Terms of Service
1. Acceptance of Terms
By creating an account, clicking an acceptance button, or using the Services, you acknowledge that you have read, understood, and agree to be bound by these Terms and our Privacy Policy. If you are entering into these Terms for an organization, you represent that you have authority to bind that organization. If you do not agree, do not use the Services.
2. Description of Service
TailoredGRC provides a cloud-based software-as-a-service (SaaS) platform for governance, risk, and compliance (“GRC”), including tools for policies, controls, evidence, risk management, and related workflows. The Services are delivered over the internet on a subscription basis. Features, availability, and performance may evolve over time. We may add, modify, or discontinue features with reasonable notice where material changes affect your use.
3. Subscription Plans and Payment
Access to the Services is provided under subscription plans—currently offered in four tiers (for example, Starter, Professional, Business, and Enterprise)—with features and limits described at the time of order or in your order form. Unless otherwise stated, subscriptions are billed annually in advance.
Payments are processed by our third-party payment processor, Stripe. By providing payment information, you authorize us and Stripe to charge applicable fees according to your selected plan and billing cycle. Fees are non-refundable except as required by law or as expressly stated in a written agreement. Taxes may apply based on your location.
4. User Accounts and Security
You are responsible for maintaining the confidentiality of your account credentials and for all activity under your account. You must provide accurate registration information and notify us promptly of unauthorized use.
Your organization may access the application using an organization slug or similar identifier in the URL (for example, paths under /app/). You are responsible for distributing slug-based links only to authorized users and for ensuring that access aligns with your internal policies.
5. Acceptable Use Policy
You agree not to misuse the Services. Without limitation, you must not:
- Use the Services for any unlawful purpose or in violation of applicable regulations;
- Attempt to probe, scan, or test the vulnerability of the Services, or breach security or authentication measures;
- Reverse engineer, decompile, or disassemble any part of the Services except where such restriction is prohibited by law;
- Use automated means (including bots or scrapers) to extract data from the Services without our prior written consent, except as allowed by public search engines or interoperability required by law;
- Interfere with or disrupt the integrity or performance of the Services or third-party data contained therein.
We may suspend or terminate access for violations of this section.
6. Data Ownership
As between you and TailoredGRC, you retain all right, title, and interest in and to your data that you or your users submit to the Services (“Customer Data”). TailoredGRC does not claim ownership of Customer Data. You grant us a limited license to host, process, and display Customer Data solely to provide and improve the Services in accordance with these Terms and our Privacy Policy.
7. Confidentiality
Each party may receive non-public information from the other that is designated as confidential or that reasonably should be understood to be confidential (“Confidential Information”). The receiving party will use reasonable care to protect Confidential Information and will not disclose it to third parties except as permitted under these Terms or with the disclosing party’s consent. Confidentiality obligations do not apply to information that is publicly available, independently developed, or rightfully received from a third party without restriction.
8. HIPAA Compliance
If you are a covered entity or business associate under the Health Insurance Portability and Accountability Act (“HIPAA”) and intend to include protected health information (“PHI”) in Customer Data, you are responsible for determining whether your use of the Services is appropriate and compliant. A Business Associate Agreement (“BAA”) may be available upon request for qualifying subscriptions. Until a BAA is executed where required, you should not upload PHI. You remain responsible for your HIPAA compliance program, including access controls, minimum necessary use, and breach notification.
9. Intellectual Property
TailoredGRC and its licensors own all rights, title, and interest in the Services, including software, branding, documentation, and related intellectual property. Subject to these Terms, we grant you a limited, non-exclusive, non-transferable right to access and use the Services during your subscription. You may not copy, modify, or create derivative works of our platform except as expressly permitted. Customer Data remains yours as stated in Section 6.
10. Limitation of Liability
To the maximum extent permitted by applicable law, neither TailoredGRC nor its suppliers will be liable for any indirect, incidental, special, consequential, or punitive damages, or for loss of profits, data, or goodwill, arising out of or related to the Services or these Terms, even if advised of the possibility of such damages.
Our aggregate liability arising out of or relating to the Services or these Terms will not exceed the greater of (a) the amounts you paid to TailoredGRC for the Services in the twelve (12) months preceding the claim, or (b) one hundred U.S. dollars (USD $100), except where liability cannot be limited by law.
11. Indemnification
You will defend, indemnify, and hold harmless TailoredGRC and its officers, directors, employees, and agents from and against any claims, damages, losses, and expenses (including reasonable attorneys’ fees) arising out of or related to your Customer Data, your use of the Services in violation of these Terms, or your violation of applicable law or third-party rights.
12. Termination
Either party may terminate your subscription as set forth in your order terms or by written notice in accordance with the agreement. We may suspend or terminate access immediately if you materially breach these Terms and fail to cure within a reasonable period where cure is feasible.
Upon termination, your right to use the Services ceases. We will make Customer Data available for export for a period of thirty (30) days after termination unless a longer period is required by law or specified in your agreement, after which we may delete Customer Data in accordance with our retention practices. Sections that by their nature should survive (including confidentiality, data ownership, limitations of liability, and indemnity) will survive termination.
13. Governing Law
These Terms are governed by the laws of the State of Missouri, without regard to conflict-of-law principles. The courts located in Missouri will have exclusive jurisdiction over disputes arising from or relating to these Terms, subject to any mandatory arbitration or venue provisions in a separate written agreement with you.
14. Changes to Terms
We may modify these Terms from time to time. We will post the updated Terms on this page and revise the “Last updated” date. If changes are material, we will provide additional notice as appropriate (for example, by email or in-product notice). Your continued use of the Services after the effective date constitutes acceptance of the revised Terms, except where prohibited by law.
15. Contact Information
For questions about these Terms, please contact us:
TailoredGRC
Missouri, United States
Website: https://tailoredgrc.com/
Legal & general inquiries: btaylor@tailoredgrc.com