These Terms of Service (the "Terms") govern access to and use of the supply chain risk-assessment platform and related services (the "Service") provided by Proof&Believe LLC, a limited liability company established under the laws of the State of Wyoming, United States, with registered office at 30 N Gould St Ste N, Sheridan, WY 82801, United States ("Provider," "we," "us," "our"). You can contact us at info@proofandtrust.com.
The Service is intended solely for businesses and professional users acting in the course of their trade, business, craft or profession. It is not offered to consumers. By accessing or using the Service, the entity on whose behalf you act ("Customer," "you," "your") accepts these Terms, and you represent that you are authorised to bind that entity. If you do not agree, do not access or use the Service.
We may update these Terms from time to time. We will notify you of material changes by email or in-product at least 30 days before they take effect. Continued use after the effective date constitutes acceptance; if you object, you may terminate under the Term and Termination section.
01Definitions
"Authorised User" means an individual the Customer permits to access the Service under the Customer's account.
"Customer Data" means all data, materials and information the Customer or its Authorised Users submit to the Service, including information about the Customer's suppliers, vendors and other third parties ("Supplier Data").
"Output" means the risk scores, reports, flags, assessments and other results the Service generates from Customer Data.
"Order" means the subscription plan, fees and term agreed via the Service, an order form, or other written agreement.
"DPA" means the Data Processing Agreement referenced in Section 10, which forms part of these Terms.
02The Service
The Service is an automated platform that ingests Customer Data and produces supply chain risk assessments and related Output to support the Customer's own risk-management and regulatory processes, including obligations relating to supply chain security under Directive (EU) 2022/2555 ("NIS2") and its national transpositions.
We grant the Customer a non-exclusive, non-transferable, non-sublicensable right to access and use the Service during the subscription term, solely for the Customer's internal business purposes and in accordance with these Terms and any plan limits in the applicable Order.
The Service is provided as a subscription. We may add, modify or remove features, provided we do not materially degrade the core functionality of a paid plan during its current term.
03Accounts and authorised users
The Customer is responsible for configuring its account, maintaining the confidentiality of credentials, and for all activity occurring under its account and that of its Authorised Users. The Customer must ensure each Authorised User complies with these Terms and must promptly disable access for any user who should no longer have it. The Customer must notify us without undue delay of any suspected unauthorised access.
04Customer obligations and acceptable use
The Customer agrees that it and its Authorised Users will not:
- use the Service unlawfully or in breach of any applicable law or third-party right;
- submit Customer Data the Customer is not entitled to submit, or for which it lacks a lawful basis to share with us for processing;
- attempt to gain unauthorised access to, interfere with, or disrupt the Service or its security features;
- copy, reverse-engineer, decompile or create derivative works of the Service, except to the extent such restriction is prohibited by applicable law;
- use the Service to build a competing product, or to systematically extract its data or models;
- introduce malicious code or use automated means in excess of documented API or plan limits;
- resell, sublicense or make the Service available to third parties except as expressly permitted in an Order.
The Customer is solely responsible for the accuracy, quality and legality of Customer Data and for obtaining any consents or notices required to submit it to the Service.
05Fees, payment and taxes
Fees are set out in the applicable Order and are payable in advance unless stated otherwise. Unless expressly agreed, all fees are non-refundable once the relevant period has begun.
Fees are stated exclusive of VAT, sales tax and other applicable taxes. We are established in the United States. For business customers established in the EU, the supply is generally subject to the reverse-charge mechanism, meaning the Customer self-accounts for VAT in its own jurisdiction; the Customer must provide a valid VAT identification number on request. The Customer is responsible for any sales, use, withholding or similar taxes arising from its use of the Service, other than taxes on our net income. Where we are nonetheless required to collect any tax, it will be added at the applicable rate.
We may change fees with at least 30 days' notice, effective from the start of the next renewal term. Late payments may accrue interest at the statutory rate under Directive 2011/7/EU on combating late payment in commercial transactions, and we may suspend the Service for non-payment in accordance with Section 16.
06Subscription term, renewal and cancellation
Each subscription runs for the term stated in the Order and renews automatically for successive periods of equal length unless either party gives notice of non-renewal at least 30 days before the end of the then-current term. Cancellation takes effect at the end of the current paid term; access continues until then.
07Customer Data and intellectual property
As between the parties, the Customer owns and retains all rights in Customer Data. We claim no ownership over it.
The Customer grants us a limited, worldwide, royalty-free licence to host, process, transmit and display Customer Data solely as necessary to provide and support the Service, to generate Output, and as otherwise instructed by the Customer. We may use aggregated and anonymised data that does not identify the Customer, any individual, or any third party to operate, secure and improve the Service.
If the Customer provides feedback or suggestions, we may use them without restriction or obligation.
08Assessment outputs — no reliance, no advice
This section is important
The Customer acknowledges and agrees that:
- The Service is an automated decision-support tool. Output is generated algorithmically from Customer Data and third-party sources and may contain inaccuracies, omissions or outdated information.
- Output does not constitute legal, regulatory, compliance, financial or professional advice, and does not establish or certify compliance with NIS2 or any other law, standard or framework.
- We do not warrant or guarantee that any supplier is or is not a risk, that any assessment is complete or correct, or that acting on the Output will satisfy the Customer's legal or regulatory obligations.
- The Customer remains solely responsible for its own risk decisions, supplier relationships, and regulatory compliance, and should apply appropriate human review and independent verification before relying on any Output.
Where the Service involves automated processing of personal data that could produce legal or similarly significant effects on an individual, the Customer is responsible for ensuring an appropriate level of human oversight in line with Article 22 GDPR and applicable law.
09Provider intellectual property
We and our licensors own all rights in the Service, including its software, models, algorithms, design, documentation and trademarks. Except for the limited access rights granted in these Terms, no rights are transferred to the Customer.
10Data protection and GDPR
To the extent we process personal data contained in Customer Data on the Customer's behalf, the Customer acts as controller and we act as processor. Such processing is governed by our Data Processing Agreement (DPA), which is incorporated into and forms part of these Terms and reflects the requirements of Article 28 GDPR.
The DPA addresses, among other things, the subject-matter, duration, nature and purpose of processing; our obligation to process only on documented instructions; confidentiality of personnel; security measures (Article 32); engagement of sub-processors (with prior notice and a right to object); assistance with data-subject requests and with the Customer's obligations under Articles 32–36; personal data breach notification without undue delay (which also supports the Customer's incident-handling and reporting duties, including under NIS2); and return or deletion of personal data on termination.
Customer Data is stored and processed on servers located in Frankfurt, Germany, within the EU; we do not host or store Customer Data outside the EEA. Although we are incorporated in the United States, we do not transfer Customer Data to the US for storage or processing. Limited administrative access for maintenance and support may take place from European countries outside the EU; where such a country is not covered by an adequacy decision, that access is subject to the European Commission's Standard Contractual Clauses and supplementary measures following a transfer impact assessment. As the operating entity, we remain potentially subject to lawful access requests under US law in respect of data we control, and will assess and where appropriate challenge any request that conflicts with EU law. Details of hosting and sub-processors are set out in the DPA.
11Confidentiality
Each party may receive confidential information of the other. The receiving party will use it only to perform under these Terms, protect it with at least reasonable care, and not disclose it except to personnel and advisers who need it and are bound by confidentiality obligations. This does not apply to information that is public through no fault of the receiving party, independently developed, or required to be disclosed by law (with notice where lawful). The Customer's Supplier Data and our non-public Service materials are each treated as confidential information.
12Security and availability
We maintain appropriate technical and organisational security measures as described in the DPA. We aim to make the Service available consistently but, unless a separate Service Level Agreement is agreed in an Order, the Service is provided without any committed uptime or availability guarantee. We may perform scheduled and emergency maintenance and will use reasonable efforts to limit disruption.
13Warranties and disclaimer
We warrant that we will provide the Service with reasonable skill and care. Except for this and any warranties that cannot be excluded under applicable law, the Service and all Output are provided "as is" and "as available," and we disclaim all other warranties, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. We do not warrant that the Service will be uninterrupted, error-free, or that Output will meet the Customer's requirements.
14Limitation of liability
Nothing in these Terms limits or excludes either party's liability for death or personal injury caused by negligence, fraud or fraudulent misrepresentation, or any other liability that cannot be limited or excluded under applicable law.
Subject to the above, neither party is liable for indirect, special, incidental, consequential or punitive damages, or for loss of profit, revenue, goodwill, business, or anticipated savings, or for loss of or corruption of data (beyond our obligation to maintain reasonable backups under the DPA), even if advised of the possibility.
Subject to the first paragraph of this Section, each party's total aggregate liability arising out of or in connection with these Terms will not exceed the total fees paid or payable by the Customer in the twelve (12) months preceding the event giving rise to the claim.
15Indemnification
The Customer will indemnify and hold us harmless against third-party claims, losses and reasonable costs (including reasonable legal fees) arising from (a) Customer Data, including any claim that it infringes third-party rights or was submitted without a lawful basis or required consents; (b) the Customer's use of the Service in breach of these Terms or applicable law; or (c) the Customer's reliance on Output contrary to Section 8.
We will defend the Customer against third-party claims that the Service, as provided by us and used in accordance with these Terms, infringes that third party's intellectual property rights, and will indemnify the Customer for amounts finally awarded, provided the Customer promptly notifies us and allows us to control the defence. This does not apply to claims arising from Customer Data or from use of the Service in combination with materials not supplied by us.
16Suspension
We may suspend access, in whole or in part, where (a) payment is overdue and not cured within 14 days of notice; (b) continued use poses a security, legal or operational risk; or (c) the Customer materially breaches Section 4. We will give notice where practicable and restore access promptly once the cause is resolved.
17Term and termination
These Terms apply for as long as the Customer uses the Service. Either party may terminate for the other's material breach not cured within 30 days of written notice, or immediately if the other becomes insolvent or ceases business.
On termination, the Customer's access ends and outstanding fees become due. For a period of 30 days after termination, the Customer may export Customer Data; thereafter we will delete or return it in accordance with the DPA, except where retention is required by law. Sections that by their nature should survive (including 7–11, 13–15, 18, 21 and 22) survive termination.
18Export controls and sanctions
Each party will comply with applicable export control and economic sanctions laws, including those of the United States (including EAR and OFAC sanctions programs) and the European Union. The Customer represents that it is not subject to such sanctions and will not use the Service in violation of them, and that any Supplier Data screening it performs through the Service is for its own lawful compliance purposes.
19Changes to the Service
We may modify, enhance or discontinue features of the Service. If we discontinue a material feature of a paid plan during its term without a substantially equivalent replacement, the Customer's sole remedy is to terminate the affected subscription and receive a pro-rata refund of prepaid fees for the unused period.
20Force majeure
Neither party is liable for failure or delay caused by events beyond its reasonable control, including acts of God, war, civil unrest, labour disputes, failures of utilities or telecommunications, cyber-attacks, or acts of government. Payment obligations are not excused.
21Governing law and jurisdiction
These Terms are governed by the laws of the State of Wyoming, United States, excluding its conflict-of-laws rules and the UN Convention on Contracts for the International Sale of Goods. The parties submit to the exclusive jurisdiction of the state and federal courts located in Wyoming, without prejudice to either party's right to seek interim or injunctive relief in any competent court. Nothing in this Section deprives a business customer of any mandatory protection it has under the law of its place of establishment, and our obligations under the GDPR and the DPA apply regardless of governing law.
22Miscellaneous
These Terms, together with the DPA and any Order, are the entire agreement between the parties and supersede prior discussions. If any provision is held unenforceable, the rest remains in effect. No waiver is effective unless in writing. The Customer may not assign these Terms without our consent; we may assign to an affiliate or in connection with a merger, acquisition or sale of assets. We may engage subcontractors but remain responsible for their performance. Notices must be in writing and sent to the contact addresses on record; electronic communications satisfy any requirement that notices be in writing.