Welcome
Thank you for using our developer portal. Our APIs are made available subject to our General Developer Terms of Use a summary of which is as follows:
Summary
- Any references to APIs within this document refer to Sandbox environment APIs and production APIs.
- Please use our services safely and in good faith and without harming SMBC or others.
- Respect the provided content, our brands and capacity.
- Use of the APIs is at your own risk. We can only provide limited warranties or accept limited liabilities to provide you with this service.
- Sometimes the service may not be fully available, because we may have to maintain and modify the portal.
- We may request additional information about you or your Application for operational and security purposes, while respecting your privacy and your intellectual property rights in the Application.
- If you do not comply with our Terms of Use, we may block/suspend your access
Please read our complete General Developer Terms of Use below, which will prevail in the event of any conflict with the summary above.
General Developer Terms of Use
[SMBC Bank International plc] (“SMBC”, “we” “us” or “our”) makes available the API Services through the Portal for use in connection with your Application. You are entitled to use the API Services in accordance with these Terms of Use.
1. Definitions and Interpretation
1.1 Definitions
"Application" means any website, software application, platform, product or service developed, operated or made available by you that accesses or uses the API Services.
"API" means any application programming interface made available by SMBC through the Portal or otherwise as part of the API Services.
"API Services" means the APIs, documentation, support materials, maintenance services, Content, Sandbox environment and related services made available by SMBC through the Portal.
"Content" means any data, text, images, drawings, functionality, technical specifications, documentation or other information, materials or content made available through the Portal or API Services.
"Confidential Information" means any non-public information disclosed or made available by SMBC in connection with the Portal or API Services, whether in written, electronic, oral or any other form, which is identified as confidential or which ought reasonably to be understood as confidential by its nature.
"Feedback" means any comments, ideas, suggestions, recommendations or other feedback relating to the Portal, the API Services or the Content.
"Payment Service User" or "PSU" means a natural or legal person making use of a payment service in the capacity of a payer, payee or both and, where applicable, who has provided any consent or authorisation required under PSD2 Requirements.
"Portal" means the SMBC developer portal through which API Services, Content, documentation and related materials are made available.
"PSD2" means Directive (EU) 2015/2366 on payment services in the internal market, together with all applicable implementing legislation, delegated legislation, regulatory technical standards and regulatory guidance issued pursuant to it, as amended, supplemented, extended, re-enacted or replaced from time to time.
"PSD2 Requirements" means PSD2 and any legislation, regulations, regulatory technical standards, implementing technical standards, guidance, supervisory statements or regulatory requirements issued under, implementing, replacing or succeeding PSD2, including any requirements arising under PSD3, FIDA or equivalent successor frameworks, to the extent applicable to the API Services.
"Sandbox" means any non-production testing environment provided by SMBC for evaluation, testing and development purposes.
"SMBC" means SMBC Bank International plc. References to SMBC's affiliates apply only where expressly stated in these Terms of Use.
"Terms of Use" means these General Developer Terms of Use, as amended from time to time in accordance with their terms.
"Third Party Provider" or "TPP" means an account information service provider (AISP), payment initiation service provider (PISP), card-based payment instrument issuer (PIISP) or any other third party entitled to access payment account information or initiate payment transactions pursuant to applicable PSD2 Requirements.
"you" and "your" mean any individual or legal entity accessing or using the Portal, the Content or the API Services.
1.2 Interpretation
In these Terms of Use:
- references to the singular include the plural and vice versa;
- references to a person include an individual, company, corporation, partnership, limited liability partnership, association, organisation, trust, governmental authority or other legal entity;
- references to legislation include that legislation as amended, extended, re-enacted or replaced from time to time;
- the words "including", "include" and similar expressions shall be construed without limitation;
- headings are included for convenience only and shall not affect interpretation; and
- references to a Section are references to a section of these Terms of Use.
2. Acceptance of these Terms of Use
2.1 Acceptance - By accessing or using the Portal, any API Services, any Content or any related documentation made available by SMBC, you agree to be bound by these Terms of Use.
If you do not agree to these Terms of Use, you must immediately cease accessing and using the Portal, the API Services, the Content and any related documentation.
2.2 Authority - If you access or use the Portal or the API Services on behalf of a company, partnership, organisation or other legal entity, you represent and warrant that:
- you are authorised to act on behalf of that entity; and
- you have the authority to bind that entity to these Terms of Use,
2.3 Additional Requirements - Certain API Services may be subject to additional technical, operational, security or regulatory requirements. We may require evidence of certifications, regulatory authorisations, credentials or other information necessary for access to particular API Services.
2.4 Notification of Changes - Where you have provided contact details to us in connection with the API Services, you will promptly notify us of any material changes affecting any information, certifications, credentials, authorisations or permissions previously provided to us.
3. Use of Security Credentials
3.1 Due care - You must keep secure any credentials, certificates, authentication keys, tokens or other security information used to access the API Services.
4. Use of the APIs Services
4.1 Right to Access and Use the API Services
Subject to these Terms of Use, SMBC permits you to access and use the Portal, the API Services, the Content and any related documentation solely for the purposes of:
- evaluating the API Services;
- developing, testing, implementing, maintaining and supporting your Application; and
- integrating your Application with the API Services.
To the extent necessary for those purposes, SMBC grants you a limited, non-exclusive, revocable, non-transferable, non-assignable, non-sublicensable and royalty-free licence to use the API Services, the Content and any related documentation made available through the Portal.
You may only use the API Services in accordance with these Terms of Use and any applicable technical specifications, operational requirements, security requirements and documentation made available by SMBC from time to time.
Except as expressly stated in these Terms of Use, no right, title or interest in or to the Portal, the API Services, the Content or any intellectual property rights of SMBC is granted, assigned or transferred to you.
Where any API Services are made available pursuant to PSD2 Requirements, this Section 4.1 shall be interpreted and applied subject to Section 13 (Legal and Regulatory Rights and Obligations Preserved).
4.2 Technical Requirements - You may only use the API Services if you fulfil the technical requirements specified for the applicable API. You will make reasonable efforts to avoid and prevent any technical problems, unauthorised access and security incidents, including the use of appropriate and up-to-date security measures.
4.3 Prohibited Use - While using the API Services, you will not:
- violate any applicable law or regulation or any intellectual property rights or other rights of SMBC or any third party;
- use the API Services in a manner that causes SMBC to be in breach of applicable law;
- interfere with, damage, disrupt or compromise the accessibility, availability, operation, integrity or security of the Portal, the API Services or related systems;
- attempt to circumvent any security controls, technical restrictions or access controls relating to the API Services; or
- perform any penetration testing, vulnerability testing, stress testing, load testing or similar activity against the API Services without SMBC's prior written consent.
4.4 Metadata - You may not use, store, disclose or exploit any proprietary operational, performance, security or technical metadata relating to the API Services except to the extent necessary for your permitted use of the API Services.
4.5 Modification - We may modify, amend, update, replace or discontinue any API, API Service, Content or aspect of the Portal from time to time. Where reasonably practicable, material changes relevant to users of the API Services may be communicated through the Portal or by such other means as we consider appropriate.
4.6 Limits on API Calls - We may implement reasonable usage limits, rate limits, throttling controls and other technical restrictions where necessary for operational, technical, security, legal or regulatory reasons.
4.7 Monitoring - Subject to Section 11 (Personal Data), we may monitor use of the API Services:
- to prevent fraud;
- to detect or investigate misuse;
- to maintain security;
- to manage capacity and performance;
- to evaluate and improve the API Services;
- to verify compliance with these Terms of Use; and
- to comply with applicable laws and regulatory obligations.
4.8 Audit - We may conduct proportionate audits, inspections or reviews of your use of the API Services where reasonably necessary:
- to verify compliance with these Terms of Use;
- to investigate suspected fraud, misuse or unlawful activity; or
- to comply with legal or regulatory obligations.
Any such audit shall be conducted in a reasonable manner and shall be limited to matters relevant to the purpose of the audit.
4.9 Availability - We will use reasonable efforts to make the API Services available. However, the API Services are provided on an "as available" basis and we do not guarantee uninterrupted availability, operation or performance.
4.10 Technical Support - The Portal and API Services are intended for use by developers, including authorised and prospective Third Party Providers.
We may provide documentation, communications, support materials and technical assistance relating to the API Services. The nature and extent of any support shall be determined by SMBC from time to time.
Where any API Services are subject to PSD2 Requirements, SMBC shall provide such documentation, communications and support arrangements as are required by applicable law.
4.11 Maintenance - We may perform maintenance, upgrades, security activities, updates and other work affecting the Portal and API Services from time to time.
Where reasonably practicable, planned maintenance may be announced through the Portal or by such other means as we consider appropriate. During such periods the Portal or API Services may be unavailable, degraded or otherwise affected.
5. Communication
5.1 Confidential Information - Any non-public communication disclosed or made available by SMBC in connection with the API Services shall be treated as Confidential Information unless stated otherwise. You will at all times (whether or not you continue to use the API Services):
- use Confidential Information only for the purpose for which it was provided;
- protect Confidential Information against unauthorised disclosure; and
- limit disclosure of Confidential Information to persons within your organisation who have a legitimate need to know such information in connection with the API Services.
5.2 Exceptions - The obligations in this Section 5 do not apply if the Confidential Information:
- becomes part of the public domain without violation of these Terms of Use;
- can be proven to have been known and on record at the receiving party prior to the first disclosure of the Confidential Information, with the exception of any Confidential Information that was prepared for or on behalf of the disclosing party; or
- can be proven to have been independently developed.
5.3 Feedback - If you provide Feedback relating to the API Services, the Portal or the Content, SMBC may use, copy, modify and incorporate such Feedback without restriction, payment or further obligation to you for the purpose of improving the API Services, the Portal or the related services.
5.4 Website communication - We take reasonable efforts to ensure the accuracy and integrity of our information, documentation and related materials provided on the Portal website, but misprints, typing errors, miscalculations or other errors appearing on the Portal are reserved.
6. Use of the Sandbox environment & data
6.1 Only for testing - You will use the Sandbox environment only for testing purposes. SMBC will only make available dummy data via the Sandbox environment. SMBC will never present customer data within the Sandbox.
6.2 Sandbox Data - You will not present dummy data that SMBC returns to the developer app as actual SMBC customer data.
6.3 Data restrictions - Only dummy data may be used in the Sandbox.
7. Use of the Content
7.1 Licence on the Content - Unless stated otherwise, SMBC grants you a non-exclusive, worldwide, revocable, non-transferable, non-assignable, non-sublicensable, royalty-free licence to use Content made available through the Portal or the API Services solely for the purposes permitted by these Terms of Use.
7.2 Open Source Materials- Certain aspects of the API Services may contain open source materials that are subject to separate open source licence terms. You agree to comply with such open source licence requirements.
7.3 No modification of Content – Except to the extent permitted by applicable law or expressly authorised by SMBC in writing, you may not modify, alter, remove, obscure or create derivative works from any Content.
7.4 Restricted Use of SMBC Intellectual Property – Nothing in these Terms of Use grants any right to use SMBC’s tradenames, logos, branding, domain names, trade dress, corporate identity elements or proprietary identifiers without SMBC’s prior written consent.
7.5 Storage and Caching Restrictions - You may not index, cache, archive or store any Content, except where:
- such storage is reasonably necessary for the proper operation of your Application or the use of the API Services;
- such storage is secure and maintained in accordance with generally accepted industry security standards;
- such storage complies with all applicable laws and regulations; and
- the Content is retained only for as long as reasonably necessary for the relevant purpose and is deleted when no longer required.
7.6 Restrictions on Bulk Collection and Commercial Exploitation - You may not:
- systematically extract, harvest, scrape, download or collect Content from the Portal or API Services;
- use Content to create, supplement or maintain an independent database, repository or data set unrelated to the permitted use of the API Services;
- use Content for unauthorised commercial resale, redistribution or licensing activities; or
- use Content in any manner that infringes SMBC's intellectual property rights.
Nothing in this Section 7.6 shall prevent the lawful storage, processing, analysis, aggregation, display or use of information obtained through the API Services to the extent necessary for the provision of account information services, payment initiation services, confirmation of funds services or other activities permitted under applicable PSD2 Requirements and authorised by the relevant Payment Service User.
7.7 Disclosure Restrictions - You may not disclose, distribute or make available any Content to any third party except:
- as expressly permitted under these Terms of Use;
- where required by applicable law or regulation; or
- where necessary for the lawful provision of services permitted under applicable PSD2 Requirements.
7.8 Ownership of Content - As between you and SMBC, all right, title and interest in and to the Content, the Portal and the API Services, including all associated intellectual property rights, shall remain vested in SMBC and its licensors.
8. Your Application
8.1 Ownership - You will own the intellectual property in your Application.
8.2 Additional requests - We may request you to provide us with additional information and/or images about your Application for promotional, technical, compliance or security purposes. You will provide such information as is reasonably requested for technical, security, operational, compliance or regulatory purposes.
8.3 Access/testing - We may request access to or information regarding your Application where reasonably necessary for technical, security, compliance or regulatory purposes. Any testing shall be proportionate and limited to the relevant functionality.
9. Termination and Suspension
9.1 Suspension or Termination - We may suspend, restrict or terminate your access to the Portal, the Sandbox environment and/or the API Services, in whole or in part, immediately and without prior notice where:
- we reasonably consider it necessary for security, operational, legal, regulatory or compliance reasons;
- we reasonably suspect fraud, misuse, unauthorised activity or a breach of these Terms of Use;
- any certificate, credential, authorisation or permission required for use of the API Services expires, is revoked, suspended or otherwise ceases to be valid;
- continued access may adversely affect the confidentiality, integrity, availability or security of the Portal, the API Services or any related systems; or
- we are required or requested to do so by applicable law, regulation, court order or competent regulatory authority.
9.2 Withdrawal, Modification or Discontinuance of Services - We may withdraw, suspend, archive, replace, discontinue, modify or update any part of the Portal, any Sandbox environment, any API, any Content or any API Service at any time for operational, technical, security, legal, regulatory or business reasons.
Where reasonably practicable, we will provide advance notice of material changes through the Portal or by such other means as we consider appropriate.
9.3 Consequences of Suspension or Termination - Upon suspension or termination:
- access to the relevant Portal functionality, Sandbox environment and/or API Services may be blocked immediately;
- any licences granted under these Terms of Use shall automatically terminate to the extent necessary to give effect to such suspension or termination; and
- Sections which by their nature are intended to survive termination shall continue in full force and effect.
9.4 No Compensation - Except to the extent required by applicable law, we shall not be liable for any compensation, losses, costs, expenses or damages arising solely as a result of any suspension, restriction, modification, withdrawal or termination carried out in accordance with these Terms of Use.
9.5 PSD2 Rights Preserved - Where any API Service is subject to PSD2 Requirements, any suspension, restriction or termination of access shall be implemented only to the extent permitted by applicable PSD2 Requirements. Nothing in this Section 9 is intended to limit, restrict or adversely affect any rights or obligations arising under PSD2 Requirements.
10. Liability/warranties
10.1 Responsibility - Use of the API Services is at your own risk. You will be fully responsible for the development, functioning, maintenance and service of your Application.
10.2 Warranty disclaimer - The API Services and Content are provided on an “as is” and “as available” basis. All warranties, representations, conditions and all other terms of any kind whatsoever implied by statute or common law are, to the fullest extent permitted by applicable law, excluded from these Terms of Use.
10.3 Limitation of liability - Our total aggregate liability in contract, tort (including negligence or breach of statutory duty), misrepresentation, restitution or otherwise, arising under or in connection with the performance or contemplated performance of these Terms of Use shall be limited to the greater of:
- GBP 100; and
- any fees actually paid by you to SMBC for the API Services during the twelve months preceding the relevant claim.
Nothing in these Terms of Use excludes the liability of either party for death or personal injury caused by negligence; or for fraud or fraudulent misrepresentation; or for any other liability which cannot be excluded under applicable law.
10.4 Exclusion of liability - Excluded from liability are any indirect, consequential damages and punitive damages, loss of goodwill and reputation, future sales or business profits, whether such claim is based on warranty, contract, unlawful act or otherwise, even if we have been advised of the possibility of such damages. Under “indirect damages” we understand any and all damages which are not directly related to the functioning of our APIs and API Services.
10.5 Indemnity - You agree to indemnify and hold harmless SMBC and its affiliates, and their respective officers, directors, employees and agents, from and against all losses, liabilities, damages, fines, costs, expenses and reasonable legal fees suffered or incurred by them to the extent arising from:
- your breach of these Terms of Use;
- your breach of any applicable law or regulation;
- any fraud, negligence, wilful misconduct or unlawful act or omission by you;
- any security incident, cyber incident or unauthorised access originating from systems, infrastructure or applications under your control;
- any claim that any application, software, content, materials or information supplied by you infringes the intellectual property rights or other rights of any third party; or
- any claim brought by a third party arising from your use of the API Services,
except to the extent that the relevant loss, liability, damage, cost or expense results from the negligence, fraud, wilful misconduct or breach of these Terms of Use by SMBC.
11. Personal data
11.1 Your data compliance - You will comply with all applicable legislation regarding personal data.
11.2 Our data compliance - We will process your personal data in accordance with the applicable data protection legislation, and have taken appropriate technical and organisational security measures to protect your personal data.
11.3 Data purposes - We may use your personal data for the following purposes:
- for identification and verification purposes;
- to provide you with the API Services, and to perform the API Services;
- for fraud detection and prevention;
- to evaluate and improve our API Services;
- to send you news and updates regarding the Portal;
- to contact you in the event of problems or security or compliance incidents, or amendments in our services or Terms of Use; or
- to ensure compliance with applicable laws and requests of regulators.
11.4 Notification of security incident - If you notice any problems or security incidents during use of the API Services, you will notify us immediately at the “Contact Us” link
11.5 Contact about personal data - If you have any questions or requests regarding the use, correction or deletion of your personal data, you can “Contact Us” using this link.
12. Miscellaneous
12.1 No partnership - Nothing in these Terms of Use will be construed as creating a partnership, franchise, agency, fiduciary, employment or joint venture relationship of any kind between the parties. Neither you nor we will have the authority to bind the other party or to contract in the name of or create a liability against the other party in performing its obligations or exercising its rights under these Terms of Use.
12.2 Assignment - You may not assign any of your rights or obligations under these Terms of Use without our prior written approval. We may assign any of our rights or obligations without your approval by providing notice to you or posting a notice on our developer portal.
12.3 Amendment of Terms of Use -
We may amend these Terms of Use from time to time for operational, technical, security, legal, regulatory or business reasons.
Any amended Terms of Use will be published on the Portal and, where reasonably practicable, may be notified by such other means as we consider appropriate.
Your continued access to or use of the Portal or API Services following publication of the amended Terms of Use shall constitute acceptance of the amended Terms of Use.
If you do not agree to the amended Terms of Use, you must cease using the Portal and the API Services.
Any amendment to these Terms of Use shall be subject to Section 13 (Legal and Regulatory Rights and Obligations Preserved).
12.4 Severability - The invalidity, illegality or lack of enforceability of any provision of these Terms of Use will not affect the validity, legality or enforceability of the remaining provisions of these Terms of Use. The affected provision will be deemed modified to the minimum extent necessary to make it valid, legal and enforceable. If such modification is not possible, the relevant provision or part thereof will be deemed deleted. Any modification to or deletion of a provision or a part thereof under this Section will not affect the validity and enforceability of the rest of these Terms of Use.
12.5 Third party rights - These Terms of Use do not give rise to any rights under the Contracts (Rights of Third Parties) Act 1999 or otherwise for any third party to enforce any provision of these Terms of Use.
13. Legal and Regulatory Rights and Obligations Preserved
13.1 Notwithstanding anything to the contrary in these Terms of Use, nothing in these Terms of Use is intended to limit, restrict or adversely affect any rights or obligations arising under PSD2 Requirements. To the extent of any inconsistency between these Terms of Use and PSD2 Requirements, the PSD2 Requirements shall prevail.
13.2 Nothing in these Terms of Use shall be applied in a manner that:
- discriminates against authorised Third Party Providers; or
- creates an obstacle to access prohibited under applicable PSD2 Requirements.
13.3 Where any API Services are made available pursuant to PSD2 Requirements, the parties shall comply with all applicable requirements arising under PSD2 Requirements relating to the use of those API Services.
14. Governing law and Jurisdiction
14.1 Governing law - These Terms of Use and any dispute or claim arising out of or in connection with their subject matter or formation (including non-contractual disputes or claims) shall be governed by and construed in accordance with the law of England and Wales.
14.2 Jurisdiction - You irrevocably agree that the courts of England and Wales shall have exclusive jurisdiction to settle any dispute or claim arising out of or in connection with these Terms of Use or their subject matter or formation (including non-contractual disputes or claims).