Subscription Terms (SMB)
Online subscription — Free / TPE / PME / ETI plans
Version 1.0.0 · Last updated on 12 August 2026
Subscription Terms
These Subscription Terms (the “Terms”) govern access to and use of the CISAPP platform by Customers subscribing online without a separately negotiated agreement. They are entered into exclusively between professionals within the meaning of French law and exclude any consumer relationship. The French version of these Terms (Conditions Générales d'Abonnement) prevails in case of discrepancy.
PREAMBLE
CISAPP SAS, a French société par actions simplifiée with share capital of 6,000 euros, whose registered office is located at 28 rue Descartes, 59000 Lille, France, registered with the Lille Métropole Trade and Companies Register under number 108 189 325, represented by its Chief Executive Officer (Directeur général) (the “Provider”), publishes and operates a Software-as-a-Service (SaaS) platform designed for companies wishing to map, evaluate and manage the risks associated with their suppliers and service providers (the “Platform”). The Provider's intra-Community VAT number is FR70108189325.
The Provider offers Customers access to the Platform under online subscription plans (including a free plan, paid plans and, where applicable, a trial period).
The Customer represents that it is a professional acting for purposes within the scope of its commercial, industrial, craft, professional or agricultural activity. The Service is not intended for consumers. By subscribing, the Customer expressly acknowledges acting in a professional capacity.
These Terms are accepted by the Customer upon online subscription by an affirmative action (check-box or equivalent). Such acceptance constitutes an electronic signature within the meaning of Article 1366 of the French Civil Code. No subscription is possible without prior acceptance.
Article 1 — Definitions
In these Terms, the following capitalised terms have the meaning set out below:
- “Affiliate” means any entity controlling, controlled by, or under common control with a Party, within the meaning of Article L. 233-3 of the French Commercial Code.
- “Order Form” means any document, online subscription screen or electronic message reflecting the Customer's order (selected plan, term, number of users, price).
- “Customer” means the legal entity in whose name the subscription is taken out.
- “Customer Data” means all data, information, documents and content entered, imported or generated by the Customer or its Users in the Platform.
- “Supplier Data” means data relating to the Customer's suppliers and service providers, entered or collected through the Platform (corporate name, sector, size, risk indicators, documents, contacts, etc.).
- “Pooled Data” means Supplier Data relating to legal entities only (excluding any personal data) that may be aggregated, anonymised at source, and reused by the Provider in accordance with Article 9.
- “Plan” means the commercial offering subscribed to by the Customer (e.g. Free, TPE, PME, ETI), as described on the Site or in the subscription screen.
- “Platform” or “Service” means the CISAPP software platform, its interfaces, functionalities and associated documentation, accessible at app.cisapp.eu.
- “Site” means the Provider's website accessible at www.cisapp.eu.
- “User” means any individual authorised by the Customer to access the Platform through a named account.
- “DPA” means the Data Processing Agreement entered into between the Parties under Article 28 GDPR, annexed to these Terms.
Article 2 — Purpose
These Terms set out the conditions under which the Provider grants the Customer a non-exclusive, non-transferable and limited right to access the Platform, together with associated services (support, updates, hosting).
These Terms and their annexes constitute the entire agreement between the Parties and prevail over any prior document. In case of conflict between the Terms and the annexes, the Terms prevail, except for provisions of the DPA on data protection, which prevail over any contrary provision.
Article 3 — Sign-up and account creation
Subscription to the Service requires the creation of an account in the Customer's name by a duly authorised individual. The Customer warrants the accuracy of the information provided at sign-up and undertakes to keep it up to date.
The Customer is solely responsible for the confidentiality of credentials and passwords assigned to its Users. Any action carried out from an account is deemed performed by the Customer. The Customer shall notify the Provider without delay of any compromise, loss or unauthorised use of its credentials.
The Provider reserves the right to refuse any sign-up that does not meet the criteria of these Terms, without having to provide reasons.
Article 4 — The Service and plans
The Provider makes the Platform available to the Customer in accordance with the functionalities described on the Site and the Plan subscribed to. Technical features, functional scope, number of Users and number of administered suppliers vary depending on the Plan.
The Provider may evolve the Platform at any time as part of continuous improvement, including by adding, modifying or removing functionalities. The Provider will use its best efforts not to materially degrade core functionalities subscribed to by the Customer. Should an essential functionality be removed, the Provider will inform the Customer with reasonable notice and propose, where applicable, a replacement functionality.
4.1 Free plan
The Provider offers a Free plan granting access to a restricted set of functionalities, for trial and discovery purposes. The Free plan is provided “as is” and “as available”. It carries no service level commitment, no guaranteed support and no maintenance or continuity obligation. The Provider may suspend, modify or discontinue the Free plan at any time, without notice and without compensation.
Any account inactive on the Free plan for a continuous period of ninety (90) days may be suspended and then deleted after notice sent by email with a fifteen (15) day grace period.
4.2 Trial period
The Provider may offer a free trial period of fourteen (14) days on paid Plans, granting access to all features of the corresponding Plan. At the end of the trial, the subscription is activated only if the Customer effectively subscribes to a paid Plan. No payment card is required to obtain the trial.
Only one trial period may be granted per Customer. The Provider reserves the right to refuse a trial to a Customer who has already benefited from a previous trial.
Article 5 — Financial terms
5.1 Prices
Prices of paid Plans are set out on the Site, in euros and exclusive of VAT. VAT and any other applicable tax are added at the rate in force on the invoicing date. Prices may be revised by the Provider, subject to at least thirty (30) days' notice prior to the renewal date of the subscription. Failing acceptance by the Customer, the Customer remains free to terminate the subscription in accordance with Article 7.
5.2 Payment
Subscriptions are paid monthly, in advance, by automatic debit via credit card or SEPA direct debit, unless an alternative method has been expressly accepted by the Provider. The Customer authorises the Provider (or its payment processor) to debit the registered payment method at each due date.
Invoices are issued electronically and made available in the Customer's account area. The Customer is deemed to have received them on their issue date.
5.3 Late payment
In the event of default, late payment interest is payable as of right, without notice, at the European Central Bank's most recent main refinancing operation rate plus ten (10) percentage points. A fixed indemnity for recovery costs of forty (40) euros is also payable, in accordance with Articles L. 441-10 and D. 441-5 of the French Commercial Code, without prejudice to the Provider's right to claim additional compensation upon evidence.
In case of persistent non-payment after formal notice remaining unanswered for fifteen (15) days, the Provider may suspend access to the Platform and/or terminate the subscription at the Customer's fault, without prejudice to any other rights and remedies.
Article 6 — Term and renewal
The subscription is concluded for an initial term of one (1) month from the subscription date. It is tacitly renewed for successive one (1) month periods, unless terminated by either Party in accordance with Article 7.
Unless otherwise stipulated in the Order Form, no minimum commitment longer than one month is imposed.
Article 7 — Termination
7.1 Termination by the Customer
The Customer may terminate its subscription at any time from its account area, with effect at the end of the current monthly period. No refund is due for started periods.
7.2 Termination by the Provider
The Provider may terminate the subscription at any time, subject to thirty (30) days' notice, for any reasonable cause and in particular: evolution of the offering, commercial repositioning, or discontinuation of the Service. In such case, the Provider refunds pro rata temporis any amounts paid in advance for the period after the effective termination date.
7.3 Termination for material breach
Each Party may terminate the contract as of right, without compensation, in the event of a material breach by the other Party of its essential obligations, remaining uncured fifteen (15) days after formal notice sent by registered post or by electronic means with acknowledgement of receipt. Material breaches include: non-payment, violation of the Platform usage rules set out in Article 10, or any fraudulent or unlawful use or use compromising the security of the Platform.
The Provider may, without notice, immediately suspend access in case of a proven and imminent threat to the security, integrity or availability of the Platform, or further to an instruction from a competent authority. Suspension is notified to the Customer as soon as possible.
7.4 Effects of termination
Upon termination, for any reason:
- Access to the Platform is disabled with effect from the termination date.
- The Customer may, within thirty (30) days of termination, download Customer Data via the export functionalities provided for that purpose.
- After this period, the Provider deletes Customer Data under the conditions set out in the DPA, subject to legal retention obligations.
- Pooled Data aggregated before termination may continue to be used by the Provider in accordance with Article 9.
Article 8 — Personal data
Processing of personal data carried out by the Parties under these Terms is governed by the Data Processing Agreement (DPA) annexed hereto. In case of conflict, the DPA prevails over these Terms in relation to data protection.
The Privacy Policy applicable to processing carried out by the Provider as a controller (Site visitors, prospects, marketing) is accessible online and forms an integral part of the relationship between the Parties.
Article 9 — Data ownership, licence and pooling
9.1 Customer Data
The Customer retains full ownership and control over Customer Data. The Customer warrants its accuracy, lawfulness and the absence of any prejudice to third parties.
The Customer grants the Provider, for the term of the subscription and solely for the purpose of providing the Service, a non-exclusive and non-transferable right to host, reproduce, display, technically modify and communicate Customer Data. This licence is strictly limited to the purposes of the Service.
9.2 Pooled Data (data-pooling clause)
The Customer acknowledges and expressly accepts that the Platform relies on a model of pooling of company data relating to suppliers and service providers. Such pooling is an essential feature of the Service and is a condition of the subscription. Accordingly:
- Scope. Pooling concerns only data relating to legal entities (corporate name, sector, size, country, aggregated risk indicators, presence or absence of public certifications, etc.) entered into or produced in the Platform. It expressly excludes any personal data, any confidential document uploaded, any contract or any element identifying the source of the information.
- Mandatory nature. Pooling is a condition of access to the Service and cannot be opted out of.
- Source anonymisation. The Provider undertakes that Pooled Data is aggregated in a way that no third-party Customer can identify the source of an individual data point. Any output is provided in statistical, aggregated or anonymised form.
- Provider's rights. The Customer grants the Provider, on a free-of-charge, worldwide, irrevocable and perpetual basis (including after termination), the right to use, reproduce, modify, aggregate and exploit the Pooled Data for the purposes of enriching the Platform, producing market indicators and reference points, sharing such aggregated indicators with its other Customers, and more generally any purpose compatible with the Service.
- Customer warranties. The Customer warrants that it holds the necessary rights to communicate Pooled Data to the Provider under this Article and that no contrary confidentiality undertaking prevents pooling.
- Effect of termination. Pooled Data aggregated before termination remains integrated into the indicators and reference points and cannot, in practice, be withdrawn from the aggregated set. This irreversibility is expressly accepted by the Customer.
The Customer acknowledges having read and accepted the nature and scope of the pooling described in this Article.
9.3 Provider's intellectual property
The Platform, its source code, interfaces, databases, documentation and all of its components remain the exclusive property of the Provider and/or its partners. No intellectual property right is transferred to the Customer beyond the limited right of use granted hereunder.
The Customer in particular undertakes not to: (i) reproduce, modify, translate, adapt, decompile or disassemble the Platform (except within the limits allowed by law); (ii) attempt to extract or reconstitute the underlying database; (iii) circumvent technical protection measures; (iv) resell, lease, sub-licence or make available to third parties access to the Platform; (v) use the Platform to develop a competing service.
Article 10 — Customer obligations and usage rules
10.1 General obligations
The Customer undertakes to:
- Use the Platform in accordance with these Terms, the DPA and the documentation.
- Designate a primary account administrator responsible for User management and access security.
- Ensure that Users comply with these Terms and be responsible for its Users' acts as if they were its own.
- Keep its billing and contact information up to date.
- Maintain an internet connection, a recent browser and hardware/software environment compatible with the Platform.
- Notify the Provider without delay of any anomaly or security incident.
The Customer is responsible for the use made of the Platform from its accounts and for the actions of its Users. The Customer ensures that its Users are aware of and comply with the rules set out in sections 10.2 to 10.7 below.
10.2 Platform security
The following are in particular prohibited:
- Attempting to circumvent, neutralise, disable or otherwise compromise the security measures or access controls of the Platform.
- Intentionally testing the security of the Platform or conducting a penetration test without prior written consent from the Provider (responsible disclosure programme, contractual audit).
- Using the Platform to store, transmit or execute malicious code, viruses, trojans, ransomware or any other harmful software.
- Attempting to access accounts, data or features for which the User is not authorised.
- Interfering with or disrupting the normal operation of the Platform, the infrastructure, the networks or third-party services used by the Provider.
10.3 Respect for third-party rights
The following are in particular prohibited:
- Uploading or distributing through the Platform any unlawful, defamatory, abusive, infringing content or content infringing third-party rights, in particular intellectual property, privacy, image rights, trade secrets, or personal data protection.
- Importing personal data in breach of the GDPR or any other applicable data-protection law.
- Importing special categories of data (Article 9 GDPR) or data relating to criminal offences (Article 10 GDPR) without the Provider's prior express consent.
- Using the Platform to send unsolicited communications (spam), chain messages or any bulk mailing not compliant with applicable rules.
10.4 Competing commercial use
Without prejudice to Article 9.3 (Provider's intellectual property), the Customer further undertakes not to:
- Use the Platform to design, develop or operate a competing service.
- Perform a functional, technical or performance comparison (benchmark) of the Platform and publish the results without prior written consent from the Provider.
10.5 Use of resources
The following are in particular prohibited:
- Performing large-scale automated operations (scraping, bots, looping requests) that are not expressly enabled by the Platform's features or documented API.
- Consuming the Platform's resources in a manner manifestly disproportionate compared to a Customer's normal use or the contractual limits of the subscribed Plan.
- Maintaining an artificially high number of User accounts or otherwise circumventing the contractual limits of the subscribed Plan.
10.6 Unlawful activities
The Customer undertakes not to use the Platform:
- For the commission, preparation or facilitation of a criminal offence.
- For activities contravening applicable international sanctions, anti-money laundering rules or counter-terrorism financing rules.
10.7 User accounts and responsible disclosure
Each User account is strictly named. It is prohibited to share credentials between multiple persons, to transfer access to an account or to use an account created in the name of another person. Any compromise or suspicion of compromise must be reported without delay to the Provider at security@cisapp.eu.
Any person identifying a security vulnerability, a defect or an abnormal behaviour of the Platform is invited to report it to the Provider at security@cisapp.eu, in compliance with responsible disclosure principles: no exfiltration of data beyond what is necessary to demonstrate the vulnerability, no public disclosure before the Provider has been able to remediate the vulnerability, no harm to the availability or integrity of other Customers' data. The Provider acknowledges receipt of the report as soon as possible and cooperates in good faith to assess, fix and, where appropriate, acknowledge the reporter.
10.8 Consequences of a breach
Without prejudice to Article 7.3, in case of a confirmed or suspected breach of the usage rules set out in this Article 10, the Provider may, depending on the gravity:
- Issue a formal warning to the Customer and request the immediate cessation of the disputed behaviour.
- Temporarily limit the available functionalities.
- Suspend, without notice where applicable, access to the affected User(s) or to the entire Customer account where the security, integrity or availability of the Platform so requires.
- Terminate the contract under the conditions provided for in Article 7.3.
- Retain the evidence necessary for any future enforcement or proceedings and report the facts to the competent authorities where they may constitute an offence.
Article 11 — Support and availability
The Service is provided on a best-effort basis, with no committed availability percentage and no service credits. The Provider operates continuous monitoring of the Platform, publishes incidents and maintenance operations on a public status page, and provides functional and technical support during Business Hours — Monday to Friday, 9:00 a.m. to 6:00 p.m. (Paris time), excluding French public holidays — within reasonable timeframes proportionate to the severity of the ticket.
The Provider performs regular backups of Customer Data and periodic restore tests. No Recovery Point Objective (RPO) or Recovery Time Objective (RTO) is committed under these Terms.
Customers seeking a contractual availability commitment (e.g. 99.9%), priority support, committed continuity objectives or service credits are invited to enter into a negotiated Master Services Agreement with the Provider's sales team (Enterprise tier).
Article 12 — Confidentiality
Each Party undertakes to keep strictly confidential the non-public information of the other Party to which it has access in the performance of these Terms, and to use such information only for the purposes of performing the contract. This obligation remains in force for five (5) years from the end of the contractual relationship.
Information is not covered by this obligation if: (i) it was already known to the receiving Party before disclosure; (ii) it is public or has fallen into the public domain without the fault of the receiving Party; (iii) it was lawfully received from a third party without confidentiality undertaking; (iv) it was independently developed; or (v) its disclosure is required by law or a competent authority.
Article 13 — Warranties and limitation of liability
13.1 Provider's warranties
The Provider undertakes to perform its obligations in accordance with the standards of the SaaS profession. This is a best-efforts obligation.
The Provider does not warrant that the Platform will be error-free or that its operation will be uninterrupted. The Provider does not warrant the fitness of the Platform for a particular purpose not described in the documentation.
13.2 Limitation of liability
The Provider is liable for direct, foreseeable damage reasonably connected to a breach of its contractual obligations. Its liability, all causes combined over the entire term of the contract, shall not exceed the total amount excluding VAT effectively paid by the Customer over the twelve (12) months preceding the event giving rise to liability. For the Free plan and the trial period, the Provider's liability shall not exceed one hundred (100) euros.
In no event shall the Provider be liable for indirect, immaterial or consequential damages, including in particular: loss of profits, loss of revenue, loss of customers, loss of reputation, loss of data (except in case of breach by the Provider of its contractual backup obligations), reputational harm, or commercial loss.
The limitations of this Article do not apply in case of gross negligence or wilful misconduct of the Provider, bodily harm, or any liability that cannot be limited under mandatory law.
13.3 Customer's indemnity
The Customer indemnifies the Provider against any third-party claim resulting from a non-compliant use of the Platform, a breach of these Terms or a breach of its own obligations, in particular in matters of data protection or intellectual property.
Article 14 — Force majeure
Neither Party shall be liable for any failure resulting from an event of force majeure within the meaning of Article 1218 of the French Civil Code or any equivalent event: a major cyberattack suffered despite reasonable measures, a major failure of a telecommunications or energy provider, decision of a public authority, pandemic, war, riot, sabotage, natural disaster. The affected Party shall inform the other Party as soon as possible and the Parties shall use good-faith efforts to mitigate the consequences. If the impediment persists more than sixty (60) days, either Party may terminate the contract without compensation.
Article 15 — Subcontracting
The Provider may engage subcontractors for the performance of all or part of the services, in accordance with the GDPR and the DPA. The list of subcontractors is maintained and may be communicated upon request.
Article 16 — Regulatory evolution
The Parties acknowledge that the Provider's activity may be subject to significant legislative or regulatory developments, including in cybersecurity (NIS2), digital operational resilience (DORA) or artificial intelligence (EU AI Act). In case of significant regulatory evolution impacting the Service or these Terms, the Provider may amend these Terms and their annexes or supplement them with specific addenda (notably NIS2 Addendum, DORA Addendum, AI Addendum). The Provider informs the Customer of any amendment at least thirty (30) days before its entry into force. Failing acceptance, the Customer may terminate the subscription under Article 7.
Article 17 — Changes to the Terms
The Provider reserves the right to amend these Terms and their annexes at any time. Any material amendment is notified to the Customer by electronic means at least thirty (30) days before its entry into force. Continued use of the Service after the entry into force of the amendments constitutes acceptance of the new version. Failing acceptance, the Customer may terminate the subscription under Article 7.
Article 18 — Assignment
The Customer may not assign its rights and obligations under these Terms without the prior written consent of the Provider. The Provider may freely assign the contract, in whole or in part, to any Affiliate or to a third party in the context of a reorganisation, merger, acquisition or business transfer, provided that the assignee assumes all obligations towards the Customer.
Article 19 — Notices
Unless otherwise provided, any notice between the Parties is validly given by electronic means to the addresses indicated in the Customer's account area. Customer notices relating to termination or claims shall be addressed to legal@cisapp.eu. Notices relating to data protection shall be addressed to privacy@cisapp.eu.
Article 20 — Governing law and jurisdiction
These Terms are governed by French law. Any dispute relating to their formation, interpretation or performance shall, failing amicable resolution within sixty (60) days of the first written complaint, fall within the exclusive jurisdiction of the courts within the jurisdiction of the Provider's registered office, notwithstanding plurality of defendants or warranty claims.
Article 21 — Miscellaneous
21.1 Severability
If any provision of these Terms is held void or unenforceable, the other provisions shall remain in full force. The Parties shall use their best efforts to replace the invalid provision by a valid one with the closest economic effect.
21.2 No waiver
A Party's failure to invoke a breach of the other Party shall not be construed as a waiver of the right to invoke such breach in the future.
21.3 Entire agreement
These Terms and their annexes (DPA, Privacy Policy) constitute the entire agreement between the Parties and supersede any previous agreement, communication or document on the same subject.
21.4 Independence of the Parties
The Parties remain independent. These Terms do not create between them any agency, joint venture or employment relationship.
21.5 Evidence
The Parties agree that electronic records kept by the Provider (access logs, subscription screens, invoices, emails exchanged from contractual addresses) are admissible as evidence, are conclusive between the Parties and shall be enforceable in the same way and with the same evidentiary value as any written document.
Last update: 12 August 2026. Version: 1.0.0.