CodeIQ Holdings Ltd · Legal Centre
The terms that govern everything we build.
One Master Subscription Agreement covers every CodeIQ product. Each product adds a short Schedule for anything specific to it, so a new product does not mean a new contract. Everything on this page is written for business customers in England and Wales.
Company information
Trading disclosures under the Companies Act 2006, s.82
Northampton NN4 6RX
United Kingdom
codeiqholdings.com
CodeIQ Holdings Ltd is the contracting entity for all products described on this page. Where a product is operated by a subsidiary of CodeIQ Holdings Ltd, the relevant Product Schedule will name that entity and these terms apply to it as though it were named throughout.
Master Subscription Agreement
Version 1.0 · Business customers only · Governed by the laws of England and Wales
Read this first
This Agreement is offered to businesses only. By entering into it you confirm you are acting in the course of a business, trade, craft or profession and not as a consumer. Nothing in this Agreement is intended to affect the statutory rights of a consumer, and if you are a consumer you may not use the Services under these terms.
This Agreement limits our liability to you and excludes certain warranties. Those clauses are set out in clause 11 and clause 12 and you should read them before agreeing.
1. The agreement and how it fits together
- This Master Subscription Agreement ("Agreement") is made between CodeIQ Holdings Ltd, company number 17454743, whose registered office is at 103 Battalion Drive, Northampton NN4 6RX ("CodeIQ", "we", "us") and the business entity identified on the Order Form ("Customer", "you").
- The Agreement consists of, in descending order of precedence where they conflict: (i) the Order Form; (ii) the applicable Product Schedule; (iii) the Data Processing Agreement; (iv) this Master Subscription Agreement; and (v) the Acceptable Use Policy, AI Use & Limitations Notice and Service Level Agreement. Where the Order Form departs from this Agreement it prevails only where it expressly says so and is signed by both parties.
- One agreement, many products. This Agreement governs every product and service made available by CodeIQ or any member of its group. Each product is described in a Product Schedule. Subscribing to an additional product adds that Schedule to this Agreement; it does not create a separate contract and does not require this Agreement to be renegotiated.
- We may introduce new products and Schedules at any time. A new Schedule binds you only in respect of a product you have ordered.
2. Definitions
- Authorised User — an individual employee, worker or contractor of the Customer whom the Customer permits to use the Services and for whom a subscription has been purchased.
- Customer Data — all data, documents, files, records and other content uploaded to, submitted to, or generated by the Customer or its Authorised Users through the Services, excluding Output and excluding Usage Data.
- Documentation — the user guides and technical documentation we make generally available for a Product.
- Intellectual Property Rights — patents, rights to inventions, copyright and related rights, trade marks, business names and domain names, goodwill, rights in designs, database rights, rights in computer software, rights to use and protect confidential information (including know-how and trade secrets), and all other intellectual property rights, in each case whether registered or unregistered and including all applications and rights to apply.
- Output — any analysis, extraction, summary, classification, score, draft, report or other material generated by the Services, including by an AI model, in response to Customer Data or an instruction from an Authorised User.
- Product — a software product made available by CodeIQ and described in a Product Schedule.
- Services — the Products ordered by the Customer, together with any support, hosting and related services we provide.
- Subscription Term — the initial term stated on the Order Form and each renewal term.
- Usage Data — technical and operational data generated by the use of the Services, such as event logs, error traces, performance measurements, feature usage counts and volumes, which does not identify the Customer, any Authorised User or any individual, and does not contain or reveal the substance of Customer Data.
3. Licence and right to use
- Subject to payment and to compliance with this Agreement, we grant the Customer a non-exclusive, non-transferable, non-sublicensable, revocable right during the Subscription Term for its Authorised Users to access and use the Services for the Customer's own internal business purposes, up to the limits stated on the Order Form.
- The Services are licensed, not sold. No right, title or interest in the Services or in any Intellectual Property Rights in them passes to the Customer.
- No source code is supplied, and nothing in this Agreement obliges us to supply, deposit in escrow, or provide access to source code.
- Access credentials are personal to each Authorised User and must not be shared. The Customer is responsible for all activity conducted under its account, including by anyone using credentials it has issued.
4. Restrictions
The Customer shall not, and shall not permit any other person to:
- copy, modify, translate, adapt or create derivative works of the Services;
- decompile, disassemble or reverse engineer any part of the Services, or attempt to derive their source code, structure, algorithms, prompts, model configuration or underlying ideas, except strictly to the extent that such activity cannot lawfully be prohibited under sections 50B or 296A of the Copyright, Designs and Patents Act 1988 and then only after giving us written notice and a reasonable opportunity to supply the interoperability information sought;
- use the Services, the Output, or any information derived from them to design, develop, train, improve, benchmark against or market any product or service that competes with any CodeIQ Product;
- use the Output or Customer Data processed by the Services to train, fine-tune or evaluate any machine learning model other than within the Services;
- rent, lease, lend, resell, sublicense, distribute, or make the Services available to any third party, or use them on behalf of or for the benefit of any third party, including as a bureau, agency or managed service, except as expressly permitted on the Order Form;
- remove, obscure or alter any proprietary notice, trade mark or attribution in the Services or the Output;
- scrape, crawl, harvest or use any automated means to extract data from the Services other than through an interface we have documented for that purpose;
- circumvent or attempt to circumvent any usage limit, credit allowance, access control, rate limit or security measure;
- publish or disclose to any third party the results of any performance, accuracy, load or security testing of the Services without our prior written consent; or
- use the Services otherwise than in accordance with the Acceptable Use Policy and the AI Use & Limitations Notice.
Each of the restrictions in this clause 4 is a condition of the licence granted in clause 3. Breach of any of them entitles us to suspend the Services immediately under clause 14.
5. Customer obligations
- The Customer shall provide all cooperation, access and information reasonably required for us to supply the Services, and is responsible for its own network, devices and internet connectivity.
- The Customer warrants that it has all rights, consents, licences and lawful bases necessary for Customer Data to be uploaded to and processed by the Services, including in respect of any document belonging to or containing information about a third party, and including any recording or transcript of a meeting.
- Where Customer Data includes a recording or transcript of any conversation, the Customer warrants that every participant was informed and that any consent required by law was obtained before the recording was made.
- The Customer shall keep its own independent copies of anything it uploads. The Services are not a system of record and are not a substitute for the Customer's own backups.
- The Customer shall notify us without undue delay of any unauthorised access to or use of the Services of which it becomes aware.
6. Intellectual property
- Ours stays ours. We and our licensors own all Intellectual Property Rights in and to the Services, the Documentation, the underlying software, models, prompts, methodologies, interfaces, designs, databases, trade marks and all improvements to any of them. Nothing in this Agreement transfers any of those rights, and all rights not expressly granted are reserved.
- Yours stays yours. The Customer retains all Intellectual Property Rights in Customer Data. The Customer grants us a non-exclusive, worldwide, royalty-free licence to host, copy, transmit, display and process Customer Data solely to the extent necessary to provide, secure, support and maintain the Services during the Subscription Term, and to comply with law.
- Output. Subject to payment and to clause 6.1, the Customer may use Output for its own internal business purposes. Output is generated in response to the Customer's data and instructions and may not be unique; substantially similar Output may be generated for other customers, and nothing in this Agreement grants the Customer exclusivity in Output.
- Feedback. If the Customer or any Authorised User gives us suggestions, feature requests, bug reports, ideas or other feedback about the Services, the Customer assigns to us with full title guarantee all Intellectual Property Rights in that feedback, free of charge, and we may use it without restriction or obligation. This clause does not give us any right in Customer Data.
- Usage Data. We may collect and use Usage Data to operate, secure, support, analyse and improve the Services and to produce statistics about our business. Usage Data as defined does not include Customer Data or Output, and we will not publish anything that identifies the Customer without its written consent.
- No model training. We do not use Customer Data or Output to train, fine-tune or otherwise improve any machine learning model, whether our own or a third party's, and we contract with our AI sub-processors on terms that prohibit them from doing so.
7. Confidentiality
- Each party shall keep confidential all information disclosed by the other that is marked confidential or that a reasonable person would regard as confidential, and shall use it only for the purposes of this Agreement. Our Confidential Information includes the Services, the Documentation, pricing, and any non-public information about how the Services work.
- Each party may disclose the other's Confidential Information to its personnel and professional advisers who need to know it and who are bound by equivalent obligations, and as required by law, a court or a regulator, giving the other party as much notice as is lawfully possible.
- These obligations do not apply to information that is or becomes public through no breach of this clause, was lawfully known before disclosure, is independently developed without use of the other's Confidential Information, or is lawfully received from a third party without restriction.
- These obligations continue for five years after the end of this Agreement, and indefinitely in respect of anything that constitutes a trade secret.
8. Fees, payment and tax
- Fees are as stated on the Order Form. Unless the Order Form says otherwise, fees are payable annually in advance, and subscriptions are for a minimum of the initial Subscription Term.
- Invoices are payable within 30 days of the date of invoice. Time for payment is of the essence.
- All fees are exclusive of VAT and any other applicable tax, which the Customer shall pay in addition at the prevailing rate.
- If any undisputed sum is not paid when due we may, without limiting our other rights: (i) charge interest on the overdue amount at 4% per annum above the Bank of England base rate from time to time, accruing daily, or claim interest and compensation under the Late Payment of Commercial Debts (Interest) Act 1998; and (ii) on 14 days' written notice, suspend the Services until payment is received.
- The Customer shall pay all sums due without set-off, counterclaim, deduction or withholding except as required by law.
- Fees are non-refundable except where this Agreement expressly says otherwise. Downgrading a subscription mid-term does not generate a refund or credit.
- We may increase fees with effect from the start of any renewal term on at least 60 days' written notice. If the Customer does not accept the increase it may elect not to renew by giving notice before the renewal date.
- Where a Product includes a credit, usage or volume allowance, that allowance is as stated on the Order Form or in the Product Schedule. Allowances do not carry over between periods unless expressly stated, and unused allowances have no cash value.
9. Warranties
- We warrant that: (i) we have the right to enter into this Agreement and to grant the licence in clause 3; (ii) the Services will be provided with reasonable care and skill by suitably qualified personnel; and (iii) during the Subscription Term the Services will perform materially in accordance with the Documentation.
- The Customer's sole and exclusive remedy for breach of clause 9.1(iii) is that we will, at our option and at our cost, correct the non-conformity within a reasonable period, or if we cannot do so within 30 days of written notice, terminate the affected Product and refund fees paid in advance for the unexpired part of the Subscription Term for that Product.
- The warranty in clause 9.1(iii) does not apply where the non-conformity arises from Customer Data, the Customer's own systems, use contrary to this Agreement or the Documentation, modification by anyone other than us, or a third-party service outside our control.
- Each party warrants that it will comply with all applicable laws in performing this Agreement, including the Bribery Act 2010, applicable anti-money-laundering, export control and sanctions laws, and applicable data protection law.
10. What we do not warrant
- No warranty of accuracy. The Services use artificial intelligence and probabilistic techniques. We do not warrant that any Output is accurate, complete, current, reliable or fit for any particular purpose. Confidence indicators displayed by the Services express a model's estimate of its own certainty; they are not a measure of verified accuracy and must not be relied on as one. The AI Use & Limitations Notice forms part of this Agreement and sets this out in full.
- Not advice. The Services do not provide legal, financial, tax, accounting, regulatory or professional advice of any kind. No part of the Output is a substitute for advice from a qualified professional, and no relationship of adviser and client arises between us and the Customer.
- Human decision-making. The Customer is solely responsible for every decision it takes, or omits to take, in reliance on the Services, and for verifying Output before relying on it for any purpose that carries legal, financial, contractual, regulatory or safety consequences.
- Availability. We do not warrant that the Services will be uninterrupted or error-free. Availability commitments, where they are given at all, are given only in the Service Level Agreement and only for the subscription tiers stated there.
- Except as expressly set out in clause 9, all warranties, conditions, terms and representations, whether express or implied by statute, common law or otherwise, including any implied term as to satisfactory quality, fitness for a particular purpose or conformity with description, are excluded to the fullest extent permitted by law.
11. Liability
- Nothing is excluded that cannot be. Nothing in this Agreement limits or excludes either party's liability for: death or personal injury caused by negligence; fraud or fraudulent misrepresentation; breach of the terms implied by section 12 of the Sale of Goods Act 1979 or section 2 of the Supply of Goods and Services Act 1982; or any other liability that cannot lawfully be limited or excluded.
- Excluded losses. Subject to clause 11.1, neither party is liable to the other, whether in contract, tort (including negligence), breach of statutory duty or otherwise, for any: loss of profit; loss of revenue; loss of business, contracts or opportunity; loss of anticipated savings; loss of or damage to goodwill or reputation; loss, corruption or inability to access data, to the extent it would have been prevented by the Customer maintaining its own backups as required by clause 5.4; wasted management or staff time; or any indirect or consequential loss, in each case however arising and whether or not foreseeable.
- Financial cap. Subject to clauses 11.1 and 11.4, each party's total aggregate liability arising out of or in connection with this Agreement in any period of 12 months is limited to the total fees paid or payable by the Customer under this Agreement in the 12 months immediately preceding the first event giving rise to the claim, or £5,000, whichever is the greater.
- The Customer's obligation to pay fees properly due, and the Customer's liability under the indemnity in clause 12.3, are not subject to the cap in clause 11.3.
- The Customer acknowledges that the fees have been set on the basis of the allocation of risk in this clause 11, that it has had the opportunity to take independent advice, and that a different allocation would carry a materially different price.
- No claim may be brought under this Agreement more than 12 months after the claiming party first became aware, or ought reasonably to have become aware, of the circumstances giving rise to it.
12. Indemnities
- Our IP indemnity. We will defend the Customer against any third-party claim that the Customer's permitted use of the Services infringes that third party's Intellectual Property Rights in the United Kingdom, and will pay damages finally awarded or amounts agreed in settlement by us, provided the Customer notifies us promptly in writing, gives us sole conduct of the defence and settlement, and provides reasonable assistance at our cost.
- Clause 12.1 does not apply to a claim arising from: Customer Data; Output, to the extent the claim arises from the Customer Data submitted or the instruction given; combination of the Services with anything not supplied by us; modification of the Services by anyone other than us; use outside this Agreement or the Documentation; or use of a version of the Services after we have notified the Customer of a modification or replacement that would have avoided the claim. If the Services become, or in our reasonable opinion are likely to become, the subject of such a claim, we may at our option modify them, replace them with functionally equivalent services, procure a licence, or terminate the affected Product on notice with a pro-rata refund of prepaid fees. Clauses 12.1 and 12.2 state our entire liability and the Customer's sole remedy for intellectual property infringement.
- Customer indemnity. The Customer shall indemnify us against all losses, liabilities, damages, costs and expenses (including reasonable legal fees) arising out of or in connection with: (i) any claim that Customer Data, or our processing of it in accordance with this Agreement, infringes the rights of a third party or breaches applicable law; (ii) any breach by the Customer of clause 4, clause 5.2, clause 5.3 or the Acceptable Use Policy; and (iii) any decision the Customer takes in reliance on the Output.
13. Term and renewal
- This Agreement begins on the date stated on the Order Form and continues for the initial Subscription Term.
- Unless the Order Form says otherwise, the Subscription Term renews automatically for successive periods equal to the initial term unless either party gives written notice of non-renewal at least 30 days before the end of the then-current term.
- Free, trial, sandbox and beta subscriptions may be terminated by either party at any time on notice, and clause 13.2 does not apply to them.
14. Suspension and termination
- We may suspend access to the Services, in whole or in part, immediately on notice where: the Customer is in breach of clause 4 or the Acceptable Use Policy; we reasonably believe the Services are being used in a way that threatens the security, integrity or availability of the Services or of any other customer; we are required to do so by law or by a supplier; or fees remain unpaid under clause 8.4. We will restore access promptly once the cause is resolved.
- Either party may terminate this Agreement or any affected Product immediately on written notice if the other: commits a material breach that is not remediable, or is remediable and not remedied within 30 days of written notice; or becomes insolvent, enters administration, has a receiver appointed, ceases or threatens to cease to carry on business, or suffers any analogous event.
- On termination or expiry: all licences end immediately; the Customer shall stop using the Services; and each party shall return or destroy the other's Confidential Information on request, save for copies required by law or held in routine backups, which remain subject to clause 7.
- Data on exit. For 30 days after termination or expiry, the Customer may export Customer Data using the export functions in the Services. After that period we will delete Customer Data in accordance with the Data Processing Agreement. We are not obliged to retain Customer Data beyond that period and will not be liable for deleting it in accordance with this clause.
- Termination does not affect any right or liability accrued before it. Clauses 2, 6, 7, 10, 11, 12, 14.3, 14.4, 14.5 and 16 survive.
15. Changes to the Services and these terms
- We may modify the Services from time to time, including adding, changing or removing features, provided we do not materially reduce the core functionality of a Product during a paid Subscription Term. Where we do materially reduce core functionality, the Customer may terminate the affected Product within 30 days of notice and receive a pro-rata refund of prepaid fees.
- We may amend this Agreement and the policies that form part of it. We will give at least 30 days' notice of any amendment that materially and adversely affects the Customer, by email to the account's registered address and by posting the revised version here. If the Customer objects, it may terminate the affected Product before the change takes effect; continued use after that date constitutes acceptance.
- Changes required by law, by a regulator or to address a security risk may take effect immediately.
16. General
- Assignment. The Customer may not assign, transfer, charge or deal in any other manner with any of its rights or obligations without our prior written consent. We may assign or novate this Agreement to any member of our group, or to a purchaser of the business or assets to which it relates, on notice.
- Subcontracting. We may subcontract performance, including to the sub-processors listed in this Legal Centre, and remain responsible for their acts and omissions in performing the Services.
- Non-solicitation. During the Subscription Term and for six months afterwards, neither party shall knowingly solicit for employment any individual employed or engaged by the other who has been directly involved in the Services, except through a general advertisement not targeted at that individual.
- Publicity. Neither party may use the other's name or logo in publicity without prior written consent, except that we may identify the Customer as a customer in a list of customers where the Customer has given written consent, which it may withdraw on 30 days' notice.
- Force majeure. Neither party is liable for any failure or delay caused by an event beyond its reasonable control, including failure of public telecommunications networks, failure of a third-party hosting or AI provider, cyber attack, act of government, epidemic, industrial action not involving that party's own workforce, fire, flood or natural disaster. If the event continues for more than 60 days either party may terminate on notice.
- Notices. Notices must be in writing and sent to our registered office or to info@codeiqholdings.co.uk, and to the Customer at the address or email on the Order Form. Email notices are deemed received at 9.00am on the next business day after sending, provided no delivery failure is received.
- Entire agreement. This Agreement constitutes the entire agreement between the parties and supersedes all previous agreements, representations and understandings relating to its subject matter. Each party acknowledges that it has not relied on any statement or representation not set out in this Agreement, but nothing limits liability for fraudulent misrepresentation. Any purchase order, supplier portal terms or standard conditions put forward by the Customer have no effect.
- Waiver and severance. No failure or delay in exercising a right is a waiver of it. If any provision is held invalid or unenforceable, it shall be modified to the minimum extent necessary to make it enforceable, or if that is not possible, deleted, and the remainder shall continue in force.
- No partnership. Nothing in this Agreement creates a partnership, joint venture, agency or employment relationship.
- Third parties. A person who is not a party to this Agreement has no rights under the Contracts (Rights of Third Parties) Act 1999 to enforce any of its terms, save that any member of our group may enforce clauses 6, 7 and 11.
- Governing law and jurisdiction. This Agreement and any dispute or claim arising out of it, including non-contractual disputes, are governed by the law of England and Wales. The parties submit to the exclusive jurisdiction of the courts of England and Wales.
Product Schedule 1 — ContractIQ
Forms part of the Master Subscription Agreement
1. Description
ContractIQ is a web-based application with integrated artificial intelligence. It ingests contracts, purchase orders, statements of work, tracking spreadsheets, scanned documents and meeting transcripts, extracts structured information from them, and presents that information as contract records, registers, portfolio views, scores and reports. It includes a conversational interface for asking questions of a document portfolio.
2. What ContractIQ is not
- ContractIQ is a procurement and commercial-management tool. It is not a legal advice service, a contract lifecycle management system of record, a signing or execution platform, or a compliance certification.
- Nothing produced by ContractIQ constitutes legal advice. Reviewing a contract with ContractIQ is not a substitute for review by a qualified lawyer, and the Customer must not represent to any third party that it is.
- Dates, deadlines, values, obligations and risk scores presented by ContractIQ are extracted by automated means and may be wrong, missing or misattributed. The Customer must verify any date or figure against the source document before acting on it, and in particular before allowing a notice period or renewal deadline to pass.
3. Editions and allowances
ContractIQ is offered in the editions stated on the Order Form. Each edition carries a credit allowance which is consumed by chargeable operations. The current consumption rates, the operations that consume no credits, and the allowance for each edition are set out in the Documentation and on the Order Form. We may change consumption rates on 30 days' notice with effect from the next renewal.
4. Transcripts and recordings
- Where the Customer uploads a recording or transcript, the Services require an Authorised User to confirm that all necessary notices were given and consents obtained. That confirmation is recorded with the identity of the user, the time, and the version of the consent wording.
- That confirmation is a warranty by the Customer under clause 5.3 of the Master Subscription Agreement. We do not verify it and we do not accept responsibility for the lawfulness of any recording the Customer uploads.
5. Optical character recognition
Scanned documents are processed using optical character recognition. Recognition of poor-quality scans, handwriting, stamps, marginalia, tables and signatures is unreliable. Where text cannot be extracted reliably the Services will indicate this, but the absence of an indication is not a warranty that recognition was complete or correct.
6. Current status
Stated plainly
ContractIQ is pre-launch. It has been built and tested but has not yet been operated across a paying customer's live contract portfolio. We publish no accuracy percentage because we have not measured accuracy against a labelled reference set, and a model's confidence score is not the same thing. Any customer contracting with us before we do publish a measured figure is doing so on that basis, and we will say so again in writing before taking payment.
Acceptable Use Policy
Forms part of the Master Subscription Agreement · Breach permits immediate suspension
This policy applies to every person who uses any CodeIQ service. It exists so that one customer's conduct cannot damage another's service, our infrastructure, or anyone's rights.
1. You must not use the Services to
- break any law, or facilitate anyone else in doing so;
- infringe any person's intellectual property, privacy, confidentiality or contractual rights;
- upload material you do not have the right to upload, including a third party's confidential documents obtained without authority;
- upload, store or transmit any material that is unlawful, defamatory, harassing, abusive, obscene, or that depicts or facilitates the abuse or exploitation of children;
- upload any virus, worm, trojan, logic bomb or other malicious code;
- impersonate any person or misrepresent your affiliation with any person or organisation;
- send unsolicited commercial communications;
- process special category personal data, criminal offence data, or payment card data, unless the Order Form expressly permits it and appropriate safeguards have been agreed in writing;
- interfere with, disrupt, probe, scan or test the vulnerability of the Services or any network or system connected to them, except strictly in accordance with our Responsible Disclosure Policy; or
- place an unreasonable or disproportionate load on the Services, including by exceeding documented rate limits or by automating requests beyond a documented interface.
2. Restrictions specific to AI features
- You must not use Output as the sole basis for any decision that produces legal effects concerning an individual, or that similarly significantly affects an individual, without meaningful human review by a person with the authority and competence to change the outcome.
- You must not present Output to any third party as though it were human-authored professional advice, or as though it had been verified by us.
- You must not use the Services to generate material designed to deceive, including fabricated records, forged documents, or content falsely attributed to a real person or organisation.
- You must not attempt to extract, reconstruct or reverse engineer any system prompt, model weight, model configuration or training data through the Services, including by prompt injection.
- You must not use the Services, or Output from them, to develop, train, benchmark or market any competing product, as set out in clause 4 of the Master Subscription Agreement.
3. Enforcement
We may investigate suspected breaches and may suspend or restrict access immediately, without notice where the risk requires it. We will tell you what we have done and why as soon as we reasonably can. Repeated or serious breach is a material breach of the Agreement under clause 14.2. Where we are required to report conduct to a law enforcement agency or regulator, we will do so.
4. Reporting
Report misuse to info@codeiqholdings.co.uk. Report security vulnerabilities under the Responsible Disclosure Policy instead.
AI Use & Limitations Notice
Forms part of the Master Subscription Agreement · Applies to every CodeIQ product
Every CodeIQ product is a web-based application with artificial intelligence built into it. This notice explains what that means, what it cannot do, and where responsibility sits. It is written to be understood, not to be skipped.
1. How the AI is used
- Documents and text you supply are sent to one or more third-party large language models, operated by the providers listed in our Sub-processor list, to be read and interpreted.
- The models return structured information, summaries, classifications, drafts and answers. That is the Output.
- Output is generated probabilistically. The same input may not produce identical output every time.
- Your content is not used to train, fine-tune or improve any model. Our AI providers are engaged on terms that prohibit training on customer content.
2. What AI cannot be relied on to do
- It can be confidently wrong. Language models produce fluent, well-formatted output whether or not the underlying reading was correct. Presentation quality carries no information about accuracy.
- It can omit. A clause, date, party or obligation that exists in a document may simply not appear in the Output. An empty field means "not found", never "not present".
- It can invent. A model may produce a value, a date or a quotation that does not appear in the source. Where the Services show a quoted source line, that line is intended to let you check; checking it is your responsibility, not ours.
- Confidence is not accuracy. Where the Services display a confidence score, it expresses the system's own estimate of its certainty. It is not a measured accuracy rate, it has not been validated against a labelled reference set, and it must never be presented to anyone as though it were.
- It is not current. Models are trained to a cut-off date and have no knowledge of events after it, and no knowledge of your organisation beyond what you supply.
3. Your obligations
- Keep a human in the loop. Verify Output against the source before relying on it for anything with legal, financial, contractual, regulatory or safety consequences.
- Do not use Output as the sole basis for a decision that significantly affects an individual, without meaningful human review.
- Tell your own people that the Services use AI and that Output must be checked.
- Where you or your customers are subject to obligations concerning AI transparency, automated decision-making or record-keeping, satisfying those obligations in respect of your own use of the Services is your responsibility. We will provide reasonable information to help.
4. Regulatory position
- Our products are general-purpose business tools. We do not intend them to be used as, and they must not be used as, an AI system in any use case classified as high risk under the EU Artificial Intelligence Act, including employment, creditworthiness, essential services, education and law enforcement uses.
- If you deploy our Services in the European Union, transparency obligations for deployers of AI systems may apply to you directly. Those obligations are yours and not ours, and you should take your own advice.
- Under UK data protection law, decisions based solely on automated processing that produce legal or similarly significant effects on individuals are subject to specific safeguards. Our Services are not designed to make such decisions and you must not configure them to.
- We will update this notice as the regulatory position develops.
5. No measured accuracy claim
We do not publish an accuracy percentage
Measuring accuracy properly requires a labelled reference set of documents where the correct answer is known independently, of sufficient size, and dated. Until we have built one, any percentage we published would be a guess dressed as a measurement. We will publish a figure when we can show the workings, including the sample size and the date. Until then, treat any accuracy figure you see quoted anywhere for any comparable product with the same scepticism.
Service Level Agreement
Applies to paid subscriptions only · Does not apply to free, sandbox, trial or beta use
1. Availability commitment
We will use commercially reasonable efforts to make the Services available at least 99.5% of the time in each calendar month, measured as the percentage of minutes in the month during which the Services are reachable and able to accept requests, excluding Excluded Downtime.
2. Excluded Downtime
- Planned maintenance notified at least 48 hours in advance, up to 8 hours per calendar month, scheduled outside 08:00–18:00 UK time on business days wherever practicable.
- Emergency maintenance required to address a security risk or prevent imminent service failure.
- Failure or degradation of a third-party hosting, network, authentication or AI provider outside our reasonable control.
- Anything caused by the Customer's own systems, network, configuration, data or breach of the Agreement.
- Suspension permitted under clause 14.1 of the Master Subscription Agreement.
- Force majeure.
3. Service credits
| Monthly availability | Credit |
|---|---|
| 99.5% or above | None |
| Below 99.5% but at or above 99.0% | 5% of that month's fees for the affected Product |
| Below 99.0% but at or above 95.0% | 10% of that month's fees for the affected Product |
| Below 95.0% | 25% of that month's fees for the affected Product |
Credits must be claimed in writing within 30 days of the end of the month concerned, are applied against future fees, are not payable in cash, and are capped at 25% of the monthly fees for the affected Product in any month. Service credits are the Customer's sole and exclusive financial remedy for any failure to meet the availability commitment. Where availability falls below 95.0% in each of three consecutive months, the Customer may terminate the affected Product on notice with a pro-rata refund of prepaid fees.
4. AI processing times
Analysis and generation times depend on document size, queue depth and third-party model availability, and are not subject to any commitment. Where a queued job fails, it is retried automatically; where it cannot be completed, the credits consumed are returned. No service level applies to processing time.
5. Support
| Severity | Meaning | Target first response |
|---|---|---|
| 1 — Critical | Service wholly unavailable or data at risk | 4 business hours |
| 2 — High | Major function unusable, no workaround | 1 business day |
| 3 — Normal | Function impaired, workaround exists | 3 business days |
| 4 — Low | Question, guidance or enhancement request | 5 business days |
Support is provided in English by email to info@codeiqholdings.co.uk, during business hours (09:00–17:30 UK time, Monday to Friday, excluding England and Wales bank holidays). These are target response times, not resolution times, and they are targets rather than contractual commitments carrying a remedy.
Beta & Early Access Terms
Applies to any Product or feature labelled beta, preview, early access, sandbox or trial
- Beta features are made available as is and as available. Clause 9.1(iii) of the Master Subscription Agreement, the Service Level Agreement and all warranties are excluded in respect of them, to the fullest extent permitted by law.
- Beta features may be incomplete, may change materially, may produce unreliable results, and may be withdrawn at any time without notice and without liability.
- Data held in a beta, sandbox or trial environment may be deleted at any time. Do not use a beta environment as the only home for anything you need.
- Do not submit special category personal data, criminal offence data, payment card data, or material of high commercial sensitivity to a beta feature.
- The existence, functionality, performance and any results of a beta feature are our Confidential Information under clause 7 until we announce the feature publicly.
- All feedback about a beta feature is assigned to us under clause 6.4 of the Master Subscription Agreement.
- Subject to clause 11.1 of the Master Subscription Agreement, our total aggregate liability in connection with any beta, free, sandbox or trial use is limited to £100.
- Where a founding-member, early-access or introductory offer is made, its terms, duration and what happens at the end of it are stated at the point of sign-up and in the Order Form. Where such an offer converts to a paid plan, we will give at least 30 days' notice in writing before the first payment is taken.
Website Terms of Use
Applies to codeiqholdings.co.uk, codeiqholdings.com and any subdomain
- This website is operated by CodeIQ Holdings Ltd. By using it you accept these terms.
- All content on this website, including text, layout, graphics, the CodeIQ name, the Aperture mark and all other branding, is owned by or licensed to us and protected by intellectual property law. You may view it, and print or download extracts for your own internal business use, provided you do not modify them and you keep all proprietary notices intact. You may not otherwise copy, republish, distribute, frame, mine or exploit any part of it without our written consent.
- The content of this website is provided for general information only. It does not constitute advice, and it is not an offer capable of acceptance. We give no warranty that it is accurate, complete or current, and we may change it at any time without notice.
- Where this website links to a third-party site, we do so for convenience and accept no responsibility for that site or its content.
- We do not guarantee that this website will be available uninterrupted. We may suspend, withdraw or restrict it without notice.
- You must not misuse this website by knowingly introducing malicious code, attempting to gain unauthorised access to it or to any server or database connected to it, or attacking it by denial-of-service. Doing so may be a criminal offence under the Computer Misuse Act 1990 and will be reported.
- Subject to clause 11.1 of the Master Subscription Agreement, and to the fullest extent permitted by law, we exclude all liability arising from use of this website or reliance on its content.
- These terms are governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction.
Privacy Policy
Controller: CodeIQ Holdings Ltd · UK GDPR, Data Protection Act 2018 and the Data (Use and Access) Act 2025
1. Who we are
CodeIQ Holdings Ltd, company number 17454743, registered office 103 Battalion Drive, Northampton NN4 6RX, is the controller of the personal data described in this policy. Our registration reference with the Information Commissioner's Office is ICO:00015500673. Contact us about anything in this policy at info@codeiqholdings.co.uk.
Where our customers upload documents containing personal data into our Services, we act as a processor on their behalf and not as a controller. The Data Processing Agreement below governs that relationship. This Privacy Policy concerns the personal data for which we are the controller: website visitors, enquirers, account holders and suppliers.
2. What we collect and why
| Who | What | Why | Lawful basis |
|---|---|---|---|
| Website visitors | IP address, device and browser information, pages viewed, referring page | Operating and securing the site, understanding which pages are used | Legitimate interests — running and protecting our website |
| Enquirers | Name, email, employer, role, the content of your enquiry | Replying to you, and following up about the thing you asked about | Legitimate interests — responding to a request you made |
| Account holders | Name, work email, role, organisation, authentication records, sign-in events, support correspondence | Providing the Services, authenticating users, security, support, billing | Performance of a contract; legitimate interests in security |
| Marketing recipients | Name, email, organisation, engagement records | Sending information about our products | Consent, or legitimate interests where you are an existing business contact. You can opt out at any time |
| Suppliers and contacts | Name, contact details, correspondence | Managing the relationship | Performance of a contract; legitimate interests |
| Everyone | Records necessary for accounting, tax and legal compliance | Meeting our statutory obligations | Legal obligation |
Where we rely on legitimate interests, we have carried out a balancing assessment and are satisfied that our interests do not override your rights. You can ask us for a summary of that assessment.
3. What we do not do
- We do not sell personal data, and we do not share it with third parties for their own marketing.
- We do not use your personal data, or our customers' uploaded content, to train machine learning models.
- We do not make decisions producing legal or similarly significant effects about you by solely automated means.
4. Who we share it with
We share personal data with the service providers listed in our Sub-processor list, each of which processes it only on our instructions and under a written contract. We may also disclose personal data to our professional advisers, to a purchaser in connection with a sale of our business, and where we are required to by law, a court or a regulator.
5. International transfers
Some of our providers are located outside the United Kingdom, principally in the United States and the European Economic Area. Where personal data leaves the UK we rely on UK adequacy regulations where they apply, and otherwise on the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment. Details for each provider are in the Sub-processor list.
6. How long we keep it
| Record | Retention |
|---|---|
| Website and security logs | Up to 12 months |
| Enquiries that do not become customers | 24 months from last contact |
| Account and user records | Duration of the account, then 12 months |
| Customer content held on behalf of a customer | As set out in the Data Processing Agreement — 30 days after termination, then deleted |
| Contracts, invoices and accounting records | 7 years, to meet statutory requirements |
| Marketing preferences and opt-outs | Indefinitely, so we can honour the opt-out |
7. Your rights
You have the right to be informed; to access a copy of your personal data; to have inaccurate data corrected; to have data erased in certain circumstances; to restrict processing; to data portability; to object to processing based on legitimate interests; and to object to direct marketing at any time. Where we rely on consent, you may withdraw it at any time without affecting processing carried out before withdrawal.
To exercise any right, email info@codeiqholdings.co.uk. We will respond within one month, and will tell you if we need to extend that period. We may ask for information to confirm your identity.
8. Complaints
If you are unhappy with how we have handled your personal data, tell us first using the Complaints Procedure below. We will acknowledge your complaint within 30 days and respond without undue delay. You also have the right to complain to the Information Commissioner's Office at ico.org.uk, by telephone on 0303 123 1113, or at Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. We would rather you came to us first, but you do not have to.
9. Changes
We will post any change to this policy here and, where the change is material and we hold your contact details, tell you directly. The version and date are shown in the Changes section below.
Data Processing Agreement
Forms part of the Master Subscription Agreement · Article 28 UK GDPR terms
This DPA applies where we process personal data contained in Customer Data on the Customer's behalf. In it, the Customer is the controller and CodeIQ is the processor. Terms defined in the Master Subscription Agreement have the same meaning here. Data protection terms have the meaning given in the UK GDPR and the Data Protection Act 2018 as amended by the Data (Use and Access) Act 2025.
1. Scope of processing (Annex A)
| Item | Detail |
|---|---|
| Subject matter | Provision of the Services described in the applicable Product Schedule |
| Duration | The Subscription Term, plus the 30-day export window under clause 14.4 |
| Nature and purpose | Hosting, storage, optical character recognition, automated extraction and analysis using AI models, indexing, search, reporting and export, all on the Customer's instructions |
| Types of personal data | Whatever the Customer chooses to upload. Typically: names, job titles, business contact details and signatures of individuals named in contracts and commercial documents; names and speech of participants in uploaded meeting transcripts; and account data for Authorised Users |
| Categories of data subject | The Customer's personnel; personnel of the Customer's suppliers and counterparties; individuals named in uploaded documents; participants in uploaded recordings |
| Special category data | Not permitted without prior written agreement (see Acceptable Use Policy, clause 1(h)) |
2. Our obligations
- We shall process personal data only on the Customer's documented instructions, which are constituted by the Agreement and the Customer's use of the Services, unless required otherwise by law, in which case we will tell the Customer first unless the law prohibits it.
- We shall tell the Customer if, in our opinion, an instruction infringes data protection law.
- We shall ensure that everyone authorised to process personal data is subject to a duty of confidentiality.
- We shall implement appropriate technical and organisational measures as set out in Annex B and in the Security Statement.
- We shall assist the Customer, taking into account the nature of the processing and the information available to us, in responding to requests from data subjects, and in complying with its obligations concerning security, breach notification, data protection impact assessments and prior consultation.
- We shall notify the Customer without undue delay, and in any event within 48 hours, of becoming aware of a personal data breach affecting Customer Data, and shall provide the information reasonably required for the Customer to meet its own notification obligations.
- At the Customer's choice, we shall delete or return personal data at the end of the provision of the Services, and delete existing copies, except where storage is required by law. Our standard practice is set out in clause 14.4 of the Master Subscription Agreement.
- We shall make available the information necessary to demonstrate compliance with this DPA and allow for and contribute to audits, on reasonable written notice, not more than once in any 12 months unless a breach has occurred or a regulator requires it, during business hours, subject to confidentiality, at the Customer's cost, and in a manner that does not disrupt the Services or compromise the security of other customers.
3. Sub-processors
- The Customer gives general written authorisation for us to appoint sub-processors. The current list is published in this Legal Centre.
- We will give at least 30 days' notice before adding or replacing a sub-processor, by updating the list and, where the Customer has subscribed to notifications, by email. The Customer may object on reasonable data protection grounds within that period. If we cannot resolve the objection, the Customer may terminate the affected Product on notice with a pro-rata refund of prepaid fees, and that is the Customer's sole remedy.
- We shall impose on each sub-processor obligations equivalent to those in this DPA and remain fully liable to the Customer for their performance.
4. International transfers
Where we transfer personal data outside the United Kingdom we will do so only where a UK adequacy regulation applies, or under the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, supported by a transfer risk assessment, or under another lawful transfer mechanism. The Customer authorises us to enter into those instruments on its behalf with our sub-processors where required.
5. Controller obligations
The Customer warrants that it has a lawful basis for the processing it instructs, that it has provided all necessary privacy information to data subjects, and that its instructions comply with data protection law. The Customer is responsible for the accuracy, quality and legality of Customer Data and for the means by which it acquired it.
6. Security measures (Annex B)
- Encryption of data in transit using TLS, and encryption of data at rest.
- Role-based access control, with least-privilege access and enforcement at the database layer.
- Multi-factor or one-time-code authentication for account access, and support for identity provider sign-in.
- Logical separation of each customer's data, enforced by row-level access policies.
- Audit logging of access and of material changes to records.
- Regular application of security patches to dependencies and infrastructure.
- Documented procedures for incident detection, escalation and notification.
- Contractual prohibition on AI sub-processors retaining or training on customer content.
The measures in Annex B may change as the Services develop. We will not make a change that materially reduces the overall level of security.
7. Liability
Each party's liability under this DPA is subject to the limitations and exclusions in clause 11 of the Master Subscription Agreement, save to the extent that the law does not permit those limitations to apply.
Sub-processors
Current as at the date shown below · 30 days' notice given before any addition or change
| Provider | Purpose | Location | Transfer mechanism |
|---|---|---|---|
| Anthropic PBC | Large language model inference — reading and interpreting documents, generating analysis and answers | United States | UK Addendum to the EU SCCs, with a transfer risk assessment. Engaged on terms prohibiting training on customer content |
| Supabase | Database, authentication, file storage and background job processing | Confirm the project region | UK adequacy where the region is in the EEA; otherwise UK Addendum to the EU SCCs |
| Website and application hosting provider | Hosting the website and application front end, content delivery | To confirm | To confirm |
| Email provider | Transactional and business email | To confirm | To confirm |
| Payment provider | Collecting subscription payments. We do not store payment card details | To confirm | To confirm |
Optical character recognition of scanned documents is performed in the user's own browser and the image is not sent to a third party for that step.
To be notified of changes to this list, email info@codeiqholdings.co.uk asking to be added to the sub-processor notification list.
Cookie Policy
Privacy and Electronic Communications Regulations 2003 · UK GDPR · Version 1.1
1. What this site actually does today
The honest position
This website sets no cookies at all beyond one small entry in your browser's local storage that records your answer to the cookie banner. Nothing is loaded from an advertising network, there is no cross-site tracking, and no analytics provider is in use at the date of this version. If that changes, this page changes first and the banner asks you again.
2. Categories, and what consent each needs
| Category | What it is for | Consent | In use today |
|---|---|---|---|
| Strictly necessary | Signing in and staying signed in, security, load balancing, and remembering your cookie choice | Not required — exempt under PECR regulation 6(4) | Yes — consent record only |
| Functional | Remembering a preference such as a chosen view or filter | Required before anything is set | No |
| Analytics | Counting visits and understanding which pages are read | Required before anything is set | No |
| Advertising and cross-site tracking | We do not do this and do not intend to | — | No, and not planned |
3. What we store
| Name | Type | Purpose | Expires |
|---|---|---|---|
codeiq_consent | Local storage, not a cookie | Records whether you accepted, rejected or customised, and when. Without it we would have to ask on every page | 6 months, after which you are asked again |
That entry contains only your choices and a timestamp. It contains no identifier, is never sent to us or to anyone else, and stays in your browser.
4. Your choices
- The banner appears before anything optional is set, and Accept all and Reject all are given equal prominence. Rejecting is exactly as easy as accepting, which is what the law requires and what most sites still get wrong.
- Choosing nothing and closing the banner sets nothing optional. Silence is not consent.
- You can change your mind at any time using the Cookie settings link in the footer of every page.
- You will be asked again after six months, and immediately if we add a category or a provider.
- You can also block or delete cookies and site data in your browser. Strictly necessary items cannot be blocked without parts of the service ceasing to work.
5. If we add analytics
When we add an analytics provider we will: name it in this table with its cookie names and durations; give at least the notice this Legal Centre requires; and load nothing until the analytics toggle is switched on. A script that loads and then waits for consent has already set its cookie, and that is the breach — so ours does not load at all.
6. Third parties
Our sign-in provider sets cookies necessary to keep an authenticated user signed in to the products; these are strictly necessary and exempt. Our public website loads a stylesheet from Google Fonts, which means your browser makes a request to Google's servers; that request carries your IP address but sets no cookie on this site. We permit no third party to set advertising or cross-site tracking cookies on any CodeIQ property.
7. Questions
Email info@codeiqholdings.co.uk. Complaints about cookies or tracking can also go to the Information Commissioner's Office at ico.org.uk.
Intellectual Property Notice
1. What we own
All Intellectual Property Rights in the CodeIQ platform, in each Product, and in all software, source code, object code, databases, data models, prompts, model configurations, interfaces, workflows, methodologies, documentation, designs, copy and branding associated with them, are owned by CodeIQ Holdings Ltd or licensed to it. This includes the name CodeIQ, the name ContractIQ, the Aperture device mark, and the get-up of our products and websites, whether or not registered. © CodeIQ Holdings Ltd. All rights reserved.
2. What is not permitted
- Copying, adapting or redistributing our software, interfaces, documentation or copy.
- Reverse engineering, decompiling or disassembling any part of our products, except as clause 4(b) of the Master Subscription Agreement permits.
- Using our names, marks or get-up in a way likely to cause confusion as to origin, endorsement or association, including in a domain name, app name, social account or advertising keyword.
- Copying the structure, wording or presentation of the documents in this Legal Centre, which are themselves original literary works protected by copyright.
3. Open source
Our products incorporate third-party open-source components, each licensed under its own terms. Nothing in our terms restricts any right you have under an open-source licence in respect of a component supplied under it. A list of components and licences is available on request to info@codeiqholdings.co.uk.
4. If you think we have infringed your rights
Write to info@codeiqholdings.co.uk marked "IP notice" with: your name and contact details; identification of the right you rely on and evidence of your ownership of it; identification of the material you say infringes it and where it appears; a statement that you believe in good faith that the use is not authorised; and a statement that the information in your notice is accurate. We will investigate and respond, and will remove or disable material where the notice is well founded.
5. Reporting infringement of our rights
If you become aware of anyone copying our software, branding or content, or presenting our products as their own, please tell us at the same address. We take the protection of our rights seriously and pursue infringement.
Security Statement
Written to be accurate rather than impressive
1. What is in place
- All traffic encrypted in transit with TLS; data encrypted at rest.
- Authentication with verified email, one-time codes, and support for Google and Microsoft identity sign-in. Passwords are never stored in plain text.
- Four access roles, enforced in the database rather than only in the interface, so a user cannot reach another customer's data by manipulating a request.
- Row-level security policies isolating each customer's workspace.
- Audit trail of access and of material changes to records.
- AI providers engaged on zero-retention terms, contractually prohibited from training on customer content.
- Optical character recognition performed in the browser, so scanned images are not sent to a third-party OCR service.
- Credits for chargeable AI operations are deducted server-side after success, not client-side, so the client cannot be manipulated to obtain free processing.
2. What is not in place, stated plainly
No certification yet
We hold no SOC 2 report, no ISO 27001 certificate and no Cyber Essentials certification at the date of this statement. We have not commissioned an independent penetration test. We do not currently offer single sign-on with SAML, a customer-managed encryption key, or a contractual data residency guarantee.
If any of those is a requirement for your organisation, tell us before you buy rather than after. We would rather lose the sale than be found out in a due diligence questionnaire, and we will tell you honestly what is planned and what is not.
3. Incident response
Where we become aware of a security incident affecting customer data we will investigate immediately, contain it, notify affected customers without undue delay and in any event within 48 hours as required by the Data Processing Agreement, and provide the information customers need to meet their own obligations. We will say what happened, what data was affected, and what we have changed.
4. Your part
Use unique credentials, do not share accounts, remove users who leave, and use the roles provided rather than granting everyone administrative access. Most incidents in services of this kind begin with a credential, not a vulnerability.
Responsible Disclosure Policy
If you believe you have found a security vulnerability in any CodeIQ service, we want to hear about it and we will not take action against you for telling us, provided you act in good faith and within this policy.
1. How to report
Email info@codeiqholdings.co.uk with the subject line "Security". Include enough detail to reproduce the issue, its impact, and how we can contact you. We will acknowledge within 5 business days, keep you informed, and credit you publicly if you would like that and the report is valid.
2. What we ask
- Give us reasonable time to investigate and fix before disclosing to anyone else.
- Do not access, modify, delete or exfiltrate data belonging to anyone else. If you encounter personal data, stop and tell us.
- Do not degrade the service: no denial-of-service, no automated scanning at volume, no social engineering of our people or suppliers, no physical attacks.
- Test only against your own account and data.
3. Our undertaking
Where you comply with this policy, we will not pursue or support any legal claim against you in connection with your research, including under the Computer Misuse Act 1990, and we will say so to any third party who asks. We do not currently operate a paid bug bounty.
4. Out of scope
Reports generated solely by an automated scanner without demonstrated impact; missing security headers with no exploitable consequence; issues in third-party services we do not control; social engineering; and anything requiring physical access to a user's unlocked device.
Complaints Procedure
Includes the data protection complaints route required from June 2026
- Tell us. Email info@codeiqholdings.co.uk with "Complaint" in the subject line, or write to us at our registered office. Tell us what happened, when, and what you would like us to do about it.
- We acknowledge. We will acknowledge every complaint in writing. Data protection complaints are acknowledged within 30 days of receipt, as required by the Data (Use and Access) Act 2025.
- We investigate. We aim to give a substantive response within 30 days, and in any event without undue delay. Where a matter is complex we will tell you why more time is needed and when to expect our response.
- If you are still unhappy. Ask for the matter to be reviewed by a director. We will respond within a further 20 business days.
- External routes. For data protection complaints you may complain to the Information Commissioner's Office at any time, at ico.org.uk or 0303 123 1113. For contractual disputes, the parties may agree to mediation before issuing proceedings, and nothing in this procedure affects either party's right to bring a claim.
Changes & versions
The documents in this Legal Centre are versioned together. When we change any of them we will record it here, and where clause 15.2 of the Master Subscription Agreement requires it, we will give notice before the change takes effect.
| Version | Date | Change |
|---|---|---|
| 1.2 | 12 September 2026 | ICO registration reference inserted |
| 1.1 | 11 September 2026 | Cookie Policy rewritten to match the consent banner now implemented; consent banner added to all pages |
| 1.0 | 11 September 2026 | First publication |
Before this goes live
The ICO registration reference is now in place. The items still marked in orange on this page must be filled before publication: the VAT position, the hosting, email and payment providers in the sub-processor list, and the Supabase project region.
These documents have been drafted to reflect standard market practice for a UK business-to-business software company and current UK law, but they have not been reviewed by a solicitor. They should be before you take a payment or sign a customer. The clauses that most need a professional eye are the liability cap and exclusions, the indemnities, and the data processing terms.