Attestra
  • Terms & Conditions
  • Privacy Notice
  • Cookie Policy
  • Back-Up Policy

Terms & Conditions

Version 2026-08-10

1.1
IMPORTANT – PLEASE READ THESE TERMS AND CONDITIONS (“TERMS”) CAREFULLY. These Terms govern Customer's access to and use of the Services and the platform provided by the Supplier. By accessing or using the Services, executing an Order Form that references these Terms, clicking a button or checkbox indicating acceptance, or otherwise using the Attestra AI platform or Attestra Academy, Customer agrees to be bound by these Terms. If Customer is agreeing to these Terms on behalf of a company or other legal entity, Customer represents and warrants that it has the authority to bind such entity and its Affiliates to these Terms. If Customer does not have such authority, or if Customer does not agree with these Terms, Customer must not accept these Terms and may not use the Services. These Terms, together with any applicable Order Form, constitute the Agreement between the Supplier and the Customer.
1.2
By accepting these Terms, the Customer represents and confirms that: (a) it is acting in the course of a trade, business, craft, or profession; and (b) it is not acting as a consumer for the purposes of applicable consumer protection legislation. Access to and use of the Services is available to business customers only. If the Customer is an individual seeking to use the Services other than in the course of a business, the Customer is not permitted to accept these Terms and must not access or use the Services.
1.3
These Terms are divided into three parts. Part 1 sets out the terms and conditions specific to the Attestra AI Platform. Part 2 sets out the terms and conditions specific to the Attestra Academy. Part 3 sets out the general provisions that apply to both the Attestra AI Platform and the Attestra Academy. Unless the context otherwise requires, references to "Services" in Part 3 shall be construed as references to the Attestra AI Platform and/or the Attestra Academy (as applicable).
1.4
Capitalised terms where used in this document or any Order Form draw their meaning from the definitions at Clause 43 of these Terms.

PART 1 – ATTESTRA AI PLATFORM

2. Fair Use

2.1
The Customer acknowledges that access to and use of the Services is subject to the consumption and usage limits set out in the applicable Order Form, as updated from time to time in accordance with clause 2.5. The Customer shall not take any action designed to manipulate, circumvent, or artificially distort its measured consumption of the Services.
2.2
Where the Supplier reasonably determines that the Customer's usage of the Services is materially and consistently exceeding the agreed limits set out in the applicable Order Form (other than due to a technical error or mis-measurement), the Supplier shall notify the Customer in writing within a reasonable period of identifying the excess usage, setting out in reasonable detail the nature of the excess and the applicable usage limits being exceeded.
2.3
Following notification under clause 2.2, the Supplier shall provide the Customer with a reasonable opportunity to discuss an upgrade to a higher subscription tier or an expansion of the applicable usage limits. If the parties are unable to agree a resolution within a reasonable period, the Supplier may, on giving reasonable prior written notice to the Customer: (a) restrict the Customer's ability to create new Authorised User accounts until such time as the Customer's usage returns to within the agreed limits or an upgrade is agreed; and/or (b) apply throttling or rate-limiting or applying a cap to the Customer's usage of rate limited resources as defined by the fair usage policy for rate limited resources.. The Supplier shall not, in exercising its rights under this clause 2.3, revoke or restrict the access rights of Authorised Users who have already been granted access to the Services, unless a separate ground for suspension or termination exists under clause 14 or clause 27.
2.4
Nothing in this clause 2 shall limit the Supplier's right to suspend the Customer's access to the Services immediately and without prior notice where the Supplier reasonably considers that immediate action is necessary to: (a) protect the integrity, security, or availability of the Services; (b) comply with applicable law; or (c) address circumstances where the Supplier reasonably suspects deliberate manipulation or circumvention of usage measurement under clause 2.1. Any such suspension shall be subject to clause 27.5 and the Supplier shall notify the Customer of the reason for suspension as soon as reasonably practicable.
2.5
The Supplier may update the fair usage thresholds applicable to the Customer's then-current subscription tier by giving the Customer not less than thirty (30) calendar days' prior written notice of any such change. Any updated thresholds shall take effect only from the commencement of the next Renewal Term following the expiry of such notice period, unless the Customer agrees to earlier implementation in writing.

3. Artificial Intelligence and Customer Compliance with Laws

3.1
The Customer acknowledges and agrees that:
(a)
AI Outputs are generated using artificial intelligence and machine learning techniques and are probabilistic in nature. AI Outputs are for informational purposes only and do not constitute professional advice of any kind (including, without limitation, regulatory, legal, or other advice). The Supplier does not warrant that any AI Output will be accurate, complete, or error-free, and AI Outputs should not be relied upon without independent verification;
(b)
the accuracy and completeness of AI Outputs is dependent on the quality, completeness, and timeliness of Customer Data and other data made available to the Services.
3.2
Customer compliance with laws.
(a)
AI Outputs are provided to support humans with operational and regulatory decision making and are subject to the limitations and disclaimers set out in clause 3.1(a) in full.
(b)
Supplier shall not be liable for any regulatory action, fine, market surveillance outcome, product recall, or enforcement measure resulting from Customer’s compliance or non-compliance with the CRA.
3.3
NOT A CONFORMITY ASSESSMENT BODY
(a)
The Supplier is not, and does not purport to be, a conformity assessment body, a notified body, an accreditation body, or a regulatory authority, whether within the meaning of the CRA, Regulation (EU) No 765/2008, or any other applicable law or regulation. The Supplier is a software-as-a-service provider. The Services are productivity and workflow tools designed to assist customers in organising and preparing for CRA compliance processes.
(b)
Use of the Services does not constitute, substitute for, or contribute to a conformity assessment within the meaning of Article 32 of, or Annex VIII to, the CRA. Without limiting clause 3.1(a), no AI Output or other content generated by or through the Services constitutes a formal declaration of conformity, a CE marking decision, or an opinion of compliance with the CRA or any harmonised standard or technical specification. The Customer shall not represent or hold out the Services, or any AI Output, as having such effect to any third party, regulatory authority, or market surveillance authority.
(c)
The Customer is solely responsible for determining whether its products require third-party conformity assessment, for engaging a duly notified body where required, and for completing all conformity assessment procedures required by the CRA and applicable harmonised standards. The Supplier has no obligation to advise on, review, or confirm the adequacy of the Customer's conformity assessment process.
3.4
The Customer shall, and shall procure that its Authorised Users shall, in connection with the use of the Services:
(a)
not use AI Outputs as the sole basis for any material operational or regulatory decision without independent verification and the exercise of independent judgement by a suitably qualified individual;
(b)
ensure that Authorised Users are made appropriately aware of the nature and limitations of AI-generated content prior to using the Services;
(c)
not use, and procure that Authorised Users do not use, the Services to engage in any Prohibited AI Practice or any other practice prohibited under Article 5 of the EU AI Act, and promptly notify the Supplier in writing if the Customer becomes aware of any use of the Services that may constitute or contribute to a Prohibited AI Practice; and
(d)
not use, and procure that Authorised Users do not use, the Services in a manner that would render the Customer or the Supplier a provider or deployer of a high-risk AI system within the meaning of Article 6 and Annex III of the EU AI Act, unless the Customer has first obtained the Supplier's prior written consent and provided the Supplier with written confirmation of compliance with the EU AI Act. For the avoidance of doubt, the Customer shall not use the Services or any AI Output as the primary basis for any automated decision that produces a legal or similarly significant effect in respect of any individual employee, worker, or other natural person without ensuring that appropriate human oversight and review is in place in accordance with the EU AI Act.
3.5
The Customer acknowledges that the Services may enable or assist it to access the website content of, correspond with, and purchase products and services from, third parties via third-party websites and that it does so solely at its own risk. The Supplier makes no representation, warranty or commitment and shall have no liability or obligation whatsoever in relation to the content or use of, or correspondence with, any such third-party website, or any transactions completed, and any contract entered into by the Customer, with any such third party. Any contract entered into and any transaction completed via any third-party website is between the Customer and the relevant third party, and not the Supplier. The Supplier recommends that the Customer refers to the third party's website terms and conditions and privacy policy prior to using the relevant third-party website. The Supplier does not endorse or approve any third-party website nor the content of any of the third-party website made available via the Services.

4. ENISA Reporting and Incident Notification.

4.1
The Services may enable or assist the Customer in preparing structured vulnerability reports and incident notifications for submission to ENISA and/or relevant national market surveillance authorities pursuant to the requirements of the CRA and its implementing or delegated acts. All AI Outputs generated in connection with any Regulatory Report are subject to clause 3.1 in full.
4.2
The Services assist in the preparation of Regulatory Reports only. The Supplier does not submit Regulatory Reports on behalf of the Customer and shall have no obligation to do so. The Customer is solely responsible for: (i) reviewing and verifying the accuracy and completeness of all Regulatory Reports prior to submission, including ensuring that the substance of any AI-assisted draft accurately reflects the underlying facts; (ii) making all submissions within the applicable statutory timeframes associated with the Regulatory Report deadlines under the CRA; and (iii) maintaining all records relating to submitted Regulatory Reports as required by applicable law.
4.3
The Supplier shall not be liable to the Customer for: (i) any failure by the Customer to meet any statutory reporting deadline under the CRA or any other applicable law or regulation; (ii) any regulatory action, sanction, or enforcement measure resulting from a late, inaccurate, or incomplete submission; or (iii) any inaccuracy or omission in a Regulatory Report that was not introduced by the Supplier. The Customer's obligations under this clause are in addition to, and not in substitution for, its obligations under clause 22 (Customer's Obligations).
4.4
The Customer acknowledges that it is responsible for exporting completed draft Regulatory Reports and associated supporting documentation from the Services in accordance with clause 7 and for retaining such records for the mandatory ten (10) year retention period under Article 13 of the CRA, as further described in clause 7.3.

5. Third Party AI Providers; End User Obligations

5.1
The Service incorporates or relies upon services, models, or infrastructure provided by third-party providers. Customer shall comply with all applicable terms, policies, and usage restrictions imposed by such providers as they apply to Customer's use of the Service, copies of which or links to which Supplier shall make reasonably available on request or by publication. Supplier may update its third-party provider stack from time to time without notice, and Customer's continued use of the Service constitutes acceptance of any consequential changes to applicable upstream requirements.
5.2
For the avoidance of doubt, the obligations of the Customer and its Authorised Users set out in clause 14 (Acceptable Use) and clause 22 (Customer's obligations) shall apply with equal force to the Customer's and its Authorised Users' use of the Services in connection with any AI-related functionality.
5.3
Supplier reserves the right to require Customer to provide reasonable written evidence of end user acceptance of compliant terms within ten business days of request. Failure to provide such evidence shall constitute a material breach of this Agreement.

6. Switching and Data Portability

6.1
The Supplier shall comply with its obligations under Articles 23, 24, 25, 26 and 29 of the Data Act in respect of the Services, and the Customer shall have all rights conferred on customers by those provisions. Without limiting the foregoing, the Supplier shall not impose obstacles to switching, shall enable the Customer to port all Exportable Data to an alternative provider or on-premises infrastructure within the timeframes and on the terms required by the Data Act, and any switching charges shall comply with Article 29 of the Data Act. The specifications of categories of data portable on switching are set out in the online register maintained by the Supplier in accordance with the Data Act.
6.2
The parties shall cooperate in good faith to make any switching process effective and maintain service continuity.

7. Data Export During the Subscription Term

7.1
During the Subscription Term, the Customer may, at any time and at no additional cost, export Customer Data from the Services using the export functionality provided on the Platform. The Supplier shall make Customer Data available in one or more of the following standard machine-readable formats (as applicable to the nature and type of the data): JSON, CSV, CycloneDX, and SPDX.
7.2
The Supplier shall maintain operational export functionality throughout the Subscription Term and shall not take any action that materially restricts or impairs the Customer's ability to export its Customer Data in standard formats.
7.3
The Customer acknowledges that it is the Customer's responsibility to export and retain copies of Customer Data as required for the Customer's own compliance obligations, including without limitation any obligation to retain technical documentation for a period of ten (10) years pursuant to Article 13 of the EU Cyber Resilience Act. The Supplier does not provide long-term data archival services and does not warrant that Customer Data will be retained beyond the Subscription Term and the post-termination export window described in clause 27.6(c).

8. Feedback

8.1
The Supplier uses a third-party product analytics service, to collect and analyse usage data relating to the Platform. The product analytics service is engaged to help the Supplier understand how Authorised Users interact with the Platform and to improve its functionality and user experience.
8.2
When an Authorised User accesses or interacts with the Platform, the product analytics service automatically collects certain usage data, which may include page views, feature interactions, click patterns, session duration, and user journey data within the Platform. This data is used solely for product improvement purposes and is not used for advertising or sold to third parties.
8.3
Where usage data is linked to an identifiable individual (such as a user identifier, email address, or IP address), it constitutes personal data and is processed in accordance with applicable data protection law, including the GDPR. Further details of the data collected, the lawful basis for processing, and applicable retention periods are set out in our Privacy Policy and Cookie Policy.
8.4
The product analytics service is engaged by the Supplier as a sub-processor and is listed as such in the Data Processing Agreement. No analytics data is transferred outside the European Economic Area.

9. Enhanced Protection for Vulnerability Data.

9.1
Vulnerability Data is a subset of Customer Data and is subject to the provisions of clause 24.2 in addition to this clause 9. In the event of any conflict between this clause 9 and clauses 24.1 or 24.2, this clause 9 shall prevail.
9.2
The Supplier shall treat all Vulnerability Data as strictly confidential and shall implement technical and organisational measures that are no less protective than: (i) encryption of Vulnerability Data at rest and in transit using industry-standard protocols; (ii) role-based access controls ensuring that access to Vulnerability Data is restricted to those Supplier personnel who require it for the sole purpose of providing the Services; and (iii) audit logging of all access to and processing of Vulnerability Data, with such logs retained for a minimum of twelve (12) months and made available to the Customer on written request.
9.3
The Supplier provides functionality for the Customer to make vulnerability disclosures. Any use of Supplier functionality for such vulnerability disclosure purposes is initiated by you, and not Supplier. Supplier shall not, without the Customer's express prior written consent in each instance: (i) publicly disclose, publish, or communicate the Customer's compliance status, assessment results, vulnerability findings, or risk scores to any third party; (ii) include any reference to the Customer's vulnerability profile, product security posture, or CRA readiness in any marketing, case study, or public communication; or (iii) disclose the existence or substance of any Vulnerability Data to any regulatory authority or law enforcement body, except where required to do so by applicable law or by order of a court of competent jurisdiction, in which case the Supplier shall (to the extent legally permissible) notify the Customer in advance of such disclosure and co-operate with the Customer in seeking to limit the scope of any required disclosure.

PART 2 – ATTESTRA ACADEMY

10. Each User Subscription to the Academy entitles one individual learner (a Named User) to access and use the Academy. Learner accounts are personal to the individual Named User and are non-transferable. The Customer shall not permit any learner account to be shared between two or more individuals. Each learner shall maintain the confidentiality of their login credentials in accordance with clause 12.2.

10.1
All Content made available through the Academy (including video lessons, written materials, quizzes, and assessments) is the Intellectual Property of the Supplier and/or its licensors. The Customer and its Authorised Users are granted a limited, non-exclusive, non-transferable, revocable licence to access and view the Content solely for the purpose of completing the applicable training programme during the Subscription Term. No other rights in or to the Content are granted.
10.2
The Customer shall not, and shall procure that its Authorised Users shall not: (a) record, screenshot, download, copy, reproduce, or create derivative works of any Content; (b) redistribute, share, publish, broadcast, or otherwise make any Content available to any third party; (c) remove, alter, or obscure any copyright, trademark, or other proprietary notice on or in any Content; or (d) use any Content for any commercial purpose other than the internal training of the Customer's personnel.
10.3
Any certificate of completion issued through the Academy is an acknowledgement of training completion only. Certificates do not constitute professional certifications, regulatory approvals, accreditations, or evidence of compliance with the EU Cyber Resilience Act or any other law or regulation. The Customer shall not represent or hold out any such certificate as having any such effect.
10.4
The Content reflects our view of the requirements of the CRA and applicable harmonised standards as understood by the Supplier at the time of publication. The Supplier does not warrant that all Content is current, complete, or accurate at every point in time. The Customer is responsible for independently verifying the currency and applicability of the Content to its own circumstances.
10.5
Where the Customer's Subscription to the Academy is terminated or expires for any reason, all Authorised Users' access to the Academy and the Content shall cease with effect from the date of termination or expiry. The Supplier shall have no obligation to retain learner progress data, quiz results, or completion records beyond the post-termination export window described in clause 27.6(c).

11. Open-Source Software

The Services incorporate or are delivered in part using open-source software components.

11.1
The Customer's use of the Services does not, by virtue of the Supplier's incorporation of OSS Components into or for the delivery of the Services, impose any open source licence obligations on the Customer in respect of the Customer's own software or products, unless the Customer independently modifies or distributes OSS Components, which the Customer is prohibited from doing under clause 14.3.
11.2
The Supplier makes no warranty in respect of OSS Components beyond what is set out in clause 21, save that the Supplier's indemnity obligations under clause 25.2 (IP Claims) shall apply to the Customer's use of OSS Components as incorporated into the Services to the same extent as they apply to the Services generally. To the extent any OSS Component is made available under an "as is" upstream licence, the Supplier's obligations and warranties under clause 21 shall be read subject to that limitation, but this shall not limit or qualify the Supplier's obligations under clause 25.2.

PART 3 – GENERAL PROVISIONS

12. User Subscriptions

12.1
Subject to the Customer’s continued adherence to these Terms, the Supplier hereby grants to the Customer a non-exclusive, non-transferable right and licence, without the right to grant sublicences, to permit the Authorised Users to use the Services and the Documentation during the Subscription Term solely for the Customer's internal business purposes, including assisting with the Customer's compliance with the CRA in respect of the Customer's own products and business operations. The licence granted under this clause 12.1 is subject to the restrictions and prohibitions set out in clause 14 (Acceptable Use), including without limitation the prohibitions on sublicensing, resale, and third-party access set out at clause 14.3(d).
12.2
In relation to the Authorised Users, the Customer undertakes that:
(a)
the maximum number of Authorised Users that it authorises to access and use the Services and the Documentation shall not exceed the number of User Subscriptions it has purchased from time to time;
(b)
it will not allow or suffer any User Subscription to be used by more than one individual Authorised User unless it has been reassigned in its entirety to another individual Authorised User, in which case the prior Authorised User shall no longer have any right to access or use the Services and/or Documentation;
(c)
each Authorised User shall use a secure password for their use of the Services and, where the functionality is available on the Platform, shall enable multi-factor authentication. Each Authorised User shall keep their password and authentication credentials strictly confidential and shall not share them with any other individual;
(d)
it shall maintain a written, up to date list of current Authorised Users and provide such list to the Supplier within five (5) Business Days of the Supplier's written request at any time or times;
(e)
it shall permit the Supplier to audit the Services to verify the identity of each Authorised User and the Customer's compliance with these Terms, on reasonable prior notice and no more than once per quarter, in a manner that does not substantially interfere with the Customer's normal conduct of business. If any audit reveals that passwords have been shared with individuals who are not Authorised Users, the Customer shall promptly disable such passwords. If any audit reveals that the Customer has underpaid Subscription Fees, the Customer shall pay the shortfall in accordance with the applicable Order Form within ten (10) Business Days of the audit.

13. Additional User Subscriptions

13.1
Subject to clause 12.2(a) and 12.2(b), the Customer may, from time to time during any Subscription Term, purchase additional User Subscriptions in excess of the number set out in an Order Form and the Supplier shall grant access to the Services and the Documentation to such additional Authorised Users in accordance with the provisions of these Terms.
13.2
If the Customer wishes to purchase additional User Subscriptions, the Customer shall notify the Supplier in writing. The Supplier shall evaluate such request and respond with approval or rejection and, if approved, an amended Order Form.

14. Acceptable Use

14.1
The Customer's use of the Services is subject to the acceptable use restrictions set out in this clause. The Supplier reserves the right, in its sole discretion and without liability or prejudice to its other rights, to disable, suspend or restrict the Customer's access to the Services, in whole or in part, or to any material that breaches the provisions of this clause. Where practicable, the Supplier shall provide the Customer with reasonable prior notice (of not less than two (2) Business Days) and an opportunity to cure such breach before any suspension or restriction takes effect. The Supplier may, however, suspend the Customer's access immediately and without prior notice where the Supplier reasonably considers that immediate action is necessary to protect the integrity, security or availability of the Services or to comply with applicable law, including (without limitation) where it reasonably suspects that: (a) any account credentials have been compromised; (b) there has been unauthorised access to the Services or any Account; or (c) the Services are being accessed or used in a manner that constitutes or is likely to constitute misuse. The Supplier shall notify the Customer of any such suspension as soon as reasonably practicable and shall lift the suspension promptly upon reasonable satisfaction that the relevant concern has been resolved.
14.2
The Customer shall, and shall procure that all Authorised Users shall, comply with the following acceptable use requirements in connection with the Services. The Customer shall not access, store, distribute or transmit any material during the course of its use of the Services that:
(a)
is unlawful, harmful, threatening, defamatory, obscene, infringing, harassing or racially or ethnically offensive;
(b)
facilitates illegal activity;
(c)
depicts sexually explicit images;
(d)
promotes unlawful violence;
(e)
is discriminatory based on race, gender, colour, religious belief, sexual orientation, disability; or
(f)
is otherwise illegal or causes damage or injury to any person or property.
14.3
The Customer shall not:
(a)
except as may be allowed by any applicable law which is incapable of exclusion by agreement between the parties and except to the extent expressly permitted under this agreement:
(i)
attempt to copy, modify, duplicate, create derivative works from, frame, mirror, republish, download, display, transmit, crawl, scrape, reproduce or distribute all or any portion of the Software and/or Documentation (as applicable) in any form or media or by any means including by using any artificial intelligence system to systematically engage in any of the above prohibited activities; or
(ii)
attempt to de-compile, reverse compile, disassemble, reverse engineer or otherwise reduce to human-perceivable form all or any part of the Software or the Services; or
(b)
access all or any part of the Services and Documentation in order to build a product or service which competes with the Services and/or the Documentation; or
(c)
use the Services and/or Documentation to provide services to third parties; or
(d)
subject to clause 32.1, license, sell, rent, lease, transfer, assign, distribute, display, disclose, or otherwise commercially exploit, or otherwise make the Services and/or Documentation available to any third party except the Authorised Users, or
(e)
attempt to obtain, or assist third parties in obtaining, unauthorised access to the Services, the Documentation, other accounts, computer systems or networks connected to the Services, whether through hacking, password mining, credential stuffing or any other means, other than as provided under this clause 14, or circumvent or attempt to circumvent any authentication, security or access control mechanisms of the Services; or
(f)
introduce or permit the introduction of any Virus or Vulnerability into the Services or the Supplier's network and information systems; or
(g)
use the Services in any manner that could damage, disable, overburden or impair the Services or any Supplier server, or interfere with any other party's use and enjoyment of the Services, including by imposing an unreasonable or disproportionately large load on the Supplier's infrastructure; or
(h)
use any automated means, including robots, crawlers, scrapers or data mining tools, to access, download, monitor or copy any part of the Services or Content, except to the extent expressly permitted by the Supplier in writing or through the Services' published application programming interfaces; or
(i)
conduct or publish any benchmark tests or performance analyses of the Services without the Supplier's prior written consent; or use the Services in a manner that would expose the Supplier to liability to any third party.
14.4
The Customer shall use all reasonable endeavours to prevent any unauthorised access to, or use of, the Services and/or the Documentation and, in the event of any such unauthorised access or use, promptly notify the Supplier.
14.5
The rights provided under clause 12.1 are granted to the Customer only, and shall not be considered granted to any subsidiary or holding company of the Customer unless expressly stated otherwise in an Order Form or the Documentation.

15. Services

15.1
The Supplier shall, during the Subscription Term, provide the Services and make available the Documentation to the Customer on and subject to these Terms.
15.2
The Supplier shall use commercially reasonable endeavours to make the Services available 24 hours a day, seven days a week, except for:
(a)
planned maintenance carried out during the maintenance window of 10.00 pm to 2.00 am Irish time, in respect of which the Supplier shall use reasonable endeavours to provide the Customer with not less than forty-eight (48) hours' prior written notice, and which shall, where practicable, be scheduled outside EU business hours (Monday to Friday, 09:00-18:00 CET); and
(b)
unscheduled maintenance performed outside Normal Business Hours, provided that the Supplier has used reasonable endeavours to give the Customer at least six (6) Normal Business Hours' notice in advance.
15.3
The Supplier shall use commercially reasonable endeavours to maintain a monthly availability target of 99.5% for the Services, measured over each calendar month and excluding downtime resulting from: (a) scheduled maintenance carried out in accordance with clause 15.2(a); (b) events of force majeure as described in clause 29; (c) the acts or omissions of the Customer or its Authorised Users; or (d) the failure or unavailability of third-party services or infrastructure beyond the Supplier's reasonable control.
15.4
No SLA service credits are available to Customers at the current time. The Supplier may introduce a service credit regime in future, in which case it shall notify existing Customers of the applicable terms in accordance with clause 31 (Variation). Enterprise customers may agree bespoke SLA commitments, including service credit entitlements, by way of a separately executed Order Form, which shall prevail over this clause to the extent of any inconsistency.
15.5
The Supplier shall, as part of the Services and at no additional cost to the Customer, provide standard customer support via email during Normal Business Hours (Monday to Friday, 09:00-18:00 Irish time, excluding Irish public holidays). The Supplier shall use reasonable endeavours to respond to support requests within two (2) Business Days of receipt.
15.6
Enterprise customers may, as specified in the applicable Order Form, receive enhanced support services including a designated account manager and agreed response time commitments. The terms of any enhanced support shall be as set out in the relevant Order Form.
15.7
For the avoidance of doubt, support services do not include, and the Supplier has no obligation to provide: (a) advice on compliance with the EU Cyber Resilience Act or any other law or regulation; (b) legal advice of any nature; (c) regulatory guidance or opinions; (d) advice on the accuracy, adequacy, or suitability of any AI Output for any compliance purpose; or (e) professional certification services of any kind. Customers requiring advice of the nature described in this clause should seek independent legal or regulatory counsel.
15.8
From time to time, the Supplier may make Beta Services available to the Customer at no extra charge. The Customer may choose to try such Beta Services in its sole discretion. Any use of Beta Services is subject to the following terms: (a) Beta Services are provided "as is" and "as available" without any warranty of any nature. The Supplier's obligations and warranties under clause 21.1 and clause 21.3 do not apply to Beta Services, and the availability target at clause 15.3 does not apply; (b) the Supplier may, in its sole discretion, withdraw, modify, or discontinue any Beta Service at any time and without prior notice or liability to the Customer. The Customer shall have no claim against the Supplier arising from the withdrawal or modification of a Beta Service; (c) AI Outputs generated through Beta Services should not be relied upon for any regulatory purpose. Clause 3.2 (Customer compliance with laws) applies with full force to all use of Beta Services; (d) all Customer obligations under these Terms, including without limitation clause 3 (Artificial Intelligence and Customer Compliance with Laws), clause 14 (Acceptable Use), and clause 22 (Customer's Obligations), apply in full to the Customer's use of Beta Services; (e) any feedback provided by the Customer or its Authorised Users in relation to Beta Services is licensed to the Supplier under clause 23.2 and may be incorporated into the production Services without compensation or attribution to the Customer; and (f) all outputs, results, and data generated through the Customer's use of Beta Services shall be treated as Confidential Information of the Supplier in accordance with clause 24.

16. Free Trials and Free Services.

16.1
The Supplier may from time to time make Services available to the Customer on a free trial or free-of-charge basis. Free Trials shall be available for the period specified at registration or until the Customer purchases a paid subscription to the applicable Services, whichever is earlier. Free Services are subject to the usage limits described in the Documentation. The Supplier may terminate the Customer's access to any Free Trial or Free Service at any time in its sole discretion and without prior notice or liability.
16.2
Free Trials or any Free Service provided by the Supplier shall only be used to gain understanding of the capabilities of the Services and should never be used for business or operational purposes.
16.3
The Customer is solely responsible for exporting Customer Data before the expiry or termination of any Free Trial or Free Service. Any Customer Data not exported before such expiry or termination may be permanently lost, and the Supplier shall have no obligation to retain or return such data, save that where the Supplier terminates the Customer's access, it shall (except as required by law) provide the Customer with a reasonable opportunity to retrieve its Customer Data.
16.4
Notwithstanding any other provision of these Terms, Free Trials and Free Services are provided "as-is" without warranty of any kind, and the disclaimers set out in clause 26.1 shall apply. The Supplier shall have no indemnification obligations and no liability of any type with respect to Free Trials or Free Services, unless such exclusion is not enforceable under applicable law, in which case the Supplier's total liability shall not exceed €1,000.00. The Customer shall be fully liable under these Terms for any damages arising out of its use of Free Trials or Free Services, any breach of these Terms, and any of the Customer’s indemnification obligations hereunder.

17. Fees, Payment, and Taxes

17.1
The Customer shall pay the Subscription Fees set out in the applicable Order Form or, where no Order Form exists, as displayed on the Supplier's published pricing page at the time of purchase. All Subscription Fees are stated in Euro (EUR).
17.2
All Subscription Fees are payable in advance: (a) for annual subscriptions, the full annual Subscription Fee is due and payable on or before the Subscription Start Date (and, on each Renewal Term, on or before the first day of that Renewal Term); and (b) for monthly subscriptions, the monthly Subscription Fee is due and payable at the commencement of each monthly billing period. Billing frequency may differ depending on agreements made in the Order Form.
17.3
All fees stated in these Terms or any Order Form are exclusive of VAT and any other applicable taxes, levies, duties, or similar charges. The Customer shall be solely responsible for all VAT or other taxes applicable to payments made under these Terms, and shall pay such amounts in addition to, and at the same time as, the relevant Subscription Fees.
17.4
If the Customer fails to pay any amount due under these Terms on the due date for payment, the Supplier may, without prejudice to any other rights or remedies available to it: (a) charge interest on the overdue amount at a rate of 8% per annum above the European Central Bank base rate, accruing daily from the due date until the date of actual payment in full; and (b) on giving not less than fourteen (14) calendar days' prior written notice to the Customer, suspend the Customer's access to the Services until all outstanding amounts (together with any accrued interest) have been paid in full. For the avoidance of doubt, the written notice given pursuant to this clause 17.4(b) shall also constitute written notice of default for the purposes of clause 27.3(a), and the Supplier may exercise its right to terminate in accordance with clause 27.3(a) if such default remains unremedied thirty (30) calendar days from the date of such notice, without the need for any further separate written demand.
17.5
The Supplier processes payments and manages subscription billing via its Payment Processors. The Customer is responsible for ensuring that valid and current payment details are held on its Account at all times. The Supplier shall not be liable for any failure to provide Services resulting from the Customer's failure to maintain valid payment details. The Supplier may update the Payment Processors from time to time and shall notify the Customer of any material change in accordance with clause 31. For the avoidance of doubt, all payments from Customer to Supplier shall be made in advance.

18. Price Changes

18.1
The Supplier may change the published Subscription Fees applicable to new customers at any time and without prior notice.
18.2
For existing customers, any increase to Subscription Fees applicable to that Customer shall not take effect until the commencement of the next Renewal Term following the date of the Supplier's notice of such change, provided that the Supplier has given the Customer not less than thirty (30) calendar days' prior written notice of the proposed change before it takes effect.
18.3
Notwithstanding clauses 18.1 and 18.2, where the Supplier makes a material addition to the Content available through the Academy (including the addition of new training modules, courses, or assessment programmes) during the Subscription Term or prior to a Renewal Term, the Supplier may increase the Subscription Fee applicable to the Customer's Academy subscription to reflect that expanded Content offering. The Supplier shall give the Customer not less than thirty (30) calendar days' prior written notice of any such increase. If the Customer does not wish to accept the increased Academy Subscription Fee, the Customer may, within fourteen (14) calendar days of receiving such notice, serve written notice to terminate the Academy subscription, such termination to take effect at the end of the then-current Subscription Term, whereupon clause 27.7 shall apply.
18.4
If the Customer does not accept a notified price increase, the Customer may cancel its Subscription by written notice to the Supplier given at any time before the start of the applicable Renewal Term. In such case, these Terms shall terminate at the end of the then-current Subscription Term and no early termination charge shall apply.
18.5
For the avoidance of doubt, the Supplier may introduce new pricing tiers, promotional pricing, discount schemes, or early bird pricing at any time, and may amend or withdraw such schemes for new customers without notice. Existing subscriptions are honoured for the duration of the then-current Subscription Term in accordance with clause 27.

19. Modifications to Services

19.1
The Supplier may, at any time and at its sole discretion, update, modify, enhance, or withdraw features or functionality of the Services, including for the purposes of improving performance, security, regulatory compliance, or user experience.
19.2
Where a proposed modification would result in a material reduction in the functionality of the Services that would adversely affect the Customer's use of the Services, the Supplier shall provide the Customer with not less than thirty (30) calendar days' prior written notice of such modification. In such case, the Customer may, by written notice to the Supplier given before the effective date of the modification, elect to terminate these Terms without penalty, in which case the Supplier shall refund to the Customer any prepaid Subscription Fees covering the period after the effective date of termination on a pro-rata basis.
19.3
New modules, features, and enhancements added to the Services during the Customer's then-current Subscription Term shall be made available to the Customer at no additional charge, unless they form part of a new, separately priced subscription tier or add-on product, in which case the Supplier shall notify the Customer of the applicable pricing before making such new tier or add-on available.

20. Data protection

20.1
The parties shall comply with the provisions of the Data Processing Agreement, which prevails over these Terms in respect of its specific terms.

21. Supplier's obligations

21.1
The Supplier shall perform the Services substantially in accordance with the Documentation and the Order Form and with reasonable skill and care.
21.2
The Supplier's obligations at clause 21.1 shall not apply to the extent of any non-conformance which is caused by use of the Services contrary to the Supplier's instructions, or modification or alteration of the Services by any party other than the Supplier or the Supplier's duly authorised contractors or agents. If the Services do not conform with the terms of clause 21.1, Supplier will, at its expense, use reasonable commercial endeavours to correct any such non-conformance promptly. Such correction constitutes the Customer's sole and exclusive remedy for any breach of the undertaking set out in clause 21.1.
21.3
The Supplier warrants that during the applicable Subscription Term:
(a)
these Terms and the Documentation will accurately describe the applicable administrative, physical, and technical safeguards for protection of the security, confidentiality and integrity of Customer Data;
(b)
the Supplier will not materially decrease the overall security of the Services;
(c)
the Services will perform materially in accordance with the applicable Documentation; and
(d)
subject to the “Third party providers” provisions above in clause 5, Supplier will not materially decrease the overall functionality of the Services.
21.4
The Supplier:
(a)
does not warrant that:
(i)
the Customer's use of the Services will be uninterrupted or error-free; or
(ii)
that the Services, Documentation and/or the information obtained by the Customer through the Services will meet the Customer's requirements; or
(iii)
the Software or the Services will be free from Vulnerabilities or Viruses; or
(iv)
the Software, Documentation or Services will comply with any Heightened Cybersecurity Requirements.
(b)
is not responsible for any delays, delivery failures, or any other loss or damage resulting from the transfer of data over communications networks and facilities, including the internet, and the Customer acknowledges that the Services and Documentation may be subject to limitations, delays and other problems inherent in the use of such communications facilities.
21.5
These Terms shall not prevent the Supplier from entering into similar agreements with third parties, or from independently developing, using, selling or licensing documentation, products and/or services which are similar to those provided under these Terms.
21.6
The Supplier warrants that it has and will maintain all necessary licences, consents, and permissions necessary for the performance of its obligations under these Terms.
21.7
The Supplier shall follow its archiving procedures for Customer Data as set out in its Back-Up Policy available at https://attestra.ai/legal/backup-policy, as such document may be amended by the Supplier from time to time. In the event of any loss or damage to Customer Data, the Customer's sole and exclusive remedy shall be for the Supplier to use reasonable commercial endeavours to restore the lost or damaged Customer Data from the latest available back-up. The Supplier shall not be responsible for any loss, destruction, alteration or disclosure of Customer Data caused by any third party, except those third parties sub-contracted by the Supplier to perform services related to Customer Data maintenance and back-up.

22. Customer's obligations

22.1
The Customer shall:
(a)
provide the Supplier with:
(i)
all necessary co-operation in relation to these Terms; and
(ii)
all necessary access to such information as may be required by the Supplier;
in order to provide the Services, including but not limited to Customer Data, security access information and configuration services;
(b)
without affecting its other obligations under these Terms, comply with all applicable laws and regulations with respect to its activities under these Terms;
(c)
carry out all other Customer responsibilities set out in these Terms in a timely and efficient manner. In the event of any delays in the Customer's provision of such assistance as agreed by the parties, the Supplier may adjust any agreed timetable or delivery schedule as reasonably necessary;
(d)
ensure that the Authorised Users use the Services and the Documentation in accordance with these Terms and shall be responsible for any Authorised User's breach of these Terms;
(e)
obtain and shall maintain all necessary licences, consents, and permissions necessary for the Supplier, its contractors and agents to perform their obligations under these Terms, including without limitation the Services;
(f)
ensure that its network and systems comply with the relevant specifications provided by the Supplier from time to time; and
(g)
be, to the extent permitted by law and except as otherwise expressly provided in these Terms, solely responsible for procuring, maintaining and securing its network connections and telecommunications links from its systems to the Supplier's data centres, and all problems, conditions, delays, delivery failures and all other loss or damage arising from or relating to the Customer's network connections or telecommunications links or caused by the internet.
22.2
The Customer retains all right, title, and interest in and to all Customer Data, including without limitation product data, SBOMs, vulnerability data, risk assessments, and technical documentation uploaded to or generated within the Services. Nothing in these Terms shall operate to transfer any Intellectual Property Rights in Customer Data to the Supplier. The Customer shall have sole responsibility for the legality, reliability, integrity, accuracy, and quality of all Customer Data.
22.3
The Customer hereby grants to the Supplier a non-exclusive, royalty-free, worldwide licence to access, copy, store, transmit, and process Customer Data solely to the extent necessary to provide the Services to the Customer during the Subscription Term, and for such period thereafter as is strictly necessary for the Supplier to fulfil its obligations on termination pursuant to clause 27. This licence shall terminate automatically upon the permanent deletion of Customer Data in accordance with clause 27.6(c).

23. Proprietary rights

23.1
The Customer acknowledges and agrees that the Supplier and/or its licensors own all intellectual property rights in the Services and the Documentation. Except as expressly stated herein, these Terms do not grant the Customer any rights to, under or in, any patents, copyright, database right, trade secrets, trade names, trade marks (whether registered or unregistered), or any other rights or licences in respect of the Services or the Documentation. The Supplier's warranty at clause 21.6 shall extend to the rights necessary to grant the licences contemplated by these Terms.
23.2
Licence by Customer to use feedback: where the Customer or its Authorised Users voluntarily provide any suggestion, enhancement request, recommendation, correction, or other feedback relating to the operation of the Services (Feedback), the Customer grants the Supplier a non-exclusive, worldwide, perpetual, royalty-free licence to use, reproduce, and incorporate such Feedback into the Services and the Supplier's related products and services. For the avoidance of doubt: (a) Feedback shall not include Customer Data or Confidential Information of the Customer, and the Supplier shall not acquire any rights in Customer Data by virtue of this clause; (b) no obligation to provide Feedback shall arise under these Terms; and (c) the Customer retains all Intellectual Property Rights in any Feedback to the extent such rights are not required to give effect to the licence granted under this clause.
23.3
Nothing in these Terms shall be construed as transferring ownership of, or granting any licence or rights in, any Intellectual Property Rights of either party, except as expressly set out herein. No licence or right is granted by implication, estoppel, or otherwise.

24. Confidentiality

24.1
Each party shall keep confidential all Confidential Information and shall use such information solely for the purpose of exercising its rights and performing its obligations hereunder. Neither party shall disclose the other party's Confidential Information to any third party, except to its employees, officers, contractors and advisers who need to know such information for such purpose and who are bound by obligations of confidentiality no less onerous than this clause. The obligations in this clause do not apply to information that: is or becomes publicly available other than through breach of this clause; was already known to the receiving party on a non-confidential basis; was independently developed by the receiving party; is received from a third party not bound by confidentiality obligations to the disclosing party; or is required to be disclosed by law, regulation or order of a court or regulatory authority of competent jurisdiction. For data-specific obligations, the parties shall comply with the Data Processing Agreement and Privacy Policy referenced in clause 20. The obligations in this clause 24 shall survive termination or expiry of these Terms for a period of three (3) years from the date of termination or expiry, save that obligations in respect of information that constitutes a trade secret shall survive for five (5) years from the date of termination or expiry (or indefinitely, to the extent permitted and required by applicable law).
24.2
All Customer Data processed by or on behalf of the Supplier shall be treated as Confidential Information of the Customer for the purposes of this clause 24, regardless of whether it has been formally designated as confidential at the time of disclosure or upload. The Supplier shall not use Customer Data for any purpose other than the provision of the Services under these Terms, and shall not disclose Customer Data to any third party save as permitted under these Terms or with the Customer's prior written consent.

25. Indemnity

25.1
The Customer shall defend, indemnify and hold harmless the Supplier and its Affiliates against all claims, losses, damages, expenses and costs (including reasonable legal fees) arising out of or in connection with: (a) the Customer's breach of clause 14 (Acceptable Use); (b) the Customer’s breach of clause 3 (Artificial Intelligence); (c) any infringement or misappropriation of third-party rights by Customer Data or other content provided by the Customer through the Services; (d) the Customer's breach of its obligations under clause 5 (Third Party AI Providers; End User Obligations); or (e) the Customer's breach of any applicable law or regulation in connection with its access to or use of the Services. The Customer's obligation to indemnify is conditional on the Supplier providing prompt notice of any claim and reasonable co-operation in the defence thereof, at the Customer's expense, and the Customer being given sole authority to defend or settle the claim. The Supplier's total recovery under this clause shall be subject to the liability cap set out in clause 26.
25.2
The Supplier shall defend, indemnify, and hold harmless the Customer and its officers, employees, and agents against all third-party claims, losses, damages, expenses, and costs (including reasonable legal fees) alleging that the Customer's use of the Services in accordance with these Terms infringes any IP Claim. This indemnity is conditional on: (a) the Customer promptly notifying the Supplier in writing of any IP Claim (and in any event within ten (10) Business Days of the Customer becoming aware of such claim); (b) the Customer granting the Supplier sole control of the defence and settlement of the IP Claim, provided that the Supplier shall not settle any IP Claim in a manner that imposes any obligation or liability on the Customer without the Customer's prior written consent (not to be unreasonably withheld or delayed); and (c) the Customer providing the Supplier with all reasonable co-operation and assistance in connection with the defence of the IP Claim, at the Supplier's expense. This indemnity shall not apply to the extent that any IP Claim arises from or relates to: (i) Customer Data; (ii) the Customer's modification of the Services other than as authorised by the Supplier; (iii) the Customer's use of the Services other than strictly in accordance with these Terms and the Documentation; or (iv) the combination or integration of the Services with any third-party product, service, or technology not provided or approved in writing by the Supplier.

26. Limitation of liability

26.1
Except as expressly and specifically provided in these Terms: (a) the Customer assumes sole responsibility for results obtained from the use of the Services and the Documentation by the Customer, and for conclusions drawn from such use, and the Supplier shall have no liability for any damage caused by errors or omissions in any Customer Data, information, instructions or scripts provided to the Supplier by the Customer in connection with the Services or any actions taken by the Supplier at the Customer's direction; (b) all warranties, representations, conditions and all other terms of any kind whatsoever implied by statute or common law are, to the fullest extent permitted by applicable law, excluded from these Terms, and the Services and the Documentation are provided to the Customer on an "as is" basis; and (c) the Customer assumes sole responsibility for conclusions drawn from the use of the Services and the Documentation.
26.2
Nothing in this agreement excludes the liability of the Supplier: (a) for death or personal injury caused by the Supplier's negligence; (b) for fraud or fraudulent misrepresentation; (c) for any liability arising directly from the Supplier's wilful misconduct or gross negligence; or (d) for any liability arising from the Supplier's breach of the Data Processing Agreement referred to in clause 20, the General Data Protection Regulation (Regulation (EU) 2016/679) (GDPR), or any equivalent applicable data protection legislation, to the extent that such breach arises from the Supplier's wilful non-compliance, deliberate circumvention of its data protection obligations, or any unauthorised use or disclosure of Customer Data that the Supplier has not implemented reasonable technical and organisational measures to prevent.
26.3
Without prejudice to clause 26.2(d), and subject to the exclusions in clauses 26.2(a)–(d), the Supplier's total aggregate liability in respect of all claims arising from breaches of data protection law or the Data Processing Agreement (other than those falling within clause 26.2(d)) shall not exceed two (2) times the Cap as defined in clause 43. For the avoidance of doubt, this sub-cap is separate from and in addition to the Cap at clause 26.4(b), which shall continue to apply to all other heads of liability. [Note for CCL: This is a business decision on risk allocation. The 2x Cap figure is a starting position. The appropriate sub-cap will depend on the level of professional indemnity and cyber liability insurance that CCL carries. CCL should confirm its coverage limits before finalising this provision.]
26.4
Subject to clause 26.1 and clause 26.2: (a) the Supplier shall have no liability for any loss of profits, loss of business, loss of revenue, loss of business opportunity, wasted expenditure, depletion of goodwill and/or similar losses, loss or corruption of data or information, or any special, indirect or consequential loss, costs, damages, charges or expenses; and (b) the Supplier's total aggregate liability to the Customer in respect of all breaches of duty occurring within any contract year shall not exceed the Cap.
26.5
References to liability in this clause 26 include every kind of liability arising under or in connection with these Terms including but not limited to liability in contract, tort (including negligence), misrepresentation, restitution or otherwise.
26.6
Nothing in these Terms excludes the liability of the Customer for any breach, infringement or misappropriation of the Supplier’s Intellectual Property Rights.

27. Term and termination

27.1
Where the Customer has subscribed to the Services on a monthly basis as specified in an Order Form, the Subscription Term shall commence on the Subscription Start Date and shall continue on a rolling monthly basis until cancelled in accordance with this clause. The Customer may cancel a monthly subscription at any time by providing written notice to the Supplier, such cancellation to take effect at the end of the then-current monthly billing period. No refund shall be payable in respect of any portion of the current billing period following the date of the cancellation notice.
27.2
Where the Customer has subscribed to the Services on an annual basis as specified in an applicable Order Form, the Subscription Term shall commence on the Subscription Start Date and shall continue for the Initial Subscription Term specified in that Order Form. At the expiry of the Initial Subscription Term, and at the expiry of each subsequent Renewal Term, the Subscription shall automatically renew for a further Renewal Term unless either party gives the other not less than thirty (30) calendar days' prior written notice of non-renewal before the end of the then-current Initial Subscription Term or Renewal Term (as the case may be). Where no such notice of non-renewal is given, the Customer shall be liable for the full Subscription Fee applicable to the Renewal Term commencing immediately thereafter, which shall be due and payable in advance in accordance with clause 17.2(a). The Supplier shall notify the Customer of any change to the Subscription Fee applicable to a Renewal Term in accordance with clause 18.2.
27.3
Without affecting any other right or remedy available to it, either party may terminate these Terms with immediate effect by giving written notice to the other party if:
(a)
the other party fails to pay any amount due under these Terms on the due date for payment and remains in default not less than 30 days after being notified in writing to make such payment;
(b)
the other party is in material or persistent breach of any of its obligations under these Terms and either that breach is incapable of remedy (as determined at the sole discretion of the non-breaching party), or the other party has failed to remedy that breach within thirty (30) days after receiving written notice requiring it to remedy that breach. Any breach of the licensing provisions of these Terms shall be deemed a breach incapable of remedy;
(c)
the other party is unable to pay its debts or becomes insolvent or an order is made or a resolution passed for the administration, winding-up or dissolution (otherwise than for the purposes of a solvent amalgamation or reconstruction) or an administrative or other receiver, manager, liquidator, administrator, trustee or similar officer is appointed over all or any substantial part of the assets of the other or the other enters into or proposes any composition or arrangement with its creditors generally or anything analogous to the foregoing occurs in any applicable jurisdiction; or
(d)
there is a Change of Control of the other party.
27.4
Notwithstanding clause 27.3(b), the Supplier may terminate these Terms with immediate effect by written notice to the Customer if the Customer or any Authorised User uses the Services for any purpose that is unlawful or in material breach of the Acceptable Use provisions at clause 14, where: (a) such breach is incapable of remedy; or (b) immediate termination is, in the Supplier's reasonable opinion, necessary to protect the security or integrity of the Services, the Supplier's systems, or the data of any third party; or (c) immediate termination is necessary to enable the Supplier to comply with applicable law or any regulatory obligation.
27.5
Without prejudice to its right to terminate under clause 27.3, the Supplier may suspend the Customer's access to the Services (without terminating these Terms) in the following circumstances: (a) immediately and without prior notice, where such suspension is necessary to protect the security, availability, or integrity of the Services or any third party's data, or where required to comply with applicable law; or (b) on giving not less than fourteen (14) calendar days' prior written notice, where any Subscription Fees remain unpaid after the due date for payment. Any suspension under this clause shall continue until the circumstances giving rise to it have been resolved to the Supplier's reasonable satisfaction. The Supplier shall notify the Customer of the reason for any suspension as soon as reasonably practicable and shall lift the suspension promptly upon resolution.
27.6
On termination of these Terms for any reason:
(a)
all licences granted under these Terms shall immediately terminate and the Customer shall immediately cease all use of the Services and/or the Documentation;
(b)
each party shall return and make no further use of any equipment, property, Documentation and other items (and all copies of them) belonging to the other party;
(c)
the Supplier may destroy or otherwise dispose of any Customer Data in its possession unless the Supplier receives, no later than thirty (30) calendar days after the effective date of termination of these Terms, a written request from the Customer for the export or delivery of the Customer's data. Upon receipt of such a request, the Supplier shall make all Customer Data available to the Customer for export in one or more standard machine-readable formats (including, as applicable, JSON, CSV, CycloneDX, and SPDX) and shall use reasonable commercial endeavours to facilitate such export within thirty (30) calendar days of receipt of the Customer's written request. The Supplier may withhold delivery of Customer Data only in respect of any undisputed Subscription Fees that remain outstanding at the date of termination. Following expiry of the thirty (30) day export window, the Supplier shall permanently delete all Customer Data from its systems in accordance with its data retention policy, save where retention is required by applicable law. The Supplier shall confirm deletion in writing to the Customer upon request; and
(d)
any rights, remedies, obligations or liabilities of the parties that have accrued up to the date of termination, including the right to claim damages in respect of any breach of these Terms which existed at or before the date of termination shall not be affected or prejudiced.
27.7
Refund or Payment upon Termination. If these Terms are terminated by Customer in accordance with clause 27.3 above, Supplier will refund Customer any prepaid fees covering the remainder of the term of all Order Forms after the effective date of termination. If these Terms are terminated by Supplier in accordance with clause 27.3 above, Customer will pay any unpaid fees covering the remainder of the term of all Order Forms to the extent permitted by applicable law. In no event will termination relieve the Customer of its obligation to pay any fees payable to Supplier for the period prior to the effective date of termination.
27.8
Where the Customer cancels or terminates an annual Subscription other than pursuant to clause 27.3, no refund shall be payable in respect of any prepaid Subscription Fees covering the unexpired portion of the then-current Subscription Term. For the avoidance of doubt, the Customer shall not be entitled to a pro-rata refund upon voluntary cancellation of an annual Subscription during the Subscription Term.

28. Survival

Any provision of these Terms that expressly or by implication is intended to come into or continue in force on or after termination or expiry of these Terms shall remain in full force and effect, including without limitation provisions relating to intellectual property, confidentiality, limitation of liability, indemnity, data protection, dispute resolution escalation (clause 40), and dispute resolution.

29. Force majeure

Neither party shall be in breach of these Terms or otherwise liable for any failure or delay in the performance of its obligations if such delay or failure results from events, circumstances or causes beyond its reasonable control. The time for performance of such obligations shall be extended accordingly. If the period of delay or non-performance continues for three (3) months, the party not affected may terminate these Terms by giving thirty (30) days' written notice to the affected party.

30. Order of Precedence and Conflict

In the event of any conflict or inconsistency among the following documents, the order of precedence shall be: (a) the applicable Order Form; (b) these Terms; and (c) the Documentation. The provisions in the main body of these Terms shall prevail over any incorporated policy or document (other than an Order Form) to the extent of any inconsistency, save for the Data Processing Agreement, which shall prevail over these Terms in respect of their subject matter.

31. Variation

The Supplier may amend these Terms from time to time by posting the updated Terms on its website or by providing notice to the Customer in accordance with clause 39. Where a proposed amendment would constitute a material change to the Customer's rights or obligations under these Terms, the Supplier shall provide the Customer with not less than thirty (30) calendar days' prior written notice of the proposed amendment, setting out in reasonable detail the nature of the change. If the Customer does not accept such material amendment, the Customer may, by written notice to the Supplier given before the effective date of the amendment, elect to terminate these Terms without penalty, in which case the Supplier shall refund to the Customer any prepaid Subscription Fees covering the period after the effective date of termination on a pro-rata basis. The Customer's continued use of the Services after the effective date of any material amendment shall constitute acceptance of the amended Terms. Amendments that are not material (including corrections, clarifications, and updates required by applicable law) shall become effective thirty (30) days after the date of posting or notice (whichever is earlier). No variation of an Order Form shall be effective unless agreed in writing by both parties.

32. Waiver

32.1
A waiver of any right or remedy is only effective if given in writing and shall not be deemed a waiver of any subsequent right or remedy.
32.2
A delay or failure to exercise, or the single or partial exercise of, any right or remedy shall not waive that or any other right or remedy, nor shall it prevent or restrict the further exercise of that or any other right or remedy.

33. Rights and remedies

Except as expressly provided in these Terms, the rights and remedies provided under these Terms are in addition to, and not exclusive of, any rights or remedies provided by law.

34. Severance

34.1
If any provision or part-provision of these Terms is or becomes invalid, illegal or unenforceable, it shall be deemed deleted, but that shall not affect the validity and enforceability of the rest of these Terms.
34.2
If any provision or part-provision of these Terms is deemed deleted under clause 34.1, the parties shall negotiate in good faith to agree a valid and enforceable replacement provision that, to the greatest extent possible, achieves the intended commercial result of the original provision.

35. Entire agreement

35.1
These Terms, together with any applicable Order Form, the Documentation, and any policies or agreements incorporated by reference at the URLs specified in these Terms (each as updated from time to time in accordance with their own terms), constitute the entire Agreement between the parties and supersede and extinguish all previous and contemporaneous agreements, promises, assurances and understandings between them, whether written or oral, relating to its subject matter. Where any incorporated document is updated, the version in force at the time of the relevant event shall apply.
35.2
Each party acknowledges that in entering into these Terms it does not rely on, and shall have no remedies in respect of, any statement, representation, assurance or warranty (whether made innocently or negligently) that is not set out in these Terms or an Order Form.
35.3
In the event of any conflict or inconsistency among the documents forming the Agreement, the order of precedence set out in clause 30 shall apply.
35.4
Each party agrees that it shall have no claim for innocent or negligent misrepresentation or negligent misstatement based on any statement in these Terms.
35.5
Nothing in this clause shall limit or exclude any liability for fraud.

36. Assignment

36.1
The Customer shall not, without the prior written consent of the Supplier, assign, transfer, mortgage, charge, subcontract, delegate, declare a trust over or deal in any other manner with any of its rights and obligations under these Terms.
36.2
The Supplier shall not, without the prior written consent of the Customer (such consent not to be unreasonably withheld or delayed), assign, transfer, subcontract or otherwise deal with any or all of its rights and obligations under these Terms. Notwithstanding the foregoing, the Supplier may assign or transfer its rights and obligations under these Terms in connection with any merger, acquisition, corporate reorganisation, or transfer of all or substantially all of its assets or business, provided that the Supplier gives the Customer not less than thirty (30) calendar days' prior written notice of any such assignment. If the Customer reasonably objects to such assignment on the grounds that the assignee is a direct competitor of the Customer or does not have the financial or technical capacity to perform the Supplier's obligations under these Terms, the Customer may terminate these Terms by written notice to the Supplier given within thirty (30) calendar days of receipt of the Supplier's notice, in which case the Supplier shall refund to the Customer any prepaid Subscription Fees covering the period after the effective date of termination on a pro-rata basis.

37. Publicity and Reference Rights

37.1
Neither party shall make any public announcement, issue any press release, or make any other public-facing communication that refers to the other party's name, trading name, brand, or logo in connection with the Services or these Terms without the other party's prior written consent in each instance.
37.2
The Supplier shall not use the Customer's legal name, trading name, brand, or logo for any purpose, including identifying the Customer as a user of the Services in the Supplier's website, pitch materials, or investor presentations, without the Customer's prior written consent in each instance. Where such consent is granted, the Customer may revoke it at any time by written notice to the Supplier, whereupon the Supplier shall remove all such references within thirty (30) calendar days of receipt of that notice.
37.3
Case studies and extended references. Any use of the Customer's name, logo, or details in a case study, testimonial, conference presentation, press release, or other promotional content beyond a bare name and logo listing shall require the Customer's prior written consent in each instance, such consent not to be unreasonably withheld or delayed.

38. No partnership or agency

Nothing in these Terms is intended to or shall operate to create a partnership between the parties, or authorise either party to act as agent for the other, and neither party shall have the authority to act in the name or on behalf of or otherwise to bind the other in any way.

39. Notices

39.1
Any notice given to a party under or in connection with these Terms shall be in writing and shall be given:
(a)
by the Supplier to the Customer: by email to the email address associated with the Customer's account or as otherwise notified by the Customer to the Supplier in writing from time to time; or
(b)
by the Customer to the Supplier: by email to contact@cybercertlabs.com or such other email address as the Supplier may notify to the Customer from time to time.
39.2
Any notice shall be deemed to have been received: (a) if sent by email, twenty-four (24) hours after sending, provided that no automated notification of non-delivery has been received by the sender within that period; or (b) if served by hand or by pre-paid first-class post at a party's registered office or principal place of business, at the time of delivery if delivered by hand, or at 9.00 am on the second Business Day after posting.
39.3
This clause does not apply to the service of any proceedings or other documents in any legal action or, where applicable, any arbitration or other method of dispute resolution.

40. Dispute Resolution

40.1
If a Dispute arises, either party shall serve written notice on the other setting out in reasonable detail the nature and particulars of the Dispute. Within ten (10) Business Days of such notice, each party shall escalate the matter to a senior representative (at director level or above) who shall meet (in person, by video conference, or by telephone, as agreed) and negotiate in good faith to attempt to resolve the Dispute.
40.2
If the Dispute is not resolved within twenty (20) Business Days of the notice served under clause 40.1 (or such longer period as the parties agree in writing), either party may refer the Dispute to mediation under the Rules of Mediation of the Mediators' Institute of Ireland for the time being in force. The mediator shall be agreed by the parties or, failing agreement within five (5) Business Days of a written request from one party to the other, appointed by the President of the Mediators' Institute of Ireland on the application of either party. The costs of mediation shall be shared equally between the parties unless the mediator orders otherwise. Nothing in this clause 40.2 prevents either party from seeking urgent injunctive or other interim relief from the courts of Ireland at any time.
40.3
Subject to clause 40.2, neither party shall commence proceedings before the courts of Ireland in accordance with clause 42 unless and until: (a) the steps in clauses 40.1 and 40.2 have been exhausted; or (b) forty-five (45) calendar days have elapsed from the date of the notice served under clause 40.1, whichever is the earlier. This restriction shall not prevent either party from commencing proceedings at any time where it reasonably considers that immediate legal action is necessary to protect its rights in relation to confidentiality, intellectual property, or payment obligations.

41. Governing law

These Terms and any dispute or claim arising out of or in connection with them or their subject matter or formation (including non-contractual disputes or claims) shall be governed by and interpreted in accordance with the laws of Ireland.

42. Jurisdiction

Each party irrevocably agrees that the courts of Ireland shall have exclusive jurisdiction to settle any dispute or claim arising out of or in connection with these Terms or their subject matter or formation (including non-contractual disputes or claims). Notwithstanding the foregoing, the parties may agree in an Order Form to submit disputes to arbitration in accordance with the rules of an internationally recognised arbitral institution, or to an alternative governing law and jurisdiction, in which case the relevant Order Form shall prevail over clauses 41 and 42 to the extent of any inconsistency.

These Terms were last updated on 10 August 2026. These Terms are effective as of the Effective Date applicable to each Customer.

43. Definitions

The definitions and rules of interpretation in this clause apply in these Terms and in each Order Form (unless the context requires otherwise or unless otherwise defined in the relevant Order Form).

Account: means the Customer's account on the Platform, through which the Customer and its Authorised Users access and use the Services.

Academy: means the Attestra Academy, being the online learning management system and associated training content provided by the Supplier, as more particularly described in the Documentation and any applicable Order Form.

Affiliate: means any entity that directly or indirectly controls, is controlled by, or is under common control with the subject entity. “Control,” for purposes of this definition, means direct or indirect ownership or control of more than 50% of the voting interests of the subject entity.

Agreement: These Terms, together with any applicable Order Form, the Documentation, and any policies or agreements incorporated by reference herein.

AI Output: any output, report, alert, briefing, recommendation, insight, analysis, or other content generated by the Services using artificial intelligence or machine learning techniques, whether delivered via the Platform or otherwise.

Authorised Users: those employees, agents and independent contractors of the Customer who are authorised by the Customer to use the Services and the Documentation, as further described in clause 12.2.

Beta Services: means Supplier services or functionality that may be made available to Customer to try at its option at no additional charge which is clearly designated as beta, pilot, limited release, developer preview, non-production, evaluation, or by a similar description.

Business Day: a day other than a Saturday, Sunday or public holiday in Ireland when banks in Dublin are open for business.

Cap: In relation to clause 26, means the total amount paid by the Customer and its Affiliates for the Services giving rise to the liability in the twelve (12) months preceding the first incident out of which the liability arose.

Change of Control: the beneficial ownership of more than 50% of the issued share capital of a company or the legal power to direct or cause the direction of the general management of the company, and controls, controlled and the expression change of control shall be interpreted accordingly.

Confidential Information: all information of a confidential nature disclosed by the other party in connection with these Terms.

Content: means all training materials, video lessons, written materials, quizzes, assessments, and other educational content made available by the Supplier through the Academy from time to time.

Cookie Policy: means the Supplier's cookie policy as published at https://attestra.ai/legal/cookie-policy and as amended by the Supplier from time to time.

CRA: EU Cyber Resilience Act (Regulation (EU) 2024/2847)

Customer: means the company or other legal entity on behalf of which an individual accepts these Terms, and Affiliates of that company or entity (for so long as they remain Affiliates) which have each entered into Order Forms.

Customer Data: the data inputted by the Customer, Authorised Users, or the Supplier on the Customer's behalf for the purpose of using the Services or facilitating the Customer's use of the Services.

Data Processing Agreement: means the data processing agreement entered into between the Supplier and the Customer in respect of the processing of personal data in connection with the Services, as published by the Supplier at [INSERT URL] and as amended by the Supplier from time to time in accordance with its terms.

Data Act: means Regulation (EU) 2023/2854 of 13 December 2023 on harmonised rules on fair access to and use of data.

Documentation: the document made available to the Customer by the Supplier online via [INSERT WEB ADDRESS] or such other web address notified by the Supplier to the Customer from time to time which sets out a description of the Services and the user instructions for the Services.

ENISA: means the European Union Agency for Cybersecurity established by Regulation (EU) 2019/881 of the European Parliament and of the Council of 17 April 2019.

Dispute: means any dispute arising out of or in connection with these Terms or their subject matter or formation (including any non-contractual dispute or claim).

Effective Date: the earlier of (a) the date on which the Customer first accepts these Terms (whether by executing an Order Form, clicking acceptance, or otherwise manifesting assent), or (b) the date on which the Customer first accesses or uses the Services.

EU AI Act: Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence, as amended, supplemented, or replaced from time to time, together with any delegated or implementing acts adopted thereunder.

Exportable Data: means input and output data, including metadata, generated or co-generated by the Customer's use of the Application Services, as defined in Article 2(38) of the Data Act, but excluding data protected by the intellectual property rights or trade secrets of the Supplier or any third party.

Free Services: means Services that Supplier makes available to Customer free of charge. Free Services exclude Services offered as a free trial and Purchased Services.

Free Trials: means Services available to the Customer on a free-of-charge basis for a limited time.

Heightened Cybersecurity Requirements: any laws, regulations, codes, guidance (from regulatory and advisory bodies. Whether mandatory or not), international and national standards, industry schemes and sanctions, which are applicable to either the Customer or an Authorised User (but not the Supplier) relating to security of network and information systems and security breach and incident reporting requirements, which may include the cybersecurity Directive ((EU) 2016/1148), Commission Implementing Regulation ((EU) 2018/151), the Network and Information systems Regulations 2018 (SI 506/2018), all as amended or updated from time to time.

Initial Subscription Term: the term set out in the Order Form.

IP Claim: any third-party Intellectual Property Right.

Intellectual Property Rights: means any and all intellectual property rights of any nature, whether registered, registerable or otherwise, including patents, utility models, trademarks, registered designs and domain names, applications for any of the foregoing, trade or business names, goodwill, copyright and rights in the nature of copyright, design rights, rights in databases, moral rights, know-how and any other intellectual property rights that subsist in computer software, computer programs, websites, documents, information, techniques, business methods, drawings, logos, instruction manuals, lists and procedures and particulars of customers, marketing methods and procedures and advertising literature, including the "look and feel" of any websites, and in each case all rights and forms of protection of a similar nature or having equivalent or similar effect to any of these that may subsist anywhere in the world, in each case for their full term, together with any future rights and renewals or extensions.

OSS Components: any software made available under an open-source licence as defined by the Open-Source Initiative (opensource.org) or the Free Software Foundation that is incorporated into or used to deliver the Services.

Named User: means an individual natural person identified by a unique login credential who is designated by the Customer to use the Services under a specific User Subscription. A Named User account is personal to the individual and may not be shared between two or more individuals.

Normal Business Hours: 09:00 to 18:00 Irish time, each Business Day.

Order Form: means the online form or hardcopy document which sets out the specific details of the Customer order including the charges and the number of Authorised Users.

Platform: means the Attestra AI Platform, being the cloud-hosted software-as-a-service platform provided by the Supplier for CRA compliance management, including all modules, features, and updates made available during the Subscription Term, as further described in the Documentation.

Privacy Policy: means the Supplier's privacy policy as published at https://attestra.ai/legal/privacy and as amended by the Supplier from time to time.

Payment Processors: means the third-party payment and subscription billing processors engaged by the Supplier from time to time for the processing of payments and management of subscription billing under these Terms, currently being Flexprice (subscription billing management) and Stripe Technology Europe, Limited (payment processing).

Prohibited AI Practice: means any artificial intelligence practice prohibited under Article 5 of the EU AI Act, as amended or supplemented from time to time.

Purchased Services: means Services that Customer or Customer's Affiliate purchases under an Order Form or online purchasing portal, as distinguished from Free Services or those provided pursuant to a free trial.

Renewal Term: means each successive period of twelve (12) months for which the Subscription Term is automatically renewed following the expiry of the Initial Subscription Term or a preceding Renewal Term, as described in clause 27.2, unless notice of non-renewal has been given in accordance with that clause.

Regulatory Reports: means structured vulnerability reports and incident notifications prepared by or on behalf of the Customer using the Services for submission to ENISA and/or relevant national market surveillance authorities pursuant to the requirements of the CRA and its implementing or delegated acts.

Services: the products and services that are ordered by Customer under an Order Form or online purchasing portal, or provided to Customer free of charge (as applicable) or under a free trial or otherwise on websites provided by us (such as our CRA Scope Assessment and Readiness Assessment tools), and made available by Supplier as described in the Documentation.

Software: the online software applications provided by the Supplier as part of the Services.

Subscription: means the Customer's right to access and use the applicable Services for the Subscription Term, as specified in the applicable Order Form and subject to these Terms.

Subscription Fees: the subscription fees payable by the Customer to the Supplier for the User Subscriptions, as set out in an Order Form.

Subscription Start Date: the date on which the Customer's Initial Subscription Term commences, as specified in the applicable Order Form or, where no Order Form exists, the date on which the Customer first accesses the Services.

Subscription Term: has the meaning given in clause 27.1 and clause 27.2 (as applicable) (being the Initial Subscription Term together with any subsequent Renewal Terms).

Supplier: means Cyber Cert Labs Limited, a company incorporated and registered in Ireland with company number 712039 whose registered office is at 2 Knockrabo Drive, Mount Anville Road, Dublin 14, Dublin 14, D14 N2T6, Ireland.

Terms: these terms and conditions as amended from time to time in accordance with clause 31.

User Subscriptions: the user subscriptions purchased by the Customer pursuant to an Order Form and clause 13.1 which entitle Authorised Users to access and use the Services and the Documentation in accordance with this agreement.

VAT: value added tax

Virus: any thing or device (including any software, code, file or programme) which may: prevent, impair or otherwise adversely affect the operation of any computer software, hardware or network, any telecommunications service, equipment or network or any other service or device; prevent, impair or otherwise adversely affect access to or the operation of any programme or data, including the reliability of any programme or data (whether by re-arranging, altering or erasing the programme or data in whole or part or otherwise); or adversely affect the user experience, including worms, trojan horses, viruses and other similar things or devices.

Vulnerability: a weakness in the computational logic (for example, code) found in software and hardware components that when exploited, results in a negative impact to the confidentiality, integrity, or availability, and the term Vulnerabilities shall be interpreted accordingly.

Vulnerability Data: means any Customer Data that constitutes or contains: (a) identified or suspected vulnerabilities in the Customer's products or systems; (b) security assessment results, penetration test findings, or risk scoring outputs; (c) CVE identifiers, CVSS scores, or equivalent structured vulnerability identifiers relating to the Customer's products; (d) SBOM data that discloses the composition of the Customer's products in a manner that could facilitate exploitation; or (e) any information relating to an unremediated security weakness.

On this page

  1. 2. Fair Use
  2. 3. Artificial Intelligence and Customer Compliance with Laws
  3. 4. ENISA Reporting and Incident Notification.
  4. 5. Third Party AI Providers; End User Obligations
  5. 6. Switching and Data Portability
  6. 7. Data Export During the Subscription Term
  7. 8. Feedback
  8. 9. Enhanced Protection for Vulnerability Data.

  1. 11. Open-Source Software

  1. 12. User Subscriptions
  2. 13. Additional User Subscriptions
  3. 14. Acceptable Use
  4. 15. Services
  5. 16. Free Trials and Free Services.
  6. 17. Fees, Payment, and Taxes
  7. 18. Price Changes
  8. 19. Modifications to Services
  9. 20. Data protection
  10. 21. Supplier's obligations
  11. 22. Customer's obligations
  12. 23. Proprietary rights
  13. 24. Confidentiality
  14. 25. Indemnity
  15. 26. Limitation of liability
  16. 27. Term and termination
  17. 28. Survival
  18. 29. Force majeure
  19. 30. Order of Precedence and Conflict
  20. 31. Variation
  21. 32. Waiver
  22. 33. Rights and remedies
  23. 34. Severance
  24. 35. Entire agreement
  25. 36. Assignment
  26. 37. Publicity and Reference Rights
  27. 38. No partnership or agency
  28. 39. Notices
  29. 40. Dispute Resolution
  30. 41. Governing law
  31. 42. Jurisdiction
  32. 43. Definitions
ATTESTRATTESTRAATESTRAAT
Attestra
Co-funded by the European UnionHosted in the EU

Cyber Cert Labs

  • Attestra AI
  • Articles & News
  • CRA Readiness Assessment
  • About us

Legal

  • Terms & Conditions
  • Privacy Notice
  • Cookie Policy

Contact

  • contact@cybercertlabs.com
  • +353 83 3608039
  • YouTube
  • LinkedIn

© 2026 Attestra. All rights reserved.Powered by Cyber Cert Labs