LEGAL

DarkoniX Terms of Service

1. Agreement and Acceptance

These Terms of Service apply to services provided by DarkoniX Limited. A binding agreement is formed when a client confirms acceptance of a Statement of Work issued by DarkoniX, including acceptance by email. The Statement of Work and these Terms of Service together form the agreement between DarkoniX and the client. If there is a conflict between the Statement of Work and these Terms, the Statement of Work will take priority for the relevant engagement.

2. Cancellation and Refunds

Cancellation terms apply once a Statement of Work has been accepted. Acceptance authorises DarkoniX to commence the engagement, and fees are payable in full once accepted. Once work has commenced, fees are non-refundable unless required by law or otherwise agreed in writing. Where delivery has materially failed to align with the agreed Statement of Work, DarkoniX may, at its discretion, offer reasonable re-performance, credit or another appropriate remedy.

3. Payment Terms

Invoices are issued upon acceptance of the Statement of Work. Payment is due within thirty days of the invoice date. Late payments may incur interest at eight percent per annum above the Bank of England base rate, calculated daily from the due date until payment is received. DarkoniX reserves the right to suspend delivery where invoices remain unpaid.

4. Service Limitations and No Guarantee

DarkoniX services are external and point-in-time assessments. Unless explicitly stated in writing, services do not include internal testing, continuous monitoring, remediation, incident response or compliance certification. DarkoniX does not guarantee that systems will not be compromised, breached or misused following an assessment. Findings represent observable conditions at the time of assessment only and may change over time.

5. Responsibility for Remediation and Risk Management

Clients retain full responsibility for security controls and system configuration, remediation decisions and implementation, ongoing risk management and monitoring, and incident management and reporting. DarkoniX provides independent assessment findings and recommendations to support organisational decision-making. Responsibility for security operations and risk management remains with the client.

6. Liability and Indemnity

To the maximum extent permitted by law, DarkoniX’s total aggregate liability arising from an engagement is limited to the fees paid for the relevant engagement. DarkoniX is not liable for indirect, consequential, special or incidental losses, including loss of profit, revenue, business, anticipated savings, goodwill or opportunity. The client will indemnify DarkoniX against third-party claims arising from misuse, alteration, unauthorised disclosure or commercial exploitation of assessment outputs, or failure to act on findings, except to the extent caused by DarkoniX’s negligence, wilful misconduct or breach of these Terms. Nothing excludes or limits liability for fraud, death or personal injury caused by negligence, or any liability that cannot legally be excluded or limited.

7. Confidentiality

All assessment outputs, findings and client-specific information are confidential. DarkoniX will not disclose client findings to third parties without written consent, unless disclosure is required by law or by a regulator. Clients may use assessment outputs internally for operational, technical and leadership purposes. Clients may reference that an independent external assessment has been commissioned without disclosing specific findings.

8. Data Protection

The parties’ roles under UK GDPR depend on the nature of the processing. Where DarkoniX processes personal data on the client’s documented instructions to deliver agreed services, the client acts as data controller and DarkoniX acts as data processor. DarkoniX may act as an independent data controller for personal data it processes for its own legal, regulatory, security, compliance and business-record purposes. DarkoniX will process only the personal data reasonably necessary to deliver agreed services and will apply appropriate technical and organisational safeguards. Assessment data is retained for up to twelve months unless a different period is agreed in writing. A data processing agreement is available on request where required.

9. Risk and Sensitive Findings

Findings that indicate elevated security risk or potential exposure will be communicated appropriately and with discretion. Clients retain full responsibility for risk decisions, escalation and any actions required following delivery of findings.

10. Intellectual Property

All assessment materials remain the intellectual property of DarkoniX. Clients are granted a non-transferable licence to use and share assessment outputs internally within their organisation for operational, technical and decision-making purposes. Clients may share assessment outputs, or extracts from them, with regulators, insurers, auditors or professional partners where this supports assurance or improvement, provided the materials are not altered, publicly published or represented as endorsements. Assessment materials may not be resold, commercially exploited or publicly republished without prior written permission from DarkoniX.

11. Governing Law

These Terms of Service and all related agreements are governed by the laws of England and Wales. Any disputes will first be addressed through good-faith discussion. If unresolved, disputes will be subject to the exclusive jurisdiction of the courts of England and Wales.