The present Terms and Conditions are entered into between TechComply, a company incorporated in the Netherlands with company number 92532748 and registered office in Amsterdam, the Netherlands (“Provider”, “we”, “us” or “our”), and the person or legal entity accessing or using the Services (“Client”, “you” or “your”).
If you use the Services on behalf of a company or other organization, you represent that you have authority to bind that organization.
“Account” means the account created to access the Services.
“Application” means the EvRisko web application that is offered by TechComply as used to deliver the Services to Clients.
“Authorized User” means an employee, contractor, officer, or other representative of Client who is authorized to use the Services.
“Client Data” means information submitted to the Services by or on behalf of Client, including company-profile information, questionnaire responses, user information, uploaded materials, and report data.
“Confidential Information” means any information that is limited to internal use by either the Provider or Client, and not normally disclosed unless specifically required for the provision of the Services.
“Documentation” means instructions, guides, and other materials that Provider makes available regarding the Services.
“Free Services” means features made available without payment.
“Paid Plan” means a paid subscription plan selected by Client.
“Personal Data” means any data that identifies, or that can reasonably identify (on its own, or in combination with other personal data) a natural person (an individual), as per the definition given by the General Data Protection Regulation (GDPR).
“Services” means the Provider’s web application, dashboard, reports, questionnaires, related software, and associated services.
“Subscription Term” means the period for which Client has subscribed to a Paid Plan.
Client must provide accurate, current, and complete information when creating an Account.
Client is responsible for keeping login credentials confidential and for all activity carried out through its Account.
Client must promptly notify Provider of unauthorized access, suspected credential compromise, or other security incidents involving the Account. To do so, Client must submit the contact form.
Client must ensure that Authorized Users comply with the present Terms.
The Services are intended primarily for business use. By accepting the present Terms, Client confirms that it is acting in a business or professional capacity unless otherwise agreed in writing.
Provider grants Client a limited, non-exclusive, non-transferable, non-sublicensable right to access and use the Services during the applicable Subscription Term.
Client may use the Services only for its internal business purposes and in accordance with the present Terms and the Documentation.
Provider may modify, improve, or update the Services from time to time. We will not materially reduce the core functionality of a Paid Plan during a current Subscription Term without reasonable notice.
Provider may offer different features, usage limits, storage limits, user limits, or reporting capabilities under different Paid Plans.
Features described as free may be changed, suspended, or discontinued by Provider at any time.
Client may create a free company profile before selecting a Paid Plan.
The Free Services may include limited functionality, storage, users, reports, or retention periods.
Client is entitled to support, service levels, data retention, or particular features for the Free Services.
Provider shall protect all Client Data provided by Client as part of the creation of the free company profile. The confidentiality, privacy and security controls referenced in sections 12 to 14 shall apply.
Provider may suspend or delete inactive free Accounts after 90 days of inactivity.
Client’s Paid Plan, price, billing interval, user limits, and included features will be shown during checkout.
A Paid Plan begins when payment is successfully authorized.
Unless otherwise stated, Paid Plans automatically renew for successive periods equal to the initial Subscription Term.
Client may cancel renewal through the Account settings or by contacting info@evrisko.io up to 30 days before the renewal date.
Cancellation normally takes effect at the end of the current paid period. Client may continue using the Services until then unless the Account is suspended under the present Terms.
Provider may change subscription prices for future renewal periods by giving at least 30 days’ notice. Price changes will not affect a current prepaid period.
If Client upgrades a plan, Provider may charge a prorated amount for the remainder of the current billing period. Downgrades may take effect at the next renewal unless otherwise stated.
Fees are stated in US dollars (USD) and are exclusive of applicable taxes unless expressly stated otherwise.
Client is responsible for VAT, sales tax, GST, withholding tax, and similar charges, except taxes imposed on Provider’s net income.
Payments are processed by Stripe. Provider does not receive or store complete payment-card numbers or payment-related data, apart from information related to payment status and Paid Plan selection.
Client authorizes Provider and its payment processor to charge the selected payment method for recurring fees, applicable taxes, upgrades, and other amounts properly payable under the present Terms.
Except where required by law or expressly stated otherwise, fees are non-refundable.
If Client believes an invoice is incorrect, it must notify Provider at info@evrisko.io within 15 days of receiving it, stating the basis of the dispute.
Client must:
Client must not:
Prohibited use on behalf of Client incur financial, criminal or statutory penalties, as stipulated by applicable law.
The Application generates risk indicators, recommendations, remediation actions, and reports based on information provided by Client.
The results may be incomplete, inaccurate, outdated, or unsuitable for Client’s particular circumstances (subject to the information provided by Client).
The Services do not constitute legal advice, regulatory advice, cybersecurity certification, penetration testing, an audit, insurance advice, or a guarantee of compliance or security.
Client remains solely responsible for evaluating risks, prioritizing actions, implementing controls, and determining whether further professional advice is required.
Provider does not guarantee that use of the Services will prevent, detect, deter or mitigate any cyberattack, data breach, loss, interruption, or regulatory action.
Client retains ownership of Client Data.
Client grants Provider a limited license to host, copy, process, transmit, display, and otherwise use Client Data as necessary to provide, secure, support, and improve the Services.
Provider may use aggregated or de-identified/anonymized information for analytics, benchmarking, product development, and reporting, provided that such information does not identify Client or an individual.
Client represents that it has all rights and permissions necessary for Provider to process Client Data as contemplated by the present Terms.
Provider may remove or restrict data that violates the present Terms or creates a security, legal, or operational risk.
Provider and its licensors own all rights in the Services, software, interfaces, websites, Documentation, templates, methodologies, scoring models, algorithms, designs, branding and related materials.
Except for the limited rights expressly granted in the present Terms, no rights are transferred to Client.
Client retains ownership of its trademarks, content, and Client Data.
Client grants Provider permission to use its name and logo only if Client has opted in or otherwise agreed in writing.
Feedback provided by Client may be used by Provider without restriction or compensation, provided that Provider does not disclose Client’s confidential information. Such feedback is encouraged and can be provided by filling in the contact form.
Each party must:
Confidential Information does not include information that is publicly available without breach, already lawfully known, independently developed, or lawfully received from a third party without confidentiality obligations.
A party may disclose Confidential Information where required by law, provided that it gives advance notice where legally permitted.
Provider’s processing of Personal Data is described in the relevant Privacy Notice.
Where Provider processes Personal Data on Client’s behalf, the Data Processing Addendum applies.
Client is responsible for determining the legal basis for submitting Personal Data to the Services and for providing any required privacy notices to individuals.
Provider will maintain reasonable technical and organizational safeguards designed to protect Client Data against unauthorized access, loss, alteration, and disclosure. The list of applicable security controls can be found here.
Client is responsible for protecting its Account credentials, configuring access permissions, and deciding what information to submit.
Client needs to to ensure that actions specified in the section Prohibited Use above are not undertaken, and apply all reasonable measures to prevent them.
Provider will use commercially reasonable efforts to make the Paid Services available, excluding scheduled maintenance, emergency maintenance, force majeure events, Client-caused issues, third-party outages, and events outside Provider’s reasonable control.
Support is available through info@evrisko.io.
Any service-level commitments are set out in the Service Level & Support Policy.
Provider may suspend access immediately where:
Provider will, where reasonably possible, give notice and an opportunity to remedy the issue before suspension.
Either party may terminate a subscription for material breach that remains uncured for 30 days after written notice.
Provider may terminate the Services or an Account for non-payment, unlawful use, or material breaches.
Client may terminate immediately if Provider materially breaches its data protection obligations and fails to cure the breach within the applicable period, as specified in applicable laws (the GDPR).
On termination, Client’s right to access the Services ends, except for any post-termination access expressly provided.
Client may request an export of Client Data within 30 days after termination. After that period, Provider may delete Client Data unless retention is required by law.
Provisions concerning fees, intellectual property, confidentiality, disclaimers, limitations of liability, indemnities, and dispute resolution survive termination.
Provider warrants that:
Except as expressly stated, the Services are provided “as is” and “as available”. To the maximum extent permitted by law, Provider disclaims implied warranties of merchantability, satisfactory quality, fitness for a particular purpose, non-infringement, and uninterrupted or error-free operation.
Neither party is liable for indirect, incidental, special, consequential, exemplary, or punitive loss, or for loss of profits, revenue, goodwill, anticipated savings, or business opportunity.
Provider’s total aggregate liability arising out of or relating to the Services will not exceed the greater of the fees paid or payable by Client during the 12 months before the event giving rise to the claim.
The limitations do not apply to liability that cannot legally be limited, including liability for fraud, willful misconduct, death or personal injury caused by negligence, or other mandatory statutory liability.
The parties may separately agree to enhanced liability limits for confidentiality, data protection, or intellectual-property infringement.
Client will defend and indemnify Provider against third-party claims arising from:
Provider will defend Client against a third-party claim that the Paid Services, as provided by Provider and used in accordance with the present Terms, infringe that third party’s intellectual property rights. Provider may modify, replace, or terminate the affected feature and refund prepaid unused fees where appropriate.
Provider may update the present Terms by posting a revised version and, where required, providing notice. Material changes will take effect no earlier than 30 days after notice, unless a shorter period is required for legal, security, or operational reasons.
Continued use after the effective date constitutes acceptance of the updated Terms.
Neither party may assign the present Terms without the other party’s prior written consent, except to an affiliate or successor in connection with a merger, restructuring, or sale of substantially all assets.
Neither party is liable for delay caused by events beyond reasonable control.
If a provision is invalid, the remaining provisions remain effective.
The present Terms constitute the entire agreement concerning the Services and supersede prior agreements on the same subject.
The present Terms are governed by the laws of the Netherlands, without regard to conflict-of-law principles.
The courts of the Netherlands have exclusive jurisdiction, unless the parties agree in writing to arbitration or another dispute-resolution procedure.
TechComply
Amsterdam, the Netherlands
Email: techcomplynl@gmail.com