Third Party Index

Snapshot 20791

Document
Terms
URL
https://opengrc.com/terms-of-service
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
70284 bytes
SHA-256 (raw)
d68f4fdbd50aef71450c0f14bb6648f79dc02ff3c26b9eebd946558d4babd5de
SHA-256 (normalized text)
0ffc05617a018842bdcce3a495ce549b8c1a1369f6db955dd8454351c2aaf517

Normalized text

Scripts and page chrome removed; this is what change detection compares.

™
Schedule a Demo
Terms of Service
January 1, 2026
Last Updated: September 23, 2026
These Terms of Service (“Terms” or “Agreement”) constitute a legally binding agreement between you and OpenGRC, LLC, a Florida limited liability company (“OpenGRC,” “Company,” “we,” “us,” or “our”). These Terms govern your access to and use of the OpenGRC software-as-a-service platform, including any related websites, applications, APIs, and professional services (collectively, the “Service”).
BY CLICKING “I AGREE,” CREATING AN ACCOUNT, ACCESSING THE SERVICE, OR OTHERWISE INDICATING YOUR ACCEPTANCE, YOU ACKNOWLEDGE THAT YOU HAVE READ, UNDERSTOOD, AND AGREE TO BE BOUND BY THESE TERMS. If you are entering into this Agreement on behalf of a company, organization, or other legal entity (“Customer”), you represent and warrant that you have the authority to bind such entity to these Terms, in which case “you” and “your” shall refer to such entity.
1. Definitions
“Affiliate” means, with respect to a party, any entity that directly or indirectly controls, is controlled by, or is under common control with such party, where “control” means the ownership of more than fifty percent (50%) of the voting securities or equivalent ownership interest of such entity.
“Authorized User” means any individual who is authorized by Customer to access and use the Service under Customer’s account.
“Customer Data” means any data, information, content, or materials that Customer or its Authorized Users upload, submit, store, or transmit through the Service.
“Documentation” means the user guides, help files, and other technical documentation made available by OpenGRC describing the features and functionality of the Service.
“Fees” means the amounts payable by Customer for the Service as set forth in an Order Form or the applicable pricing page.
“Intellectual Property Rights” means all patent rights, copyrights, trademark rights, trade secret rights, and any other proprietary rights recognized by law.
“Order Form” means any ordering document, online subscription page, or written agreement that specifies the Service, subscription term, fees, and other terms applicable to Customer’s use of the Service.
“Professional Services” means implementation, configuration, training, consulting, or other professional services provided by OpenGRC as set forth in a Statement of Work or Order Form.
“Security Incident” means any confirmed unauthorized access to, or acquisition, disclosure, alteration, or loss of, Customer Data while in the possession or control of OpenGRC or its Subprocessors.
“Service” means the OpenGRC software-as-a-service platform, including all features, functionality, updates, and improvements made available by OpenGRC.
“Subprocessor” means any third party engaged by OpenGRC that processes Customer Data in connection with the Service.
“Subscription Term” means the period during which Customer is authorized to access and use the Service, as specified in an Order Form.
“Third-Party Services” means any third-party applications, integrations, APIs, or services that interoperate with the Service.
2. Account Registration and Eligibility
2.1 Eligibility
To use the Service, you must be at least eighteen (18) years of age and have the legal capacity to enter into binding contracts. By using the Service, you represent and warrant that you meet these eligibility requirements.
2.2 Account Registration
To access the Service, you must create an account by providing accurate, current, and complete information. You agree to update your account information promptly to keep it accurate and complete. OpenGRC reserves the right to suspend or terminate accounts that contain inaccurate or incomplete information.
2.3 Account Security
You are responsible for maintaining the confidentiality of your account credentials and for all activities that occur under your account. You agree to immediately notify OpenGRC of any unauthorized use of your account or any other breach of security. OpenGRC shall not be liable for any loss or damage arising from your failure to protect your account credentials.
2.4 Authorized Users
Customer is responsible for ensuring that all Authorized Users comply with these Terms. Customer shall be liable for any acts or omissions of its Authorized Users that would constitute a breach of these Terms if performed by Customer.
3. Grant of License
3.1 License Grant
Subject to Customer’s compliance with these Terms and payment of all applicable Fees, OpenGRC grants Customer a limited, non-exclusive, non-transferable, non-sublicensable right to access and use the Service during the Subscription Term solely for Customer’s internal business purposes in accordance with these Terms and any applicable Documentation.
3.2 Restrictions
Customer shall not, and shall not permit any third party to:
Copy, modify, adapt, translate, or create derivative works based on the Service
Reverse engineer, disassemble, decompile, or otherwise attempt to derive the source code or underlying algorithms of the Service
Rent, lease, loan, sell, sublicense, distribute, or otherwise transfer the Service to any third party
Remove, alter, or obscure any proprietary notices on the Service
Use the Service to develop a competing product or service
Share account credentials with unauthorized parties or allow multiple individuals to use a single account
Access the Service through any automated means, including bots, scrapers, or similar technologies, except through approved APIs
Interfere with, disrupt, or attempt to gain unauthorized access to the Service or its related systems
Use the Service in violation of any applicable laws or regulations
4. Customer Data and Responsibilities
4.1 Ownership of Customer Data
As between OpenGRC and Customer, Customer retains all right, title, and interest in and to Customer Data. OpenGRC acquires no rights in Customer Data except the limited rights necessary to provide the Service.
4.2 License to Customer Data
Customer grants OpenGRC a limited, non-exclusive, worldwide license to access, use, process, copy, and display Customer Data solely as necessary to provide and maintain the Service, comply with Customer’s instructions, and fulfill OpenGRC’s obligations under this Agreement.
4.3 Customer Responsibilities for Data
Customer is solely responsible for:
The accuracy, quality, integrity, and legality of all Customer Data
Obtaining all necessary rights, consents, and permissions to collect, use, and process Customer Data through the Service
Ensuring that Customer Data does not violate any applicable laws, regulations, or third-party rights
Compliance with all applicable data protection and privacy laws with respect to Customer Data
Maintaining appropriate backups of Customer Data independent of the Service
4.4 Prohibited Content and Uses
Customer agrees that it shall not upload, store, or transmit through the Service any content that:
Is unlawful, harmful, threatening, abusive, harassing, defamatory, or otherwise objectionable
Infringes any Intellectual Property Rights or other proprietary rights of any third party
Contains any viruses, malware, or other harmful code
Violates the privacy or publicity rights of any third party
Is otherwise inappropriate for a governance, risk, and compliance platform
The Service is designed and intended for governance, risk, and compliance purposes. Customer shall not use the Service as a general-purpose file sharing or storage application.
4.5 Protected Health Information
The Service is a governance, risk, and compliance platform and is not designed or intended as a repository for Protected Health Information (“PHI”) as defined under the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations (“HIPAA”). Customer shall not upload, store, or transmit PHI through the Service unless Customer is a HIPAA Covered Entity or Business Associate and has executed a Business Associate Agreement (“BAA”) with OpenGRC. Where a BAA has been executed, the BAA governs the parties’ respective obligations with respect to PHI and controls in the event of any conflict with these Terms. Customer is encouraged to de-identify PHI or substitute a non-PHI summary wherever practical, including in uploaded evidence and free-text fields.
4.6 Payment Card Data
The Service is not designed or intended to store, process, or transmit cardholder data or sensitive authentication data as defined by the Payment Card Industry Data Security Standard (“PCI DSS”). Customer shall not upload, store, or transmit through the Service any full primary account numbers, card verification codes, PINs, or magnetic stripe or chip data. Customer shall redact, mask, or truncate such data consistent with PCI DSS before uploading evidence, screenshots, logs, or other materials. OpenGRC will delete any such data promptly upon discovering it or upon Customer’s request.
4.7 Security Responsibilities
Customer is responsible for the security of its own systems, networks, and devices used to access the Service, including but not limited to endpoint security, access controls, and network security. OpenGRC is not responsible for any unauthorized access to Customer’s account or data resulting from Customer’s failure to maintain adequate security measures on its own systems.
4.8 Data Security
OpenGRC shall implement and maintain administrative, technical, and physical safeguards designed to protect the security, confidentiality, and integrity of Customer Data. Without limiting the foregoing, OpenGRC shall:
Maintain a SOC 2 Type II examination of the Service, performed at least annually by an independent auditor, and make its most recent report available to Customer upon request, subject to Section 10
Encrypt Customer Data in transit and at rest using industry-standard encryption
Logically isolate Customer Data in a dedicated database schema and storage location, encrypted with a key unique to Customer’s instance
Store Customer Data in the data residency region specified in the Order Form or, if none is specified, in the United States
Have the Service penetration tested at least annually by an independent third party
4.9 Security Incidents
OpenGRC shall notify Customer of any Security Incident without undue delay, and in any event within twenty-four (24) hours after OpenGRC confirms the Security Incident. The notice shall describe, to the extent then known, the nature of the Security Incident, the categories of Customer Data affected, and the measures OpenGRC has taken or will take in response. OpenGRC shall provide reasonable updates as its investigation proceeds and reasonable cooperation to assist Customer in meeting any notification obligations Customer has under applicable law.
4.10 Subprocessors
OpenGRC may engage Subprocessors, including hosting and artificial intelligence providers, to provide the Service. OpenGRC shall: (a) bind each Subprocessor by written agreement to data protection and confidentiality obligations no less protective than those in this Agreement; (b) remain responsible for each Subprocessor’s performance of those obligations with respect to Customer Data; and (c) make a current list of Subprocessors available to Customer upon request.
4.11 Artificial Intelligence Features
The Service includes features that use artificial intelligence to process Customer Data at Customer’s direction. OpenGRC shall not use Customer Data to train, fine-tune, or otherwise improve artificial intelligence or machine learning models, and shall not permit its Subprocessors to do so. As between the parties, outputs generated by these features from Customer Data are Customer Data. Outputs are provided for Customer’s review and are not a substitute for Customer’s professional judgment. This Section 4.11 applies notwithstanding Section 9.3.
5. Third-Party Services and Integrations
5.1 Third-Party Integrations
The Service may offer integrations with Third-Party Services. Customer’s use of any Third-Party Services is governed by the terms and conditions and privacy policies of those third parties. OpenGRC does not control and is not responsible for Third-Party Services, and Customer’s use of Third-Party Services is at Customer’s sole risk.
5.2 APIs
OpenGRC may provide APIs to enable Customer to integrate the Service with other applications. Customer’s use of APIs is subject to these Terms, any applicable API documentation, and any additional terms provided by OpenGRC. OpenGRC reserves the right to modify, deprecate, or discontinue APIs at any time with reasonable notice.
5.3 No Warranties for Third-Party Services
OPENGRC MAKES NO WARRANTIES, EXPRESS OR IMPLIED, REGARDING ANY THIRD-PARTY SERVICES, INCLUDING BUT NOT LIMITED TO WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, OR NON-INFRINGEMENT. CUSTOMER ACKNOWLEDGES THAT THE AVAILABILITY, PERFORMANCE, AND FUNCTIONALITY OF THIRD-PARTY SERVICES ARE OUTSIDE OPENGRC’S CONTROL.
6. Professional Services
6.1 Scope
OpenGRC may provide Professional Services as described in a Statement of Work or Order Form. Professional Services may include implementation, configuration, training, consulting, and other services. The scope, deliverables, timeline, and fees for Professional Services shall be set forth in the applicable Statement of Work.
6.2 Customer Cooperation
Customer shall provide timely access to personnel, information, systems, and resources reasonably required for OpenGRC to perform Professional Services. Delays caused by Customer’s failure to provide such cooperation may result in additional fees or schedule adjustments.
6.3 Professional Services Warranty
OpenGRC warrants that Professional Services will be performed in a professional and workmanlike manner consistent with industry standards. Customer must notify OpenGRC in writing of any claimed breach of this warranty within thirty (30) days of performance. Customer’s sole remedy for breach of this warranty shall be re-performance of the deficient Professional Services at no additional charge.
7. Fees and Payment
7.1 Fees
Customer shall pay all Fees specified in the applicable Order Form or pricing page. All Fees are quoted in United States Dollars unless otherwise specified. Fees are exclusive of all taxes, levies, or duties imposed by taxing authorities, and Customer shall be responsible for payment of all such amounts.
7.2 Billing and Payment
Fees are billed annually in advance. Payment is due within thirty (30) days of the invoice date unless otherwise specified in an Order Form. Customer shall provide accurate and complete billing information and promptly update such information as necessary.
7.3 Late Payment
If Customer fails to pay any Fees when due, OpenGRC may: (a) charge interest on the overdue amount at the rate of one and one-half percent (1.5%) per month or the maximum rate permitted by law, whichever is less; (b) suspend access to the Service in accordance with Section 8.4; and (c) pursue any other remedies available at law or in equity, subject to Section 15.
7.4 Price Changes
OpenGRC may increase Fees upon renewal of the Subscription Term by providing written notice to Customer at least sixty (60) days prior to the renewal date. The new Fees shall apply to the renewal term unless Customer provides written notice of non-renewal in accordance with Section 8.2.
7.5 No Refunds
ALL FEES ARE NON-REFUNDABLE EXCEPT AS EXPRESSLY SET FORTH IN THIS AGREEMENT (INCLUDING SECTIONS 8.6, 11.1, 11.4, AND 13.4) OR AS REQUIRED BY APPLICABLE LAW. Without limiting the foregoing, no refunds shall be provided for partial subscription periods, unused services, or termination by Customer for convenience.
8. Term and Termination
8.1 Term
This Agreement commences on the date Customer first accepts these Terms or accesses the Service and continues until terminated in accordance with this Section 8. The initial Subscription Term shall be as specified in the Order Form. Subscription Terms are annual unless otherwise specified.
8.2 Automatic Renewal
Unless either party provides written notice of non-renewal at least thirty (30) days prior to the end of the then-current Subscription Term, the Subscription Term shall automatically renew for successive periods equal to the initial Subscription Term (or one year, whichever is shorter) at the then-current Fees.
8.3 Termination for Cause
Either party may terminate this Agreement immediately upon written notice if the other party: (a) materially breaches this Agreement and fails to cure such breach within thirty (30) days after receiving written notice thereof; or (b) becomes the subject of a bankruptcy, insolvency, receivership, liquidation, or similar proceeding.
8.4 Suspension
OpenGRC may suspend access to the Service: (a) if any undisputed Fees remain unpaid ten (10) days after OpenGRC provides Customer written notice of non-payment; (b) immediately, if Customer violates Section 3.2 (Restrictions) or Section 4.4 (Prohibited Content and Uses) in a manner that threatens the Service, its security, or other customers; or (c) immediately, to the extent reasonably necessary to comply with applicable law or to address a security risk posed by Customer’s use of the Service. OpenGRC shall limit any suspension to the minimum scope and duration reasonably necessary, notify Customer of the reason (in advance where practicable), and restore access promptly once the cause of the suspension is resolved.
8.5 Termination by OpenGRC
OpenGRC may terminate this Agreement upon written notice if: (a) undisputed Fees remain unpaid thirty (30) days after OpenGRC provides Customer written notice of non-payment; (b) Customer materially violates Section 3.2 (Restrictions) or Section 4.4 (Prohibited Content and Uses) and fails to cure the violation within ten (10) days after written notice, or the violation is not capable of cure; or (c) continued provision of the Service to Customer would violate applicable law.
8.6 Effect of Termination
Upon termination or expiration of this Agreement: (a) all rights and licenses granted to Customer shall immediately terminate; (b) Customer shall immediately cease all use of the Service; (c) each party shall return or destroy all Confidential Information of the other party, except that Customer Data shall be handled in accordance with Section 8.7; (d) Customer shall pay all Fees accrued through the date of termination; and (e) if Customer terminates under Section 8.3, or OpenGRC terminates under Section 8.5(c), OpenGRC shall refund to Customer any prepaid Fees covering the remainder of the Subscription Term after the effective date of termination.
8.7 Data Retention and Export
Following termination or expiration, OpenGRC will retain Customer Data for ninety (90) days to allow Customer to export or retrieve such data, unless a shorter retention period is specified in the applicable Order Form or otherwise requested by Customer in writing. Customer may request earlier deletion of Customer Data by contacting OpenGRC at [email protected]. After the retention period, OpenGRC shall have no obligation to maintain or provide Customer Data and may delete all Customer Data in its systems or otherwise in its possession or control. Upon Customer’s written request, OpenGRC shall certify in writing that Customer Data has been deleted. Customer Data residing in backups will be deleted in the ordinary course of OpenGRC’s backup rotation and remains subject to Section 10 until deleted.
8.8 Survival
The following sections shall survive any termination or expiration of this Agreement: Sections 1, 4.1, 7 (with respect to amounts accrued), 8.6, 8.7, 9, 10, 11, 12, 13, 14, 15, 16, and 17.
9. Intellectual Property
9.1 OpenGRC Intellectual Property
OpenGRC and its licensors retain all right, title, and interest in and to the Service, including all software, technology, documentation, and other materials provided by OpenGRC, and all Intellectual Property Rights therein. Except for the limited license expressly granted in Section 3.1, no rights in the Service are granted to Customer.
9.2 Feedback
If Customer provides any suggestions, ideas, enhancement requests, recommendations, or other feedback regarding the Service (“Feedback”), Customer hereby grants OpenGRC a perpetual, irrevocable, worldwide, royalty-free, fully paid-up, non-exclusive license to use, reproduce, modify, create derivative works from, distribute, and otherwise exploit such Feedback for any purpose without compensation or attribution to Customer.
9.3 Aggregated Data
Notwithstanding anything to the contrary, OpenGRC may collect and use aggregated, anonymized, or de-identified data derived from Customer’s use of the Service for purposes of improving the Service, developing new products and services, and conducting research and analytics, provided that such data does not identify Customer or any individual.
10. Confidentiality
10.1 Definition
“Confidential Information” means any information disclosed by one party to the other that is designated as confidential or that reasonably should be understood to be confidential given the nature of the information and circumstances of disclosure. Confidential Information includes, but is not limited to, business plans, pricing, technical data, and Customer Data.
10.2 Obligations
Each party agrees to: (a) maintain the confidentiality of the other party’s Confidential Information using at least the same degree of care it uses to protect its own confidential information, but no less than reasonable care; (b) not disclose Confidential Information to any third party except to its and its Affiliates’ employees, contractors, Subprocessors, and professional advisors who need to know it for purposes of this Agreement and are bound by confidentiality obligations no less protective than those in this Section 10, provided that the receiving party remains responsible for any breach of this Section 10 by such persons; and (c) use Confidential Information only for purposes of performing its obligations or exercising its rights under this Agreement.
10.3 Exceptions
Confidential Information does not include information that: (a) is or becomes publicly available through no fault of the receiving party; (b) was rightfully in the receiving party’s possession prior to disclosure; (c) is rightfully obtained by the receiving party from a third party without restriction; or (d) is independently developed by the receiving party without use of the disclosing party’s Confidential Information.
10.4 Required Disclosures
A party may disclose Confidential Information to the extent required by law or legal process, provided that such party gives the other party prompt written notice (to the extent legally permitted) and reasonable assistance in contesting such disclosure.
11. Disclaimers
11.1 Limited Warranty
OpenGRC warrants that during the Subscription Term: (a) the Service will perform materially in accordance with the Documentation; and (b) OpenGRC will not materially decrease the overall security or functionality of the Service. If OpenGRC breaches this warranty, Customer shall notify OpenGRC in writing with reasonable detail, and OpenGRC shall use commercially reasonable efforts to correct the nonconformity. If OpenGRC does not correct the nonconformity within thirty (30) days after receiving Customer’s notice, Customer may terminate this Agreement upon written notice and receive a refund of any prepaid Fees covering the remainder of the Subscription Term. This warranty does not apply to nonconformities caused by Customer, Customer Data, Third-Party Services, or use of the Service other than in accordance with this Agreement and the Documentation. This Section 11.1 states Customer’s sole and exclusive remedy for breach of this warranty.
11.2 As-Is Basis
EXCEPT AS EXPRESSLY SET FORTH IN THIS AGREEMENT, THE SERVICE IS PROVIDED “AS IS” AND “AS AVAILABLE” WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED. TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, OPENGRC EXPRESSLY DISCLAIMS ALL WARRANTIES, INCLUDING BUT NOT LIMITED TO IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, NON-INFRINGEMENT, AND ANY WARRANTIES ARISING FROM COURSE OF DEALING OR USAGE OF TRADE.
11.3 No Guarantee
EXCEPT AS EXPRESSLY SET FORTH IN THIS AGREEMENT, OPENGRC DOES NOT WARRANT THAT: (A) THE SERVICE WILL MEET CUSTOMER’S REQUIREMENTS; (B) THE SERVICE WILL BE UNINTERRUPTED OR ERROR-FREE; (C) ANY ERRORS OR DEFECTS IN THE SERVICE WILL BE CORRECTED; (D) THE SERVICE WILL BE COMPATIBLE WITH CUSTOMER’S SYSTEMS OR OTHER SOFTWARE; OR (E) THE RESULTS OBTAINED FROM USE OF THE SERVICE WILL BE ACCURATE OR RELIABLE.
11.4 Service Availability
OpenGRC shall use commercially reasonable efforts to make the Service available with an uptime of no less than ninety-nine and one-half percent (99.5%) per calendar month (“Monthly Uptime”), excluding: (a) scheduled maintenance windows for which OpenGRC has provided reasonable advance notice; (b) emergency maintenance reasonably necessary to address security vulnerabilities or prevent imminent service degradation; (c) unavailability caused by Customer, Customer Data, Customer’s systems or network, or Third-Party Services; (d) force majeure events as described in Section 14; and (e) any suspension permitted under this Agreement. If Monthly Uptime falls below 99.5%, Customer will be entitled to a service credit equal to the following percentage of one-twelfth (1/12) of the annual Fees for the affected Subscription Term:
Monthly Uptime below 99.5% but at least 99.0%: five percent (5%)
Monthly Uptime below 99.0% but at least 95.0%: ten percent (10%)
Monthly Uptime below 95.0%: twenty-five percent (25%)
To receive a service credit, Customer must request it in writing within thirty (30) days after the end of the month in which the shortfall occurred. Service credits will be applied against Customer’s next invoice or, if no further invoice will be issued, refunded. If Monthly Uptime falls below 99.5% in any three (3) months within a rolling six (6) month period, Customer may terminate this Agreement by written notice given within thirty (30) days after the end of the third such month and receive a refund of any prepaid Fees covering the remainder of the Subscription Term. Service credits and the termination right in this Section 11.4 are Customer’s sole and exclusive remedies for any failure to meet the availability commitment, and such failure shall not otherwise constitute a breach of this Agreement.
11.5 Security
OpenGRC maintains the security program described in Section 4.8, including an annual SOC 2 Type II examination and annual independent penetration testing. No security program can eliminate all risk, and except as expressly set forth in this Agreement, OpenGRC does not guarantee that the Service will be free from all security breaches, unauthorized access, or data loss. Customer is responsible for determining whether the Service meets Customer’s security requirements.
11.6 Compliance Disclaimer
The Service is a tool to assist Customer with governance, risk, and compliance activities. OpenGRC does not guarantee that use of the Service will result in compliance with any law, regulation, or industry standard. Customer is solely responsible for determining its compliance obligations and ensuring that its use of the Service satisfies such obligations.
12. Limitation of Liability
12.1 Exclusion of Consequential Damages
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, IN NO EVENT SHALL EITHER PARTY OR ITS AFFILIATES, OFFICERS, DIRECTORS, EMPLOYEES, AGENTS, OR LICENSORS BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, PUNITIVE, OR EXEMPLARY DAMAGES, INCLUDING BUT NOT LIMITED TO DAMAGES FOR LOSS OF PROFITS, REVENUE, GOODWILL, DATA, OR OTHER INTANGIBLE LOSSES, EVEN IF SUCH PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
12.2 Cap on Liability
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, EACH PARTY’S TOTAL CUMULATIVE LIABILITY TO THE OTHER FOR ALL CLAIMS ARISING OUT OF OR RELATING TO THIS AGREEMENT, WHETHER IN CONTRACT, TORT (INCLUDING NEGLIGENCE), OR OTHERWISE, SHALL NOT EXCEED THE TOTAL FEES PAID OR PAYABLE BY CUSTOMER TO OPENGRC DURING THE TWELVE (12) MONTHS IMMEDIATELY PRECEDING THE EVENT GIVING RISE TO THE CLAIM.
12.3 Basis of the Bargain
The parties acknowledge that OpenGRC has set its prices and each party has entered into this Agreement in reliance upon the limitations of liability and disclaimers of warranties set forth herein, and that the same form an essential basis of the bargain between the parties. The parties agree that the limitations and exclusions of liability and disclaimers specified in this Agreement will survive and apply even if found to have failed of their essential purpose.
12.4 Exceptions
The exclusions and limitations in Sections 12.1 and 12.2 shall not apply to: (a) Customer’s obligation to pay Fees; (b) Customer’s breach of Section 3.2 (Restrictions); (c) either party’s breach of Section 10 (Confidentiality), other than a breach involving Customer Data, which is governed exclusively by Section 12.5; (d) either party’s gross negligence, willful misconduct, or fraud; and (e) either party’s liability for death or physical bodily injury caused by its negligence, or for any other liability that cannot be limited or excluded under applicable law. Each party’s indemnification obligations under Section 13 are not subject to Section 12.2 and are instead subject to Section 13.5.
12.5 Security Incidents
OpenGRC’s total cumulative liability arising out of or relating to all Security Incidents, and any breach of Sections 4.8 through 4.11 or of Section 10 involving Customer Data, shall not exceed five hundred thousand dollars ($500,000), in lieu of the cap in Section 12.2. The following reasonable costs shall be treated as direct damages recoverable within this cap and shall not be excluded by Section 12.1: (a) forensic investigation; (b) notification of affected individuals and regulators as required by law; (c) credit monitoring or identity protection services for affected individuals where required by law; and (d) regulatory fines and penalties assessed as a result of the Security Incident. These costs do not include costs attributable to data Customer uploaded in violation of Section 4.5 or Section 4.6. This Section 12.5 does not limit either party’s liability for gross negligence, willful misconduct, or fraud.
13. Indemnification
13.1 Indemnification by Customer
Customer shall defend, indemnify, and hold harmless OpenGRC and its affiliates, officers, directors, employees, and agents from and against any third-party claim, and all resulting damages, losses, liabilities, costs, and expenses (including reasonable attorneys’ fees), arising out of or relating to: (a) Customer Data, including any claim that Customer Data infringes, misappropriates, or violates any third-party rights or applicable law; or (b) use of the Service by Customer or its Authorized Users in violation of Section 3.2, Section 4.4, or applicable law.
13.2 Indemnification by OpenGRC
OpenGRC shall defend, indemnify, and hold harmless Customer from and against any third-party claim alleging that the Service, as provided by OpenGRC and used in accordance with this Agreement, directly infringes a valid United States copyright or trademark, and all resulting damages, losses, liabilities, costs, and expenses (including reasonable attorneys’ fees).
13.3 Limitations on OpenGRC Indemnification
OpenGRC’s indemnification obligations under Section 13.2 shall not apply to claims arising from: (a) modifications to the Service made by anyone other than OpenGRC; (b) combination of the Service with third-party products, services, or data not provided by OpenGRC; (c) Customer’s continued use of the Service after being notified of allegedly infringing activity; (d) Customer Data; or (e) Customer’s breach of this Agreement.
13.4 Infringement Remedies
If the Service becomes, or in OpenGRC’s reasonable opinion is likely to become, the subject of an infringement claim, OpenGRC may, at its sole option and expense: (a) procure for Customer the right to continue using the Service; (b) replace or modify the Service to make it non-infringing while maintaining substantially equivalent functionality; or (c) if neither (a) nor (b) is commercially practicable, terminate this Agreement and refund to Customer any prepaid Fees for the unused portion of the Subscription Term.
13.5 Cap on Indemnification
NOTWITHSTANDING ANYTHING TO THE CONTRARY, EACH PARTY’S TOTAL LIABILITY UNDER THIS SECTION 13 SHALL NOT EXCEED THE GREATER OF (A) TWO HUNDRED THOUSAND DOLLARS ($200,000) OR (B) THE TOTAL FEES PAID OR PAYABLE BY CUSTOMER TO OPENGRC DURING THE TWELVE (12) MONTHS IMMEDIATELY PRECEDING THE CLAIM. THIS CAP DOES NOT APPLY TO LIABILITY ARISING FROM A PARTY’S GROSS NEGLIGENCE, WILLFUL MISCONDUCT, OR FRAUD.
13.6 Exclusive Remedy
THIS SECTION 13 STATES OPENGRC’S ENTIRE LIABILITY AND CUSTOMER’S SOLE AND EXCLUSIVE REMEDY FOR ANY CLAIMS OF INTELLECTUAL PROPERTY INFRINGEMENT.
13.7 Indemnification Procedure
The party seeking indemnification shall: (a) promptly notify the indemnifying party in writing of the claim, provided that a delay in notice relieves the indemnifying party of its obligations only to the extent the delay prejudices its defense; (b) grant the indemnifying party sole control of the defense and settlement of the claim, except that the indemnifying party may not settle any claim in a manner that imposes liability or an admission of fault on the indemnified party without its prior written consent; and (c) provide reasonable cooperation at the indemnifying party’s expense. The indemnified party may participate in the defense with counsel of its choosing at its own expense.
14. Force Majeure
Neither party shall be liable for any failure or delay in performing its obligations under this Agreement (except for payment obligations) to the extent such failure or delay results from circumstances beyond the party’s reasonable control, including but not limited to acts of God, natural disasters, war, terrorism, riots, embargoes, acts of civil or military authorities, fire, floods, epidemics, pandemics, strikes, power outages, internet or telecommunications failures, or cyberattacks. The affected party shall promptly notify the other party and use reasonable efforts to mitigate the effects of the force majeure event. Notwithstanding the foregoing, a cyberattack shall not excuse OpenGRC’s performance to the extent the resulting failure or delay would have been prevented by the safeguards OpenGRC is required to maintain under Section 4.8, and no force majeure event shall excuse OpenGRC’s notification obligations under Section 4.9.
15. Dispute Resolution
15.1 Informal Resolution
Before initiating any formal dispute resolution proceeding, the parties agree to first attempt to resolve any dispute, claim, or controversy arising out of or relating to this Agreement (“Dispute”) through good faith negotiations. Either party may initiate negotiations by sending written notice describing the Dispute to the other party. Within ten (10) business days after such notice, representatives of each party with authority to resolve the Dispute shall meet in person or by videoconference. The parties shall negotiate in good faith for at least thirty (30) days after the notice before commencing litigation, except as provided in Section 15.3.
15.2 Litigation
Any Dispute not resolved under Section 15.1 shall be brought exclusively in the state courts located in Seminole County, Florida, or the United States District Court for the Middle District of Florida, Orlando Division, and each party irrevocably submits to the personal jurisdiction and venue of those courts.
15.3 Equitable Relief
Either party may seek injunctive or other equitable relief in any court of competent jurisdiction to protect its Intellectual Property Rights or Confidential Information, without first complying with Section 15.1.
15.4 Waiver of Jury Trial
EACH PARTY KNOWINGLY, VOLUNTARILY, AND INTENTIONALLY WAIVES ANY RIGHT TO A TRIAL BY JURY IN ANY ACTION OR PROCEEDING ARISING OUT OF OR RELATING TO THIS AGREEMENT.
15.5 Attorneys’ Fees
In any action or proceeding to enforce this Agreement, including the collection of Fees, the prevailing party shall be entitled to recover its reasonable attorneys’ fees and costs.
16. Governing Law
This Agreement shall be governed by and construed in accordance with the laws of the State of Florida, without regard to its conflict of laws principles.
17. General Provisions
17.1 Entire Agreement
This Agreement, together with any Order Forms and Statements of Work, constitutes the entire agreement between the parties with respect to the subject matter hereof and supersedes all prior and contemporaneous agreements, proposals, or representations, written or oral, concerning such subject matter. In the event of any conflict between this Agreement and an Order Form, the Order Form shall control.
17.2 Modifications
OpenGRC may modify these Terms from time to time by posting the updated Terms on its website or notifying Customer by email. Such modifications shall become effective thirty (30) days after posting or notification, unless Customer objects in writing within such period. Customer’s continued use of the Service after the effective date of any modifications constitutes acceptance of the modified Terms. Notwithstanding the foregoing, with respect to Customers who have entered into a signed Order Form, any modification that materially and adversely affects Customer’s rights or OpenGRC’s material obligations under this Agreement shall not apply to the then-current Subscription Term and shall take effect no earlier than the next renewal. If OpenGRC notifies such Customer of a material adverse modification that will apply upon renewal, Customer may terminate this Agreement effective at the end of the then-current Subscription Term by providing written notice within thirty (30) days after OpenGRC’s notice, in which case no automatic renewal shall occur.
17.3 Waiver
No failure or delay by either party in exercising any right under this Agreement shall constitute a waiver of that right. Any waiver must be in writing and signed by an authorized representative of the waiving party.
17.4 Severability
If any provision of this Agreement is held to be invalid, illegal, or unenforceable, such provision shall be modified to the minimum extent necessary to make it valid, legal, and enforceable, or if such modification is not possible, such provision shall be severed from this Agreement, and the remaining provisions shall continue in full force and effect.
17.5 Assignment
Neither party may assign or transfer this Agreement or any rights or obligations hereunder without the other party’s prior written consent, except that either party may assign this Agreement in its entirety, without consent, to an Affiliate or to a successor in connection with a merger, acquisition, corporate reorganization, or sale of all or substantially all of its assets or of the business to which this Agreement relates, provided that the assignee agrees in writing to be bound by this Agreement and the assigning party gives the other party written notice of the assignment. Any attempted assignment in violation of this provision shall be void. This Agreement shall bind and inure to the benefit of the parties and their respective permitted successors and assigns.
17.6 Independent Contractors
The relationship between the parties is that of independent contractors. Nothing in this Agreement shall be construed to create a partnership, joint venture, agency, or employment relationship between the parties.
17.7 Notices
All notices under this Agreement shall be in writing and shall be deemed given when delivered personally, sent by email with confirmation of receipt, or sent by certified mail, return receipt requested, to the addresses specified in the Order Form or to such other address as either party may specify in writing. Notices to OpenGRC shall also be sent to: [email protected].
17.8 Publicity
OpenGRC may identify Customer as a customer and use Customer’s name and logo in marketing materials, customer lists, and on OpenGRC’s website. Customer may opt out of such use by providing written notice to OpenGRC.
17.9 Export Compliance
Customer shall comply with all applicable export control laws and regulations of the United States and other applicable jurisdictions. Customer shall not export, re-export, or transfer the Service or any technical data obtained through the Service to any country, entity, or person prohibited by such laws.
17.10 Government Users
If Customer is a U.S. government entity or the Service is being used on behalf of a U.S. government entity, the Service is provided as “commercial computer software” and “commercial computer software documentation” as defined in 48 C.F.R. § 2.101, and the use, duplication, and disclosure of the Service is subject to the restrictions set forth in these Terms.
17.11 Insurance
OpenGRC shall maintain, at its own expense and from insurers with an A.M. Best rating of A- or better, the following minimum insurance coverages during the Subscription Term: (a) Commercial General Liability insurance with limits of not less than five hundred thousand dollars ($500,000) per occurrence; (b) Professional Liability (Technology Errors & Omissions) insurance with limits of not less than one million dollars ($1,000,000) per claim; and (c) Cyber Liability insurance with limits of not less than one million dollars ($1,000,000) per claim. OpenGRC shall provide certificates of insurance evidencing such coverages upon Customer’s written request.
18. Contact Information
If you have any questions about these Terms, please contact us at:
OpenGRC, LLC
Casselberry, Florida, United States
Email: [email protected]
Privacy Inquiries: [email protected]