This is a comprehensive UK and EU-oriented website template, not a substitute for advice from a solicitor or data-protection professional. Replace every highlighted field with the company’s real legal name, company number, registered office, privacy email and service-specific information before launch.
Agreement and business details
These Terms govern access to the SecureFlowGroup website, account area and website-protection services. A contract is formed between the customer identified in an order form or checkout and the SecureFlowGroup legal entity identified above when SecureFlowGroup accepts the order, activates a paid plan or otherwise confirms access.
If an order form, statement of work or enterprise agreement conflicts with these Terms, the specifically agreed document takes priority for that subject. The Privacy Policy, Acceptable Use Policy and, where applicable, the Data Processing Addendum form part of the agreement.
The service
SecureFlowGroup provides tools and managed services for authorised website scanning, attack-surface monitoring, malware and script-change detection, firewall or bot controls, security alerts, reporting and incident support. Exact features, limits, service levels, response commitments and regions depend on the selected plan or order form.
Security findings are risk indicators based on available evidence and are not a guarantee that every vulnerability, compromise or attack will be found or prevented. SecureFlowGroup is not a substitute for secure development, patching, backups, access control, insurance or professional legal and compliance advice.
Accounts and authority
Account users must be at least 18 years old, have legal capacity to enter the agreement and be authorised to act for the customer. The customer is responsible for all authorised users, accurate account details, strong credentials, multi-factor authentication where available and prompt removal of access when a user no longer needs it.
Customers may only scan, monitor or test domains, applications, infrastructure and accounts they own or are expressly authorised to assess. SecureFlowGroup may request evidence of authority and may refuse or stop activity that could affect a third party or create legal, operational or safety risk.
Orders, subscriptions and payment
Prices, currencies, included usage, billing frequency and taxes are shown at checkout or in the order form. Unless stated otherwise, subscriptions renew automatically for the same billing period until cancelled. Customers authorise SecureFlowGroup and its payment provider to collect fees when due.
Usage above plan limits may be blocked, throttled or charged at published or agreed rates. Fees are normally non-refundable except where the agreement, a service credit, an order form or mandatory law says otherwise. Overdue amounts may result in restricted access after reasonable notice.
SecureFlowGroup may change future prices by giving advance notice. A price change does not apply retrospectively and will normally take effect at the next renewal.
Consumer protections
The service is primarily offered to businesses. If a customer contracts as a consumer, nothing in these Terms removes rights that cannot legally be excluded. UK consumers may have rights under the Consumer Rights Act 2015 and distance-contract rules, including rights relating to reasonable care and skill, conformity with description and cancellation in applicable circumstances.
Where a consumer asks for a service to begin during a statutory cancellation period, SecureFlowGroup may require express consent and may charge a proportionate amount for service already supplied if the consumer later cancels. Digital content or immediately performed services may have different cancellation rules. The checkout must clearly state the applicable right before an order is placed.
EEA consumers retain mandatory protections in their country of residence and may bring proceedings in the courts available under applicable consumer law.
Customer responsibilities
- Maintain lawful authority for every protected or assessed asset.
- Provide accurate scope, ownership, contact and emergency information.
- Keep software, plugins, dependencies, credentials and backups reasonably secure.
- Review alerts and implement appropriate remediation without unreasonable delay.
- Avoid submitting unnecessary personal data, secrets or production credentials.
- Comply with laws, contractual duties, hosting rules and third-party platform terms.
- Tell SecureFlowGroup promptly about suspected unauthorised access, account compromise or harmful service behaviour.
Security limitations and emergency action
Customers understand that testing and defensive action can create load, block legitimate traffic, alter availability or produce false positives. SecureFlowGroup uses reasonable safeguards, but customers should maintain backups, recovery plans, maintenance windows and emergency contacts.
SecureFlowGroup may immediately isolate traffic, pause a scan, disable an integration or restrict an account where reasonably necessary to protect systems, users or third parties. We will provide notice as soon as reasonably practical unless law, security or an active investigation prevents it.
Acceptable use
The service must not be used for unauthorised scanning, intrusion, credential attacks, malware delivery, surveillance, evasion, harassment, disruption, unlawful content or any activity prohibited by the Acceptable Use Policy. Attempting to bypass plan limits, security controls or technical restrictions is prohibited.
Intellectual property
SecureFlowGroup and its licensors retain all rights in the platform, website, software, documentation, detection logic, models, reports, branding and improvements. During the subscription, SecureFlowGroup grants the customer a limited, non-exclusive, non-transferable right to use the service for its internal authorised purposes.
The customer retains rights in customer content, websites and data. The customer grants SecureFlowGroup the rights reasonably necessary to host, process, scan, analyse and transmit that material to provide and secure the service. Feedback may be used to improve SecureFlowGroup without identifying the customer or disclosing confidential information.
Data protection and confidentiality
Each party must comply with applicable data-protection law. Where SecureFlowGroup processes personal data for the customer, the Data Processing Addendum applies. Each party must protect the other’s confidential information using reasonable care and may use it only for the agreement, legal compliance, professional advice or approved support.
Confidentiality does not cover information lawfully known without restriction, made public without breach, independently developed or lawfully received from another source.
Availability, changes and support
SecureFlowGroup aims to provide reliable service but does not promise uninterrupted availability unless a written service-level agreement says otherwise. Maintenance, emergency security work, internet failures, third-party outages, customer configuration and events outside reasonable control may affect service.
We may update features, interfaces, detection methods and limits to improve security, comply with law or maintain the service. We will give reasonable notice of a material reduction to a paid core feature where practical.
Suspension and termination
A customer may cancel through the account area or the method stated in the order. Cancellation normally stops renewal and access continues until the end of the paid billing period unless the order says otherwise.
Either party may terminate for a serious breach that is not remedied within a reasonable period after notice, or immediately where the breach cannot be remedied, payment failure persists, insolvency occurs, use is unlawful, or continued service creates material security or legal risk.
After termination, access ends and customer data is deleted or returned according to the agreement and Data Processing Addendum. Provisions intended to survive—including payment, confidentiality, intellectual property, liability and dispute terms—continue.
Liability
Nothing excludes liability that cannot lawfully be excluded, including liability for death or personal injury caused by negligence, fraud or fraudulent misrepresentation, or mandatory consumer rights.
Subject to that, neither party is liable for indirect or consequential loss, loss of profit, revenue, business, goodwill, anticipated savings or data, except where expressly agreed. SecureFlowGroup’s aggregate liability arising from the service should be set in the order form; if no amount is stated, the template default is the fees paid or payable for the affected service during the twelve months before the event giving rise to the claim.
The liability wording must be reviewed by a UK solicitor for the actual business model, insurance cover, customer type and service risk before publication.
Changes, governing law and disputes
SecureFlowGroup may update these Terms for legal, security, operational or product reasons. Material changes will be notified in advance where reasonably possible. Continued use after the effective date means the updated Terms apply, unless mandatory law requires fresh consent.
For business customers, the agreement is governed by the law of England and Wales and the courts of England and Wales have exclusive jurisdiction, unless the order form says otherwise. Consumers retain any mandatory right to rely on the law and courts of their home country.
Before court proceedings, the parties should try in good faith to resolve the dispute through written notice and a reasonable escalation period, except where urgent injunctive relief is needed.
Contact
Legal notices must be sent to [LEGAL EMAIL] and by post to [REGISTERED OFFICE]. Customer support questions can be submitted through the contact page.