1. Parties and Acceptance
These Terms of Service are between:
- Provider: Deliri Software Inc., operating as Off Grid Software, with offices at 40 Frank Faubert Drive, Scarborough, Ontario, M1C 5H7, Canada ("Off Grid Software", "Provider", "we", "us", or "our").
- Client: the person, company, organization, or other legal entity that accesses, purchases, subscribes to, downloads, installs, or uses the Services or Products ("Client", "Customer", "you", or "your").
If you access, purchase, subscribe to, download, install, or use the Services or Products on behalf of a company, organization, or other legal entity, you represent that you have authority to bind that entity to these Terms. In that case, "Client", "Customer", "you", and "your" refer to that entity. If you do not have that authority, you must not accept these Terms or use the Services or Products on behalf of that entity.
Provider and Client may each be called a "Party" and together the "Parties".
Off Grid Software is a brand, trade name, product name, or public-facing business name of Deliri Software Inc. Unless a signed Order expressly states otherwise, Deliri Software Inc. is the legal contracting entity, owner of Provider rights, payee of Provider invoices, and party entitled to enforce this Agreement. Use of a brand, product name, website name, statement descriptor, support name, email domain, invoice memo, legacy name, or marketing name does not create a separate contracting party and does not change the Parties' rights or obligations.
These Terms apply to all access to and use of the Off Grid Properties and to Provider websites, downloadable binaries, software products, hosted services, statements of work, proposals, order forms, product subscriptions, license keys, invoices, support plans, hosting plans, maintenance plans, renewals, and change orders accepted by Client, unless a later written agreement signed by Provider expressly states that it overrides these Terms.
2. Business-to-Business Use Only
The Services and Products are offered only for business, professional, internal operational, software development, audit preparation, and commercial use. They are not offered to consumers for personal, family, or household use. Client represents that it is entering into these Terms for business purposes and has authority to bind the business or organization on whose behalf it uses the Services or Products.
Any individual who accepts these Terms, creates an account, or uses the Services or Products on behalf of Client must be at least eighteen years old or the age of majority in that individual's jurisdiction, whichever is higher.
Client represents that it is not buying or using the Services or Products as a consumer under Quebec, Ontario, Canadian, U.S., or other consumer-protection law. If Client is located in Quebec or serves Quebec users, Client remains responsible for Quebec laws that apply to Client's own business, customers, employees, language obligations, consumer relationships, privacy obligations, tax obligations, marketing, and use of the Services or Products.
To the maximum extent permitted by law, Client agrees that these Terms are governed by Ontario law, disputes must be handled in Ontario under these Terms, and Client will not bring claims against Provider in Quebec or any other province, state, or country outside the Ontario forum stated in these Terms. Any mandatory non-waivable law applies only to the minimum extent required and does not change the Parties' chosen law, forum, arbitration agreement, liability limits, payment obligations, or other terms to the extent those terms can still be enforced.
Before purchasing, subscribing to, or activating a Product, and when creating an account, Client must confirm that it is acquiring and using the Services and Products for business or professional purposes and not as a consumer, and must provide the name of the business or organization on whose behalf it is acting. Provider relies on that confirmation. Provider does not knowingly sell to consumers and may refuse, cancel, suspend, or refund any purchase, account, or subscription that Provider reasonably determines is being acquired or used for personal, family, or household purposes.
2A. Access to and Use of the Off Grid Properties
These Terms govern all access to and use of the Off Grid Properties, whether by a visitor, prospective customer, Client, authorized user, account holder, developer, or agent, and whether or not that person purchases, subscribes to, or pays for anything. By accessing, browsing, creating an account on, signing in to, calling an API of, downloading from, or otherwise using any Off Grid Property, you accept these Terms.
The Off Grid Properties, including the marketing website, marketing sites, landing pages, product and pricing pages, documentation, the web application, account and administrative dashboards, sign-in and sign-up flows, and the public and licensing APIs, are offered for business, professional, and evaluation use and are provided on an "as is" and "as available" basis as described in Section 37. Provider may add, change, limit, suspend, deprecate, or discontinue any Off Grid Property, feature, page, endpoint, or API as described in Section 35B.
Access to and use of the Off Grid Properties is subject to the acceptable use, abuse monitoring, and emergency suspension rules in Section 30A. You must not probe, scan, scrape, overload, disrupt, reverse engineer, or attempt unauthorized access to any Off Grid Property, and you are responsible for all activity under any account, credential, API key, or token issued to you, as described in Sections 7, 30, and 30A. The product-specific terms for bug and witness in Sections 8 and 9, and the marketing and performance-claim limits in Section 5A, apply to the corresponding Off Grid Properties.
2B. Language and Quebec Customers
The Services, Products, Off Grid Properties, this Agreement, each Order, and all related notices, invoices, and communications are provided in English only. The Parties have expressly requested that this Agreement and all documents relating to it be drawn up in English. Les parties ont expressément demandé que cette convention et tous les documents qui s'y rattachent soient rédigés en anglais.
Off Grid Software does not offer the Services or Products in French and does not knowingly market, sell, or provide them to a person acquiring or using them as a consumer, or in a transaction that would require a French-language contract or French-language dealings under Quebec law. Client represents that it is not such a person and is not contracting as a Quebec consumer. If Client requires documents or dealings in French, Provider may decline the transaction.
3. Definitions
"Agreement" means these Terms of Service and all attached or incorporated schedules, statements of work, order forms, invoices, product terms, and change orders.
"Deliverables" means websites, applications, APIs, documentation, configuration, code, designs, reports, test artifacts, evidence packages, integrations, product outputs, or other materials that Provider agrees to deliver under an Order.
"Order" means a signed statement of work, accepted proposal, signed quote, online checkout, license purchase, invoice, subscription order, change order, or other written commercial order accepted by Provider.
"Products" means Provider's proprietary software products, including bug, witness, related CLIs, agents, hosted services, APIs, documentation, templates, workflows, and other commercial software made available by Provider.
"Off Grid Properties" means Provider's own public and operated web properties and interfaces, including the Off Grid Software marketing website, marketing sites, landing pages, product and pricing pages, documentation pages, the web application, account and administrative dashboards, sign-in and sign-up flows, the public and licensing APIs, and the downloadable bug and witness products, together with the related pages, endpoints, and services operated by Provider.
"Services" means professional services provided by Provider, including website development, application development, API development, consulting, implementation, testing, support, maintenance, hosting management, compliance evidence implementation, product onboarding, and training.
"Client Materials" means content, data, source code, repositories, test suites, configuration, credentials, policies, procedures, designs, trademarks, business rules, records, regulated data, and other materials provided or controlled by Client.
"Provider Background IP" means all technology, software, source code, object code, scripts, libraries, frameworks, templates, processes, know-how, methodologies, products, product roadmaps, designs, tools, agents, testing systems, compliance evidence systems, bug, witness, general-purpose components, and reusable work product owned, developed, licensed, or used by Provider before, during, or after an Order, excluding Client Materials and Client-owned custom Deliverables expressly assigned under this Agreement.
"Confidential Information" means non-public business, technical, security, financial, legal, customer, source code, product, pricing, credential, audit, compliance, roadmap, or operational information disclosed by one Party to the other, whether orally, visually, electronically, or in writing.
"Regulated Data" means personal information, personal data, protected health information, payment card data, financial records, government controlled information, export-controlled information, credentials, secrets, or any other data subject to special legal, regulatory, contractual, or industry restrictions.
4. Order of Precedence
If documents conflict, the following order controls:
- A signed amendment that expressly names the clause it overrides.
- A signed Order or statement of work.
- Product-specific terms in this Agreement.
- This Agreement.
- Documentation, proposals, website copy, marketing materials, ticket comments, emails, and informal messages.
No marketing page, sales discussion, roadmap statement, demo, estimate, or informal communication creates a warranty, guarantee, service level, legal commitment, certification promise, or acceptance obligation unless it is expressly included in a signed Order.
5. Scope of Services
Provider may provide Services including the canonical Off Grid Software website services reflected in `alfred/website/services_gen.go` and `alfred/website/pages.go`:
- Website redesigns.
- Custom websites.
- Landing pages.
- Custom ecommerce stores.
- Web applications.
- API and integrations.
Provider may also provide related Services including:
- Internal tools and operational software.
- API design, development, integration, testing, documentation, and cloud deployment support.
- Checkout, lead capture, booking, CRM, analytics, payment, email, automation, and third-party platform integrations.
- Hosting setup, domain support, SSL/TLS setup, monitoring, support, maintenance, and managed deployment.
- Product implementation, configuration, onboarding, and training for bug and witness.
- Testing systems, evidence generation systems, and audit-readiness implementation.
- Code quality, compiler-driven workflow, agent-readable workflow, and software engineering consulting.
Provider is responsible only for the scope expressly stated in the applicable Order. Anything not expressly included is out of scope.
The Parties acknowledge that Client may describe a business symptom rather than a technical specification. Provider may help diagnose whether the appropriate route is a redesign, website, landing page, ecommerce store, web application, API/integration, Product implementation, or another scoped solution. Diagnosis discussions do not expand scope unless captured in an Order.
5A. Marketing and Performance Claims
Provider's website, proposals, demos, case studies, and sales materials may describe positioning, speed, scale, trust, lead generation, conversion, checkout, reliability, quality, or performance goals. Those statements are commercial descriptions and examples only.
No claim about requests per second, zero errors, uptime, latency, scalability, conversion, checkout performance, search ranking, revenue, security, audit readiness, or business impact is a warranty, guarantee, acceptance criterion, service level, or legal commitment unless the applicable Order states the exact metric, test method, test environment, data set, duration, exclusions, and remedy.
Performance depends on many factors outside Provider's control, including Client Materials, hosting environment, traffic mix, third-party APIs, databases, caches, browsers, devices, payment processors, DNS, networks, integrations, and Client operations.
6. No Informal Scope Expansion
Scope may not be expanded by Slack messages, emails, calls, comments in tickets, pull request comments, verbal statements, screenshots, demos, or assumptions. Out-of-scope work requires a written change order or written approval by Provider stating the scope, fee, and timeline impact.
Provider may choose to perform small out-of-scope items without waiving its right to charge for future out-of-scope work.
7. Client Responsibilities
Client will:
- Provide timely access to systems, repositories, domains, accounts, environments, documentation, personnel, policies, and decision makers.
- Provide accurate Client Materials, requirements, business rules, test data, acceptance criteria, compliance objectives, and legal/compliance assumptions.
- Review Deliverables, product outputs, evidence, reports, recommendations, and notices promptly.
- Maintain appropriate backups of Client systems and data.
- Maintain its own policies, controls, security program, privacy notices, compliance program, audit relationship, and legal obligations.
- Obtain all consents, licenses, approvals, and rights required for Provider to use Client Materials.
- Keep credentials, secrets, tokens, and access controls secure.
- Configure, secure, monitor, and maintain Client systems, repositories, identity providers, cloud accounts, payment accounts, admin accounts, production environments, backups, encryption settings, and access policies unless an Order expressly assigns a specific task to Provider.
- Remain responsible for all activity under Client accounts, API keys, tokens, service accounts, seats, projects, repositories, dashboards, and payment accounts, whether authorized or unauthorized, except to the extent caused by Provider's willful misconduct.
- Tell Provider before providing Regulated Data.
- Avoid using the Services or Products for unlawful, deceptive, abusive, infringing, unsafe, or high-risk purposes.
- Keep billing, legal, technical, security, admin, and notice contacts accurate and current.
- Cooperate with reasonable information requests from Provider, auditors, cloud providers, payment processors, communications providers, regulators, law enforcement, and other infrastructure providers when the request relates to Client's use of the Services or Products.
Client delays, missing information, inaccurate assumptions, account restrictions, unavailable personnel, third-party issues, or late approvals extend timelines and may increase fees.
8. Product-Specific Terms for bug
bug is a software development workflow and proof-of-fix system designed to support high-quality code, agent-readable work, compiler-visible contracts, traceable remediation, and evidence-driven development.
Client acknowledges:
- bug is a development tool and workflow aid, not a guarantee that software is defect-free, secure, compliant, profitable, available, or suitable for any specific production environment.
- bug depends on Client's repositories, commands, tests, configuration, environment, permissions, user inputs, and operational discipline.
- Results, reports, tickets, tests, and evidence produced by bug must be reviewed by qualified humans before reliance.
- Provider does not guarantee that every defect, regression, vulnerability, misconfiguration, legal risk, architectural flaw, or operational risk will be found.
- Client remains responsible for release decisions, production deployment, security review, code review, backups, incident response, and business outcomes.
Unless a signed Order expressly states otherwise, bug is licensed, not sold, and no ownership interest in bug or its source code transfers to Client.
8.1 License Check-Ins and Usage Counters
bug periodically contacts Provider's license service (at most approximately once per 24 hours when the device is online) to renew its license lease. Each check-in transmits only the following:
- the license key identifier and a device identifier and device label for the registered device;
- the bug binary's version and build hash, used to confirm the binary is an unmodified release build;
- a fixed, closed set of per-command usage counters: for each bug command, the number of times it was invoked on that device since the previous check-in, together with the start and end timestamps of that counting window.
Check-ins do not transmit source code, file contents, file paths, repository names or identifiers, command arguments, issue or ticket titles or content, test output, or any other content from Client's repositories or systems. The counter set is fixed in the published wire contract and does not expand silently.
Provider uses check-in data solely for license administration, seat and device fairness, abuse prevention, billing integrity, and aggregate product planning under Section 35A. Check-in data is not sold and is not used to profile individual developers beyond license enforcement.
If a device is offline, bug continues to operate for the remainder of its current lease and any applicable grace period without contacting Provider. Offline enterprise licenses issued for air-gapped environments perform no check-ins and transmit nothing.
9. Product-Specific Terms for witness
witness is a testing, evidence, and audit-readiness support system intended to help companies generate, organize, and validate technical evidence for security, compliance, and certification workflows.
Client acknowledges:
- witness is not a CPA firm, auditor, law firm, compliance certification body, attestation provider, Qualified Security Assessor, penetration testing firm, or regulator.
- Provider does not provide legal, accounting, tax, audit, attestation, certification, regulatory, privacy, security certification, or public accounting advice.
- witness may help prepare evidence for frameworks such as SOC 2, ISO 27001, HIPAA, HITRUST, CMMC, PCI DSS, FedRAMP, GDPR, PIPEDA, or internal vendor reviews, but Provider does not guarantee that Client will obtain, keep, pass, renew, or satisfy any certification, audit, attestation, procurement review, regulator review, customer review, insurance review, or security questionnaire.
- witness outputs depend on Client's controls, policies, procedures, systems, code, tests, logs, personnel, vendors, audit scope, configurations, and evidence accuracy.
- Client and its auditors, lawyers, compliance advisors, security advisors, and management are solely responsible for determining whether evidence is sufficient for any certification, audit, legal obligation, or business purpose.
- witness does not replace independent audit procedures, management assertions, control ownership, legal review, risk assessment, vulnerability management, security monitoring, or incident response.
- Client owns its control design, control operation, control evidence, management assertions, auditor relationship, remediation decisions, vendor questionnaire answers, trust-center publications, and certification scope. No auditor, regulator, customer, insurer, investor, marketplace, or other third party may rely on witness outputs unless Provider signs a separate written reliance agreement.
Unless a signed Order expressly states otherwise, witness is licensed, not sold, and no ownership interest in witness or its source code transfers to Client.
10. No Professional Advice
Provider does not provide legal, accounting, audit, tax, financial, investment, insurance, medical, regulatory, public accounting, or certification-body services. Any templates, controls, tests, reports, policies, checklists, evidence packages, comments, recommendations, or product outputs are technical and operational aids only.
Client must obtain advice from qualified professionals before relying on any Deliverable or Product output for legal compliance, audit certification, regulatory reporting, insurance, securities disclosures, tax filings, privacy compliance, employment matters, health information, financial services, public procurement, or other regulated purposes.
11. No Guarantee of Business, Security, Compliance, or Certification Outcomes
Provider does not guarantee:
- Bug-free, error-free, uninterrupted, secure, vulnerability-free, or incident-free software.
- Specific SEO ranking, ad performance, conversion rate, revenue, fundraising, valuation, customer growth, uptime, latency, scalability, marketplace approval, app-store approval, procurement approval, or business result.
- Compliance with any law, regulation, standard, policy, contract, security framework, certification, audit, attestation, or customer requirement.
- That any website, app, API, Product, report, evidence package, test, recommendation, or workflow will satisfy a third party.
- That any AI, automation, agent, compiler, test, lint, scan, or analysis result is complete, current, or correct.
All warranties are limited to those expressly stated in this Agreement or a signed Order.
12. Project Management and Communications
Provider will use commercially reasonable efforts to communicate project status through the channels and cadence stated in the Order. If no cadence is stated, Provider may choose a reasonable cadence based on project complexity.
Client must identify one authorized decision maker. Provider may rely on instructions, approvals, credentials, access grants, and acceptance from that person unless Client gives Provider written notice of a replacement.
13. Delivery Dates and Dependencies
Delivery dates are estimates unless the Order expressly states that a date is a fixed deadline. Delivery dates depend on timely Client cooperation, third-party availability, payment, stable requirements, and access to required systems.
If Client delays a dependency, requests changes, changes priorities, withholds payment, fails to provide access, or misses an approval deadline, Provider may extend the schedule and charge for idle time, restart time, remobilization, or additional work.
14. Expedited Work
Expedited delivery, rush work, emergency work, after-hours work, weekend work, and priority support are available only if Provider agrees in writing. Expedited work may require additional fees and may require scope reduction, changed milestones, or changed acceptance criteria.
Expedited fees are non-refundable unless a signed Order expressly states otherwise.
15. Change Control
Changes to scope, features, designs, integrations, APIs, data models, hosting, compliance objectives, testing requirements, controls, evidence requirements, security assumptions, or acceptance criteria require written approval by Provider.
Provider may refuse a change request if it creates legal risk, security risk, unreasonable support burden, architectural risk, quality risk, timeline risk, payment risk, or conflict with Provider's standards.
Approved changes may alter price, timeline, dependencies, acceptance criteria, support obligations, and maintenance fees.
16. Revisions
Unless an Order states otherwise, custom Services include two rounds of reasonable revisions limited to the agreed scope. A revision round must be consolidated, specific, and delivered by Client in writing.
Additional revisions, contradictory feedback, late feedback, redesigns, new features, changed business rules, changed copy, changed integrations, changed acceptance criteria, or changes after acceptance are out of scope and billable.
17. Testing and Quality
Provider will use commercially reasonable testing practices appropriate to the Order. Testing may include functional tests, integration tests, user acceptance support, accessibility checks, security-oriented checks, performance checks, linting, static analysis, CI checks, compiler checks, or Product-specific evidence checks.
Testing does not guarantee that all defects, vulnerabilities, regressions, browser issues, device issues, accessibility issues, compliance issues, edge cases, or third-party failures will be found.
Client is responsible for user acceptance testing, business-rule validation, production readiness decisions, and verifying that Deliverables meet Client's operational, legal, compliance, and security needs.
18. Acceptance and Deemed Acceptance
Unless an Order states otherwise, Client has five business days after delivery to accept or reject a Deliverable in writing.
A rejection must identify specific material nonconformities against the signed Order. Provider will use commercially reasonable efforts to correct valid material nonconformities.
A Deliverable is deemed accepted if:
- Client does not provide a valid written rejection within the review period.
- Client uses the Deliverable in production or for business operations.
- Client makes the Deliverable public.
- Client provides approval in writing.
- Client prevents final testing or deployment through delay, withheld access, or missing inputs for more than ten business days after Provider requests them.
Acceptance does not waive unpaid fees, license restrictions, confidentiality obligations, or Provider Background IP rights.
19. Fees
Client will pay the fees stated in the applicable Order or invoice. Fees may include fixed project fees, deposits, milestone fees, hourly fees, subscriptions, license fees, hosting fees, maintenance fees, support fees, domain fees, SSL/TLS fees, usage-based fees, overage fees, third-party expenses, and taxes.
Unless an Order states otherwise:
- Deposits are due before work begins.
- Subscription fees are due in advance.
- Invoices are due on receipt.
- ALL SALES ARE FINAL. No refunds, no credits.
- Fees are non-refundable once paid.
- Taxes, duties, withholding, bank fees, chargeback fees, and currency conversion fees are Client's responsibility.
- Client may not withhold, offset, or reduce payment because of unrelated disputes.
- Usage measurements, seat counts, quota consumption, license activations, storage use, API calls, overages, and other Product billing calculations are determined by Provider's records unless Client shows a manifest calculation error.
- Minimum commitments, prepaid subscriptions, license terms, reserved capacity, discounted packages, and accepted Orders are non-cancellable and non-refundable except to the extent a signed Order expressly states otherwise.
- Any invoice dispute must be raised in writing within thirty days after the invoice date, with reasonable detail. Client must timely pay all undisputed amounts while the dispute is reviewed.
20. Deposits, Milestones, and Non-Refundable Fees
Deposits reserve Provider capacity and are non-refundable. Milestone payments become due when the milestone is reached, whether or not Client has completed its internal review, unless Provider is the sole cause of the missed milestone.
Fees for completed work, accepted work, Product subscriptions, license keys, setup, onboarding, training, rush work, third-party services, domain purchases, SSL/TLS certificates, cloud services, hosting, maintenance, support retainers, and expenses are non-refundable to the maximum extent permitted by law.
If Client cancels or pauses work, Client remains responsible for work performed, committed costs, non-cancellable expenses, approved third-party costs, unpaid subscriptions, and any applicable kill fee.
21. Late Payment, Suspension, and Collection
Amounts not paid when due may accrue interest at the lesser of 2% per month, 24% per year, or the maximum rate permitted by applicable law, calculated from the due date until paid.
If payment is late, Provider may suspend Services, Products, hosting, support, maintenance, license access, deployments, deliverables, domain management, or account access until all overdue amounts are paid. Provider is not liable for losses arising from a suspension caused by nonpayment.
If recurring fees for website hosting, email services, witness, bug, Product subscriptions, maintenance, support, or other recurring services remain unpaid for forty-five days after the due date, Provider may disconnect, disable, suspend, or terminate the affected services. Reconnection is at Provider's discretion and requires payment of all overdue amounts plus a CAD $100 reactivation fee unless an Order states a higher reactivation fee.
Client will reimburse Provider for reasonable collection costs, chargeback costs, bank fees, legal fees, arbitration fees, court fees, and enforcement costs incurred in collecting overdue amounts.
21A. Payment Processors, Chargebacks, and Merchant Risk
If Services or Products integrate with Stripe, Shopify Payments, PayPal, banks, card networks, merchant acquirers, app marketplaces, or other payment processors, Client remains responsible for processor account approval, know-your-customer checks, prohibited or restricted business rules, payment method rules, reserves, holds, refunds, reversals, disputes, chargebacks, fraud, fulfillment, taxes, customer claims, and processor suspension or termination.
Provider is not liable for payment processor decisions, payment holds, declined transactions, account freezes, reserve requirements, processor underwriting, network fines, customer disputes, chargebacks, tax reporting, settlement delays, or lost revenue caused by payment infrastructure unless a signed Order expressly assigns that risk to Provider.
If Client or Client's bank, card issuer, payment provider, representative, employee, contractor, or agent reports, disputes, reverses, claws back, reclaims, charges back, or flags a valid payment as fraudulent, suspicious, unauthorized, mistaken, duplicate, defective, or otherwise improper, Client must promptly reimburse Provider for the full invoiced amount, the full amount reclaimed, held, deducted, reserved, debited, or withheld by any bank, card issuer, payment provider, processor, or marketplace, all Stripe or other payment processor fees, the original payment processor fee, any lost non-refundable processing percentage, chargeback fee, dispute fee, retrieval fee, investigation fee, bank fee, reserve fee, currency-conversion cost, collection cost, legal fee, and reasonable administrative cost incurred by Provider.
Client must also pay Provider for owner, employee, contractor, and advisor time spent investigating, responding to, documenting, disputing, reversing, reconciling, collecting, or remediating the payment report, dispute, reversal, chargeback, clawback, bank reclaim, Stripe reclaim, processor reclaim, or related account restriction. Unless an Order states a different rate, this time is billed at Provider's then-current hourly rate for professional services. This obligation applies whether the report or reversal is made intentionally, accidentally, automatically, by a bank fraud system, or by a person acting for Client.
If Client believes an invoice or payment is incorrect, Client must first use the invoice-dispute process in this Agreement and must not initiate a chargeback, fraud report, bank reversal, payment-provider dispute, or similar reclaim unless required by law or unless Provider has failed to respond to a proper written invoice dispute within a reasonable time.
21B. witness Evidence Custody, Payment Status, and Export
Unless a signed Order expressly states otherwise, witness evidence custody is an active paid service, not an unconditional storage lease. Bronze, Silver, and Gold retention periods describe the maximum custody period available for eligible sealed evidence while Client's account remains paid, active, and in good standing, or while a separately purchased paid-up archive, legal hold, court order, law, or signed Order requires longer retention.
Provider may configure accepted witness evidence with a default technical retention lock of ninety days. While Client remains paid and in good standing, Provider may extend the scheduled expiry date for eligible retained evidence according to Client's active plan, billing status, and Order. If Client stops paying, cancels, fails payment, reverses payment, or lets the account lapse, Provider has no obligation to extend future retention dates, accept new evidence into custody, or keep making the custody service available except as stated in this section or an Order.
If a payment for witness evidence custody is not paid when due, Client has thirty days to cure the nonpayment. During that cure period, Provider may suspend new evidence intake, support, portal features, exports, and other Product functions, but Provider will not intentionally delete retained witness evidence solely because of that missed payment before the cure period expires.
If the payment remains uncured after the thirty-day cure period, Provider may place the account into an export-only wind-down period for thirty additional days. During the wind-down period, Client may download technically available retained evidence through the available export method, subject to account authentication, security controls, legal restrictions, and payment of any amounts required by the Order. Provider has no obligation during the wind-down period to accept new evidence, extend retention, provide support, perform custom exports, preserve convenience features, or keep nonessential services running.
After the wind-down period expires, unpaid, cancelled, lapsed, or abandoned witness evidence may be treated as expired operational material and may be deleted, allowed to expire, made inaccessible, or otherwise disposed of, including from active systems, indexes, backups, and storage, unless a paid-up archive, legal hold, court order, law, technical retention lock not yet expired, or signed Order requires Provider to keep it. Client is responsible for exporting evidence before the wind-down period ends. Provider is not liable for loss, deletion, expiry, inaccessibility, or non-extension of witness evidence caused by nonpayment, cancellation, lapse, account closure, plan expiry, abandonment, or failure to export during the available period.
22. Taxes and Withholding
Fees are exclusive of applicable taxes unless stated otherwise. Client must pay all HST, GST, PST, QST, sales tax, use tax, VAT, withholding tax, duties, levies, and similar charges arising from the Agreement, except taxes based on Provider's net income.
If Client is required by law to withhold an amount, Client must gross up the payment so Provider receives the full amount invoiced, unless the Parties agree otherwise in writing.
23. Hosting, Domains, SSL/TLS, and Third-Party Platforms
Hosting, domains, SSL/TLS certificates, email, analytics, payment processors, cloud infrastructure, CI systems, source control systems, registrars, marketplaces, and other third-party platforms are subject to third-party terms, fees, availability, security, rate limits, policies, outages, and changes.
Provider is not responsible for third-party outages, policy changes, price changes, security incidents, account suspensions, API changes, domain registry failures, DNS propagation delays, email deliverability failures, marketplace rejections, search engine changes, payment processor holds, or platform conduct outside Provider's control.
Client owns its domain name unless an Order states otherwise. Client must keep registration, billing, access, and ownership information current. If Provider manages a domain, Client must provide timely approvals and payment. Provider is not responsible for domain loss, expiry, suspension, or transfer delay caused by Client delay, inaccurate account information, third-party registrar issues, or nonpayment.
24. Maintenance and Support
Maintenance and support are provided only if included in an Order or active plan. Unless an Order states otherwise:
- Support is provided during Provider's normal business hours.
- Response times are targets, not guaranteed resolution times.
- Support excludes new features, redesigns, third-party outages, emergency response, incident response, security remediation, compliance remediation, data recovery, client-caused issues, custom training, and work outside the supported version.
- Unused support time, maintenance time, retainers, and subscription periods do not roll over.
Provider may refuse support for unpaid accounts, unsupported versions, modified code, insecure configurations, missing access, unlawful use, abusive conduct, or systems outside the agreed support scope.
25. Security
Provider will use commercially reasonable security practices appropriate to the scope and fees of the Order. Security practices may include access controls, least-privilege access, secrets handling, dependency review, secure development practices, logging, or testing as Provider determines appropriate.
No system is perfectly secure. Provider does not guarantee prevention of unauthorized access, data loss, malware, ransomware, credential compromise, supply-chain compromise, third-party breach, insider threat, zero-day exploit, misconfiguration, phishing, denial of service, or vulnerability.
Client is responsible for its own security program, access control, employee training, endpoint security, identity provider, backups, production monitoring, vulnerability management, incident response, legal notices, breach notices, and compliance obligations.
25A. Shared Responsibility for Identity, Access, and Configuration
Security, identity, access control, and configuration are shared-responsibility areas. Unless an Order expressly assigns a specific responsibility to Provider, Client is responsible for identity-provider configuration, SSO, MFA, OAuth apps, API keys, secrets, webhooks, role design, permission assignments, privileged users, employee onboarding and offboarding, service accounts, session settings, password-reset flows, account recovery, access reviews, audit-log review, production authorization logic, and downstream use of Provider deliverables.
Provider may recommend or implement technical controls, but implementation support does not transfer ownership of Client's access governance, account security, or production authorization model unless a signed Order expressly states otherwise.
26. Regulated Data and Data Processing
Client must not provide Regulated Data unless the applicable Order expressly permits it and the Parties have signed any required data processing agreement, business associate agreement, security addendum, or regulated-data addendum.
Client is responsible for determining whether PIPEDA, PHIPA, GDPR, UK GDPR, CCPA/CPRA, HIPAA, GLBA, FERPA, PCI DSS, export controls, data residency rules, breach notification rules, sector-specific laws, or other privacy/security requirements apply to Client Materials or Client's use of the Services or Products.
Client represents that it has all required rights, notices, consents, permissions, lawful bases, contracts, and authorizations for Provider to process Client Materials as necessary to provide the Services and Products.
Provider may process Client Materials to provide, secure, troubleshoot, support, improve, and document the Services and Products, subject to confidentiality obligations and any signed data processing terms.
27. Confidentiality
Each Party will protect the other Party's Confidential Information using reasonable care and at least the same care it uses for its own similar information.
The receiving Party may use Confidential Information only to perform or receive benefits under this Agreement. The receiving Party may disclose Confidential Information to employees, contractors, advisors, auditors, lawyers, accountants, insurers, hosting providers, subprocessors, and financing sources who need to know it and are bound by confidentiality obligations or professional duties.
Confidentiality obligations do not apply to information that:
- Is or becomes public without breach.
- Was already known without confidentiality restriction.
- Is independently developed without use of the disclosing Party's Confidential Information.
- Is received from a third party without known confidentiality breach.
- Must be disclosed by law, subpoena, regulator, court, arbitrator, or stock exchange rule, provided the receiving Party gives notice when legally allowed.
Confidentiality obligations survive for five years after termination. Trade secrets, credentials, source code, security information, audit evidence, and regulated data remain protected for as long as they remain non-public and legally protectable.
28. Client Materials
Client retains ownership of Client Materials. Client grants Provider a non-exclusive, worldwide, royalty-free license to use, copy, modify, process, transmit, host, display, test, and create derivative works from Client Materials as necessary to provide the Services and Products.
Client represents and warrants that Client Materials do not infringe, misappropriate, violate privacy rights, violate publicity rights, violate confidentiality obligations, violate laws, contain unlawful content, contain malicious code, or require Provider to violate third-party terms.
Provider may remove, refuse, or suspend work involving Client Materials that Provider reasonably believes are unlawful, infringing, unsafe, misleading, abusive, security-sensitive beyond the agreed scope, or likely to create liability.
29. Intellectual Property Ownership
Subject to full payment of all amounts due, Client owns custom Deliverables expressly created for Client under a custom Services Order, excluding Provider Background IP, third-party materials, open-source software, Product software, generic components, know-how, templates, methodologies, and tools.
Provider retains all rights, title, and interest in Provider Background IP. No rights transfer by implication, estoppel, access, delivery, payment, or use.
To the extent Provider Background IP is embedded in a custom Deliverable and necessary for Client to use that Deliverable, Provider grants Client a non-exclusive, non-transferable, non-sublicensable, perpetual license to use that embedded Provider Background IP solely as part of the Deliverable for Client's internal business purposes, subject to payment and this Agreement.
Products are licensed, not sold. Client receives only the license rights expressly stated in the applicable Order or Product terms.
30. Product License Restrictions
Unless an Order expressly permits otherwise, Client must not:
- Copy, resell, sublicense, distribute, rent, lease, timeshare, or commercially host the Products for third parties.
- Reverse engineer, decompile, disassemble, scrape, or attempt to derive source code, non-public APIs, models, or internal logic.
- Remove proprietary notices.
- Circumvent license keys, usage limits, metering, access controls, rate limits, or security controls.
- Use Products to build a competing product or service.
- Use Products for unlawful surveillance, credential theft, spam, malware, exploitation, fraud, harassment, deception, or unauthorized testing.
- Use Products in life-safety, weapons, critical infrastructure, emergency services, nuclear, aviation, medical-device, or other high-risk systems where failure could cause death, bodily injury, severe property damage, or severe environmental harm.
- Permit third parties to access Products except authorized users working for Client's internal business purposes.
For clarity, Client may not resell, redistribute, sublicense, rent, lease, lend, host, or otherwise make bug or witness, or access to them, available to any third party, and may not act as a reseller, distributor, or marketplace for bug or witness, unless a signed Order or a separate written reseller agreement with Provider expressly permits it. A bug or witness seat and license are for Client's own internal business use only.
Provider may suspend or terminate access for suspected license breach, security risk, unlawful use, nonpayment, or use that threatens Provider, other customers, or third parties.
30A. Acceptable Use, Abuse Monitoring, and Emergency Suspension
Client and its authorized users must comply with Provider's acceptable use rules, security instructions, documentation, and reasonable operational limits. Provider may investigate suspected abuse, misuse, unlawful activity, security risk, license breach, platform risk, excessive usage, spam, malware, scraping, credential abuse, denial-of-service activity, unauthorized access, or violation of third-party platform rules.
Provider may immediately suspend or restrict any Service, Product, account, domain, integration, API token, deployment, repository access, hosting environment, feature, or user if Provider reasonably believes suspension is needed to protect Provider, Client, other customers, end users, infrastructure, third-party platforms, data, legal compliance, security, reputation, or service integrity.
Provider may remove, disable, quarantine, limit, or refuse content, code, integrations, traffic, accounts, features, or configurations that Provider reasonably believes are unlawful, infringing, abusive, unsafe, misleading, security-sensitive, technically harmful, or likely to create liability. Provider is not liable for losses arising from good-faith suspension, restriction, removal, investigation, or refusal under this section.
Client is responsible for all activity under Client accounts, credentials, tokens, domains, repositories, payment methods, users, administrators, and environments, whether or not Client authorized or knew about the activity, except to the extent caused by Provider's willful misconduct.
30B. Reverse Engineering and Technological Protection Measures
The bug and witness binaries, together with their license keys, signatures, license leases, activation checks, metering, and update mechanisms, are technological protection measures that control access to and use of Provider's proprietary software. Except to the minimum extent a non-waivable law expressly permits, Client and its users must not reverse engineer, decompile, disassemble, deobfuscate, or otherwise attempt to derive the source code, internal logic, non-public interfaces, or cryptographic material of any bug, witness, or other Provider binary, and must not circumvent, disable, bypass, or tamper with any license key, signature, license lease, activation check, metering, or other technological protection measure.
These restrictions are contractual and are also protected by law, including the technological protection measure provisions of the Copyright Act (Canada) and, for United States users, the anti-circumvention provisions of the Digital Millennium Copyright Act. Nothing in this section prevents Client from exercising a right that cannot be waived by contract, such as a statutory interoperability, repair, maintenance, or security-research exception, strictly to the extent that right applies and cannot lawfully be excluded.
31. Open Source and Third-Party Materials
Deliverables and Products may include open-source software or third-party materials. Those materials are governed by their own licenses and terms. Nothing in this Agreement limits rights Client may have under applicable open-source licenses.
Provider is not responsible for Client's failure to comply with third-party licenses, third-party platform terms, export restrictions, attribution requirements, or procurement requirements unless a signed Order expressly assigns that responsibility to Provider.
32. Feedback
Client may provide ideas, suggestions, bug reports, feature requests, workflows, tests, evidence formats, or other feedback. Provider may use feedback without restriction, payment, attribution, or obligation, provided Provider does not disclose Client Confidential Information in violation of this Agreement.
33. Portfolio and Publicity
Provider may identify Client as a customer and may display non-confidential project summaries, screenshots, names, logos, links, and case studies in Provider's portfolio, website, sales materials, proposals, and investor materials unless Client opts out in writing before publication.
Provider will not knowingly publish Client Confidential Information, security-sensitive implementation details, non-public audit evidence, credentials, private repositories, or regulated data.
34. Marketing, Email, and Communications Compliance
If Provider builds or supports marketing websites, email flows, lead capture, analytics, advertising, SMS, newsletters, or outreach tooling, Client remains responsible for compliance with applicable marketing, privacy, anti-spam, consumer protection, platform, and advertising laws, including CASL in Canada and CAN-SPAM in the United States.
Client is responsible for consent records, unsubscribe handling, lawful contact lists, truthful claims, privacy notices, cookie notices, advertising substantiation, accessibility obligations, and sector-specific marketing restrictions unless an Order expressly states otherwise.
34A. Client Sites, Storefronts, End Users, and Customer Policies
If Provider builds, hosts, supports, integrates, or supplies tooling for any Client website, application, ecommerce store, booking flow, subscription flow, member area, payment flow, community, form, portal, API, or public-facing workflow, Client remains solely responsible for Client's customers, visitors, users, members, buyers, subscribers, vendors, contractors, and other end users.
Client is solely responsible for products and services sold or promoted through Client systems, product claims, pricing, taxes, duties, shipping, fulfillment, refunds, returns, warranties, chargebacks, customer support, consumer notices, age gates, accessibility, marketplace rules, payment processor rules, professional licensing, regulated goods, and industry-specific restrictions.
Client must publish and maintain legally adequate terms of service, privacy policy, refund policy, cookie notice, accessibility notice, customer support process, and any other notices required for Client's business, industry, customers, geography, data, and sales model unless an Order expressly assigns drafting responsibility to Provider.
Provider does not provide legal advice to Client or Client end users and is not responsible for claims by, on behalf of, or against Client end users, including claims relating to Client's products, services, sites, stores, content, data collection, cookies, pixels, payments, refunds, taxes, fulfillment, or customer support.
34B. Pixels, Cookies, Analytics, Tracking, and Customer Consent
Client is responsible for obtaining and recording all required consents and providing all required notices for cookies, pixels, analytics, session replay, advertising tags, conversion APIs, email tracking, SMS tracking, CRM tracking, payment tracking, and similar technologies used on or through Client systems.
Provider may implement tracking, analytics, consent, or privacy tooling only as a technical service. Provider does not warrant that any banner, policy, preference center, tag manager, consent mode, analytics configuration, or tracking setup satisfies any law or platform rule unless a signed Order expressly states the exact legal standard and acceptance criteria.
34C. Off Grid Software Electronic Messages and Software Installation
Client consents to receive transactional, administrative, security, billing, support, and service electronic messages from Provider in connection with the Services, Products, and Off Grid Properties. Provider may also send commercial electronic messages, such as product news and offers, and will identify itself, identify on whose behalf each message is sent where applicable, and provide a working unsubscribe mechanism in each such message, consistent with Canada's anti-spam legislation. Client may withdraw consent to commercial electronic messages at any time using that mechanism, without affecting transactional or service messages Provider needs to send.
By downloading, installing, activating, or updating bug, witness, or any Off Grid Software binary, agent, or update, Client consents to that installation and to the periodic updates and license check-ins described in the applicable Product terms and the Privacy Policy. Client is responsible for obtaining any consent its own users, employees, or contractors require before Client installs a Provider binary on their devices.
35. Artificial Intelligence, Agents, and Automation
Provider may use software agents, automation, AI-assisted tools, compilers, test runners, linters, static analysis tools, code generators, documentation generators, or other tools to provide Services and Products.
Client acknowledges that agentic and automated outputs may be incomplete, outdated, wrong, insecure, non-compliant, or unsuitable without human review. Provider does not guarantee that AI-assisted or agentic outputs will be correct, complete, non-infringing, secure, or compliant.
Client must review all generated code, tests, evidence, policies, reports, and recommendations before relying on them.
35A. Usage Data, Telemetry, Aggregated Data, and Public Fields
Provider may collect and use technical, diagnostic, security, usage, performance, billing, abuse-prevention, and operational data about the Services and Products to provide, secure, debug, support, bill, improve, and plan the Services and Products.
Provider may create and use aggregated, de-identified, anonymized, or statistical data derived from use of the Services and Products for analytics, benchmarking, security, product improvement, planning, and marketing, provided it does not identify Client or disclose Client Confidential Information.
Client must not place secrets, credentials, tokens, private keys, personal information, regulated data, sensitive security details, or confidential information in public fields, account names, project names, repository names, branch names, commit messages, ticket titles, URLs, DNS records, metadata, logs intended for public sharing, or support channels not designated for confidential exchange. Provider is not responsible for exposure caused by Client placing sensitive information in public, shared, or unsupported fields.
Unless an Order expressly permits otherwise, Provider will not train public AI models on Client Confidential Information. Provider may use Client feedback, de-identified usage patterns, telemetry, and non-confidential suggestions to improve Provider products and services, subject to this Agreement.
35B. APIs, Quotas, Feature Changes, Benchmarking, and Service Evolution
Provider may set and enforce quotas, rate limits, storage limits, seat limits, usage limits, fair-use limits, API limits, file-size limits, build limits, retention limits, and other technical or commercial controls. Usage above included limits may be billed as overage, throttled, rejected, queued, or require an upgraded plan.
Provider may modify, discontinue, suspend, replace, deprecate, or make backwards-incompatible changes to features, APIs, integrations, models, agents, templates, documentation, SDKs, CLIs, hosting configurations, or third-party dependencies when Provider reasonably determines the change is needed for security, legal compliance, service integrity, product improvement, commercial feasibility, vendor change, third-party platform change, or technical maintenance.
Provider will use commercially reasonable efforts to avoid unnecessary disruption to generally available paid features, but Client acknowledges that security, law, vendor change, abuse prevention, infrastructure integrity, and commercial feasibility may require changes with limited or no advance notice.
Client may not publicly disclose performance tests, benchmark results, security test results, vulnerability details, availability measurements, competitive comparisons, or technical reviews of Products or hosted Services without Provider's prior written consent, except where prohibited by law. This does not restrict Client from making confidential disclosures to its lawyers, auditors, regulators, insurers, investors, or security advisors under appropriate confidentiality obligations.
35C. AI Output, Similarity, Accuracy, and Human Review
AI, agentic, or automated outputs may be inaccurate, incomplete, misleading, outdated, biased, unsafe, non-unique, non-copyrightable, or similar to outputs generated for others. Client must independently review outputs before using them in production, audits, legal positions, customer communications, marketing campaigns, regulated decisions, or security decisions.
Client is responsible for notices, disclosures, human review, end-user instructions, and independent verification needed for Client's use case. Client must not submit health information, payment card data, government identifiers, children's data, export-controlled data, or other regulated data to AI or automation features unless the applicable Order and required addendum expressly permit it.
Client may not use Products or outputs to train competing foundation models, reverse engineer model behavior, extract hidden system prompts, bypass safety systems, or violate third-party AI, API, or platform terms.
35D. Logs, Telemetry, Error Reports, and Sensitive Data
Unless an Order expressly permits otherwise, Client must not place sensitive personal information, PHI, payment card data, financial account numbers, government identifiers, trade secrets, production secrets, private keys, access tokens, customer passwords, or regulated data in logs, traces, crash reports, error messages, support tickets, telemetry fields, analytics events, issue titles, or debugging payloads.
Monitoring, logging, tracing, alerting, evidence collection, linting, scanning, and error-reporting tools are operational aids only. Provider does not guarantee that they will detect, identify, prevent, preserve, classify, prioritize, or correct every bug, incident, vulnerability, outage, control failure, evidence gap, or compliance issue.
Storage limits, sampling, retention schedules, account downgrades, plan changes, deletions, export limits, and suspension may result in loss of logs, telemetry, evidence, alerts, history, or product data, and Provider is not liable for loss caused by Client configuration, nonpayment, plan limits, or third-party platform limits.
36. Warranty for Custom Services
For custom Services, Provider warrants that it will perform the Services in a professional and workmanlike manner. Client's exclusive remedy for breach of this limited warranty is re-performance of the nonconforming Services or, if Provider determines re-performance is commercially unreasonable, a refund of the fees paid for the specific nonconforming Services.
Client must report warranty claims in writing within thirty days after delivery. The warranty does not apply to issues caused by Client Materials, Client changes, third-party services, unsupported environments, misuse, unauthorized modifications, nonpayment, security incidents outside Provider's control, open-source components, production data, changed requirements, changed laws, changed third-party APIs, or systems outside the agreed scope.
37. Product Warranty Disclaimer
Products, hosted services, license keys, documentation, templates, examples, tests, evidence packages, recommendations, reports, APIs, integrations, and beta features are provided "as is" and "as available" except as expressly stated in an Order.
To the maximum extent permitted by law, Provider disclaims all implied warranties and conditions, including merchantability, fitness for a particular purpose, title, non-infringement, quiet enjoyment, accuracy, availability, security, compatibility, and uninterrupted operation.
38. Beta, Preview, Trial, Free, and Evaluation Features
Beta, preview, trial, experimental, free, evaluation, proof-of-concept, pre-release, early-access, and no-charge features are not part of Provider's generally available paid Services unless a signed Order expressly says otherwise. They may be changed, limited, suspended, removed, deleted, made paid, or discontinued at any time and may never become generally available.
They are provided without warranty, indemnity, support commitment, service level, data retention commitment, availability commitment, security commitment beyond any non-waivable legal duty, or liability to the maximum extent permitted by law.
Client must not use beta, preview, trial, experimental, free, evaluation, proof-of-concept, pre-release, early-access, or no-charge features for production, regulated, mission-critical, audit-critical, security-critical, privacy-critical, or safety-critical purposes. Client must not process personal information, regulated data, payment data, health data, confidential customer data, or audit-critical evidence through those features unless Provider expressly authorizes that use in writing.
Information about non-public features, betas, previews, roadmaps, experiments, and evaluations is Provider Confidential Information unless Provider publicly releases it.
39. Limitation of Liability
To the maximum extent permitted by law, Provider's total aggregate liability arising out of or related to this Agreement, any Order, Services, Products, Deliverables, hosting, maintenance, support, or third-party services will not exceed the fees actually paid by Client to Provider for the specific Order giving rise to the claim during the three months before the event giving rise to liability.
If the claim relates to a one-time custom project, the cap will not exceed the fees actually paid for the specific portion of the custom Services giving rise to the claim.
To the maximum extent permitted by law, Provider will not be liable for indirect, incidental, special, consequential, exemplary, aggravated, punitive, or enhanced damages; lost profits; lost revenue; lost savings; lost business opportunity; lost goodwill; lost data; data restoration costs; business interruption; procurement failure; audit failure; certification failure; regulatory action; customer claim; security incident; or cost of substitute goods or services, even if Provider was advised of the possibility.
The limitations apply regardless of legal theory, including contract, tort, negligence, strict liability, warranty, statute, equity, indemnity, or otherwise.
40. Essential Basis of Bargain
Client agrees that the fees reflect the allocation of risk in this Agreement. Provider would not provide the Services or Products at the stated fees without the warranty disclaimers, liability limits, indemnities, payment obligations, arbitration clause, and scope controls in this Agreement.
41. Client Indemnity
Client will defend, indemnify, and hold harmless Provider and its owners, directors, officers, employees, contractors, agents, affiliates, successors, and assigns from and against all claims, demands, losses, damages, liabilities, penalties, fines, settlements, judgments, costs, and expenses, including reasonable legal fees, arising out of or related to:
- Client Materials.
- Client's products, services, business, customers, users, employees, contractors, vendors, or systems.
- Client's use or misuse of Services, Products, Deliverables, reports, evidence, recommendations, or outputs.
- Client's breach of this Agreement or an Order.
- Client's violation of law, regulation, third-party rights, privacy obligations, security obligations, anti-spam obligations, export controls, platform terms, or industry standards.
- Client's instructions to Provider.
- Client's failure to obtain required consents, permissions, licenses, legal bases, notices, or approvals.
- Client's compliance program, audit, certification, attestation, procurement, or regulator interaction.
- Allegations that Client Materials infringe, misappropriate, defame, violate privacy rights, violate publicity rights, or are unlawful.
- Security incidents, data breaches, credential compromise, or unauthorized access caused by Client systems, Client personnel, Client vendors, Client configurations, Client Materials, or Client instructions.
Provider may participate in the defense with counsel of its choice. Client may not settle a claim in a way that admits fault by Provider, imposes obligations on Provider, restricts Provider's business, or requires payment by Provider without Provider's written consent.
42. Provider IP Indemnity
If a third party claims that a custom Deliverable created by Provider and used as authorized infringes that third party's Canadian or U.S. copyright, Provider will defend Client against that claim and pay final damages awarded or settlements approved by Provider, subject to this Agreement.
Provider has no obligation for claims arising from:
- Client Materials.
- Client instructions.
- Third-party materials.
- Open-source software.
- Products.
- Modified Deliverables.
- Combination with items not provided by Provider.
- Use outside the scope of the Order.
- Continued use after Provider provides a non-infringing alternative or asks Client to stop use.
- Alleged infringement based on business methods, data, content, APIs, compliance frameworks, standards, or general ideas.
Provider may resolve an infringement claim by procuring continued use rights, modifying the Deliverable, replacing the Deliverable, or terminating the affected rights and refunding prepaid unused fees for the affected item. This section states Provider's entire obligation for IP infringement claims.
43. Insurance
Client should maintain insurance appropriate for its business, including cyber liability, technology errors and omissions, commercial general liability, crime/social engineering, data breach, and business interruption coverage.
Provider will maintain insurance only if expressly required by an Order and priced into the engagement.
44. Term and Renewal
This Agreement begins on the effective date of the first Order or acceptance and continues until terminated.
Subscriptions, hosting, maintenance, and support plans renew for successive monthly or annual periods unless either Party gives written non-renewal notice at least thirty days before the renewal date, unless the Order states a different notice period.
Renewal fees may change on notice before renewal. Continued use after renewal or fee change constitutes acceptance.
45. Termination for Convenience
Either Party may terminate a custom Services Order for convenience on thirty days written notice unless the Order states otherwise.
Upon termination for convenience by Client, Client must pay:
- All fees for work performed.
- All accepted or deemed accepted Deliverables.
- All non-refundable fees.
- All committed, non-cancellable, or approved expenses.
- All third-party costs.
- Any unpaid subscription, hosting, maintenance, or support fees through the end of the then-current term.
- A kill fee equal to 50% of the remaining unpaid project fees, unless the Order states a different kill fee.
The Parties agree that the kill fee is a genuine advance estimate of the capacity, scheduling, remobilization, and lost opportunity costs that early termination causes Provider, and is not a penalty.
Provider may withhold incomplete Deliverables, source code, credentials, transfer assistance, and licenses until all amounts due are paid.
46. Termination for Cause
Either Party may terminate an Order or this Agreement if the other Party materially breaches and does not cure within ten business days after written notice.
Provider may terminate or suspend immediately if:
- Client fails to pay when due.
- Client breaches license restrictions.
- Client creates security, legal, reputational, operational, or platform risk.
- Client uses Services or Products unlawfully or abusively.
- Client asks Provider to violate law, third-party terms, professional obligations, security standards, or ethical constraints.
- Client becomes insolvent, bankrupt, dissolved, or unable to pay debts.
Termination does not relieve Client of payment obligations accrued before termination.
47. Effect of Termination
Upon termination:
- Client must stop using Products and Provider Background IP except for licenses that expressly survive.
- Provider may stop Services, support, hosting, maintenance, access, licenses, and deliverables.
- Client must pay all outstanding amounts immediately.
- Each Party must return or destroy Confidential Information upon request, except archival backups, legal records, audit records, and materials required for dispute resolution or compliance.
- Sections intended to survive will survive, including payment, confidentiality, IP, license restrictions, warranty disclaimers, limitations of liability, indemnities, dispute resolution, governing law, and general terms.
48. Data Return and Deletion
Upon written request after termination, Provider will use commercially reasonable efforts to export or return Client data in a reasonable format if technically available and if Client has paid all amounts due.
Provider may delete Client data after termination, non-renewal, account closure, nonpayment, or expiry of retention periods. Provider is not required to retain data unless an Order states otherwise.
Client is responsible for maintaining independent backups. Provider is not liable for lost data unless caused by Provider's willful misconduct and subject to the liability cap.
48A. Legal Orders, Abuse Reports, and Infrastructure Requests
Provider may preserve, access, review, suspend, remove, disclose, or retain Client Materials, account information, logs, billing records, abuse reports, security records, or product data when Provider reasonably believes it is required or permitted by law, court order, subpoena, regulator request, payment processor request, telecommunications provider request, cloud provider request, platform policy, abuse investigation, security investigation, or protection of Provider, Client, users, third parties, or infrastructure.
Where legally permitted and commercially reasonable, Provider will attempt to notify Client of compulsory legal process seeking Client information. Provider may delay or omit notice if prohibited by law, if notice could create security risk, if the request relates to abuse or fraud, or if the request is an emergency.
Client will reimburse Provider for reasonable costs, legal fees, vendor fees, employee time, contractor time, and expenses incurred responding to subpoenas, court orders, law-enforcement requests, regulator requests, payment processor requests, telecommunications provider requests, cloud provider requests, third-party claims, or abuse investigations arising from Client's use of Services or Products.
49. Non-Solicitation
During the term and for twelve months after termination, Client will not knowingly solicit for employment or contract work any employee, contractor, or subcontractor of Provider who was involved in the Services, except through general solicitations not targeted at that person.
If Client breaches this section, Client will pay Provider a placement fee equal to 50% of the person's first-year compensation or contractor fees, as a reasonable estimate of recruitment, replacement, and business disruption costs.
50. Independent Contractor
Provider is an independent contractor. Nothing in this Agreement creates an employment, partnership, joint venture, fiduciary, franchise, agency, trustee, or representative relationship.
Provider controls the manner and means of performing Services, subject to the agreed scope. Provider may use employees, contractors, subcontractors, agents, automation, tools, and third-party providers.
51. Force Majeure
Provider is not liable for delay or failure caused by events beyond its reasonable control, including natural disasters, fire, flood, severe weather, pandemic, epidemic, war, terrorism, civil unrest, labor dispute, government action, court order, power failure, internet failure, cloud provider failure, registrar failure, platform outage, supply-chain issue, third-party API failure, cyberattack, denial-of-service attack, malware, ransomware, vulnerability, or other event beyond Provider's reasonable control.
Payment obligations are not excused by force majeure.
52. Export Controls and Sanctions
Client will comply with applicable export control, sanctions, anti-corruption, anti-bribery, and trade compliance laws. Client will not use Services or Products in embargoed jurisdictions, for prohibited end users, for prohibited end uses, or in violation of sanctions or export restrictions.
Client represents that it is not located in, organized under the laws of, or ordinarily resident in a sanctioned jurisdiction and is not on any restricted party list applicable to Provider.
Client will not use Services or Products in violation of anti-bribery, anti-corruption, procurement-integrity, government-contracting, campaign-finance, lobbying, sanctions, or export laws, including laws applicable to U.S., Canadian, provincial, state, municipal, public-sector, and quasi-government customers.
53. Compliance With Laws
Each Party will comply with laws applicable to its own business and performance under this Agreement.
Client is responsible for laws and obligations applicable to Client's business, industry, data, customers, users, products, services, marketing, employment, regulated activities, audit scope, certification scope, procurement requirements, and use of Deliverables or Products.
Provider is responsible for laws applicable to Provider's business as a technology service provider, subject to Client providing accurate information, lawful instructions, and necessary cooperation.
54. Dispute Resolution
Before arbitration, the Parties will attempt in good faith to resolve disputes through direct executive-level negotiation. A Party must provide written notice describing the dispute and requested resolution. The Parties will meet within ten business days unless they agree otherwise.
If the dispute is not resolved within twenty business days after notice, either Party may start arbitration.
Except for payment collection, injunctive relief, IP misuse, confidentiality breach, security misuse, account suspension, or enforcement of an arbitration award, disputes arising out of or related to this Agreement will be finally resolved by arbitration under the Arbitration Act, 1991 (Ontario), or successor legislation.
The seat of arbitration will be Toronto, Ontario. The arbitration will be conducted in English by one arbitrator. The arbitrator may award damages, costs, legal fees, interest, and equitable relief to the extent permitted by law and this Agreement. The award will be final and binding and may be enforced in any court with jurisdiction.
Either Party may instead bring an individual claim that falls within the monetary jurisdiction of the Ontario Small Claims Court in that court rather than in arbitration. Where a dispute does proceed to arbitration, the Parties intend the process to stay proportionate and accessible: a single arbitrator seated in Toronto may decide a smaller claim on documents and written submissions, and the arbitrator may allocate the arbitrator's fees and the costs of the arbitration between the Parties as the arbitrator considers fair.
For U.S. clients, the Parties intend that any arbitration agreement involving interstate or international commerce also be enforceable under the U.S. Federal Arbitration Act to the extent applicable.
55. Class Action and Jury Trial Waiver
To the maximum extent permitted by law, disputes must be brought only on an individual basis and not as a plaintiff, claimant, class member, or representative in a class, collective, consolidated, mass, private attorney general, or representative proceeding.
To the maximum extent permitted by law, each Party waives the right to a jury trial for disputes arising out of or related to this Agreement.
56. Governing Law and Venue
This Agreement and all Orders are governed by the laws of Ontario and the federal laws of Canada applicable in Ontario, without regard to conflict-of-laws rules.
Subject to the arbitration clause, courts located in Toronto, Ontario will have exclusive jurisdiction for court proceedings arising out of or related to this Agreement. Client consents to personal jurisdiction and venue in those courts. Client waives any objection that Toronto, Ontario is an inconvenient forum.
Client agrees that it will not start, continue, join, or support a court, tribunal, administrative, consumer, class, collective, representative, or other proceeding against Provider in Quebec or any forum outside Toronto, Ontario, except to the extent that a non-waivable law prohibits enforcement of this forum clause. If Client starts a proceeding in another forum, Client must reimburse Provider for reasonable legal fees, travel costs, filing costs, translation costs, administrative costs, and other expenses incurred enforcing this Ontario forum clause, to the maximum extent permitted by law.
No law of Quebec, another Canadian province, a U.S. state, or another country will apply merely because Client is located there, uses the Services or Products there, or serves its own customers there, except to the minimum extent that the law is mandatory and cannot be waived by a business customer.
The United Nations Convention on Contracts for the International Sale of Goods does not apply.
57. Injunctive Relief
Provider may seek immediate injunctive or equitable relief in court for actual or threatened breach involving nonpayment-related suspension, IP misuse, license restrictions, confidentiality, security, credentials, reverse engineering, unlawful use, or harm that may not be adequately remedied by damages.
58. Limitation Period
The Parties agree that this Agreement is a business agreement under the Limitations Act, 2002 (Ontario) and that no Party to it is a consumer. To the maximum extent permitted by law, and except for Provider's claims for unpaid fees, any claim by Client arising out of or related to this Agreement, an Order, the Services, the Products, or the Off Grid Properties must be commenced within one year after the day on which the claim was discovered or ought reasonably to have been discovered. This one-year period applies to every such claim, and the Parties vary and exclude the operation of any other limitation period that would otherwise apply to it, other than the ultimate fifteen-year period in section 15 of the Limitations Act, 2002, which the Parties do not vary.
59. Notices
Notices must be in writing and delivered by personal delivery, courier, registered mail, or email to the addresses stated in the Order or later designated by notice.
Unless an Order states otherwise, notices to Provider must be sent to Deliri Software Inc. at the address stated in Section 1, with a copy by email to the contact address published on the Off Grid Software website. Notices to Client may be sent to the email address associated with Client's account, order, billing contact, or notice contact.
Email notices are effective when sent unless the sender receives an automated bounce-back or delivery failure. Notices for breach, termination, arbitration, or legal claims should also be sent by courier or registered mail when practical.
60. Electronic Signatures and Electronic Records
The Parties consent to electronic signatures, electronic records, electronic notices, online acceptance, click-through acceptance, and electronic contracting where permitted by law.
An electronic signature, typed name, checkbox, online checkout, license activation, invoice payment, continued use, or written approval in an agreed system may evidence acceptance if the surrounding records reasonably identify the accepting Party and accepted terms.
Client is responsible for verifying signer authority, signer identity, internal approval authority, account access, retention of electronic records, and compliance with any law requiring paper records, wet signatures, special consumer disclosures, notarization, witness signatures, or other formalities. Provider does not guarantee that any electronic signature workflow, clickwrap, SMS notice, email notice, or electronic record will satisfy every legal requirement for Client's transaction.
SMS, email, push, webhook, carrier, DNS, registrar, payment, marketplace, and third-party delivery systems are outside Provider's full control. Provider does not guarantee message delivery, timing, carrier acceptance, inbox placement, webhook receipt, marketplace approval, payment settlement, or DNS propagation.
61. Assignment
Client may not assign this Agreement or any Order without Provider's prior written consent.
Provider may assign this Agreement or any Order to an affiliate, successor, purchaser, merger party, acquirer, financing source, or transferee of substantially all relevant assets or business, provided the assignee assumes Provider's obligations.
62. Subcontractors
Provider may use subcontractors, contractors, hosting providers, cloud providers, payment processors, AI tools, development tools, security tools, support tools, and other vendors to perform Services or provide Products.
Provider remains responsible for subcontracted work to the same extent Provider would be responsible if it performed the work directly, subject to this Agreement.
62A. Marketplaces, Resellers, and Third-Party Billing Channels
If Client purchases through a marketplace, reseller, referral partner, procurement portal, app store, cloud marketplace, payment processor, or other third-party billing channel, that third party may impose additional ordering, billing, refund, tax, suspension, renewal, cancellation, marketplace-credit, usage, and procurement terms.
Provider is not responsible for reseller acts or omissions, marketplace approval, marketplace credits, payment processor refunds, marketplace tax calculation, third-party procurement workflows, third-party purchase orders, or third-party billing disputes unless a signed Order expressly states otherwise. If marketplace or reseller terms conflict with this Agreement, counsel should specify the intended order of precedence in the applicable Order.
63. No Third-Party Beneficiaries
This Agreement is for the benefit of Provider and Client only. No customer, user, employee, auditor, regulator, vendor, investor, insurer, certification body, or other third party has rights under this Agreement unless expressly stated in a signed writing.
64. Severability
If any provision is invalid or unenforceable, the remaining provisions remain in effect. The invalid or unenforceable provision will be modified to the minimum extent necessary to make it enforceable while preserving the Parties' intent as much as possible.
65. Waiver
A waiver must be in writing and signed by the waiving Party. Failure to enforce a provision is not a waiver. Waiver of one breach is not waiver of another breach.
66. Entire Agreement
This Agreement and applicable Orders are the entire agreement between the Parties regarding their subject matter and replace all prior or contemporaneous discussions, proposals, emails, quotes, presentations, demos, drafts, negotiations, representations, and understandings.
No purchase order, vendor portal term, security questionnaire term, invoice memo, email footer, or procurement document modifies this Agreement unless Provider signs a written amendment expressly accepting that modification.
67. Amendments
Provider may update online Product terms for future renewals, new Orders, new features, or continued Product use after notice. Material changes will not retroactively reduce Client's rights for a prepaid subscription period unless required by law, security, third-party platform changes, or product integrity.
Signed Orders may be amended only by written agreement of the Parties.
68. Interpretation
Headings are for convenience only. "Including" means "including without limitation." "Written" includes electronic writing. "Days" means calendar days unless stated otherwise. Business days exclude Saturdays, Sundays, Ontario statutory holidays, and Canadian federal statutory holidays.
69. Lawyer Review Checklist
Ask counsel to review and adjust:
- Exact legal name, business number, legal notice address, registered office, trade-name registration, and contracting entity.
- Whether Deliri Software Inc. is the correct contracting corporation and whether Off Grid Software should be registered and used as a trade name, business name, trademark, or product brand.
- Whether invoices, Stripe/customer support information, statement descriptors, email domains, websites, tax records, proposals, and Orders consistently identify Deliri Software Inc. as the legal payee/contracting party while presenting Off Grid Software as the brand.
- Ontario enforceability of liability caps, warranty disclaimers, non-refundable deposits, kill fee, late interest, limitation-period shortening, class waiver, jury waiver, and non-solicit.
- U.S. enforceability for customers in key states, including arbitration, class waiver, jury waiver, governing law, limitation of liability, warranty disclaimers, and tax obligations.
- Whether separate Terms of Service, Privacy Policy, Data Processing Addendum, Acceptable Use Policy, SLA, Security Addendum, and Product License Agreement should be split from this master contract.
- Whether bug and witness need separate on-prem, SaaS, enterprise, evaluation, and reseller terms.
- Whether witness claims need additional disclaimers for SOC 2, ISO 27001, HIPAA, HITRUST, CMMC, PCI DSS, FedRAMP, procurement, cyber insurance, and auditor reliance.
- Whether the forty-five-day recurring-service disconnect right, CAD $100 reactivation fee, and chargeback/fraud-report clawback provisions are enforceable and commercially appropriate in Ontario, Canada, and target U.S. states.
- Whether payment processor, card network, chargeback, reserve, KYC, restricted business, refund, tax-reporting, and ecommerce merchant-risk clauses should be separated into a payment addendum.
- Whether identity-provider, SSO, MFA, admin-user, API-key, webhook, access review, and account-takeover responsibilities should be expanded into a security shared-responsibility exhibit.
- Whether AI-output, output-similarity, non-uniqueness, regulated-data, no-competing-model-training, and human-review clauses need separate Product terms for bug, witness, and services work.
- Whether logs, telemetry, crash reports, support tickets, traces, secrets, PHI, payment card data, and sensitive personal information need a standalone data-handling and support-channel policy.
- Whether legal-order response, abuse-investigation, regulator request, law-enforcement request, and infrastructure-provider request clauses should include a detailed notice and cost-reimbursement schedule.
- Whether electronic signature, clickwrap, SMS/email notice, carrier delivery, webhook delivery, and record-retention language satisfies Ontario, Canadian, and U.S. electronic commerce laws.
- Whether marketplace, reseller, app-store, cloud-marketplace, procurement portal, and third-party billing channel precedence should be handled in a dedicated reseller or marketplace addendum.
- Whether the acceptable use, emergency suspension, abuse monitoring, public benchmarking, beta confidentiality, telemetry, and aggregated-data clauses should be split into separate product terms or an acceptable use policy.
- Whether the customer-site, storefront, end-user, cookie, pixel, refund, tax, and payment-flow clauses should be strengthened for ecommerce and consumer-facing client builds.
- Whether professional-services IP should transfer by assignment or license only.
- Whether source code escrow, repository transfer, moral rights waiver, and contractor assignment language is required.
- Privacy/data processing language for PIPEDA, PHIPA, GDPR, UK GDPR, CCPA/CPRA, HIPAA, GLBA, FERPA, PCI DSS, data residency, breach notification, and subprocessors.
- CASL/CAN-SPAM responsibilities for websites, email flows, newsletters, SMS, lead capture, and CRM integrations.
- Insurance requirements and whether technology E&O/cyber coverage is needed before enterprise sales.
- Whether a separate security exhibit should define access, secrets, logging, vulnerability handling, incident notice, and data deletion.
- Tax collection duties for Canadian provinces, U.S. states, and international sales.
- Whether consumer-protection laws could apply if any customer is not strictly B2B.
70. Source Notes for Lawyer Review
This draft was prepared using protections extracted from the prior Moonlit Studio contract page located at `legal/moonlit_contract_page.html`, including payment, refund, revision, acceptance, IP, domain, hosting, liability, indemnity, termination, force majeure, and Ontario arbitration concepts.
Primary and regulator sources checked on July 4, 2026:
- Ontario Arbitration Act, 1991, SO 1991, c 17, current CanLII consolidation.
- Ontario Business Names Act, RSO 1990, c B.17, current CanLII consolidation.
- Ontario Electronic Commerce Act, 2000, SO 2000, c 17, current CanLII consolidation.
- Ontario Limitations Act, 2002, SO 2002, c 24, Sch B, current CanLII consolidation.
- Quebec Charter of the French Language, CQLR c C-11, current CanLII consolidation.
- Personal Information Protection and Electronic Documents Act, SC 2000, c 5, Department of Justice Canada consolidation.
- Office of the Privacy Commissioner of Canada PIPEDA overview.
- Government of Canada Canada's anti-spam legislation overview.
- U.S. Federal Arbitration Act, 9 U.S.C., Office of the Law Revision Counsel.
- U.S. Federal Trade Commission CAN-SPAM compliance guide for business.
- Official major-platform agreements reviewed for additional protective patterns: Google Cloud Platform Terms of Service and Service Specific Terms, Google Workspace Terms, YouTube Terms of Service, Cloudflare Self-Serve Subscription Agreement, Microsoft Azure Product Terms, Apple Media Services Terms, GitHub Terms of Service, Atlassian Customer Agreement, Squarespace Terms of Service, WordPress.com Terms of Service, Wix Terms of Use, and Shopify Terms of Service.
- Additional official platform agreements checked for edge-case protections: AWS Customer Agreement, Stripe Services Agreement and Prohibited/Restricted Businesses, Twilio Terms of Service, Mailchimp Terms of Use, OpenAI Services Agreement, Anthropic Commercial Terms, Netlify Terms of Use, Sentry Terms, Datadog Terms, DocuSign Terms and Conditions, Vanta Master Subscription Agreement, and Drata Terms.
Acceptance
No handwritten signature is required for these Terms to be binding. Client accepts these Terms by accessing, purchasing, subscribing to, downloading, installing, activating, renewing, paying for, or using the Services or Products, or by accepting an Order, invoice, checkout, quote, or other transaction that references these Terms.