Terms of Service
These terms govern your use of the HackRisk service provided by CyberLab (Cyberlab Security Limited). By accessing or using the service you agree to be bound by these terms.
1. Introduction
HackRisk.AI is a threat detection service provided by CyberLab that performs comprehensive, automated analysis of a customer’s cyber exposure, identifying potential security weaknesses and providing actionable insights.
By accepting this Agreement or accessing/using the Service, the Customer agrees to be bound by these terms and conditions. CyberLab may modify this Agreement as permitted in clause 14.
Purchase from Reseller: If Customer purchases from an authorised reseller, use is governed by this Agreement subject to clause 14.12.
2. The Service
Use of Service. Subject to payment of Fees, CyberLab grants Customer a non-exclusive, non-transferable right during the Term to access and use the Service (including Reports) solely for Customer and its Users.
Restrictions. Except as expressly permitted, Customer shall not:
- Copy, reproduce, publish, distribute, sell, license, rent, assign, transfer, disclose, or commercially exploit any part of the Service
- Permit third-party use including timesharing, service bureau or outsourced use
- Combine, merge or incorporate the Service into other programs or create derivative works
- Reverse engineer, decompile, or seek source code except as permitted by Applicable Law
- Remove or obscure proprietary notices
- Use the Service to develop similar or competing products
- Use for storing or transmitting viruses or illegal content
- Resell the Service without express written consent
- Access from Prohibited Territories or as a Prohibited Entity
Trial Service. Customer may access the Service as a Trial for 30 days. If a paid subscription is not activated within 30 days, access is revoked. Either party may terminate the Trial before the 30-day period for any reason.
Updates. CyberLab may change or update the Service using reasonable endeavours to ensure modifications do not materially adversely affect Customer’s use.
3. Users
Permitted Users. Only Users may access and use the Service. Customer is responsible for Users’ actions and for ensuring Users keep login credentials confidential. Customer must promptly notify CyberLab of any account compromise.
Unauthorised Access. Customer must use all reasonable endeavours to prevent unauthorised access and promptly notify CyberLab of any such access.
Age Requirement. The Service is not intended for anyone under 16.
4. Term and Renewals
The Agreement is effective on the Start Date and continues for the Plan Term. On expiry, the Agreement continues on a rolling monthly basis. Customer may cause non-renewal by giving CyberLab no less than 30 days’ written notice, effective at the end of the following month.
5. Fees
Fees are payable monthly during the Plan Term, or as otherwise agreed. All payment obligations are non-cancellable and Fees are non-refundable once invoiced.
CyberLab may increase Fees on 30 days’ written notice, provided the increase is not higher than current standard rates and not effective before current Plan Term expiry.
Late payments are subject to a 1.5% monthly service charge. All Fees are exclusive of applicable taxes. No Fees are payable for Trial Service unless otherwise agreed.
6. Warranties and Disclaimers
Limited Warranty. CyberLab warrants that the Service operates materially per the website description when used in accordance with this Agreement, and that CyberLab will not materially decrease Service functionality during the Term.
Warranty Remedy. If CyberLab breaches the warranty above and Customer makes a reasonably detailed claim within 30 days of discovering the issue, CyberLab will use commercially reasonable efforts to correct the issue within 60 days. If unable to do so, either party may terminate the applicable Service and Customer is entitled to a refund of unused pre-paid Fees as their sole remedy.
Disclaimer. Other than as expressly stated, the Service is provided ‘as is’ without warranty. CyberLab accepts no liability that the Service meets Customer’s individual needs, ensures systems are completely secure against cyber-attacks, discovers all Customer content on the dark web, or is free of minor errors or defects.
7. Intellectual Property and Publicity
CyberLab IP. CyberLab (or its licensors) owns all Intellectual Property Rights in the Service. Customer has no right to a copy of the underlying computer code.
Customer IP. Customer owns all Intellectual Property Rights in Customer Content and grants CyberLab a limited licence to use and store Customer Content to the extent necessary to perform the Service.
Feedback. CyberLab may freely use any suggestions, recommendations or corrections provided by Customer or Users relating to the Service.
Usage Data. CyberLab may collect and use Usage Data to develop, improve and operate its products and services. CyberLab will not share Usage Data with third parties unless aggregated and anonymised such that Customer and Users are unidentifiable.
8. Confidentiality
Each party receiving Confidential Information must maintain its confidentiality, not disclose it to third parties except as permitted, and not use it except as necessary for performance of the Agreement.
Confidentiality obligations do not apply to information that becomes publicly known without fault, is lawfully received from a third party free of confidence obligations, is independently developed, or is required to be disclosed by law or court order.
9. Customer Content and Reports
In the event of loss or damage to Customer Content, Customer’s sole remedy is for CyberLab to use reasonable endeavours to restore it from the latest backup.
Reports may be viewed within or exported from the Service portal during the Plan Term.
Deletion or Return. After termination, CyberLab will, at Customer’s choice, delete or return Customer Content and Reports containing personal data, after which all data is permanently deleted.
10. Data Protection and Security
Each party will comply with relevant data protection laws. CyberLab acts as data processor and Customer acts as data controller for personal data processed when using the Service. The parties shall comply with their respective obligations under the Data Processing Addendum (Schedule 1).
CyberLab implements appropriate technical and organisational security measures to protect the Service and Customer Content in accordance with Applicable Law.
11. Indemnity
CyberLab Indemnity. CyberLab will defend, indemnify and hold Customer harmless from third-party claims that the Service infringes that third party’s Intellectual Property Rights, subject to the limitations in this clause.
Customer Indemnity. Customer will defend, indemnify and hold CyberLab harmless from third-party claims arising from Customer Content.
Indemnification requires prompt written notice (within five Business Days), no adverse comment or admission, provision of reasonable assistance, and sole authority to the indemnifying party to control, defend and settle the claim.
12. Limitation of Liability
Liability Cap. Each party’s total aggregate liability shall not exceed the higher of £100 or the Fees paid or payable by Customer in the 12-month period immediately preceding the first incident giving rise to the claim. CyberLab’s liability in respect of Trial Service shall not exceed £100.
Excluded Losses. Neither party is liable for: consequential, indirect or special losses; loss of profit; data destruction or corruption; loss of use, contract or opportunity; or reputational harm or goodwill loss.
Unlimited Liability. Nothing limits either party’s liability for death or personal injury caused by negligence, fraud or fraudulent misrepresentation, or any other losses that cannot be excluded by Applicable Law.
13. Termination
Termination for Cause. Either party may terminate immediately by written notice if the other: commits a non-remediable material breach; fails to remedy a material breach within 15 days of notice; ceases operations without a successor; or becomes subject to insolvency proceedings not dismissed within 60 days.
Termination for Convenience. CyberLab may terminate on 90 days’ notice, refunding pre-paid Fees. Customer may terminate in writing at any time, but is not entitled to any refund and any outstanding Fees become immediately due.
Effect of Termination. On termination, all rights granted under this Agreement terminate and Customer must stop using the Service. Accrued rights and liabilities are unaffected.
Suspension. CyberLab may suspend access if Customer breaches key provisions, if activity threatens service security, if Fees are overdue by more than 30 days, or if required by law.
14. General
Entire Agreement. This Agreement constitutes the entire agreement between the parties, superseding all prior agreements relating to its subject matter.
Modifications. CyberLab may modify these terms from time to time. Modifications are effective on Customer’s next Term renewal. If Customer objects within 30 days, CyberLab may permit Customer to continue under existing terms until current Term expiration, or allow Customer to terminate and receive a refund.
Force Majeure. Neither party is liable for delays in performance caused by events beyond their reasonable control.
Assignment. Neither party may assign this Agreement without prior written consent, except CyberLab may assign in connection with a merger, reorganisation, acquisition or transfer to an Affiliate.
Governing Law. This Agreement is governed by the laws of England and Wales. The courts of England have exclusive jurisdiction to settle any dispute or claim arising out of or in connection with this Agreement.
Severability. If any provision is held unenforceable, it shall be limited to the minimum extent necessary so the Agreement otherwise remains in full effect.
Third Party Rights. A person who is not a party to this Agreement has no rights under the Contracts (Rights of Third Parties) Act 1999 to enforce any of its provisions.
15. Definitions
- Agreement
- These Terms of Service and any Orders entered into between the parties.
- CyberLab
- Cyberlab Security Limited, Mereside, Alderley Park, Congleton Road, Alderley Edge, Cheshire SK10 4TG. Company registration number 12392586.
- Customer
- The legal entity or person placing an Order or accessing the Service.
- Customer Content
- All data and materials provided to CyberLab by or on behalf of Customer or Users, or relating to Customer and its IT assets that CyberLab collects or discovers as part of the Service.
- Fees
- Fees payable by Customer for use of the Service, based on CyberLab’s standard pricing or as set out in the relevant Order.
- Plan Term
- The minimum subscription period – either rolling-monthly or 12-month – commencing on the Start Date.
- Report
- A summary of CyberLab’s findings, including the HackRisk Score. Available in the Service portal and exportable as a PDF during the Plan Term.
- Service
- Access to CyberLab’s HackRisk service as software-as-a-service, as described at hackrisk.ai. Includes Trial Service, exportable Reports, and (where applicable) installed software.
- Trial Service
- Service provided on a trial basis for 30 days, including a free Report with restricted results.
- User
- An individual permitted by Customer to use the Service under Customer’s account.
Schedule 1 – Data Processing Addendum
This Data Processing Addendum (“DPA”) forms part of the Agreement and applies where CyberLab processes Personal Data on behalf of Customer in the course of providing the Service.
Processing details: CyberLab processes Customer Personal Data solely to provide the Services described in the Agreement. Processing duration equals the Agreement term, plus any period post-termination during which CyberLab retains Customer Personal Data in accordance with the Agreement.
Categories of data subjects may include: Customer’s employees, consultants and agents authorised as Users; and any other individuals whose personal data is submitted by Customer or discovered from the dark web as part of the Service.
Types of personal data may include: name and contact details; online and device identifiers; employment details; payment details; and personal data discovered from the dark web (including passwords, usernames and card data).
CyberLab’s obligations as processor: process Personal Data only per this DPA and Customer’s instructions; maintain confidentiality; assist with data subject requests and regulatory engagement; notify Customer without undue delay of any Personal Data Breach; and on Agreement expiry delete or return Customer Personal Data at Customer’s written request.
Full details of security measures, sub-processor arrangements, data transfer mechanisms and audit rights are available on request from [email protected].