1. Agreement and Scope
These Terms of Use (the “Terms”) are a binding agreement between AssurSight Ltd (“Company,” “we,” “us,” or “our”) and the organisation on whose behalf the Portal is accessed or used (“Customer”). They govern access to and use of AssurSight, a multi-tenant customer-assurance and managed-service-delivery platform, including its websites, dashboards, customer workspaces, application programming interfaces, software components, documentation, AI-assisted features, and related online features (collectively, the “Portal”).
By clicking an acceptance button or checkbox, completing Account creation after being presented with these Terms, or accepting an invitation that expressly incorporates them, you agree to these Terms on Customer’s behalf and represent that you have authority to bind Customer. If you do not have that authority, or if Customer does not agree, do not access or use the Portal.
The Portal is intended solely for business use by Customers and their Authorised Users. It is not offered for personal, family, or household use.
2. Definitions
“Account” means the credentials and administrative profile used to access the Portal.
“AI Customer Success Manager” or “AI CSM” means the Portal capability that analyses permitted Customer Data and service activity to identify risk, adoption gaps, recommended actions, workflow opportunities, and potential commercial signals, and that may prepare communications or coordinate approved workflows subject to Provider-configured permissions and approval controls.
“Provider” means the managed service provider, managed security service provider, or other authorised service organisation that subscribes to AssurSight and uses it to deliver Services to one or more Customers. Where the Provider accesses the Portal for its own internal purposes, references to Customer include the Provider as applicable.
“Customer Workspace” means the customer-facing part of the Portal through which a Customer may view onboarding tasks, service scope, monitored assets, recommendations, reports, documents, packs, acceptance requests, and related information made available by the Provider.
“Service Pack” means a structured collection of service definitions, documents, templates, reports, onboarding requirements, operational scope, and related customer actions assigned through the Portal.
“Authorised User” means an individual whom Customer authorizes to use the Portal for Customer’s internal business purposes.
“Company Content” means the Portal, Documentation, dashboard and workflow designs, service and document templates, reporting structures, AI prompts and orchestration logic, detection and correlation logic, interfaces, and other content or materials made available by Company, excluding Customer Data and third-party materials. A report or deliverable may contain both Company Content and Customer Data, and ownership follows each component.
“Customer Data” means data, content, files, configurations, credentials, logs, alerts, telemetry, communications, asset details, and other information submitted to, collected through, or processed by the Portal on Customer’s behalf. Customer Data excludes Usage Data and Company Content.
“Customer Systems” means networks, devices, applications, cloud environments, domains, accounts, and other assets that Customer owns or controls, or that Customer is legally authorised to submit for Services.
“Documentation” means Company’s then-current user guides, technical documentation, and usage instructions for the Portal.
“Services” means the managed-security, monitoring, assessment, response, support, or related services described in an applicable Customer Agreement.
“Usage Data” means technical, operational, diagnostic, and usage information about the performance, configuration, and use of the Portal that does not constitute Customer Data in identifiable form.
3. Eligibility, Authority, and Business Use
An Authorised User must be at least 18 years old, have legal capacity to accept these Terms, and use the Portal solely for Customer’s legitimate business purposes. The Portal is not directed to children.
Customer is responsible for determining who may become an Authorised User, assigning appropriate provider, customer-administrator, engineer, analyst, or customer-facing roles and permissions, and ensuring that each Authorised User complies with these Terms and the Customer Agreement. Customer must promptly remove access when an individual no longer requires it.
Company may request reasonable information to verify Customer, an Authorised User, authority to act, or eligibility to use particular Services. Customer must provide accurate, current, and complete registration and billing information.
4. Accounts and Administrative Controls
Customer and each Authorised User must protect credentials, authentication devices, recovery codes, API keys, certificates, and access tokens; use unique credentials; enable multi-factor authentication where offered or required; and avoid sharing individual credentials. Customer must apply least-privilege access and periodically review permissions.
Customer must promptly notify Company at info@assursight.com of suspected compromise, unauthorised access, credential loss, or misuse of an Account. Customer must reasonably cooperate with containment and investigation.
Company may rely on instructions submitted through an authenticated Account by Customer’s designated administrators. Customer is responsible for actions taken through its Accounts by Authorised Users or by persons to whom Customer gave access, except to the extent an unauthorised action results from Company’s breach of an applicable security obligation.
Customer must maintain current administrative, security, billing, and emergency contacts. Company is not responsible for a missed notice caused by outdated contact information supplied by Customer.
5. Limited Right to Use the Portal
Subject to these Terms and the Customer Agreement, Company grants Customer a limited, non-exclusive, non-transferable, non-sublicensable, revocable right during the applicable subscription or authorised access period to permit Authorised Users to access and use the Portal and Documentation for Customer’s internal business purposes.
Except to the extent a restriction is prohibited by applicable law, Customer and Authorised Users must not: (a) copy, modify, translate, or create derivative works of the Portal or Company Content; (b) reverse engineer, decompile, disassemble, or attempt to discover source code, non-public APIs, models, or underlying structure; (c) bypass authentication, technical limits, rate limits, or security controls; (d) rent, lease, sell, resell, sublicense, distribute, or provide the Portal as a service bureau; (e) use the Portal to build or train a competing product using Company Content; (f) remove proprietary notices; (g) scrape or access the Portal through unauthorised automated means; or (h) publish non-public performance or security benchmark results without Company’s prior written consent.
Automated access is permitted only through Company-authorised APIs and in accordance with the Documentation, rate limits, and any API-specific terms.
6. Customer Systems, Authorisation, and Responsibilities
6.1 Scope of authorisation
Customer represents and warrants that it owns or controls each Customer System submitted to the Portal or has all written permissions necessary for Company and its subprocessors to perform the agreed Services. Customer must not request or permit scanning, monitoring, access, testing, collection, containment, remediation, or incident-response activity involving a third party’s systems without that third party’s legally sufficient authorisation.
Entering an asset, address, domain, credential, or integration into the Portal does not by itself authorize active testing, exploitation, remediation, or material system changes. Company may perform those activities only within the scope, methods, timing, and safeguards stated in a signed Customer Agreement or separately approved through an authenticated workflow that Company designates for that purpose.
6.2 Notices and consents
Customer is responsible for providing legally required notices and obtaining legally required consents from employees, contractors, users, customers, and other individuals before monitoring communications or activity, deploying agents, collecting telemetry, or providing their personal information to Company.
6.3 Customer security obligations
Customer must maintain reasonable administrative, technical, and physical safeguards appropriate to its environment, including backups, patching, endpoint and identity controls, secure configuration, logging, recovery procedures, and trained personnel. Customer must follow material security instructions in the Documentation and promptly address high-risk findings within Customer’s control.
Customer must provide only the minimum access and privileges reasonably necessary for the Services; keep integrations and contact details current; promptly rotate or revoke credentials when access is no longer needed or compromise is suspected; and notify Company of material changes that may affect the Services. Customer must also keep connector credentials and integration permissions current; review onboarding and handover tasks; maintain accurate service scope, asset, site, administrative-contact, and escalation information; and review or respond to recommendations, reports, document requests, acceptance actions, and AI-assisted workflow proposals within a reasonable period.
6.4 Customer decisions and continuity
Customer remains responsible for business, operational, legal, and risk decisions, including whether and how to act on an alert or recommendation. Customer must maintain independent backups and business-continuity and disaster-recovery plans. The Portal and Services are not a substitute for those controls.
6.5 Regulated and highly sensitive data
Unless an applicable Customer Agreement expressly authorizes it, Customer must not submit protected health information, payment-card authentication data, criminal-justice information, government-classified information, export-controlled technical data, biometric identifiers used for unique identification, personal information of children, or other data subject to heightened contractual or legal safeguards. Customer must not use the Portal in a manner that causes Company to become subject to a sector-specific obligation that Company has not expressly accepted in writing.
7. Acceptable Use
Customer and Authorised Users must not use the Portal or Services to:
- violate any law, regulation, court order, contractual duty, intellectual-property right, privacy right, or other right;
- access, scan, monitor, test, exploit, disrupt, or alter any system, account, data, or communication outside the authorised scope;
- introduce, distribute, or activate malware, ransomware, destructive code, credential stealers, or exploit payloads, except for legitimate security analysis in a Company-approved isolated workflow;
- conduct phishing, credential stuffing, denial-of-service activity, spam, fraud, impersonation, harassment, unlawful surveillance, or deceptive activity;
- interfere with the integrity, availability, performance, or security of the Portal, another customer, or a third-party service;
- probe or circumvent access controls, rate limits, logging, audit mechanisms, tenant isolation, or protective measures;
- attempt to access another Provider or Customer tenancy, alter tenant identifiers, or exploit a configuration or permission error to view or change data outside the authorised workspace;
- submit malicious document templates, workflow definitions, prompts, instructions, attachments, or payloads intended to manipulate AI-assisted features, compromise another user, or bypass approval controls;
- use AI-generated summaries, recommendations, communications, or commercial signals to discriminate unlawfully, mislead a Customer, or make a high-impact decision without appropriate human review;
- upload or disclose data without sufficient rights, permissions, notices, or consents;
- share Accounts, misrepresent identity or authority, or attempt to obtain another customer’s data;
- use findings, indicators, or Company Content to facilitate unlawful intrusion, harm, or evasion of security controls;
- access or use the Portal from a prohibited jurisdiction or in violation of export-control, sanctions, or anti-corruption laws; or
- encourage, assist, or permit another person to do any of the above.
Company may investigate suspected misuse and may preserve relevant records, restrict functionality, or suspend access as described in Section 17. Company may report conduct to Customer administrators, affected providers, or authorities where reasonably necessary to protect rights, systems, users, or the public, or where required by law.
8. Customer Data, Usage Data, and Feedback
8.1 Ownership and instructions
As between the parties, Customer retains its rights in Customer Data. Customer instructs Company to host, copy, transmit, display, analyse, correlate, secure, and otherwise process Customer Data as reasonably necessary to provide, support, protect, and improve the Portal and Services; comply with the Customer Agreement and documented instructions; prevent or investigate abuse; and comply with law.
Customer represents and warrants that it has all rights, permissions, legal bases, notices, and consents necessary for Company to process Customer Data as contemplated by the parties’ agreements.
8.2 Usage Data and threat intelligence
Company may collect and use Usage Data to operate, secure, support, analyse, and improve the Portal and Services; allocate resources; detect fraud or abuse; and develop service metrics. Company may create aggregated or de-identified analytics, threat indicators, signatures, detection logic, and security intelligence derived from Customer Data and Usage Data, provided that Company does not publicly identify Customer, an Authorised User, or a Customer System unless Customer consents or disclosure is required by law or reasonably necessary for coordinated incident response.
Company will treat information as de-identified or aggregated only to the extent it meets applicable legal requirements and Company has implemented appropriate measures to prevent re-identification.
8.3 Automated and machine-learning features
The Portal may use automated analysis, rules, statistical techniques, or machine-learning models to classify events, calculate or explain service-health and risk indicators, prioritise alerts, detect adoption gaps, generate summaries, recommend actions, identify possible commercial opportunities, prepare draft communications, schedule review activity, and coordinate approved workflows.
AI CSM outputs are generated from the information available to the Portal and may be incomplete, delayed, inaccurate, or unsuitable for a particular Customer. Unless a Customer Agreement expressly authorises a defined automated action, AI CSM outputs are advisory and require review by an appropriately authorised Provider user before they are communicated externally or used to make a material operational, contractual, personnel, legal, or commercial decision.
Where a Provider enables an autonomous workflow, the workflow will operate only within the configured role permissions, approval policies, data boundaries, and integration capabilities. The Provider remains responsible for selecting those controls, reviewing material outputs, and determining whether an action is appropriate. The Portal may record prompts, source signals, recommendations, approvals, actions, and outcomes for audit, security, support, and service-improvement purposes.
Unless a Customer Agreement expressly provides otherwise, Company will not use Customer Data to train a general-purpose model for unrelated third parties. Company may use Customer Data to deliver service-specific automated features and may improve those features using information that is aggregated or de-identified in accordance with applicable law and the data processing addendum.
8.4 Feedback
If Customer or an Authorised User provides suggestions, ideas, or other feedback, Company may use it without restriction or compensation, provided Company does not disclose Customer’s Confidential Information in doing so.
9. Privacy and Data Protection
Company’s Privacy Policy, available at https://assursight.com/privacy.html, explains how Company processes personal information for account administration, security, support, marketing, and other purposes for which Company determines the means and purposes of processing.
When Company processes personal information in Customer Data on Customer’s behalf, the parties’ data processing addendum, available at the data processing addendum made available with the applicable Customer Agreement or on request from info@assursight.com or executed separately, applies. The data processing addendum must identify the processing details, permitted purposes, confidentiality and security obligations, subprocessor terms, assistance duties, return or deletion requirements, audit or verification mechanisms, and transfer safeguards required by applicable law.
Information about subprocessors is available at the subprocessor information supplied with the applicable Customer Agreement or on request from info@assursight.com. Customer’s rights to receive notice of, or object to, a new subprocessor are governed by the data processing addendum.
Company will maintain the security measures expressly committed in the applicable Customer Agreement. General information about Company’s security program is available at security information supplied during due diligence or on request from info@assursight.com. Company will notify Customer of a confirmed security incident affecting Customer Data as required by the data processing addendum and applicable law. No security measure can eliminate all risk.
Customer is responsible for responding to privacy requests relating to Customer Data unless applicable law assigns responsibility differently. Company will provide reasonable assistance as required by the data processing addendum.
The Portal is not directed to children, and Customer must not permit anyone under 18 to create an Account or submit personal information through the Portal.
10. Confidentiality
“Confidential Information” means non-public information disclosed by or on behalf of a party that is marked confidential or that a reasonable person would understand to be confidential given its nature and the circumstances of disclosure. Customer Data, security findings, credentials, investigation materials, product roadmaps, non-public pricing, technical information, and the non-public features of the Portal are Confidential Information.
The receiving party will: (a) use Confidential Information only to exercise rights and perform obligations under the parties’ agreements; (b) protect it using at least reasonable care and no less care than it uses for similar information of its own; and (c) disclose it only to personnel, affiliates, professional advisers, and subcontractors who need to know it and are bound by confidentiality obligations at least as protective as this Section.
Confidential Information does not include information that the receiving party can document: (a) is or becomes public without breach; (b) was lawfully known without restriction before disclosure; (c) is received lawfully from a third party without confidentiality duty; or (d) is independently developed without use of the disclosing party’s Confidential Information.
A receiving party may disclose Confidential Information if required by law, subpoena, or court order, provided it gives advance notice where legally permitted and reasonable assistance at the disclosing party’s expense. The receiving party will disclose only the portion legally required.
Each party acknowledges that unauthorised disclosure of security-sensitive or proprietary information may cause irreparable harm for which monetary damages may be inadequate, and the disclosing party may seek appropriate injunctive relief in addition to other remedies.
These confidentiality obligations continue during the parties’ relationship and for five years after the relevant disclosure. Trade secrets, credentials, personal data, and security-sensitive information must remain protected for as long as they remain confidential or applicable law requires.
11. Security-Service Limitations and Portal Operation
Company will use commercially reasonable efforts to operate the Portal in accordance with the applicable Customer Agreement. Availability commitments and service credits, if any, are stated only in the service-level agreement.
Cybersecurity is probabilistic and adversarial. Alerts, detections, threat intelligence, automated summaries, and recommendations may be incomplete, delayed, inaccurate, or subject to false positives and false negatives. Company does not guarantee that the Portal or Services will identify, prevent, contain, or remediate every vulnerability, malicious act, security event, data loss, or service interruption.
Unless a signed statement of work expressly authorizes Company to take a particular response action, Company provides findings and recommendations for Customer’s decision. Company may take temporary protective measures that are reasonably necessary to protect the Portal or other customers, such as revoking a token, blocking traffic, or isolating an integration, and will notify Customer as soon as reasonably practicable when doing so would not increase risk or violate law.
The Portal and Services do not constitute legal, regulatory, insurance, accounting, medical, or other professional advice and do not by themselves establish compliance with any law, regulation, certification, or security framework.
Documents, document packs, templates, acceptance records, service schedules, statements of work, evidence packs, reports, health scores, risk scores, recommendations, and executive summaries generated or stored through the Portal are tools for service delivery and governance. Customer and Provider must verify their accuracy, completeness, legal effect, signatory authority, version status, and suitability before relying on them. Electronic acceptance recorded in the Portal evidences the action taken through the relevant Account but does not replace any signature formality required by law or the applicable Customer Agreement.
Company may perform maintenance, deploy security updates, change non-material features, and modify technical limits. For a material reduction in core paid functionality during a subscription term, the applicable Customer Agreement controls.
12. Third-Party Services and Open-Source Components
The Portal may interoperate with third-party products, cloud platforms, identity providers, data sources, or integrations. Customer’s use of a third-party service is governed by its provider’s terms and privacy practices. When Customer enables an integration, Customer instructs Company to exchange Customer Data with that provider as necessary for the integration.
Company is not responsible for a third-party service’s acts, omissions, security, availability, changes, or discontinuation, except to the extent Company has expressly accepted responsibility in a Customer Agreement or liability cannot be excluded by law.
Open-source software components are licensed under their applicable open-source licenses. To the extent an open-source license conflicts with these Terms for that component, the open-source license controls.
13. Trials, Previews, and Beta Features
Company may offer trials, previews, lab environments, early-access features, or beta services. Unless Company states otherwise in writing, they are provided for evaluation, may be changed or discontinued at any time, are excluded from service-level commitments, and should not be used for production workloads or regulated data.
Beta features may contain defects and may generate inaccurate or incomplete results. Customer assumes the risk of using them and must independently validate outputs before relying on them.
14. Fees, Taxes, and Commercial Terms
Fees, payment terms, usage commitments, renewal, cancellation, taxes, and refunds for paid Services are governed by the applicable Customer Agreement or checkout terms presented before purchase. These Terms do not independently create an automatic-renewal obligation.
Customer is responsible for applicable sales, use, value-added, withholding, and similar taxes, excluding taxes based on Company’s net income, except to the extent a Customer Agreement states otherwise.
15. Intellectual Property
Company and its licensors own all rights, title, and interest in the Portal, Services, Documentation, Company Content, software, interfaces, dashboard layouts, workflow definitions, service-catalogue structures, document and report templates, AI orchestration, prompt libraries, methods, detection logic, and the Company-provided portions of reports and templates, together with all related intellectual property. Customer retains its rights in Customer Data embedded in a report or deliverable. No rights are granted except the limited rights expressly stated in the parties’ agreements.
Customer may use reports and deliverables expressly provided for Customer’s internal business purposes, subject to the Customer Agreement. Customer must not remove attribution or proprietary notices or distribute Company Confidential Information outside Customer without permission.
Company’s names, logos, and marks are Company property. Customer may not use them without prior written permission, except for accurate nominative reference as permitted by law.
To report suspected infringement or unlawful content, contact info@assursight.com with enough information for Company to identify the work or right, locate the material, contact the reporting party, and assess the claim. Company may remove or restrict material and terminate repeat infringers where required by applicable law.
16. Legal Compliance, Export Controls, and Sanctions
Each party will comply with laws applicable to its performance under the parties’ agreements. Customer is responsible for laws applicable to Customer’s business, Customer Systems, Customer Data, monitoring activities, and use of security findings.
The Portal, software, encryption, technical data, and Services may be subject to United States and other export-control and economic-sanctions laws. Customer must not access, export, re-export, transfer, release, or use them in a prohibited country, territory, end use, or transaction, or for a restricted person, without all required authorisation.
Customer represents that neither Customer nor an Authorised User is a prohibited or restricted party and that Customer will not permit access by one. Customer must promptly notify Company if this representation becomes inaccurate. Company may screen accounts and suspend access where reasonably necessary to comply with law.
17. Suspension and Protective Measures
Company may suspend or restrict access to all or part of the Portal when reasonably necessary to: (a) address an actual or suspected security threat, compromise, abuse, or unauthorised access; (b) prevent material harm to Company, Customer, another customer, a third party, or the public; (c) comply with law, sanctions, a court order, or a government request; (d) respond to Customer’s material breach; or (e) address undisputed overdue fees where the Customer Agreement permits suspension.
Where practicable and lawful, Company will give advance notice and a reasonable opportunity to cure. In an emergency, Company may act immediately and will provide notice as soon as reasonably practicable. Company will seek to limit the scope and duration of a suspension to what is reasonably necessary.
Customer may request review of a suspension by contacting info@assursight.com. Restoration may require remediation, credential rotation, verification, payment, or other reasonable safeguards.
18. Termination and Data Lifecycle
Customer may stop using a free Portal Account at any time. Termination of paid Services is governed by the Customer Agreement. Company may terminate standalone Portal access for an uncured material breach, repeated misuse, legal prohibition, or a security risk that cannot reasonably be mitigated.
Upon expiration or termination, Customer’s right to use the affected Portal or Services ends. Customer must stop access, remove Company software where instructed, and return or destroy Company Confidential Information, subject to legal retention duties.
Unless a Customer Agreement or law requires a different period, Customer may export available Customer Data during the subscription and for 30 days after termination. Company may delete Customer Data after that period. Residual copies in backups may remain until overwritten under Company’s normal retention cycle and will remain protected and isolated from routine use. Company may retain records required for security, fraud prevention, dispute resolution, legal compliance, or enforcement.
Sections that by their nature should survive termination survive, including ownership, confidentiality, disclaimers, limitations of liability, indemnification, dispute terms, and general provisions.
19. Disclaimers
EXCEPT FOR AN EXPRESS WARRANTY IN A SIGNED CUSTOMER AGREEMENT, AND TO THE MAXIMUM EXTENT PERMITTED BY LAW, THE PORTAL, SERVICES, DOCUMENTATION, BETA FEATURES, ALERTS, REPORTS, RECOMMENDATIONS, AND COMPANY CONTENT ARE PROVIDED “AS IS” AND “AS AVAILABLE.” COMPANY AND ITS LICENSORS DISCLAIM ALL EXPRESS, IMPLIED, STATUTORY, AND OTHER WARRANTIES, INCLUDING WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, NON-INFRINGEMENT, ACCURACY, QUIET ENJOYMENT, AND ANY WARRANTY ARISING FROM COURSE OF DEALING OR USAGE OF TRADE.
COMPANY DOES NOT WARRANT THAT ACCESS WILL BE UNINTERRUPTED OR ERROR-FREE; THAT DATA WILL NEVER BE LOST, CORRUPTED, OR ACCESSED WITHOUT AUTHORIZATION; THAT EVERY THREAT, VULNERABILITY, OR INCIDENT WILL BE DETECTED, ATTRIBUTED, PREVENTED, CONTAINED, OR REMEDIATED; OR THAT USE WILL SATISFY CUSTOMER’S LEGAL, REGULATORY, CONTRACTUAL, INSURANCE, OR CERTIFICATION REQUIREMENTS.
THE DISCLAIMERS IN THIS SECTION DO NOT APPLY TO THE EXTENT THEY ARE PROHIBITED BY APPLICABLE LAW.
20. Limitation of Liability
If a signed Customer Agreement contains limitation-of-liability terms, those terms control for claims relating to the applicable paid Services.
Otherwise, to the maximum extent permitted by law: (a) neither party will be liable for indirect, incidental, special, consequential, exemplary, or punitive damages, or for lost profits, revenue, goodwill, business opportunities, anticipated savings, loss or corruption of data, business interruption, or the cost of substitute services, even if advised of the possibility; and (b) each party’s total aggregate liability arising out of or relating to these Terms or standalone Portal use will not exceed the greater of the amounts Customer paid Company for that Portal use during the 12 months before the event giving rise to liability or GBP 500.
The exclusions and cap in the preceding paragraph do not apply to: (a) Customer’s payment obligations; (b) a party’s fraud, wilful misconduct, or gross negligence to the extent liability cannot lawfully be limited; (c) death or personal injury caused by negligence to the extent liability cannot lawfully be limited; (d) a party’s infringement or misappropriation of the other party’s intellectual property; (e) breach of Section 10; (f) Customer’s unauthorised access to or testing of third-party systems; (g) indemnification obligations; or (h) liability that applicable law does not permit the parties to exclude or limit.
Each limitation applies to all theories of liability and reflects the allocation of risk on which the parties relied in entering into these Terms.
21. Customer Indemnification
Customer will defend Company, its affiliates, and their personnel against a third-party claim to the extent arising from: (a) Customer Data that Customer lacked the right to provide; (b) Customer’s or an Authorised User’s unauthorised access to, monitoring of, testing of, or interference with a third party’s systems, accounts, data, or communications; (c) Customer’s material violation of Section 7; or (d) Customer’s violation of law in its use of the Portal or Services. Customer will pay damages, settlements, and reasonable external legal fees finally awarded or agreed in settlement.
Company must promptly notify Customer of the claim, provide reasonable cooperation at Customer’s expense, and allow Customer to control the defense and settlement. Customer may not settle a claim in a manner that admits fault by Company, imposes non-monetary obligations on Company, or fails to unconditionally release Company without Company’s prior written consent. Company may participate with counsel at its own expense.
22. Informal Resolution, Governing Law, and Venue
Before filing a lawsuit, the parties will attempt in good faith for at least 30 days to resolve the dispute through business representatives with authority to settle, unless urgent injunctive relief is reasonably necessary or a limitations period would expire.
These Terms and disputes arising from them are governed by the laws of England and Wales, without regard to conflict-of-laws rules. The parties consent to the exclusive jurisdiction and venue of the courts of England and Wales. The United Nations Convention on Contracts for the International Sale of Goods does not apply.
Nothing in these Terms prevents either party from seeking temporary or injunctive relief to protect security, confidential information, or intellectual property. Mandatory rights or remedies that cannot lawfully be waived remain unaffected.
23. Changes to the Terms and Portal
Company may update these Terms to reflect legal, security, technical, or business changes. Company will post the updated version with a revised “Last Updated” date. For a material change that adversely affects existing rights or obligations, Company will provide at least 30 days notice through the Portal or by email, unless a shorter period is reasonably necessary for law or urgent security.
Material changes apply prospectively on the stated effective date and do not retroactively change the terms governing a dispute that arose before that date. Company will obtain renewed affirmative assent where required by law or where Company determines the nature of the change warrants it. If Customer objects, Customer must stop using the affected Portal before the change takes effect and may exercise any termination right in the Customer Agreement.
24. Electronic Communications and Notices
Customer agrees that Company may provide agreements, operational messages, security notices, invoices, and other communications electronically, including by email, the Portal, or a designated support channel. Customer can retain these Terms by downloading or printing them.
Formal legal notices must be sent to the addresses stated in the applicable Customer Agreement. If none is stated, notices to Company must be sent to info@assursight.com, and notices to Customer may be sent to Customer’s current Account administrator or legal contact. A notice is effective as provided by the Customer Agreement or, if none, when received.
Nothing in this Section changes a legally required method of notice or service of process.
25. General
Neither party may assign these Terms without the other party’s prior written consent, except to an affiliate or in connection with a merger, reorganisation, sale of substantially all assets, or change of control, provided the assignee agrees in writing to be bound and the assignment does not materially reduce the other party’s rights. Any prohibited assignment is void.
Neither party is liable for delay or failure caused by events beyond its reasonable control, excluding payment obligations, provided the affected party uses reasonable efforts to mitigate and resume performance.
If a provision is unenforceable, it will be enforced to the maximum lawful extent and the remainder will remain in effect. A waiver must be in writing and applies only to the specific instance. Failure to enforce a provision is not a waiver.
The parties are independent contractors. These Terms do not create a partnership, franchise, fiduciary, agency, employment, or joint-venture relationship. There are no third-party beneficiaries except indemnified parties under Section 21.
These Terms and the applicable Customer Agreement constitute the entire agreement concerning their subject matter and supersede prior or contemporaneous communications on that subject. Headings are for convenience. “Including” means “including without limitation.”
The English version controls except where applicable law requires otherwise. An electronic copy is treated as an original.
26. Contact Information
- Company: AssurSight Ltd, the legal entity providing AssurSight
- Legal notices: info@assursight.com
- Privacy: info@assursight.com
- Security incidents and vulnerability reports: info@assursight.com
- Support and suspension review: info@assursight.com