Regula Terms of Service

Version 1.0.0 · Effective from 1 October 2026 · Zug, Switzerland
Document key: terms · Scope: all users · Language: English (authoritative)

Provider: KROIN AG, a company incorporated in Switzerland (Commercial Register no. CHE-498.889.894), Ahornstrasse 6, 6300 Zug, Switzerland ("KROIN AG", "we", "us"). Contact: support@kroin.net.

Companion documents, incorporated by reference: the Regula Privacy Policy (privacy) and the Regula Data Processing Agreement (dpa), each version 1.0.0. Users who register an organisation on Regula also sign the Level 2 Owner Declaration (l2-declaration).

How you accept these Terms. You accept them by signing them with your Regula wallet key. Your signature covers this exact document, identified by its version and cryptographic fingerprint (SHA-256), and is recorded by KROIN AG with a timestamp. You may download your signed copy at any time from Settings → Legal.


1. What Regula is

Regula is a self-custody digital identity wallet. With the Regula app (the "Platform") you create and hold a wallet controlled by a key that only you possess, you can have your identity verified at increasing levels, you can sign documents and acts so that anyone can verify who signed and when, you can log in to third-party services and share verified information with them case by case ("Login with Regula"), and — from Level 2 — you can register an organisation ("Entity") and manage its members with signed, verifiable mandates.

Two principles govern the service and rest on cryptography, not on policy:

  • Your data stays yours. Personal content you store in Regula (address book, documents, transaction vault) is encrypted on your device with keys KROIN AG does not hold. What reaches our servers is ciphertext, one-way lookup tokens and cryptographic fingerprints. The one exception is the identity dossier created during verification, which Section 4 describes precisely.
  • Every act is a signature. Anything you do that has legal or organisational effect — accepting these Terms, verifying a document, sharing data, creating an Entity, giving or taking a role — is an act signed with your key, timestamped, and where indicated anchored on the network as a fingerprint. Nothing is done "by the Entity" or "by KROIN AG" in your name without your signature.

2. Definitions

  • Wallet — your self-custody account on the network, controlled by your Key.
  • Key — the private key generated on your device from a seed that only you hold; it signs your acts and decrypts your content. KROIN AG never receives the seed or the private Key.
  • Login shares — access credentials issued by our servers to let you sign in on a device; they encode your account identifier and wallet address and are protected by a threshold scheme. They are not fragments of your Key and cannot decrypt your content.
  • Level — the degree to which your identity has been verified: Level 0 (no verification), Level 1 (identity document and face match), Level 2 (Level 1 plus a second government document, proof of address and payment). Each Level is an attestation dated by KROIN AG (Section 4.5).
  • Verified Data — identity attributes verified through KYC and stored under the rules of Section 4.
  • Act — a message in a fixed format, signed with your Key, that KROIN AG records; where indicated, its SHA-256 fingerprint (the commitment) is also written to the network (anchoring).
  • HumanSigned — the Regula service that lets you sign any file so that a third party can verify that a verified human signed it, at which Level, and when.
  • Login with Regula (LwR) — the consent-based flow to authenticate to, and share Verified Data with, a Relying Party.
  • Relying Party — a third party (business, authority or other organisation) to which you log in or disclose data through LwR.
  • Entity — an organisation registered on Regula by a Level 2 user (its Owner), with a verification status and members holding roles.
  • Member / Role — a person who joined an Entity by accepting a signed invitation, holding one of the roles Owner, Admin, Supervisor, Manager, Operator.
  • RGL — the network's utility unit used to pay for on-network operations (Section 7).

3. Accounts and eligibility

3.1 You must be at least 18 years old, legally capable of entering into a binding agreement and, where you act for an organisation, authorised to bind it.
3.2 One person, one identity: you may not hold or verify more than one Regula identity, or verify an identity that is not yours.
3.3 You are responsible for your device, your credentials and — above all — your seed and recovery material (Section 5).

4. Identity verification, Levels and re-verification

4.1 Provider. Verification is performed with Shufti Pro Ltd. as our processor. The data categories, flows and retention are described in the Privacy Policy, Sections 3 and 7.
4.2 What you warrant. The identity documents and data you submit are genuine, valid, your own and lawfully provided, and you will not submit forged, altered, impersonated or synthetic material (Section 12).
4.3 The identity dossier. Unlike the content described in Section 1, the verification result (document data, screening result, face-match score, images and timestamps) is data that KROIN AG must be able to retain and, when the law requires it, produce. It is held encrypted under the rules of the Privacy Policy, Section 7: retained for ten years after the end of our relationship, protected by a threshold scheme so that KROIN AG alone cannot open it, and opened only for the reasons stated there, with a record.
4.4 Validity and re-verification. Every Level is valid for twelve months from its attestation. Before it expires, you are invited to re-verify (Level 1 and, for Level 2, the additional checks again). Re-verification requires your participation: KROIN AG holds no data with which to verify you silently.
4.5 A Level is a dated statement, not a lock. Your Level is an attestation signed by KROIN AG stating that on a given date you were verified at that Level. It never blocks your wallet, which is yours. What changes with your Level is what Regula will attest about you from that moment on:

  • if a document has expired or been withdrawn, or you do not re-verify within 30 days after expiry, your Level lapses to the highest Level still supported by valid checks (down to Level 0), until you verify again;
  • acts you signed while verified remain valid as "signed at Level n on date"; new acts that require a Level are refused until you regain it;
  • if your Level lapses below Level 2 while you are the Owner of an Entity, Section 9.6 applies.
    4.6 Adverse findings. If verification shows a fraudulent document or a confirmed sanctions or politically-exposed-person hit that the law obliges us to act on, your Level is withdrawn immediately without a grace period, any Entity you own is suspended, and KROIN AG follows its legal obligations. Your wallet remains under your control; Regula's attestations, Login with Regula and HumanSigned are no longer available to you.

5. Self-custody: your seed, your recovery, your responsibility

5.1 How it works. Your Key is derived on your device from a seed you generate and keep. Personal content is encrypted on your device and only you can decrypt it. KROIN AG holds ciphertext and cannot read it: this is a technical fact, not a promise of good conduct.
5.2 Login shares are not your Key. To sign in on a device, our servers issue login shares (Section 2). Losing them means re-authenticating, not losing your wallet. Holding them gives KROIN AG no ability to sign for you or read your content.
5.3 Recovery. Access is recovered by proving possession of your seed with a signed challenge. During recovery you replace your contact details and password; where enabled, a face check is required. KROIN AG cannot bypass this procedure and will not attempt to.
5.4 If you lose your seed. KROIN AG cannot restore your Key, your wallet or your encrypted content. Loss of the seed, or wiping a device without recovery material, may mean permanent loss of access. You accept this as the condition of self-custody.
5.5 Owner-only access. Verified Data and stored content are returned only to their owner or to a recipient the owner has explicitly authorised.

6. Login with Regula

6.1 Consent, each time. Before you log in to a Relying Party you see which fields it requires and which are optional, and you sign your consent. Nothing is shared without it.
6.2 Grants. A share you authorise is a grant with a lifecycle (pending, active, expired, revoked). You may revoke it at any time with a signed act; revocation stops further access.
6.3 Relay, not inspection. KROIN AG relays what you chose to share and does not read it. Once shared, the Relying Party is an independent controller of that data under its own terms.
6.4 Relying Parties may require a Level. A Relying Party may restrict access to verified users, or to members of its Entity. Where your Level or membership no longer meets the requirement, access is refused.

7. Wallet, RGL and fees

7.1 Utility. RGL is the network's utility unit, used to pay the network fee of on-chain operations (anchoring an act, a signature or an attestation). Fees are determined by network parameters and shown before you sign.
7.2 Pilot network, no value. During the pilot the network is operated by KROIN AG. RGL is non-tradable, non-convertible, not redeemable for money or other assets, carries no monetary value, is provided solely to exercise Platform functions, and is not an investment. KROIN AG gives no financial, legal or tax advice and makes no representation as to any current or future value. Any future public distribution, tradability or migration would be governed by separate terms and by applicable Swiss financial-market law.
7.3 Who pays. The person who signs an act pays its network fee. KROIN AG may sponsor the fee of specific acts (for example accepting an invitation) and an Entity may sponsor the acts of its members; when a fee is sponsored, the record shows who paid.
7.4 Level 2 fee. The Level 2 verification is paid in fiat currency through our payment processor; the price is shown before payment. Fees paid are not refundable once the verification has been performed, except where the law provides otherwise.

8. Signatures, HumanSigned and anchoring

8.1 What a Regula signature is. A signature made with your Key is an electronic signature uniquely linked to your Key, created under your sole control and tamper-evident. Where your Level is 1 or higher, the signature is also linked to your verified identity through KROIN AG's Level attestation. Regula signatures are not qualified electronic signatures within the meaning of the Swiss Federal Act on Electronic Signatures (ZertES) or of the EU eIDAS Regulation; where the law requires a qualified signature or a handwritten form, a Regula signature does not replace it.
8.2 What HumanSigned proves. A HumanSigned verification page proves that a specific file (identified by its fingerprint) was signed by the holder of a specific Key, verified at a stated Level, at a stated time, and whether the signature was anchored on the network. It does not prove who authored the file, whether its content is true, or whether it was produced by a human or by software. A HumanSigned signature can be revoked by its signer; the page then shows the revocation.
8.3 What is anchored. Only fingerprints (SHA-256 commitments) and timestamps are written to the network — never personal content, never document content, never the text of a reason.
8.4 Anchors are permanent. Once written, an anchor cannot be altered or removed by anyone, including KROIN AG. Erasure (Privacy Policy, Section 8) applies to off-chain content; what remains on-chain is a fingerprint from which the erased information cannot be reconstructed.
8.5 Effect on receipt. An act takes effect when KROIN AG has verified its signature and recorded it. Anchoring is evidence of the act, not a condition of its effect; the record shows whether and when the anchor was confirmed.

9. Entities, Owners and Members

9.1 Creating an Entity. A Level 2 user may register an organisation (company, public authority, association, foundation or other) by submitting its data and supporting documents, each signed and anchored, and signing the creation act. The creator becomes the Entity's Owner. The Owner signs the Level 2 Owner Declaration, which sets out the Owner's responsibility for the Entity (Section 9.4).
9.2 Review. A new Entity is pending until KROIN AG (today directly; in future with a registry data provider it names in the Privacy Policy) has reviewed the submission. While pending, the Entity's data are frozen and its services are not available to third parties. KROIN AG may verify or reject with a stated reason. A verified Entity is shown on a public verification page containing its name, type, country, verification status and the fingerprint of its creation act — never the personal data of its Owner or members, never its documents.
9.3 Self-declared details. An Entity's website and contact e-mail are not part of the verified record. They may be changed by the Owner or an Admin; a changed detail is marked "self-declared" until it is verified through the procedure Regula offers for it.
9.4 The Owner's responsibility. The Owner warrants that the Entity exists, that the documents submitted are genuine and current, that the Owner is authorised to represent it, and that the Entity's use of Regula complies with the law. The Owner and the Entity are jointly and severally liable towards KROIN AG for the Entity's obligations under these Terms. This responsibility extends to every Entity the Owner registers now or in the future (Declaration, clause 2).
9.5 One Owner, signed mandates. Each Entity has exactly one Owner. Roles are given, changed and taken only by signed acts of a member whose role is higher than the affected role; the Owner acts on all roles; no one acts on the Owner. Freezing, demoting or removing a member requires a written reason, whose fingerprint is anchored and whose text is stored encrypted and readable only by the affected member and by persons the Entity has authorised to audit. A member may leave an Entity at any time by a signed act, except an Owner without a successor.
9.6 Succession and lapse. An Owner who wishes to leave designates a successor among the Entity's Admins verified at Level 2; the successor accepts by a signed act (including the Level 2 Owner Declaration) and becomes Owner. If the Owner's Level lapses below Level 2 (Section 4.5), the Entity is suspended after the grace period: its data remain, its members keep their roles, but its services to third parties are refused until the Owner re-verifies or a successor accepts.
9.7 Members' rights. Every member can see, in "My memberships", every act that concerns them in any Entity, including the reasons, can export that record, and can add a signed statement in reply to a freeze, demotion or removal. The statement does not reverse the act; it stands beside it in the same record.
9.8 Freezing takes effect immediately. When a member is frozen, removed or their mandate expires, their access to the Entity's services through Regula is withdrawn at once; their Regula wallet and their own data are unaffected.

10. Acceptable use

You will not: submit unlawful content or a false or impersonated identity; register an Entity you are not entitled to represent; infringe third-party rights; use a reason field to defame or to record data you have no right to process; circumvent access controls or attempt to defeat the custody, signature or anchoring mechanisms; or use the Platform in breach of applicable law, including data-protection, anti-money-laundering, export-control and sanctions rules.

11. Intellectual property

11.1 You retain all rights in your data and documents. You grant KROIN AG a limited licence to process the ciphertext, fingerprints and metadata solely to provide the service.
11.2 KROIN AG retains all rights in the Platform, its software, and the names and marks "Regula", "HumanSigned" and "KROIN".

12. Data Authenticity, Ownership and Provenance Undertaking

Because KROIN AG cannot inspect most of what you store and relies on the verification process for the rest, you represent and undertake, on a continuing basis, that: (a) the identity, documents and data you submit are your own, or you are lawfully authorised to submit them; (b) they are genuine, valid and unaltered, and you will not submit forged, altered, impersonated or synthetic material nor present such material as genuine; (c) where your data include third-party personal data — including the reasons you write about members of an Entity — you have the right and a lawful basis to process them; (d) your use of the Platform complies with applicable law. Breach entitles KROIN AG to suspend or terminate access with immediate effect, to withdraw attestations and grants, and to pursue any remedy at law; you will indemnify KROIN AG against third-party claims arising from your breach.

13. Cookies and local storage

The Platform uses only strictly necessary local storage and session tokens to operate and secure your session. No advertising, marketing, cross-site tracking or profiling analytics are used. Any non-essential technology would be introduced only with your consent.

14. Pilot phase

The Platform is offered during a pilot on an invitation basis, "as is", against a network operated by KROIN AG. Features may change and some functions may be introduced gradually. Where a change affects what you have signed, Section 18 applies.

15. Warranties and disclaimers

The Platform is provided "as is" to the extent permitted by law. KROIN AG does not warrant the recovery of a lost seed (Section 5.4), does not warrant that a Relying Party will accept a Level or a signature, and does not provide legal, financial or advisory services. An Entity's verification status is KROIN AG's statement that the submitted documents were reviewed, not a guarantee of the Entity's conduct.

16. Limitation of liability

To the extent permitted by law, KROIN AG's aggregate liability arising out of or in connection with the Platform is limited to the fees you paid to KROIN AG in the twelve months preceding the event giving rise to the claim, and in any case to CHF 1,000 per user. Nothing limits liability that cannot be limited by law (intent, gross negligence, personal injury). KROIN AG is not liable for loss resulting from the loss of your seed or recovery material, for acts of a Relying Party or of an Entity, or for the content of what you sign.

17. Suspension and termination

17.1 KROIN AG may suspend or terminate access for breach of Sections 10 or 12, for an adverse finding under Section 4.6, or for non-payment. You may close your account at any time; an Owner must first transfer the Entity or close it.
17.2 On termination your encrypted content is deleted or crypto-shredded under the Privacy Policy; the identity dossier is retained for the legal period; anchors persist by design (Section 8.4).

18. Changes to these Terms

KROIN AG may update these Terms. Each version has a number and a fingerprint. Material changes (a new major version) are notified thirty days before they take effect, with a plain-language summary of what changed, and require your new signature before you continue to use the Platform. Minor clarifications are notified in the app and do not require a new signature. All versions remain available for download.

19. Governing law and disputes

These Terms are governed by Swiss law. The courts of Zug, Switzerland have exclusive jurisdiction, subject to mandatory consumer-protection rules that give a consumer another forum. Personal-data matters are governed by the Swiss Federal Act on Data Protection (FADP) and, where applicable, the GDPR, as set out in the Privacy Policy.

20. Contact

KROIN AG · Ahornstrasse 6, 6300 Zug, Switzerland · support@kroin.net (service) · privacy@kroin.net (data protection).