Legal
The terms, policies and agreements that govern your use of PrivIQ. Click any document to expand.
The master agreement governing your use of PrivIQ – covering subscription, fees, data processing (Data Processing Agreement / DPA), warranties, liability, term and termination. This document also serves as the controller-processor DPA required under Article 28 GDPR.
1. Definitions
Sets out the defined terms used throughout the agreement, including Affiliate, Authorized User, Customer Data, Documentation, Services, Subscription Term and similar.
2. The PrivIQ Services
PrivIQ grants the Customer a limited, non-exclusive, non-transferable right to access and use the Services during the Subscription Term, in accordance with the Documentation and the Order Form.
3. Customer Data and Security
Customer retains all rights, title and interest in Customer Data. PrivIQ implements technical and organisational measures appropriate to the risk – including AWS Well-Architected infrastructure, encryption in transit and at rest, role-based access controls and audit logging.
4. Fees and Payment
Subscription fees are payable in advance per the Order Form. PrivIQ reserves the right to adjust fees on renewal with prior written notice.
5. Term and Termination
The agreement commences on the Effective Date and continues for the Subscription Term unless terminated earlier in accordance with these Terms. Either party may terminate for material breach not cured within 30 days of notice.
6. Confidentiality
Each party will protect the Confidential Information of the other with the same degree of care it uses to protect its own confidential information, and will not disclose it to third parties except as permitted under this agreement.
7. Warranties and Disclaimers
PrivIQ warrants that the Services will materially conform to the Documentation. Except as expressly stated, the Services are provided “as is” to the fullest extent permitted by law.
8. Limitation of Liability
Neither party will be liable to the other for indirect, consequential, special or punitive damages. Aggregate liability is capped at the fees paid in the 12 months preceding the claim.
9. Data Processing Agreement (DPA)
When PrivIQ processes personal data on behalf of Customer, it acts as a Processor. The DPA addresses subject-matter and duration, nature and purpose of processing, types of personal data and categories of data subjects, sub-processor arrangements (with advance notice and right to object), data subject rights assistance, security measures, breach notification, audit rights, and return or deletion of data at end.
10. Sub-processors
PrivIQ may engage sub-processors to support service delivery. A current list of sub-processors is maintained and available on request. PrivIQ provides advance notice of material sub-processor changes.
11. International Transfers
Where personal data is transferred outside the EEA or UK to a non-adequate destination, PrivIQ relies on Standard Contractual Clauses with supplementary measures as appropriate.
12. Governing Law
These Terms are governed by the laws of the Netherlands. Disputes will be resolved in the competent courts of Amsterdam, subject to applicable mandatory consumer-protection laws.
Supplementary terms applicable to professional and consulting services delivered by PrivIQ – including onboarding, configuration, training, and “Build a Risk Solution” engagements.
1. Scope
These Additional Services Terms apply where PrivIQ provides professional services in addition to the standard subscription – onboarding, configuration, training, ongoing support, framework development or consultant-branded delivery.
2. Statement of Work
Each engagement is governed by a Statement of Work (SOW) describing the scope, deliverables, timeline, fees and acceptance criteria. The SOW is incorporated by reference into the master agreement.
3. Customer Responsibilities
Customer will provide reasonable cooperation, timely access to relevant stakeholders, and the information PrivIQ requires to deliver the engagement. Delays in customer cooperation may extend timelines accordingly.
4. Acceptance
Deliverables are deemed accepted on the earlier of (a) written acceptance, (b) productive use, or (c) the lapse of any acceptance window specified in the SOW.
5. Change Control
Material changes to scope, deliverables or timeline are documented through a written change request signed by both parties.
6. Intellectual Property
PrivIQ retains all rights in its pre-existing IP and any general-purpose tools, methods or know-how. Customer receives a non-exclusive licence to use deliverables specifically prepared for the engagement.
7. Fees
Professional services fees are billed per the SOW – typically on a fixed-fee, time-and-materials or milestone basis.
8. Travel and Expenses
Reasonable, pre-approved travel and expenses are reimbursed at cost, subject to the SOW.
9. Subcontractors
PrivIQ may engage qualified subcontractors to deliver the engagement, subject to equivalent confidentiality and data-protection obligations.
10. Termination of an SOW
Either party may terminate an SOW for material breach not cured within 30 days. On termination, Customer pays for services rendered up to the effective date.
Rules governing how the PrivIQ Services may and may not be used. Forms part of the Terms of Service.
1. Purpose
The Acceptable Use Policy (AUP) protects the security, integrity and availability of the PrivIQ Services for all customers. It sets out conduct that is permitted and conduct that is prohibited.
2. Prohibited Activities
Customer and Authorized Users will not: (a) use the Services to violate applicable law; (b) infringe intellectual-property or privacy rights of others; (c) upload malicious code, viruses or other harmful content; (d) interfere with or disrupt the integrity or performance of the Services; (e) attempt unauthorized access to other customers’ data; (f) reverse-engineer or attempt to derive the source code of the Services except as permitted by mandatory law; (g) resell or sub-licence the Services except as expressly permitted.
3. Content Restrictions
Customer will not upload personal data of categories prohibited or restricted by law without a lawful basis, including special categories of personal data, children’s data, criminal-offence data and similar.
4. Authorized Users
Customer is responsible for the acts and omissions of its Authorized Users as if they were its own. Customer will ensure each Authorized User is bound by terms at least as protective as this AUP.
5. Security
Customer will use commercially reasonable measures to protect its credentials and notify PrivIQ promptly of any suspected compromise.
6. AI-Assisted Features
Where Customer enables AI-assisted features (e.g. ChatGPT-integrated assistance), Customer will not input personal, sensitive or illegal information into prompts. Misuse of AI features may result in suspension of those features.
7. Investigations and Enforcement
PrivIQ may investigate suspected violations and, where appropriate, suspend access pending resolution. PrivIQ may terminate the agreement for material or repeated violations of this AUP.
8. Reporting Abuse
To report a suspected violation of this AUP, contact info@priviq.com.
PrivIQ’s commitments on Service availability, support response times, and service credits for missed targets. Forms part of the Terms of Service. Last updated 1 October 2022.
1. General
This Service Level Agreement (SLA) describes the level of service Customer can expect from PrivIQ. It is incorporated into the Terms of Service. PrivIQ may update this SLA from time to time – the current version is always published at priviq.com/legal-service-level-agreement.
2. Access to Customer Success
PrivIQ provides Customer with access to its Customer Success team. The team supports Customer with onboarding, configuration questions, training and ongoing optimisation of the platform.
3. Support Channels and Hours
Support is provided in English, Monday to Friday from 09:00 to 17:00 UK time (excluding UK public holidays), through the in-product chat and via email to support@priviq.com.
4. Error Response Times
PrivIQ classifies errors by severity and targets the following initial response times: Critical (system-wide outage or data-loss event) – two (2) hours; High (significant feature impairment affecting many users) – four (4) hours; Medium (limited-impact issue with available workaround) – twenty-four (24) hours; Low (cosmetic issue, question or feature request) – twenty-four (24) hours. Response times are measured during support hours.
5. Service Monthly Uptime
PrivIQ targets a Service Monthly Uptime of 99% for the Production Service, measured on a calendar-month basis. Uptime calculation excludes Scheduled Maintenance, Emergency Maintenance and factors outside PrivIQ’s reasonable control.
6. Service Level Credits
Where Service Monthly Uptime falls below the 99% target, Customer may claim service credits calculated as a percentage of the monthly subscription fee for the affected service. Indicative credit bands: 100% – 0.5%; 99-95% – 1%; 95-90% – 5%; 90-85% – 10%; 85-50% – 15%; 50-0% – 20%. Service credits are Customer’s sole and exclusive remedy for breach of this SLA.
7. Exclusions
This SLA does not apply to: (a) Scheduled Maintenance or Emergency Maintenance; (b) factors outside PrivIQ’s reasonable control, including force majeure, internet failures and third-party services; (c) issues caused by Customer, its Authorized Users, or systems Customer controls; (d) beta, trial or evaluation features.
8. Claims and Changes
Service credit claims must be submitted within thirty (30) days of the end of the affected calendar month, accompanied by reasonable evidence. PrivIQ may modify this SLA from time to time, with material changes notified through the canonical page on priviq.com.
How PrivIQ handles allegations of copyright infringement and the rights of copyright holders to request removal. Last updated 1 October 2022.
1. Respect for Intellectual Property
PrivIQ respects the intellectual-property rights of others and expects users of the Services to do the same. In appropriate circumstances and at its discretion, PrivIQ may disable or terminate the accounts of users who repeatedly infringe the copyrights of others.
2. Removal of Content – Notice Requirements
A copyright owner (or authorised agent) who believes content on the PrivIQ Services infringes their copyright may submit a written notice to info@priviq.com. The notice must include: (a) a physical or electronic signature of the person authorised to act on behalf of the copyright owner; (b) identification of the copyrighted work claimed to be infringed; (c) identification of the allegedly infringing material with information reasonably sufficient to locate it; (d) the complaining party’s contact details (address, telephone number and email); (e) a statement that the complaining party has a good-faith belief that use of the material in the manner complained of is not authorised by the copyright owner, its agent or the law; (f) a statement that the information in the notification is accurate and, under penalty of perjury, that the complaining party is authorised to act on behalf of the owner of an exclusive right that is allegedly infringed.
3. Counter-Notification
A user who believes their material was removed or disabled as a result of mistake or misidentification may submit a counter-notification to info@priviq.com. The counter-notification must include: (a) the user’s physical or electronic signature; (b) identification of the material that has been removed or to which access has been disabled, and the location at which the material appeared before it was removed or disabled; (c) a statement under penalty of perjury that the user has a good-faith belief that the material was removed or disabled as a result of mistake or misidentification; (d) the user’s name, address and telephone number, together with a statement that the user consents to the jurisdiction of the courts of the Netherlands.
4. Misrepresentations
Any person who knowingly materially misrepresents that (a) material or activity is infringing, or (b) material or activity was removed or disabled by mistake or misidentification, may be liable for damages, including costs and attorneys’ fees, incurred by the alleged infringer, the copyright owner or its authorised licensee, or PrivIQ.
5. Repeat Infringers
PrivIQ may, in appropriate circumstances and at its discretion, suspend or terminate the accounts of users who are determined to be repeat infringers of copyright.
6. Modifications
PrivIQ may modify this Copyright Policy from time to time. The current version is always published at priviq.com/legal-copyright-policy.