Skip to content
Legal Documentation

Terms of
Service.

Version 2.0. Last updated: 19 September 2026. These terms govern your use of the Vivid Risk Platform and all associated services.

Contracting Entity Notice & Recitals

These Terms of Service ("Terms" or "Agreement") govern access to and use of the cloud-based compliance self-assessment, risk scoring, and governance platform ("Service" or "Platform") operated by Vivid Risk Limited, a private company limited by shares incorporated in Ireland under company registration number 818204, having its registered office at 15 The Meadows, Portlaoise, Co. Laois, Ireland ("Vivid Risk", "we", "us", or "our").

By registering an account, accessing, or using the Service, or clicking "I Accept", you ("Customer", "User", or "you") agree to be bound by these Terms. If you are entering into these Terms on behalf of a company, partnership, or other legal entity, you represent and warrant that you have full legal authority to bind such entity and its affiliates to these Terms.

1. Acceptance & Service Provision

1.1 Acceptance of Terms

By accessing or using the Service, you agree to be bound by these Terms. If you do not agree to these Terms, you must not access or use the Service.

1.2 Provision of Service

Vivid Risk provides a cloud-based risk assessment and compliance assurance platform. We reserve the right to modify, suspend, or discontinue any part of the Service at any time with prior notice when possible. Continuous improvement is part of our DNA; updates to our risk assessment methodologies ("Vivid Methodology") are deployed regularly to maintain alignment with evolving standards (NCSC CAF, ISO/IEC 27001, NIST CSF, NIS 2, DORA, Cyber Essentials, and CRA reporting guidelines).

2. Acceptable Usage & Data Security

2.1 Acceptable Usage

Users are prohibited from using the Service to store or transmit infringing, libelous, or otherwise unlawful material. You may not attempt to gain unauthorized access to any parts of the platform or its related systems. Reverse engineering of our proprietary assessment algorithms, scoring logic, or remediation roadmap logic is strictly prohibited.

2.2 Data Security & Infrastructure

Your data is encrypted in transit and at rest by Google Cloud, whose infrastructure the Service runs on, and access between tenants is separated by database security rules. We do not operate our own datacentres or encryption stack. Our Privacy Policy and our published sub-processor register at vividrisk.ai/subprocessors set out which sub-processors receive your data and where they process it; our Data Processing Agreement is incorporated into these Terms and governs our processing of Customer Content wherever you are a controller and we are your processor. You remain responsible for the confidentiality of your credentials and for activity under your account.

Compliance Notice

Vivid Risk is designed to assist in meeting requirements for ISO 27001, NIS 2, DORA, and NIST CSF. Use of our platform does not guarantee compliance with these standards but facilitates the technical and administrative evidence-gathering required.

3. Intellectual Property Rights

3.1 Vivid Risk IP

As between the parties, Vivid Risk (and its licensors) retains all right, title, and interest — including all patent, copyright, trade secret, trademark, and other intellectual property rights — in and to the Service, the Vivid Methodology, scoring algorithms, compliance citation libraries, AI cross-mapping engines, report templates, software code, UI designs, and cryptographic verification mechanisms. Except as expressly granted herein, no rights or licenses are granted to Customer.

3.2 Customer Content & Ownership

Customer retains sole ownership of all data, assessment inputs, evidence files, vendor registries, and incident records uploaded, submitted, or entered into the Platform by Customer ("Customer Content"). Customer grants Vivid Risk a non-exclusive, worldwide, royalty-free license to host, store, process, and display Customer Content solely as necessary to provide, maintain, and secure the Service in accordance with this Agreement and our Data Processing Agreement.

3.3 Generated Reports & Output Artifacts

Subject to full payment of applicable fees, Customer owns the compliance reports, risk matrix exports, cryptographic proof bundles (HMAC-SHA256 chains), and assessment outputs generated specifically for Customer by the Service.

3.4 Feedback

If Customer or its users provide feedback, suggestions, or recommendations regarding the Service, Vivid Risk may use such feedback without restriction, royalty, or obligation.

4. Fees & Subscription Terms

4.1 Payment Terms

Customer agrees to pay all fees associated with the selected subscription tier or one-time service as displayed at checkout. All payments are processed via our third-party billing processor, Stripe.

4.2 Fee Structures

  • Tier 1 (One-Time Baseline Assessment): Paid as a single, non-refundable one-time charge granting access to generate one complete framework-mapped self-assessment report.
  • Tier 2 & Tier 3 (Recurring Subscriptions): Billed monthly or annually in advance. Subscriptions auto-renew automatically for additional successive periods equal to the initial term unless cancelled prior to the renewal date.

4.3 Taxes

All fees are exclusive of Value Added Tax (VAT) and other applicable statutory taxes, which shall be added to invoices where applicable under relevant EU/UK tax laws.

5. Limited Warranties & Disclaimers

5.1 Limited Performance Warranty

Vivid Risk warrants that the Service will operate in material conformity with its published documentation. Customer's sole and exclusive remedy for breach of this warranty shall be for Vivid Risk to use commercially reasonable efforts to correct or remediate the non-conformity.

5.2 Regulatory Advice Disclaimer

Vivid Risk is a governance, risk assessment, and compliance enabling tool. Vivid Risk does not provide formal legal, regulatory, or audit opinions. Use of the Service, including AI-generated narratives and framework cross-mappings, does not guarantee compliance with NIS 2, DORA, ISO 27001, or any statutory mandate. Customer remains solely responsible for verifying assessment outputs and ensuring its own statutory compliance.

5.3 General Disclaimer

Except as expressly provided herein, the Service is provided "as is" and "as available." Vivid Risk disclaims all other warranties, express, implied, or statutory, including warranties of merchantability, fitness for a particular purpose, and non-infringement.

6. Limitation of Liability

6.1 Consequential Damages Waiver

To the maximum extent permitted by applicable law, neither party shall be liable to the other for any indirect, incidental, consequential, special, punitive, or exemplary damages, including loss of profits, data, goodwill, or business interruption, arising out of or in connection with these Terms or the Service, regardless of the theory of liability.

6.2 Aggregate Liability Caps

  • Subscription Tiers (Tier 2 and Tier 3): Vivid Risk's aggregate liability arising out of or related to these Terms or the Service shall not exceed the total fees paid or payable by Customer to Vivid Risk in the twelve (12) month period immediately preceding the event giving rise to the claim.
  • One-Time Assessment (Tier 1): Vivid Risk's total aggregate liability shall be strictly limited to the total one-time fee paid by Customer for that specific assessment engagement.

6.3 Exceptions

The limitations in Section 6.1 and Section 6.2 shall not apply to: (a) gross negligence, fraud, or willful misconduct; (b) breach of payment obligations; or (c) liabilities that cannot be limited or excluded under applicable Irish or EU law.

7. Term, Termination & Data Disposition

7.1 Term

This Agreement takes effect upon Customer's acceptance or initial access to the Service and continues until terminated in accordance with this Section.

7.2 Termination for Convenience

Customer may cancel recurring subscriptions at any time via account settings. Subscription fees are non-refundable, and termination will take effect at the end of the current paid billing cycle.

7.3 Termination for Cause

Either party may terminate these Terms immediately upon written notice if the other party materially breaches these Terms and fails to cure such breach within thirty (30) days of receipt of written notice.

7.4 Data Retention & Disposition Post-Termination

Upon termination, Customer's right to access the Service will cease. Customer data shall be handled in accordance with platform retention rules:

  • Erasure on Request: Customer Content (including assessment answers, evidence files, vendor records, and incident logs across active database collections) will be permanently erased upon written request.
  • Statutory & System Retentions: Certain collections are retained following termination where legally required or operationally justified: (i) financial and tax records (retained for statutory periods under applicable tax law); (ii) append-only audit logs — our database rules provide no update or delete path for them — together with the HMAC-SHA256 report chain, both of which are required to keep historic exports tamper-evident; and (iii) managed-client organizational records.
  • Data Export Grace Period: Customer shall have a period of thirty (30) days post-termination to export its report outputs and evidence files. Vivid Risk operates no automated deletion schedule; Customer Content persists until erased on request as set out above.

8. Governing Law & Jurisdiction

8.1 Governing Law

These Terms, and any dispute or claim (including non-contractual disputes or claims) arising out of or in connection with them or their subject matter, shall be governed by and construed in accordance with the laws of Ireland.

8.2 Jurisdiction

The parties irrevocably agree that the courts of Dublin, Ireland shall have exclusive jurisdiction to settle any dispute or claim arising out of or in connection with these Terms or their formation.

9. Contact & Legal Enquiries

For legal, procurement, or data protection enquiries, please contact:

Questions regarding our terms?

Please reach out to our support center if you have any questions or require clarification on our terms.