Terms of Service
Breachday LLC · breachday.io
Version 1.4 · Effective Date: October 5, 2026
1. Agreement to Terms
These Terms of Service ("Terms") are a legally binding agreement between you or the organization you represent ("Customer," "you," or "your") and Breachday LLC ("Breachday," "we," "us," or "our"), governing access to and use of the Breachday platform available at app.breachday.io, including associated features, APIs, exports, documentation, and related services (collectively, the "Service").
You agree to these Terms when you affirmatively accept them through a checkbox, button, checkout flow, Order Form, or other electronic acceptance mechanism that presents or links to these Terms. The Breachday Data Protection Addendum (the "DPA") is incorporated into these Terms by reference, and the Breachday Privacy Policy describes Breachday's privacy practices. If you accept on behalf of an organization, you represent and warrant that you have authority to bind that organization.
If you do not agree to these Terms, do not create an Account or use the Service.
2. Definitions
- "Account" - the registered account associated with an Organization on the Service.
- "Beta Feature" - a feature identified as beta, preview, early access, experimental, evaluation, or similar.
- "Confidential Information" - nonpublic information disclosed by one party to the other that is designated confidential or that reasonably should be understood to be confidential given its nature and the circumstances of disclosure. Customer Data is Customer Confidential Information.
- "Customer Data" - all data, content, files, and materials submitted to or generated within the Service by Customer or its users, including scenarios, injects, business continuity program data, playbooks, exercise session logs, generated reports, and AI-generated scenario content.
- "DPA" - the Breachday Data Protection Addendum available at breachday.io, which forms part of these Terms.
- "Exercise Session" - a single live tabletop exercise instance run through the Service.
- "Facilitator" - an authenticated user with permissions to create, configure, and run Exercise Sessions.
- "Observer" - an authenticated user with read-only access to sessions and reports.
- "Organization" - the company or entity associated with a Customer Account.
- "Participant" - an individual who joins an Exercise Session via room code and optional room password without a registered Account.
- "Renewal Term" - a renewal period following the initial Subscription Term.
- "Sensitive Personal Data" - personal information treated as sensitive or special-category data under applicable law, including health information, government identifiers, precise financial account credentials, biometric identifiers, authentication credentials, and similarly regulated information.
- "Subscription" - the paid plan and term governing Service access.
- "Subscription Term" - the initial fixed term selected at checkout or stated in an Order Form.
- "MSP" - a managed service provider, consultant, advisory firm, or other organization that has entered into a separate MSP agreement with Breachday to use the Service for clients.
- "Client Organization" - an Organization created and managed by an MSP for one, and only one, client under an MSP agreement.
- "System Templates" - scenario and exercise templates authored by Breachday or adapted from third-party or U.S. Government source materials and made available within the Service.
3. Account Registration and Access
3.1 Account Creation
To access authenticated portions of the Service, you must register an Account, verify your email address, and provide accurate organizational information. You are responsible for maintaining the confidentiality of credentials and for activity conducted through your Account, except to the extent caused by Breachday's breach of these Terms.
3.2 Participant Access
Participants may join an Exercise Session using a room code and optional password without creating an Account. Participants provide a display name and may submit responses, votes, confidence ratings, and hotwash feedback. Technical information, including IP address and request metadata, may also be processed for security and service operation as described in the Privacy Policy. Organizations are responsible for providing Participants any notices required by workplace policy or applicable law before a session.
3.3 Two-Factor Authentication
Two-factor authentication (TOTP) is available for authenticated users and may be required for high-impact actions. You are responsible for securely storing backup codes and for promptly reporting suspected Account compromise.
3.4 Roles and Permissions
Each Organization supports ADMIN, FACILITATOR, and OBSERVER roles. MSP Organizations may have additional roles governed by the applicable MSP agreement. Customer is responsible for assigning appropriate roles and promptly removing access that is no longer required.
3.5 Eligibility
The Service is designed for business use by individuals 18 years of age or older who are authorized to act for an organization. It is not directed to consumers or minors.
4. Subscriptions and Billing
4.1 Plans
Breachday offers self-service and negotiated subscription plans. Feature availability and usage limits are defined in the Service, pricing page, checkout flow, Order Form, or other applicable ordering document. The price and terms displayed or executed at purchase control for that order.
4.2 Subscription Terms and Automatic Renewal
Self-service Subscriptions are sold on fixed initial terms of one (1) or two (2) years unless otherwise stated at checkout or in an Order Form. The full Subscription fee for the selected initial term is due at the start of the Subscription Term unless the applicable ordering document states otherwise.
- Pricing is locked for the initial Subscription Term at the rate confirmed at checkout or in the applicable Order Form.
- Unless cancelled, a Subscription automatically renews for successive one (1) year Renewal Terms, unless Customer separately and affirmatively agrees to a longer Renewal Term permitted by applicable law.
- Renewal pricing will be the then-current applicable price unless an Order Form or written agreement states otherwise.
- Breachday will present automatic-renewal terms clearly at purchase, provide renewal notices required by applicable law, and provide an online cancellation mechanism for subscriptions accepted online.
4.3 Free Trial
New Organizations may be eligible for a free trial, typically 15 days unless a different period is displayed at signup. If a payment method is collected, the checkout flow will disclose whether the trial automatically converts to a paid Subscription, the price and term that will apply, and how to cancel before the charge. If checkout is not completed, no paid Subscription is created.
4.4 Cancellation, Expiration, and Post-Cancellation Retention
You may cancel automatic renewal at any time through Settings > Billing > Manage subscription, the Stripe Customer Portal, or by contacting Breachday. Cancellation disables future renewal but does not terminate the then-current prepaid Subscription Term, reduce committed fees, or entitle Customer to a refund except as expressly stated in these Terms or required by law. Customer retains normal Service access through the end of the paid Subscription Term unless the Subscription is earlier terminated for cause.
When the paid Subscription Term expires, the Organization enters a six (6) month read-only retention period unless a different lifecycle applies under an MSP or Enterprise agreement:
- No new Exercise Sessions may be created or run.
- Previously retained reports, session data, and other Customer Data remain accessible for export, and reports may be regenerated where the underlying structured report data is retained.
- Breachday will provide deletion reminders at 30 days and 5 days before the scheduled deletion date.
- At the end of the retention period, Customer Data is deleted from active systems unless Customer renews or deletes the Organization earlier.
- Data deleted from active systems may persist in encrypted disaster-recovery backups for up to 7 days before rolling expiration. If a backup is restored, recorded deletion requests are re-applied.
4.5 Organization Self-Deletion
An Organization ADMIN may permanently delete the Organization through account settings using required confirmation controls. Self-deletion removes Customer Data from active systems, cancels an active Stripe subscription, and removes associated user access. The action cannot be reversed. Backup copies may persist solely for disaster recovery for up to 7 days before rolling expiration.
4.6 MSP-Managed Organizations
Client Organizations managed under an MSP agreement are subject to the billing, retention, and lifecycle terms of that agreement and may be exempt from the standard post-expiration lifecycle in Section 4.4.
4.7 Taxes
Fees are exclusive of applicable taxes. Where required by law, Breachday or its payment processor may collect and remit sales, use, VAT, or similar taxes. Customer is responsible for taxes imposed on Customer's purchase or use of the Service, excluding taxes based on Breachday's net income.
4.8 Payment Processing
Payments are processed by Stripe. Breachday does not store raw payment card numbers or CVV data. By submitting payment information, you authorize Stripe and Breachday to process charges associated with the Subscription. Failure to resolve payment failure may result in suspension and, after applicable notice, termination or expiration under these Terms.
5. Acceptable Use
5.1 Permitted Use
The Service is provided for lawful business purposes, including designing, facilitating, analyzing, and documenting cybersecurity and business continuity tabletop exercises for Customer's own Organization and, where authorized by an MSP agreement, for Client Organizations.
5.2 Prohibited Conduct
You agree not to:
- use the Service for an unlawful purpose or in violation of applicable law;
- upload or transmit actual PHI, live payment card data, classified or government-restricted information, real passwords, private keys, or other Sensitive Personal Data except where Breachday has expressly approved such processing in writing;
- attempt to access, scrape, or exfiltrate another Organization's data or systems;
- bypass tenant isolation, rate limits, room access controls, authentication, or other security mechanisms;
- distribute malware or malicious code through the Service;
- reverse engineer, decompile, or attempt to derive source code except to the limited extent such restriction is prohibited by law;
- resell, sublicense, white-label, or use the Service to provide exercises to another organization except under an applicable MSP agreement;
- use automation in a manner that places unreasonable load on the Service;
- misrepresent Breachday-authored or adapted templates as official U.S. Government exercises or imply government endorsement;
- upload content that infringes or misappropriates third-party rights; or
- use the Service in violation of applicable export-control, sanctions, or trade-restriction laws.
5.3 Enforcement
Breachday may investigate suspected violations and suspend or terminate access where reasonably necessary to protect the Service, customers, third parties, or Breachday. Where appropriate and feasible, Breachday will provide notice and an opportunity to cure.
6. Customer Data and Intellectual Property
6.1 Customer Data Ownership
Customer retains all right, title, and interest in and to Customer Data. Breachday does not acquire ownership of Customer Data.
6.2 License to Process Customer Data
Customer grants Breachday a limited, non-exclusive, worldwide, royalty-free license to host, access, process, transmit, copy, and otherwise use Customer Data only as reasonably necessary to provide, secure, support, and administer the Service; generate exports and reports; maintain backups and data integrity; enforce usage limits and prevent abuse; comply with lawful obligations; and exercise rights or perform obligations under the Agreement. This license ends when Customer Data is permanently deleted, except to the extent retention is legally required.
6.3 No AI Training on Customer Data
Breachday does not use Customer Data to train or fine-tune Breachday or third-party artificial intelligence models. When Customer uses the AI Scenario Builder, prompt and response content is transmitted through OpenRouter for inference. Breachday configures OpenRouter routing to require Zero Data Retention (ZDR) eligible provider endpoints and to deny provider data collection where supported. Under OpenRouter's ZDR controls, eligible inference providers do not persist prompt or response content after processing. ZDR does not prevent transient processing and does not prevent OpenRouter from retaining non-content request metadata, such as model, token, latency, and cost information, under its own policies. Customer must not place Sensitive Personal Data or real credentials in AI prompts.
6.4 Breachday Intellectual Property
Breachday retains all right, title, and interest in the Service, including application code, interfaces, designs, algorithms, documentation, Breachday-authored System Templates, trademarks, and related intellectual property. No ownership rights are transferred except the limited rights expressly granted in these Terms.
6.5 Government and Third-Party Source Materials
Certain System Templates may be adapted from materials that Breachday believes are works of the United States Government or are otherwise lawfully available for reuse. Third-party materials, trademarks, logos, or separately protected content are excluded from any public-domain characterization. Customer may clone and modify eligible templates within the Service but must not represent an adapted template as an official CISA or U.S. Government product or imply endorsement.
6.6 Feedback
If Customer voluntarily provides feedback, suggestions, or improvement ideas, Customer grants Breachday a perpetual, irrevocable, worldwide, royalty-free right to use that feedback without restriction or compensation, provided Breachday does not identify Customer publicly without permission.
6.7 Customer Authority and Lawful Basis
Customer represents and warrants that it has the rights, permissions, notices, consents, and lawful bases necessary to submit Customer Data and to authorize Breachday and its subprocessors to process Customer Data as contemplated by the Agreement. Where Customer acts for a Client, Customer also represents that it is authorized by that Client to engage Breachday and its subprocessors.
7. Exports and the Public Scenario Builder
7.1 Exports
The Service can generate reports, scenarios, and crisis communication documents in PDF, DOCX, JSON, or other supported formats. PDF and DOCX files may be generated through transient server-side processing and are not necessarily stored as binary files by Breachday. Customer is responsible for the security, distribution, and retention of downloaded exports.
7.2 Report Data Persistence
Structured report data and facilitator notes may be retained on plans that support report regeneration. During an applicable read-only retention period, retained report data may remain accessible and may be used to regenerate reports.
7.3 Public Scenario Builder (/build)
The public scenario builder at breachday.io/build is available without an Account. Draft content is stored in the user's browser local storage. When a user requests a PDF or DOCX export, draft content is transmitted to Breachday transiently for file generation and is not retained as Customer Data. JSON exports may be generated locally in the browser. Users should export work before clearing browser storage or switching devices.
8. Exercise Participants and Room Access
Participants join using a room code and optional room password shared by the Facilitator. Customer is responsible for controlling distribution of room credentials and for providing Participants legally required notices regarding workplace monitoring, data processing, or exercise participation.
Participants do not create Breachday Accounts and are not required to provide a legal name or email address. Breachday may process technical information such as IP addresses and request metadata for security, rate limiting, diagnostics, and Service operation as described in the Privacy Policy. Room passwords are protected using cryptographic controls appropriate to their use.
9. System Templates
Breachday provides System Templates to eligible plan tiers. Customers may clone and customize templates within their Organization. A cloned or customized copy becomes Customer Data to the extent of Customer modifications and organization-specific content. Breachday may add, modify, or retire System Templates, but changes to System Templates do not alter Customer's existing cloned copies.
10. Using the Service for Other Organizations (MSPs and Consultants)
10.1 Your Own Organization
Each standard Organization Account is for one organization. Customer may invite outside participants, such as vendors, partners, auditors, or regulators, to Customer's own exercises. Customer may not use a standard Organization Account to deliver exercises as a service to another organization.
10.2 Serving Client Organizations
An MSP, consultant, or advisory firm that wants to deliver exercises or related services to other organizations must enter into a separate MSP agreement with Breachday. Each client must have its own Client Organization, and one Client Organization may be used for only one client. Serving other organizations without an applicable MSP agreement is a material breach and may result in suspension, termination, and charges for unauthorized client usage at the applicable commercial rate.
10.3 Data Roles When You Serve Others
When Customer uses the Service for a Client under an MSP agreement, the Client is the controller of its personal data, Customer acts as the Client's processor or service provider, and Breachday acts as Customer's subprocessor under the DPA. Customer is responsible for Client authorization, passing Client instructions to Breachday, and handling Client requests and notices. Breachday takes instructions from Customer unless the MSP agreement states otherwise.
10.4 Client Organizations
Client Organizations are governed by the applicable MSP agreement, including client-slot licensing, white-label options, access grants, billing, and data lifecycle terms. If an MSP Organization is deleted, managed Client Organizations may be deleted first as described in the MSP agreement. The MSP is responsible for providing any required notices to affected Clients.
10.5 Order of Precedence for MSP Matters
The DPA controls regarding processing of Personal Data. An executed MSP agreement controls over these Terms for MSP-specific commercial matters expressly addressed in that agreement. Applicable cross-border transfer terms control for Restricted Transfers.
10.6 Compliance Verification
Breachday may review account and usage information reasonably necessary to verify plan limits, MSP licensing, security, and abuse prevention. Any access to Customer Data for this purpose will be limited to the minimum information reasonably necessary and handled under the DPA and confidentiality obligations in these Terms.
11. Support and Platform Administration
11.1 Customer Support
Support is provided through in-app tickets and other channels Breachday makes available. Breachday personnel may create internal support notes. Response times are not guaranteed for self-service plans unless a separate agreement states otherwise.
11.2 Platform Administration
Authorized Breachday personnel may access tenant and account records, reset user access, administer MSP relationships, investigate security or abuse, and perform other administrative actions reasonably necessary to operate and support the Service. Privileged administrative actions are recorded in security audit logs with access restricted to authorized personnel. Breachday does not access Customer Data except as reasonably necessary to provide support, secure or operate the Service, verify contractual usage, investigate suspected abuse, or comply with law.
12. Confidentiality
12.1 Protection and Use
Each party receiving Confidential Information ("Recipient") will use the other party's Confidential Information only to exercise rights and perform obligations under the Agreement. Recipient will protect Confidential Information using at least reasonable care and no less than the care it uses to protect its own information of similar sensitivity. Recipient may disclose Confidential Information only to personnel, professional advisers, contractors, and subprocessors that have a need to know and are bound by confidentiality obligations at least as protective as those in this Section.
12.2 Exclusions
Confidential Information does not include information that Recipient can demonstrate: (a) is or becomes publicly available without breach of the Agreement; (b) was lawfully known to Recipient without confidentiality restriction before disclosure; (c) is received lawfully from a third party without confidentiality duty; or (d) is independently developed without use of the disclosing party's Confidential Information.
12.3 Required Disclosure
Recipient may disclose Confidential Information when required by law, subpoena, or court order, provided Recipient gives advance notice to the disclosing party where legally permitted and reasonably cooperates, at the disclosing party's expense, with efforts to seek confidential treatment or protective relief.
12.4 Duration
These confidentiality obligations continue during the Agreement and for five (5) years after termination, except that obligations for trade secrets and Customer Data continue for so long as the information remains protected as a trade secret or remains in Breachday's possession, respectively.
13. Availability and Service Changes
13.1 Availability
Breachday will use commercially reasonable efforts to operate the Service. No uptime SLA applies to self-service Subscriptions unless a separate agreement states otherwise. The Service depends on third-party infrastructure, and Breachday is not responsible for outages outside its reasonable control, subject to applicable law.
13.2 Beta and Preview Features
Beta Features may be incomplete, change materially, contain errors, or be discontinued at any time. Unless a separate written agreement states otherwise, Beta Features are provided without SLA commitments and may be excluded from support commitments. Customer should not rely on Beta Features for production-critical workflows.
13.3 Service and Roadmap Changes
Breachday may modify, add, or remove features with reasonable notice where the change materially reduces purchased core functionality. Marketing statements regarding planned, coming-soon, Beta, or Enterprise features are not binding delivery commitments unless expressly included in an executed Order Form.
14. Sensitive and Regulated Data
The Service is designed for cybersecurity and business continuity simulation. Unless Breachday expressly approves a use case in writing, Customer must not submit actual PHI, payment card account data subject to PCI DSS, classified or government-restricted information, real authentication credentials, or other Sensitive Personal Data unnecessary for exercise facilitation.
Breachday is not a HIPAA Business Associate by default. Customer must not submit PHI unless Breachday has expressly approved that use in writing and the parties have executed a Business Associate Agreement and any required service-specific terms before the PHI is submitted. Customer remains responsible for determining whether its use of the Service complies with applicable regulatory requirements.
15. Disclaimers
THE SERVICE IS PROVIDED "AS IS" AND "AS AVAILABLE" TO THE MAXIMUM EXTENT PERMITTED BY LAW, WITHOUT WARRANTIES OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, OR NON-INFRINGEMENT.
THE SERVICE IS A SIMULATION AND TRAINING TOOL. BREACHDAY DOES NOT WARRANT THAT USE OF THE SERVICE CONSTITUTES LEGAL OR REGULATORY COMPLIANCE, SATISFIES AN AUDIT STANDARD, OR DEMONSTRATES ACTUAL INCIDENT-RESPONSE READINESS. REPORTS AND EXERCISE OUTPUTS ARE INFORMATIONAL AND DO NOT CONSTITUTE LEGAL, REGULATORY, OR PROFESSIONAL ADVICE.
AI-GENERATED CONTENT IS INFORMATIONAL AND MAY CONTAIN ERRORS OR OMISSIONS. CUSTOMER IS RESPONSIBLE FOR REVIEWING AND VALIDATING AI-GENERATED CONTENT BEFORE USING IT IN AN EXERCISE, DECISION, OR COMPLIANCE PROCESS.
16. Limitation of Liability
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, NEITHER BREACHDAY NOR ITS AFFILIATES WILL BE LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, CONSEQUENTIAL, OR PUNITIVE DAMAGES, OR FOR LOSS OF DATA, PROFITS, REVENUE, GOODWILL, OR BUSINESS INTERRUPTION, ARISING OUT OF OR RELATED TO THE AGREEMENT OR SERVICE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
TO THE MAXIMUM EXTENT PERMITTED BY LAW, BREACHDAY'S TOTAL CUMULATIVE LIABILITY ARISING OUT OF OR RELATED TO THE AGREEMENT OR SERVICE WILL NOT EXCEED THE FEES PAID OR PAYABLE BY CUSTOMER TO BREACHDAY FOR THE SERVICE DURING THE TWELVE (12) MONTHS IMMEDIATELY PRECEDING THE EVENT GIVING RISE TO THE CLAIM. THIS CAP DOES NOT LIMIT PAYMENT OBLIGATIONS OWED BY CUSTOMER. A SEPARATE MSP, ENTERPRISE, OR ORDER FORM MAY SPECIFY DIFFERENT CAPS.
17. Indemnification
Customer will defend, indemnify, and hold harmless Breachday LLC and its officers, directors, employees, and agents from third-party claims, liabilities, damages, judgments, losses, and reasonable attorneys' fees arising out of or relating to: (a) Customer's or its users' use of the Service in violation of the Agreement or applicable law; (b) Customer Data or an allegation that Customer Data infringes or misappropriates third-party rights; (c) Participant activity facilitated by Customer; (d) Customer's failure to provide required notices or obtain required permissions; or (e) Customer's breach of Section 6.7. Breachday will provide reasonably prompt notice of an indemnified claim and reasonable cooperation at Customer's expense. Customer may not settle a claim in a manner that admits fault by Breachday or imposes non-monetary obligations on Breachday without Breachday's written consent.
18. Term and Termination
18.1 Term
These Terms begin when Customer accepts them and remain in effect while Customer has an Account, active Subscription, or applicable post-expiration retention period, except for provisions that survive termination.
18.2 Cancellation by Customer
Customer may cancel automatic renewal at any time as described in Section 4.4. Unless otherwise agreed, cancellation takes effect at the end of the then-current paid Subscription Term and does not create a refund right.
18.3 Suspension or Termination for Cause
Breachday may suspend or terminate access for material breach, Acceptable Use violations, fraud, nonpayment, security risk, sanctions or legal restrictions, or where required by law. Where feasible and appropriate, Breachday will provide notice and a reasonable opportunity to cure before termination.
18.4 Termination or Discontinuation Without Customer Cause
If Breachday terminates a paid Subscription without Customer cause or permanently discontinues materially all of the purchased Service before the end of the paid Subscription Term, Breachday will provide a pro-rata refund of prepaid fees attributable to the unused portion of the terminated Subscription, unless Customer accepts a substantially equivalent replacement service or other remedy.
18.5 Survival
Provisions that by their nature should survive termination will survive, including payment obligations accrued before termination, intellectual property, confidentiality, disclaimers, limitation of liability, indemnification, dispute resolution, and provisions governing retained or exported data.
19. Copyright Complaints and Repeat Infringer Policy
Breachday respects intellectual property rights. A copyright owner or authorized agent may send a written infringement complaint to compliance@breachday.io identifying: (a) the copyrighted work claimed to be infringed; (b) the allegedly infringing material and information reasonably sufficient to locate it; (c) contact information for the complaining party; (d) a good-faith statement that the disputed use is not authorized by the copyright owner, its agent, or law; and (e) a statement under penalty of perjury that the information is accurate and the complaining party is authorized to act for the owner, together with an electronic or physical signature.
Breachday may remove or disable access to material in response to a sufficiently supported complaint and may notify the affected Customer. A Customer that believes material was removed by mistake or misidentification may submit a counter-notice identifying the removed material, stating under penalty of perjury a good-faith belief that removal resulted from mistake or misidentification, providing contact information and consent to the jurisdiction required by applicable law, and including a physical or electronic signature.
Breachday maintains a policy of terminating, in appropriate circumstances, Accounts of users or Organizations that repeatedly infringe third-party intellectual property rights. Breachday will accommodate and not interfere with standard technical measures for protecting copyrighted works to the extent required by applicable law.
20. Modifications to Terms
Breachday may update these Terms. Material changes will be communicated by email to the registered address or through a prominent in-Service notice at least 14 days before the effective date unless a shorter period is required to address law, security, abuse, or an urgent operational issue. Where applicable law requires affirmative consent to a change, Breachday will obtain that consent. Otherwise, continued use after the effective date constitutes acceptance. A Customer that does not agree may cancel renewal before the change takes effect.
21. Governing Law and Disputes
These Terms are governed by the laws of the State of Colorado, without regard to conflict-of-law principles. The Federal Arbitration Act governs the interpretation and enforcement of the arbitration provisions below.
Before filing arbitration, the parties will attempt in good faith for at least 30 days to resolve a dispute through written notice and business-level negotiation, unless emergency injunctive relief is reasonably necessary. Unresolved disputes will be finally resolved by binding arbitration administered by the American Arbitration Association under its Commercial Arbitration Rules before one arbitrator in Denver, Colorado, in English. The arbitrator may award any remedy available under applicable law and the Agreement. Judgment on an award may be entered in any court of competent jurisdiction.
Either party may seek temporary or emergency injunctive relief in a court of competent jurisdiction to protect intellectual property, Confidential Information, security, or access controls without waiving arbitration. For court proceedings permitted under this Section, the parties consent to exclusive jurisdiction and venue in the state and federal courts located in Denver, Colorado. TO THE EXTENT PERMITTED BY LAW, EACH PARTY WAIVES TRIAL BY JURY FOR ANY DISPUTE PERMITTED TO PROCEED IN COURT.
If an executed MSP, Enterprise, Order Form, or other written agreement establishes a different dispute process for claims arising under that agreement, the executed agreement controls for those claims.
22. General Provisions
- Order of Precedence: For conflicts, the following order applies: (1) applicable Standard Contractual Clauses or other written transfer mechanism for Restricted Transfers; (2) the DPA for processing of Personal Data; (3) an executed Order Form, MSP Agreement, Enterprise agreement, or other negotiated agreement for matters expressly addressed there; and (4) these Terms. The Privacy Policy describes privacy practices but does not override contractual terms unless expressly stated.
- Entire Agreement: The documents described in the Order of Precedence provision constitute the entire agreement between the parties regarding the Service and supersede prior proposals or understandings on the same subject.
- Severability: If a provision is held unenforceable, it will be modified to the minimum extent necessary to make it enforceable, and the remaining provisions remain in effect.
- Waiver: Failure to enforce a provision is not a waiver of future enforcement.
- Assignment: Customer may not assign the Agreement without Breachday's prior written consent, except to a successor in connection with a merger, reorganization, or sale of substantially all assets where the assignee agrees in writing to be bound. Breachday may assign the Agreement in connection with a merger, acquisition, financing, reorganization, or sale of all or substantially all relevant assets.
- Force Majeure: Neither party is liable for delay or failure caused by events beyond its reasonable control, except payment obligations for Services already provided.
- Export Controls and Sanctions: Each party will comply with applicable U.S. and other export-control, sanctions, and trade laws. Customer represents that it is not prohibited from receiving the Service under applicable sanctions or export restrictions and will not make the Service available to prohibited persons or destinations.
- Notices: Legal notices to Breachday must be sent to compliance@breachday.io. Breachday may send contractual notices to the registered Account email, through the Service, or as otherwise stated in an executed agreement.
23. Contact
For questions about these Terms:
compliance@breachday.io
Breachday LLC
breachday.io