CyberProva

Terms of Service

1. Who the agreement is with

CyberProva is based in the United Kingdom.

Service and contractual notices: hello@cyberprova.com. Privacy enquiries: hello@cyberprova.com.

“We”, “us” and “our” mean that operator. “You” means the organisation subscribing to the service. The person accepting these terms must be authorised to bind that organisation. The service is offered for business purposes, not personal or household use.

The agreement consists of these terms, the selected plan or order, and the data-processing schedule below. The schedule takes priority for personal-data processing; a variation expressly agreed in writing takes priority over these standard terms. The privacy notice explains how we handle personal data and is not a request for consent to all processing.

We may transfer this agreement to a company we set up to run CyberProva, provided the service and your rights under these terms are unaffected. We will tell you before that happens.

2. Assessment and decision support

CyberProva helps you assess selected security controls, collect and review evidence, record risks and prepare reports. Features, usage limits and export access depend on your plan.

Connected Microsoft tenant checks are read-only. We do not administer your tenant, implement remediation, operate your security controls, monitor every threat or provide incident response. Scheduled checks and notifications do not constitute a continuously staffed monitoring service.

Results describe the declared scope and information available when each check ran. Permissions, incomplete evidence, unsupported systems, stale data and changes after a check can limit results. An export date does not make older observations current.

Automated observations, customer or provider declarations, evidence accepted by a workspace reviewer and recommendations are distinct sources of information. Acceptance of uploaded evidence is not independent verification by CyberProva. Scores and passing results are not proof of security, an independent audit, certification, insurance eligibility or legal compliance. An assessment may miss a material weakness or incident.

We will provide the service with reasonable care and skill. These limitations define its scope; they do not remove that obligation.

3. Your responsibilities and permitted use

You and your IT provider remain responsible for security decisions, validating recommendations, testing and implementing changes, backups and incident response. Use qualified advice where your circumstances require it.

Provide accurate scope and information, keep it current, and obtain authority to connect tenants, assess websites and supply evidence about other people. Manage workspace membership and protect accounts and upload links. Tell us promptly about suspected unauthorised access to CyberProva.

Upload only what is necessary. Redact unrelated personal data and secrets. Do not upload passwords, private keys, access tokens, payment-card details or special-category or criminal-offence data unless we have expressly agreed an appropriate arrangement in writing.

You must not use the service unlawfully, assess systems without authority, upload malicious material, bypass access or usage restrictions, or interfere with other customers. Provider upload access does not grant general access to a customer's workspace.

4. Subscriptions, payment and cancellation

The checkout shows the plan, billing currency, monthly or annual billing period, price and applicable taxes before purchase. Paid subscriptions start billing at checkout unless an eligible subscription uses a valid invitation trial code, in which case the trial length, first payment date and recurring charge are shown before you confirm.

Subscriptions renew for the selected billing period until cancelled. Use the subscription-management portal to cancel or update payment details; contact us if you cannot access it. Cancellation takes effect at the end of the paid period unless an earlier termination is agreed or required by law. Revoking Microsoft consent does not cancel billing; cancelling billing does not itself revoke Microsoft consent or delete workspace data.

If payment fails, we may restrict paid features after notifying the billing contact and giving a reasonable opportunity to resolve it. A downgrade may remove exports or reduce usage allowances.

We do not give pro-rata refunds for cancellation part-way through a billing period. This does not affect refunds due because of our breach, an incorrect charge or applicable law. We will give at least 30 days' notice of a price increase, which takes effect no earlier than your next renewal after that notice, so you can cancel beforehand.

5. Availability, support and changes

Access depends partly on Microsoft, payment, hosting and communications services. Maintenance, outages, consent withdrawal and third-party API changes may interrupt checks or delay notifications. We do not promise uninterrupted availability or a response time unless a separate written service-level agreement says otherwise.

We may update the service for security, reliability and functionality. We will notify you of material reductions to paid functionality or material changes to these terms before they apply. Except where law or an urgent security issue requires earlier action, material changes will have at least 30 days' notice. If a change materially disadvantages you during a prepaid period, you may terminate before it takes effect and receive a refund for the unused affected period.

6. Customer data, reports and confidentiality

You retain your rights in data you supply. You authorise us to use it only as needed to provide, secure and support the service, follow your lawful instructions and meet legal obligations. The schedule below governs personal data processed on your behalf.

We retain rights in the software, assessment methodology and report templates. You may use and share reports generated for your organisation for legitimate business purposes, including with advisers, insurers and customers, provided scope, dates, source labels and limitations remain attached. Sharing does not turn the report into a certification or create a duty to a third party.

Each party will protect the other's confidential information, use it only for the agreement and disclose it only to people or providers who need it and are bound to protect it, or where law requires disclosure. These duties do not cover information already lawfully public, independently developed or lawfully obtained without restriction. They continue after termination.

7. Suspension and ending the agreement

We may suspend affected access where reasonably necessary to address unlawful use, a material security risk or material breach. Where practicable we will explain the reason, limit the suspension and provide an opportunity to remedy it. Either party may terminate for a material breach that remains unremedied 30 days after written notice, or immediately if it cannot be remedied.

On termination, access and paid features end on the notified date. You should download any reports you need before access ends. Billing cancellation is not a deletion request; customer personal data is returned or deleted as set out in the schedule below.

8. Liability

Nothing in this agreement excludes or limits liability for fraud, fraudulent misrepresentation, death or personal injury caused by negligence, or liability that cannot lawfully be excluded or limited. Nothing restricts individuals' statutory data-protection rights or a regulator's powers.

Subject to the preceding paragraph, each party's total liability arising from this agreement in any 12-month period is limited to the greater of £1,000 and the fees paid or payable for the service in that period. Your obligation to pay subscription fees properly due is outside this limit.

Subject to the same exceptions, neither party is liable for indirect or consequential loss. This clause does not treat every loss from a cyber incident as indirect or excuse a failure by us to exercise reasonable care and skill. Each party must take reasonable steps to mitigate loss.

9. Disputes and general provisions

Please raise complaints using the service contact above so we can seek a practical resolution. This agreement is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction, subject to any mandatory applicable law.

No person other than the parties has a right to enforce these terms under the Contracts (Rights of Third Parties) Act 1999. If a provision is unenforceable, the remaining provisions continue. A delay in enforcing a right is not a waiver. Nothing creates an agency, employment or partnership relationship.

These terms are written in English. Any translation is provided for convenience; if a translation differs from the English version, the English version prevails.

Schedule: processing customer personal data

This schedule applies where you determine the purposes and means of customer-data processing and we process it on your behalf. Where you act for another controller, you must hold authority to instruct us as a sub-processor and pass on that controller's lawful instructions. Our own controller activities are described in the privacy notice.

Processing description

For the term of the agreement and the return or deletion period below, we collect, organise, store, retrieve and analyse authorised tenant configuration and supplied evidence; generate assessments and reports; and send requested service notifications. Data may include names, work contact details, directory identifiers, roles, device and user references, evidence documents, declarations, findings and communication records. People concerned include your users, staff, contractors, providers and other individuals whose information you lawfully include. The service is not intended for sensitive data. You determine the scope, permitted users, content, and return or deletion instructions.

Instructions and confidentiality

We will process this data only on your documented instructions, including this agreement and actions you authorise in the service, unless applicable law requires otherwise. We will notify you of a legal requirement before processing unless prohibited, and inform you immediately if we believe an instruction infringes applicable data-protection law. Everyone authorised to process the data is bound by confidentiality obligations.

Security

We implement technical and organisational measures appropriate to the risk under Article 32 UK GDPR, including:

  • sign-in through Microsoft Entra ID, with workspace roles controlling what each member can see and change;
  • separation of every customer's data by workspace, enforced on each request;
  • encryption in transit (TLS 1.2 or later) and encryption at rest for the database and file storage;
  • database and file storage reachable only from the application's private network and named administrator connections, with application secrets held in Azure Key Vault;
  • administrative access limited to named individuals, with no shared or basic-authentication deployment credentials;
  • database backups for recovery, and security and request logs for investigating incidents.

We will notify you without undue delay after becoming aware of a personal-data breach affecting your data, supply available information about its nature, likely effects, affected data and mitigation, and provide updates as information becomes available. This concerns data we process; it does not make us your tenant incident-response provider.

Taking account of the processing and information available, we will assist with individuals' rights requests, security obligations, breach notifications, impact assessments and regulatory consultation. We will pass on requests concerning your data promptly and will not respond on your behalf except on instruction or as required by law.

Sub-processors and transfers

You authorise these sub-processors:

  • Microsoft: Azure hosting, database, file storage and logs in the United Kingdom; Microsoft Entra ID sign-in; Microsoft Graph access to tenants you connect.
  • Stripe: subscription billing and payment processing.
  • Our email delivery provider: delivery of service messages.

We will give at least 30 days' advance written notice of additions or replacements so you may object on reasonable data-protection grounds. We will seek a resolution before allowing the disputed processing; if none is possible, you may end the affected service with a refund of unused prepaid fees.

We impose equivalent data-protection obligations on sub-processors and remain responsible to you for their performance. Customer data is stored in the United Kingdom. Where a sub-processor accesses it from another country, the transfer is protected by UK adequacy regulations or the International Data Transfer Addendum to the standard contractual clauses.

Return, deletion and verification

At the end of processing, at your choice, we will provide your reports and uploaded evidence for download or securely delete customer personal data. We delete it from active systems within 30 days of the end of the agreement or your deletion request, unless law requires retention. Database backups expire within 7 days and deleted files are permanently removed from storage within 30 days. Until then, backups are not used for ordinary processing, and deletion is reapplied if a backup is ever restored.

We will provide information needed to demonstrate compliance with this schedule and allow and contribute to audits and inspections by you or your appointed auditor, on reasonable notice. Reasonable arrangements may protect other customers and security without preventing required oversight. Neither this schedule nor the liability clause removes either party's direct statutory obligations.

Read the privacy notice