Terms of Service
Retrievy — Unified Security Posture Management Platform
Effective Date: April 15, 2026 Last Updated: April 15, 2026 Version: 1.0
These Terms of Service ("Terms") constitute a legally binding agreement between you ("Customer," "you," or "your") and Retrievy ("Company," "we," "us," or "our"), governing your access to and use of the Retrievy platform and all associated services. By registering for an account, clicking "Get Started," or otherwise accessing or using the Service, you acknowledge that you have read, understood, and agree to be bound by these Terms in their entirety. If you do not agree, you must immediately cease all use of the Service.
Table of Contents
- Definitions
- Eligibility and Account Registration
- Description of the Service
- Subscription Plans, Fees, and Payment
- Acceptable Use Policy
- Customer Data and Data Ownership
- Multi-Tenancy, Data Isolation, and Security Architecture
- Third-Party Integrations and Cloud Providers
- Proprietary Rights and Intellectual Property
- Confidentiality
- Warranties and Disclaimers
- Limitation of Liability
- Indemnification
- Security Findings — Special Disclaimer
- Service Availability and SLA
- Suspension and Termination
- Data Retention and Deletion Upon Termination
- Modifications to the Service and Terms
- Privacy and Data Protection
- Governing Law and Dispute Resolution
- General Provisions
- Contact Information
1. Definitions
For the purposes of these Terms, the following definitions apply:
1.1 "Service" means the Retrievy cloud-based Software-as-a-Service platform, including all features, functionalities, modules, dashboards, APIs, agents, documentation, and related services made available by the Company, including but not limited to:
- CSPM (Cloud Security Posture Management): Automated auditing and continuous monitoring of cloud infrastructure configurations across providers such as Microsoft Azure, Amazon Web Services (AWS), Google Cloud Platform (GCP), and Oracle Cloud Infrastructure (OCI);
- ISPM (Identity Security Posture Management): Security analysis of identity infrastructure, including Microsoft Active Directory (AD) and Microsoft Entra ID (formerly Azure AD);
- SCM (Security Configuration Management): Automated configuration auditing of on-premises and network devices, including FortiGate firewalls and Windows Group Policy Objects (GPOs);
- Hardening Kanban: A workflow management interface for tracking, prioritizing, and managing the remediation lifecycle of security findings;
- Executive Reporting Engine: A module capable of generating formatted PDF reports for compliance, audit, and executive communication purposes;
- X-Ray Modules: Deep-inspection dashboards providing granular visibility into firewall configurations (FortiGate X-Ray) and Group Policy Objects (GPO X-Ray);
- Windows Agent: A lightweight on-premises agent deployed on Customer infrastructure to collect and securely transmit scan data to the Service.
1.2 "Customer" means the individual or legal entity that has registered for and subscribes to the Service under these Terms.
1.3 "Authorized User" means any employee, contractor, consultant, or agent of the Customer who is authorized by the Customer to access and use the Service under the Customer's account.
1.4 "Tenant" means the Customer's isolated logical and physical environment within the Service, including a dedicated database provisioned exclusively for the Customer's data.
1.5 "Customer Data" means all data, files, configurations, security scan results, agent telemetry, findings, exceptions, and other information submitted, uploaded, transmitted, or generated by the Customer or its Authorized Users through the use of the Service, including data processed by the Windows Agent.
1.6 "CIS Benchmarks" means the technical security configuration standards published by the Center for Internet Security (CIS), including but not limited to the CIS Microsoft Azure Foundations Benchmark and the Microsoft Azure Security Benchmark (MASB).
1.7 "Finding" means a security control result — whether a "Pass," "Fail," "Info," "Warning," or "Manual Review" outcome — generated by the Service's scanning engines based on analysis of Customer Data against security frameworks (e.g., CIS, NIST, MITRE ATT&CK).
1.8 "Subscription" means the paid plan under which the Customer has licensed access to the Service for the applicable Subscription Term.
1.9 "Subscription Term" means the duration of the Customer's paid subscription, as set forth in the applicable Order Form or plan selection made during registration.
1.10 "Order Form" means any written, electronic, or other order document that specifies the Subscription plan, pricing, term, and other commercial details agreed upon between the Company and the Customer.
1.11 "Intellectual Property Rights" means all patents, copyrights, trademarks, trade secrets, database rights, know-how, and any other form of intellectual property recognized in any jurisdiction.
1.12 "Documentation" means any user guides, technical specifications, API references, and other materials provided by the Company describing the features and operation of the Service.
1.13 "Confidential Information" has the meaning set forth in Section 10.
2. Eligibility and Account Registration
2.1 Eligibility. The Service is intended for use by organizations and qualified professionals. By registering, you represent and warrant that:
- (a) you are at least eighteen (18) years of age;
- (b) if registering on behalf of a legal entity, you have the full authority to bind that entity to these Terms;
- (c) your use of the Service will not violate any applicable local, state, national, or international law or regulation;
- (d) you are not located in, or a citizen or resident of, any jurisdiction against which the applicable laws prohibit the provision of software services.
2.2 Account Registration. To access the Service, you must create an account by providing accurate, current, and complete registration information. You agree to maintain and promptly update this information to keep it accurate, current, and complete.
2.3 Account Security. You are solely responsible for:
- (a) maintaining the confidentiality of your account credentials;
- (b) all activities that occur under your account;
- (c) immediately notifying the Company at [email protected] of any unauthorized use or breach of your account;
- (d) ensuring that your Authorized Users comply with these Terms.
The Company will not be liable for any loss or damage arising from your failure to maintain the security of your account.
2.4 One Account per Tenant. Each Customer organization is entitled to one primary Tenant. The Company may, at its sole discretion, authorize multi-tenant configurations for consulting firms or managed service providers (MSPs) managing multiple client environments.
3. Description of the Service
3.1 Service Overview. Retrievy is a unified security posture management platform designed to help organizations identify, prioritize, and remediate security misconfigurations across multi-cloud environments, identity systems, and network infrastructure.
3.2 Core Functionality. The Service includes the following primary capabilities, subject to the Customer's applicable Subscription plan:
- (a) Automated Security Scanning: Automated collection and analysis of security scan data across cloud providers, identity systems, and on-premises infrastructure, using Retrievy's proprietary scanning engine and the Retrievy Windows Agent, mapped against industry standard frameworks including CIS, NIST, and MITRE ATT&CK;
- (b) Hardening Kanban Workflow: A Kanban-style board for managing the lifecycle of security remediations, including assignment of tasks, status tracking, and notes;
- (c) Exception Management: A tracked workflow for formally documenting accepted security risks, exception justifications, and review schedules;
- (d) Executive PDF Reporting: Generation of formatted, branded PDF reports suitable for compliance audits, board presentations, and regulatory submissions;
- (e) X-Ray Visualizations: Deep-inspection dashboards for FortiGate firewall configurations and Active Directory Group Policy Objects, including inheritance chain analysis and drift detection;
- (f) GPO Drift Detection: Automated detection and alerting of unauthorized or unexpected changes to Group Policy Object configurations over time;
- (g) Fleet Management Dashboard: Centralized management of all registered infrastructure assets, scanning agents, and cloud accounts;
- (h) Multi-Provider Support: Visibility across Azure, AWS, GCP, OCI, Cloudflare, Microsoft 365, Active Directory, and FortiGate infrastructure.
3.3 No Automated Remediation. The Service provides actionable remediation guidance, remediation playbooks, and workflow management. The Service does not automatically apply changes, configurations, or patches to the Customer's infrastructure. All remediation actions are performed exclusively by the Customer's authorized personnel. The Company bears no responsibility for any changes the Customer elects to make to its own infrastructure based on Service outputs.
3.4 Scan Data Ingestion. The Service is designed to receive scan data through: (a) Retrievy's cloud scanning engine, which processes structured scan output generated within the Customer's own cloud environment; (b) the Retrievy Windows Agent installed on Customer-controlled hosts; and (c) future API integrations as made available by the Company. The Company does not access Customer cloud environments directly and does not store cloud provider credentials.
4. Subscription Plans, Fees, and Payment
4.1 Subscription Plans. The Company offers various Subscription plans with different feature sets, scan limits, user limits, and support levels. Current plan details, including pricing, are available at retrievy.com and may be amended from time to time in accordance with Section 18.
4.2 Free Trial. The Company may offer a limited free trial period at its sole discretion. Upon expiration of the trial period, continued access requires upgrading to a paid Subscription. The Company reserves the right to modify, suspend, or terminate free trial offerings at any time.
4.3 Fees. The Customer agrees to pay all fees associated with the selected Subscription plan as set forth in the Order Form or pricing page at the time of purchase ("Fees"). All Fees are quoted in United States Dollars (USD) unless otherwise specified.
4.4 Payment Terms. Fees for Subscriptions are billed in advance on a monthly or annual basis, depending on the plan selected. Payment must be made via the payment methods accepted by the Company at checkout. All payments are non-refundable except as expressly stated in Section 4.7.
4.5 Taxes. All Fees are exclusive of applicable taxes, levies, or duties imposed by taxing authorities, including value-added tax (VAT), goods and services tax (GST), and withholding taxes. The Customer is solely responsible for payment of all such taxes associated with purchases of the Service, except for taxes on the Company's income.
4.6 Automatic Renewal. Subscriptions automatically renew for successive periods equal to the initial Subscription Term unless the Customer cancels at least thirty (30) days before the renewal date through the account settings panel or by contacting [email protected].
4.7 Refund Policy. Due to the nature of the Service, all Fees paid are non-refundable unless: (a) the Company has materially breached these Terms and failed to cure such breach within thirty (30) days of written notice; or (b) required by applicable law. Any refund claims must be submitted within thirty (30) days of the invoice date.
4.8 Late Payments and Suspension. If any invoice is not paid within fifteen (15) days of the due date, the Company may, without prejudice to its other rights: (a) charge interest on overdue amounts at the rate of one and a half percent (1.5%) per month or the maximum rate permitted by applicable law; (b) suspend the Customer's access to the Service until all outstanding amounts are paid in full.
4.9 Fee Changes. The Company reserves the right to modify Fees at any time. For existing Customers, fee changes will take effect at the start of the next Subscription renewal period, and the Company will provide at least thirty (30) days' prior written notice.
5. Acceptable Use Policy
5.1 Permitted Use. The Customer may access and use the Service solely for its own internal business purposes, including the security analysis of infrastructure assets over which the Customer has lawful authority, ownership, or an explicit legal right to audit.
5.2 Prohibited Conduct. The Customer agrees not to, and shall ensure its Authorized Users do not:
- (a) use the Service to scan, probe, or analyze any systems, networks, or infrastructure for which the Customer lacks explicit written authorization from the lawful owner;
- (b) attempt to circumvent, disable, or interfere with any security features, encryption, or access control mechanisms of the Service;
- (c) reverse engineer, decompile, disassemble, or otherwise attempt to derive the source code, algorithms, or data models underlying the Service;
- (d) copy, reproduce, modify, create derivative works of, sublicense, sell, resell, transfer, assign, or exploit any portion of the Service or its Documentation without express written consent from the Company;
- (e) access or use the Service to build a competing product or service;
- (f) benchmark or publicly disclose the performance characteristics of the Service for competitive purposes without prior written consent;
- (g) use the Service to transmit malware, viruses, or any other malicious code;
- (h) use the Service in violation of any applicable law, regulation, court order, or government directive, including data protection laws and export control regulations;
- (i) impersonate any person or entity or misrepresent an affiliation with any person or entity;
- (j) use automated scraping tools, bots, crawlers, or any other automated means to access the Service in a manner that exceeds normal usage patterns or places undue load on the Service infrastructure;
- (k) share, publish, or distribute any portion of the Service's output — including Findings, dashboards, or reports — in a manner that discloses another organization's security posture without the express consent of the relevant data owner;
- (l) use the Service to engage in whistleblowing or unauthorized disclosure of a third party's security vulnerabilities.
5.3 Compliance with Laws. The Customer is solely responsible for ensuring that its use of the Service complies with all applicable laws and regulations, including cybersecurity laws, privacy laws, and regulations governing penetration testing and vulnerability assessments in the applicable jurisdiction.
6. Customer Data and Data Ownership
6.1 Ownership. As between the Company and the Customer, the Customer retains all right, title, and interest in and to the Customer Data. The Company claims no ownership rights over Customer Data.
6.2 License to Process Customer Data. By submitting Customer Data to the Service, the Customer grants the Company a limited, non-exclusive, worldwide, royalty-free license to access, store, process, display, and use Customer Data solely to the extent necessary to: (a) provide, maintain, and improve the Service; (b) fulfill the Company's obligations under these Terms; and (c) comply with applicable law.
6.3 Prohibition on Use for Training. The Company expressly agrees that Customer Data will not be used to train machine learning models, artificial intelligence systems, or any other algorithm for purposes external to the Customer's own Service instance, without the Customer's prior explicit written consent.
6.4 Prohibition on Cross-Tenant Data Sharing. The Company shall implement and maintain technical and organizational measures to ensure that Customer Data is never shared with, or made accessible to, another Tenant or third party other than as required by applicable law or authorized by the Customer.
6.5 Customer Responsibility for Data Accuracy. The Company is not responsible for the accuracy, legality, or completeness of Customer Data submitted to the Service. The Customer represents and warrants that it has obtained all necessary rights, consents, and permissions to submit such data and that doing so does not violate any third-party rights or applicable law.
6.6 Sensitive Data. The Customer acknowledges that the Service is not designed or intended to store or process data that is subject to heightened regulatory protection, including protected health information (PHI) under HIPAA, payment card data governed by PCI DSS (other than incidental inclusion in scan metadata), or classified government information. The Customer assumes all risk associated with submitting such data to the Service.
7. Multi-Tenancy, Data Isolation, and Security Architecture
7.1 Database-per-Tenant Architecture. The Service operates a multi-tenant architecture in which each Customer Tenant is assigned a dedicated, isolated PostgreSQL database. Customer Data is never stored in a shared database schema and is not commingled with the data of any other Customer.
7.2 Encryption. The Company employs AES-256 encryption for data at rest and TLS 1.2 or higher for data in transit. The Company's encryption practices are subject to change in accordance with evolving industry standards.
7.3 Agent Security. The Windows Agent uses token-based authentication and encrypted communication channels to transmit scan data to the Service. The Customer is responsible for the physical and logical security of systems on which the Windows Agent is installed.
7.4 Customer Responsibility for In-Scope Systems. The Customer is solely responsible for obtaining all necessary authorizations before deploying the Windows Agent on any host system, and for ensuring that its deployment and use complies with all applicable laws, regulations, and internal policies.
7.5 Acknowledgment of Security Limitations. While the Company implements industry-standard security controls, no system is completely secure. The Customer acknowledges that there are inherent risks in transmitting information over the Internet and in cloud-hosted environments, and accepts these risks as a condition of using the Service.
8. Third-Party Integrations and Cloud Providers
8.1 Third-Party Services. The Service may interface with, display data from, or provide integrations to third-party platforms and cloud providers, including but not limited to Microsoft Azure, Amazon Web Services, Google Cloud Platform, Oracle Cloud Infrastructure, Cloudflare, Microsoft 365 / Entra ID, and FortiGate / Fortinet. The Company does not endorse, warrant, or guarantee the availability, accuracy, or security of any such third-party platforms.
8.2 No Credential Storage. The Service is architected so that Customer cloud provider credentials are not persistently stored by the Company. Scan data is generated within the Customer's own cloud environment or on-premises infrastructure and transmitted to the Service as structured output. The Customer is solely responsible for the security of all credentials used within its own environment.
8.3 Customer Responsibility for Third-Party Terms. The Customer is solely responsible for complying with the terms of service, acceptable use policies, and applicable laws governing any third-party platforms it connects to or scans through the Service.
9. Proprietary Rights and Intellectual Property
9.1 Company IP. The Service, including its software, source code, algorithms, scoring engine (including the Retrievy asymptotic-decay scoring model), user interface, design, Documentation, trademarks, trade names, logos, and all derivatives thereof, are and shall remain the exclusive property of the Company and its licensors. Nothing in these Terms transfers any ownership rights in the foregoing to the Customer.
9.2 License Grant. Subject to the Customer's compliance with these Terms and timely payment of Fees, the Company grants the Customer a limited, non-exclusive, non-transferable, non-sublicensable license during the Subscription Term to access and use the Service solely for the Customer's internal business purposes as described herein.
9.3 Feedback. If the Customer or any Authorized User provides suggestions, enhancement requests, recommendations, or other feedback regarding the Service ("Feedback"), the Customer hereby grants the Company a perpetual, irrevocable, royalty-free, worldwide license to use, incorporate, modify, and commercialize such Feedback without restriction. The Company has no obligation to act on any Feedback.
9.4 Reservation of Rights. All rights not expressly granted herein are reserved by the Company. No implied licenses are granted by these Terms.
10. Confidentiality
10.1 Definition. "Confidential Information" means any non-public information disclosed by one party ("Disclosing Party") to the other ("Receiving Party"), whether orally, in writing, or in digital form, that is designated as confidential or that reasonably should be understood to be confidential given the nature of the information and the circumstances of disclosure. The Service, its architecture, algorithms, pricing, and roadmap constitute the Company's Confidential Information. Customer Data constitutes the Customer's Confidential Information.
10.2 Obligations. Each Receiving Party agrees to: (a) hold the Disclosing Party's Confidential Information in strict confidence; (b) use it solely for the purposes contemplated by these Terms; and (c) not disclose it to any third party without the prior written consent of the Disclosing Party, except to its employees, contractors, or advisors who have a need to know and are bound by confidentiality obligations no less protective than those herein.
10.3 Exceptions. The confidentiality obligations under this Section do not apply to information that: (a) is or becomes publicly known without breach of any obligation; (b) was known to the Receiving Party prior to disclosure, as evidenced by written records; (c) is independently developed by the Receiving Party without reference to the Confidential Information; or (d) must be disclosed by law, regulation, or valid court order, provided that the Receiving Party gives the Disclosing Party prompt prior written notice to permit it to seek a protective order, to the extent legally permissible.
10.4 Duration. Confidentiality obligations survive termination or expiration of these Terms for a period of five (5) years.
11. Warranties and Disclaimers
11.1 Company Warranties. The Company warrants that: (a) it has the authority to enter into these Terms; (b) the Service will function in material conformance with the Documentation during the Subscription Term; and (c) it will implement and maintain commercially reasonable technical and organizational security measures.
11.2 Customer Warranties. The Customer warrants that: (a) it has the authority to enter into these Terms; (b) the Customer Data does not infringe any third-party intellectual property rights; (c) it has all necessary authorizations to scan the infrastructure described in its Customer Data; and (d) its use of the Service will comply with all applicable laws and regulations.
11.3 Disclaimer of Warranties.
THE SERVICE IS PROVIDED "AS IS" AND "AS AVAILABLE," WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED. TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, THE COMPANY EXPRESSLY DISCLAIMS ALL WARRANTIES, INCLUDING BUT NOT LIMITED TO: (A) IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT; (B) ANY WARRANTY THAT THE SERVICE WILL BE UNINTERRUPTED, ERROR-FREE, OR FREE OF VIRUSES OR OTHER HARMFUL COMPONENTS; (C) ANY WARRANTY AS TO THE ACCURACY, COMPLETENESS, OR RELIABILITY OF ANY SECURITY FINDINGS OR POSTURE SCORES GENERATED BY THE SERVICE; AND (D) ANY WARRANTY THAT THE SERVICE WILL MEET THE CUSTOMER'S COMPLIANCE OBJECTIVES, AUDIT REQUIREMENTS, OR REGULATORY OBLIGATIONS.
12. Limitation of Liability
12.1 Exclusion of Consequential Damages.
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, IN NO EVENT SHALL THE COMPANY, ITS AFFILIATES, DIRECTORS, OFFICERS, EMPLOYEES, AGENTS, LICENSORS, OR SERVICE PROVIDERS BE LIABLE TO THE CUSTOMER OR ANY THIRD PARTY FOR ANY INDIRECT, INCIDENTAL, CONSEQUENTIAL, SPECIAL, EXEMPLARY, OR PUNITIVE DAMAGES, INCLUDING BUT NOT LIMITED TO LOSS OF PROFITS, LOSS OF REVENUE, LOSS OF DATA, LOSS OF BUSINESS, LOSS OF GOODWILL, OR COST OF SUBSTITUTE SERVICES, EVEN IF THE COMPANY HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES AND REGARDLESS OF THE THEORY OF LIABILITY.
12.2 Cap on Liability.
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, THE COMPANY'S TOTAL CUMULATIVE LIABILITY TO THE CUSTOMER ARISING OUT OF OR RELATED TO THESE TERMS OR THE SERVICE, WHETHER IN CONTRACT, TORT (INCLUDING NEGLIGENCE), STRICT LIABILITY, OR OTHERWISE, SHALL NOT EXCEED THE TOTAL AMOUNT OF FEES ACTUALLY PAID BY THE CUSTOMER TO THE COMPANY IN THE TWELVE (12) MONTH PERIOD IMMEDIATELY PRECEDING THE EVENT GIVING RISE TO THE CLAIM.
12.3 Essential Basis. The parties acknowledge that the limitations of liability in this Section 12 are an essential element of the basis of the bargain between the parties and that the Company would not have entered into these Terms without such limitations.
12.4 Exceptions. Nothing in these Terms shall limit or exclude liability for: (a) death or personal injury caused by negligence; (b) fraud or fraudulent misrepresentation; or (c) any other liability that cannot be limited or excluded under applicable law.
13. Indemnification
13.1 Customer Indemnification. The Customer shall defend, indemnify, and hold harmless the Company and its affiliates, directors, officers, employees, and agents from and against any and all claims, actions, proceedings, losses, damages, liabilities, costs, and expenses (including reasonable attorneys' fees) arising out of or relating to:
- (a) the Customer's use of the Service in violation of these Terms;
- (b) the Customer's Customer Data, including any allegation that Customer Data infringes any third-party intellectual property rights or violates applicable law;
- (c) the Customer's failure to obtain the necessary authorizations to scan or audit any infrastructure;
- (d) any breach by the Customer or its Authorized Users of these Terms; or
- (e) any actions taken by the Customer based on the Findings or output of the Service.
13.2 Company Indemnification. The Company shall defend, indemnify, and hold harmless the Customer from and against any third-party claims alleging that the Service, as provided and used in accordance with these Terms, infringes any third-party copyright, patent, or trademark, except to the extent that such infringement arises from: (a) Customer Data; (b) modifications to the Service made by the Customer; or (c) the Customer's combination of the Service with third-party products not authorized by the Company.
13.3 Indemnification Procedure. The indemnified party must: (a) promptly notify the indemnifying party in writing of any claim; (b) grant the indemnifying party sole control of the defense and settlement (except that the indemnifying party may not settle any claim in a way that imposes liability on or disparages the indemnified party without its prior written consent); and (c) provide reasonable cooperation in the defense at the indemnifying party's expense.
14. Security Findings — Special Disclaimer
14.1 Nature of Security Assessments. The Findings, posture scores, compliance mappings, and remediation guidance generated by the Service are produced by automated analysis of data submitted by the Customer. These outputs represent automated assessments based on known security frameworks at a specific point in time and may not reflect all vulnerabilities, misconfigurations, or risks present in the Customer's environment.
14.2 Not a Guarantee of Security. The Customer expressly acknowledges and agrees that:
- (a) a high posture score or "Pass" result from the Service does not guarantee that the Customer's infrastructure is secure, compliant, or free from vulnerabilities;
- (b) the Service does not replace the need for qualified security professionals, penetration testing, manual security reviews, or compliance audits;
- (c) Findings may be false positives, incomplete, or contextually inaccurate depending on the Customer's specific infrastructure configuration;
- (d) the Company makes no representation that the Service covers all security controls required for any specific regulatory or compliance framework (e.g., ISO 27001, SOC 2, PCI DSS, HIPAA, GDPR);
- (e) the Company is not liable for any security breach, data loss, or regulatory penalty suffered by the Customer, regardless of whether the Service detected or failed to detect the relevant vulnerability.
14.3 Professional Judgment Required. All remediation decisions must be reviewed and approved by qualified security personnel. The Customer assumes all risk associated with remediation actions taken or not taken based on Service output.
15. Service Availability and SLA
15.1 Target Availability. The Company will use commercially reasonable efforts to make the Service available with a monthly uptime of at least 99.5%, excluding Scheduled Maintenance and circumstances beyond the Company's reasonable control.
15.2 Scheduled Maintenance. The Company may periodically take the Service offline for maintenance, updates, or improvements. The Company will provide at least forty-eight (48) hours' advance notice for Scheduled Maintenance where practicable, and will endeavor to conduct such maintenance during off-peak hours.
15.3 Exclusions. Downtime attributable to the following is excluded from uptime calculations: (a) Customer's own infrastructure failures; (b) third-party cloud provider outages; (c) denial-of-service attacks or other malicious acts directed at the Service; (d) Force Majeure Events (as defined in Section 21.5); (e) the Customer's failure to follow the Documentation.
15.4 SLA Remedies. If the Company fails to meet the uptime commitment in Section 15.1 in any given calendar month, the Customer's sole and exclusive remedy shall be a service credit equal to a pro-rated portion of the monthly Subscription Fee for the affected period, applied to a future invoice, provided the Customer submits a written claim within fifteen (15) days of the end of the month in which the outage occurred.
16. Suspension and Termination
16.1 Termination for Convenience. Either party may terminate these Terms upon thirty (30) days' written notice to the other party. If the Customer terminates for convenience, no refund of prepaid Fees will be issued.
16.2 Termination for Cause. Either party may terminate these Terms immediately upon written notice if the other party: (a) materially breaches these Terms and fails to cure such breach within thirty (30) days of receiving written notice specifying the breach; or (b) becomes insolvent, makes an assignment for the benefit of creditors, or becomes subject to bankruptcy, liquidation, or similar proceedings.
16.3 Immediate Suspension. The Company reserves the right to immediately suspend the Customer's access to the Service, without prior notice or liability, if:
- (a) the Customer violates Section 5 (Acceptable Use Policy);
- (b) the Customer's account poses a security risk to the Service or other Customers;
- (c) required to do so by law or a government authority;
- (d) the Customer's payment is more than fifteen (15) days past due.
16.4 Effect of Termination. Upon termination or expiration of these Terms for any reason: (a) all licenses granted herein immediately terminate; (b) the Customer must cease all use of the Service; (c) each party must return or destroy the other party's Confidential Information in its possession; and (d) outstanding payment obligations survive termination.
17. Data Retention and Deletion Upon Termination
17.1 Post-Termination Data Access. Upon termination or expiration of the Subscription Term, the Customer may request an export of its Customer Data within thirty (30) days of termination. The Company will provide the data in a standard, machine-readable format.
17.2 Data Deletion. Following the thirty (30) day export window (or upon the Customer's earlier written request for deletion), the Company will delete the Customer's Tenant database and all associated Customer Data from active systems within thirty (30) days. Backup copies may be retained for up to ninety (90) days following deletion from active systems, after which they will be permanently purged.
17.3 Legal Hold. The Company may retain Customer Data beyond the periods stated above if required to do so by applicable law, regulation, or a valid legal order, in which case the Company will notify the Customer of such requirement to the extent legally permissible.
18. Modifications to the Service and Terms
18.1 Modifications to the Service. The Company reserves the right to modify, update, enhance, deprecate, or discontinue any feature or aspect of the Service at any time. For material changes that adversely affect the Customer's existing use, the Company will provide at least thirty (30) days' prior written notice.
18.2 Modifications to These Terms. The Company may update these Terms from time to time. When material changes are made, the Company will: (a) post the updated Terms at the Service's legal documents page; (b) provide notice to the Customer via the email address associated with the Customer's account; and (c) update the "Last Updated" date at the top of this document.
18.3 Acceptance of Updated Terms. Continued use of the Service after the effective date of updated Terms constitutes the Customer's acceptance of the modifications. If the Customer does not agree to the updated Terms, it must cease using the Service and may terminate its subscription in accordance with Section 16.1.
19. Privacy and Data Protection
19.1 Privacy Policy. The Company's collection, use, and handling of personal data in connection with the Service is governed by the Company's Privacy Policy, available at retrievy.com/privacy-policy, which is incorporated into these Terms by reference.
19.2 Data Processing Agreement. If the Customer's use of the Service involves the processing of personal data subject to the European Union General Data Protection Regulation (GDPR), the UK GDPR, or other applicable data protection legislation, the parties agree to execute a Data Processing Agreement (DPA) upon the Customer's written request. The DPA will govern the processing of such personal data and will be incorporated into these Terms by reference.
19.3 Customer as Controller. For the purposes of data protection laws, the Customer is the data controller for personal data contained in Customer Data, and the Company acts as a data processor. The Customer bears responsibility for the lawfulness of the data submitted to the Service.
19.4 Sub-Processors. The Company may engage sub-processors (e.g., cloud infrastructure providers) to assist in delivering the Service. A current list of sub-processors is available upon written request. The Company shall ensure that all sub-processors are bound by data protection obligations no less protective than those set forth herein.
20. Governing Law and Dispute Resolution
20.1 Governing Law. These Terms shall be governed by and construed in accordance with the laws of the Federative Republic of Brazil, without regard to its conflict of law provisions. If the Customer is located outside Brazil, the parties agree to submit to the exclusive jurisdiction of the courts of Brazil for the resolution of disputes arising out of these Terms, unless otherwise required by applicable law.
20.2 Informal Resolution. Before initiating any formal dispute resolution proceedings, the parties agree to attempt to resolve any dispute, controversy, or claim arising out of or relating to these Terms or the Service in good faith for a period of at least thirty (30) days following written notice from the claiming party describing the dispute in reasonable detail.
20.3 Arbitration. If informal resolution fails, any dispute, controversy, or claim arising out of or in connection with these Terms shall be submitted to binding arbitration in accordance with the Rules of the Brazilian Arbitration Association (or applicable arbitration rules in the Customer's jurisdiction), except that either party may seek injunctive or other equitable relief from a court of competent jurisdiction to prevent irreparable harm pending arbitration.
20.4 Class Action Waiver. TO THE MAXIMUM EXTENT PERMITTED BY LAW, EACH PARTY WAIVES ITS RIGHT TO PARTICIPATE IN A CLASS ACTION LAWSUIT OR CLASS-WIDE ARBITRATION IN CONNECTION WITH ANY CLAIM AGAINST THE OTHER PARTY ARISING UNDER THESE TERMS.
21. General Provisions
21.1 Entire Agreement. These Terms, together with the applicable Order Form, Privacy Policy, DPA (if executed), and any other documents incorporated by reference, constitute the entire agreement between the parties with respect to the subject matter hereof and supersede all prior and contemporaneous agreements, negotiations, representations, and warranties, whether written or oral.
21.2 Severability. If any provision of these Terms is held invalid, illegal, or unenforceable by a court of competent jurisdiction, such provision shall be modified to the minimum extent necessary to make it enforceable, and the remaining provisions shall continue in full force and effect.
21.3 Waiver. No failure or delay by either party in exercising any right or remedy under these Terms shall constitute a waiver of such right or remedy. No single or partial exercise of any right or remedy shall preclude or restrict the further exercise of any such right or remedy.
21.4 Assignment. The Customer may not assign or transfer any of its rights or obligations under these Terms without the prior written consent of the Company. The Company may freely assign these Terms in connection with a merger, acquisition, corporate reorganization, or sale of all or substantially all of its assets. Any attempted assignment in violation of this Section is void.
21.5 Force Majeure. Neither party shall be liable for any failure or delay in performance resulting from causes beyond its reasonable control ("Force Majeure Events"), including acts of God, natural disasters, pandemics, government actions, war, terrorism, civil unrest, cyberattacks by third parties, or widespread Internet disruptions. The affected party must promptly notify the other party and resume performance as soon as practicable.
21.6 Export Compliance. The Customer may not use or export the Service in violation of any applicable export laws or regulations, including the U.S. Export Administration Regulations and applicable sanctions programs.
21.7 Anti-Corruption. Each party agrees to comply with all applicable anti-bribery and anti-corruption laws. Neither party will pay, offer, or accept any bribe, kickback, or improper payment in connection with these Terms or the Service.
21.8 No Agency. Nothing in these Terms creates any agency, partnership, joint venture, or employment relationship between the parties. Neither party has authority to bind the other.
21.9 Notices. All legal notices required or permitted under these Terms must be in writing and delivered: (a) by email with confirmation of receipt to the addresses specified in the Order Form or account settings; or (b) by courier or registered mail. Notices to the Company must be directed to [email protected]. Notices are deemed delivered upon receipt.
21.10 Headings. Section headings are for convenience only and shall not affect the interpretation of these Terms.
22. Contact Information
If you have any questions, concerns, or requests regarding these Terms, please contact us:
| Contact | Details |
|---|---|
| Email (General) | [email protected] |
| Website | retrievy.com |
The Company will endeavor to respond to all legal inquiries within five (5) business days.
These Terms of Service were last reviewed and updated by Retrievy on April 15, 2026.
By using the Retrievy platform, you confirm that you have read, understood, and agree to be bound by these Terms.
© 2026 Retrievy. All rights reserved.