Qualified and Advanced Electronic Signatures)
Total Page:16
File Type:pdf, Size:1020Kb
R Terms and Conditions of Use Swisscom certification service (Qualified and advanced Electronic Signatures) Terms and Conditions of Use for the use of the Swisscom qualified certificate is permitted in connection with the use certification service with qualified and advanced certificates of the trust service in accordance with these Terms and Con- for qualified and advanced electronic signatures (Swisscom ditions of Use ("limitation of use"). certificate class "Saphir and Diamant") 2.2 Identity verification process and retention of the infor- mation Swisscom or the registration authority appointed by 1 Scope of these Terms and Conditions of Use Swisscom checks your identity in the identity verification pro- These Terms and Conditions of Use shall apply in the rela- cess. For qualified electronic signatures, this is done by tionship between you and Swisscom (Schweiz) AG, Alte means of your passport or an identity card allowing travel to Tiefenaustrasse 6, Worblaufen, Switzerland, company ID Switzerland. Depending in each case on the actual organisa- CHE-101.654.423 (hereinafter "Swisscom") for your use of tion of the identity verification process, you may be re- the Swisscom certification service with qualified and ad- quested in the verification process for advanced electronic vanced certificates for qualified and advanced electronic sig- signatures to also submit other documents than those re- natures. quired for qualified electronic signatures. 2 Swisscom’s Services Based on your identify verification process for qualified elec- tronic signatures, you may also create advanced electronic 2.1 Certification service in general signatures in accordance with these Terms and Conditions of For your certification services with qualified certificates, Use where the subscriber application used by you offers dif- Swisscom is an accredited certification services provider in ferent types of signatures. However, not every identity verifi- Switzerland pursuant to the Swiss Federal Act concerning cer- cation process for advanced electroniac signatures can also tification services in the area of electronic signature (Elec- be used for the superior grade signature level of the qualified tronic Signature Act, ZertES; SR 943.03) and is audited and electronic signature. supervised by the ZertES accreditation agency. For your certi- fication services with advanced certificates, Swisscom pro- Swisscom registers and files the personal information about vides certification services in accordance with internationally you which is collected in the identity verification process in recognised technical standards. accordance with the applicable regulations. The handling of your data is described in section 6 of these Terms and Condi- In general, the certification service is provided in accordance tions of Use. with the Swisscom certificate policy in its then current ver- sion. This certificate policy – Certificate Policy (CP/CPS) for 2.3 Issuance of certificate and keys, creation of signature the issuance of "Diamant" (Diamond) class certificates (quali- Swisscom creates the qualified or advanced certificate and fied) and "Saphir" (Sapphire) class certificates (advanced) – the cryptographic pair of keys for the signing process on a form an integral part of these Terms and Conditions of Use. special server (Hardware Security Module, HSM). The quali- You can view and download the document online at fied or advanced certificate is a certificate which assigns to http://www.swissdigicert.ch/download_docs (in the “CH” you the public key of the asymmetrical cryptographic pair of section). keys. You alone have the activation data which allows you to use the private key by deploying your mobile phone (e.g. Mo- As part of the certification service, Swisscom creates a digital bile ID or SMS authentication process, see also in this regard certificate which includes personal information about you. sections 3 and 4 of these Terms and Conditions of Use). As Swisscom links this digital certificate with the file which you soon as you enter the activation data after being requested sign electronically (e.g. a PDF document of your bank). The to do so, Swisscom creates the qualified or advanced elec- electronic signature on the document is thereby assigned to tronic signature for you. you as an individual, just as if it were signed in your own hand, where the writing of the name on the document is as- For each signing process Swisscom creates a new digital cer- signed to the individual signing it. The result is that third par- tificate (with a short validity period of 10 minutes) with a ties can also rely on the electronic signature and on the infor- new pair of keys. mation contained in the digital certificate. 2.4 Verification of the electronic signature In each case, depending on the type of signature offered by The Swisscom certification service allows the validity of the the subscriber application (see section 3 in this regard), a electronic signature to be validated. Third parties also (often qualified electronic signature is created pursuant to Article 2 referred to as the "relying party") can validate the validity of letter e of the Electronic Signature Act (ZertES; SR 943.03) or your electronic signature (e.g. for qualified electronic signa- an advanced signature is created. No other type of use of the tures on the website www.validator.ch or generally with the Swisscom (Schweiz) AG September 2018 Page 1 of 5 R Terms and Conditions of Use Swisscom certification service (Qualified and advanced Electronic Signatures) Adobe Systems Incorporated Adobe Acrobat programme). and separate from your mobile phone or encrypted and must The information provided in section 5 of these Terms and be protected from access by third parties. Conditions of Use must be noted concerning the legal effects If you do not use the mobile ID and use a password and a of the different electronic signatures. one-time password sent by SMS, you shall ensure that this is 2.5 Availability always entered on input screens of Swisscom systems. Fur- Swisscom shall endeavour to provide the certification service ther information about this can be found in this document. continuously. Swisscom shall not, however, be liable for en- You undertake to immediately stop creating signatures and suring that the signing service is constantly available. where necessary to change the access data (e.g. mobile ID Swisscom may limit the availability temporarily if this is nec- PIN or password) if your mobile ID PIN and/or the personal essary, for example, with regard to capacity limits, or the password which you have to provide in the SMS authentica- safety or integrity of the servers, or to perform technical tion process has been stolen or if you know or suspect that maintenance or repairs and this is for the purpose of provid- another person has acquired knowledge of it (compromise). ing the services properly or improving them (maintenance work). Swisscom shall endeavour in this process to take ac- In the event of the loss or theft of the SIM card or the end count of the interests of the users of the certification service. device including the SIM card, you undertake to have the SIM card blocked immediately. 3 Preconditions of use As soon as there are any changes to your mobile phone num- You have an adequate understanding of digital certificates ber, the SIM card used or the identity data, you shall inform and of qualified and advanced electronic signatures. your registration authority or Swisscom directly of these You use a device and log in to an internet portal or an appli- changes. cation which allow the Swisscom certification service to be You undertake to take every reasonable and readily available used (so-called “subscriber application”). For example, it may opportunity to protect your device and your mobile phone be your employer's accounting software or your bank's or in- from attacks and malware ("viruses", "worms", "Trojan surance company's internet portal. The terms and conditions horses" and the like), particularly through using software of the subscriber application used by you may result in limita- from an official source that is continually updated. tions in the use of the certification service. In particular, the subscriber application used by you determines whether you You undertake to check the electronic signatures after they can create qualified or advanced electronic signatures. The have been created in accordance with section 2.4 of these linking of the subscriber application to the Swisscom certifi- Terms and Conditions of Use and to promptly report any dis- cation service is the subject of a separate agreement (All-in crepancies in the digital certificate to Swisscom. Signing Service Agreement). You have a mobile phone for the multi-factor authentication when the signing process is triggered, e.g. SMS or Mobile ID can be used as authentication methods. The actual signature authorisation results from the connection of the subscriber application used by you. If the signature is authorised through Mobile ID, you must have a Mobile ID with a Swiss Mobile ID provider (e.g. Swisscom) in order to use the certification service. 4 Your cooperation obligations You undertake as part of the identity verification process to provide Swisscom and/or the registration authority with complete and true information. You undertake not to use any data relating to your personal information (date of birth etc.) for the secret number se- quence (PIN) for your mobile ID or for your personal pass- word when using the SMS signature approval process. Any records of the mobile ID PIN and/or personal password must not be disclosed to any other person, must be kept securely Swisscom (Schweiz) AG September 2018 Page 2 of 5 R Terms and Conditions of Use Swisscom certification service (Qualified and advanced Electronic Signatures) 5 Legal effects of the electronic signature the law of a country other than Switzerland and that require- ments as to form (such as the written form requirement) The certification service in accordance with these Terms and might not be met.