← Home
PLEN

Terms of Service for the Provision of Services by Electronic Means

The rules on which we make Guardiso available to you: what the subscription covers, how you pay for it, when and how you may cancel, and what we are responsible for and what you are.

Terms of Service for the Provision of Services by Electronic Means

Document version: 15 September 2026 Document effective from: 1 September 2026

These Terms set out the rules on which Guardiso provides services by electronic means, and the rules for the paid use of the Guardiso platform on a subscription basis. These Terms constitute terms of service within the meaning of Article 8(1)(1) of the Polish Act of 18 July 2002 on Providing Services by Electronic Means (ustawa o świadczeniu usług drogą elektroniczną).

These Terms are made available free of charge before the Agreement is concluded, in a form that allows them to be downloaded, reproduced and recorded, in accordance with Article 8(1)(2) of that Act.


Table of Contents

  1. General provisions and Service Provider details
  2. Definitions
  3. Type and scope of the Services provided
  4. Scope of the individual Plans
  5. Technical requirements
  6. Conclusion of the Agreement, Account registration and confirmation
  7. Trial Period
  8. Prices, currency and value added tax
  9. Payments and invoices
  10. Subscription renewal and termination
  11. Price changes
  12. Changes to the scope and functions of the Service
  13. Payment arrears and suspension of access
  14. Conformity of the Service with the Agreement
  15. Complaints procedure
  16. Right of withdrawal from the Agreement by a Protected Customer
  17. Prohibition on supplying unlawful content and acceptable use rules
  18. Intellectual property and ownership of Customer Data
  19. Confidentiality
  20. Protection of personal data
  21. Liability of the parties
  22. Termination of the Agreement, deletion of the Account and the fate of Customer Data
  23. Order of precedence of documents
  24. Force majeure
  25. Assignment of rights and obligations
  26. Amendments to these Terms
  27. Dispute resolution, governing law and competent court
  28. Contact details and final provisions

Annex No 1 — Model withdrawal form Annex No 2 — List of sub-processors


§ 1. General provisions and Service Provider details

  1. The service provider is Guardiso Michał Lewandowski, ulica Święty Marcin 29 lokal 8, 61-806 Poznań, Poland, tax identification number (NIP) 6060011996, operating under the Guardiso brand. In the remainder of these Terms the service provider is referred to as Guardiso.

  2. Electronic mail address for contact in all matters covered by these Terms: kontakt@guardiso.com. The address for written correspondence is the same as the address indicated in paragraph 1.

  3. The address of the website at which the Service is made available: https://guardiso.com.

  4. These Terms apply to all Agreements concluded with Guardiso, including to use of the Service during the Trial Period.

  5. Guardiso provides the Services in accordance with these Terms, pursuant to Article 8(4) of the Act on Providing Services by Electronic Means.

  6. The Customer is not bound by those provisions of these Terms which were not made available to the Customer before the conclusion of the Agreement in the manner described in the introductory paragraph of these Terms.


§ 2. Definitions

The terms used in these Terms have the following meanings:

  1. Service — a service provided by electronic means consisting in granting the Customer, for the duration of the Subscription and by means of a web browser, access to the Platform together with its functions, content library and data storage space, within the scope resulting from the selected Plan. The Service is a digital service supplied continuously.

  2. Platform — the Guardiso software made available at https://guardiso.com together with associated service addresses, serving to manage information security and compliance with selected standards and regulations.

  3. Subscription — the paid right to use the Service within the scope of the selected Plan for the duration of the Billing Period, renewed on the terms described in § 10.

  4. Billing Period — the unit of time for which the Subscription fee is charged. The Billing Period is one month or twelve months, according to the choice made by the Customer at the time of purchase. The first Billing Period begins on the day the first payment is credited, and each subsequent one on the day following the end of the previous one.

  5. Plan — a named set of functions, standards and limits in which the Service is sold. The Plans are described in § 4 and in the Price List.

  6. Price List — the list of Plans, their scope and prices, together with the fee for each further Organisation. The Price List is made available on the Platform in the billing section and at https://guardiso.com/pricing. The current content of the Price List is presented to the Customer before the Agreement is concluded and before each purchase.

  7. Account — an individual set of data and permissions assigned to a User, allowing that User to authenticate on the Platform and to use it within an Organisation.

  8. Organisation — a separate space on the Platform belonging to a single entity, in which Customer Data is collected and in which Users work together. One Customer may have more than one Organisation on the terms described in § 8(6).

  9. Account Owner — a User who has been assigned the owner role in the Organisation. The Account Owner represents the Customer in matters of purchase, change of Plan and termination of the Agreement.

  10. User — a natural person using the Platform within an Organisation, on the basis of an Account created independently or as a result of an invitation from the Account Owner or an administrator of the Organisation.

  11. Customer — the entity for whom Guardiso provides the Service and who is obliged to pay the remuneration. The Customer is an entrepreneur, including a natural person conducting business activity, a legal person and an organisational unit that is not a legal person but to which the law grants legal capacity. Guardiso does not address its offer to persons who do not conduct business activity.

  12. Protected Customer — a natural person conducting business activity who concludes an Agreement directly connected with that activity, where it follows from the content of the Agreement that it is not of a professional nature for that person, as results in particular from the subject matter of the business activity carried on by that person, made available on the basis of the provisions on the Central Register and Information on Business Activity (Centralna Ewidencja i Informacja o Działalności Gospodarczej). The provisions concerning consumers contained in Chapters 4, 5a and 5b of the Polish Act of 30 May 2014 on Consumer Rights (ustawa o prawach konsumenta) apply to a Protected Customer pursuant to Article 7aa of that Act, as do Articles 385¹ to 385³ of the Polish Civil Code (Kodeks cywilny) pursuant to Article 385⁵ of the Civil Code.

  13. Customer Data — all data, documents, policies, risk registers, controls, evidence, attachments and other materials entered into the Platform by the Customer or by Users, as well as data produced on the Platform at the Customer's instruction, including documents prepared with the assistance of artificial intelligence mechanisms.

  14. Business Day — a day from Monday to Friday, excluding days that are public holidays in the Republic of Poland. All time limits in these Terms are calculated according to the time in force in the Republic of Poland, that is according to the Europe/Warsaw time zone.

  15. Trial Period — free access to the Platform, limited in time and in scope, described in § 7. The Trial Period is not a Subscription.

  16. Agreement — the agreement for the provision of services by electronic means concluded between Guardiso and the Customer on the terms set out in these Terms, covering use of the Service during the Trial Period or under a Subscription.

  17. Terms — this document together with its annexes.


§ 3. Type and scope of the Services provided

  1. Guardiso provides the following Services by electronic means:

    1. The main, paid Service — provision of the Platform on a subscription basis, comprising the maintenance of information security management system documentation, the maintenance of registers of risks, controls, evidence, incidents, suppliers and tasks, the preparation and circulation of internal documents, the preparation of materials for audit purposes and making them available to an external auditor, as well as the use of artificial intelligence mechanisms supporting these activities. The detailed scope depends on the Plan and is described in § 4.

    2. The free Service — maintenance of the Account, authentication, the contact form, the product demonstration sign-up form and the Trial Period.

  2. The Service consists in making an IT tool available. Guardiso does not provide legal assistance, does not provide tax advice, does not act as an auditor or a certification body and does not issue certificates. Obtaining a certificate of conformity with any standard depends solely on the outcome of an independent audit carried out by an authorised external entity.

  3. Materials prepared with the assistance of artificial intelligence mechanisms, including draft policies, risk descriptions, proposed controls and summaries, constitute a proposal intended for verification and approval by the Customer. The decision to accept such material and to apply it rests with the Customer.

  4. Compliance indicators, readiness levels and other measures presented on the Platform are the result of processing data entered by the Customer. They do not constitute an assessment of compliance with the law or with a standard and do not replace an audit.

  5. Guardiso does not undertake in these Terms to any particular level of Service availability. Guardiso makes every effort to ensure that the Service is available without interruption, and plans maintenance work in the manner least burdensome for Customers that is reasonably possible. An undertaking as to a particular level of availability, as to particular response times to reports and as to credits for failing to meet them results solely from the Service Level Agreement and solely to the extent described therein. That agreement itself determines to which Plans and to what extent it applies; Guardiso does not undertake in this document to any percentage level of availability, because it does not measure the availability of its own Service.

  6. Customer support is provided by electronic mail, on Business Days, between 9:00 and 17:00. Guardiso does not operate a round-the-clock duty service or a response team available outside those hours.

  7. Guardiso makes database backups on a daily cycle, with a retention period of seven days. Guardiso does not specify a guaranteed time for restoring the Service after a failure or a guaranteed scope of data recovery.


§ 4. Scope of the individual Plans

  1. The Starter Plan covers three standards: ISO/IEC 27001, the General Data Protection Regulation and the NIS 2 Directive, whereby for Organisations established in the Republic of Poland the set covers NIS 2 together with the Polish National Cybersecurity System Act (ustawa o krajowym systemie cyberbezpieczeństwa). The Starter Plan comprises: maintenance of documentation and configuration of the information security management system, the personal data protection module, the Statement of Applicability and readiness assessment, the incident register, the business continuity plan, internal audit, external auditor access together with an evidence pack, the trust portal, the domain security assessment, as well as the setup wizard, the document analyser and the Assistant based on artificial intelligence.

  2. The Professional Plan covers all standards and regulations available in the Platform catalogue and, beyond the scope of the Starter Plan: supplier risk management, employee training, integrations with external systems, security operations together with monitoring of leaked authentication credentials, the management board dashboard together with reporting for senior management, the audit programme, cross-mapping between standards, extended compliance tools, the advisor based on artificial intelligence, the register of artificial intelligence systems, and questionnaires and readiness assessments.

  3. The Enterprise Plan covers the scope of the Professional Plan and, in addition: the Customer's own standards, sign-in using a corporate identity provider together with automatic account provisioning, support for a capital group structure and full export of the Organisation. The terms of the Enterprise Plan, including its price, are agreed individually in a separate agreement.

  4. Guardiso additionally makes available a plan intended for public sector entities, covering the National Interoperability Framework (Krajowe Ramy Interoperacyjności), the NIS 2 Directive together with the National Cybersecurity System Act, and the General Data Protection Regulation. This plan is not offered through self-service sales and is made available solely on individually agreed terms.

  5. Enabling a standard on the Platform causes the corresponding set of controls to be prepared. Under the Professional Plan and the Enterprise Plan the Customer may enable any standard from the catalogue, whereby immediately after purchase only the starter set is prepared, so that the scope remains manageable.

  6. The current, detailed scope of each Plan, together with its limits, is presented in the Price List and on the Platform in the billing section, before the purchase is made. The number of Users in an Organisation is not limited under any Plan. The limits which the Platform checks before a resource is added concern the number of standards enabled at the same time and the monthly budget of queries to artificial intelligence mechanisms. The number of Organisations covered by the price of the Plan results from the Price List and from the Plan description, and each further Organisation is subject to the fee described in § 8(6).

  7. Exceeding a limit referred to in paragraph 6, third sentence, results in the suspension of the ability to add a further resource until the Plan is changed or a resource is released. Exceeding any limit does not automatically trigger an additional charge. The number of Organisations maintained is not currently enforced by a technical mechanism, and therefore a further Organisation is added upon request, and the fee for it is added to the invoice.


§ 5. Technical requirements

  1. Use of the Service requires:

    1. a device with access to the Internet and a permanent connection;
    2. a web browser in the current major version or in one of the two immediately preceding it: Google Chrome, Microsoft Edge, Mozilla Firefox or Apple Safari;
    3. JavaScript and cookie support enabled;
    4. an active electronic mail account to which Guardiso sends confirmations, notifications and one-time sign-in links;
    5. in the case of signing in with a Google account — an active account with that service.
  2. Registration for the Trial Period requires the provision of a corporate electronic mail address. Addresses in free, publicly available mail domains are not accepted.

  3. Guardiso is not liable for the Service not working, or working incorrectly, as a result of failure to meet the requirements described in paragraph 1, in particular as a result of using a browser in an unsupported version, blocking cookies or restrictions imposed by the Customer's network.

  4. Use of the Service involves the typical risks of transmitting data over the Internet, in particular the risk of sign-in credentials being intercepted by unauthorised persons, the risk of message sender spoofing and the risk of malicious software operating on the User's device. Guardiso recommends using up-to-date software, separate and unique passwords, and two-factor authentication with the identity provider.

  5. Guardiso makes available updates to the Service, including security updates, necessary to keep the Service in conformity with the Agreement, throughout the term of the Agreement. Updates are introduced on the Guardiso side and do not require any action by the Customer. This provision implements the obligation arising from Article 43k(3) of the Consumer Rights Act.


§ 6. Conclusion of the Agreement, Account registration and confirmation

  1. Use of the Service requires the creation of an Account. An Account is created by completing the registration form available on the website or by accepting an invitation sent by the Account Owner or by an administrator of an existing Organisation.

  2. Authentication takes place using a Google account or using a one-time sign-in link sent to the User's electronic mail address. Guardiso does not store Users' passwords.

  3. By registering an Account, the User declares that:

    1. they are eighteen years of age or older and have full legal capacity;
    2. the data provided is true and up to date;
    3. they are authorised to act on behalf of the entity for which they are creating the Organisation;
    4. they have read these Terms and accept their content.
  4. The agreement for the provision of the free Service is concluded upon confirmation of the electronic mail address by the first sign-in using the link sent, or upon the first sign-in with a Google account.

  5. The agreement for the provision of the paid Service, that is the Subscription, is concluded upon the crediting of the first payment by the payment operator. Placing an order is a declaration of intent by the Customer, and acceptance of that declaration consists in making the Plan available and issuing an invoice.

    The agreements binding the Customer as an entrepreneur, that is the Data Processing Agreement, the End User Licence Agreement, the Service Level Agreement and the Exit and Data Portability Terms, are concluded earlier than the Subscription: at the moment the person authorised to represent the Customer makes the declaration of their conclusion on the Platform, on the screen preceding the placing of the order. The moment each of them is concluded is recorded in the evidence referred to in paragraph 13. Neither the mere creation of an Account nor the mere commencement of use of the Platform concludes any of those agreements.

  6. Before placing an order, the Customer sees in the summary: the name of the Plan, the length of the Billing Period, the net price, the currency, information about Subscription renewal, and also — in the case of a Protected Customer — information about the right of withdrawal from the contract together with Annex No 1. Value added tax is not included in the price; its rate and amount are determined on the terms described in § 8(7) and shown on the invoice. If the payment operator calculates the tax in the payment summary, the tax amount and the gross amount are presented there before the charge is made.

  7. Guardiso provides the Customer with confirmation of the conclusion of the Agreement on a durable medium, by electronic mail to the address of the Account Owner, immediately after the Agreement is concluded and at the latest before the provision of the paid Service begins. The confirmation covers the content of these Terms, the selected Plan, the price, the length of the Billing Period, the renewal rules and — in the case of a Protected Customer — the information required by Article 21(1) of the Consumer Rights Act.

  8. Purchase by payment card is possible only in respect of the Starter Plan. The Professional Plan and the Enterprise Plan are made available following prior contact with Guardiso and on individually agreed terms.

  9. Only a User holding the owner or administrator role in the Organisation may make a purchase, change the Plan or terminate the Subscription.

  10. The Agreement is concluded in electronic form. Acceptance of these Terms, expressed by ticking the relevant box in the Platform by a User authenticated in the manner described in paragraph 2, constitutes a declaration of intent and is made in documentary form.

  11. Electronic form does not weaken the legal force of the Agreement in any Member State of the European Union. Under Article 25(1) of Regulation (EU) No 910/2014 of the European Parliament and of the Council of 23 July 2014 on electronic identification and trust services for electronic transactions in the internal market (eIDAS), an electronic signature shall not be denied legal effect and admissibility as evidence in legal proceedings solely on the grounds that it is in an electronic form or that it does not meet the requirements for qualified electronic signatures. The ability to conclude contracts by electronic means is further guaranteed by Article 9 of Directive 2000/31/EC on electronic commerce. Under Polish law, which governs this Agreement, the same declaration constitutes a declaration of intent within the meaning of Article 60 of the Polish Civil Code and is made in documentary form within the meaning of Article 77² of that Code.

  12. The Data Processing Agreement is concluded in electronic form, which is expressly permitted by Article 28(3) of Regulation (EU) 2016/679, requiring writing "including in electronic form". A separate document bearing a qualified electronic signature is not required. At the Customer's request, Guardiso will make the Data Processing Agreement available for signature in that manner.

  13. Guardiso records and retains evidence of the conclusion of the Agreement. The evidence comprises: the name and email address of the person making the declaration, the date and time it was made, the internet protocol address from which it was made, the browser identification, and the full text of every accepted document together with a cryptographic hash of that text computed using SHA-256. The hash makes it possible to demonstrate that the wording held by Guardiso is exactly the wording the Customer accepted and that it has not been altered since. If the internet protocol address cannot be established, the evidence states expressly that no address was recorded. Guardiso does not enter a substitute value in its place, nor an address originating from an event other than the one to which the evidence relates.

  14. The evidence referred to in paragraph 13 is available for download in the Platform throughout the term of the Agreement and for the limitation period applicable to claims after its termination, and is in addition delivered to the Customer by email immediately after the Agreement is concluded, in accordance with paragraph 7.


§ 7. Trial Period

  1. Guardiso makes available a Trial Period lasting fourteen days counted from the day the Organisation is created. Where the Trial Period has been made available on the basis of an individual invitation, its length results from the content of the invitation.

  2. The Trial Period is free of charge and does not require payment card details to be provided.

  3. The scope of the Trial Period corresponds to the functional scope of the Starter Plan, save that it covers only one standard: ISO/IEC 27001. The remaining standards are not made available during the Trial Period.

  4. During the Trial Period, limits apply to the number of documents generated and to the number of queries to artificial intelligence mechanisms. Information on limit usage is presented on the Platform.

  5. One Trial Period is available per electronic mail address. Re-registration with the same address does not result in a further Trial Period being made available.

  6. The Trial Period does not automatically convert into a paid Subscription. After it ends, no payment is taken and access to paid functions is restricted. Moving to a Subscription requires a separate action by the Customer consisting in placing an order.

  7. After the Trial Period ends, the Organisation remains available for a further fourteen days, during which the Customer retains the ability to sign in, review the data entered, use the export functions and purchase a Subscription. The restrictions on paid functions apply in full during that time.

  8. Upon expiry of the period indicated in paragraph 7, the Organisation is moved to the archive and ceases to be available to the Customer. From that moment § 22(5) and (6) apply to Customer Data, with all periods counted from the day the Trial Period ended. This means that:

    1. Customer Data is retained for thirty days from the end of the Trial Period; during that time the Customer may request a copy of it or declare that it is to be deleted, and the absence of a declaration means that deletion is chosen;
    2. Customer Data is permanently deleted from the production environment within fourteen days after expiry of the period indicated in point 1, that is at the latest on the forty-fourth day from the end of the Trial Period;
    3. Customer Data disappears from backups at the latest on the fifty-first day from the end of the Trial Period, on the terms described in § 22(6).

    Restoration of the Organisation from the archive before the expiry of the period indicated in point 2 takes place at a request submitted to the electronic mail address indicated in § 1(2). After that period restoration is not possible, because Customer Data has been deleted.

  9. After the permanent deletion referred to in paragraph 8, Guardiso retains only: the account of the person who created the Organisation together with their electronic mail address, the record that the Trial Period has been used by that address, which serves to give effect to the rule in paragraph 5, and the evidence of the conclusion of the legal documents referred to in § 6(13), retained for the limitation period for claims. Documents, risk registers, controls, evidence and the remaining Customer Data are not retained. Using the Platform again with the same electronic mail address remains possible, but begins with an empty Organisation.

  10. An Organisation created within the Trial Period in which no sign-in has ever taken place and in which no data has been produced is subject to deletion on the terms described in paragraph 8. Guardiso may delete such an Organisation earlier, but not earlier than forty-eight hours after its creation. This provision serves to limit the retention of data originating from registrations made to non-existent addresses.

  11. Data entered during the Trial Period remains available after the purchase of a Subscription. The purchase of a Subscription ends the Trial Period.

  12. § 16 does not apply to the Trial Period, because the right of withdrawal from the contract concerns a paid contract. The Customer may cancel the Trial Period at any time, without giving a reason and without incurring any costs.


§ 8. Prices, currency and value added tax

  1. Prices are stated as net amounts. Value added tax is added to the net price at the rate resulting from the provisions in force on the date the invoice is issued and from the Customer's tax status. The tax amount and the gross amount are shown on the invoice and, in addition, in the payment summary if the payment operator calculates the tax. The net price visible before the order is placed does not change.

  2. The prices of the Plans are as follows:

PlanMonthlyAnnually
StarterEUR 199EUR 2,189
ProfessionalEUR 499EUR 4,990
Enterpriseprice agreed individuallyprice agreed individually
  1. The annual price of the Starter Plan corresponds to eleven times the monthly price, which means a discount equal to one month. The annual price of the Professional Plan corresponds to ten times the monthly price, which means a discount equal to two months.

  2. The sales currency results from the language version of the website in which the Customer makes the purchase. The Polish language version sells in Polish zloty; every other language version sells in euro. The Customer is charged exactly the amount, and in the currency, that the Customer saw on screen before placing the order.

  3. The currency of an ongoing Subscription is not subject to change. A change of currency requires the existing Subscription to be ended and a new Agreement to be concluded.

  4. Maintaining each further Organisation under the same Account is subject to a fee in the amount specified in the Price List, charged independently of the Plan fee. The number of Organisations covered by the price of the Plan results from the Price List. A further Organisation is added upon a request submitted to the electronic mail address indicated in § 1(2); the Platform does not currently offer self-service purchase of a further Organisation, and Guardiso does not undertake to any deadline for performing this action.

  5. The value added tax rate is determined according to the following rules:

    1. sale to an entity established in the Republic of Poland — the domestic rate of 23 per cent;
    2. sale to an entity from another Member State of the European Union holding an identification number for intra-Community transactions — reverse charge, a rate of 0 per cent together with the appropriate annotation on the invoice;
    3. sale to a person from another Member State of the European Union who does not hold such a number — the rate applicable in the purchaser's country, under the One Stop Shop procedure;
    4. sale outside the European Union — a rate of 0 per cent, whereby settlement of the tax remains the responsibility of the purchaser.
  6. The rules described in paragraph 7 result from tax legislation. Should that legislation change, or should the Customer's tax status change, Guardiso applies the rate resulting from the provisions in force on the date the invoice is issued, without the need to amend these Terms.


§ 9. Payments and invoices

  1. Payments are handled by the payment operator Stripe. Guardiso does not store the Customer's full payment card details.

  2. The Subscription fee is charged in advance for the whole Billing Period, on the day it begins. The first fee is charged at the moment the order is placed.

  3. The day of payment is deemed to be the day on which the Guardiso account is credited or the day on which Guardiso receives confirmation from the payment operator that the payment has been credited, whichever occurs earlier.

  4. The invoice is issued once the payment has been credited and delivered in electronic form to the electronic mail address assigned to the Organisation. The invoice is additionally available for download on the Platform, in the billing section.

  5. Issuing an invoice requires the Customer to provide a tax identification number. If the Organisation does not have a tax identification number completed, the invoice will not be issued until it is completed. The Customer is responsible for the correctness and currency of the invoicing details, including the name, address and tax identification number.

  6. The Customer consents to receiving invoices in electronic form. Consent is given when the order is placed and may be withdrawn by a statement sent to the electronic mail address indicated in § 1(2), with effect for the future. Withdrawal of consent results in invoices being delivered in paper form to the Customer's correspondence address.

  7. From the moment Guardiso becomes subject to the obligation to issue structured invoices in the National e-Invoicing System (Krajowy System e-Faktur), invoices will be issued and made available in that system, and delivery of the invoice will take place in accordance with the provisions governing that system. Paragraph 6 then applies to the extent that it remains consistent with those provisions.

  8. The Customer is obliged to ensure that funds are available for the charge on the day each subsequent Billing Period begins. The consequences of a lack of funds are described in § 13.


§ 10. Subscription renewal and termination

  1. The Subscription renews automatically for a further Billing Period of the same length and under the same Plan, unless it has previously been terminated. Renewal takes place by charging the fee for the next Billing Period on the day it begins.

  2. A monthly Subscription renews for a further month, and an annual Subscription for a further twelve months.

  3. The Customer may terminate the Subscription at any time, without giving a reason. A termination submitted no later than on the last day of the current Billing Period takes effect at the end of that Billing Period. Until then the Customer retains full access to the Service within the scope paid for.

  4. Termination is effected:

    1. on the Platform, in the Settings section, in the part concerning billing, by opening the payment operator's billing panel and selecting cancellation of the subscription; the function is available to a User holding the owner or administrator role; or
    2. by a statement sent to the electronic mail address indicated in § 1(2); it is sufficient, in order to meet the deadline, that the statement is sent before it expires.
  5. Guardiso confirms receipt of the termination by electronic mail, indicating the day on which the Subscription will cease.

  6. Termination does not give rise to a refund of the fee for the Billing Period that has begun, unless these Terms or a provision of law state otherwise. A pro rata refund for the unused part of the Billing Period is due in the cases described in paragraph 8 of this section, in § 12(5), in § 24(4), in § 25(4) and in § 26(5). A refund of all or part of the amount paid is additionally due in the case of withdrawal from the contract on the terms described in § 16 and in the case of a lack of conformity of the Service with the Agreement on the terms described in § 14.

  7. An upgrade to a higher Plan takes effect from the moment the additional payment is made, whereby the additional payment is calculated in proportion to the remaining part of the Billing Period. A downgrade to a lower Plan takes effect from the beginning of the next Billing Period. Every change of Plan requires the amount to be confirmed by the Customer before it is charged.

  8. Guardiso may terminate the Agreement with thirty days' notice, with effect at the end of the paid Billing Period, refunding to the Customer the fee for the unused part of that Period. In relation to a Protected Customer, this right applies solely for the important reasons indicated in § 22(4).


§ 11. Price changes

  1. The price applicable in a paid Billing Period does not change. A price increase does not have retroactive effect and does not apply to a Billing Period for which the Customer has already paid.

  2. Guardiso may change the price of a Plan with effect from the beginning of the next Billing Period, solely for the following reasons:

    1. an increase in the costs of providing the Service, in particular infrastructure costs, the costs of services of the sub-processors listed in Annex No 2 and the costs of processing queries by artificial intelligence mechanisms;
    2. a change in generally applicable legislation affecting the cost of providing the Service, including a change in tax rates and public levies;
    3. a material extension of the scope of the Plan by new functions or by new standards;
    4. a change in the consumer price index announced by the President of Statistics Poland (Prezes Głównego Urzędu Statystycznego) for the period since the previous price change.
  3. Guardiso notifies the Customer of a price change by electronic mail, to the address of the Account Owner, at least thirty days before the beginning of the Billing Period to which the change relates. The notification indicates the existing price, the new price, the reason for the change and the day from which the new price applies, together with information about the right under paragraph 4.

  4. A Customer who does not agree to the new price may terminate the Subscription no later than on the last day of the current Billing Period, with effect as at the day preceding the entry into force of the new price, without incurring any costs on that account. Termination is effected in the manner described in § 10(4).

  5. Failure to terminate within the time limit indicated in paragraph 4 means acceptance of the new price.

  6. A price change does not constitute an amendment to these Terms and does not require the procedure described in § 26.


§ 12. Changes to the scope and functions of the Service

  1. Guardiso develops the Platform on an ongoing basis. Changes necessary to keep the Service in conformity with the Agreement, including security updates and bug fixes, are introduced without separate notification and involve no costs on the Customer's side.

  2. Guardiso may make a change to the Service that is not necessary to keep it in conformity with the Agreement solely for the following valid reasons:

    1. adapting the Platform to a change in generally applicable legislation or to a new edition of a norm or standard supported on the Platform;
    2. raising the level of security of the Service or removing a vulnerability;
    3. a change in, restriction of, or discontinuation of a service by a sub-processor listed in Annex No 2, where a Platform function relies on that service;
    4. withdrawal of a function that no Customer has used in the last twelve months, or of a function replaced by a function with an equivalent purpose;
    5. technical development of the Platform, including a change in the manner of presenting data and in screen layout, provided that this does not restrict the scope of the Service.
  3. A change referred to in paragraph 2 may not involve any costs on the Customer's side. Guardiso informs the Customer of it in a clear and comprehensible manner.

  4. Where a change referred to in paragraph 2 materially and adversely affects a Protected Customer's access to the Service or use of it, Guardiso notifies that Customer with appropriate advance notice, on a durable medium, indicating the characteristics of the change, the date of its introduction and the right described in paragraph 5.

  5. In the case referred to in paragraph 4, the Protected Customer may terminate the Agreement without notice within thirty days of the day the change was made or of the day of notification of it, if notification took place later than the change. Guardiso then refunds the fee for the unused part of the Billing Period. This right does not apply if Guardiso provides the Protected Customer with the ability to continue using the Service unchanged, at no additional cost.

  6. Paragraphs 2 to 5 implement Articles 43p and 43q of the Consumer Rights Act.

  7. In relation to a Customer who is not a Protected Customer, the right under paragraph 5 applies accordingly if the change deprives that Customer of a function constituting a material element of the Plan for which the Customer has paid.


§ 13. Payment arrears and suspension of access

  1. If the fee for the next Billing Period is not collected due to a lack of funds, expiry of the payment card or another reason attributable to the Customer, Guardiso makes further charge attempts over a period of seven days from the day that Billing Period begins. During that time the Service is provided without restrictions.

  2. If, after the period indicated in paragraph 1 has expired, the payment is still not credited, Guardiso sends the Customer a payment demand by electronic mail, to the address of the Account Owner, setting an additional period of seven days. The demand states the amount of the arrears, the payment deadline and a warning that access will be suspended.

  3. Once the time limit indicated in the demand has expired without effect, that is no earlier than on the fourteenth day from the day the unpaid Billing Period began, Guardiso may suspend access to the Service.

  4. During suspension:

    1. Customer Data is not deleted, is not modified and is not disclosed to third parties, and remains covered by the same safeguards as before the suspension;
    2. signing in to the Platform remains possible, and access is limited to the billing section, to the export functions and to Guardiso's contact details;
    3. the Organisation's automated tasks are not performed, including evidence collection, domain scanning and the sending of notifications;
    4. no fee is charged for the period of suspension.
  5. Payment of the arrears results in the immediate restoration of full access.

  6. If the arrears are not settled within thirty days of the day of suspension, Guardiso may terminate the Agreement with immediate effect. § 22 then applies to the fate of the Customer Data.

  7. Guardiso does not charge interest or handling fees on account of suspension. The entitlement to statutory interest for delay in commercial transactions remains unaffected in relation to a Customer who is not a Protected Customer.


§ 14. Conformity of the Service with the Agreement

  1. Guardiso undertakes to supply a Service that is in conformity with the Agreement. The Service is in conformity with the Agreement if, in particular, its description, type, quantity, quality, completeness, functionality, compatibility, interoperability and the availability of technical support and updates are in conformity with the Agreement, and additionally if the Service is fit for the purposes for which a digital service of that type is normally used and has the features typical of such a service that the Customer may reasonably expect.

  2. In relation to a Protected Customer, Chapter 5b of the Consumer Rights Act applies, in particular:

    1. Article 43k — the criteria for conformity of the Service with the Agreement and the obligation to supply updates;
    2. Article 43l(3) — Guardiso is liable for a lack of conformity of the Service with the Agreement that occurred or became apparent during the time in which the Service was to be supplied, whereby a lack of conformity is presumed to have occurred during that time if it became apparent during that time;
    3. Article 43m — the Protected Customer may demand that the Service be brought into conformity with the Agreement; Guardiso brings the Service into conformity within a reasonable time of being notified and without significant inconvenience to the Protected Customer, at its own expense;
    4. Article 43n — if bringing the Service into conformity is impossible or would require excessive costs, if Guardiso has not brought the Service into conformity, if the lack of conformity persists despite an attempt to remove it, or if the lack of conformity is so material as to justify this without a prior demand for repair — the Protected Customer may make a declaration of price reduction or of withdrawal from the contract; in the case of a price reduction, account is taken of the time during which the Service remained not in conformity with the Agreement;
    5. Article 43o — following withdrawal, Guardiso is not entitled to demand payment for the time during which the Service was not in conformity with the Agreement, even if the Protected Customer actually used it, and makes available, on request and at its own expense, within a reasonable time and in a commonly used machine-readable format, the content produced or supplied by the Protected Customer in the course of using the Service.
  3. A Protected Customer may not withdraw from the Agreement on the basis of paragraph 2, point 4 if the lack of conformity of the Service with the Agreement is immaterial. A lack of conformity is presumed to be material.

  4. In relation to a Customer who is not a Protected Customer, Guardiso is liable for improper performance of the Agreement on the general principles resulting from the Civil Code, with the limitations described in § 21.

  5. A lack of conformity of the Service with the Agreement is reported under the complaints procedure described in § 15.


§ 15. Complaints procedure

  1. The Customer and the User have the right to submit a complaint concerning the performance of the Service, including a complaint concerning a lack of conformity of the Service with the Agreement and a complaint concerning billing.

  2. A complaint is submitted:

    1. by electronic mail to kontakt@guardiso.com; or
    2. in writing to the address indicated in § 1(1).
  3. A complaint should contain:

    1. identification of the person submitting the complaint and the name of the Organisation to which the complaint relates;
    2. the electronic mail address of the Account to which the response is to be sent;
    3. a description of the irregularity together with an indication of when it occurred and, if possible, the address of the screen on which it occurred;
    4. the demand of the person submitting the complaint.
  4. The absence of any of the elements indicated in paragraph 3 is not a ground for refusing to consider the complaint. Guardiso then asks for it to be supplemented to the extent necessary to consider the matter, and the time limit referred to in paragraph 5 begins to run from the day the complaint is received.

  5. Guardiso responds to a complaint within fourteen days of the day it is received.

  6. If Guardiso does not respond to a Protected Customer's complaint within the time limit indicated in paragraph 5, the complaint is deemed to have been upheld. This rule results from Article 7a(2) of the Consumer Rights Act, applied to a Protected Customer.

  7. Guardiso provides the response to a complaint on paper or on another durable medium, in particular by electronic mail, in accordance with Article 7a(3) of the Consumer Rights Act.

  8. Use of the complaints procedure does not limit the rights available under provisions of law, including the right to pursue claims before a court.


§ 16. Right of withdrawal from the Agreement by a Protected Customer

Information on the right of withdrawal from the contract

  1. A Protected Customer has the right to withdraw from a distance contract within fourteen days, without giving a reason and without incurring costs, subject to paragraph 7. This right results from Article 27(1) of the Consumer Rights Act, applied to a Protected Customer on the basis of Article 7aa of that Act.

  2. The time limit begins to run from the day the Agreement is concluded. This rule results from Article 28(2) of the Consumer Rights Act, because the subject of the Agreement is a service and not goods. The day of conclusion of a paid Agreement is deemed to be the day the first payment is credited, in accordance with § 6(5).

  3. It is sufficient, in order to meet the deadline, that the statement is sent before it expires.

  4. Withdrawal is effected by submitting to Guardiso a statement of withdrawal from the contract. The statement may be submitted:

    1. by electronic mail to kontakt@guardiso.com;
    2. in writing to the address indicated in § 1(1);
    3. using the model statement constituting Annex No 1 to these Terms, whereby use of that model is not obligatory; the model corresponds to the model contained in Annex No 2 to the Consumer Rights Act.
  5. Guardiso promptly sends the Protected Customer, on a durable medium, confirmation of receipt of the statement of withdrawal from the contract.

  6. In the case of withdrawal, the Agreement is deemed not to have been concluded. Guardiso refunds to the Protected Customer all payments made by that Customer promptly, and no later than within fourteen days of the day the statement of withdrawal is received, using the same means of payment as the Protected Customer used, unless the Protected Customer has expressly agreed to another means of refund which involves no costs for that Customer.

Request to begin performance before the withdrawal period expires

  1. The Service is made available immediately after the payment is credited. Beginning performance before the period for withdrawal from the contract expires requires an express request from the Protected Customer, submitted by ticking a separate checkbox, unticked by default, in the order summary, reading:

    "I request that performance of the service begin before the period for withdrawal from the contract expires. I acknowledge that if I withdraw from the contract I will pay for the performance rendered up to the moment of withdrawal."

    This provision implements Article 21(2) of the Consumer Rights Act.

    The checkbox referred to in the first sentence is available in the order summary and remains unticked by default. Ticking it is voluntary and is not a condition of placing an order or of concluding the Agreement. Guardiso records the ticking of that checkbox together with the full wording of the declaration, the date, the time, the internet protocol address and the browser identification, on the terms described in § 6(13).

    If Guardiso does not hold such evidence, it assumes that the request has not been made, with the effect described in paragraph 9, that is with a refund of the full amount paid in the event of withdrawal. Guardiso does not invoke against a Protected Customer a request whose making it is unable to demonstrate.

  2. Making the request referred to in paragraph 7 does not deprive the Protected Customer of the right of withdrawal from the contract. The only effect of such a request is the obligation to pay for the performance rendered up to the moment of withdrawal, calculated in proportion to the scope of the performance rendered, having regard to the price agreed in the Agreement. This rule results from Article 35 of the Consumer Rights Act. In such a case Guardiso refunds the amount reduced by that part.

  3. If the Protected Customer has not made the request referred to in paragraph 7, that Customer does not bear the costs of the Service for the period up to withdrawal from the contract, in accordance with Article 36(1)(b) of the Consumer Rights Act. In such a case, in the event of withdrawal from the contract, Guardiso refunds the full amount paid, including where the Protected Customer used the Platform during that time.

Loss of the right of withdrawal from the contract

  1. The right of withdrawal from the contract does not apply to a Protected Customer solely where Guardiso has fully performed the Service with the express and prior consent of the Protected Customer, who was informed before performance began that upon completion of the performance that Customer would lose the right of withdrawal from the contract, and who acknowledged this. This rule results from Article 38(1)(1) of the Consumer Rights Act.

  2. Guardiso clarifies that in the case of a Subscription the situation described in paragraph 10 does not arise, because the Service is supplied continuously throughout the Billing Period and cannot be fully performed within fourteen days. The right of withdrawal from the contract therefore also applies to a Protected Customer who has begun using the Platform, and the only consequence of such use is the obligation to make the proportionate payment referred to in paragraph 8.

Time limit where the information was not provided

  1. If Guardiso has not informed the Protected Customer of the right of withdrawal from the contract, that right expires only upon the lapse of twelve months from the day the time limit indicated in paragraph 1 expires. If the Protected Customer is informed of that right before it expires, the withdrawal period ends fourteen days after the information is provided. This rule results from Article 29 of the Consumer Rights Act.

  2. Guardiso provides the information referred to in paragraph 12 in the content of this section, in the order summary and in the confirmation of conclusion of the Agreement sent on a durable medium in accordance with § 6(7), and provides the model statement as Annex No 1. The purpose of these steps is that the withdrawal period should be fourteen days and not fourteen days plus twelve months.

Data following withdrawal

  1. Following withdrawal from the contract, Guardiso does not use Customer Data other than personal data, produced or supplied by the Protected Customer in the course of using the Service, subject to the exceptions resulting from Article 43o(1) of the Consumer Rights Act. At the request of the Protected Customer and at its own expense, Guardiso makes that data available to that Customer within a reasonable time, in a commonly used machine-readable format.

  2. The right of withdrawal described in this section does not apply to a Customer who is not a Protected Customer, that is in particular to a company or to a natural person conducting business activity for whom the purchase is of a professional nature.

  3. If it does not follow from the content of the Agreement whether it is of a professional nature for a natural person conducting business activity, that person may at the latest at the moment the Agreement is concluded submit a statement on the matter. Guardiso does not make the conclusion of the Agreement conditional on the submission of such a statement.


§ 17. Prohibition on supplying unlawful content and acceptable use rules

  1. The Customer and the User are subject to a prohibition on supplying content of an unlawful nature. The prohibition results from Article 8(3)(2)(b) of the Act on Providing Services by Electronic Means.

  2. In particular, it is prohibited to introduce into the Platform content infringing the rights of third parties, content infringing personal rights, content inciting hatred, content containing malicious software and data obtained unlawfully.

  3. Detailed rules for using the Platform, including rules on load placed on resources, automated retrieval of content, use of the application programming interface, conducting security testing and granting access to third parties, are set out in the Acceptable Use Policy, available at https://guardiso.com/dozwolone-uzytkowanie. The Acceptable Use Policy forms an integral part of the Agreement.

  4. The Customer is liable for the acts and omissions of Users to whom the Customer has granted access to the Organisation as for its own.

  5. Where a breach of the prohibition under paragraph 1 or a material breach of the Acceptable Use Policy is established, Guardiso calls upon the Customer to cease the breach, setting a period of not less than seven days, and in matters covered by the End User Licence Agreement not less than fourteen days, in accordance with § 15(1) of that agreement. If the breach threatens the security of other Customers' data or the operational continuity of the Platform, Guardiso may suspend access immediately, notifying the Customer of this and indicating the reason.

  6. Receipt of official notification or credible information about the unlawful nature of stored data gives rise on the Guardiso side to the obligations resulting from the Act on Providing Services by Electronic Means. Guardiso promptly notifies the Customer of its intention to prevent access to such data.


§ 18. Intellectual property and ownership of Customer Data

  1. The Platform, including its source code, interface, documentation and content library comprising model policies, the risk catalogue, control mappings between standards and implementation guides, is the subject of exclusive rights of Guardiso or its licensors.

  2. The Customer receives a licence that is non-exclusive, non-transferable and without the right to grant sub-licences, limited to the duration of the Subscription and to use of the Platform for its own internal needs. The detailed scope of the licence, including the scope of the restrictions, is set out in the End User Licence Agreement.

  3. Customer Data is the property of the Customer. Guardiso acquires no rights to it and does not use it for its own purposes.

  4. The Customer grants Guardiso a licence limited to processing Customer Data solely for the purpose of providing the Service, including for the purpose of storing, presenting and processing it by artificial intelligence mechanisms at the Customer's instruction, generating reports and making backups. The licence expires upon deletion of the Customer Data in accordance with § 22.

  5. Customer Data is not used to train artificial intelligence models, either by Guardiso or by a sub-processor providing artificial intelligence services.

  6. Documents generated on the Platform for the Customer's needs may, once verified and approved by the Customer, be used by that Customer internally without time limitation, including after the Subscription has ended. This does not include the right to resell the Guardiso content library or to build a competing product on its basis.

  7. A creation arising without a creative human contribution is not a work within the meaning of copyright law. The parties assume that in respect of materials prepared solely by artificial intelligence mechanisms neither party holds economic copyright, which does not limit the Customer's right described in paragraph 6.


§ 19. Confidentiality

  1. The parties undertake to keep confidential information obtained in connection with the performance of the Agreement, in particular information about safeguards, about vulnerabilities, about incidents, about commercial terms and about data collected on the Platform.

  2. The confidentiality obligation does not cover information that is publicly available without breach of the Agreement, was known to a party before it was received, was obtained from a third party entitled to disclose it, or the disclosure of which is required by a mandatory provision of law or by a decision of a competent authority. In the last case, the disclosing party notifies the other party before disclosure, unless the law prohibits this.

  3. The confidentiality obligation is binding for the duration of the Agreement and for three years after it ends.

  4. Guardiso may cite the Customer as a reference, giving only the Customer's name and trade mark, after obtaining the Customer's prior consent given in documentary form. Consent may be withdrawn at any time with effect for the future.


§ 20. Protection of personal data

  1. In respect of personal data collected in the Organisation, the Customer is the controller and Guardiso is the processor. The rules of processing are set out in the Data Processing Agreement, concluded in accordance with Article 28 of the General Data Protection Regulation.

  2. In respect of Users' personal data processed for the purposes of maintaining the Account, billing and contact, Guardiso is the controller. These rules are described in the Privacy Policy.

  3. Guardiso uses sub-processors, a complete list of which constitutes Annex No 2 to these Terms. The list is changed under the procedure provided for in the Data Processing Agreement.

  4. Data is stored in infrastructure located in the Republic of Poland, in the Warsaw region. The use of certain sub-processors may involve the transfer of data outside the European Economic Area, on the terms described in the Data Processing Agreement.

  5. The personal data of each Organisation is encrypted with a separate key assigned solely to that Organisation. The Customer may independently initiate key rotation on the Platform.

  6. Guardiso does not have standing access to Customer Data. Every access by Guardiso personnel requires a request stating the scope, the time and the justification, requires the Customer's consent, is limited in time and is recorded in an access log. The Customer may withdraw consent at any time. The details, including the emergency access procedure, are described in the Data Processing Agreement.


§ 21. Liability of the parties

  1. Guardiso is liable for non-performance or improper performance of the Agreement on the principles resulting from generally applicable provisions of law.

  2. In relation to a Customer who is not a Protected Customer, the following limitations apply:

    1. Guardiso's total liability under the Agreement is limited to the sum of the net fees paid by the Customer in the twelve months preceding the event giving rise to the claim;
    2. Guardiso is not liable for lost profits, for loss of reputation, for loss of anticipated savings or for indirect damage;
    3. Guardiso is not liable for the consequences of decisions taken by the Customer on the basis of materials generated on the Platform, if the Customer did not subject them to the verification referred to in § 3(3);
    4. Guardiso is not liable for the outcome of any audit, certification or inspection procedure conducted in relation to the Customer by a third party.
  3. The limitations described in paragraph 2 do not apply in relation to a Protected Customer. In relation to a Protected Customer, Guardiso is liable on general principles and on the principles of Chapter 5b of the Consumer Rights Act, and provisions not individually agreed with that Customer which would shape that Customer's rights and obligations in a manner contrary to good practice, grossly infringing that Customer's interests, are not binding on that Customer in accordance with Article 385¹ of the Civil Code, applied on the basis of Article 385⁵ of the Civil Code.

  4. No provision of these Terms excludes or limits liability for damage caused intentionally. A stipulation to the contrary would be invalid by operation of Article 473 § 2 of the Civil Code. Liability for personal injury is likewise not excluded, nor is liability the exclusion of which is impermissible under mandatory provisions of law.

  5. The Customer is liable for:

    1. the truthfulness and currency of the data provided on registration and on purchase, including invoicing details;
    2. the lawfulness of the Customer Data and the legal basis for its processing;
    3. securing Users' devices and accounts, in particular the electronic mail boxes used for signing in;
    4. the consequences of granting access to the Organisation to unauthorised persons.
  6. The Customer promptly notifies Guardiso of any suspicion of unauthorised access to the Account or to the Organisation, at security@guardiso.com. The same address serves for reporting vulnerabilities and security incidents and is indicated in the file published at https://guardiso.com/.well-known/security.txt.


§ 22. Termination of the Agreement, deletion of the Account and the fate of Customer Data

  1. The Customer may terminate the Agreement at any time, in the manner described in § 10(4). Termination of a paid Agreement takes effect at the end of the paid Billing Period.

  2. The Customer may request deletion of the Account and of the Organisation before the end of the paid Billing Period, by submitting a request to the electronic mail address indicated in § 1(2). Such a request does not give rise to a right to a refund of the fee for the Billing Period that has begun, unless the basis is withdrawal from the contract, a lack of conformity of the Service with the Agreement or another circumstance indicated in these Terms.

  3. The agreement for the provision of the free Service may be terminated by either party at any time, without giving a reason.

  4. Guardiso may terminate the Agreement with immediate effect solely for important reasons, which include:

    1. gross breach of the prohibition on supplying unlawful content or of the Acceptable Use Policy, despite a demand that has produced no effect;
    2. conduct threatening the security of other Customers' data or the operational continuity of the Platform;
    3. failure to settle arrears within the time limit indicated in § 13(6);
    4. provision of untrue data material to the conclusion of the Agreement or to the issuing of an invoice, despite a demand for rectification that has produced no effect;
    5. a final ruling of a competent authority ordering the Service to the Customer to cease.
  5. After the Agreement ends, Customer Data remains available for thirty days. During that time:

    1. the Customer may independently download documents and registers using the export functions available on the Platform;
    2. at a request submitted within that period, Guardiso provides the Customer with a copy of the Customer Data in a commonly used machine-readable format, free of charge and on one occasion, within fourteen days of receiving the request;
    3. the Customer has the choice between the return of the Customer Data and its deletion, in accordance with Article 28(3)(g) of the General Data Protection Regulation. The statement of choice is submitted within the same thirty-day period. The absence of a statement means the choice of deletion. The procedure is described in § 11 of the Data Processing Agreement and in the document "Service Exit and Data Portability Rules".
  6. Customer Data is permanently deleted from the production environment within fourteen days after the expiry of the period indicated in paragraph 5, that is at the latest on the forty-fourth day from the end of the Agreement. Database backups are created once a day and retained for seven days, after which they are overwritten in the normal cycle; Customer Data therefore disappears from backups no later than seven days after its deletion from the production environment, that is at the latest on the fifty-first day from the end of the Agreement. Until they are overwritten, the backups remain covered by the Data Processing Agreement and by the same safeguards as production data.

  7. Deletion of data does not cover documents the retention of which is required by provisions of law, in particular invoices and tax documentation, retained for the period resulting from those provisions.

  8. Termination of the Agreement does not affect obligations which by their nature continue longer, in particular the confidentiality obligation, the settlement of amounts due arising before termination and the provisions on liability, governing law and court jurisdiction.


§ 23. Order of precedence of documents

  1. The legal relationship between the parties is made up of the following documents. In the event of a conflict between them, the documents listed higher take precedence over the documents listed lower:

    1. a separate written agreement concluded individually with the Customer, including the order form and offer for the Enterprise Plan and the Partner Agreement concluded with a consultant — in respect of matters expressly regulated therein;
    2. the Data Processing Agreement — solely in respect of the protection of personal data;
    3. the Service Level Agreement — solely in respect of availability, response times, credits and data recovery, and solely to the extent that that document itself states that it applies to the Plan selected by the Customer;
    4. these Terms together with their annexes;
    5. the End User Licence Agreement — solely in respect of the scope of the licence and the rights to the content library;
    6. the Service Exit and Data Portability Rules — solely in respect of the download, release and deletion of Customer Data;
    7. the Acceptable Use Policy;
    8. the Price List and the Plan descriptions published on the website.
  2. The Privacy Policy is of an informational nature and does not create contractual obligations. It does not take part in the order of precedence described in paragraph 1.

  3. Mandatory provisions of law, including provisions protecting a Protected Customer, take precedence over each of the documents listed in paragraph 1. A provision less favourable to a Protected Customer than a provision of statute is not binding on that Customer.

  4. A provision of a document of lower precedence which extends the Customer's rights beyond a document of higher precedence remains effective.

  5. If a document of higher precedence is silent on a given matter, the document of lower precedence applies. To the extent that the Service Level Agreement does not apply to the Plan selected by the Customer, in matters of availability and support only § 3(5) to (7) of these Terms apply.


§ 24. Force majeure

  1. Neither party is liable for non-performance or improper performance of the Agreement to the extent that it is a consequence of force majeure, that is an external event which could not have been foreseen and which could not have been prevented.

  2. Force majeure is deemed to include in particular: a natural disaster, a state of emergency, acts of war, an act of terror, a general power failure, a widespread failure of telecommunications networks, an act of public authority preventing the provision of the Service, and a widespread failure of the infrastructure provider, provided that its effects could not have been removed by reasonable means.

  3. The party affected by force majeure notifies the other party promptly, indicating the cause and the anticipated duration of the impediment.

  4. If force majeure prevents the provision of the Service continuously for thirty days, either party may terminate the Agreement with immediate effect. Guardiso then refunds the fee for the unused part of the Billing Period.

  5. No fee is charged for the time during which the Service was unavailable as a result of force majeure. If it has already been collected, it is credited pro rata against the next Billing Period.


§ 25. Assignment of rights and obligations

  1. The Customer may not transfer the rights and obligations arising from the Agreement to a third party without the prior consent of Guardiso given in documentary form. Consent is not refused without a justified reason.

  2. The consent referred to in paragraph 1 is not required in the case of a transformation, merger or division of the Customer, if the legal successor assumes all of the Customer's rights and obligations. The Customer notifies Guardiso of such an event within fourteen days.

  3. Guardiso may transfer the rights and obligations arising from the Agreement to a third party in the case of a disposal of the business or of an organised part of it, or in the case of a change of legal form, in particular the transformation of a sole trader business into a commercial law company. Transfer of obligations requires the Customer's consent in accordance with the provisions of the Civil Code on assumption of debt.

  4. Guardiso notifies the Customer of its intention to transfer at least thirty days in advance, indicating the identity of the legal successor. A Customer who does not give consent may terminate the Agreement with effect as at the day preceding the transfer, with a refund of the fee for the unused part of the Billing Period.

  5. A change in Guardiso's legal form or a change in its designation does not affect the content of the Agreement or the Customer's rights.


§ 26. Amendments to these Terms

  1. Guardiso may amend these Terms solely for important reasons, which include:

    1. a change in generally applicable provisions of law or in their interpretation, affecting the content of the Agreement;
    2. the issuing of a court judgment or an administrative decision concerning the Service;
    3. a change in the scope of the Service, including the addition of a new function or Plan, or the withdrawal of a function on the terms described in § 12;
    4. a change in the manner of providing the Service for technical or security reasons;
    5. a change of sub-processor, in so far as it affects the manner of providing the Service;
    6. the need to remove ambiguities, clerical errors or inconsistencies in the content of these Terms, provided that this does not lead to a change in the scope of the parties' rights and obligations.
  2. Guardiso notifies the Customer of an amendment to these Terms at least thirty days before the day it enters into force, by electronic mail to the address of the Account Owner and by a message on the Platform. The notification covers the content of the amendments or a summary of the amendments, the reason for the amendment, the day of entry into force and information about the right under paragraph 4.

  3. An amendment to these Terms does not affect Agreements concluded before the day it enters into force to the extent that it would be less favourable for the Customer, until the end of the current Billing Period.

  4. A Customer who does not accept an amendment may terminate the Agreement by the day preceding the entry into force of the amendment, without incurring any costs on that account.

  5. In the event of a termination referred to in paragraph 4, Guardiso refunds the fee for the unused part of the Billing Period, in proportion to the number of days remaining until its end.

  6. Failure to terminate within the time limit indicated in paragraph 4 means acceptance of the amendment.

  7. A change in Guardiso's contact details, a change to Annex No 2 and the correction of an obvious clerical error do not constitute an amendment to these Terms within the meaning of paragraph 1 and are announced by publication of a new version of the document.


§ 27. Dispute resolution, governing law and competent court

  1. The parties will make every effort to resolve disputes arising from the Agreement amicably. Before bringing a matter before a court, a party notifies the other party of its claim in writing or by electronic mail, setting a period of not less than fourteen days for it to state its position.

  2. A Protected Customer may make use of out-of-court means of handling complaints and pursuing claims, in particular by:

    1. applying to the district or municipal consumer ombudsman (powiatowy lub miejski rzecznik konsumentów) for free assistance in the matter;
    2. applying to the provincial inspector of the Trade Inspection Authority (wojewódzki inspektor Inspekcji Handlowej) to initiate proceedings for the out-of-court resolution of a consumer dispute or for the matter to be heard by the permanent arbitration court at that inspectorate;
    3. using the assistance of a social organisation whose statutory tasks include consumer protection.
  3. The list of entities authorised to conduct proceedings for the out-of-court resolution of consumer disputes is maintained by the President of the Office of Competition and Consumer Protection (Prezes Urzędu Ochrony Konkurencji i Konsumentów) on the basis of the Polish Act of 23 September 2016 on the Out-of-Court Resolution of Consumer Disputes (ustawa o pozasądowym rozwiązywaniu sporów konsumenckich). The list is available on the website of that Office.

  4. The European online dispute resolution platform was discontinued with effect from 20 July 2025 on the basis of Regulation (EU) 2024/3228 of the European Parliament and of the Council and is no longer available. Guardiso does not refer to it.

  5. Use of out-of-court means of dispute resolution is voluntary and requires the consent of both parties.

  6. The Agreement is governed by Polish law. The choice of Polish law does not deprive a Protected Customer residing in another Member State of the European Union of the protection resulting from the mandatory provisions of the law of the country of that Customer's residence, in accordance with Article 6 of Regulation (EC) No 593/2008 of the European Parliament and of the Council on the law applicable to contractual obligations.

  7. The competent court for disputes with a Customer who is not a Protected Customer is the common court having local jurisdiction over the registered seat of Guardiso.

  8. For disputes with a Protected Customer, court jurisdiction is determined according to the general provisions. Guardiso does not stipulate contractual jurisdiction in this respect.


§ 28. Contact details and final provisions

  1. Contact details:
MatterChannel
All matters covered by these Terms, complaints, withdrawal from the contract, terminationkontakt@guardiso.com
Vulnerabilities, security incidents, suspicion of unauthorised accesssecurity@guardiso.com
Written correspondenceGuardiso Michał Lewandowski, ulica Święty Marcin 29 lokal 8, 61-806 Poznań, Poland
Websitehttps://guardiso.com
  1. Guardiso holds a certificate of conformity of its information security management system with the ISO/IEC 27001 standard, issued by TÜV NORD, valid from 17 July 2026 to 16 July 2029. This information is of an informational nature and does not constitute an undertaking as to any particular level of Service availability.

  2. If any provision of these Terms proves to be invalid or ineffective, the remaining provisions remain in force. In place of an invalid provision, a provision of law applies and, in the absence of one, the provision closest to the intended economic purpose.

  3. These Terms are made available free of charge in a form that allows them to be downloaded, reproduced and recorded, at https://guardiso.com/terms.

  4. These Terms are drawn up in the Polish language. Should a translation into another language be made available, the Polish version prevails in the event of any discrepancy.

  5. The annexes forming an integral part of these Terms:

    1. Annex No 1 — Model withdrawal form;
    2. Annex No 2 — List of sub-processors.

Annex No 1 — Model withdrawal form

This form should be completed and returned only if you wish to withdraw from the Agreement. Use of this model is not obligatory. The model corresponds to the model constituting Annex No 2 to the Polish Act of 30 May 2014 on Consumer Rights (ustawa o prawach konsumenta).


Addressee:

Guardiso Michał Lewandowski ulica Święty Marcin 29 lokal 8 61-806 Poznań, Poland electronic mail address: kontakt@guardiso.com


I, the undersigned, hereby give notice of my withdrawal from the contract for the provision of the following service:

Name of the service: ................................................................ (for example: Guardiso subscription, Starter plan, monthly billing period)

Date of conclusion of the contract: ..............................................

Name of the organisation on the Guardiso website: ..............................................

Name and surname of the person making the statement: ..............................................

Business name and tax identification number: ..............................................

Address: ................................................................

Electronic mail address of the account: ..............................................

Bank account number for the refund, if the refund is to be made by means other than those used for payment: ................................................................


Date: ..............................

Signature (only if this form is sent on paper): ..............................


Note: if the person making the statement requested that performance of the service begin before the period for withdrawal from the contract expired, that person is obliged to pay for the performance rendered up to the moment of withdrawal, calculated in proportion to the scope of the performance rendered. The remaining part of the payment is refunded within fourteen days of the day the statement is received.


Annex No 2 — List of sub-processors

The list covers nine entities and is identical to Annex No 2 to the Data Processing Agreement and to the list in the Privacy Policy.

Sub-processorScopeCountry of processingNotes
Scaleway, S.A.S.Compute infrastructure, database, file storage, key managementPoland, Warsaw regionData does not leave the European Economic Area
Fakturownia sp. z o.o.Issuing and making available invoicesPolandPurchaser's invoicing details: name, address, tax identification number
Stripe Payments Europe, LimitedCard payment handling and subscription managementIreland, the Stripe group also in the United StatesBilling data. Guardiso neither sees nor stores payment card details — these go directly to the payment operator
Google Ireland Ltd. and Google LLCAuthentication of Users with a Google accountIreland, the Google group also in the United StatesMail address and first name from the Google account, solely where the User selects this sign-in method. Guardiso does not receive passwords
Plus Five Five, Inc. (the Resend service)Sending outgoing mail, including confirmations and sign-in linksUnited States, where the provider stores the data. The eu-west-1 region we selected governs only where mail is sent fromRecipient's mail address, first name and surname, content of the system message. The transfer is made on the basis of standard contractual clauses
Cloudflare, Inc.Network traffic handling, domain name system, protection against attacks and web application firewallUnited States, edge network nodes also in the European UnionInternet protocol addresses and request headers. Request content is not stored
Anthropic Ireland, LimitedLanguage model — Guardiso Assistant, generation of draft documents and analysesUnited States, the provider's servers. The party to the agreement is the company established in Dublin, IrelandData transferred solely at the Customer's instruction; it is not used to train models. The transfer is made on the basis of standard contractual clauses
OpenAI Ireland Ltd.Conversion of text into vectors for the purpose of searching the knowledge baseUnited States, processing outside the European Economic Area. The party to the agreement is the Irish companyFragments of text converted into numerical vectors; they are not used to train models. The transfer is made on the basis of standard contractual clauses
Superlative Enterprises Pty Ltd (the Have I Been Pwned service)Checking whether electronic mail addresses have appeared in known leaks of authentication credentialsUnited States, a Microsoft Azure data centre in the western part of the country. The entity's registered office is in the state of Queensland, AustraliaThe check does not cover passwords. The transfer is made on the basis of standard contractual clauses

The legal basis for each transfer of data outside the European Economic Area is indicated in Annex No 2 to the Data Processing Agreement.

The current list of sub-processors is published at https://guardiso.com/subprocessors. Guardiso notifies the Customer of any intention to add or change a sub-processor under the procedure provided for in the Data Processing Agreement, with at least thirty days' notice.