    (1) must use the Digital Certificate only in the Approved Manner;

    (2) warrants to VillageMall and the VillageMall CA that the Subscriber generated the matching cryptographic key pair immediately prior to the Subscriber applying for a Digital Certificate; and that the Subscriber's Private Key (or any part of it) was not available to any other person before the Subscriber applied for the Digital Certificate;

    (3) must keep, and use, the Subscriber's Private Key (or any part of it) and any system incorporating or using that Subscriber's Private Key (or any part of it) in such a manner as ensures that the Subscriber's Private Key is not compromised, provided that the Subscriber is not in breach of this obligation as a result of compromise of the Subscriber's Private Key as a result only of mathematical calculation which is unassisted by the Subscriber;

    (4). It is important that each Token-holder safeguard the Token and take precautions against unauthorised use of the Token and PIN. Specifically Token holders must:

    • not tell anyone the PIN, not even VillageMall staff, other members of an organisation; not let anyone else use the Token; and
    • take care to avoid letting anyone else see the PIN being entered. Each Token-holder should memorise his Or her PIN and then destroy any record of it. Even if Token-holder do not feel confident about remembering the PIN, they must not:
    • record it on the Token; or
    • record it on any article normally carried with the Token without making a reasonable attempt to disguise it in such a way that it cannot be ascertained or decoded by anyone else.

    (5) must ensure that any person having access to the Subscriber's Private Key does so only in accordance with the terms of this Agreement; and

    (6) must keep any authentication information in such a manner as ensures that the authentication information is readily available to the Subscriber for the purpose of revoking the Digital Certificate or ID but not available to any other person.

6. Unauthorised transactions

    (1) You will be liable for losses arising from unauthorised transactions entered into before you notify VillageMall that the Token has been misused, lost or stolen or that your PIN has become known to someone else where you  have contributed to such losses by for example.

    • indicating the PIN on the Token;
    • keeping a record of the PIN (without making any reasonable attempt to disguise it) with any article carried with the Token or likely to be lost or stolen simultaneously with it;
      or
    • voluntarily disclosing the PIN to someone else.

    You will be liable for any losses directly attributable to your unreasonable delay in notifying VillageMall of the misuse, loss or theft of the card or that the PIN has become known to someone else.

    You will be liable for transactions entered Into by means of the Token after its cancellation if, at the time of such transactions, you have failed to return the Token to VillageMall or report it lost or stolen to VillageMall.

    You will not he liable for losses resulting from unauthorised transactions before you have received your Token or after VillageMall has been notified that the Token has been misused, lost or stolen or the PIN has been disclosed to someone else.

    (2) If unauthorised transactions occur as a direct or indirect result of your failure to safeguard a Token or to report the loss, theft or unauthorised use of the Token, you indemnify VillageMall for any loss occasioned as a result of such transactions subject to any applicable limitation of liability or these Conditions of Use and VillageMall is authorised to debit Subscriber provided account for the amount of such transactions.

7. Subscriber Responsibility for Revocation and Notification

The Subscriber must request revocation of the Digital Certificate using the revocation facility on VillageMall's website, or directly from VillageMall CA immediately on:

    (1) the insolvency, winding up or bankruptcy of the Subscriber;

    (2) any reason to suspect that the Subscriber's Private Key (or any part of it) has been compromised which includes (without limitation) the temporary availability of the Subscriber's Private Key (or any part of it) to any person not expressly authorised by the Subscriber to use the Subscriber's Private Key and the compromise of the Subscriber's Private Key as a result of mathematical calculation;

    (3) any reason to suspect that the Subscriber's Token PIN has been compromised which includes (without limitation) the temporary availability of the Subscriber's Token PIN  to any person; or

    (4) any attempt by a person other than a person authorised by the Subscriber to use the Subscriber's Token.

and

notify VillageMall or VillageMall CA [immediately by e-mail] of:

    (a) any event for which the Subscriber must revoke the Digital Certificate identified above;

    (b) any change to the name or other identifying details of the Subscriber included in the application for a Digital Certificate; or

    (c) the commencement of any legal or quasi-legal claim or action of which the Subscriber is aware which in any way involves or relates to, or which in the reasonably formed opinion of the Subscriber might at a later stage involve or relate to, the existence of or information contained in the Subscriber's Digital Certificate.

8. Services Provided by VillageMall

VillageMall will:

    (1) use its reasonable efforts to make available to the Subscriber and to other persons including CA's, by electronic means, the CRL or information regarding the status of any Digital Certificate;

    (2) use its reasonable efforts to make available the website referred to in clauses 4.1(b) and 6;

    (3) revoke Digital Certificates in accordance with clause 8

provided that VillageMall will not be in breach of this Agreement for any failure or delay in the performance of these services as a result of any equipment or network breakdown or other act, omission or event which is beyond VillageMall's reasonable control.

9. Revocation of Digital Certificates

VillageMall may revoke the Digital Certificate:

When appropriate, VillageMall may alter the status of a Digital Certificate at VillageMall's sole discretion.

10. Reissue of Revoked Digital Certificates

Upon expiry of the Validity Period VillageMall or the Issuing CA will at the request of the Subscriber issue the Subscriber a new Digital Certificate on completion of the relevant verification process and payment by the Subscriber of the then current application fee. VillageMall or the Issuing CA may, in its sole discretion, waive the requirement of any of the steps of verification or the payment of the application fee.

11. Subscriber's Consent to Publish

The Subscriber agrees that VillageMall or any CA may at any time make available or publish by any means, information contained within the Subscriber's Digital Certificate or concerning the status of the Digital Certificate.

12. Subscriber's Undertaking to Make Enquires

The Subscriber agrees that at any time when the Subscriber is contemplating interacting with or relying on information in a digital document which is roughly functionally equivalent to a Digital Certificate ('certificate'), the Subscriber will make enquires which are reasonable in the circumstances to find information which will advise the Subscriber about the steps taken by the provider of the 'certificate' to verify the identity of the holder of the certificate and the limitation, if any, which that provider places on its liability to any person interacting with or relying on such a certificate.

13. Disclaimer of Warranty

To the maximum extent permissible by law, VillageMall CA disclaims any warranties with respect to the Digital Certificate and services provided by VillageMall CA under this Agreement including without limitation any and all implied warranties of merchantability or fitness for a particular purpose or use of skill to a particular standard. VillageMall gives no assurance of the security of any communications or the results of any encryption methods used by the Subscriber, VillageMall, or any other person. No oral or written information or advice given by VillageMall, any CA or their employees or representatives shall create a warranty or in any way increase the extent of VillageMall's obligations.

14. Limitation of Liability

Neither VillageMall nor the Issuing CA will be liable to the Subscriber for any consequential, indirect or incidental damages, loss of business, loss of management time whether foreseeable or unforeseeable, arising out of breach of any express or implied warranty, breach of contract, tort, misrepresentation, negligence, strict liability however arising, except only in the case of wilful misconduct, death or personal injury where and to the extent that applicable law requires such liability.

The parties agree that VillageMall's and the Issuing CA's total liability under this Agreement will not exceed the amounts paid by the Subscriber to VillageMall or the Issuing CA under this Agreement except to the extent that such liability arises from VillageMall's or the Issuing CA's wilful misconduct or in relation to death or personal injury.

The terms contained within this Agreement are in addition to the statutory rights implied by the trade practices act 1974 or any corresponding state or territory legislation applicable to the sale of this service to the Subscriber.

15. Term and Termination

This Agreement may be terminated:

16. Effect of Termination

Any termination of this Agreement and the rights and obligations under this Agreement will not affect any accrued rights or liabilities of either party, nor will it affect the coming into force or the continuance in force of any provision of this Agreement which is expressly, or by implication, intended to come into or to continue in force on or after termination.

17. Intellectual Property

Neither the Subscriber nor VillageMall nor any CA acquires any rights of any kind in any trademark, brand name, logo or product designation of the other party. The Subscriber must not make any use of any device or mark of VillageMall or a CA other than in the manner provided for in clause 4.1(2).

18. Miscellaneous

18.1 Assignment

The Subscriber may not assign, sub-license or otherwise transfer the Digital Certificate, this Agreement or any of its rights or obligations under this Agreement either in whole or in part.

18.2 Waiver of Remedies

No forbearance, delay or indulgence by either VillageMall or the Subscriber in enforcing the provisions of this Agreement will prejudice or restrict its rights, nor will any waiver of any right operate as a waiver of any subsequent breach. No right, power or remedy conferred in this Agreement on or reserved to either party is exclusive of any other right, power or remedy available to it and each such right, power and remedy is cumulative.

18.3 Severability

If the whole or any part of any provision of this Agreement proves to be illegal or unenforceable the other provisions of this Agreement and the remainder of the provision in question shall remain in full force and effect.

18.4 Entire Agreement

This Agreement and the documents referred to in it constitute the entire understanding and agreement of the parties with respect to its subject matter and supersede all prior and contemporaneous agreements or understandings between the parties.

18.5 Notices

Notice to VillageMall from the Subscriber with respect to this Agreement must be sent by signed e-mail and confirmed by facsimile to VillageMall as outlined from time to time on its website.  Notices to VillageMall are effective when they are first received, by whichever means.

Notices to the Subscriber from VillageMall with respect to this Agreement may be in electronic format and will be sent to the contact details provided by the Subscriber in the application for a Digital Certificate or as notified to VillageMall from time to time by the Subscriber. Notices to the Subscriber are deemed to be received:

18.6 Governing Law

This Agreement is to be governed by, construed and enforced according to the laws of the State of Queensland Australia.

19. All Tokens remain our property

You agree that any Token remains the property of VillageMall and agree to return the Token to us on:

20. Using the Token

20.1 When can you use your Token?

Your Token is valid only if it has a private key that is associated with a valid certificate issued by VillageMall or the Additional Token holder (whichever is appropriate) and is used during the validity period of the Certificate.

20.2 Where can you use your Token/Certificate?

(a) You can use your token and any contained or associated certificate within the VillageMall network.

(b) You can use your Token and certificate at any merchant site, institution, web server or terminal that is part of the VillageMall network.

(c) We are not responsible if a merchant or institution refuses to accept a Certificate. Subject to any applicable law, we are not responsible for goods or services supplied to you by a third party.

20.3 Token Loss or Theft

What to do:
You must immediately notify us if your Token is lost or stolen or you suspect that unauthorised transactions have been made using your Token.. We will give you a notification number or some other form of acknowledgement which you should retain as evidence of the date and time of your report. Where your report is made by telephone, we may require you to confirm it at one of our branches and complete certain documentation.

20.4 Your liability

(a) Until we receive notice of your lost or stolen Token or of any unauthorised transactions, you may be liable for unauthorised transactions made using your Token. You will not be liable for any unauthorised transactions made after we receive notice from you.

21. Non-Assignment

You may not assign your rights under this contract to another person. VillageMall may transfer this Agreement to someone else. If VillageMall wants to do so it can give anyone all information that privacy laws allow it to give. If VillageMall transfers this Agreement, the Agreement will apply to the transferee as if it were VillageMall.

22. Arbitration

The parties agree that they will use their best efforts to amicably resolve any dispute arising out of or relating to this Agreement. Either party may declare to the other party the existence of a dispute in writing stating the circumstances of the dispute, whereupon the parties shall meet without delay to attempt resolution of the dispute. Where resolution can not be effected after a reasonable period of time then the parties shall refer the dispute to an agreed arbitrator for resolution or where can not agree the choice of an arbitrator the then the dispute shall be referred to the nominee of the chairman for the time being the Institute of Arbitrators, Australia which arbitration shall be conducted under UNCITRAL Arbitration Rules at Brisbane in the English language in accordance with the laws of the State of Queensland. Each party shall bear its own costs and expenses and an equal share of the arbitrators expenses and administrative fees of arbitration.