End User Platform Agreement
This End User Platform Agreement outlines the terms and conditions governing your use of the CyberRank SaaS platform and services.
Introduction
CyberRank is a SaaS platform operated by the Independent Information Security Rating Institute Ltd and its sister company IISRI® Global Service Centre Ltd (both as "IISRI®"), providing cybersecurity and privacy ratings along with third-party risk management services (the "Services"). Our platform relies in its basic version exclusively on publicly available data collected and displayed through proprietary technology. We process limited personal data as described in our Privacy Policy and Section 3.6.
The intellectual property in the CyberRank platform and Services (the "CyberRank IP") is owned by Novimix ltd, which licenses IISRI® and IISRI® GSC to use, operate, provide and commercialise the Services. Professional Services are provided by IISRI® and/or IISRI® GSC under separate statements of work or purchase orders.
This End User Agreement outlines the terms and conditions governing your use of CyberRank's services. By purchasing, accessing, or utilizing our services, you agree to comply with the terms set forth in this Agreement. If you register for a free trial, these terms will also apply unless explicitly stated otherwise.
By accepting this Agreement-whether by clicking a confirmation box, using our services, or signing a document or purchase order referencing this Agreement-you acknowledge and accept all included terms. If you lack the authority to accept these terms on behalf of an entity, or if you disagree with any provision, you must not accept this Agreement and may not use the services.
This Agreement is effective from the earlier of:
- (a)The date you accept this Agreement; or
- (b)The date you first access or use the services (the "Effective Date").
This Agreement regulates the terms and conditions for end users (Customers). Specific terms, service scope, and costs for support are detailed in a separate contract for Partners, including resellers and managed security service providers.
1. Definitions
Any entity that directly or indirectly controls, is controlled by, or shares common control with another entity. "Control" means direct or indirect ownership of more than 50% of the voting interest of the subject entity.
This End User SaaS Agreement.
Data privacy and security laws applicable within relevant jurisdictions, including the EU GDPR, the New Zealand Privacy Act (NZPA), the Australian Privacy Act, Indonesia's Personal Data Protection Law (UU PDP, Law No. 27 of 2022), the UK GDPR and Data Protection Act 2018, and the CCPA as amended by the CPRA.
The individual or entity accepting this Agreement.
Data submitted by or for the customer to CyberRank, or collected due to the customer's use of the services, such as ratings, risks, vulnerabilities, usernames, contact details, IP addresses, device identifiers, support requests, billing info, issue remediation and organisational association derived from the email domain used at registration.
Service descriptions and related materials provided by IISRI®, updated periodically.
A purchase order via online subscription, quote, or other formal documentation specifying the services purchased from CyberRank or its resellers.
Any data that identifies or relates to an individual.
CyberRank's official privacy policy, available at CyberRank.ai, subject to updates.
Services acquired through a purchase order, distinct from free trial services.
The online products, features, and functionalities offered by CyberRank.
The duration for which the customer has the right to use the services, as defined in the purchase order, including renewals or extensions.
The immediate restriction of access to services to prevent further use due to a violation of this Agreement.
Any individual authorized by the customer to access and use the services, including employees, consultants, contractors, and agents.
Independent Information Security Rating Institute Ltd and IISRI® Global Service Centre Ltd, together and each individually, as the provider of the Services and party to this Agreement (also "we," "us" or "our"). All acts, obligations, warranties, rights and liabilities of the provider under this Agreement are those of IISRI®.
The CyberRank platform and Services. The CyberRank IP is owned by Novimix and licensed to IISRI®.
Data collected electronically by IISRI® about a Vendor from publicly available sources and processed on behalf of the Customer to assess vendors, including public business information, security ratings, risk indicators, breach information, cloud infrastructure details, data residency information, and identified vulnerabilities.
Aggregated, anonymised reports derived from Customer Services Data or Vendor Services Data that do not identify any individual Customer, User, or Vendor.
Any act or omission by a User or Customer that materially disrupts, degrades, or threatens the integrity, security, or availability of the Services or CyberRank's infrastructure.
Any consulting, implementation, or advisory services provided by IISRI® and/or IISRI® GSC to the Customer under a separate statement of work or purchase order.
Novimix, the owner and licensor of the CyberRank IP.
Novimix, IISRI®, and each of their respective officers, directors and employees.
Valid, current, written authorisation from a Scan Target permitting the relevant scan (including any invasive scan) of that Scan Target's systems or data.
Data identifying credentials (such as email addresses) of a Vendor's or Scan Target's personnel that are already publicly exposed and are surfaced by the Services in truncated form. "Scan Target" means a vendor, partner or other third party whose systems or data are the subject of a scan initiated by the Customer.
2. IISRI® Responsibilities and Support
2.1Service Availability
IISRI® will provide purchased services as outlined in this Agreement and applicable Purchase Orders. Access may be temporarily unavailable due to scheduled maintenance (with advance notice), or external factors beyond IISRI®'s control such as natural disasters, cyberattacks, or third-party service failures.
2.2Security Measures
IISRI® follows industry-standard security protocols and undergoes periodic audits. IISRI® will report any actual or reasonably suspected security breach, personal data breach, or cyber event affecting the Services or data to affected customers without undue delay and in any event within twenty-four (24) hours of discovery. This 24-hour obligation applies in addition to, and does not replace, any regulatory notification timeframe (including any 72-hour requirement under Applicable Data Privacy Laws and the Addenda).
2.3Beta Services
Customers may be invited to test beta services at no charge. These features are not yet fully developed and may be modified or discontinued at IISRI®'s discretion, and are provided without warranties and may be subject to additional terms. Any scanning or invasive functionality made available as a beta service is subject to the same authorisation, consent-attestation and record-keeping requirements as the paid Services under Section 8.4(f). The "as is" basis and any exclusion of warranties or liability for beta services operate only as between IISRI® and the Customer, and do not limit or exclude any obligation owed to any Vendor, Scan Target, other third party, or regulator.
2.4Service Commitment
IISRI® aims for high availability and performance. Interruptions may occur as described in Section 2.1, and IISRI® is not liable for events beyond its reasonable control (see Section 11.9).
2.5Standard Support
IISRI® provides standard "Basic" support with commercially reasonable efforts at no additional charge, via email and online resources during designated support hours.
2.6Premium Support
Customers requiring prioritized support, dedicated account management, or enhanced SLAs may opt for "Pro" and "Enterprise" packages under a separate agreement.
2.7Reseller Support
Where a Customer has been referred by a Reseller, the Reseller is the primary support contact. IISRI® provides second-line technical support to the Reseller, and may assist Customers directly in exceptional circumstances.
Response Time
| Tier | P1 | P2 | P3 | P4 |
|---|---|---|---|---|
| Enterprise | 2h | 6h | 1 day | 2 days |
| Pro | 4h | 8h | 2 days | 4 days |
| Basic | 1 day | 2 days | 4 days | 5+ days |
Resolution Time
| Tier | P1 | P2 | P3 | P4 |
|---|---|---|---|---|
| Enterprise | 8h | 1 day | 3 days | 7 days |
| Pro | 1 day | 2 days | 5 days | 2 weeks |
| Basic | Best effort | Best effort | Backlog | Backlog |
3. Use of Services and Subscription Terms
3.1Free Trial
Customers who register for a free trial or use free features have temporary access at no cost until:
- (a)The trial period ends;
- (b)Free credits are used; or
- (c)The customer subscribes.
If the customer does not subscribe before the trial ends, stored Customer Services Data may be permanently deleted. During the trial, services are provided "as-is" without warranties and IISRI® assumes no liability for loss related to the free trial. Any scanning or invasive functionality used during a free trial is subject to the authorisation and consent requirements of Section 8.4(f), and the "as-is" basis and liability exclusions operate only as between IISRI® and the Customer and do not limit any obligation owed to any third party or regulator.
3.2Subscriptions
Customers use services by expending credits over a one-year subscription. At the end of the period, unused credits may be void without refund; impacted customers are notified 60 days before expiry. If additional credits are purchased during an active term, remaining credits roll over and extend for a further 12 months. The term begins on the purchase-order date and renews automatically for successive terms unless cancelled in accordance with this Agreement.
3.3Usage Limits
Usage is subject to the quantities in applicable purchase orders (Slots or Credits). Purchasing additional credits automatically increases the usage limit for the remainder of the term and beyond, if applicable.
3.4Customer Responsibilities
The customer is responsible for:
- (a)Ensuring Users comply with this Agreement and for all activities through its use of the Services;
- (b)Maintaining the accuracy, legality and validity of Customer Services Data, including obtaining necessary consents or rights;
- (c)Preventing unauthorized access, securing credentials, and promptly notifying IISRI® of any unauthorized access or suspected breach; and
- (d)Complying with the terms of any Non-CyberRank Applications integrated with the Services.
3.5Usage Restrictions
Customers may not:
- (a)Provide access to unauthorized persons;
- (b)Resell, license, sublicense, lease, rent or distribute any portion of the Services, including reports or outputs;
- (c)Transmit illegal, defamatory, infringing or otherwise tortious material;
- (d)Introduce Malicious Code;
- (e)Use the Services unlawfully or for fraudulent or harmful purposes;
- (f)Interfere with or degrade the Services;
- (g)Attempt unauthorized access to the Services or related systems;
- (h)Circumvent usage limits;
- (i)Remove or alter proprietary notices;
- (j)Frame or mirror the Services except for internal business use;
- (k)Develop a competing product or service; or
- (l)Modify, reverse-engineer, disassemble or tamper with the Services or website.
Partners, including managed security service providers, are subject to a separate signed agreement with IISRI® permitting them to resell, license, sublicense or distribute the Services, including reports or outputs.
3.6Privacy
CyberRank's privacy policy is available at CyberRank.ai and is subject to updates. It includes, among others:
- (a)Data Collection - IISRI® may collect personal information in connection with a customer's use of the Services, as detailed in the Privacy Policy;
- (b)Customer Obligations - the customer affirms it has adhered to all Applicable Data Privacy Laws concerning the collection and disclosure of personal information and is not relying on IISRI® to fulfil its compliance obligations; and
- (c)IISRI® Obligations - in relation to the limited personal information received from customers or Users, IISRI® will independently adhere to all applicable legal requirements as a data controller and will not rely on the customer to fulfil its controller obligations.
3.7Service Suspension
Where IISRI® identifies a violation by a User, it may request the customer suspend that User; if the customer does not comply, IISRI® may suspend the User directly until the violation is resolved. In a Disruption Event, IISRI® may impose an automatic suspension limited to the minimum scope and duration necessary. Where suspension occurs without prior notice, IISRI® will explain as soon as reasonably possible on request.
3.8Non-CyberRank Applications
IISRI® and third parties may offer Non-CyberRank Applications and consulting services; interactions with external providers are independent of IISRI®, which neither guarantees nor supports them. The customer is responsible for reviewing any additional terms, and IISRI® is not liable for third-party products, services, websites or content.
3.9Renewal and Cancellation
Customers may cancel by written notice at least 30 days before the renewal date; failure to do so results in automatic renewal.
3.10Modification of Subscription
IISRI® may update offerings, pricing and features at renewal, with 60 days' notice of material changes. For reseller-referred customers, price changes are also subject to the notice and protections in the applicable Reseller Agreement.
3.11Suspension
IISRI® may suspend access for material breach, non-payment (in accordance with Section 4.5), or activities that disrupt CyberRank's infrastructure or security. Termination is governed exclusively by Section 12.
3.12Usage Tracking and Compliance
IISRI® may monitor usage to ensure compliance; on exceedance or misuse it may require additional credits or restrict access in accordance with Section 3.11.
3.13United States Scan Targets and US Personal Data
- (a)Permission by acceptance. By accepting this Agreement, the Customer is permitted to use the Services in respect of Scan Targets domiciled in, or with systems located in, the United States of America, its territories or possessions ("US Scan Targets"), and in respect of personal information of United States residents (including California residents), subject to the Customer's compliance with this Agreement, including the authorisation and consent requirements of Section 8.4(f).
- (b)Assumption of risk. The Customer acknowledges that such use may subject the Customer, and claims arising from it, to the laws and jurisdiction of the United States, and the Customer accepts that risk.
- (c)Indemnity. The Customer shall indemnify and hold harmless the Provider Group against any claim, proceeding, regulatory action, loss, liability, damage, cost or expense (including the costs of defending or responding) brought or arising in, or under the laws of, the United States of America, its territories or possessions, or by or on behalf of any US Scan Target or United States resident, arising out of or in connection with the Customer's use of the Services, including any Scan initiated by the Customer and any collection or processing of US-resident data. This indemnity applies whether or not authorisation was obtained, is additional to Sections 8.2 and 8.4(f) (without duplication of amounts recovered under those Sections), and is carved out of the exclusive remedy and the liability caps, as provided in Section 9.1.
- (d)Downstream (where a contract exists). Where the Customer has a contractual relationship with a US Scan Target, the Customer shall use reasonable endeavours to bind that Scan Target to resolve any claim relating to the Services or CyberRank outside the courts of the United States, and to name IISRI® as a third-party beneficiary of that provision.
- (e)Limits of this Section. The Customer acknowledges that IISRI®'s dispute-resolution mechanism in Section 10.2 and the indemnities in this Agreement bind only the Customer and do not bind any Scan Target, other third party, or regulator.
4. Fees and Payment for Purchased Services
4.1Reseller Purchases
Where the Customer acquires the Services through a Reseller, payment terms are governed by the Customer's separate agreement with the Reseller and prevail only on payment matters. IISRI® may suspend or terminate access if amounts payable to IISRI® are not received when due, including where non-payment results in the Reseller failing to remit. The Reseller agreement governs only pricing and payment mechanics, imposes no obligations on IISRI®, and does not affect other provisions. If no enforceable Reseller agreement exists, this Agreement applies directly. Where referred customers pay IISRI® directly, a separate IISRI®-Reseller agreement governs fees/commissions.
4.2Fees
The Customer must pay all fees in applicable purchase orders. Unless otherwise stated:
- (i)Fees are based on credits purchased, not actual usage;
- (ii)Payment obligations are non-cancelable and fees are non-refundable except as outlined in Section 12; and
- (iii)Purchased credits cannot be reduced during the term.
4.3Invoicing and Payment
Fees are paid in advance via CyberRank's online portal (currently Stripe or PayPal). Where invoiced, charges are due on receipt and payable within thirty (30) days. Overdue amounts accrue interest at 18% per annum or the maximum lawful rate, whichever is lower. The Customer must keep billing and contact information accurate. Third-party processors may receive necessary payment information.
4.4Overdue Charges
If an undisputed invoice is unpaid within thirty (30) days, IISRI® may, without waiving rights:
- (a)Impose shorter payment terms for future renewals or orders; and/or
- (b)Require the Customer to cover reasonable legal or collection costs.
4.5Suspension and Acceleration
If any amount for purchased services is unpaid for thirty (30) days or more, IISRI® may accelerate all unpaid fees and suspend access until paid, giving at least ten (10) days' prior notice before suspension.
4.6Taxes
Fees exclude applicable taxes ("Taxes"). The Customer is responsible for all applicable Taxes. Where IISRI® must collect and remit Taxes, they are invoiced unless a valid exemption is provided. IISRI® remains responsible for taxes on its own income, property and employees.
4.7Future Functionality
Purchases are not contingent on future features or on any statements about potential future enhancements.
5. Proprietary Rights and Licenses
5.1Reservation of Rights
- (a)Except for the limited rights expressly granted, the CyberRank IP is owned by Novimix and licensed to IISRI®, and IISRI® retains all other ownership, title and interest in the Services and associated proprietary materials; the Customer acquires no rights by implication.
- (b)The Customer retains ownership of its Customer Services Data; however, IISRI® may use Customer Services Data (excluding username, password and billing info) to generate Generic Reports and as specified in Section 5.2.
- (c)IISRI® grants the Customer a non-exclusive right to use and publish only its own aggregated security and privacy ratings at its discretion.
5.2IISRI®'s Right to Use Vendor Services Data
Customers acknowledge that IISRI® processes publicly available vendor data under its own legal basis as an independent data controller. Vendor Services Data is the proprietary information of IISRI®, which may process and use it (including ratings) in compliance with applicable laws to:
- (a)Provide the Services, including providing Vendor data to Customers;
- (b)Communicate with vendors or contacts designated by the Customer;
- (c)Identify and resolve service or technical issues;
- (d)As explicitly authorized by the Customer; and
- (e)As required by law.
IISRI® may also use Vendor Services Data in aggregated, anonymized, de-identified form for internal research, benchmarking, analytics and product improvement, provided such use is for administrative purposes and general statistics, does not identify the Customer or individuals, and any public disclosure is limited to overall trends. Vendor-specific findings (including unpatched vulnerabilities and breach details) are shared with Customers solely for their own third-party risk assessments and may not be used for competitive intelligence or disclosed to third parties.
5.2AVendor Services Data - controller basis and safeguards
In respect of Vendor Services Data (including Compromised Credential Data):
- (a)Lawful basis - IISRI® processes the data on the basis of its legitimate interests (and those of its Customers and the public) in assessing and improving information security, which it has assessed as not overridden by the interests or rights of the data subjects, having regard to the security purpose and the minimisation measures below;
- (b)Data minimisation - IISRI® displays Compromised Credential Data in truncated form as a minimisation measure and acknowledges that truncated data may remain Personal Information and treats it accordingly;
- (c)Transparency - IISRI® maintains a public privacy notice describing this processing and, as it has no direct relationship with the affected individuals and individual notification would involve disproportionate effort, relies on the disproportionate-effort exemption from individual notification (Article 14(5)(b) EU/UK GDPR and the equivalent under the New Zealand Privacy Act 2020); and
- (d)Data-subject rights - IISRI® operates a process to receive and respond to access, correction, objection and erasure requests at privacy@iisri.com within applicable statutory timeframes.
5.3Customer's License to Provide Feedback
The Customer grants IISRI® a worldwide, perpetual, irrevocable, transferable, royalty-free license to use and incorporate feedback into the Services, provided IISRI® does not publicly attribute it to the Customer without consent.
5.4Use of Customer Ratings for Marketing
The Customer grants IISRI® a royalty-free license to use its ratings for marketing, including publishing on IISRI®'s or CyberRank's website, provided that:
- (i)The rating is at least "B" (else it may be published as "Lower than B"); or
- (ii)The Customer gives explicit consent regardless of level.
Consent may be withdrawn and removal required within 10 business days by contacting IISRI® per Section 10.
6. Confidentiality
6.1Definition
"Confidential Information" means information disclosed by one party ("Disclosing Party") to the other ("Receiving Party"), orally or in writing, labeled or reasonably understood as confidential. IISRI®'s includes the Services and proprietary materials; the Customer's includes personal identifiable information in Customer Services Data; both parties' includes pricing, business and marketing strategies, technology, specifications, roadmaps, designs and operational processes. It excludes information that:
- (i)Becomes public without breach;
- (ii)Was lawfully held before disclosure;
- (iii)Is received from a third party without breach;
- (iv)Is independently developed; or
- (v)Is used or disclosed in aggregated or anonymised form under Sections 5.2 or 5.4 (which does not remove confidentiality from any personal information or identifiable Customer Services Data).
6.2Protection
The Receiving Party will:
- (i)Protect the information with at least reasonable care;
- (ii)Use it only within the scope of this Agreement;
- (iii)Disclose it only to personnel who need it and are bound by equivalent obligations, remaining accountable for their compliance; and
- (iv)Maintain confidentiality for five (5) years after termination, except trade secrets, which remain confidential indefinitely.
6.3Compelled Disclosure
The Receiving Party may disclose Confidential Information when legally required, provided it gives the Disclosing Party prior notice (unless prohibited) and reasonable assistance, at the Disclosing Party's expense, to challenge or limit the disclosure. If disclosure is required in a proceeding where the Disclosing Party is a party and does not contest it, the Disclosing Party will reimburse the reasonable costs of providing secure access.
7. Representations, Warranties, Exclusive Remedies, and Disclaimers
7.1Representations
Each party represents it has legal authority to enter into this Agreement and perform its obligations.
7.2IISRI®'s Warranties
IISRI® warrants that:
- (a)The Purchased Services will perform materially in accordance with the Documentation;
- (b)Professional Services will be performed competently and professionally; and
- (c)IISRI® has taken commercially reasonable measures to prevent Malicious Code.
The Customer's exclusive remedy for breach of these warranties is as specified in Sections 12.1 and 12.2; this does not limit the indemnities in Section 8.
7.3Mutual Warranties
Both parties warrant they will comply with all applicable laws concerning the provision and use of the Services, including data security and breach notification laws.
7.4Disclaimers
Except as expressly provided, neither party makes any warranties, express, implied, statutory or otherwise, and each disclaims implied warranties of merchantability and fitness for a particular purpose to the maximum extent permitted by law. Neither party assumes liability for damages caused by third-party hosting providers or non-CyberRank applications.
8. Mutual Indemnification
8.1Indemnification by IISRI®
IISRI® shall defend the Customer against any third-party claim alleging that the Customer's use of a Purchased Service infringes or misappropriates intellectual property rights ("Claim Against Customer"), provided the Customer:
- (a)Promptly notifies IISRI® in writing;
- (b)Grants IISRI® full control over defense and settlement; and
- (c)Provides reasonable assistance.
IISRI® may, at its option:
- (i)Modify the Services to avoid infringement without materially reducing functionality;
- (ii)Obtain a license for continued use; or
- (iii)Terminate the affected Services on 30 days' notice and refund prepaid, unused fees.
IISRI® has no obligation to the extent the claim arises from:
- (i)Any Non-CyberRank Application;
- (ii)The Customer's breach;
- (iii)The Customer's negligence, recklessness or wilful misconduct;
- (iv)Combination with unauthorized products, systems or data; or
- (v)Modifications by the Customer or its agents.
This indemnification liability is capped at total fees paid in the prior 12 months.
8.2Indemnification by Customer
The Customer shall defend IISRI® against any third-party claim arising out of or in connection with the Customer's use of the Services, including:
- (i)Claims arising from Customer Services Data alleging infringement or misappropriation of intellectual property rights;
- (ii)Claims arising from the Customer's use of the Services in breach of this Agreement;
- (iii)Claims by any Scan Target or other third party alleging unauthorised access to, interference with, or scanning of their systems or data, or breach of privacy, arising from a scan initiated by the Customer, or arising from the Customer's breach of Section 8.4(f); and
- (iv)Claims falling within Section 3.13 (United States exposure).
The Customer shall indemnify IISRI® for damages, losses, settlement amounts approved in writing by IISRI®, and reasonable legal fees, provided IISRI®:
- (a)Promptly notifies the Customer;
- (b)Grants the Customer control over defense and settlement (except the Customer cannot settle without unconditionally releasing IISRI®); and
- (c)Provides reasonable assistance at the Customer's expense.
This clause does not apply to the extent the claim arises from IISRI®'s breach, negligence, recklessness or wilful misconduct. The Customer's liability under limbs (i) and (ii) is capped at total fees paid in the prior 12 months; the Customer's liability under limbs (iii) and (iv) and under Section 8.4(f) is not subject to that cap or to the exclusive remedy in Section 8.3.
8.3Exclusive Remedy
This Section 8 sets forth the exclusive remedies and obligations of the parties with respect to the claims described herein. Nothing in this Section 8.3 limits or excludes the Customer's obligations under Sections 3.13 or 8.4(f), which are additional to, and not the exclusive remedy for, the matters they cover.
8.4Nature of CyberRank Services - Cyber Risk Intelligence Disclaimer
The Customer acknowledges that IISRI® provides AI, cybersecurity and privacy intelligence and analytical services based on aggregation and interpretation of External Data Sources, including publicly available information, internet-facing infrastructure, domain and network metadata, threat intelligence feeds, third-party datasets, and non-invasive scanning techniques. Outputs may be probabilistic, predictive or inferred and are subject to limitations in data quality, completeness, timeliness and model interpretation, including bias, uncertainty and error.
- (a)CyberRank outputs (risk scores, alerts, reports, classifications, recommendations) may be based on both factual data and probabilistic, inferred or predictive modelling.
- (b)Such outputs are subject to uncertainty, including limitations in data availability, timing delays, incomplete visibility, false positives and false negatives.
- (c)IISRI® does not guarantee that any output is accurate, complete, current or free from error.
- (d)IISRI® does not perform intrusive penetration testing, exploitation, or internal system auditing through CyberRank unless expressly agreed in a separate written agreement.
- (e)CyberRank outputs do not constitute legal, regulatory, compliance, or security certification or assurance.
- (f)Authorisation and consent for scanning. Before initiating any invasive scanning functionality made available through CyberRank, the Customer must obtain all necessary Authorisations and consents from the organisation being assessed or scanned (the "Scan Target"), and must confirm, via the attestation presented in the platform, that it holds valid Authorisation to perform the scan. IISRI® records each such confirmation (including the user, timestamp, Scan Target and attestation text). The Customer warrants that each person completing the attestation is authorised to give it on the Customer's behalf and that the Authorisation is accurate and subsisting. The Customer assumes full responsibility and liability for such activities and releases, indemnifies, and holds harmless the Provider Group from any claims, losses, liabilities, damages, or expenses arising from or relating to the Customer's use of such functionality. The Customer's confirmation does not transfer to IISRI® any responsibility for obtaining or verifying the underlying Authorisation. The Customer's indemnity under this Section 8.4(f) is carved out of the exclusive remedy and the liability caps, as provided in Section 9.1.
The Customer acknowledges that any reliance on CyberRank outputs is at the Customer's sole risk, and the Customer shall independently evaluate and validate all outputs before taking any action or making any business, security, or compliance decision.
9. Limitation of Liability
9.1Limitation of Liability
Except for the Customer's payment obligations under Section 4, neither party shall be liable for any single incident or series of related incidents in excess of the total amount paid by the Customer in the twelve (12) months preceding the event giving rise to the claim, and in no event shall aggregate liability exceed total amounts paid during the term. These limitations apply regardless of the form of action, to the maximum extent permitted by law. However, the exclusions and limitations in this Section 9 do not apply to, and do not limit:
- (a)The Customer's indemnification obligations under Section 8.2(iii) and Section 8.4(f);
- (b)Any liability arising from the Customer's breach of Section 8.4(f) (authorisation and consent for scanning);
- (c)The Customer's payment obligations under Section 4;
- (d)Either party's liability for fraud or fraudulent misrepresentation or wilful misconduct;
- (e)Breach of Section 6 (Confidentiality); or
- (f)The Customer's obligations under Section 3.13 (United States exposure).
Except as so provided, nothing in this Section 9.1 expands or removes the caps expressly stated in Sections 8.1 and 8.2.
9.2Exclusion of Consequential Damages
Except for each party's indemnification obligations under Section 8, neither party shall be liable for indirect, incidental, special, consequential, punitive or exemplary damages, including loss of profits, revenue, data, business opportunity or goodwill, even if advised of the possibility. Where a Customer is referred by a Reseller, the indemnification caps in Sections 8.1 and 8.2 apply only to disputes between IISRI® and the Customer and have no bearing on any caps agreed separately between IISRI® and a Reseller.
10. Notices, Governing Law, and Dispute Resolution
10.1Manner of Giving Notice
All notices must be in writing and are deemed given:
- (i)Upon personal delivery;
- (ii)Five business days after mailing;
- (iii)Two business days after confirmed facsimile; or
- (iv)One business day after email transmission with confirmation of receipt or delivery, or upon electronic confirmation of an in-platform notice.
Indemnification notices may be given by any method in this Section 10.1, including by email with confirmation of receipt or delivery or by in-platform notice with electronic confirmation. Notices to IISRI®: Independent Information Security Rating Institute (IISRI®) Ltd, Level G, 26 Hobson Street, Auckland City 1010, New Zealand; Legal@iisri.com.
10.2Governing Law and Dispute Resolution
This Agreement is governed by and interpreted under the laws of New Zealand, without regard to conflict-of-law principles. Any dispute arising out of or in connection with this Agreement, including any question regarding its existence, validity or termination, shall be finally resolved by arbitration under the Rules of Arbitration of the International Chamber of Commerce (ICC), which Rules are deemed incorporated by reference. The seat of arbitration shall be [Auckland, New Zealand / Singapore]; the tribunal shall consist of [one] arbitrator; and the language of the arbitration shall be English. Notwithstanding the foregoing, either party may seek urgent injunctive or interim relief from any court of competent jurisdiction. Customers established in the EEA, the UK, or California, or whose use of the Services involves personal data of individuals in those jurisdictions, are subject to the applicable addenda: Addendum A (EU GDPR), Addendum B (UK GDPR), and Addendum C (CCPA/CPRA); in the event of conflict, the relevant addendum prevails to the extent required by applicable law. Where a Customer has been referred by a Reseller and a dispute involves both this Agreement and the applicable Reseller Agreement, this Agreement and any dispute between IISRI® and the Customer shall remain governed exclusively by the laws of New Zealand and resolved by ICC arbitration as set out above, regardless of the governing law or dispute-resolution mechanism in the Reseller Agreement. The Reseller Agreement governs only the IISRI®-Reseller relationship and shall not affect the governing law or dispute resolution applicable to any Customer.
11. General Provisions
11.1Entire Agreement and Order of Precedence
This Agreement, including all Purchase Orders, is the complete understanding and supersedes prior agreements. Conflicting terms in Customer-issued documents are void. Order of precedence:
- Applicable jurisdiction-specific addenda (to the extent required by law);
- The applicable Purchase Order;
- This Agreement;
- The Documentation.
11.2Assignment
Neither party may assign without prior written consent, except in a merger, acquisition, or sale of substantially all assets; provided that IISRI® may assign or novate to Novimix or to any other member of the Provider Group that is a body corporate. If a party is acquired by a direct competitor of the other, the other may terminate on written notice.
11.3Relationship of the Parties
The parties are independent contractors; no partnership, franchise, joint venture, agency, fiduciary, or employment relationship is created.
11.4Third-Party Beneficiaries
Except for members of the Provider Group in respect of Sections 8 and 9, this Agreement creates no third-party beneficiary rights, and no person who is not a party has any right under the Contract and Commercial Law Act 2017 or otherwise to enforce it.
11.5Waiver
Failure to enforce any provision is not a waiver of it.
11.6Severability
If any provision is invalid, the remaining provisions continue in effect.
11.7Headings
Section headings are for reference only.
11.8Equitable Relief
Each party may seek equitable relief to prevent unauthorized use of its intellectual property.
11.9Force Majeure
Neither party is liable for delays or failures due to causes beyond reasonable control, including natural disasters, terrorism, labor disruptions and internet failures. A merger, acquisition or change of control shall not itself constitute a force majeure event and is governed by Section 11.2.
11.10Consumer Guarantees Act and Fair Trading Act (New Zealand)
The Customer acknowledges that it is acquiring the Services and Professional Services in trade, that both parties are in trade, and that it is fair and reasonable that the parties are bound by this clause. To the maximum extent permitted by section 43 of the Fair Trading Act 1986 and section 5D of the Consumer Guarantees Act 1993, the parties agree that the Consumer Guarantees Act 1993 and sections 9, 12A, 13 and 14(1) of the Fair Trading Act 1986 do not apply to this Agreement. This clause does not apply where the Customer acquires the Services as a consumer otherwise than in trade, in which case the Customer's rights under the Consumer Guarantees Act 1993 are unaffected.
12. Termination
12.1Termination for Cause
Termination of this Agreement is governed exclusively by this Section 12, save for any termination right expressly stated elsewhere (Sections 8.1 and 11.2). Either party may terminate for cause on written notice if the other materially breaches and fails to cure within twenty (20) days.
- (a)If the Customer terminates for IISRI®'s uncured breach, IISRI® refunds prepaid fees for the unused portion of the term, pro rata.
- (b)If IISRI® terminates for the Customer's uncured breach, all amounts paid or payable remain due and no refund is provided.
12.2Termination Without Cause
- (a)The Customer may terminate without cause on thirty (30) days' notice, with no refund of prepaid fees.
- (b)IISRI® may terminate without cause on thirty (30) days' notice and shall refund prepaid fees for the unused portion of the term, pro rata.
12.3Effect of Termination
On termination or expiration, the Customer's right to access the Services ceases immediately. Termination does not relieve accrued obligations. IISRI® will retain personal identifiable information of the Customer for no longer than 90 days, after which it is deleted or anonymised, unless retention is required by law. Sections and provisions that by their nature survive (including Sections 3.13, 5, 6, 8, 9, 10, 11.10 and the Addenda) survive termination.
Addendum A: EU General Data Protection Regulation (GDPR) Data Processing Agreement
Effective as part of the CyberRank End User Platform Agreement
A.1Scope and Purpose
This Addendum applies where the Customer is established in the EEA, or where the Customer's use of the Services involves processing personal data of individuals located in the EEA, as governed by Regulation (EU) 2016/679 (GDPR).
A.2Roles of the Parties
- (a)IISRI® acts as an independent Data Controller in respect of personal data it collects directly from Customers and Users (such as account credentials and billing contact details) and processes for its own purposes per its Privacy Policy.
- (b)IISRI® does not act as a Data Processor on behalf of the Customer; IISRI® processes Vendor Services Data under its own legal basis as an independent data controller, and the Customer is not instructing IISRI® to process personal data on its behalf through the Services.
- (c)Where the Customer inputs personal data beyond what is contemplated, it does so as an independent controller and is solely responsible for a valid legal basis.
A.3IISRI®'s Obligations as Data Controller
IISRI® shall:
- (a)Process personal data only for the purposes in its Privacy Policy and this Agreement;
- (b)Implement appropriate measures under Article 32 GDPR;
- (c)Notify affected Customers of a personal data breach within 72 hours of becoming aware where it is likely to risk individuals' rights and freedoms, per Articles 33 and 34 GDPR (without prejudice to the 24-hour contractual notification in Section 2.2);
- (d)Honour data-subject rights requests within one month, extendable by two months for complex or numerous requests, per Article 12(3);
- (e)Not transfer personal data outside the EEA without adequate protection, including SCCs or another Chapter V mechanism; and
- (f)Maintain records under Article 30.
A.4International Data Transfers
Where IISRI® transfers personal data from the EEA to New Zealand, the parties acknowledge New Zealand holds an EU adequacy decision. For transfers to other third countries, IISRI® shall implement appropriate safeguards including the EU SCCs (Commission Implementing Decision (EU) 2021/914) or successors.
A.5Sub-processors
IISRI® may engage sub-processors bound by data-protection obligations at least equivalent to this Addendum, and shall make available a current list on request.
A.6Supervisory Authority
The lead supervisory authority shall be determined by the location of IISRI®'s EU representative (Article 27) or the supervisory authority of the Member State where processing takes place.
A.7Conflict
In case of conflict between this Addendum and the main Agreement, this Addendum prevails to the extent necessary to ensure GDPR compliance.
A.8Vendor Services Data
IISRI® acts as an independent controller of Vendor Services Data (including Compromised Credential Data) on the legal basis and subject to the minimisation, transparency and data-subject-rights safeguards set out in Section 5.2A, which applies for the purposes of this Addendum.
Addendum B: UK General Data Protection Regulation (UK GDPR)
Effective as part of the CyberRank End User Platform Agreement
B.1Scope and Purpose
This Addendum applies where the Customer is established in the UK, or where its use of the Services involves personal data of individuals in the UK, governed by the UK GDPR and the Data Protection Act 2018 ("UK Data Protection Law").
B.2Relationship to EU GDPR Addendum
Addendum A is incorporated by reference, with:
- (a)"GDPR" read as "UK GDPR" / "UK Data Protection Law";
- (b)"European Commission" read as "UK Secretary of State" or "ICO" as appropriate;
- (c)"EEA" read as "United Kingdom";
- (d)The supervisory authority being the ICO (ico.org.uk); and
- (e)UK transfers governed by the ICO's IDTA or the UK Addendum to the EU SCCs (or successors).
B.3Adequacy
The parties acknowledge New Zealand holds a UK adequacy regulation. For transfers to other non-adequate countries, IISRI® shall implement the IDTA or another ICO-approved mechanism.
B.4Conflict
In case of conflict between this Addendum and the main Agreement or Addendum A, this Addendum prevails to the extent necessary for UK Data Protection Law compliance.
Addendum C: California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA)
Effective as part of the CyberRank End User Platform Agreement
C.1Scope and Purpose
This Addendum applies where the Customer is a business subject to the CCPA as amended by the CPRA, and its use of the Services involves personal information of California residents.
C.2Roles of the Parties
IISRI® acts as an independent Business in respect of personal information it collects for its own commercial purposes. Where IISRI® processes personal information solely on the Customer's behalf and direction, it acts as a Service Provider and shall not: sell or share the information for cross-context behavioural advertising; retain, use or disclose it outside the Services or as permitted by law; or combine it with information from other sources except as permitted by CCPA/CPRA.
C.3IISRI®'s Obligations
IISRI® shall:
- (a)Provide the same level of privacy protection required of businesses under CCPA/CPRA;
- (b)Notify the Customer promptly if it can no longer meet its obligations;
- (c)On verified consumer request forwarded by the Customer, assist within 45 days with requests to know, delete, correct, or opt out of sale/sharing;
- (d)Not sell or share personal information; and
- (e)On termination, delete or return personal information as directed unless retention is required by law.
C.4Customer Obligations
The Customer represents that it has provided required notices to California consumers, has a valid legal basis to share personal information with IISRI®, and will honour consumer rights requests within CCPA/CPRA timelines.
C.5No Sale of Personal Information
IISRI® confirms it does not sell personal information of California residents as defined under CCPA/CPRA and will not do so without explicit agreement and required notices.
C.6Conflict
In case of conflict between this Addendum and the main Agreement, this Addendum prevails to the extent necessary for CCPA/CPRA compliance.
Questions about this agreement?
If you have any questions or need clarification regarding the terms of this Platform Agreement, please contact our support team.