Software as a Service Terms of Use
Latest Update: 17 July 2026
ZEROQUARRY PTY LTD ACN 699 756 075 (Supplier, We, Us, Our) owns and operates the software platform known as ZeroQuarry (Platform) and supplies automated software security-scanning and related services through the Platform (Services).
These Software as a Service Terms of Use (Terms) govern access to and use of the Platform and Services by the person or entity identified as the customer in an Order Form or, if no Order Form identifies a customer, the entity or individual on whose behalf an account is created or the Services are used (Customer). An individual who accepts these Terms for an entity does so as its representative and does not become the Customer merely by accepting them in that capacity.
By accepting an Order Form, creating an account, clicking to accept these Terms or using the Platform, the Customer agrees to be bound by these Terms.
1. Definitions and interpretation
1.1In these Terms:
- Account Data
- means the names, business contact details, account credentials and other information provided to create, administer or support an account, excluding Application Data.
- Application Data
- means source code, software, repositories, applications, files, binaries, scripts, configuration files, infrastructure definitions, APIs, software components, documentation, Customer System Credentials and other digital materials submitted or made available by or on behalf of the Customer for analysis, scanning or other processing through the Services. Application Data excludes Account Data, Usage Data, Service Outputs and Supplier Materials.
- Australian Consumer Law
- means the Australian Consumer Law set out in Schedule 2 to the Competition and Consumer Act 2010 (Cth).
- Authorised User
- means an individual whom the Customer authorises to access or use the Platform under the Customer's account.
- Business Day
- means a day other than a Saturday, Sunday or public holiday in Melbourne, Victoria.
- Confidential Information
- means information disclosed by or on behalf of a party that is confidential by nature or designation, including Application Data, account credentials, Customer System Credentials, non-public software and architecture information, detailed vulnerability and remediation information, security practices, business plans, pricing and trade secrets. It excludes information that the recipient can establish is public other than through breach, was lawfully known without restriction, was independently developed without use of the discloser's information, or was lawfully received from a third party without restriction.
- Customer Systems
- means the Customer's software, networks, infrastructure, devices, repositories, applications and systems that are connected to, submitted to or assessed through the Services.
- Customer System Credentials
- means passwords, access tokens, API keys, private keys, certificates or other authentication information supplied or made available to enable the Services to access Customer Systems, excluding credentials used to access the Platform.
- External Service Output
- means a Service Output expressly identified by the Supplier as suitable for external disclosure.
- Fees
- means the fees and charges specified in an Order Form or otherwise communicated by the Supplier, together with any other amounts payable under these Terms.
- GST
- has the meaning given in A New Tax System (Goods and Services Tax) Act 1999 (Cth).
- Insolvency Event
- means, in relation to a person, liquidation, provisional liquidation, administration, receivership, bankruptcy, a compromise or arrangement with creditors arising from insolvency, inability to pay debts when due, or an analogous event, but excludes a solvent reconstruction or reorganisation approved in writing by the other party.
- Internal Service Output
- means a Service Output expressly identified by the Supplier as Confidential, Internal, Internal Use Only or by a similar designation, including a Service Output identified as containing detailed vulnerability, exploit, source-location or remediation information unsuitable for external disclosure.
- Order Form
- means an order form, accepted quotation, statement of work, online subscription selection or other ordering document that identifies the Services, Fees, Subscription Term or usage entitlements.
- Permitted Analytics Data
- means information derived from Usage Data, Service Outputs or operation of the Services that has been aggregated, de-identified and processed so that it cannot reasonably identify the Customer or an individual, disclose Customer-specific vulnerabilities or Confidential Information, or permit reconstruction of Application Data.
- Personal Information
- has the meaning given in the Privacy Act 1988 (Cth) and includes any equivalent category of protected personal information under another privacy law applicable to the parties or the Services.
- Privacy Policy
- means the Supplier's privacy policy made available through the Platform or the Supplier's website available at https://zeroquarry.com/privacy, as updated from time to time in accordance with applicable law.
- Security Incident
- means unauthorised access to, disclosure of, loss of or material interference with Application Data, Customer System Credentials, Account Data containing credentials or Personal Information, Confidential Information of the Customer or Service Outputs in the Supplier's possession or control.
- Service Output
- means a report, analysis, finding, summary, recommendation, alert, dashboard, score, metric or other information generated by or made available through the Platform as a result of processing or analysing Application Data. Service Outputs exclude Application Data and Supplier Materials.
- Service Provider
- means a third-party hosting, cloud, payment, support, artificial intelligence, scanning or other technology provider engaged by the Supplier to support or provide the Platform or Services.
- Subscription Term
- means the subscription period specified in an Order Form, including any renewal period.
- Supplier Materials
- means the Platform, Services, software, source code, user interface, designs, tools, features, vulnerability and defect libraries, taxonomies, detection logic, models, algorithms, methodologies, scoring systems, report formats and templates, documentation, trade marks, know-how and other materials owned, developed or licensed by the Supplier, excluding Application Data.
- Usage Data
- means technical, diagnostic, security, performance and account-activity data generated through operation or use of the Platform, excluding Application Data and Service Outputs.
1.2A reference to a law includes any amendment, replacement or subordinate instrument made under it. The words including and includes do not limit the words that precede them. A singular expression includes the plural and vice versa.
1.3Headings assist navigation only and do not affect interpretation.
2. Agreement, authority and changes
2.1These Terms and each applicable Order Form form the agreement between the Supplier and the Customer for the Services.
2.2If there is an inconsistency, the following order of precedence applies:
- any signed enterprise agreement, data processing agreement or security schedule, if any,
- the Order Form,
- these Terms; and
- then the Privacy Policy.
2.3An Order Form prevails only to the extent of the specific inconsistency.
2.4A person who accepts these Terms on behalf of an entity represents that the person has authority to bind that entity.
2.5The Supplier may amend these Terms by giving the Customer at least 14 days' prior notice, other than in the following circumstances:
- A change that is reasonably required to comply with law, address an urgent security risk, prevent fraud or protect the integrity of the Platform may take effect on shorter notice or immediately where reasonably necessary.
- A materially adverse change (as determined by the Supplier) will not take effect during a current prepaid Subscription Term unless the Customer is given at least 30 days' notice and may terminate the affected Services before the change takes effect.
- If the Customer terminates under subclause (b), the Supplier will refund any prepaid Fees for the unused part of the affected Subscription Term (however, the Customer remains liable to pay any Fees up until the date of termination).
2.6For purpose of clause 2.5, the continued use of any Supplier Material after a change takes effect constitutes acceptance of the amended Terms, except where the Customer has exercised a termination right under that clause.
3. Accounts and Authorised Users
3.1The Customer must create and maintain an account to access the Platform unless the Supplier agrees otherwise.
3.2The Customer must ensure that each Authorised User is at least 18 years old, uses the Platform only for the Customer's business purposes and complies with these Terms.
3.3The Customer is responsible for activity conducted through its account, except to the extent caused by the Supplier's breach of these Terms.
3.4The Customer must keep credentials secure, use reasonable access controls and notify the Supplier promptly of suspected unauthorised account access.
3.5The Customer must provide complete and accurate Account Data and billing information and update it when it changes.
3.6If Account Data is incomplete or inaccurate, the Supplier may require correction and may suspend affected functionality where the information is reasonably required to provide the Services, process payment, manage security or comply with law.
3.7The Supplier may terminate for inaccurate Account Data only if the Customer fails to correct a material inaccuracy within a reasonable period after notice, or the inaccuracy is fraudulent or materially prejudices the Services or the Supplier.
4. Services
4.1The Services use automated and artificial intelligence-assisted processes to analyse Application Data and assist the Customer to identify potential security vulnerabilities, weaknesses and related risks.
4.2The scope, frequency, usage entitlements and any supported systems or integrations are set out in the applicable Order Form.
4.3If an Order Form uses employee, personnel, user, repository, application, scan or other usage metrics, the Customer must provide accurate information relevant to those metrics. The Supplier may adjust prospective Fees or require migration to the appropriate plan if actual use exceeds the purchased entitlement, after giving reasonable notice.
4.4The Supplier may introduce reasonable usage controls to prevent excessive, abusive, unlawful or automated use that materially affects the performance, security or availability of the Platform or breaches these Terms or the Order Form. Those controls must not materially reduce the Customer's purchased entitlement.
4.5The Supplier may modify the Platform or Services from time to time, but will not materially reduce the core functionality purchased for the current Subscription Term without giving the Customer the rights that would apply under clauses 2.5(b) and 2.5(c) as if the reduction were a materially adverse change to these Terms.
4.6The Supplier will use reasonable endeavours to make the Platform available, but does not guarantee uninterrupted or error-free availability. Availability may be affected by scheduled or emergency maintenance, telecommunications services, Service Providers, Customer Systems, security events and events beyond the Supplier's reasonable control.
4.7Where practicable, the Supplier will give reasonable notice of scheduled maintenance likely to cause material interruption.
4.8The Customer acknowledges that the Services are a decision-support tool. The Customer remains responsible for its software, security program, remediation decisions, compliance obligations and the suitability of any action taken in response to a Service Output.
5. Customer obligations and acceptable use
5.1The Customer must:
- provide Application Data and access reasonably required to perform the Services, and ensure that material information supplied for a scan is accurate and complete;
- maintain its own current backups of Application Data and Customer Systems;
- review Service Outputs and determine whether findings require validation, remediation, further testing or professional advice;
- implement appropriate remediation and security controls in its own systems;
- ensure that its use of the Platform and Services complies with applicable law and third-party contractual obligations;
- cooperate reasonably with the Supplier in investigating misuse, security issues or technical faults; and
- not submit production Customer System Credentials unless reasonably necessary for the Services and expressly requested by the Supplier or submitted through functionality made available by the Supplier for that purpose, and ensure that any Customer System Credentials submitted are limited to the minimum permissions reasonably required and are revoked or rotated when no longer required.
5.2The Customer must not, and must not permit any other person to:
- use the Platform or Services for an unlawful, fraudulent or malicious purpose;
- introduce malware or harmful code into the Platform, except where expressly agreed for a controlled security assessment;
- attempt to gain unauthorised access to the Platform, another customer's account or any connected system;
- conduct penetration testing, vulnerability testing, load testing or security research against the Platform without the Supplier's prior written approval;
- interfere with or disrupt the integrity, performance or availability of the Platform;
- reverse engineer, decompile, disassemble or attempt to derive the source code, models, algorithms or non-public design of the Platform, except to the extent that applicable law prohibits this restriction;
- copy, scrape, extract, data-mine or use Supplier Materials to develop, train or materially improve a product or service that competes with the Platform;
- sell, sublicense or provide access to the Platform to a third party, except to Authorised Users;
- remove proprietary notices from Supplier Materials; or
- use the Platform in a manner that infringes another person's rights or breaches an obligation of confidence.
5.3Nothing in this clause restricts the Customer from using, reproducing, disclosing, licensing, assigning, selling, transferring or otherwise commercialising its own Application Data, software or intellectual property outside the Platform.
6. Application Data
6.1As between the parties, the Customer or its licensors retain all rights, title and interest in Application Data.
6.2The Customer grants the Supplier a non-exclusive, worldwide, royalty-free licence during the Subscription Term and any limited retention period under clause 6.8 to host, copy, transmit, reproduce, process, analyse and scan Application Data solely to:
- provide, operate and support the Services;
- generate and deliver Service Outputs;
- maintain, secure, monitor and troubleshoot the Platform;
- prevent or investigate misuse, fraud and Security Incidents;
- comply with applicable law; and
- create Permitted Analytics Data in accordance with clause 6.7.
6.3The Supplier may permit a Service Provider to exercise the rights in clause 6.2 only to the extent reasonably required to provide or support the Services and subject to contractual obligations concerning confidentiality, security and permitted use.
6.4The licence in clause 6.2 does not transfer ownership of Application Data to the Supplier and does not permit the Supplier to sell, license or independently commercialise Application Data.
6.5The Supplier may, subject to any contrary provision in an Order Form or a signed data processing agreement, security schedule or enterprise agreement between the parties, use Permitted Analytics Data to train, fine-tune and improve artificial intelligence or machine-learning models used to identify, classify, assess or assist in remediating security vulnerabilities and to improve the Services. The Supplier must not use raw Application Data to train, fine-tune or improve a code-generation, coding or general-purpose model. Any exclusion or modification of the permission in this clause applies only to use occurring after the date on which the relevant instrument takes effect and does not require the Supplier to reverse, retrain or remove model improvements lawfully made before that date, provided those improvements do not identify the Customer, disclose Customer-specific vulnerabilities or Confidential Information, or permit reconstruction of Application Data.
6.6The Supplier will ensure that its personnel, and will require its Service Providers to ensure that their personnel, do not intentionally access or review Application Data except where access is reasonably necessary to provide technical support requested by the Customer, investigate or respond to a Security Incident, prevent misuse, comply with law, or perform maintenance or troubleshooting that cannot reasonably be completed without that access. Access must be limited to authorised personnel with a need to know and subject to appropriate access controls and confidentiality obligations.
6.7The Supplier may create, use, disclose and commercialise Permitted Analytics Data for security analytics, benchmarking, capacity planning, service improvement, model training and improvement in accordance with clause 6.5, and research. Permitted Analytics Data must not identify the Customer or an individual, disclose Customer-specific vulnerabilities or Confidential Information, or permit reconstruction of Application Data.
6.8The Supplier may retain Application Data only for as long as reasonably necessary to provide the Services, support the Customer, protect the Platform, comply with law or preserve evidence for an actual or reasonably anticipated dispute. After the relevant purpose ends, the Supplier will delete Application Data from active systems within 90 days and remove residual copies through its ordinary backup cycle. While residual copies remain in backups, the Supplier will place them beyond ordinary use, maintain appropriate access controls and not restore or use them except for legitimate disaster recovery, security or legal purposes. If a backup is restored, the Supplier will reapply the applicable deletion process. The Supplier may retain only Permitted Analytics Data in accordance with clause 6.7.
6.9On a verified written request, the Supplier will delete Application Data earlier where technically practicable and not inconsistent with a legal obligation, security requirement, active investigation, insurance requirement or preservation obligation.
6.10The Supplier is not required to retain Application Data after termination. The Customer must retain any copy it requires for its records or ongoing use.
7. Authority to submit and scan Application Data
7.1The Customer represents and warrants that:
- it owns, controls or has all rights, licences, permissions and authority required to submit Application Data and authorise the Supplier and its Service Providers to exercise the rights in clause 6.2;
- the submission, processing, analysis and scanning of Application Data will not infringe intellectual property rights, breach confidentiality, privacy, licence or contractual obligations, or otherwise violate applicable law;
- it has obtained all permissions required for third-party code, open-source components, repositories, APIs, linked systems, Customer System Credentials and materials included in or accessed through Application Data; and
- it will not submit material where automated scanning, copying or analysis is prohibited or restricted without obtaining the necessary consent.
7.2The Customer indemnifies the Supplier and its directors, officers, employees, contractors, agents and Service Providers against losses, liabilities, damages and reasonable legal costs arising from a third-party claim to the extent caused by the Customer's breach of these Terms (including notably clause 5.2 and clause 7.1).
8. Service Outputs
8.1As between the parties, the Supplier retains all rights in Supplier Materials incorporated into or used to generate Service Outputs. To the extent intellectual property rights subsist in a Service Output, those rights vest in the Supplier, excluding Application Data and third-party materials.
8.2Subject to this clause 8, the Supplier grants the Customer a perpetual, irrevocable, worldwide, royalty-free, non-exclusive licence to use, reproduce, adapt and disclose each Service Output generated for the Customer.
8.3The Supplier will identify each Service Output as an Internal Service Output or an External Service Output when it is made available to the Customer. A Service Output not identified under this clause 8.3 is taken to be an Internal Service Output unless and until the Supplier identifies it as an External Service Output.
8.4The Customer may use an Internal Service Output for its internal security, remediation, governance, risk-management, insurance and compliance purposes.
8.5The Customer may disclose an Internal Service Output only:
- to its personnel, contractors, insurers and professional advisers who need the information for a permitted purpose and are subject to confidentiality obligations;
- with the Supplier's prior written consent; or
- where disclosure is required by law, a regulator, a court or a stock exchange, after giving the Supplier prior notice where legally permitted and taking reasonable steps to limit the disclosure.
8.6Subject to the Supplier’s prior written consent, the Customer may use and disclose an External Service Output for its legitimate business purposes, including disclosure to current or prospective customers, procurement teams, auditors, insurers, investors, regulators and professional advisers.
8.7The Customer must not alter, excerpt or present a Service Output in a manner that is misleading, removes a material qualification or implies independent human verification where none occurred.
8.8The Supplier may prepare different versions of a Service Output and may omit or redact detailed vulnerability, exploit, source-location or remediation information from an External Service Output.
8.9The Customer must not systematically extract or use any non-public methodology, taxonomy, scoring structure or other Supplier proprietary element contained in Service Outputs to develop, train or materially improve a product or service that competes with the Platform. This does not restrict use of Service Outputs for remediation, governance, procurement, audit, insurance, compliance or professional advice.
8.10The Customer must not remove proprietary notices from a Service Output.
8.11The rights and restrictions in this clause survive expiry or termination.
9. Automated analysis and security findings
9.1The Services use automated and artificial intelligence-assisted processes. Unless a Service Output expressly states otherwise, findings have not been independently verified by a human reviewer.
9.2A Service Output reflects the Application Data, access, scanning methods, vulnerability information and other inputs available at the time of the assessment.
9.3The Services and Service Outputs may contain errors, omissions, false positives or false negatives. They may not identify every vulnerability, weakness, exploit, dependency or compliance issue.
9.4The Supplier does not represent that use of the Services will make Customer Systems secure, prevent an incident, satisfy an audit, achieve certification or establish compliance with a law, standard or framework.
9.5The Customer must assess the significance of findings, obtain specialist advice where appropriate and remain responsible for remediation and security decisions.
9.6The qualifications in this clause do not exclude any guarantee, warranty or liability that cannot lawfully be excluded.
10. Privacy, confidentiality and security
10.1Each party must protect the other party's Confidential Information and use it only to perform or receive the Services and exercise rights under the agreement.
10.2A party may disclose Confidential Information to its personnel, professional advisers, insurers and Service Providers who need it for those purposes and are subject to appropriate confidentiality obligations.
10.3A party may disclose Confidential Information where required by law, after giving prior notice where legally permitted and taking reasonable steps to limit the disclosure.
10.4The Supplier will maintain reasonable technical and organisational measures appropriate to the nature and sensitivity of the following information: (a) Application Data, including Customer System Credentials; (b) Account Data containing credentials or Personal Information; (c) Confidential Information of the Customer; and (d) Service Outputs, to protect that information against unauthorised access, disclosure, loss, misuse and interference.
10.5The Supplier will notify the Customer without undue delay after becoming aware of a Security Incident that has affected, or is reasonably likely to affect, the Customer. The Supplier may give an initial notice before all details are known and will provide material updates and reasonable cooperation available to it as further information becomes available, to assist the Customer to assess and respond to the incident.
10.6The Supplier will handle Personal Information in accordance with applicable privacy law and the Privacy Policy.
10.7The Customer represents that it has given all notices and obtained all consents or other authority required to disclose Personal Information contained in Application Data to the Supplier and its Service Providers.
10.8The Supplier may use Service Providers in Australia or overseas. Information about material categories of Service Providers and overseas handling of Personal Information will be set out in the Privacy Policy or an applicable data processing agreement.
10.9The obligations in this clause survive expiry or termination.
11. Fees and payment
11.1The Customer must pay the Fees in the amounts and at the times specified in the applicable Order Form.
11.2Fees may be charged monthly, annually in advance or such other timeframe, as specified in the Order Form. The Customer authorises the Supplier and its payment provider to process recurring payments using the nominated payment method.
11.3Unless stated otherwise, Fees are exclusive of GST. The Customer must pay any applicable GST at the same time as the relevant Fee, subject to receipt of a valid tax invoice.
11.4Except as required by law or expressly provided in these Terms, prepaid Fees are non-refundable.
11.5The Supplier may change Fees for a renewal period by giving the Customer at least 30 days' notice before the renewal date. If the Customer does not accept the revised Fees, the Supplier reserves the right to prevent renewal. A Fee change will not apply during a current prepaid Subscription Term unless agreed in writing or required by a change in GST or another mandatory government charge.
11.6A Fee change does not affect Fees already paid for the current prepaid Subscription Term.
11.7The Customer must maintain complete and accurate billing information and sufficient funds or credit to pay the Fees.
11.8The Customer must notify the Supplier promptly of any bona fide invoice dispute, identify the disputed amount and the reasons for the dispute, and pay the undisputed balance when due. If an undisputed amount remains unpaid after its due date, or a dispute is not bona fide, the Supplier may give notice requiring payment. If payment is not made within 7 days after that notice, the Supplier may suspend the affected Services until payment is made.
11.9The Customer must reimburse only pass-through costs expressly stated in an Order Form or approved by the Customer in writing before they are incurred.
11.10Expiry or termination does not affect Fees accrued before the effective date of expiry or termination.
12. Suspension
12.1The Supplier may suspend access to all or part of the Platform where reasonably necessary to:
- address an actual or suspected security risk or Security Incident;
- prevent unlawful, fraudulent or materially abusive use;
- prevent material harm to the Platform, the Supplier, another customer or a third party;
- investigate a material suspected breach of these Terms;
- comply with law or a binding direction; or
- respond to non-payment under clause 11.8.
12.2Where practicable, the Supplier will give notice before suspension. If advance notice is not reasonably practicable, the Supplier will give notice promptly after suspension.
12.3A suspension must be limited in scope and duration to what is reasonably necessary. The Supplier will restore access promptly after the basis for suspension is resolved.
13. Term and termination
13.1The agreement starts when the Customer first accepts an Order Form or these Terms and continues for the Subscription Term unless terminated earlier under these Terms. The Supplier may otherwise terminate this agreement with the provision of 60 days notice.
13.2A subscription renews only if and as expressly stated in the Order Form. If renewal is automatic, the Order Form must state the renewal period, the cancellation method and deadline, and the applicable renewal Fees or how they will be determined. The Customer may prevent renewal by giving notice before the stated cancellation deadline or using the cancellation function made available through the Platform.
13.3Either party may immediately terminate the agreement by written notice if the other party:
- commits a material breach that cannot be remedied;
- fails to remedy a remediable material breach within 30 days after receiving notice describing the breach and requiring it to be remedied; or
- becomes subject to an Insolvency Event, to the extent termination is permitted by law.
13.4The Customer may terminate the affected Services under clauses 2.5(b) or 4.5 and may prevent renewal under clause 13.2.
13.5On expiry or termination:
- access to the Platform ends, except that, for 30 days after expiry or termination, the Customer may request copies of Service Outputs previously generated for it, subject to payment of outstanding undisputed Fees, the Supplier's reasonable technical capability and no legal or material security impediment. The Supplier is not required to maintain Platform access during that period;
- the Customer may continue to use and commercialise its Application Data without restriction from these Terms;
- the Customer may retain and use Service Outputs under clause 8;
- the Supplier will deal with Application Data under clause 6.8;
- each party must return or destroy the other party's Confidential Information on request, except to the extent retention is permitted under these Terms or required by law; and
- accrued rights and liabilities are not affected (including the Customer’s obligation to settle all outstanding Fees).
14. Intellectual property
14.1The Supplier and its licensors own the Supplier Materials and retain all rights, title and interest in the Supplier Materials.
14.2Subject to payment of the Fees and any lawful suspension under clause 12, the Supplier grants the Customer a non-exclusive, non-transferable, revocable right during the Subscription Term (and any renewal thereof) to permit its Authorised Users to access and use the Platform for the Customer's internal business purposes. The licence ends on expiry or termination of this agreement.
14.3The Customer does not acquire ownership of Supplier Materials, and the Supplier does not acquire ownership of Application Data.
14.4If the Customer provides feedback, suggestions or ideas about the Platform, the Customer grants the Supplier a perpetual, worldwide, royalty-free licence to use and incorporate that feedback, provided that the Supplier does not identify the Customer or disclose Application Data or Confidential Information.
14.5Third-party software, models, libraries or materials may be subject to separate licence terms. The Supplier will identify material third-party terms where they impose obligations directly on the Customer.
14.6Nothing in these Terms restricts rights that cannot lawfully be restricted.
15. Warranties and Australian Consumer Law
15.1Each party warrants that it has authority to enter into and perform the agreement.
15.2The Supplier will use reasonable care and skill in providing the Services.
15.3Subject to the Australian Consumer Law and any other rights that cannot lawfully be excluded, the Supplier does not warrant that:
- the Platform will be uninterrupted, continuously available, error-free or free from all security vulnerabilities;
- every error or defect will be corrected;
- every vulnerability or compliance issue in Customer Systems will be detected;
- a Service Output will be complete, independently verified or suitable as the sole basis for a decision; or
- use of the Services will achieve a certification, audit, insurance or regulatory outcome.
15.4Nothing in these Terms excludes, restricts or modifies a consumer guarantee, right or remedy under the Australian Consumer Law or other law that cannot lawfully be excluded, restricted or modified.
15.5Where the Australian Consumer Law permits the Supplier to limit liability for failure to comply with a consumer guarantee relating to services, the Supplier's liability is limited, at its option, to supplying the Services again or paying the cost of having the Services supplied again.
16. Liability
16.1Subject to:
- the Customer’s infringement of the Supplier’s intellectual property or ownership rights in relation to the Supplier Materials; and
- clauses 16.4 and 16.5,
neither party is liable to the other for any indirect, incidental, special or consequential loss, or for loss of profit, revenue, anticipated savings, business opportunity or goodwill, arising from the agreement.
16.2Subject to clauses 16.3 and 16.4, the Supplier's aggregate liability arising out of or in connection with the agreement, whether in contract, tort, statute or otherwise, is limited to the greater of: (a) the Fees paid or payable by the Customer in the 2 months immediately preceding the first event giving rise to the claim; and (b) AUD 1,000.
16.3Clauses 16.1 and 16.2 do not apply to fraud, wilful misconduct, death or personal injury caused by negligence to the extent liability cannot lawfully be limited, or any other liability that cannot lawfully be limited or excluded.
16.4The Customer's payment obligations, liability for infringement or misuse of Supplier Materials and liability under clause 7.2 are not limited by clauses 16.1 or 16.2. To the extent of any inconsistency, this clause 16.4 prevails.
16.5The Supplier is not liable to the extent loss is caused or increased by:
- incomplete, inaccurate, outdated or inaccessible Application Data or Customer Systems;
- the Customer's failure to review, validate or act on a Service Output;
- the Customer's failure to implement reasonable remediation or security controls;
- unauthorised access caused by the Customer's failure to secure account credentials or Customer System Credentials;
- a third-party product, service or system not selected or controlled by the Supplier; or
- an event beyond the Supplier's reasonable control.
16.6Each party must take reasonable steps to mitigate loss for which it seeks recovery.
17. Service Providers and third-party services
17.1The Supplier may use Service Providers to support or provide the Platform and Services.
17.2The Supplier remains responsible for performing its obligations under these Terms notwithstanding its use of a Service Provider.
17.3The Platform may contain links to or interoperate with third-party products or websites that are not controlled by the Supplier. The Supplier is not responsible for the content, availability or separate terms of those third-party products or websites.
17.4The Customer acknowledges that third-party hosting, telecommunications, vulnerability databases and artificial intelligence services may affect availability or processing. The Supplier will not disclose Application Data to a Service Provider for a purpose unrelated to providing or supporting the Services. The Supplier will require any Service Provider involved in training, fine-tuning or improving a model using Permitted Analytics Data to use that data only on the Supplier's behalf and in accordance with clause 6.5.
18. Force majeure
18.1Subject to the Customer’s payment obligations, a party is not liable for delay or failure to perform an obligation, other than an obligation to pay money, to the extent caused by an event beyond its reasonable control.
18.2The affected party must notify the other party promptly, take reasonable steps to reduce the effect of the event and resume performance as soon as reasonably practicable.
18.3If the event prevents a material part of the Services for more than 60 consecutive days, either party may terminate the affected Services by written notice. The Supplier will refund prepaid Fees for the unused part of the terminated Services.
19. Complaints and disputes
19.1A complaint may be submitted using the contact details stated in the Order Form or published on the Platform or the Supplier's website.
19.2Each party must give the other a reasonable opportunity to investigate and respond to a dispute before commencing proceedings, except where urgent interlocutory relief is required or a limitation period is about to expire.
19.3The parties may agree to refer a dispute to mediation. This clause does not restrict any statutory right to complain to a regulator or seek a remedy.
20. General
20.1Notices under these Terms must be in writing and may be sent: (a) to the Supplier, at the notice email address stated in the Order Form, published on the Platform or the Supplier's website for contractual notices, or otherwise notified by the Supplier in writing; and (b) to the Customer, at the email address stated in the Order Form, recorded for the Customer's account or otherwise notified by the Customer in writing. A notice is taken to be received on the next Business Day after sending unless the sender receives an automated failure notice.
20.2The Customer may assign the agreement to a purchaser of all or substantially all of its business or assets by giving prior written notice, provided the assignee is not a competitor of the Supplier and agrees in writing to be bound. Any other assignment requires the Supplier's consent, which must not be unreasonably withheld.
20.3The Supplier may assign the agreement to a related body corporate or in connection with a sale, merger, reorganisation or transfer of all or substantially all of the business relating to the Services, after giving notice to the Customer, provided that the assignee agrees in writing to assume the Supplier's obligations under the agreement. The Supplier is released from those obligations only when the assignee has assumed them.
20.4Nothing in the agreement creates a partnership, joint venture, employment, fiduciary or agency relationship.
20.5A failure or delay to exercise a right is not a waiver. A waiver must be in writing and applies only to the specific circumstance for which it is given.
20.6If a provision is illegal, invalid or unenforceable, it is to be read down to the minimum extent necessary and otherwise severed without affecting the remaining provisions.
20.7The agreement constitutes the entire agreement concerning the Services and supersedes prior representations and communications on that subject, except that nothing excludes liability for fraud or misleading or deceptive conduct.
20.8Clauses 6, 7, 8, 9, 10, 11.10, 13.5, 14, 15, 16, 19 and 20, and any provision intended by its nature to continue, survive expiry or termination.
20.9The agreement is governed by the laws of Victoria, Australia. Each party submits to the jurisdiction of the courts of Victoria and courts competent to hear appeals from them, subject to any mandatory right of a consumer to commence proceedings elsewhere.