Legal
Six documents, all published in full rather than available on request. Each states its effective date, and material changes are logged in the changelog rather than applied silently.
DPA, security questionnaire, or an executed counterpart on your own paper. We turn most around in five business days.
The documents
| If you are… | Read |
|---|---|
| Browsing the website | Privacy Policy, Cookie Policy |
| Evaluating and requesting an assessment | Privacy Policy, Terms |
| A customer | Terms, DPA, SLA, AUP |
| A customer’s employee, vendor, or customer whose data is in their tenant | Privacy Policy §3 — then contact that organisation, not us |
| Running a vendor security review | DPA Annex II, Compliance, Security, Subprocessors |
| A security researcher | AUP §5 — we will not pursue good-faith research |
Where documents conflict: an executed master agreement, then the DPA for personal data matters, then an Order Form, then the SLA, then the AUP, then the Terms, then the Documentation. Purchase orders and vendor portal terms have no effect, even if we acknowledge them.
These documents were prepared carefully and comprehensively, and they have not yet been reviewed by qualified legal counsel. They should not be relied upon as legal advice, and anyone contracting with us should have their own counsel review them. We would rather say that than imply a review that has not happened.
These are not contractual but are frequently requested during a vendor review, and several are referenced by the documents above.
Questions
Executed DPA, security questionnaire, SCCs, insurance certificate, or transfer impact assessment.