Terms of Service
Effective 26 August 2026. Last updated 26 August 2026. These terms apply to all use of the Tasirio service from that date.
1. Who these terms are with
These Terms of Service are an agreement between you — the organisation using Tasirio ("you", "Customer") — and Smartware Holdings, Inc., a Wyoming corporation doing business as "Tasirio", 4637 Indian Rock Drive, Fort Worth, TX 76244, United States ("Tasirio", "we", "us").
You accept these terms by using Tasirio — by signing in, connecting a system, or letting your people do either. If you are accepting for an organisation, you confirm you are authorised to bind it.
2. Who may use Tasirio
- Tasirio is sold to organisations for business use. It is not a consumer product and is not offered to consumers.
- Accounts are created by us. There is no public sign-up. We create your tenant when you buy, or when you agree to a pilot or design-partner arrangement.
- You may not use Tasirio if we have terminated your account. You confirm that you are not located in, and are not a national or resident of, a country subject to a United States embargo, and that you are not named on any United States government restricted-party list. Each party will comply with applicable export-control and sanctions laws.
3. Your account and your users
- Your users. You decide who gets access and at what role. You are responsible for their acts and omissions as if they were your own.
- Access hygiene. Keep credentials confidential. Remove people who leave. Tell us promptly at security@tasirio.com if you think an account has been compromised.
- Share links. Tasirio can mint read-only links that let someone view a single report without logging in — useful for an auditor, a broker or a board member. Anyone holding the link can view that report. You choose who receives them and you can revoke them. Treat them as you would any other confidential document. A person who views a report through a share link gets no rights under this agreement (see section 24).
- Two-factor authentication is available and can be switched on for your tenant. It is not on by default. We recommend enabling it for every administrator account.
- Accuracy. Keep your billing and notification contacts current.
4. What the service reads
Tasirio is a governance and accountability service. You connect the systems you want governed. We read their security and permission configuration, analyse it, and report exposures with guidance on how to fix them.
| We read | Examples |
|---|---|
| Who exists and what they can reach | Users, groups and membership, roles and role assignments, app registrations and the permissions granted to them, conditional-access and authorisation policy settings, sign-in timestamps |
| How sharing and access are configured | Site and drive inventory, sharing links, permission grants, sensitivity-label catalogues, channel membership, installed apps. Item and site names — never the contents of an item |
| Schema shape and reachability | Which tables and columns exist, which regulated data classes they hold, how many rows, and whether our read-only credential can select them |
| Supplier and payment master data — accounts-payable connector only | Supplier name, supplier ID, tax or company registration number, address, telephone, contact email, and a bank-account identifier. See below. |
| Network usage records — only if you deploy the shadow-AI agent | A device IP address and the AI service hostname it looked up, aggregated to device, service and count. A device IP is personal data in many places, which is why it is listed here rather than left implicit. |
| The people you nominate for alerts | Name, work email and, if you enter one, mobile number of your own colleagues |
We do not read the contents of documents, files, mailboxes, chat or Teams messages, calendar entries, notebooks or attachments. We do not download file bytes.
Two connectors read business record fields, deliberately, and we would rather say so than hide behind the word "metadata".
- Accounts-payable automation. The payment-fraud checks you buy — two suppliers sharing a bank account, a person who can both approve and pay — cannot be computed without supplier master data, so the connector reads it, bank details included. What we store is a partial mask: for an account identifier longer than eight characters we keep the first four and the last four; for eight characters or fewer we keep the last two. That is a partial mask, not full redaction, and we describe it that way. The full identifier is used in memory to group and is not written to our database. Supplier names, supplier IDs, registration numbers and the user roster are stored.
- Dealer ERP. The opposite discipline, and our model for the rest: we read table and column names, whether our credential can select them, and row counts. We never select a row value. A result of the form "cardholder data is present on roughly N rows" is a count plus a permission check — no cardholder value leaves your database.
On our Microsoft 365 connector, the "no content" rule is enforced by the code and not only by policy: every request goes through a single choke point that pins the method to GET, refuses any host other than Microsoft Graph, rejects a fixed list of content paths (messages, mail folders, calendar, chat, contacts, attachments, photos, thumbnails, versions, notebooks and raw-value paths), and then requires what is left to match an explicit list of permission and inventory endpoints. That specific mechanism is the Microsoft 365 connector's. Other connectors reach their vendors through their own read paths and read-only credentials. The commitment not to read content applies to all of them; the structural enforcement described here does not, and we will not imply that it does.
5. What the service is not
- Findings are not a guarantee of safety. If we report nothing in an area, that means we looked and saw nothing — not that the area is secure. Where we could not look, we report the surface as "not assessed" rather than clean.
- We tell you who can reach data, not who did. Tasirio computes effective access from your permission model. It does not ingest your systems' access logs and cannot tell you that a particular person actually opened a particular thing. No report or statement of work may imply otherwise.
- Not a certification, audit, or legal opinion. For reference only. Tasirio maps its findings to publicly described control themes to help you prioritise — this is not a compliance certification, assessment, or audit opinion, and does not attest conformance with any framework. Tasirio is an independent product and is not affiliated with, endorsed by, or sponsored by NIST, ISO/IEC, the PCI Security Standards Council, OWASP, the Cloud Security Alliance, the European Union, or any other standards body, regulator, or insurer. All framework, standard, and company names are trademarks of their respective owners, used for nominative reference only.
- Scheduling, stated accurately. Every account is placed on a daily automated pass, and that schedule is created and enabled by us when the account is created — you do not have to turn it on. That pass re-runs our analysis over data we already hold, updates findings, and can raise alerts. Re-reading your connected systems on that schedule is a separate setting, and it is off by default. Unless you turn it on or someone runs a scan, we read your systems when a person asks us to. If you have linked findings to a ticketing system, the daily pass also polls that system for ticket status. We do not describe any of this as continuous monitoring.
- Not a substitute for your own security programme. You decide what to fix and when.
6. Connecting your systems
6.1 You must have authority to connect
You may only connect a system your organisation owns or is authorised to administer, using access you are authorised to grant. You are also responsible for having a lawful basis for the processing and for giving your people any notice their law requires. We cannot verify any of this for you.
6.2 We do not write to the systems we govern
Tasirio does not create, modify, or delete data in the systems it reads. Our connectors issue read calls. Where a vendor's read operation requires an HTTP POST — an OAuth token exchange, a query API that takes a request body — we use it for that read and nothing else. We compute who can reach what from your permission model; we never test access by probing or by escalating our own privileges.
6.3 Outbound integrations you configure — where we do write
This is the honest exception, and it belongs on the same page as the promise above.
If you configure an outbound ticketing integration, Tasirio creates and updates records in that destination, using credentials you supply, at your instruction. Concretely: we create issues in Jira, incidents in ServiceNow, and tickets in Zendesk and Syncro; we update their status when a finding's status changes; and we add comments or work notes explaining a re-verification outcome. We also post to Slack and to generic webhooks you nominate.
Two of those destinations — ServiceNow and Zendesk — can also be connected as systems we govern. When the same system is both governed and used as your ticket destination, we read it under section 6.2 and write to it under this section. That is not a contradiction, but it is exactly the kind of thing a contract should say plainly rather than leave to be discovered.
6.4 How we authenticate
Most connectors use a credential issued directly to Tasirio. A few vendors only expose the data we need through delegation: for Google Workspace we sign as a service account and act as an administrator you designate in your own domain, using read-only scopes; DocuSign uses a similar impersonation grant. You choose the account we act as, and you can revoke it. We disclose this because "we never act as one of your users" would not be true, even though we never do it in order to test access.
6.5 Permissions with write-sounding names
Some vendors put read-only data behind a permission whose name implies write access, and publish no narrower alternative. Reading SharePoint site permission grants is the clearest example. We do not silently decline these — declining is not free, and quietly collecting less is not the same as looking and finding nothing.
Before such a permission is granted we show you: what it is for, what it unlocks, why no read-only version exists, what is still not collected even with it, and what stays invisible if you decline. You must acknowledge it explicitly, and that acknowledgement is recorded. Consent is never inferred from the grant merely existing. For every connector that holds such a permission, a build check fails our deployment if that connector's code could issue any non-GET call, and the connector must pin its HTTP method at a single fetch choke point.
The limit, stated plainly: that build check covers the connectors that declare a write-named permission, and it scans connector code only. The others are protected because the credential you issue is read-only — a write would be refused by the vendor rather than by our code. No connector contains a mutating call to a vendor today, but that is a measured state, not a compiled guarantee. We will not claim "the build fails if any connector stops being read-only".
6.6 The one thing we write outside our own systems
The only thing Tasirio writes anywhere outside its own database is the credential you give us, into a key vault — ours, or your own — so it never sits in a database. That is separate from the outbound integrations in section 6.3, which write into destinations you chose and control.
6.7 Software you run on your premises
Some systems sit inside your network. For those we provide a collector agent you install and run. It makes read-only queries against the system you point it at and one outbound HTTPS call to us. Nothing inbound; no firewall change on your side. You are responsible for the host it runs on and for the read-only database account you create for it. We grant you a non-exclusive, non-transferable licence to run the agent during the term, solely to send data to your own Tasirio tenant. The agent is an early-access capability and section 16 applies to it.
6.8 Where we can and cannot verify the address you type
Where a system has a vendor-owned domain, the address you type is locked to that vendor's own registrable domain, so a credential cannot be sent to a look-alike host. Some systems are genuinely yours — an on-premises SQL Server, a self-hosted ERP, an on-premises Oracle endpoint. For those there is no vendor domain to anchor to, and the only guarantee available is that the address is not one of ours. We check that on every sync rather than only when you save it, because a name that resolves publicly today can be re-pointed tomorrow. In those cases the address you type is the address we dial, and getting it right is a shared responsibility.
7. Credentials and keys
- Every credential you give us goes to Azure Key Vault. Our database holds only a reference to it, never the value. Credentials are fetched into memory at sync time. An automated check in our release process fails the deployment if any connector field that looks like a credential is routed anywhere other than the vault.
- We do not log credentials, and no API of ours returns one.
- Bring your own key has two modes and the difference is material. In customer-key mode you generate, supply, rotate and revoke the key, but it lives in our vault so unattended syncs keep working — you control it, we have operational custody. In bring-your-own-vault mode (Azure Key Vault, AWS Secrets Manager, Google Secret Manager, Oracle Vault) your secrets stay in your vault and we hold only a scoped, revocable credential to read them. Only the second is zero-custody. The own-cloud vault integrations are supported and are certified with you during onboarding; the Oracle Vault integration is in beta and section 16 applies to it.
- Customer-supplied keys and connector credentials are held as key-vault secrets, which are software-protected on every Key Vault tier. We do not describe them as hardware-protected, because they are not.
- In both modes, deleting the key or revoking the access makes the stored secrets unusable to us. That is your kill switch.
- You can disconnect a system at any time. Revoking the credential on your side takes effect immediately regardless of anything we do, and it is the fastest route.
8. Your data, and who owns what
8.1 You own your data
You own everything you connect and everything we derive from it for you: the configuration and permission metadata we collect, the findings, the evidence and the reports. We claim no ownership. You grant us the limited right to read, store, process and display that data to operate the service for you, for your users and for the people you share reports with. We do not sell it, and we do not use it to train any machine-learning model. That right ends when this agreement ends, except as sections 8.3 and 15.3 describe.
8.2 We own the software
Tasirio owns the platform: the software, the connectors, the detection logic, the reports and their templates, and all related intellectual property. Nothing here transfers any of it. You get a non-exclusive, non-transferable right to use the service for your own organisation during the term. If you send us feedback or suggestions we may use them without obligation, and will not identify you as the source without your permission.
8.3 Aggregate statistics
We keep a separate, deliberately narrow record of finding activity: the type of finding, the connector it came from, its severity, and when it was first seen and when it was resolved. That record carries no resource name, no description, no account and no user — those columns do not exist in it. Issues are linked over time by a one-way keyed identifier that cannot be reversed into the underlying resource.
We use it for three things, and we list all three because enumerating two would make the omission of the third a misstatement:
- Our own product analytics — which detections fire, which are resolved, where the product is weak.
- Peer benchmarking — described below.
- Aggregate outcome statistics we publish about the product, of the form "N findings on a real customer estate". These never name a customer and never identify one.
Benchmarking, stated precisely. The product contains two different comparisons and they must not be confused. One is a modelled reference distribution built from our own configuration; every response it produces is labelled as such in the product, and it is not real peer data. The other is a genuine peer comparison computed from the record above, and it will only ever return a figure when the cohort contains at least five organisations other than you, so no single peer can be identified. Only aggregates and your own position leave that system — never another customer's identity or numbers. Today the peer comparison rarely meets that floor, so what you are most likely to see is the modelled reference, labelled.
These records are durable. They are designed to survive the deletion of an account so historical totals are not retroactively rewritten. They contain nothing that identifies you or your systems, but they are not deleted when your account is.
9. Acceptable use
You may not, and may not permit anyone else to:
- Connect a system you do not own or are not authorised to administer, or use a credential you were not authorised to issue.
- Use Tasirio against a third party's environment as a scanning or reconnaissance tool.
- Attempt to make Tasirio write to, alter, disrupt, or escalate privileges in any system — ours or anyone else's.
- Probe, penetration-test, or load-test the Tasirio platform without our prior written permission. Report suspected vulnerabilities to security@tasirio.com; we will acknowledge your report and will not pursue a claim against you for good-faith research conducted within a scope we have agreed in writing.
- Resell, sublicense, distribute or provide the service to a third party, or use it to deliver a service to a third party, without a signed Tasirio partner agreement. Managing another organisation's Tasirio tenant requires a partner agreement and that organisation's authorisation.
- Share account credentials, or give access to anyone outside your organisation other than through the report-sharing features we provide.
- Copy, reverse engineer, decompile, or attempt to derive the source of the platform, or build a competing product from it.
- Remove or obscure the disclaimers on reports we generate, or present a Tasirio report as a certification, audit opinion or attestation of compliance.
- Use the service in violation of law, or to store or transmit anything unlawful.
If you breach this section we may suspend access immediately and without notice. We will tell you why as soon as we reasonably can.
10. Fees and billing
- Fees, term and payment terms are those set out in your order form or written arrangement with us. Nothing on this page sets a price.
- Subscriptions are arranged directly with us and invoiced. Payment terms are net 30 from the invoice date unless your order form says otherwise.
- Fees are exclusive of taxes. You are responsible for sales, use, VAT and similar taxes other than taxes on our income. Where we are required to collect a tax, it will be shown on the invoice.
- Subscriptions are billed annually in advance for the term stated on your order form. We do not offer monthly, quarterly or semi-annual billing.
- Fees are non-refundable except where the law requires otherwise, where your order form expressly says otherwise, or where these terms expressly provide for a refund (sections 13, 18 and 21 do).
- A one-time assessment fee is refundable if the assessment has not yet been delivered.
- If an invoice goes unpaid past its due date and a ten-day grace period, we may suspend the account. Suspension makes the account read-only — you can still see what we have already found, but scans and new connections stop. We do not delete your data because of non-payment.
- Renewal and cancellation. Annual terms renew automatically for successive terms of the same length unless either party gives written notice of non-renewal at least 30 days before the end of the current term. Cancellation takes effect at the end of the then-current term and there is no pro-rated refund for a partial term. There is no self-service cancellation in the product: tell your account contact in writing, and we will confirm.
- We will give you at least 30 days' written notice of a fee change, and a fee change takes effect no earlier than your next renewal.
11. Trials and pilots
- There is no self-service free trial. A trial or pilot exists only where we have granted it in writing.
- A trial gives you access for the period we state. If we did not state a period, we may end it at any time on notice.
- Trials are provided as-is, with no warranty and no commitment of any kind. We may change or withdraw features during a trial.
- Report share links created during a trial have a shorter lifetime than those on a paid subscription.
- If you do not convert to a paid subscription your access ends and section 15.3 applies to your data.
12. The Exposure Assessment
The Assessment is a one-time engagement, not a subscription. If you buy one, this section applies in addition to the rest of these terms.
- Fee and scope are as stated on your order form.
- Scope caps. Up to five connected systems; two successful data gathers per system (a baseline and a re-check); up to 1,500 licensed identities; within a six-month window from purchase. Analysis of the data gathered is not separately metered. A gather that fails does not count against your two.
- A cap is a stated boundary, never a silent truncation. If your environment exceeds a cap we tell you exactly what was and was not assessed — for example, "this assessment covers 1,500 identities; your tenant has 4,200, and the remaining 2,700 were not assessed". We will never quietly assess a subset and report it as though it were the whole.
- Beyond the caps is a subscription, not a larger assessment. We will tell you before doing further work, and further work is chargeable.
- Access after delivery. The fee includes access to the findings and reports produced by the engagement, in the product, for 180 days after delivery. Continued access after that is a subscription.
- Retention. Scan history and findings from the engagement are deleted 183 days (about six months) after each scan date, by an automated sweep. Evidence packs and the activity log are retained as described in section 15.3 and are not covered by that figure.
- The Assessment is a point-in-time review. It is not monitoring and it is not a certification. Section 5 applies in full.
13. Availability, maintenance and changes to the service
These terms contain no service level agreement. We do not commit to an uptime percentage, to a recovery time, or to any availability target, and you should not rely on one. We aim to keep the service running and to give reasonable notice of planned maintenance. That is the whole of the commitment.
We may change, add to, or remove features. If we remove something you depend on, or make a change that materially reduces the service, we will give you reasonable notice; and if the change materially reduces the service for the remainder of your term, you may terminate the affected part of the service and receive a pro-rated refund of prepaid fees for the unused period.
We may suspend the service, in whole or in part, where we reasonably need to in order to protect the platform, our other customers, or you.
14. Security and privacy
How we handle personal information is described in our Privacy Policy. Where we process personal data on your behalf, our Data Processing Addendum governs — including the sub-processor list, international transfers, and how we notify you of changes.
What we can say about our security posture, precisely:
- Governed data — your findings and the permission records behind them — is isolated by PostgreSQL row-level security that the database itself enforces, including against the table owner. The application connects as a restricted role that is neither a superuser nor able to bypass row security. Platform records such as your connector settings and notification recipients sit in a separate schema where every query is tenant-filtered, under the same restricted role. Both are real; they are not the same control, and we do not describe them as one.
- Findings and their supporting detail — the resource, the description and the evidence — are encrypted at the application layer with AES-256-GCM under a data key unique to your account, before they are written. That data key is wrapped by a key-encryption key held only in Azure Key Vault and never in the database, so the database holds ciphertext and wrapped keys and nothing else: a database compromise alone yields no readable findings. The key-encryption key is itself wrapped by a non-exportable RSA-HSM key in Azure Key Vault Premium and is unwrapped inside that hardware boundary. The connector tables holding names, work emails and group membership are protected by row-level security and platform encryption at rest, not by that additional layer.
- Each completed synchronisation we run against your systems, and each administrative action in your account, is recorded in an append-only, hash-chained activity log that our application cannot rewrite or delete, together with which surfaces were read and which checks could not run. A synchronisation that fails part-way is recorded on the connection's status rather than in that log.
- Evidence packs are held under a 365-day write-once retention policy, so an evidence pack cannot be altered or deleted while that policy stands.
- All customer data at rest resides in Microsoft Azure, East US 2, in the United States. We operate a single region and offer no other data-residency option. Some Azure services we use are not region-scoped; where any processing may occur outside the United States, our Data Processing Addendum says so and says which. Do not rely on any regional commitment; we cannot make one today.
- We run no analytics, no advertising trackers and no session recording in the product or on our website.
- Our optional in-product AI features send finding types, severities and counts to our AI sub-processor. Prompts are redacted before they are sent. No document, file, message or record content is sent to any model, and customer content is not used to train any model. The Data Processing Addendum sets this out in full.
- We are not SOC 2 certified and we are not ISO 27001 certified. We maintain an internal self-assessment against the SOC 2 criteria and SOC 2 readiness work is in progress. No third-party penetration test has been performed.
15. Term, termination, and what happens to your data
15.1 Term
These terms apply from when you first use the service until your subscription ends and your account is closed.
15.2 Termination
- You may terminate at the end of your current term, as described in section 10.
- Either party may terminate immediately for material breach not cured within 30 days of written notice.
- We may suspend or terminate immediately for a breach of section 9, for non-payment after the grace period, or where we are required to by law.
15.3 Your data on termination
On termination, and on your written request, we will return or delete your data within 30 days. Some categories behave differently, and all of them are listed here rather than summarised:
| Data | What happens |
|---|---|
| Findings, permission records, scan history, connector settings, your tenant and user records | Deleted within 30 days of termination or your written request. |
| Connector credentials | Deleted from the key vault within 30 days. The vault keeps a recoverable soft-deleted copy for 90 days and then purges it. Under bring-your-own-vault there is nothing for us to delete — you revoke our access. In every case you can revoke the credential in your own system immediately, without us. |
| Evidence packs | Held under a 365-day write-once retention policy. While that policy stands they cannot be deleted or overwritten, which is what makes them usable as evidence. The policy is in an unlocked state, so we retain the technical ability to lift it where the law requires erasure. It is therefore not impossible to erase them, but it is not automatic either. |
| The activity log | Cannot be edited or purged during the term — the database refuses the operation, and deleting entries would break the tamper-evidence that is the point of it. It is deleted together with your tenant record on termination. |
| Backups | Deleted data may persist in a point-in-time database backup for up to 35 days before it ages out. Backups are restored only for disaster recovery, never to retrieve data that was deleted on request. |
| Aggregate statistics (section 8.3) | Retained. They carry no resource, account or user identifiers. |
| Billing and tax records | Retained as required by law. These are our own records, not your data. |
While your account is active you can export your data yourself. Ask us before termination if you want a final export; we will provide your findings and reports within 30 days in the formats the service supports at the time.
15.4 What survives
Sections 7 (your right to revoke), 8.1 (final sentence), 8.2, 8.3, 15.3, 15.4, 16, 17, 18, 19, 20, 22, 23 and 24 survive termination, together with any payment obligation already accrued.
16. Warranties and disclaimers
We will perform the service with reasonable skill and care. That is the only warranty we give.
Subject to that, the service is provided "as is" and "as available". To the fullest extent the law allows we disclaim all other warranties, express or implied, including merchantability, fitness for a particular purpose, title and non-infringement.
In particular, we do not warrant that:
- findings are complete, or that we will identify every exposure, misconfiguration or risk in your environment;
- the absence of a finding means the absence of risk;
- a risk grade or score is an assessment of your organisation's overall security posture;
- the service will be uninterrupted, timely or error-free;
- acting on our guidance will make you compliant with any law, regulation, framework or insurance requirement.
Descriptions are not warranties. Sections 4, 5, 6 and 14 describe how the service works so you can make an informed decision. They are accurate as at the effective date and we will not change them to be less accurate without notice, but they are descriptions of software behaviour, not performance warranties, and the disclaimer above applies to them.
Early-access features. Some capabilities are built but not yet proven in a customer environment — at the date of these terms that includes the own-cloud key-vault integrations, export to a customer's security-monitoring platform, and the on-premises collector agent. Where we identify a feature as early access, beta or preview, it is provided as-is, is excluded from the warranty in the first paragraph of this section, and is excluded from our indemnity in section 18.
You remain responsible for your own security decisions. Findings are input to your judgement, not a replacement for it.
17. Limitation of liability
Neither party is liable to the other for indirect, incidental, special, consequential or punitive damages, or for lost profits, lost revenue, lost data or business interruption, however caused and regardless of the theory of liability, even if told such damages were possible.
Each party's total aggregate liability arising out of or relating to this agreement is limited to the fees you paid or owed to us in the twelve months before the event giving rise to the claim. Where the service has been provided without charge — a pilot, a trial or a design-partner arrangement — that cap is one thousand United States dollars (US$1,000).
These limits do not apply to:
- your obligation to pay fees;
- either party's breach of its confidentiality obligations under section 19;
- either party's indemnity obligations under section 18;
- a party's fraud or wilful misconduct; or
- any liability that cannot be limited by law.
18. Indemnity
You will defend and indemnify us against third-party claims arising from: (a) your connecting a system you did not own or were not authorised to administer, or using a credential you were not authorised to issue; (b) your use of the service in breach of section 9; (c) your own acts or omissions in acting on the findings and reports we produce, except to the extent the claim arises from our own negligence, wilful misconduct or breach of this agreement; or (d) your violation of law.
We will defend and indemnify you against third-party claims that the Tasirio platform, used as permitted by these terms, infringes that party's intellectual property rights. This does not apply where the claim arises from your data, from your combining the service with something else, from an early-access feature under section 16, or from your use in breach of these terms. If the service becomes subject to such a claim we may modify it, obtain a licence, or terminate the affected part and refund fees for the unused period.
The indemnified party must notify the other promptly, allow it to control the defence, and cooperate reasonably. Neither party may settle in a way that admits liability for the other without consent.
19. Confidentiality
Each party will protect the other's confidential information with at least the care it uses for its own, will use it only to perform this agreement, and will disclose it only to people who need it and are bound to keep it confidential. This does not cover information that is public, already known, independently developed, or lawfully received from someone else. Either party may disclose where legally compelled, after giving the other notice where it is lawful to do so.
Your findings, reports and connected-system data are your confidential information.
20. Security incidents
If we become aware of a security incident affecting your data in our systems, we will notify you without undue delay, and in any event no later than 72 hours after we become aware. This applies whether or not the data involved is personal data — the schema inventories, supplier records and stored credentials we hold on your behalf are not obviously personal data and we do not want a scope argument standing between you and a notice. Where the incident involves personal data, section 12 of the Data Processing Addendum also applies.
Our notice will describe what we know at the time and will be followed by updates as facts are established. We will not delay a first notice in order to complete an investigation. A notice is not an admission of fault or liability.
21. Changes to these terms
We may update these terms. If a change materially affects your rights we will give you at least 30 days' notice by email to your account contact and by posting the updated terms with a new effective date. If you do not agree you may terminate before the change takes effect and we will refund fees for the unused portion of your term. Changes that are not material — corrections, clarifications, and changes required by law — take effect when posted.
22. Publicity
Neither party will name the other, or use its logo, in marketing without prior written consent. Consent for one use is not consent for another. This does not restrict the aggregate, non-identifying statistics described in section 8.3.
23. Governing law and disputes
These terms are governed by the laws of the State of Texas, without regard to its conflict-of-laws rules, and the United Nations Convention on Contracts for the International Sale of Goods does not apply. The parties submit to the exclusive jurisdiction of the state and federal courts located in Tarrant County, Texas, and each party consents to venue there.
Before filing, the parties will try in good faith for 30 days to resolve a dispute through their named contacts. Either party may seek injunctive relief at any time to protect its confidential information or intellectual property.
Where the European Commission's Standard Contractual Clauses apply to the processing of personal data, the governing law and forum for those clauses are as stated in our Data Processing Addendum, and they prevail over this section for that processing.
24. General
- Entire agreement. These terms, your order form, our Data Processing Addendum and any agreement we have both signed are the whole agreement between us on this subject and replace anything said before.
- Order of precedence. A countersigned agreement, then your order form, then the Data Processing Addendum, then this page — except that for the processing of personal data the Data Processing Addendum prevails over all of them, and where the Standard Contractual Clauses apply they prevail over everything.
- No third-party beneficiaries. Nobody other than you and us acquires rights under this agreement. That includes anyone who views a report through a share link.
- Assignment. Neither party may assign without the other's consent, except to a successor in a merger or sale of substantially all assets. Consent will not be unreasonably withheld.
- No waiver. Not enforcing something once does not waive it.
- Severability. If a provision is unenforceable, the rest stays in force and the unenforceable provision is limited to the minimum extent necessary.
- Force majeure. Neither party is liable for delay or failure caused by events beyond its reasonable control. This does not excuse payment.
- Independent contractors. Nothing here creates a partnership, agency or employment relationship.
- Notices. To you, at your account contact email. To us, at legal@tasirio.com and at the address in section 1.
Questions
Commercial questions: your account contact. Privacy: privacy@tasirio.com. Security: security@tasirio.com. Legal notices: legal@tasirio.com.
Related: Privacy Policy · Terms of Service · Data Processing Addendum · Sub-processors · Security & Trust