Terms of Service
Last updated: December 30, 2025
These Terms of Service ("Terms", "Agreement") constitute a legally binding agreement between you (either as an individual or on behalf of an entity) and BafaTech Consulting ("AthenGuard", "we", "us", "our") regarding your access to and use of the AthenGuard compliance platform and related services (collectively, the "Services").
PLEASE READ THESE TERMS CAREFULLY BEFORE USING OUR SERVICES. BY ACCESSING OR USING THE SERVICES, YOU ACKNOWLEDGE THAT YOU HAVE READ, UNDERSTOOD, AND AGREE TO BE BOUND BY THESE TERMS. IF YOU DO NOT AGREE TO THESE TERMS, YOU MAY NOT ACCESS OR USE THE SERVICES.
1. Acceptance of Terms
1.1 Binding Agreement
By accessing, registering for, or using the AthenGuard platform, you enter into a binding legal agreement with BafaTech Consulting. These Terms govern your access to and use of:
- The AthenGuard web application and platform
- Mobile applications and desktop clients
- APIs and integration endpoints
- Documentation, guides, and support resources
- All related services, features, and functionality
1.2 Who May Use the Services
Organizational Use:
- These Services are designed for business and organizational use
- You must be at least 18 years of age to use the Services
- You must have authority to bind your organization to these Terms
- Individual users must be authorized by their organization
Account Types:
- Enterprise Accounts: Governed by separate Master Subscription Agreement (MSA)
- Team Accounts: Governed by these Terms and applicable order forms
- Trial Accounts: Subject to additional trial-specific terms
1.3 Acceptance Methods
You accept these Terms by:
- Clicking "I Accept" or "I Agree" during registration
- Executing an order form or subscription agreement that references these Terms
- Accessing or using any part of the Services
- Continuing to use the Services after Terms updates
1.4 Additional Terms
Certain Services may be subject to additional terms, including:
- Service-specific terms for integrations or add-ons
- Acceptable Use Policy (incorporated by reference)
- Privacy Policy (available at athenguard.io/privacy)
- Service Level Agreement (SLA)
- Data Processing Addendum (DPA)
In case of conflict, service-specific terms prevail for that service, then order forms, then these Terms.
1.5 Modifications to Terms
We reserve the right to modify these Terms at any time. We will provide notice of material changes:
- 30 days advance notice via email to account administrators
- In-platform notifications
- Updated "Last updated" date at the top of this document
Your Options:
- Continued use after the effective date constitutes acceptance
- If you disagree, you may terminate your account before the effective date
- Enterprise customers may have different amendment procedures per their MSA
2. Description of Services
2.1 Platform Overview
AthenGuard provides a continuous compliance monitoring and management platform designed to help organizations:
Core Capabilities:
- Map and manage compliance across multiple frameworks (SOC 2, ISO 27001, NDPR, PCI DSS, NIST, HIPAA, etc.)
- Automate evidence collection from connected systems and endpoints
- Validate security controls in real-time
- Generate audit-ready reports and compliance documentation
- Track remediation activities and compliance gaps
- Maintain immutable audit trails of all activities
Key Components:
- CROP Engine: Compliance frameworks and requirements management
- C3E Application: Evidence collection, validation, and storage
- Helios Suite: Monitoring, alerting, and analytics
- Agent Infrastructure: Distributed evidence collection agents
- Integration Hub: Connectors for third-party systems
2.2 Service Models
Software as a Service (SaaS):
- Cloud-hosted, multi-tenant architecture
- Automatic updates and feature releases
- Included infrastructure and maintenance
- Standard data retention policies
Private Cloud / On-Premises:
- Dedicated infrastructure (where available)
- Custom deployment configurations
- Extended data residency options
- Subject to separate agreement and pricing
Hybrid Deployments:
- Cloud-based control plane with on-premises agents
- Flexible data routing and storage options
- Custom integration architectures
2.3 Service Tiers
Services are provided according to your subscription tier:
Essential:
- Core compliance management features
- Up to 3 frameworks
- Standard evidence collection
- Email support (business hours)
- 99.5% uptime SLA
Professional:
- Everything in Essential
- Unlimited frameworks
- Advanced automation and integrations
- Priority support with phone/chat
- 99.9% uptime SLA
- Custom reporting
Enterprise:
- Everything in Professional
- Dedicated tenant infrastructure options
- SSO/SAML integration
- Custom retention policies
- 24/7 premium support with dedicated CSM
- 99.95% uptime SLA
- API rate limit increases
- Professional services included
2.4 Beta and Preview Features
We may offer beta, preview, or experimental features:
- Marked clearly as "Beta", "Preview", or "Labs"
- Provided "as is" without warranties
- May be modified or discontinued without notice
- Subject to additional terms and conditions
- Not covered by SLA commitments
- May have data retention limitations
Your use of beta features constitutes acceptance of these additional risks and limitations.
2.5 Service Modifications
We reserve the right to:
- Add, modify, or discontinue features
- Update platform capabilities and architecture
- Change APIs (with reasonable notice and backward compatibility efforts)
- Implement new security controls or requirements
Our Commitments:
- 90 days notice for deprecation of major features
- 30 days notice for breaking API changes
- Migration assistance for significant changes
- Documentation of all modifications
3. Account Registration and Management
3.1 Account Creation
Registration Requirements:
- Provide accurate, complete, and current information
- Use a valid business email address
- Accept these Terms and Privacy Policy
- Complete email verification
- Provide necessary business information (company name, size, industry)
Verification:
- We may verify your identity and business credentials
- Additional documentation may be required for certain features
- We reserve the right to refuse service or terminate accounts
3.2 Account Credentials and Security
Your Responsibilities:
- Maintain confidentiality of passwords and authentication credentials
- Use strong, unique passwords
- Enable multi-factor authentication (MFA) when available
- Immediately notify us of unauthorized access or security breaches
- Ensure all users with access to your account comply with these Terms
Security Requirements:
- MFA is mandatory for administrative users
- Password complexity requirements must be met
- Session timeouts will be enforced
- IP allowlisting available for additional security
Account Compromise:
If you believe your account has been compromised:
- Change your password immediately
- Contact
- Review audit logs for suspicious activity
- Revoke access for compromised credentials
3.3 User Roles and Permissions
You are responsible for:
- Defining appropriate roles and permissions for your users
- Implementing principle of least privilege
- Regular access reviews and recertification
- Promptly removing access for departed employees
- Training users on security and acceptable use
Available Roles:
- Organization Administrator
- Compliance Officer
- Auditor (read-only)
- Evidence Contributor
- Custom roles (Enterprise tier)
3.4 Account Information Updates
You must:
- Keep contact information current
- Update billing details promptly
- Notify us of organization changes (mergers, acquisitions, name changes)
- Maintain accurate user lists
3.5 Account Termination
By You:
- Cancel anytime through platform settings or written notice
- Export your data before termination
- Pay all outstanding fees through the end of current billing period
- 30-day data retention after cancellation (then permanent deletion)
By Us:
We may suspend or terminate your account:
- For violation of these Terms
- For non-payment after 15 days notice
- If required by law or regulatory order
- For fraudulent or harmful activity
- If your use poses security risks to other users
Notice and Opportunity to Cure:
- We will provide 10 days notice for most violations
- Immediate suspension for security threats or illegal activity
- Opportunity to cure violations where appropriate
4. Acceptable Use Policy
4.1 Permitted Uses
You may use the Services only for lawful business purposes, including:
- Compliance management and audit preparation
- Security control monitoring and validation
- Risk assessment and remediation tracking
- Evidence collection and documentation
- Regulatory reporting and certification support
4.2 Prohibited Activities
You agree NOT to:
Illegal and Harmful Activities:
- Violate any applicable laws, regulations, or third-party rights
- Engage in fraudulent, defamatory, or malicious activities
- Facilitate money laundering, terrorism, or other criminal activities
- Harass, threaten, or harm others
- Impersonate any person or entity
Security Violations:
- Attempt unauthorized access to any systems, accounts, or networks
- Probe, scan, or test vulnerabilities without authorization
- Breach authentication or security measures
- Intercept or monitor data not intended for you
- Launch denial-of-service attacks or interfere with service operation
- Distribute malware, viruses, or harmful code
Platform Misuse:
- Reverse engineer, decompile, or disassemble the Services
- Remove or modify proprietary notices or labels
- Frame or mirror any content without permission
- Use automated tools to access the Services (except authorized APIs)
- Create derivative works or competing products
- Overload infrastructure or abuse rate limits
Data and Content Violations:
- Upload content you don't have rights to
- Store or transmit illegal, defamatory, or obscene material
- Violate intellectual property rights
- Transmit unsolicited communications (spam)
- Store personal data of minors
Account Misuse:
- Share account credentials with unauthorized parties
- Create accounts using false information
- Purchase, sell, or transfer accounts
- Use accounts to resell or sublicense the Services
4.3 Resource Usage
Fair Use:
- Services are provided for reasonable business use
- Excessive use that impacts other tenants may be throttled
- We may impose rate limits or usage caps
- Bulk operations should use provided APIs
Storage Limits:
- Evidence storage subject to plan limits
- Retention policies apply per configuration
- Additional storage available at standard rates
4.4 Compliance with Laws
You are responsible for:
- Complying with all applicable export control and sanctions laws
- Obtaining necessary licenses for data transfers
- Meeting industry-specific regulations (HIPAA, PCI DSS, etc.)
- Ensuring your use complies with data protection laws
- Maintaining proper authorization for all monitored systems
4.5 Monitoring and Enforcement
Our Rights:
- Monitor for compliance with these Terms
- Investigate suspected violations
- Suspend or terminate accounts for violations
- Preserve and disclose information as required by law
- Implement technical measures to enforce these policies
We Are Not Obligated To:
- Monitor all user activities
- Screen content before it is posted
- Remove any specific content
- Resolve disputes between users
4.6 Reporting Violations
To report violations:
- Email:
- Include account details and description of violation
- Provide relevant evidence (screenshots, logs, etc.)
- We will investigate and respond within 5 business days
5. Intellectual Property Rights
5.1 AthenGuard's Intellectual Property
Ownership:
AthenGuard and its licensors own all rights, title, and interest in:
- The Services, including all software, code, and algorithms
- Platform design, user interface, and architecture
- Documentation, guides, and training materials
- Trademarks, logos, and brand elements
- Proprietary methodologies and processes
- All improvements and derivative works
Protected by:
- Copyright, trademark, patent, and trade secret laws
- International intellectual property treaties
- Contractual restrictions
5.2 Your License to Use the Services
Grant:
Subject to your compliance with these Terms, we grant you a:
- Limited, non-exclusive, non-transferable, revocable license
- To access and use the Services
- For your internal business purposes only
- During the subscription term
Restrictions:
You may not:
- Sublicense, resell, or distribute the Services
- Use the Services for service bureau or time-sharing purposes
- Make the Services available to competitors
- Use the Services to develop competing products
- Remove or modify any proprietary notices
5.3 Your Data and Content
You Retain Ownership:
- All compliance data, evidence, and documentation you upload
- Custom policies, procedures, and control definitions
- Reports, assessments, and analysis you generate
- Organizational information and configurations
License to AthenGuard:
You grant us a limited license to:
- Store, process, and display your data
- Perform services you request
- Improve and optimize platform performance
- Generate anonymized analytics and aggregated insights
- Backup and recover your data
Our Commitments:
- We will not sell or share your data with third parties for their marketing
- We will not use your compliance data to train AI models
- We will process data only as instructed by you
- We maintain tenant isolation and data segregation
5.4 Feedback and Suggestions
Voluntary Contributions:
If you provide feedback, suggestions, or ideas:
- They are provided voluntarily
- No compensation is required
- We may use them without restriction or attribution
- You waive any intellectual property claims
- They become our property
This includes:
- Feature requests and product ideas
- Bug reports and technical feedback
- User experience suggestions
- Integration proposals
5.5 Open Source Components
The Services may include open source software:
- Subject to separate open source licenses
- Available for inspection upon request
- Governed by their respective license terms
- AthenGuard complies with all open source obligations
5.6 Third-Party Materials
The Services may incorporate third-party:
- Software libraries and frameworks
- Data sources and threat intelligence feeds
- Icons, fonts, and design elements
- APIs and integration components
These remain the property of their respective owners.
5.7 Trademark Usage
AthenGuard Trademarks:
- "AthenGuard" and associated logos are our trademarks
- May not be used without prior written permission
- Customer may reference our services in marketing (with approval)
- Must comply with our trademark guidelines
Your Trademarks:
- We may display your name/logo as a customer reference
- Only with your prior written consent
- You may revoke permission at any time
- Subject to our trademark usage guidelines
6. Data Protection and Privacy
6.1 Data Ownership and Control
You Own Your Data:
- You retain all ownership rights to your data
- We are a data processor acting on your behalf
- You control access, retention, and deletion
- You determine what data to collect and store
6.2 Data Processing
Our Role:
- We process data solely to provide the Services
- We follow your instructions regarding data handling
- We implement appropriate technical and organizational measures
- We maintain data processing agreements (DPAs)
Processing Activities:
- Evidence collection and storage
- Compliance analysis and reporting
- Audit trail generation
- Integration with authorized third-party services
6.3 Privacy Policy
Our Privacy Policy governs:
- What information we collect
- How we use and protect information
- Your privacy rights and choices
- International data transfers
The Privacy Policy is incorporated by reference into these Terms. Available at: athenguard.io/privacy
6.4 Data Location and Residency
Default Storage:
- Primary data centers in US, EU, Nigeria
- You may select your preferred region
- Data residency options available per plan tier
Data Transfers:
- May transfer data internationally to provide Services
- Governed by Standard Contractual Clauses (SCCs)
- Compliant with GDPR, NDPR, and applicable laws
- Encryption in transit and at rest
6.5 Data Security
We implement:
- Encryption (TLS 1.3, AES-256)
- Multi-factor authentication
- Role-based access controls
- Network segmentation and tenant isolation
- Regular security assessments and penetration testing
- 24/7 security monitoring
Full details in our Security Documentation and Privacy Policy.
6.6 Data Retention
Active Accounts:
- Data retained throughout subscription period
- Subject to your configured retention policies
- Available for immediate access and export
Terminated Accounts:
- 30-day grace period for data recovery
- Complete deletion within 90 days
- Some audit logs retained per legal requirements
- Deletion certificates available upon request
6.7 Data Portability
You may export your data at any time:
- Through platform export tools
- In standard formats (JSON, CSV, PDF)
- Including all evidence, reports, and configurations
- Via API for automated exports
6.8 Subprocessors
We engage carefully selected subprocessors:
- Cloud hosting and infrastructure providers
- Email and communication services
- Support and analytics tools
- Payment processors
Our Commitments:
- Maintain current subprocessor list (available on request)
- Conduct security assessments of all subprocessors
- Bind subprocessors to equivalent data protection obligations
- Provide notice of new subprocessors
6.9 Security Incidents
Breach Notification:
If we discover a data breach affecting your data:
- We will notify you without undue delay
- Within 72 hours of discovery (or as required by law)
- Via email to account administrators
- Including nature of breach, affected data, and remediation steps
Your Responsibilities:
- Implement your own incident response procedures
- Notify affected individuals as required by law
- Cooperate with our investigation and remediation
6.10 Compliance Support
We provide documentation to support your compliance efforts:
- SOC 2 Type II reports
- ISO 27001 certificates
- Security questionnaire responses
- DPA and SCC documentation
- Privacy certifications
7. Payment Terms
7.1 Subscription Fees
Pricing:
- Fees as specified in your order form or subscription plan
- Pricing available at athenguard.io/pricing
- Custom pricing for enterprise agreements
- All fees in USD unless otherwise specified
Subscription Types:
- Monthly subscriptions (billed monthly)
- Annual subscriptions (billed annually, typically discounted)
- Multi-year agreements (custom terms)
7.2 Billing and Payment
Payment Methods:
- Credit card (Visa, Mastercard, Amex)
- ACH/wire transfer (annual plans only)
- Invoice billing (Enterprise tier, credit approval required)
Billing Cycle:
- Charges occur on subscription anniversary date
- Prorated for mid-cycle changes
- Usage-based charges billed monthly in arrears
Automatic Renewal:
- Subscriptions renew automatically
- At then-current rates unless locked in agreement
- 30 days notice of price changes
- Cancel anytime to prevent next renewal
7.3 Taxes
Tax Responsibility:
- Fees exclude applicable taxes (VAT, GST, sales tax, etc.)
- You are responsible for all taxes except our income taxes
- Provide valid tax exemption certificates if applicable
- International customers may owe import duties or levies
Invoicing:
- Itemized invoices provided via email
- Available in platform under Billing section
- Include tax breakdown where applicable
7.4 Late Payment
Consequences:
- Late fees of 1.5% per month (or maximum allowed by law)
- Service suspension after 15 days notice
- Account termination after 30 days
- Collection costs and legal fees may apply
Disputes:
- Notify us within 30 days of invoice date
- Pay undisputed amounts while resolving
- We will work with you in good faith
7.5 Refund Policy
No Refunds:
Subscription fees are non-refundable except:
- Service availability below SLA thresholds (see Section 8)
- Billing errors (corrected via credit)
- Cancellation within trial period
- Legal requirements in your jurisdiction
Trial Periods:
- Free trial accounts not charged until conversion
- Must cancel before trial end to avoid charges
- Data deleted after trial expiration unless converted
7.6 Plan Changes
Upgrades:
- Effective immediately
- Prorated charges for remainder of billing period
- Access to upgraded features immediately
Downgrades:
- Effective at end of current billing period
- May require data/feature migration
- No refunds for unused portion of higher-tier plan
7.7 Usage-Based Charges
Some features incur additional costs:
- Storage beyond plan limits
- API calls exceeding tier limits
- Premium integrations
- Professional services hours
- Dedicated infrastructure
Usage Monitoring:
- Real-time usage dashboard
- Email alerts at 75% and 90% of limits
- Option to set hard caps or auto-scaling
7.8 Price Changes
Notice:
- 30 days advance notice for increases
- Applies to renewal, not current term
- Annual plans locked for term duration
Your Options:
- Accept new pricing and continue service
- Downgrade to different plan
- Cancel before renewal to avoid increase
8. Service Level Agreement (SLA)
8.1 Availability Commitment
Uptime Guarantees:
- Essential Tier: 99.5% monthly uptime
- Professional Tier: 99.9% monthly uptime
- Enterprise Tier: 99.95% monthly uptime
Measurement:
- Calculated monthly per calendar month
- Based on platform availability for API and web interface
- Excludes scheduled maintenance and customer-initiated downtime
8.2 Scheduled Maintenance
Maintenance Windows:
- Announced 7 days in advance via email and status page
- Typically performed during low-usage periods
- Maximum 4 hours per month for standard maintenance
- Does not count against SLA uptime
Emergency Maintenance:
- May be performed with shorter notice
- Only for critical security or stability issues
- Still excluded from SLA calculations
8.3 Service Credits
Eligibility:
If we fail to meet SLA commitments:
- Must submit claim within 30 days of incident
- Provide details of service interruption experienced
- Credits issued as percentage of monthly fees
Credit Schedule:
| Actual Uptime | Credit |
|---|---|
| 99.0% - 99.5% | 10% |
| 95.0% - 99.0% | 25% |
| Below 95.0% | 50% |
Limitations:
- Maximum credit: 50% of monthly fees for affected service
- Credits applied to future invoices (not cash refunds)
- Only remedy for SLA breaches
- Not available for free or trial accounts
8.4 Exclusions from SLA
Downtime does not count if caused by:
- Factors outside our reasonable control (force majeure)
- Your acts or omissions
- Internet backbone or connectivity issues
- Denial-of-service attacks
- Third-party software or services not provided by us
- Beta or preview features
- Suspension due to Terms violation
8.5 Support Response Times
Support Channels:
- Essential: Email support, business hours (9am-5pm local time)
- Professional: Email + phone, extended hours (7am-9pm local time)
- Enterprise: 24/7 email, phone, chat with dedicated CSM
Response Time Targets:
| Severity | Essential | Professional | Enterprise |
|---|---|---|---|
| Critical (P1) | 4 hours | 1 hour | 30 minutes |
| High (P2) | 8 hours | 4 hours | 2 hours |
| Medium (P3) | 24 hours | 8 hours | 4 hours |
| Low (P4) | 48 hours | 24 hours | 8 hours |
Severity Definitions:
- P1: Complete service outage affecting all users
- P2: Major functionality impaired, significant impact
- P3: Minor functionality affected, workaround available
- P4: General questions, feature requests, cosmetic issues
8.6 Status and Incident Communication
Status Page:
- Real-time status at status.athenguard.io
- Subscribe to email/SMS updates
- Historical uptime data available
- Incident post-mortems published
Incident Updates:
- Initial acknowledgment within 30 minutes for P1
- Regular updates every 2 hours during incidents
- Post-incident reports within 5 business days
9. Warranties and Disclaimers
9.1 Limited Warranty
We warrant that:
- Services will perform substantially as described in documentation
- We will use commercially reasonable efforts to maintain service availability
- We have the right to provide the Services to you
- Services will not violate third-party intellectual property rights
Warranty Period: Duration of your subscription
9.2 Disclaimer of Warranties
EXCEPT AS EXPRESSLY PROVIDED IN SECTION 9.1, THE SERVICES ARE PROVIDED "AS IS" AND "AS AVAILABLE" WITHOUT WARRANTIES OF ANY KIND, EITHER EXPRESS OR IMPLIED.
WE SPECIFICALLY DISCLAIM:
- Implied warranties of merchantability, fitness for particular purpose, non-infringement
- Guarantees that services will be uninterrupted, error-free, or secure
- Warranties regarding results, accuracy, or reliability of information
- Representations about third-party integrations or services
9.3 No Compliance Guarantee
Important Limitations:
- AthenGuard is a tool to facilitate compliance management
- We do not guarantee that your use will result in compliance with any specific regulation
- You are solely responsible for achieving and maintaining compliance
- You must conduct your own assessments and obtain appropriate certifications
- We do not provide legal, audit, or compliance advice
Audit Readiness vs. Compliance:
- We help you prepare for audits
- Final compliance determinations rest with auditors and regulators
- You must validate all automated findings
- Professional judgment required for control implementations
9.4 Third-Party Services
No Warranty for Integrations:
- Third-party services operate independently
- We don't control their availability, security, or functionality
- Integration failures don't constitute breach by us
- Check third-party terms and warranties separately
9.5 Beta Features
Additional Disclaimers for Beta/Preview:
- Provided "as is" with all faults
- May contain errors or defects
- Performance may vary significantly
- Features may change or be discontinued
- Data loss possible; backup recommended
- Not recommended for production use
10. Limitation of Liability
10.1 Maximum Liability Cap
TO THE MAXIMUM EXTENT PERMITTED BY LAW, OUR TOTAL AGGREGATE LIABILITY ARISING FROM OR RELATED TO THESE TERMS OR THE SERVICES SHALL NOT EXCEED:
- For Monthly Plans: The fees paid by you in the 3 months immediately preceding the claim
- For Annual Plans: The fees paid by you in the 12 months immediately preceding the claim
- For Trial/Free Accounts: $100 USD
10.2 Exclusion of Consequential Damages
WE SHALL NOT BE LIABLE FOR:
- Indirect, incidental, special, exemplary, or consequential damages
- Loss of profits, revenue, data, or business opportunities
- Cost of substitute goods or services
- Business interruption or system failure
- Reputational harm or goodwill loss
- Failure to achieve compliance or pass audits
EVEN IF:
- We were advised of possibility of such damages
- The limited remedies fail of their essential purpose
- Damages were foreseeable
10.3 Exceptions to Limitations
Limitations do not apply to:
- Your indemnification obligations (Section 11)
- Your payment obligations
- Your violations of intellectual property rights
- Gross negligence or willful misconduct
- Death or personal injury caused by our negligence
- Violations that cannot be limited by law
- Data breaches caused by our failure to implement reasonable security
10.4 Basis of the Bargain
You acknowledge that:
- These limitations are fundamental elements of the agreement
- We would not provide Services at current pricing without these limitations
- You have had opportunity to obtain insurance or negotiate different terms
- These limitations allocate risk fairly between parties
10.5 Claim Procedures
To bring a claim:
- Provide written notice within 30 days of event giving rise to claim
- Include detailed description and supporting documentation
- Attempt good faith resolution before litigation
- File suit within 1 year of claim arising (or jurisdictional maximum if less)
10.6 Multiple Claims
If you suffer multiple incidents:
- Liability cap applies in aggregate, not per incident
- Related incidents treated as single claim
- Annual reset of liability cap at subscription renewal
10.7 Force Majeure
We are not liable for delays or failures caused by:
- Natural disasters, pandemics, acts of God
- War, terrorism, civil unrest, government actions
- Internet infrastructure failures beyond our control
- Cyberattacks (unless caused by our gross negligence)
- Labor disputes, strikes, supplier failures
- Other events outside our reasonable control
Our Obligations During Force Majeure:
- Use commercially reasonable efforts to mitigate impact
- Provide timely updates on status
- Resume normal operations as soon as practicable
- Right to terminate if event exceeds 30 days
11. Indemnification
11.1 Your Indemnification Obligations
You agree to indemnify, defend, and hold harmless AthenGuard, its affiliates, officers, directors, employees, agents, and licensors from and against any claims, liabilities, damages, losses, costs, or expenses (including reasonable attorneys' fees) arising from or related to:
Your Use of Services:
- Your violation of these Terms or Acceptable Use Policy
- Your violation of any law, regulation, or third-party rights
- Your data, content, or compliance configurations
- Your negligence or willful misconduct
- Claims by your users, employees, or contractors
Your Business Operations:
- Claims that your use of Services violates IP rights
- Claims related to your collection or handling of personal data
- Regulatory actions against your organization
- Claims from your end users or customers
- Employment claims from your staff members using the platform
11.2 Our Indemnification Obligations
We agree to indemnify, defend, and hold you harmless from claims that:
- The Services, when used as authorized, infringe third-party intellectual property rights
- We violated applicable data protection laws in processing your data
Limitations:
- Only applies to unmodified Services used in accordance with these Terms
- Not applicable if infringement results from your modifications or combinations
- Not applicable to beta features or services provided free of charge
11.3 Indemnification Procedures
For indemnified party to receive protection:
- Prompt Notice: Provide written notice within 30 days of learning of claim
- Cooperation: Reasonably cooperate in defense of claim
- Control: Allow indemnifying party to control defense and settlement
- No Prejudice: Don't admit liability or settle without consent
Indemnifying Party Rights:
- Select legal counsel
- Control litigation strategy and settlement negotiations
- Settle on reasonable terms without indemnified party's consent (if no admission of liability required)
11.4 Exclusive Remedy for IP Claims
If Services are claimed to infringe, we may (at our option):
- Obtain rights for you to continue using Services
- Replace or modify Services to be non-infringing
- If neither option is commercially reasonable, terminate Services and refund prepaid fees (pro-rated)
This is your sole and exclusive remedy for intellectual property infringement claims.
11.5 Mitigation Cooperation
Both parties agree to:
- Mitigate damages where reasonably possible
- Cooperate in defense strategy
- Preserve relevant evidence
- Participate in settlement discussions in good faith
12. Confidentiality
12.1 Definition of Confidential Information
"Confidential Information" means all non-public information disclosed by one party ("Disclosing Party") to the other ("Receiving Party"), including:
AthenGuard's Confidential Information:
- Platform architecture, source code, and algorithms
- Security practices and vulnerability information
- Pricing, financial information, and business strategies
- Product roadmaps and unreleased features
- Customer lists and usage statistics
Your Confidential Information:
- Compliance data, evidence, and assessments
- Security configurations and control implementations
- Business information and organizational data
- Authentication credentials and access tokens
- Audit findings and remediation plans
Marked or Reasonably Understood as Confidential:
- Information marked "Confidential," "Proprietary," or similar
- Information disclosed under circumstances indicating confidentiality
- Information about security vulnerabilities or incidents
12.2 Obligations
Receiving Party must:
- Protect Confidential Information with same care as own confidential information (minimum reasonable care)
- Use Confidential Information only for purposes of these Terms
- Limit disclosure to employees and contractors with need to know
- Not disclose to third parties without written consent
- Return or destroy upon request or termination
12.3 Exceptions
Confidential Information does not include information that:
- Was publicly known before disclosure
- Becomes public through no fault of Receiving Party
- Was independently developed without access to Confidential Information
- Was rightfully received from third party without confidentiality obligations
- Must be disclosed by law or court order (with notice to Disclosing Party if permitted)
12.4 Compelled Disclosure
If legally required to disclose:
- Provide prompt notice to Disclosing Party (unless prohibited)
- Cooperate in seeking protective order
- Disclose only minimum information required
- Request confidential treatment from receiving authority
12.5 Duration
Confidentiality obligations survive for:
- 3 years after termination of these Terms
- Indefinitely for trade secrets
- Indefinitely for personal data and compliance information
13. Term and Termination
13.1 Term
Agreement Duration:
- Begins upon first access or acceptance
- Continues for subscription term (monthly or annual)
- Renews automatically unless cancelled
- Survives through wind-down period
13.2 Termination by You
You may terminate:
- For convenience with 30 days written notice
- Immediately if we materially breach and fail to cure within 30 days
- Through platform cancellation settings
- By written notice to
Effect of Termination:
- Access continues through end of paid period
- No refunds for unused time (except as required by law)
- Data available for export during notice period
13.3 Termination by Us
We may terminate or suspend immediately:
- For material breach of these Terms
- Non-payment after 15 days notice
- Violation of Acceptable Use Policy
- Fraudulent or illegal activities
- If required by law or regulation
- Risk to platform security or other customers
We may terminate with notice:
- For convenience with 90 days notice (providing refund of prepaid fees)
- If you become competitor or launch competing service
- Due to legal or regulatory changes
13.4 Effect of Termination
Upon Termination:
- All access rights immediately cease (except data export period)
- Outstanding fees become immediately due
- Licenses granted under these Terms terminate
- Mutual return or destruction of Confidential Information
Data Retention:
- 30-day grace period for data recovery
- Self-service export tools remain available
- After 30 days, deletion process begins
- Complete deletion within 90 days
Survival:
Sections survive termination:
- Payment obligations (Section 7)
- Intellectual Property (Section 5)
- Warranties and Disclaimers (Section 9)
- Limitation of Liability (Section 10)
- Indemnification (Section 11)
- Confidentiality (Section 12)
- Dispute Resolution (Section 14)
13.5 Transition Assistance
Upon termination, we will:
- Provide data export in standard formats
- Reasonable assistance with data migration (fees may apply for extensive assistance)
- Maintain data integrity during transition
- Provide final invoice and usage reports
We are not obligated to:
- Provide source code or proprietary methodologies
- Convert data to competitor formats
- Provide ongoing technical support after termination
- Retain data beyond stated retention periods
14. Dispute Resolution
14.1 Informal Resolution
Before filing formal claim:
- Contact us at
- Provide detailed description of dispute
- Allow 30 days for good faith negotiation
- Escalate to senior management if needed
Benefits:
- Faster and less expensive resolution
- Preserves business relationship
- Flexible solutions possible
14.2 Governing Law
These Terms are governed by:
- The laws of the State of Georgia, United States
- Without regard to conflict of law principles
- Federal laws of the United States where applicable
- Excluding the UN Convention on Contracts for the International Sale of Goods
14.3 Jurisdiction and Venue
For litigation not subject to arbitration:
- Exclusive jurisdiction: State or Federal courts located in the State of Georgia, USA (specifically Fulton County or the corresponding federal district)
- You consent to personal jurisdiction in this venue
- You waive objections based on forum non conveniens
14.4 Arbitration
Either party may elect binding arbitration:
- Administered by the American Arbitration Association (AAA) under its Commercial Arbitration Rules
- Single arbitrator mutually selected (or appointed by the AAA)
- Seat of arbitration: Atlanta, Georgia, USA
- Language: English
Exceptions - Not Subject to Arbitration:
- Intellectual property disputes
- Injunctive relief requests
- Claims under $25,000 (small claims court)
- Claims for emergency relief
Arbitration Process:
- Notice of arbitration within 60 days of dispute arising
- Discovery limited to essential documents
- Hearing within 6 months where possible
- Award final and binding, limited appeal rights
- Each party bears own costs unless award specifies otherwise
14.5 Class Action Waiver
YOU AND ATHENGUARD AGREE:
- All claims must be brought individually
- No class actions, representative actions, or consolidated proceedings
- No acting as representative or class member in others' proceedings
- Arbitrator cannot consolidate claims without consent
If Class Action Waiver Unenforceable:
- Arbitration clause does not apply
- Litigation proceeds in courts specified above
14.6 Injunctive Relief
Either party may seek:
- Temporary restraining orders
- Preliminary injunctions
- Emergency equitable relief
Without waiting for arbitration when:
- Immediate harm likely
- Breach of confidentiality obligations
- Intellectual property infringement
- Security threats to platform or users
14.7 Fees and Costs
General Rule:
- Each party bears own attorneys' fees and costs
- Unless statute or these Terms provide otherwise
- Prevailing party in IP disputes recovers reasonable fees
Arbitration Costs:
- Filing fees split equally
- Arbitrator fees split equally
- Each party's representation costs borne separately
15. General Provisions
15.1 Entire Agreement
These Terms, together with:
- Privacy Policy
- Order forms and subscription agreements
- Service Level Agreement
- Data Processing Addendum
- Any referenced incorporated policies
Constitute the entire agreement and supersede all prior:
- Negotiations and discussions
- Proposals and counterproposals
- Written or oral agreements
- Industry customs or practices
15.2 Amendments
Modification Process:
- We may modify Terms at any time
- Material changes with 30 days notice
- Notice via email and in-platform notification
- Continued use constitutes acceptance
Your Options:
- Accept changes and continue using Services
- Terminate before effective date to avoid changes
- Enterprise customers may have different amendment rights per MSA
Unauthorized Modifications:
- These Terms can only be amended by us in writing
- Your purchase orders or terms do not modify this Agreement
- Additional or different terms in your documents are rejected
15.3 Assignment
By You:
- You may not assign without our prior written consent
- Assignment without consent is void
- Permitted for corporate reorganization or sale if successor agrees to be bound
By Us:
- We may freely assign to affiliates
- We may assign in connection with merger, acquisition, or sale of business
- We will provide notice of assignment
15.4 Notices
To You:
- Email to address associated with account
- In-platform notifications
- Deemed received when sent (if email) or when displayed (if in-platform)
To Us:
- Email:
- Legal notices require written confirmation of receipt
Routine Communications:
- Support:
- Billing:
- Security:
15.5 Force Majeure
Neither party liable for delays or failures caused by:
- Acts of God, natural disasters, pandemics
- War, terrorism, civil unrest, government acts
- Strikes, labor disputes, supplier failures
- Internet infrastructure failures
- Power outages, telecommunications failures
- Events beyond reasonable control
Obligations During Force Majeure:
- Promptly notify other party
- Use reasonable efforts to mitigate
- Resume performance when able
- Right to terminate if exceeds 60 days
15.6 Relationship of Parties
Independent Contractors:
- Parties are independent contractors
- No partnership, joint venture, or agency relationship
- Neither party has authority to bind the other
- No employee-employer relationship created
15.7 Severability
If any provision is found invalid or unenforceable:
- Remaining provisions continue in full force
- Invalid provision modified to minimum extent necessary
- Parties' intent preserved to maximum extent possible
- Entire Terms not rendered void
15.8 Waiver
Failure to enforce any right:
- Does not constitute waiver of that right
- Does not waive future enforcement
- Must be in writing and signed to be effective
- Applies only to specific instance waived
15.9 Interpretation
Interpretive Rules:
- Headings for convenience only, don't affect meaning
- "Including" means "including but not limited to"
- Singular includes plural and vice versa
- "Days" means calendar days unless specified otherwise
- "May" indicates discretion; "shall" or "will" indicates obligation
15.10 Language
Controlling Language:
- English version controls in case of translations
- Translations provided for convenience only
- Disputes resolved based on English text
15.11 Third-Party Beneficiaries
No Third-Party Rights:
- These Terms benefit only you and AthenGuard
- No third parties may enforce Terms
- Except: our affiliates and licensors may enforce IP protections
15.12 Export Compliance
You agree:
- Services subject to export control laws
- You will not export or re-export in violation of law
- You are not on restricted party lists
- You will not use Services in embargoed countries
- You will comply with all applicable trade restrictions
15.13 Government Use
If you are a government entity:
- Services are "Commercial Items" as defined in FAR 2.101
- Provided with only those rights granted to commercial customers
- Use, reproduction, and disclosure subject to these Terms
15.14 Publicity
Customer References:
- We may list you as customer on website and marketing materials
- We may use your logo subject to trademark guidelines
- You may opt-out at any time by written request
- Case studies and testimonials require separate approval
15.15 Compliance with Laws
Both parties agree:
- To comply with all applicable laws and regulations
- To obtain necessary licenses and authorizations
- To comply with anti-corruption laws (FCPA, UK Bribery Act, etc.)
- To comply with sanctions and export control laws
- To comply with data protection and privacy laws
15.16 Feedback and Suggestions
If you provide us with feedback:
- You grant us unlimited rights to use it
- No compensation required
- May be incorporated into Services
- You waive moral rights and attribution claims
16. Contact Information
16.1 General Inquiries
Email:
Website: www.athenguard.io
Support Portal: support.athenguard.io
16.2 Legal and Compliance
Legal Department:
Privacy Inquiries:
Data Protection Officer:
Security Issues:
16.3 Business Address
BafaTech Consulting (AthenGuard)
Georgia, USA
17. Definitions
- "Affiliate" means any entity that controls, is controlled by, or is under common control with a party, where "control" means ownership of 50% or more of voting securities.
- "Confidential Information" has the meaning set forth in Section 12.1.
- "Customer Data" means all data, information, and content provided by you or collected through your use of the Services.
- "Documentation" means the user guides, technical documentation, and help materials made available by AthenGuard.
- "Force Majeure Event" has the meaning set forth in Section 15.5.
- "Intellectual Property Rights" means patents, copyrights, trademarks, trade secrets, and any other proprietary rights.
- "Services" means the AthenGuard platform and all related services, features, and functionality.
- "Terms" means these Terms of Service, including all incorporated policies and agreements.
- "User" means any individual authorized by you to access or use the Services.
- "We," "Us," "Our" refers to BafaTech Consulting, doing business as AthenGuard.
- "You," "Your" refers to the individual or entity accepting these Terms.
Acknowledgment
BY USING THE SERVICES, YOU ACKNOWLEDGE THAT:
- You have read and understand these Terms
- You have authority to bind your organization to these Terms
- You agree to be legally bound by all provisions
- You understand the limitations and exclusions of liability
- You have had opportunity to seek legal counsel
- You accept the risks associated with using the Services
- You understand your data ownership and privacy rights
- You will comply with all applicable laws and these Terms
If you do not agree to these Terms, you must immediately discontinue use of the Services.
Version: 1.0
Last Updated: December 30, 2025
Effective Date: December 30, 2025
Questions about these Terms?
Contact us at