Legal

Terms of Service

These terms define the rights and responsibilities that apply when an organisation or its users access RiskGear.

Effective date: 5 September 2026

These Terms of Service govern access to RiskGear, including its websites, applications, reports, notifications, and related services (the “Service”). By creating an account, accepting an invitation, or using the Service, you agree to these Terms. If you use RiskGear for an organisation, you confirm that you have authority to bind that organisation; “Customer” then means that organisation.

You must be legally capable of entering a binding agreement and must not use the Service where prohibited by applicable law.

Customers are responsible for account information, authorised users, role assignments, and all activity under their workspace. Credentials must be kept confidential and suspected unauthorised access must be reported promptly.

Workspace Owners control invitations and access. Customer is responsible for ensuring it has a lawful basis to add users and any personal or business information submitted to the Service.

Customer retains ownership of risk records, incident records, comments, attachments, user information, and other content submitted to the Service (“Customer Data”). Customer grants RiskGear the limited right to host, process, transmit, back up, and display Customer Data only as needed to provide, secure, support, and improve the Service.

For personal data contained in Customer Data, Customer is generally the controller and RiskGear acts as processor on Customer’s documented instructions, except where RiskGear processes account, billing, security, or service-usage data for its own legitimate purposes as described in the Privacy Policy.

You may use the Service only for lawful business purposes. You must not:

  • upload unlawful, infringing, malicious, or intentionally misleading content;
  • probe, bypass, disable, or interfere with authentication, permissions, rate limits, tenant isolation, or security controls;
  • introduce malware, scrape the Service at unreasonable volume, or use it to attack another system;
  • reverse engineer or copy the Service except where applicable law expressly permits it;
  • resell or provide the Service to third parties unless agreed in writing.

Paid plans, limits, billing intervals, and prices are shown at checkout. Paddle acts as Merchant of Record for paid purchases and handles payment processing, applicable taxes, invoices, cancellations, and refunds under the checkout terms presented to the purchaser.

Plan limits may restrict seats, open records, approval workflows, branding, or other functionality. If payment fails or a subscription ends, access may be limited or suspended after applicable notices.

RiskGear may improve, modify, or discontinue features, provided that material reductions to paid core functionality will be communicated where reasonably possible. The Service may be unavailable during maintenance, provider outages, security incidents, or events outside reasonable control. No uptime commitment applies unless separately agreed in writing.

RiskGear uses reasonable technical and organisational safeguards, including tenant access controls, row-level security, encryption provided by hosting vendors, and audit logging. No system is completely secure. Customer remains responsible for configuring roles appropriately, reviewing exported reports, and determining whether the Service meets its legal, regulatory, insurance, certification, or tender requirements. RiskGear does not provide legal, compliance, insurance, or professional advice.

RiskGear and its licensors own the Service, software, visual design, documentation, trademarks, and related intellectual property, excluding Customer Data. If you provide suggestions or feedback, RiskGear may use them without restriction or payment, provided this does not identify Customer or disclose confidential Customer Data.

Each party must protect the other party’s non-public confidential information using reasonable care and use it only for the agreement. This obligation does not cover information that is public without breach, independently developed, lawfully received from another source, or required to be disclosed by law. Where legally permitted, the receiving party will provide advance notice of a compelled disclosure.

Customer may stop using the Service or cancel a paid subscription through the available billing flow. RiskGear may suspend or terminate access for material breach, unlawful use, security risk, non-payment, or where required by law, normally after reasonable notice when the issue can be cured.

RiskGear uses soft deletion for inactive or closed workspaces because compliance records may be required for audits. Retention and deletion are described in the Privacy Policy. Customers should export any required records before termination. Provisions that by their nature should survive—including ownership, confidentiality, disclaimers, liability limits, and payment obligations—continue after termination.

To the maximum extent permitted by law, the Service is provided “as is” and “as available.” RiskGear disclaims implied warranties of merchantability, fitness for a particular purpose, non-infringement, and that the Service will be uninterrupted or error-free. Nothing in these Terms excludes rights or warranties that cannot lawfully be excluded.

To the maximum extent permitted by law, neither party is liable for indirect, incidental, special, exemplary, punitive, or consequential damages, or for loss of profits, revenue, goodwill, or data, arising from the Service.

RiskGear’s aggregate liability arising from the Service will not exceed the amount Customer paid for the Service during the 12 months before the event giving rise to the claim. These limits do not apply where liability cannot legally be limited, or to fraud or wilful misconduct.

RiskGear may update these Terms to reflect changes in the Service, law, or security practices. Material changes will be communicated through the Service or by email where appropriate. Continued use after the effective date constitutes acceptance of the updated Terms.

The parties will first attempt in good faith to resolve disputes informally. Mandatory law and any governing terms in an applicable order form or Merchant of Record checkout remain controlling. If no separate governing terms apply, the laws and courts of the place where the RiskGear operator is established apply, excluding conflict-of-law rules.

Questions about these Terms may be sent to hello@tryriskgear.com.