Terms of Service

    Last updated: December 30, 2025

    These Terms of Service ("Terms", "Agreement") constitute a legally binding agreement between you (either as an individual or on behalf of an entity) and BafaTech Consulting ("AthenGuard", "we", "us", "our") regarding your access to and use of the AthenGuard compliance platform and related services (collectively, the "Services").

    PLEASE READ THESE TERMS CAREFULLY BEFORE USING OUR SERVICES. BY ACCESSING OR USING THE SERVICES, YOU ACKNOWLEDGE THAT YOU HAVE READ, UNDERSTOOD, AND AGREE TO BE BOUND BY THESE TERMS. IF YOU DO NOT AGREE TO THESE TERMS, YOU MAY NOT ACCESS OR USE THE SERVICES.

    1. Acceptance of Terms

    1.1 Binding Agreement

    By accessing, registering for, or using the AthenGuard platform, you enter into a binding legal agreement with BafaTech Consulting. These Terms govern your access to and use of:

    • The AthenGuard web application and platform
    • Mobile applications and desktop clients
    • APIs and integration endpoints
    • Documentation, guides, and support resources
    • All related services, features, and functionality

    1.2 Who May Use the Services

    Organizational Use:

    • These Services are designed for business and organizational use
    • You must be at least 18 years of age to use the Services
    • You must have authority to bind your organization to these Terms
    • Individual users must be authorized by their organization

    Account Types:

    • Enterprise Accounts: Governed by separate Master Subscription Agreement (MSA)
    • Team Accounts: Governed by these Terms and applicable order forms
    • Trial Accounts: Subject to additional trial-specific terms

    1.3 Acceptance Methods

    You accept these Terms by:

    • Clicking "I Accept" or "I Agree" during registration
    • Executing an order form or subscription agreement that references these Terms
    • Accessing or using any part of the Services
    • Continuing to use the Services after Terms updates

    1.4 Additional Terms

    Certain Services may be subject to additional terms, including:

    • Service-specific terms for integrations or add-ons
    • Acceptable Use Policy (incorporated by reference)
    • Privacy Policy (available at athenguard.io/privacy)
    • Service Level Agreement (SLA)
    • Data Processing Addendum (DPA)

    In case of conflict, service-specific terms prevail for that service, then order forms, then these Terms.

    1.5 Modifications to Terms

    We reserve the right to modify these Terms at any time. We will provide notice of material changes:

    • 30 days advance notice via email to account administrators
    • In-platform notifications
    • Updated "Last updated" date at the top of this document

    Your Options:

    • Continued use after the effective date constitutes acceptance
    • If you disagree, you may terminate your account before the effective date
    • Enterprise customers may have different amendment procedures per their MSA

    2. Description of Services

    2.1 Platform Overview

    AthenGuard provides a continuous compliance monitoring and management platform designed to help organizations:

    Core Capabilities:

    • Map and manage compliance across multiple frameworks (SOC 2, ISO 27001, NDPR, PCI DSS, NIST, HIPAA, etc.)
    • Automate evidence collection from connected systems and endpoints
    • Validate security controls in real-time
    • Generate audit-ready reports and compliance documentation
    • Track remediation activities and compliance gaps
    • Maintain immutable audit trails of all activities

    Key Components:

    • CROP Engine: Compliance frameworks and requirements management
    • C3E Application: Evidence collection, validation, and storage
    • Helios Suite: Monitoring, alerting, and analytics
    • Agent Infrastructure: Distributed evidence collection agents
    • Integration Hub: Connectors for third-party systems

    2.2 Service Models

    Software as a Service (SaaS):

    • Cloud-hosted, multi-tenant architecture
    • Automatic updates and feature releases
    • Included infrastructure and maintenance
    • Standard data retention policies

    Private Cloud / On-Premises:

    • Dedicated infrastructure (where available)
    • Custom deployment configurations
    • Extended data residency options
    • Subject to separate agreement and pricing

    Hybrid Deployments:

    • Cloud-based control plane with on-premises agents
    • Flexible data routing and storage options
    • Custom integration architectures

    2.3 Service Tiers

    Services are provided according to your subscription tier:

    Essential:

    • Core compliance management features
    • Up to 3 frameworks
    • Standard evidence collection
    • Email support (business hours)
    • 99.5% uptime SLA

    Professional:

    • Everything in Essential
    • Unlimited frameworks
    • Advanced automation and integrations
    • Priority support with phone/chat
    • 99.9% uptime SLA
    • Custom reporting

    Enterprise:

    • Everything in Professional
    • Dedicated tenant infrastructure options
    • SSO/SAML integration
    • Custom retention policies
    • 24/7 premium support with dedicated CSM
    • 99.95% uptime SLA
    • API rate limit increases
    • Professional services included

    2.4 Beta and Preview Features

    We may offer beta, preview, or experimental features:

    • Marked clearly as "Beta", "Preview", or "Labs"
    • Provided "as is" without warranties
    • May be modified or discontinued without notice
    • Subject to additional terms and conditions
    • Not covered by SLA commitments
    • May have data retention limitations

    Your use of beta features constitutes acceptance of these additional risks and limitations.

    2.5 Service Modifications

    We reserve the right to:

    • Add, modify, or discontinue features
    • Update platform capabilities and architecture
    • Change APIs (with reasonable notice and backward compatibility efforts)
    • Implement new security controls or requirements

    Our Commitments:

    • 90 days notice for deprecation of major features
    • 30 days notice for breaking API changes
    • Migration assistance for significant changes
    • Documentation of all modifications

    3. Account Registration and Management

    3.1 Account Creation

    Registration Requirements:

    • Provide accurate, complete, and current information
    • Use a valid business email address
    • Accept these Terms and Privacy Policy
    • Complete email verification
    • Provide necessary business information (company name, size, industry)

    Verification:

    • We may verify your identity and business credentials
    • Additional documentation may be required for certain features
    • We reserve the right to refuse service or terminate accounts

    3.2 Account Credentials and Security

    Your Responsibilities:

    • Maintain confidentiality of passwords and authentication credentials
    • Use strong, unique passwords
    • Enable multi-factor authentication (MFA) when available
    • Immediately notify us of unauthorized access or security breaches
    • Ensure all users with access to your account comply with these Terms

    Security Requirements:

    • MFA is mandatory for administrative users
    • Password complexity requirements must be met
    • Session timeouts will be enforced
    • IP allowlisting available for additional security

    Account Compromise:

    If you believe your account has been compromised:

    • Change your password immediately
    • Contact
    • Review audit logs for suspicious activity
    • Revoke access for compromised credentials

    3.3 User Roles and Permissions

    You are responsible for:

    • Defining appropriate roles and permissions for your users
    • Implementing principle of least privilege
    • Regular access reviews and recertification
    • Promptly removing access for departed employees
    • Training users on security and acceptable use

    Available Roles:

    • Organization Administrator
    • Compliance Officer
    • Auditor (read-only)
    • Evidence Contributor
    • Custom roles (Enterprise tier)

    3.4 Account Information Updates

    You must:

    • Keep contact information current
    • Update billing details promptly
    • Notify us of organization changes (mergers, acquisitions, name changes)
    • Maintain accurate user lists

    3.5 Account Termination

    By You:

    • Cancel anytime through platform settings or written notice
    • Export your data before termination
    • Pay all outstanding fees through the end of current billing period
    • 30-day data retention after cancellation (then permanent deletion)

    By Us:

    We may suspend or terminate your account:

    • For violation of these Terms
    • For non-payment after 15 days notice
    • If required by law or regulatory order
    • For fraudulent or harmful activity
    • If your use poses security risks to other users

    Notice and Opportunity to Cure:

    • We will provide 10 days notice for most violations
    • Immediate suspension for security threats or illegal activity
    • Opportunity to cure violations where appropriate

    4. Acceptable Use Policy

    4.1 Permitted Uses

    You may use the Services only for lawful business purposes, including:

    • Compliance management and audit preparation
    • Security control monitoring and validation
    • Risk assessment and remediation tracking
    • Evidence collection and documentation
    • Regulatory reporting and certification support

    4.2 Prohibited Activities

    You agree NOT to:

    Illegal and Harmful Activities:

    • Violate any applicable laws, regulations, or third-party rights
    • Engage in fraudulent, defamatory, or malicious activities
    • Facilitate money laundering, terrorism, or other criminal activities
    • Harass, threaten, or harm others
    • Impersonate any person or entity

    Security Violations:

    • Attempt unauthorized access to any systems, accounts, or networks
    • Probe, scan, or test vulnerabilities without authorization
    • Breach authentication or security measures
    • Intercept or monitor data not intended for you
    • Launch denial-of-service attacks or interfere with service operation
    • Distribute malware, viruses, or harmful code

    Platform Misuse:

    • Reverse engineer, decompile, or disassemble the Services
    • Remove or modify proprietary notices or labels
    • Frame or mirror any content without permission
    • Use automated tools to access the Services (except authorized APIs)
    • Create derivative works or competing products
    • Overload infrastructure or abuse rate limits

    Data and Content Violations:

    • Upload content you don't have rights to
    • Store or transmit illegal, defamatory, or obscene material
    • Violate intellectual property rights
    • Transmit unsolicited communications (spam)
    • Store personal data of minors

    Account Misuse:

    • Share account credentials with unauthorized parties
    • Create accounts using false information
    • Purchase, sell, or transfer accounts
    • Use accounts to resell or sublicense the Services

    4.3 Resource Usage

    Fair Use:

    • Services are provided for reasonable business use
    • Excessive use that impacts other tenants may be throttled
    • We may impose rate limits or usage caps
    • Bulk operations should use provided APIs

    Storage Limits:

    • Evidence storage subject to plan limits
    • Retention policies apply per configuration
    • Additional storage available at standard rates

    4.4 Compliance with Laws

    You are responsible for:

    • Complying with all applicable export control and sanctions laws
    • Obtaining necessary licenses for data transfers
    • Meeting industry-specific regulations (HIPAA, PCI DSS, etc.)
    • Ensuring your use complies with data protection laws
    • Maintaining proper authorization for all monitored systems

    4.5 Monitoring and Enforcement

    Our Rights:

    • Monitor for compliance with these Terms
    • Investigate suspected violations
    • Suspend or terminate accounts for violations
    • Preserve and disclose information as required by law
    • Implement technical measures to enforce these policies

    We Are Not Obligated To:

    • Monitor all user activities
    • Screen content before it is posted
    • Remove any specific content
    • Resolve disputes between users

    4.6 Reporting Violations

    To report violations:

    • Email:
    • Include account details and description of violation
    • Provide relevant evidence (screenshots, logs, etc.)
    • We will investigate and respond within 5 business days

    5. Intellectual Property Rights

    5.1 AthenGuard's Intellectual Property

    Ownership:

    AthenGuard and its licensors own all rights, title, and interest in:

    • The Services, including all software, code, and algorithms
    • Platform design, user interface, and architecture
    • Documentation, guides, and training materials
    • Trademarks, logos, and brand elements
    • Proprietary methodologies and processes
    • All improvements and derivative works

    Protected by:

    • Copyright, trademark, patent, and trade secret laws
    • International intellectual property treaties
    • Contractual restrictions

    5.2 Your License to Use the Services

    Grant:

    Subject to your compliance with these Terms, we grant you a:

    • Limited, non-exclusive, non-transferable, revocable license
    • To access and use the Services
    • For your internal business purposes only
    • During the subscription term

    Restrictions:

    You may not:

    • Sublicense, resell, or distribute the Services
    • Use the Services for service bureau or time-sharing purposes
    • Make the Services available to competitors
    • Use the Services to develop competing products
    • Remove or modify any proprietary notices

    5.3 Your Data and Content

    You Retain Ownership:

    • All compliance data, evidence, and documentation you upload
    • Custom policies, procedures, and control definitions
    • Reports, assessments, and analysis you generate
    • Organizational information and configurations

    License to AthenGuard:

    You grant us a limited license to:

    • Store, process, and display your data
    • Perform services you request
    • Improve and optimize platform performance
    • Generate anonymized analytics and aggregated insights
    • Backup and recover your data

    Our Commitments:

    • We will not sell or share your data with third parties for their marketing
    • We will not use your compliance data to train AI models
    • We will process data only as instructed by you
    • We maintain tenant isolation and data segregation

    5.4 Feedback and Suggestions

    Voluntary Contributions:

    If you provide feedback, suggestions, or ideas:

    • They are provided voluntarily
    • No compensation is required
    • We may use them without restriction or attribution
    • You waive any intellectual property claims
    • They become our property

    This includes:

    • Feature requests and product ideas
    • Bug reports and technical feedback
    • User experience suggestions
    • Integration proposals

    5.5 Open Source Components

    The Services may include open source software:

    • Subject to separate open source licenses
    • Available for inspection upon request
    • Governed by their respective license terms
    • AthenGuard complies with all open source obligations

    5.6 Third-Party Materials

    The Services may incorporate third-party:

    • Software libraries and frameworks
    • Data sources and threat intelligence feeds
    • Icons, fonts, and design elements
    • APIs and integration components

    These remain the property of their respective owners.

    5.7 Trademark Usage

    AthenGuard Trademarks:

    • "AthenGuard" and associated logos are our trademarks
    • May not be used without prior written permission
    • Customer may reference our services in marketing (with approval)
    • Must comply with our trademark guidelines

    Your Trademarks:

    • We may display your name/logo as a customer reference
    • Only with your prior written consent
    • You may revoke permission at any time
    • Subject to our trademark usage guidelines

    6. Data Protection and Privacy

    6.1 Data Ownership and Control

    You Own Your Data:

    • You retain all ownership rights to your data
    • We are a data processor acting on your behalf
    • You control access, retention, and deletion
    • You determine what data to collect and store

    6.2 Data Processing

    Our Role:

    • We process data solely to provide the Services
    • We follow your instructions regarding data handling
    • We implement appropriate technical and organizational measures
    • We maintain data processing agreements (DPAs)

    Processing Activities:

    • Evidence collection and storage
    • Compliance analysis and reporting
    • Audit trail generation
    • Integration with authorized third-party services

    6.3 Privacy Policy

    Our Privacy Policy governs:

    • What information we collect
    • How we use and protect information
    • Your privacy rights and choices
    • International data transfers

    The Privacy Policy is incorporated by reference into these Terms. Available at: athenguard.io/privacy

    6.4 Data Location and Residency

    Default Storage:

    • Primary data centers in US, EU, Nigeria
    • You may select your preferred region
    • Data residency options available per plan tier

    Data Transfers:

    • May transfer data internationally to provide Services
    • Governed by Standard Contractual Clauses (SCCs)
    • Compliant with GDPR, NDPR, and applicable laws
    • Encryption in transit and at rest

    6.5 Data Security

    We implement:

    • Encryption (TLS 1.3, AES-256)
    • Multi-factor authentication
    • Role-based access controls
    • Network segmentation and tenant isolation
    • Regular security assessments and penetration testing
    • 24/7 security monitoring

    Full details in our Security Documentation and Privacy Policy.

    6.6 Data Retention

    Active Accounts:

    • Data retained throughout subscription period
    • Subject to your configured retention policies
    • Available for immediate access and export

    Terminated Accounts:

    • 30-day grace period for data recovery
    • Complete deletion within 90 days
    • Some audit logs retained per legal requirements
    • Deletion certificates available upon request

    6.7 Data Portability

    You may export your data at any time:

    • Through platform export tools
    • In standard formats (JSON, CSV, PDF)
    • Including all evidence, reports, and configurations
    • Via API for automated exports

    6.8 Subprocessors

    We engage carefully selected subprocessors:

    • Cloud hosting and infrastructure providers
    • Email and communication services
    • Support and analytics tools
    • Payment processors

    Our Commitments:

    • Maintain current subprocessor list (available on request)
    • Conduct security assessments of all subprocessors
    • Bind subprocessors to equivalent data protection obligations
    • Provide notice of new subprocessors

    6.9 Security Incidents

    Breach Notification:

    If we discover a data breach affecting your data:

    • We will notify you without undue delay
    • Within 72 hours of discovery (or as required by law)
    • Via email to account administrators
    • Including nature of breach, affected data, and remediation steps

    Your Responsibilities:

    • Implement your own incident response procedures
    • Notify affected individuals as required by law
    • Cooperate with our investigation and remediation

    6.10 Compliance Support

    We provide documentation to support your compliance efforts:

    • SOC 2 Type II reports
    • ISO 27001 certificates
    • Security questionnaire responses
    • DPA and SCC documentation
    • Privacy certifications

    7. Payment Terms

    7.1 Subscription Fees

    Pricing:

    • Fees as specified in your order form or subscription plan
    • Pricing available at athenguard.io/pricing
    • Custom pricing for enterprise agreements
    • All fees in USD unless otherwise specified

    Subscription Types:

    • Monthly subscriptions (billed monthly)
    • Annual subscriptions (billed annually, typically discounted)
    • Multi-year agreements (custom terms)

    7.2 Billing and Payment

    Payment Methods:

    • Credit card (Visa, Mastercard, Amex)
    • ACH/wire transfer (annual plans only)
    • Invoice billing (Enterprise tier, credit approval required)

    Billing Cycle:

    • Charges occur on subscription anniversary date
    • Prorated for mid-cycle changes
    • Usage-based charges billed monthly in arrears

    Automatic Renewal:

    • Subscriptions renew automatically
    • At then-current rates unless locked in agreement
    • 30 days notice of price changes
    • Cancel anytime to prevent next renewal

    7.3 Taxes

    Tax Responsibility:

    • Fees exclude applicable taxes (VAT, GST, sales tax, etc.)
    • You are responsible for all taxes except our income taxes
    • Provide valid tax exemption certificates if applicable
    • International customers may owe import duties or levies

    Invoicing:

    • Itemized invoices provided via email
    • Available in platform under Billing section
    • Include tax breakdown where applicable

    7.4 Late Payment

    Consequences:

    • Late fees of 1.5% per month (or maximum allowed by law)
    • Service suspension after 15 days notice
    • Account termination after 30 days
    • Collection costs and legal fees may apply

    Disputes:

    • Notify us within 30 days of invoice date
    • Pay undisputed amounts while resolving
    • We will work with you in good faith

    7.5 Refund Policy

    No Refunds:

    Subscription fees are non-refundable except:

    • Service availability below SLA thresholds (see Section 8)
    • Billing errors (corrected via credit)
    • Cancellation within trial period
    • Legal requirements in your jurisdiction

    Trial Periods:

    • Free trial accounts not charged until conversion
    • Must cancel before trial end to avoid charges
    • Data deleted after trial expiration unless converted

    7.6 Plan Changes

    Upgrades:

    • Effective immediately
    • Prorated charges for remainder of billing period
    • Access to upgraded features immediately

    Downgrades:

    • Effective at end of current billing period
    • May require data/feature migration
    • No refunds for unused portion of higher-tier plan

    7.7 Usage-Based Charges

    Some features incur additional costs:

    • Storage beyond plan limits
    • API calls exceeding tier limits
    • Premium integrations
    • Professional services hours
    • Dedicated infrastructure

    Usage Monitoring:

    • Real-time usage dashboard
    • Email alerts at 75% and 90% of limits
    • Option to set hard caps or auto-scaling

    7.8 Price Changes

    Notice:

    • 30 days advance notice for increases
    • Applies to renewal, not current term
    • Annual plans locked for term duration

    Your Options:

    • Accept new pricing and continue service
    • Downgrade to different plan
    • Cancel before renewal to avoid increase

    8. Service Level Agreement (SLA)

    8.1 Availability Commitment

    Uptime Guarantees:

    • Essential Tier: 99.5% monthly uptime
    • Professional Tier: 99.9% monthly uptime
    • Enterprise Tier: 99.95% monthly uptime

    Measurement:

    • Calculated monthly per calendar month
    • Based on platform availability for API and web interface
    • Excludes scheduled maintenance and customer-initiated downtime

    8.2 Scheduled Maintenance

    Maintenance Windows:

    • Announced 7 days in advance via email and status page
    • Typically performed during low-usage periods
    • Maximum 4 hours per month for standard maintenance
    • Does not count against SLA uptime

    Emergency Maintenance:

    • May be performed with shorter notice
    • Only for critical security or stability issues
    • Still excluded from SLA calculations

    8.3 Service Credits

    Eligibility:

    If we fail to meet SLA commitments:

    • Must submit claim within 30 days of incident
    • Provide details of service interruption experienced
    • Credits issued as percentage of monthly fees

    Credit Schedule:

    Actual UptimeCredit
    99.0% - 99.5%10%
    95.0% - 99.0%25%
    Below 95.0%50%

    Limitations:

    • Maximum credit: 50% of monthly fees for affected service
    • Credits applied to future invoices (not cash refunds)
    • Only remedy for SLA breaches
    • Not available for free or trial accounts

    8.4 Exclusions from SLA

    Downtime does not count if caused by:

    • Factors outside our reasonable control (force majeure)
    • Your acts or omissions
    • Internet backbone or connectivity issues
    • Denial-of-service attacks
    • Third-party software or services not provided by us
    • Beta or preview features
    • Suspension due to Terms violation

    8.5 Support Response Times

    Support Channels:

    • Essential: Email support, business hours (9am-5pm local time)
    • Professional: Email + phone, extended hours (7am-9pm local time)
    • Enterprise: 24/7 email, phone, chat with dedicated CSM

    Response Time Targets:

    SeverityEssentialProfessionalEnterprise
    Critical (P1)4 hours1 hour30 minutes
    High (P2)8 hours4 hours2 hours
    Medium (P3)24 hours8 hours4 hours
    Low (P4)48 hours24 hours8 hours

    Severity Definitions:

    • P1: Complete service outage affecting all users
    • P2: Major functionality impaired, significant impact
    • P3: Minor functionality affected, workaround available
    • P4: General questions, feature requests, cosmetic issues

    8.6 Status and Incident Communication

    Status Page:

    • Real-time status at status.athenguard.io
    • Subscribe to email/SMS updates
    • Historical uptime data available
    • Incident post-mortems published

    Incident Updates:

    • Initial acknowledgment within 30 minutes for P1
    • Regular updates every 2 hours during incidents
    • Post-incident reports within 5 business days

    9. Warranties and Disclaimers

    9.1 Limited Warranty

    We warrant that:

    • Services will perform substantially as described in documentation
    • We will use commercially reasonable efforts to maintain service availability
    • We have the right to provide the Services to you
    • Services will not violate third-party intellectual property rights

    Warranty Period: Duration of your subscription

    9.2 Disclaimer of Warranties

    EXCEPT AS EXPRESSLY PROVIDED IN SECTION 9.1, THE SERVICES ARE PROVIDED "AS IS" AND "AS AVAILABLE" WITHOUT WARRANTIES OF ANY KIND, EITHER EXPRESS OR IMPLIED.

    WE SPECIFICALLY DISCLAIM:

    • Implied warranties of merchantability, fitness for particular purpose, non-infringement
    • Guarantees that services will be uninterrupted, error-free, or secure
    • Warranties regarding results, accuracy, or reliability of information
    • Representations about third-party integrations or services

    9.3 No Compliance Guarantee

    Important Limitations:

    • AthenGuard is a tool to facilitate compliance management
    • We do not guarantee that your use will result in compliance with any specific regulation
    • You are solely responsible for achieving and maintaining compliance
    • You must conduct your own assessments and obtain appropriate certifications
    • We do not provide legal, audit, or compliance advice

    Audit Readiness vs. Compliance:

    • We help you prepare for audits
    • Final compliance determinations rest with auditors and regulators
    • You must validate all automated findings
    • Professional judgment required for control implementations

    9.4 Third-Party Services

    No Warranty for Integrations:

    • Third-party services operate independently
    • We don't control their availability, security, or functionality
    • Integration failures don't constitute breach by us
    • Check third-party terms and warranties separately

    9.5 Beta Features

    Additional Disclaimers for Beta/Preview:

    • Provided "as is" with all faults
    • May contain errors or defects
    • Performance may vary significantly
    • Features may change or be discontinued
    • Data loss possible; backup recommended
    • Not recommended for production use

    10. Limitation of Liability

    10.1 Maximum Liability Cap

    TO THE MAXIMUM EXTENT PERMITTED BY LAW, OUR TOTAL AGGREGATE LIABILITY ARISING FROM OR RELATED TO THESE TERMS OR THE SERVICES SHALL NOT EXCEED:

    • For Monthly Plans: The fees paid by you in the 3 months immediately preceding the claim
    • For Annual Plans: The fees paid by you in the 12 months immediately preceding the claim
    • For Trial/Free Accounts: $100 USD

    10.2 Exclusion of Consequential Damages

    WE SHALL NOT BE LIABLE FOR:

    • Indirect, incidental, special, exemplary, or consequential damages
    • Loss of profits, revenue, data, or business opportunities
    • Cost of substitute goods or services
    • Business interruption or system failure
    • Reputational harm or goodwill loss
    • Failure to achieve compliance or pass audits

    EVEN IF:

    • We were advised of possibility of such damages
    • The limited remedies fail of their essential purpose
    • Damages were foreseeable

    10.3 Exceptions to Limitations

    Limitations do not apply to:

    • Your indemnification obligations (Section 11)
    • Your payment obligations
    • Your violations of intellectual property rights
    • Gross negligence or willful misconduct
    • Death or personal injury caused by our negligence
    • Violations that cannot be limited by law
    • Data breaches caused by our failure to implement reasonable security

    10.4 Basis of the Bargain

    You acknowledge that:

    • These limitations are fundamental elements of the agreement
    • We would not provide Services at current pricing without these limitations
    • You have had opportunity to obtain insurance or negotiate different terms
    • These limitations allocate risk fairly between parties

    10.5 Claim Procedures

    To bring a claim:

    • Provide written notice within 30 days of event giving rise to claim
    • Include detailed description and supporting documentation
    • Attempt good faith resolution before litigation
    • File suit within 1 year of claim arising (or jurisdictional maximum if less)

    10.6 Multiple Claims

    If you suffer multiple incidents:

    • Liability cap applies in aggregate, not per incident
    • Related incidents treated as single claim
    • Annual reset of liability cap at subscription renewal

    10.7 Force Majeure

    We are not liable for delays or failures caused by:

    • Natural disasters, pandemics, acts of God
    • War, terrorism, civil unrest, government actions
    • Internet infrastructure failures beyond our control
    • Cyberattacks (unless caused by our gross negligence)
    • Labor disputes, strikes, supplier failures
    • Other events outside our reasonable control

    Our Obligations During Force Majeure:

    • Use commercially reasonable efforts to mitigate impact
    • Provide timely updates on status
    • Resume normal operations as soon as practicable
    • Right to terminate if event exceeds 30 days

    11. Indemnification

    11.1 Your Indemnification Obligations

    You agree to indemnify, defend, and hold harmless AthenGuard, its affiliates, officers, directors, employees, agents, and licensors from and against any claims, liabilities, damages, losses, costs, or expenses (including reasonable attorneys' fees) arising from or related to:

    Your Use of Services:

    • Your violation of these Terms or Acceptable Use Policy
    • Your violation of any law, regulation, or third-party rights
    • Your data, content, or compliance configurations
    • Your negligence or willful misconduct
    • Claims by your users, employees, or contractors

    Your Business Operations:

    • Claims that your use of Services violates IP rights
    • Claims related to your collection or handling of personal data
    • Regulatory actions against your organization
    • Claims from your end users or customers
    • Employment claims from your staff members using the platform

    11.2 Our Indemnification Obligations

    We agree to indemnify, defend, and hold you harmless from claims that:

    • The Services, when used as authorized, infringe third-party intellectual property rights
    • We violated applicable data protection laws in processing your data

    Limitations:

    • Only applies to unmodified Services used in accordance with these Terms
    • Not applicable if infringement results from your modifications or combinations
    • Not applicable to beta features or services provided free of charge

    11.3 Indemnification Procedures

    For indemnified party to receive protection:

    • Prompt Notice: Provide written notice within 30 days of learning of claim
    • Cooperation: Reasonably cooperate in defense of claim
    • Control: Allow indemnifying party to control defense and settlement
    • No Prejudice: Don't admit liability or settle without consent

    Indemnifying Party Rights:

    • Select legal counsel
    • Control litigation strategy and settlement negotiations
    • Settle on reasonable terms without indemnified party's consent (if no admission of liability required)

    11.4 Exclusive Remedy for IP Claims

    If Services are claimed to infringe, we may (at our option):

    • Obtain rights for you to continue using Services
    • Replace or modify Services to be non-infringing
    • If neither option is commercially reasonable, terminate Services and refund prepaid fees (pro-rated)

    This is your sole and exclusive remedy for intellectual property infringement claims.

    11.5 Mitigation Cooperation

    Both parties agree to:

    • Mitigate damages where reasonably possible
    • Cooperate in defense strategy
    • Preserve relevant evidence
    • Participate in settlement discussions in good faith

    12. Confidentiality

    12.1 Definition of Confidential Information

    "Confidential Information" means all non-public information disclosed by one party ("Disclosing Party") to the other ("Receiving Party"), including:

    AthenGuard's Confidential Information:

    • Platform architecture, source code, and algorithms
    • Security practices and vulnerability information
    • Pricing, financial information, and business strategies
    • Product roadmaps and unreleased features
    • Customer lists and usage statistics

    Your Confidential Information:

    • Compliance data, evidence, and assessments
    • Security configurations and control implementations
    • Business information and organizational data
    • Authentication credentials and access tokens
    • Audit findings and remediation plans

    Marked or Reasonably Understood as Confidential:

    • Information marked "Confidential," "Proprietary," or similar
    • Information disclosed under circumstances indicating confidentiality
    • Information about security vulnerabilities or incidents

    12.2 Obligations

    Receiving Party must:

    • Protect Confidential Information with same care as own confidential information (minimum reasonable care)
    • Use Confidential Information only for purposes of these Terms
    • Limit disclosure to employees and contractors with need to know
    • Not disclose to third parties without written consent
    • Return or destroy upon request or termination

    12.3 Exceptions

    Confidential Information does not include information that:

    • Was publicly known before disclosure
    • Becomes public through no fault of Receiving Party
    • Was independently developed without access to Confidential Information
    • Was rightfully received from third party without confidentiality obligations
    • Must be disclosed by law or court order (with notice to Disclosing Party if permitted)

    12.4 Compelled Disclosure

    If legally required to disclose:

    • Provide prompt notice to Disclosing Party (unless prohibited)
    • Cooperate in seeking protective order
    • Disclose only minimum information required
    • Request confidential treatment from receiving authority

    12.5 Duration

    Confidentiality obligations survive for:

    • 3 years after termination of these Terms
    • Indefinitely for trade secrets
    • Indefinitely for personal data and compliance information

    13. Term and Termination

    13.1 Term

    Agreement Duration:

    • Begins upon first access or acceptance
    • Continues for subscription term (monthly or annual)
    • Renews automatically unless cancelled
    • Survives through wind-down period

    13.2 Termination by You

    You may terminate:

    • For convenience with 30 days written notice
    • Immediately if we materially breach and fail to cure within 30 days
    • Through platform cancellation settings
    • By written notice to

    Effect of Termination:

    • Access continues through end of paid period
    • No refunds for unused time (except as required by law)
    • Data available for export during notice period

    13.3 Termination by Us

    We may terminate or suspend immediately:

    • For material breach of these Terms
    • Non-payment after 15 days notice
    • Violation of Acceptable Use Policy
    • Fraudulent or illegal activities
    • If required by law or regulation
    • Risk to platform security or other customers

    We may terminate with notice:

    • For convenience with 90 days notice (providing refund of prepaid fees)
    • If you become competitor or launch competing service
    • Due to legal or regulatory changes

    13.4 Effect of Termination

    Upon Termination:

    • All access rights immediately cease (except data export period)
    • Outstanding fees become immediately due
    • Licenses granted under these Terms terminate
    • Mutual return or destruction of Confidential Information

    Data Retention:

    • 30-day grace period for data recovery
    • Self-service export tools remain available
    • After 30 days, deletion process begins
    • Complete deletion within 90 days

    Survival:

    Sections survive termination:

    • Payment obligations (Section 7)
    • Intellectual Property (Section 5)
    • Warranties and Disclaimers (Section 9)
    • Limitation of Liability (Section 10)
    • Indemnification (Section 11)
    • Confidentiality (Section 12)
    • Dispute Resolution (Section 14)

    13.5 Transition Assistance

    Upon termination, we will:

    • Provide data export in standard formats
    • Reasonable assistance with data migration (fees may apply for extensive assistance)
    • Maintain data integrity during transition
    • Provide final invoice and usage reports

    We are not obligated to:

    • Provide source code or proprietary methodologies
    • Convert data to competitor formats
    • Provide ongoing technical support after termination
    • Retain data beyond stated retention periods

    14. Dispute Resolution

    14.1 Informal Resolution

    Before filing formal claim:

    • Contact us at
    • Provide detailed description of dispute
    • Allow 30 days for good faith negotiation
    • Escalate to senior management if needed

    Benefits:

    • Faster and less expensive resolution
    • Preserves business relationship
    • Flexible solutions possible

    14.2 Governing Law

    These Terms are governed by:

    • The laws of the State of Georgia, United States
    • Without regard to conflict of law principles
    • Federal laws of the United States where applicable
    • Excluding the UN Convention on Contracts for the International Sale of Goods

    14.3 Jurisdiction and Venue

    For litigation not subject to arbitration:

    • Exclusive jurisdiction: State or Federal courts located in the State of Georgia, USA (specifically Fulton County or the corresponding federal district)
    • You consent to personal jurisdiction in this venue
    • You waive objections based on forum non conveniens

    14.4 Arbitration

    Either party may elect binding arbitration:

    • Administered by the American Arbitration Association (AAA) under its Commercial Arbitration Rules
    • Single arbitrator mutually selected (or appointed by the AAA)
    • Seat of arbitration: Atlanta, Georgia, USA
    • Language: English

    Exceptions - Not Subject to Arbitration:

    • Intellectual property disputes
    • Injunctive relief requests
    • Claims under $25,000 (small claims court)
    • Claims for emergency relief

    Arbitration Process:

    • Notice of arbitration within 60 days of dispute arising
    • Discovery limited to essential documents
    • Hearing within 6 months where possible
    • Award final and binding, limited appeal rights
    • Each party bears own costs unless award specifies otherwise

    14.5 Class Action Waiver

    YOU AND ATHENGUARD AGREE:

    • All claims must be brought individually
    • No class actions, representative actions, or consolidated proceedings
    • No acting as representative or class member in others' proceedings
    • Arbitrator cannot consolidate claims without consent

    If Class Action Waiver Unenforceable:

    • Arbitration clause does not apply
    • Litigation proceeds in courts specified above

    14.6 Injunctive Relief

    Either party may seek:

    • Temporary restraining orders
    • Preliminary injunctions
    • Emergency equitable relief

    Without waiting for arbitration when:

    • Immediate harm likely
    • Breach of confidentiality obligations
    • Intellectual property infringement
    • Security threats to platform or users

    14.7 Fees and Costs

    General Rule:

    • Each party bears own attorneys' fees and costs
    • Unless statute or these Terms provide otherwise
    • Prevailing party in IP disputes recovers reasonable fees

    Arbitration Costs:

    • Filing fees split equally
    • Arbitrator fees split equally
    • Each party's representation costs borne separately

    15. General Provisions

    15.1 Entire Agreement

    These Terms, together with:

    • Privacy Policy
    • Order forms and subscription agreements
    • Service Level Agreement
    • Data Processing Addendum
    • Any referenced incorporated policies

    Constitute the entire agreement and supersede all prior:

    • Negotiations and discussions
    • Proposals and counterproposals
    • Written or oral agreements
    • Industry customs or practices

    15.2 Amendments

    Modification Process:

    • We may modify Terms at any time
    • Material changes with 30 days notice
    • Notice via email and in-platform notification
    • Continued use constitutes acceptance

    Your Options:

    • Accept changes and continue using Services
    • Terminate before effective date to avoid changes
    • Enterprise customers may have different amendment rights per MSA

    Unauthorized Modifications:

    • These Terms can only be amended by us in writing
    • Your purchase orders or terms do not modify this Agreement
    • Additional or different terms in your documents are rejected

    15.3 Assignment

    By You:

    • You may not assign without our prior written consent
    • Assignment without consent is void
    • Permitted for corporate reorganization or sale if successor agrees to be bound

    By Us:

    • We may freely assign to affiliates
    • We may assign in connection with merger, acquisition, or sale of business
    • We will provide notice of assignment

    15.4 Notices

    To You:

    • Email to address associated with account
    • In-platform notifications
    • Deemed received when sent (if email) or when displayed (if in-platform)

    To Us:

    • Email:
    • Legal notices require written confirmation of receipt

    Routine Communications:

    • Support:
    • Billing:
    • Security:

    15.5 Force Majeure

    Neither party liable for delays or failures caused by:

    • Acts of God, natural disasters, pandemics
    • War, terrorism, civil unrest, government acts
    • Strikes, labor disputes, supplier failures
    • Internet infrastructure failures
    • Power outages, telecommunications failures
    • Events beyond reasonable control

    Obligations During Force Majeure:

    • Promptly notify other party
    • Use reasonable efforts to mitigate
    • Resume performance when able
    • Right to terminate if exceeds 60 days

    15.6 Relationship of Parties

    Independent Contractors:

    • Parties are independent contractors
    • No partnership, joint venture, or agency relationship
    • Neither party has authority to bind the other
    • No employee-employer relationship created

    15.7 Severability

    If any provision is found invalid or unenforceable:

    • Remaining provisions continue in full force
    • Invalid provision modified to minimum extent necessary
    • Parties' intent preserved to maximum extent possible
    • Entire Terms not rendered void

    15.8 Waiver

    Failure to enforce any right:

    • Does not constitute waiver of that right
    • Does not waive future enforcement
    • Must be in writing and signed to be effective
    • Applies only to specific instance waived

    15.9 Interpretation

    Interpretive Rules:

    • Headings for convenience only, don't affect meaning
    • "Including" means "including but not limited to"
    • Singular includes plural and vice versa
    • "Days" means calendar days unless specified otherwise
    • "May" indicates discretion; "shall" or "will" indicates obligation

    15.10 Language

    Controlling Language:

    • English version controls in case of translations
    • Translations provided for convenience only
    • Disputes resolved based on English text

    15.11 Third-Party Beneficiaries

    No Third-Party Rights:

    • These Terms benefit only you and AthenGuard
    • No third parties may enforce Terms
    • Except: our affiliates and licensors may enforce IP protections

    15.12 Export Compliance

    You agree:

    • Services subject to export control laws
    • You will not export or re-export in violation of law
    • You are not on restricted party lists
    • You will not use Services in embargoed countries
    • You will comply with all applicable trade restrictions

    15.13 Government Use

    If you are a government entity:

    • Services are "Commercial Items" as defined in FAR 2.101
    • Provided with only those rights granted to commercial customers
    • Use, reproduction, and disclosure subject to these Terms

    15.14 Publicity

    Customer References:

    • We may list you as customer on website and marketing materials
    • We may use your logo subject to trademark guidelines
    • You may opt-out at any time by written request
    • Case studies and testimonials require separate approval

    15.15 Compliance with Laws

    Both parties agree:

    • To comply with all applicable laws and regulations
    • To obtain necessary licenses and authorizations
    • To comply with anti-corruption laws (FCPA, UK Bribery Act, etc.)
    • To comply with sanctions and export control laws
    • To comply with data protection and privacy laws

    15.16 Feedback and Suggestions

    If you provide us with feedback:

    • You grant us unlimited rights to use it
    • No compensation required
    • May be incorporated into Services
    • You waive moral rights and attribution claims

    16. Contact Information

    16.1 General Inquiries

    Email:

    Website: www.athenguard.io

    Support Portal: support.athenguard.io

    16.2 Legal and Compliance

    Legal Department:

    Privacy Inquiries:

    Data Protection Officer:

    Security Issues:

    16.3 Business Address

    BafaTech Consulting (AthenGuard)
    Georgia, USA

    17. Definitions

    • "Affiliate" means any entity that controls, is controlled by, or is under common control with a party, where "control" means ownership of 50% or more of voting securities.
    • "Confidential Information" has the meaning set forth in Section 12.1.
    • "Customer Data" means all data, information, and content provided by you or collected through your use of the Services.
    • "Documentation" means the user guides, technical documentation, and help materials made available by AthenGuard.
    • "Force Majeure Event" has the meaning set forth in Section 15.5.
    • "Intellectual Property Rights" means patents, copyrights, trademarks, trade secrets, and any other proprietary rights.
    • "Services" means the AthenGuard platform and all related services, features, and functionality.
    • "Terms" means these Terms of Service, including all incorporated policies and agreements.
    • "User" means any individual authorized by you to access or use the Services.
    • "We," "Us," "Our" refers to BafaTech Consulting, doing business as AthenGuard.
    • "You," "Your" refers to the individual or entity accepting these Terms.

    Acknowledgment

    BY USING THE SERVICES, YOU ACKNOWLEDGE THAT:

    • You have read and understand these Terms
    • You have authority to bind your organization to these Terms
    • You agree to be legally bound by all provisions
    • You understand the limitations and exclusions of liability
    • You have had opportunity to seek legal counsel
    • You accept the risks associated with using the Services
    • You understand your data ownership and privacy rights
    • You will comply with all applicable laws and these Terms

    If you do not agree to these Terms, you must immediately discontinue use of the Services.

    Version: 1.0

    Last Updated: December 30, 2025

    Effective Date: December 30, 2025

    Questions about these Terms?
    Contact us at