A shared registry only works if every member behaves as though the others are watching — because they are. This policy sets out what is permitted, what is prohibited, and what happens when it is breached. It forms part of the Terms and Conditions.
01 Permitted use
Members and their authorised users may use the registry to:
- register shipments, invoices, collateral charges and cheques arising from their own business;
- check a proposed transaction against existing registry records before committing funds;
- record financing, factoring and payment decisions so other Members see current status;
- investigate, work and close fraud alerts raised against their records;
- produce reports for internal risk committees, auditors and regulators;
- meet obligations under applicable anti-fraud, AML and prudential rules.
02 Prohibited use
Misuse of registry data
- Using registry output to solicit, approach or price against another Member's customer.
- Extracting, scraping or bulk-downloading records to build a competing database or resell as a data product.
- Disclosing output to any third party except as required by law or to auditors and advisers under equivalent confidentiality.
- Using the registry as a credit reference or credit scoring service — it is a duplicate-detection control, not a bureau.
- Searching for a person or business without a genuine transaction or compliance purpose.
Data integrity
- Submitting records the Member has no right to submit, or that it knows to be false or misleading.
- Deliberately varying identifiers, splitting or restating records to evade duplicate detection.
- Failing to register a financing decision in order to keep it invisible to other Members.
- Registering speculative or placeholder records to reserve a position on an asset.
Security and access
- Sharing credentials, or allowing a person to use an account provisioned to someone else.
- Assigning a role that exceeds the authority the individual holds inside the Member institution.
- Attempting to access another organisation's data, escalate privileges or bypass access controls.
- Probing, scanning or load-testing the service without written authorisation — see the Responsible Disclosure Policy.
- Introducing malware, or interfering with the availability or integrity of the service.
- Automated access at a rate that degrades service for others, or outside an agreed API arrangement.
Unlawful conduct
- Any use that breaches applicable law, including data protection, AML, sanctions, competition and anti-corruption law.
- Using the registry to facilitate money laundering, terrorist financing, sanctions evasion or tax evasion.
- Using it to harass, defame, discriminate against or unlawfully disadvantage any person.
Competition
Members must not use registry access or its data to coordinate pricing, allocate customers or markets, or otherwise engage in conduct that restricts competition. The registry exists to detect duplicate financing, and nothing more. Members are responsible for their own competition law compliance.
03 Member responsibilities
Each Member must:
- bring this policy to the attention of every user it provisions, and train them on it;
- deprovision users promptly when they leave or change role;
- review its own users' access at least quarterly;
- investigate suspected misuse by its own personnel and tell us the outcome;
- report any suspected breach of this policy by any Member to legal@supersaveprotocol.com.
04 Monitoring
Every registry action is logged. We monitor for patterns consistent with misuse — unusual search volumes, searches without matching transactions, access outside normal hours or geography, and repeated near-miss submissions consistent with evasion. Monitoring is proportionate, automated in the first instance, and reviewed by named individuals.
05 Consequences of breach
Depending on severity, we may:
- ask the Member to explain, and require remediation within a stated period;
- suspend an individual user's access;
- suspend the Member's access, immediately where the risk to other Members requires it;
- terminate membership under the Terms and Conditions;
- notify affected Members, the relevant regulator or law enforcement where we are required or entitled to do so.
Suspension for suspected misuse does not relieve the Member of its fee obligations for the period of suspension where the suspicion is later substantiated.
06 Reporting misuse
Report suspected misuse to legal@supersaveprotocol.com, or security concerns to security@supersaveprotocol.com. Reports are treated confidentially and we do not disclose the reporter's identity to the subject of the report except where the law requires.
Questions about this document?
Write to legal@supersaveprotocol.com, or to Super Save Protocol Ltd, 207 Regent Street, London, W1B 3HH, United Kingdom. You can also see all our legal documents.