IMPORTANT — READ BEFORE USING THE APPLICATION
This End User Licence Agreement (“Agreement”) is a binding legal agreement between you, the business accepting payments (“Merchant”, “you”), and KaiOS.
By tapping “I ACCEPT”, by activating the Kai MPoC Application, or by using the Application to process a payment, you confirm that:
- you have read and understood this Agreement;
- you accept it on behalf of the business named in your merchant profile; and
- you are authorised to bind that business.
If you do not accept this Agreement, do not activate or use the Application. Payment acceptance functionality will not be enabled.
What this Agreement covers — and what it does not
| This Agreement (KaiOS) covers | This Agreement does NOT cover |
|---|---|
| Your licence to use the Kai MPoC Application and the software on the Device | Your merchant agreement with your bank |
| How the Device must be kept secure and used | The supply of the Device to you — its price, ownership, warranty, repair and replacement |
| Software updates, security monitoring and support of the Application | Your merchant account, onboarding and KYC |
| Your security responsibilities when accepting payments on the Device | Card acceptance, authorisation, clearing, settlement and payout of funds |
| Merchant discount rate, transaction fees, chargebacks and disputes |
Your payment acceptance service is provided to you by your Acquiring Bank (the bank, financial institution, payment service provider or mobile money operator that onboarded you and holds your merchant account, the “Acquirer”), under a separate agreement between you and the Acquirer (the “Merchant Services Agreement”). KaiOS is not a party to that agreement, is not your acquirer, does not hold merchant funds, and does not decide whether a transaction is approved or when you are paid.
KaiOS supplies the technology. Your Acquirer supplies the device, the merchant account and the payment service.
1. DEFINITIONS
“A&M” (Attestation and Monitoring) means the KaiOS backend system that continuously verifies the security state and integrity of the Device and the Application, as required by the PCI MPoC Standard.
“Acquirer” means the bank, financial institution, payment service provider, payment facilitator or mobile money operator that has onboarded you as a merchant and with which you have entered into the Merchant Services Agreement.
“Application” means the Kai MPoC Application, being the MPoC payment acceptance application supplied by KaiOS, including the MPoC SDK, the EMV kernels, the PIN entry component and any Application Updates, documentation and configuration data supplied with it.
“Application Update” means any patch, correction, security fix, new version or configuration change to the Application by KaiOS.
“Approved Device List” means the list of device models, hardware revisions and operating system versions approved by KaiOS for use with the Application, published in the Application and at https://merchant.kaiostech.com/mpoc/devices and updated from time to time.
“Cardholder” means a person presenting a payment card, mobile wallet or other payment credential to you for a Transaction.
“Cardholder Data” means account data relating to a payment card or payment credential, including the primary account number, expiry date and any PIN or PIN block.
“COTS Software Update” means any patch, correction, security fix, new version for Device software supplied by OEM vendor.
“Device” means the KaiOS-approved COTS (commercial off-the-shelf) device on which the Application is installed and licensed to run, provided to you by your Acquirer or by a Distributor acting for your Acquirer, and of a model identified in the Approved Device List. The Merchant shall ensure the Device accepts the latest COTS Software Updates when received over-the-air, to be align with MPoC Application requirement on COTS Operating Systems.
“Distributor” means any party appointed by the Acquirer or by KaiOS to supply, deploy, provision or support Devices and the Application in your market.
“MPoC Standard” means the PCI Security Standards Council Mobile Payments on COTS (MPoC) Security and Test Requirements, as amended, and the associated PCI MPoC Programme Guide.
“Payment Backend Provider” means the PCI DSS and PCI PIN certified payment processing platform that connects the Application to the Acquirer and the payment networks.
“Product Baseline” means the combination of Device model, operating system version, Application version and configuration approved by KaiOS as compliant with the MPoC Standard.
“Solution” means the certified MPoC solution that supports mobile payment acceptance and protection of account data on COTS device. It includes the MPoC Application, the attestation system, and the back-end systems and environments that perform attestation, monitoring, and payment processing.
“Transaction” means a payment, refund, reversal or other financial operation initiated through the Application.
2. LICENCE GRANT
2.1 Licence. Subject to your continuing compliance with this Agreement, KaiOS grants you a limited, non-exclusive, non-transferable, non-sublicensable, revocable licence, for the term of this Agreement, to install and use the Application in object code form on an approved Device, solely:
- to accept Transactions in the course of your own lawful business;
- in the country or countries in which you have been onboarded by your Acquirer; and
- in accordance with the user documentation supplied with the Application.
2.2 No sale. The Application is licensed, not sold. KaiOS and its licensors retain all right, title and interest in and to the Application, the Device software, the A&M and all related intellectual property.
2.3 Licence is tied to your merchant status. The licence is granted to you as an onboarded merchant of the Acquirer. If your Merchant Services Agreement ends, is suspended, or your merchant account is closed, the licence granted under this Agreement is suspended or terminates automatically at the same time (see clause 13).
2.4 One business, one licence. The Application must be used only by you and your authorised staff, for your own business, at the locations and for the merchant category recorded in your merchant profile. You may not allow any third party to use the Application to accept payments on its own behalf.
2.5 Activation and provisioning. The Application must be installed and activated only through the approved process: it is either pre-installed on the Device before the Device is provided to you, or downloaded from the KaiOS-approved distribution channel. It is then activated using unique configuration and credential data issued to you by the Acquirer or the Distributor and bound to your merchant profile and to that specific Device. You must not attempt to install the Application by any other means, to use configuration or credential data issued to another merchant or Device, or to transfer your provisioning data to another device. The step-by-step activation procedure is set out in the user documentation provided with the Device, and changes to it will be communicated to you under clause 8.
3. LICENCE RESTRICTIONS
You must not, and must not permit any person to:
- copy, modify, adapt, translate, reverse engineer, decompile, disassemble or attempt to derive the source code of the Application or the Device software, except to the extent this restriction cannot lawfully be excluded;
- rent, lease, lend, resell, sublicense, distribute, assign or otherwise make the Application available to any third party;
- remove, obscure or alter any proprietary notice, brand, trademark, security marking or version identifier;
- circumvent, disable, tamper with or attempt to defeat any security feature, integrity check, attestation mechanism, anti-tamper protection, encryption, key management or licence control in the Application, the Device or the A&M;
- install or run the Application on any device that is not on the Approved Device List, or on any device that is rooted, jailbroken, unlocked, running a modified or unofficial operating system, running an emulator or virtualised environment, or on which the bootloader has been unlocked;
- run the Application on a Device that has been modified in hardware or software otherwise than by your Distributor or a repairer approved by your Acquirer;
- intercept, capture, log, screenshot, screen-record, photograph or otherwise record the PIN entry screen or any Cardholder Data displayed or entered on the Device;
- install on the Device any application, keyboard, accessibility service, screen overlay, screen recorder, remote access tool or software that could observe, capture or interfere with the Application or with PIN entry;
- use the Application to accept Transactions that are unlawful, that are prohibited by your Acquirer or by the payment network rules, that are not genuine sales of your own goods or services, or that are for personal, family or household purposes rather than a bona fide commercial purpose;
- use the Application to process a Transaction on your own payment card or on a card you control, other than as expressly permitted by your Acquirer;
- use the Device as an unattended payment terminal, leave it accessible to the public without supervision, or allow a Cardholder to hold or operate the Device other than for the purpose of presenting their card and entering their PIN under your supervision; or
- use the Application in any way that would cause KaiOS, the Payment Backend Provider or the Acquirer to breach the MPoC Standard, PCI DSS or payment network rules.
4. THE DEVICE — CONDITIONS OF USE
4.1 KaiOS does not supply the Device to you. The Device is provided to you by your Acquirer, or by a Distributor acting for your Acquirer. Title to the Device, risk, price, deposit, lease or loan terms, delivery, replacement, repair, hardware warranty and return are matters between you and your Acquirer under the Merchant Services Agreement or the separate device terms given to you with the Device. KaiOS is not the supplier or seller of the Device to you and gives you no hardware warranty. Nothing in this clause 4 creates a supply relationship between you and KaiOS.
4.2 Why this clause exists. KaiOS is nevertheless the provider of the certified MPoC Solution, and that certification depends on the Device remaining in an approved and unmodified state. The conditions in this clause 4 are therefore conditions of your licence to run the Application on the Device. If you do not meet them, the Application may stop working on that Device, whatever your device arrangements with your Acquirer say.
4.3 Approved configuration only. The Application is certified only on the Devices, operating system versions and Application versions in the Product Baseline. As KaiOS continuously update the Product Baseline, the Merchants shall accept each and any Application Updates and COTS Software Update to remain in conformity with the approved configuration. You must not use the Application on any other configuration. KaiOS may block the Application on any Device outside the Product Baseline.
4.4 Device integrity. You must keep the Device in the state in which it was provided to you and accept any COTS Software Update received by the Device. You must not root, jailbreak, unlock, re-flash, downgrade, sideload system software onto, or otherwise modify the Device, and must not install software from sources other than the your distributer-approved distribution channel.
4.5 Physical control. You are responsible for the physical security of the Device while it is in your possession. You must keep it under your control or the control of your authorised staff, and must not lend, give, sell or transfer it to any person who is not authorised to use it. This is without prejudice to whatever obligations you owe your Acquirer in respect of the Device.
4.6 Loss, theft or compromise. If the Device is lost, stolen, damaged, tampered with, or you suspect it has been compromised, you must stop using it immediately and notify your Acquirer support without undue delay and in any event within 24 hours of becoming aware.
4.7 End of support. KaiOS will notify you in advance, in accordance with clause 8, if your Device model or operating system version is approaching the end of its support period and can no longer be accommodated in the Product Baseline. After the notified date the Application may cease to function on that Device. Obtaining a replacement Device is a matter between you and your Acquirer; KaiOS will give the Acquirer the same notice so that replacement can be arranged.
4.8 Faults and repairs. If the Device is faulty or damaged, contact your Acquirer. Do not have the Device opened, repaired or serviced by anyone other than a repairer approved by your Acquirer — an unapproved repair will take the Device outside the Product Baseline and payment acceptance will be disabled.
5. YOUR SECURITY RESPONSIBILITIES
You acknowledge that the security of payment acceptance on a COTS device depends on you as well as on KaiOS. You must:
5.1 Protect PIN entry. Ensure that, when a Cardholder enters their PIN, the screen cannot be observed by you, your staff, other customers, a mirror, a camera, CCTV or any recording device. You must never ask for, look at, note down, or assist in entering a Cardholder’s PIN.
5.2 Keep credentials secret. Keep secret the credentials, activation codes, passwords, PIN codes and provisioning data issued to you for the Application and the Device. Do not share them, write them down where they can be found, or reuse them elsewhere. Notify your Acquirer immediately if you believe a credential has been disclosed.
5.3 Control who uses the Device. Allow only trained, authorised staff to operate the Application. Remove access promptly for anyone who leaves your business.
5.4 Apply Updates (Application Update and COTS Software Update). Install every Update once it is available for you. Updates may include security fixes that are mandatory for continued MPoC compliance. Payment acceptance may be disabled on a Device that has not applied a mandatory Update.
5.5 Do not install risky software. Do not install applications other than from the KaiOS-approved distribution channel (KaiStore).
5.6 Keep the Device connected. The Application requires network connectivity for attestation, monitoring and Transaction processing. You are responsible for the cost and availability of that connectivity.
5.7 Handle Cardholder Data correctly. Never write down, photograph, store, or repeat a card number, expiry date, security code or PIN. The Application is designed so that you never need to. Never accept a card number verbally or on paper for entry into the Application unless your Acquirer has expressly authorised that method.
5.8 Report incidents. Notify your Acquirer without undue delay, and in any event within 24 hours, if you become aware or suspect: tampering with the Device; unauthorised access to the Application; a suspicious message purporting to come from KaiOS or your Acquirer; unusual Application behaviour; or any actual or suspected compromise of Cardholder Data.
5.9 Peripherals. The Solution is certified for use without peripherals. You must not connect any card reader, magnetic stripe reader or PIN entry device to the Device or use one with the Solution. Where KaiOS approves a peripheral for use in a future release, it will be notified to you under clause 8.
5.10 Cooperate with investigations. Provide reasonable cooperation, information and access to the Device to KaiOS, your Acquirer, the payment networks and their appointed investigators in the event of a suspected security incident, and to any assessor or regulator entitled to inspect the Solution.
5.11 Conduct at the point of sale. When taking a payment you must: let the Cardholder present their own card or device and enter their own PIN without assistance from you; hold the Device so that the Cardholder can enter the PIN unobserved, or hand the Device to the Cardholder for PIN entry and take it back immediately afterwards; not take possession of, retain or copy a Cardholder’s card; not complete a Transaction on behalf of a Cardholder who is not present, unless your Acquirer has expressly authorised that transaction type; and provide the Cardholder with a receipt or transaction confirmation in the form and by the means required by your Acquirer.
A plain-language summary of these responsibilities is provided at Annex A and is displayed in the Application.
6. ATTESTATION, MONITORING AND SECURITY ENFORCEMENT
6.1 Continuous monitoring. The MPoC Standard requires the Solution to continuously verify that the Device and the Application are in a secure state. You acknowledge that the A&M collects and processes technical information from the Device for this purpose. That information falls into two groups.
- Security attestation, required by the MPoC Standard: Device and Application identifiers and versions; hardware configuration, operating system state and integrity measurements; environment security checking (e.g. root, tamper, debugger, emulator, integrity) results; installed-package and configuration signals relevant to security; network and location signals as required, including the Device’s location where the Device provides it; audit logs for risk assessment; and Application security event logs.
- Additional monitoring carried out by KaiOS: records of key-injection, enrolment and Transaction activity (the type, time and outcome of each operation, and the amount and currency of a Transaction, but not the Cardholder’s payment details) which KaiOS uses to detect abnormal activity and to monitor the performance and reliability of the Solution.
The legal basis on which KaiOS processes this information is set out in the Privacy Notice.
6.2 What is not collected. The A&M does not collect the Cardholder number, PIN, merchant name, password, phone number. Cardholder Data is transmitted only through the certified secure channel to the Payment Backend Provider and is not retained on the Device after the Transaction completes.
6.3 Automatic protective action. Where the A&M or KaiOS detects a condition that presents a security risk — including a rooted or tampered Device, a failed integrity check, an out-of-date Product Baseline, a prohibited application on the Device, an anomalous usage pattern, or an instruction from your Acquirer or a payment network — KaiOS may, without prior notice where the risk requires immediate action:
- disable payment acceptance on the affected Device;
- suspend or terminate the Application session;
- require re-provisioning or re-attestation of the Device; or
- block the Device from the Solution.
6.4 Notification. Where KaiOS takes action under clause 6.3, it will notify you through the Application and, where the condition is remediable, tell you what you need to do to restore service. If you want the action reviewed by a person, contact your Acquirer, who will raise it with KaiOS. KaiOS carries out the review, because KaiOS operates the checks, and your Acquirer will give you the outcome.
6.5 No monitoring of your business. KaiOS does not use A&M data to monitor your commercial performance, your customers, or your business activity beyond what is necessary for security, fraud prevention, compliance and support.
7. UPDATES, MAINTENANCE AND AVAILABILITY
7.1 Application Updates. KaiOS may issue updates at any time. All updates are mandatory, including security updates and updates required to maintain MPoC certification. You agree to permit the automatic download and installation of updates.
7.2 COTS Software Updates. KaiOS may deliver security patch in KaiOS and MPoC application may require certain security patch level to run. OEM will deliver FOTA packages which include such OS security updates. All updates are mandatory, including security updates and updates required to maintain MPoC certification. You agree to permit the OS OTA download and installation of updates.
7.3 Changes to the Product Baseline. KaiOS may change the Product Baseline, including by adding or withdrawing supported Device models, operating system versions or Application versions. You will be notified in advance of any change that requires action from you (see clause 8).
7.4 Planned maintenance. KaiOS will use reasonable efforts to notify you in advance of planned maintenance that will make the Application or the A&M unavailable, and to schedule it outside typical trading hours in your market.
7.5 Availability. The Application depends on the Device, your network connectivity, the A&M, the Payment Backend Provider, the Acquirer and the payment networks. KaiOS does not warrant uninterrupted or error-free operation and gives no service level commitment to you directly under this Agreement. Any service level applicable to your payment acceptance service is a matter between you and your Acquirer.
8. HOW KAIOS COMMUNICATES WITH YOU
8.1 Channels. KaiOS (or the Acquirer or Distributor on its behalf) will communicate with you through one or more of: in-Application messages and notifications; the Device notification screen; the support page at https://merchant.kaiostech.com/mpoc/support; and the merchant tutorial portal at https://merchant.kaiostech.com/mpoc/tutorial.
8.2 What you will be told. KaiOS will inform you, in advance where practicable, of at least:
- changes to the Product Baseline, including the Device models and operating system versions supported, and any Device approaching end of support;
- changes to the user documentation, including how the Application is installed and provisioned, how to use it securely, your security responsibilities, information about any peripheral used with the Solution, and how to contact support;
- planned maintenance downtime;
- matters concerning credentials provisioned to you, including re-provisioning and expiry;
- information about any actual or potential compromise or security incident affecting the Solution, and any action you must take; and
- changes to this Agreement (see clause 15).
8.3 Keep your details current. You must keep your contact details up to date with your Acquirer and must read communications sent to you. Communications sent through the Application are deemed received when displayed.
8.4 Urgent security communications. Where a security condition requires immediate action, KaiOS may communicate through any available channel and may act under clause 6.3 before or at the same time as notifying you.
9. THIRD-PARTY SERVICES AND APPLICATIONS
9.1 Payment services. All payment acceptance, authorisation, settlement, funding, refunds, chargebacks and dispute handling are provided by your Acquirer and its Payment Backend Provider under the Merchant Services Agreement. KaiOS is not responsible for those services, for any decision to approve or decline a Transaction, or for the timing or amount of any settlement to you.
9.2 Other applications on the Device. Where the Device supports other applications (including a merchant super-app, mobile money or third-party applications from the KaiOS distribution channel), those applications are governed by their own terms. This Agreement covers only the Application.
9.3 Network rules. Your acceptance of cards is also subject to the operating rules of the applicable payment networks, as passed on to you by your Acquirer.
10. PERSONAL DATA
10.1 Our role depends on the data.
- Payment acceptance data — your Acquirer is the controller. Your Acquirer determines the purposes and means of processing your merchant data, Cardholder Data and Transaction data, and is the data controller in respect of that data. KaiOS transmits it through the Solution and processes it only as a service provider acting on the documented instructions of the Acquirer (and, where applicable, of the Payment Backend Provider acting for the Acquirer). Any question about how that data is used, retained or disclosed should be directed to your Acquirer in the first instance.
- Data KaiOS determines itself — KaiOS is the controller. For a limited set of data KaiOS decides the purposes and the means, and is the controller: your acceptance of this Agreement and of the Privacy Notice (the version accepted, the date and time, and your merchant and Device identifiers); the attestation, monitoring and service-performance information described in clause 6.1; and records of support or security matters you raise with KaiOS directly. The Privacy Notice sets out how KaiOS handles that data and how you may exercise your rights over it.
10.2 Pass-through of payment data. Cardholder Data entered on the Device is encrypted at the point of capture and transmitted through the certified secure channel to the Payment Backend Provider and the Acquirer. KaiOS cannot decrypt it (KaiOS does not hold the keys required to do so), does not store it, and does not use it for any purpose of its own. PINs are never available to KaiOS in clear form.
10.3 Technical data processed to keep the Solution secure. KaiOS processes the Device and Application technical data described in clause 6.1, together with your business contact and support data, strictly for the purposes of: operating and securing the Solution; detecting and responding to security incidents, abnormal activity and fraud; monitoring the quality, performance and reliability of the Solution; providing support; and meeting its obligations under the MPoC Standard, PCI DSS, payment network rules and applicable law. KaiOS does not use this data to profile you, to market to you, or for any commercial purpose of its own.
10.4 KaiOS’s obligations as a service provider. In respect of all personal data it handles under this Agreement, KaiOS will: process it only as instructed by the Acquirer or as required by law; apply appropriate technical and organisational security measures; impose confidentiality obligations on its personnel; engage sub-processors only where permitted under its agreement with the Acquirer and remain responsible for them; assist the Acquirer in responding to requests from individuals and to regulators; notify the Acquirer without undue delay of any personal data breach affecting the Solution; and delete or return the data at the end of the engagement, save where retention is legally required.
10.5 Requests from individuals. Where a request relates to data for which your Acquirer is the controller under clause 10.1, KaiOS will not respond substantively but will refer the request to your Acquirer and assist the Acquirer in responding. Where a request relates to data for which KaiOS is the controller under clause 10.1, KaiOS will respond directly in accordance with applicable law; where KaiOS is required to retain information for compliance, certification or evidential reasons, it will tell you so.
10.6 Disclosure. KaiOS may disclose data to your Acquirer, the Payment Backend Provider, the Distributor, the payment networks, its assessors and auditors, its hosting, infrastructure and security service providers, KaiOS group companies providing technical, security or support functions, and to regulators, courts or law enforcement where legally required. The Privacy Notice identifies which of these act on KaiOS’s behalf and which act for their own purposes.
10.7 Transfers and retention. Details of processing locations, international transfers and retention periods are set out in the KaiOS Privacy Notice at https://merchant.kaiostech.com/privacy, which forms part of this Agreement, and are governed by the data processing terms agreed between KaiOS and your Acquirer.
10.8 Your obligations. You must comply with applicable data protection law in respect of Cardholder and customer personal data you handle, and must provide your customers with the disclosures required of you by law and by your Acquirer.
11. WARRANTIES AND DISCLAIMERS
11.1 KaiOS warranty. KaiOS warrants that the Application, when used on an approved Device within the Product Baseline and in accordance with the documentation, will perform substantially in accordance with that documentation, and that the Solution is certified against the MPoC Standard for the certified configuration.
11.2 No hardware and device OS software warranty from KaiOS. KaiOS gives you no warranty in respect of the Device as an item of hardware and device OS software — including its condition, durability, battery, screen, fitness for purpose or freedom from defects. The Device is provided to you by your Acquirer, and any warranty, repair or replacement right you have in respect of the hardware is given by your Acquirer or the Distributor under the terms provided to you with the Device. Clause 11.1 is a warranty about the Application only.
11.3 Disclaimer. Except as expressly stated in clause 11.1 and to the maximum extent permitted by applicable law, the Application and the Device software are provided “as is” and “as available”, and KaiOS disclaims all other warranties, express or implied, including implied warranties of merchantability, fitness for a particular purpose, non-infringement, accuracy and uninterrupted availability.
11.4 Statutory rights. Nothing in this Agreement excludes or limits any right you have under applicable law that cannot lawfully be excluded or limited.
11.5 No financial advice or guarantee. KaiOS does not guarantee that any Transaction will be authorised, that funds will be received, or that the Application will detect every fraudulent card or Transaction.
12. LIABILITY
12.1 Excluded losses. To the maximum extent permitted by law, KaiOS is not liable to you for: loss of profit, revenue, business, goodwill, anticipated savings or data; business interruption; any defect in, damage to, loss of or failure of the Device as an item of hardware; the failure of your Acquirer or a Distributor to deliver, repair or replace a Device; the acts or omissions of your Acquirer, the Payment Backend Provider, a Distributor or a payment network; unauthorised or fraudulent Transactions; chargebacks; the non-receipt, delay or shortfall of settlement funds; or any indirect or consequential loss.
12.2 Cap. To the maximum extent permitted by law, KaiOS’s total aggregate liability arising out of or in connection with this Agreement, whether in contract, tort (including negligence), statute or otherwise, is limited to the greater of:
- the amounts (if any) paid by you for the Application, whether to KaiOS, the Acquirer or a Distributor, in the 12 months before the event giving rise to the claim; and
- US$50 (fifty United States dollars), or its equivalent in the currency in which you were invoiced.
12.3 Your liability. You are responsible for loss arising from your breach of clauses 3, 4 or 5, including any loss resulting from your failure to keep the Device secure, to protect PIN entry, to apply Application Updates and COTS Software Updates, or to report a suspected compromise.
12.4 Carve-outs. Nothing in this Agreement limits liability for death or personal injury caused by negligence, for fraud or fraudulent misrepresentation, or for any other liability that cannot lawfully be limited.
13. SUSPENSION AND TERMINATION
13.1 Term. This Agreement starts when you accept it and continues until terminated under this clause.
13.2 Termination by you. You may terminate at any time by ceasing to use the Application and uninstalling or returning the Device. Termination of this Agreement does not terminate your Merchant Services Agreement.
13.3 Automatic suspension or termination. The licence granted under clause 2 is suspended or terminates automatically, without notice, if your Merchant Services Agreement is suspended or terminated, or if your Acquirer instructs KaiOS to suspend or remove your access.
13.4 Termination by KaiOS. KaiOS may suspend or terminate the licence immediately on notice if: you breach clause 3, 4 or 5; the Device is outside the Product Baseline and you do not remediate within the notified period; KaiOS reasonably suspects fraud, tampering or a security compromise; or continued provision would put KaiOS in breach of the MPoC Standard, PCI DSS, payment network rules or applicable law.
13.5 Effect of termination. On termination you must immediately stop using the Application and uninstall it where instructed. Any obligation to return the Device is owed to your Acquirer under your arrangements with it, not to KaiOS.
13.6 Decommissioning. On termination, or when a Device is withdrawn from service, returned, sold, transferred or replaced, KaiOS will remotely disable payment acceptance and remove or render unusable the cryptographic keys, credentials and configuration data provisioned to that Device. You must not sell, transfer, dispose of or scrap a Device before this decommissioning has been completed, and you must notify your Acquirer before doing so. Where remote decommissioning is not possible, you must return the Device to your Acquirer or the Distributor for secure erasure.
13.7 Survival. Clauses 1, 3, 10, 11, 12, 13.5, 13.6, 13.7, 14, 16 and 17 survive termination.
14. INTELLECTUAL PROPERTY
14.1 Ownership. KaiOS, the Solution, the Application, the A&M, the documentation and all associated intellectual property rights are and remain the property of KaiOS and its licensors. No rights are granted to you other than the licence in clause 2.
14.2 Third-party components. The Application includes components licensed to KaiOS by third parties, including EMV kernels, cryptographic libraries and open source software. Attributions and applicable third-party licence terms are available in the Application under Settings > Open Source Licences. Where a third-party open source licence conflicts with this Agreement in respect of that component, the third-party licence prevails for that component.
14.3 Trademarks. “KaiOS” and associated logos are trademarks of KaiOS. You are granted no right to use them. Where the Application is presented under your Acquirer’s brand, that brand belongs to the Acquirer.
14.4 Feedback. If you provide suggestions or feedback about the Application, KaiOS may use them without restriction or payment.
15. CHANGES TO THIS AGREEMENT
15.1 Amendment. KaiOS may amend this Agreement where reasonably necessary, including to reflect changes to the Application, the MPoC Standard, PCI DSS, payment network rules, or applicable law.
15.2 Notice. KaiOS will give you at least 30 days’ notice of a material change through the Application or the contact details in your merchant profile, except where a shorter period is required for security, certification or legal compliance reasons.
15.3 Acceptance. Continued use of the Application after the change takes effect constitutes acceptance. If you do not accept a change, you must stop using the Application and may terminate under clause 13.2.
15.4 Version history. The current version of this Agreement, and previous versions, are available in the Application under Settings > Terms of Services and at https://merchant.kaiostech.com/mpoc/terms. Each version carries a version number and effective date, and the version you accepted and the date of your acceptance are recorded.
16. SUPPORT AND HOW TO CONTACT KAIOS
16.1 KaiOS support. For anything concerning the Application or the security of the Solution, contact KaiOS:
- Email: merchant@kaiostech.com
- Web: https://merchant.kaiostech.com/feedback
- Security incidents and suspected compromise: contact your Acquirer immediately if the Device is lost, stolen, tampered with or behaving abnormally
16.2 Device support. For any issue related to your device (damaged, faulty device), contact your Distributor.
16.3 Your Acquirer’s support. For anything concerning your merchant account, your money, a Transaction, a fee, a refund or a dispute, contact your Acquirer.
16.4 First-line support. Where your Acquirer or a Distributor provides first-line support, contact them first; they will escalate to KaiOS where necessary. This does not affect your right to contact KaiOS directly about a security matter, through KaiOS support channels provided in 16.1.
16.5 Keeping the contact details current. The current support contact details are always available in the Application and at https://merchant.kaiostech.com/mpoc/support, and take precedence over any details printed elsewhere.
17. GENERAL
17.1 Entire agreement. This Agreement, together with the documents referred to in it, is the entire agreement between you and KaiOS regarding the Application and supersedes any prior statement, other than any fraudulent misrepresentation.
17.2 Consideration. The licence granted by KaiOS and the undertakings given by you under this Agreement, including those in clauses 3, 4, 5 and 6, are given in consideration of each other and constitute good and valuable consideration, whether or not any payment is made by you to KaiOS.
17.3 No partnership or agency. Nothing in this Agreement creates a partnership, joint venture, employment or agency relationship between you and KaiOS. KaiOS is not your agent and does not act on your behalf in dealings with your Acquirer.
17.4 Assignment. You may not assign or transfer this Agreement. KaiOS may assign it to an affiliate or in connection with a corporate reorganisation, merger or sale of the business, on notice to you.
17.5 Third parties. Your Acquirer, the Payment Backend Provider, the Distributor and KaiOS’s licensors may enforce any provision of this Agreement that benefits them, under the Contracts (Rights of Third Parties) Ordinance (Cap. 623) of Hong Kong. No other person has any right under that Ordinance to enforce any provision of this Agreement. KaiOS and you may vary or rescind this Agreement without the consent of any third party.
17.6 Severability. If any provision is held invalid or unenforceable, the remainder continues in force and the invalid provision is to be read down to the minimum extent necessary.
17.7 No waiver. Failure or delay in enforcing a right is not a waiver of it.
17.8 Force majeure. KaiOS is not liable for failure or delay caused by events beyond its reasonable control.
17.9 Language. This Agreement is issued in English. Where a translation is provided, it is provided for convenience and the English version prevails in the event of conflict.
17.10 Governing law. This Agreement and any dispute or claim arising out of or in connection with it, including any non-contractual dispute or claim, are governed by and construed in accordance with the laws of the Hong Kong Special Administrative Region of the People’s Republic of China.
17.11 Jurisdiction. The courts of the Hong Kong Special Administrative Region have non-exclusive jurisdiction over any dispute arising out of or in connection with this Agreement. Nothing in this clause prevents KaiOS from bringing proceedings, including proceedings to protect its intellectual property, to recover a Device, or to restrain a breach of clause 3, 4 or 5, in any other court of competent jurisdiction, including the courts of the country in which you are established.
17.12 Mandatory local law preserved. Clauses 17.10 and 17.11 do not deprive you of the protection of any provision of the law of the country in which you are established that cannot be derogated from by agreement, and do not affect the jurisdiction of any regulator or payment systems authority in that country.
17.13 Electronic records and acceptance. You agree that this Agreement may be entered into electronically, and that your acceptance recorded in the Application — comprising the EULA version, the date and time, your merchant identifier and the Device identifier — constitutes a valid and binding acceptance. You agree that this record, and electronic records of communications sent to you under clause 8, may be relied on as evidence of the terms agreed and of the notices given, and that neither party will dispute their validity solely because they are in electronic form. KaiOS retains acceptance records for 5 years.
17.14 Sanctions and export control. You represent that you are not, and are not owned or controlled by, a person subject to applicable trade sanctions, and that you will not use or export the Application in breach of applicable sanctions or export control laws. KaiOS may suspend or terminate the licence immediately if this ceases to be the case.
17.15 Notices. Notices from KaiOS to you may be given through the Application or to the contact details in your merchant profile. Notices from you to KaiOS must be given to the support or security contacts in clause 16 and, for legal notices, to merchant@kaiostech.com.
17.16 Contact. KaiOS: merchant@kaiostech.com –https://merchant.kaiostech.com/mpoc/support. Registered address: 12F, 133 Wai Yip street, Kwun Tong, Kowloon, Hong Kong.
ACCEPTANCE
By tapping “I ACCEPT” you confirm that you have read, understood and agree to be bound by this Agreement, and that you are authorised to accept it on behalf of your business.
Merchant: [merchant legal name, as recorded by the Acquirer]
Merchant ID: [MID]
Device serial / ID: [serial]
EULA version accepted: [1.0]
Date and time of acceptance: [timestamp, recorded automatically]
ANNEX A — YOUR SECURITY RESPONSIBILITIES AT A GLANCE
Plain-language summary. It does not replace clauses 3 to 5, which prevail in the event of conflict. This Annex is displayed in the Application and should be provided at merchant training.
Keep the PIN private. When your customer types their PIN, turn the screen away from you, your staff, other customers and any camera. Never ask for, look at, or type in a customer’s PIN.
Never write down card details. You never need to. Do not photograph, copy or repeat a card number or PIN.
Keep the device with you. Do not leave it unattended, do not lend it, and do not let a customer walk away with it.
Do not modify the device. No rooting, no unlocking, no unofficial software, no apps from outside the approved store — especially no keyboards, screen recorders or remote-access apps.
Install updates (Application Updates and COTS Software Updates) straight away. Some updates are security updates. If you skip them, payments will stop working.
Keep your codes secret. Your activation code, password and PIN are yours alone. Never share them, including with someone claiming to be from KaiOS or your bank.
Only trained staff should use it. Remove access for staff who leave.
Let the customer do the tapping and the typing. Hand them the device or hold it so they can enter their PIN unseen. Never hold their card or complete a payment for them. Always give them a receipt.
Tell someone immediately if something is wrong. If the device is lost, stolen, damaged, behaving oddly, or you think someone has tampered with it — stop using it and contact your bank or payment collection service provider at once.
The device belongs to your bank’s arrangement, not to us. If it is faulty, damaged, lost or needs replacing, contact your bank — not KaiOS. Never let anyone other than an approved repairer open it.
Before you get rid of a device. Never sell, give away or scrap a device before it has been switched off properly. Tell your bank first.
Who to call
| If it is about… | Contact |
|---|---|
| The app, an update, or anything that looks like tampering | KaiOS support: merchant@kaiostech.com | https://merchant.kaiostech.com/mpoc/support |
| A lost or stolen device, or a suspected security problem | Your Acquirer support |
| Your money, a payment, a fee, a refund or a dispute | Your Acquirer support |
| The device | Your Distributor or Your Acquirer support if you buy the device from them. |
ANNEX B — WHO IS RESPONSIBLE FOR WHAT
Provided for clarity. It does not vary the terms of this Agreement or of your Merchant Services Agreement.
| Topic | Responsible party |
|---|---|
| Merchant onboarding, KYC, merchant account | Acquirer |
| Terms of payment acceptance, fees, pricing | Acquirer |
| Authorisation, clearing, settlement, payout | Acquirer / Payment Backend Provider |
| Chargebacks, disputes, refunds policy | Acquirer |
| Payment processing platform and secure channel | Payment Backend Provider |
| Kai MPoC Application, SDK, EMV kernels, PIN entry | KaiOS |
| Supply of the Device to the Merchant — price, ownership, warranty, repair, replacement, return | Distributor, or a Distributor acting for the Acquirer |
| Product Baseline, MPoC certification and terminal management System | KaiOS |
| Productization of the Product Baseline (the software integration of KaiOS software on a specific COTS hardware) and subsequent COTS Software Updates | Device manufacturer |
| Attestation and monitoring (A&M) | KaiOS |
| Application Updates | KaiOS |
| Device provisioning and activation; remote decommissioning and removal of cryptographic keys and credentials | Distributor (provisioning and activation); KaiOS (remote decommissioning — clause 13.6) |
| Receipts and cardholder disclosures at the point of sale | Merchant, in the form required by the Acquirer |
| Data controller for merchant, cardholder and transaction data | Acquirer (KaiOS transmits only, as service provider) |
| Merchant training and first-line support | Acquirer / Distributor |
| Physical security of the Device, PIN privacy, staff access | Merchant |
| Applying COTS Software Updates and Application Updates, avoiding prohibited software, reporting incidents | Merchant |