﻿---
title: "Terms of Service - CentralCSP"
description: "The terms governing your use of CentralCSP, the EU-hosted client-side security platform."
url: "https://centralcsp.com/en/legal/terms/"
lang: "en"
---

Legal

# Terms of Service - CentralCSP

Last updated: August 9, 2026  Effective: September 13, 2026

## Preamble: Acceptance of Terms

These Terms of Service, including all documents, policies, and addenda incorporated by reference (collectively, the "Agreement" or "Terms"), form a legally binding contract between **CentralSaaS**, a _société par actions simplifiée_ incorporated under the laws of France, registered office at 1 Allée des Frênes, 38240 Meylan, France, registered with the _Registre du Commerce et des Sociétés_ of Grenoble under number **927 890 756**, operating the CentralCSP service ("CentralCSP", "we", "us", "our"), and the entity or individual creating an account or using the Services ("Customer", "you", "your").

By creating an account, clicking a button or checkbox indicating acceptance (for example "I Agree"), or using any part of the Service, you confirm that you have read, understood, and agree to be bound by this Agreement in its entirety. If you do not agree to all of its terms, you must not access or use the Service.

If you accept this Agreement on behalf of a company or other legal entity, you represent that you have authority to bind that entity, and "Customer", "you", and "your" refer to that entity. If you lack such authority, you must not accept this Agreement or use the Service.

The Service is offered exclusively to businesses and to professionals acting in the course of their trade, business, craft, or profession. By accepting this Agreement, you represent and warrant that you are acting for purposes falling within your trade, business, craft, or profession, and not as a consumer within the meaning of the preliminary article of the French _Code de la consommation_. If you do not meet this condition, you must not create an account or use the Service.

This Agreement expressly incorporates by reference the CentralCSP Privacy Policy and the CentralCSP Data Processing Agreement (DPA), each of which is an integral part of these Terms.

## 1\. Definitions

-   **Service(s)** means the web security and compliance tools and services provided by CentralCSP. This includes, without limitation, the CSP Scanner, CSP Evaluator, CSP Builder, the reporting endpoint (which collects all supported browser Reporting-API report types), event-based alerting, script inventory and vulnerability (CVE) detection, PCI DSS evidence generation, on-demand website security scanning, the hash and Subresource Integrity (SRI) calculators, the security-header checker, the CentralCSP browser extension, the API and MCP integrations, and any related websites (including centralcsp.com), software, documentation, and support. The definition also covers all updates, modifications, and new features introduced from time to time.
-   **Customer Data** means all electronic data submitted to or generated by the Service by or for the Customer. It comprises (a) data provided by the Customer, including website URLs, existing Content Security Policies, information entered into forms, and browser reports transmitted to the reporting endpoint; and (b) data generated for the Customer, such as analysis reports, security and compliance scores, script inventories, vulnerability assessments, alerts, PCI DSS evidence, and the recommended Content Security Policies produced by the CSP Builder.
-   **Personal Data** means information that constitutes "personal data", "personal information", or a similar term under applicable data protection laws, including the GDPR. This may include Authorized User account information (for example name and email) and personal data incidentally contained in browser reports (for example IP addresses or identifiers embedded in URLs).
-   **Authorized User(s)** means an individual (such as an employee, consultant, or contractor of the Customer) authorized by the Customer to use the Service under the rights granted to the Customer.
-   **Documentation** means the official user guides, articles, and technical or functional documentation for the Service provided by CentralCSP.
-   **Intellectual Property Rights** means all registered and unregistered rights under patent, copyright, trademark, trade secret, database, and other intellectual property laws anywhere in the world.
-   **Confidential Information** means non-public information disclosed by one party (the "Disclosing Party") to the other (the "Receiving Party") that is designated as confidential or that should reasonably be understood to be confidential. CentralCSP's Confidential Information includes the non-public aspects of the Service; the Customer's Confidential Information includes Customer Data.
-   **Order Form** means an ordering document or online order specifying the Service(s) to be provided, entered into between the Customer and CentralCSP, incorporating this Agreement by reference and detailing the subscription term, fees, and any usage parameters.
-   **Plan Limits** means the usage parameters applicable to the Customer's plan, including the maximum number of browser reports ingested per month, the maximum number of Authorized Users, and the maximum number of monitored websites, as published on the CentralCSP website or set out in the applicable Order Form.
-   **Third-Party Service** means any product, service, or destination operated by a party other than CentralCSP that the Customer elects to connect to the Service, including alert delivery channels (for example Slack, Microsoft Teams, PagerDuty, email, or a webhook endpoint) and any AI assistant or agent connected through the API or MCP integrations.
-   **SLA** means the CentralCSP Service Level Agreement, which sets out the availability commitment for the Services it covers and is negotiated and executed separately with Enterprise customers as an optional addition to their plan, incorporated into this Agreement by reference where agreed.

## 2\. The Service

### 2.1. License grant

Subject to the Customer's compliance with this Agreement and payment of all applicable fees, CentralCSP grants the Customer a limited, personal, non-exclusive, non-transferable, and non-sublicensable right to access and use the Service(s) and Documentation during the subscription term, solely for the Customer's internal business purposes and in accordance with any applicable Order Form. This Agreement grants a right to access and use the Service; it is not a sale of software or any underlying Intellectual Property Rights.

### 2.2. Acceptable use

The Customer shall not, and shall not permit any Authorized User or third party to:

-   Reverse engineer, decompile, disassemble, or otherwise attempt to discover the source code, structure, or algorithms of the Service, except to the extent this restriction is prohibited by applicable law.
-   Access or use the Service to monitor its availability or performance, or for benchmarking or competitive purposes, including to build a competing product or service.
-   Use the Service's scanning or analysis tools (for example the CSP Scanner or Evaluator, or on-demand scanning) on any website or digital property for which the Customer does not hold explicit, verifiable, and lawful authorization to conduct such security assessments. The Customer bears the burden of establishing that authorization, and shall retain evidence of it for the duration of the subscription term and for twelve (12) months thereafter. Breach of this obligation is a material breach and is grounds for immediate termination under Section 10.2.
-   Use the Service to store or transmit content that is infringing, libelous, or otherwise unlawful, or that violates third-party privacy rights.
-   Use the Service to transmit any viruses, worms, malicious code, or software intended to damage or alter a system or data.
-   Attempt to gain unauthorized access to the Service or to any accounts, systems, or networks connected to it.
-   Submit false, misleading, or malicious data (including fabricated browser or violation reports) with the intent to disrupt or degrade the Service or its analytical capabilities.
-   Exceed the Plan Limits, or circumvent or attempt to circumvent any technical measure applied under Section 4.1.

### 2.3. Service modifications, updates, and discontinuation

CentralCSP may modify, enhance, or update the Service(s) or any feature. We will make commercially reasonable efforts to ensure that such changes do not materially decrease the core functionality of the Service(s) purchased by the Customer during an active subscription term.

If CentralCSP discontinues the Service, or discontinues a feature that constitutes a material part of the Service(s) purchased by the Customer, during an active subscription term, CentralCSP will give the Customer at least thirty (30) days' prior written notice and will refund, on a pro-rata basis, any prepaid fees covering the period after the discontinuation takes effect. The Customer may terminate the affected subscription without penalty on receipt of such notice.

### 2.4. Customer's implementation

The Customer is solely responsible for the actions required to use the Service. This includes correctly configuring the reporting endpoint on its web properties and correctly deploying any Content Security Policies generated by the Service to its servers, headers, or infrastructure. CentralCSP provides tools and recommendations, but responsibility for implementation, testing, and validation rests with the Customer. CentralCSP is not responsible for damage arising from the Customer's incorrect or incomplete implementation of a policy.

### 2.5. Free trials and free tools

CentralCSP may offer free trials or free tools (such as the CSP Scanner, CSP Evaluator, CSP Hash Calculator, SRI Hash Calculator, Security Headers Scanner, Reporting-API Checker, and Compare tool). Any Service provided on a free basis is offered "AS IS", without warranty, support, or indemnification of any kind, and CentralCSP may modify, limit, or withdraw it at any time.

By submitting a URL, policy, or set of headers to a free tool, you represent that you own the corresponding website or digital property, or that you hold explicit, verifiable, and lawful authorization from its owner to have it analysed. CentralCSP may rate-limit, block, or log submissions to protect the Service and to investigate suspected unauthorized use.

Data you enter during a free trial is retained in accordance with our standard retention periods, as set out in the Privacy Policy and in Section 8 of the DPA.

### 2.6. Beta and preview features

CentralCSP may make features available on a beta, preview, early-access, or experimental basis ("Beta Features"). Beta Features are identified as such, are provided "AS IS" and without warranty, support, indemnity, or any availability commitment, and are excluded from the SLA. They may be changed, suspended, or withdrawn at any time and may be less reliable than generally available features. The Customer's use of a Beta Feature is voluntary and at its own risk, and the Customer should not use a Beta Feature in a production-critical workflow without independent validation. Information about Beta Features is CentralCSP's Confidential Information.

### 2.7. Third-Party Services

The Service allows the Customer to connect Third-Party Services. Any such connection is made at the Customer's election and under its own agreement with the provider of that Third-Party Service. CentralCSP does not control, endorse, or assume responsibility for any Third-Party Service, its availability, its security, or its handling of data transmitted to it. Where the Customer directs the Service to transmit Customer Data to a Third-Party Service, Section 5.4 and Section 6.4 apply. CentralCSP may suspend or disable an integration where it poses a security risk or where the provider of the Third-Party Service ceases to make it available.

### 2.8. Suspension

CentralCSP may suspend the Customer's or an Authorized User's access to the Service, in whole or in part, with notice where practicable, if: (a) the Customer materially breaches Section 2.2 (Acceptable Use); (b) the use poses a security risk to the Service, to CentralCSP's systems, or to others; (c) the use is unlawful or exposes CentralCSP to liability; (d) an invoiced amount is overdue as described in Section 4.3; or (e) the Customer materially or repeatedly exceeds the Plan Limits and does not resolve the excess after notice under Section 4.1. CentralCSP will limit any suspension in scope and duration to what is reasonably necessary and will restore access promptly once the cause is resolved. A suspension under this Section does not relieve the Customer of its payment obligations.

## 3\. Customer Obligations

### 3.1. Account security

The Customer is responsible for all activity under its account(s) and for keeping its passwords and credentials confidential and secure. The Customer shall notify CentralCSP promptly of any unauthorized use of its account or any known or suspected security breach.

### 3.2. Authorized Users

The Customer is responsible and liable for the acts and omissions of its Authorized Users. Any breach of this Agreement by an Authorized User is deemed a breach by the Customer.

### 3.3. Customer Data accuracy and legality

The Customer represents and warrants that it has obtained all rights, consents, and permissions required to provide and use the Customer Data with the Service, and that the Customer Data and its use will not violate any law or infringe any third-party rights.

### 3.4. Compliance with laws

The Customer shall use the Service in compliance with all applicable laws and regulations, including those relating to data privacy and the transmission of technical or personal data.

### 3.5. Sanctions and export control

The Customer represents and warrants that neither it, nor any of its Authorized Users, nor any party controlling or controlled by it, is subject to sanctions or listed on any restricted-party list maintained by the European Union, France, the United Nations, the United Kingdom, or the United States, and that it is not located in, or ordinarily resident in, a territory subject to comprehensive sanctions. The Customer shall not access, use, export, or re-export the Service in violation of any applicable export-control or sanctions law. CentralCSP may suspend or terminate the Service immediately if this Section is or becomes untrue.

## 4\. Fees, Payment, and Subscription

### 4.1. Plans, fees, and usage

The Customer shall pay all fees in the applicable Order Form or as stated on the CentralCSP website. Fees are determined by the plan purchased and its Plan Limits, and are not calculated on metered usage below those limits. Except as otherwise specified, payment obligations are non-cancelable and fees paid are non-refundable.

The Plan Limits are binding. CentralCSP may reject, discard, or decline to ingest browser reports submitted in excess of the applicable monthly limit, and may apply rate limits or other technical measures to enforce the Plan Limits, in each case without liability and without any reduction in fees. Where the Customer's requirements exceed its Plan Limits, CentralCSP will notify the Customer and may require an upgrade to a plan with sufficient capacity as a condition of continued ingestion. Nothing in this Section obliges CentralCSP to retain, process, or restore data that was not ingested.

### 4.2. Billing

Fees are invoiced in advance in accordance with the Order Form. The Customer is responsible for providing complete and accurate billing information. All fees are exclusive of taxes, which the Customer is responsible for paying. Payments are processed by our third-party payment processor; we do not store full card details.

### 4.3. Late payments

If an invoiced amount is overdue, without limiting our other remedies, it accrues interest at 1.5% of the outstanding balance per month, or the maximum permitted by law, whichever is lower, from the day following the due date and without any reminder being required.

Where the Customer is a professional, and in accordance with Articles L.441-10 and D.441-5 of the French _Code de commerce_, a fixed indemnity for recovery costs of forty euros (€40) is also due for each unpaid invoice, without prejudice to additional compensation on supporting evidence where recovery costs actually incurred exceed that amount.

CentralCSP may suspend access to the Service until payment is made, and may pursue recovery of unpaid fees by any available means, including the _procédure d'injonction de payer_ provided for by the French _Code de procédure civile_.

### 4.4. Auto-renewal

Unless otherwise specified in an Order Form, the subscription renews automatically for successive periods equal to the expiring term, unless either party gives written notice of non-renewal at least thirty (30) days before the end of the term. Renewal pricing is CentralCSP's then-current pricing unless otherwise agreed in writing.

## 5\. Intellectual Property and Data Rights

### 5.1. CentralCSP's intellectual property

CentralCSP and its licensors retain all right, title, and interest, including all Intellectual Property Rights, in the Service, the underlying technology, the Documentation, and any modifications or derivative works. This Agreement conveys no ownership in the Service. The CentralCSP name, logo, and product names are trademarks of CentralCSP or third parties; no right to use them is granted.

### 5.2. Customer's intellectual property

As between the parties, the Customer owns all right, title, and interest in the Customer Data, including the Customer's website content and the data generated by it (all types of reports collected and the various policies generated).

### 5.3. License to provide the Service

The Customer grants CentralCSP a worldwide, non-exclusive, royalty-free, limited-term license to host, copy, transmit, display, and otherwise use Customer Data as reasonably necessary to provide, maintain, and support the Service for the Customer.

### 5.4. License for service improvement; artificial intelligence

The Customer grants CentralCSP a perpetual, irrevocable, worldwide, royalty-free, non-exclusive license to use, copy, modify, and create derivative works of Customer Data in aggregated and de-identified (anonymized) form, for the purposes of improving the Service, developing new features, and conducting research and industry reporting (for example our periodic "State of the Web" report). CentralCSP exercises this license consistently with the DPA; in particular, where a browser report incidentally contains personal data, that data is never used for public research reporting, and any conflict between this Section and the DPA is resolved in favour of the DPA.

CentralCSP does not use Customer Data to train, fine-tune, or develop artificial intelligence or machine-learning models.

Where the Customer connects the Service to an AI assistant, agent, or other Third-Party Service, including through the API or the MCP integration, the Customer initiates and directs that transmission and is solely responsible for it. That transmission is not a disclosure by CentralCSP. The Customer is responsible for the terms on which the recipient processes the transmitted data, including whether it is used for model training, and for any transfer outside the European Economic Area that results.

### 5.5. Feedback

If the Customer or an Authorized User provides feedback, comments, or suggestions about the Service ("Feedback"), such Feedback is given voluntarily, and CentralCSP may use, disclose, and exploit it without obligation or restriction.

### 5.6. Publicity

The Customer grants CentralCSP the right to use and display the Customer's name and logo to identify the Customer as a customer of CentralCSP, on CentralCSP's website and in its marketing materials, presentations, and customer lists. CentralCSP will use the logo in accordance with any reasonable trademark usage guidelines the Customer provides, and this right does not otherwise transfer any ownership of the Customer's trademarks. The Customer may opt out at any time by written notice to the contact details in Section 12, after which CentralCSP will cease new use of the Customer's name and logo within a reasonable period.

## 6\. Confidentiality, Privacy, and Security

### 6.1. Confidentiality

The Receiving Party shall protect the Disclosing Party's Confidential Information with at least the same degree of care it uses for its own confidential information of like kind (and no less than reasonable care), shall not use it outside the scope of this Agreement, and shall not disclose it to any third party except as authorized in writing. The Receiving Party may disclose Confidential Information to its employees, contractors, and professional advisers who need it to perform this Agreement and who are bound by confidentiality obligations no less protective than this Section, and remains responsible for their compliance.

### 6.2. Exclusions

The obligations in Section 6.1 do not apply to information that the Receiving Party can demonstrate: (a) is or becomes publicly known through no act or omission of the Receiving Party; (b) was rightfully in the Receiving Party's possession without restriction before disclosure by the Disclosing Party; (c) is rightfully received from a third party without breach of any obligation of confidentiality; or (d) is independently developed by the Receiving Party without use of or reference to the Disclosing Party's Confidential Information.

### 6.3. Compelled disclosure

The Receiving Party may disclose Confidential Information to the extent required by law, regulation, or a valid order of a court or other governmental authority, provided that it (where legally permitted) gives the Disclosing Party prompt written notice so the Disclosing Party may seek a protective order or other remedy, discloses only the portion legally required, and uses reasonable efforts to obtain confidential treatment for the disclosed information.

### 6.4. Duration

The obligations in this Section 6 apply during the term of this Agreement and for five (5) years after its termination or expiration, except that they apply for as long as the information remains a trade secret under applicable law, and except in respect of Personal Data, which remains protected for as long as it is retained.

### 6.5. Privacy Policy

CentralCSP collects, uses, and discloses Personal Data in accordance with its [Privacy Policy](https://centralcsp.com/en/legal/privacy/), which is incorporated by reference and describes how we handle the information you provide when you use the Service.

### 6.6. Data Processing Agreement (DPA)

To the extent CentralCSP processes Personal Data contained in Customer Data on the Customer's behalf, and such processing is subject to data protection laws such as the GDPR, the parties are bound by the CentralCSP [Data Processing Agreement](https://centralcsp.com/en/legal/dpa/), which is incorporated by reference. The DPA sets out the roles and obligations of the parties as required by regulations such as the GDPR and covers the following details of processing:

| Processing detail | Description |
| --- | --- |
| Subject-matter of the processing | Collection and analysis of browser-generated security telemetry and website security data to monitor and enhance the security of the Customer's web properties. |
| Duration of the processing | For the term of the Customer's subscription, and as specified in the data retention section of the DPA (a rolling 90-day maximum for browser reports; scan results contain no personal data and are kept indefinitely or aggregated into statistics). |
| Nature and purpose of the processing | To provide the Services, including collecting and analysing all supported browser Reporting-API report types, generating event-based alerts, maintaining a script inventory and detecting vulnerabilities (CVEs), producing PCI DSS evidence, scanning and evaluating website security, and generating recommended CSP policies. To use aggregated, anonymized data for service improvement. |
| Type of Personal Data processed | Account data: name, email, company, password (hashed). Report data: IP addresses, user-agent strings, URLs, and other technical data incidentally contained in browser reports. Scan results describe a website's publicly accessible configuration and contain no personal data. No special categories of data and no cardholder data. |
| Categories of Data Subjects | The Customer's Authorized Users, and End-Users of the Customer's websites whose browsers submit reports. |
| Obligations and rights of the Controller | The Customer's obligations and rights as data controller are set out in this Agreement and the DPA. |

### 6.7. Security measures and data residency

CentralCSP maintains appropriate administrative, technical, and physical safeguards designed to protect the security, confidentiality, and integrity of Customer Data against unauthorized access, use, modification, or disclosure. These are based on industry standards and include data encryption, access controls, and secure development practices, as further described in the DPA.

CentralCSP hosts and stores all Customer Data within the European Union. This commitment covers the data CentralCSP holds and processes on its own infrastructure and that of its sub-processors, as listed in the DPA.

It does not cover destinations the Customer chooses. Where the Customer configures the Service to transmit Customer Data to a Third-Party Service (including an alert delivery channel such as Slack, Microsoft Teams, PagerDuty, an email address, or a webhook endpoint, or an AI assistant connected through the API or MCP integration), the Customer directs that transmission as controller and is solely responsible for it, including for any resulting transfer outside the European Economic Area and for putting in place any transfer mechanism such transfer requires.

## 7\. Warranties and Disclaimers

### 7.1. Mutual warranties

Each party represents and warrants that it has the legal power and authority to enter into this Agreement.

### 7.2. CentralCSP's service commitment

CentralCSP warrants that, during the subscription term, it will provide the Service with reasonable care and skill, in substantial conformity with the Documentation, and using personnel with the requisite skill and experience. If the Service materially fails to conform to this warranty, the Customer's remedy, and CentralCSP's obligation, is for CentralCSP to use commercially reasonable efforts to correct the non-conformity; if it cannot do so within a reasonable period after written notice, the Customer may terminate the affected subscription and receive a refund of prepaid fees covering the remainder of the term. This Section does not limit any remedy available to the Customer under Section 8.3.

### 7.3. Disclaimer of warranties

Except as expressly provided in Section 7.2 and in any applicable SLA, the Service(s) and all related components and information are provided on an "AS IS" and "AS AVAILABLE" basis. CentralCSP disclaims all other warranties, whether express, implied, statutory, or otherwise, including implied warranties of merchantability, fitness for a particular purpose, title, and non-infringement, to the fullest extent permitted by applicable law.

Except as expressly set out in the SLA, CentralCSP does not warrant that the Service will be uninterrupted, timely, or error-free, or that all defects will be corrected. CentralCSP makes no guarantee regarding the results obtained from the Service, the accuracy of any security or compliance score, or the effectiveness of any generated Content Security Policy. The Customer acknowledges that no security tool provides absolute protection, and CentralCSP does not guarantee that use of the Service will prevent all security vulnerabilities (such as cross-site scripting, click-jacking, or data injection) or that generated policies will be optimal or compliant in all circumstances. The Service is a tool to aid security efforts, not a guarantee of security.

Nothing in this Section 7 excludes or limits any warranty or liability that cannot be excluded or limited under applicable law.

## 8\. Limitation of Liability

### 8.1. Cap on direct damages

Subject to Section 8.3, in no event shall either party's total aggregate liability arising out of or related to this Agreement exceed the total amount paid or payable by the Customer to CentralCSP in the twelve (12) months preceding the event giving rise to the claim. This limitation applies whether the claim is in contract or tort and regardless of the theory of liability.

### 8.2. Exclusion of indirect damages

Subject to Section 8.3, under no legal theory shall either party be liable for any indirect, special, incidental, exemplary, punitive, or consequential damages, including lost profits, losses, or expenses, whether or not the party was advised of the possibility of such damage.

### 8.3. Exclusions from the cap

The limitations in Sections 8.1 and 8.2 do not apply to:

-   the Customer's obligation to pay fees due under Section 4, including interest and recovery costs;
-   a party's willful and unauthorized disclosure or use of the other party's Confidential Information, made in knowing breach of Section 6. For the avoidance of doubt, liability arising from a security incident or Personal Data Breach affecting Customer Data, or from any other non-intentional breach of Section 6, remains subject to Sections 8.1 and 8.2, except where it results from fraud, _dol_, or _faute lourde_;
-   the Customer's breach of Section 2.1 (License grant), Section 2.2 (Acceptable Use), or Section 3.5 (Sanctions and export control);
-   fraud, _dol_ (willful misconduct), or _faute lourde_ (gross negligence); or
-   death or personal injury caused by a party's negligence, and any other liability that cannot lawfully be excluded or limited.

## 9\. Indemnification

### 9.1. By the Customer

The Customer shall defend, indemnify, and hold CentralCSP and its affiliates, officers, directors, agents, partners, and employees harmless from any third-party claim or demand, and any resulting damages, losses, and reasonable attorneys' fees finally awarded or agreed in settlement, arising out of (a) the Customer Data, (b) the Customer's use of the Service in breach of this Agreement, or (c) the Customer's scanning or analysis of a website or digital property without the authorization required by Section 2.2.

### 9.2. No indemnity by CentralCSP

CentralCSP gives no indemnity under this Agreement. Except where an indemnity is required by mandatory applicable law, CentralCSP has no obligation to defend, indemnify, or hold the Customer harmless against any third-party claim, including a claim that the Service infringes a third party's Intellectual Property Rights.

If the Service becomes, or in CentralCSP's opinion is likely to become, the subject of a third-party claim alleging infringement of Intellectual Property Rights, CentralCSP may at its option procure the right to continue using the Service, replace or modify it so it is non-infringing, or terminate the affected subscription and refund prepaid fees covering the remainder of the term.

### 9.3. Procedure

The indemnified party shall promptly notify the indemnifying party of the claim, give the indemnifying party sole control of the defence and settlement (provided that no settlement imposing a non-indemnified obligation on the indemnified party may be made without its consent, not unreasonably withheld), and provide reasonable cooperation at the indemnifying party's expense. A delay in notice relieves the indemnifying party only to the extent it is prejudiced by the delay.

### 9.4. Sole remedy

Sections 9.1 to 9.3 state the Customer's sole liability and CentralCSP's exclusive remedy for the claims they cover. The Customer's liability under this Section is subject to the limitations in Section 8. The obligations in this Section survive termination of this Agreement.

## 10\. Term and Termination

### 10.1. Term

This Agreement begins on the date the Customer first accepts it and continues for the initial subscription term in the applicable Order Form. The term renews automatically as described in Section 4.4.

### 10.2. Termination for cause

Either party may terminate this Agreement for cause if the other materially breaches it and fails to cure the breach within thirty (30) days of written notice. If the Customer terminates for cause under this Section, CentralCSP will refund any prepaid fees covering the remainder of the subscription term following the effective date of termination.

### 10.3. Termination for convenience

The Customer may terminate its subscription at any time using the cancellation procedures within the Service. Such termination takes effect at the end of the then-current billing period, and the Customer is not entitled to a refund of prepaid fees, except as provided in Section 2.3.

### 10.4. Effect of termination and data export

On termination or expiration, all rights granted to the Customer immediately cease.

For thirty (30) days following the effective date of termination or expiration, CentralCSP will make Customer Data available for export by the Customer through the Service or, on written request, provide it in a structured, commonly used, machine-readable format. This export window does not apply where the Customer's access is terminated for breach of Section 2.2 or Section 3.5, in which case CentralCSP will provide the data on written request only.

After the export window closes, CentralCSP has no obligation to maintain Customer Data and will delete it in accordance with Section 8 of the DPA and applicable law, including the storage-limitation principle under the GDPR. Scan results are excepted: they are designed to describe a website's publicly accessible configuration and are retained as described in Section 8 of the DPA; where a scan result incidentally contains personal data, CentralCSP deletes or redacts it on written request.

### 10.5. Survival

The following survive termination or expiration: Section 1 (Definitions), Section 4 (Fees) for fees owed, Section 5 (Intellectual Property and Data Rights), Section 6 (Confidentiality, Privacy, and Security) subject to the duration in Section 6.4, Section 7.3 (Disclaimer of Warranties), Section 8 (Limitation of Liability), Section 9 (Indemnification), Section 10.4 (Effect of Termination and Data Export), Section 10.5 (Survival), and Section 11 (General Provisions).

## 11\. General Provisions

### 11.1. Governing law

This Agreement is governed by and construed in accordance with the laws of France, without regard to its conflict-of-laws rules and excluding the United Nations Convention on Contracts for the International Sale of Goods.

### 11.2. Dispute resolution and jurisdiction

The parties shall first attempt to resolve any dispute through good-faith negotiation, initiated by written notice describing the dispute, for a period of thirty (30) days.

If the dispute is not resolved within that period, it shall be submitted to the **exclusive jurisdiction of the Tribunal de commerce de Grenoble (France)**, including in the case of multiple defendants, an emergency application, a protective measure, or a third-party claim. Where the Customer is a professional that is not a _commerçant_ and the Tribunal de commerce cannot hear the claim, the competent courts of Grenoble (France) have exclusive jurisdiction instead.

Nothing in this Section prevents either party from applying to any competent court for interim or injunctive relief, or prevents CentralCSP from pursuing recovery of unpaid fees through the _procédure d'injonction de payer_ or any other summary procedure available under French law.

### 11.3. Notices

Legal notices must be in writing and are deemed given on (i) personal delivery; (ii) the second business day after mailing within France, or the fifth business day after international mailing; or (iii) the first business day after sending by email. Notices to CentralCSP are sent to the address in Section 12; notices to the Customer are sent to the email associated with its account.

### 11.4. Assignment

Neither party may assign its rights or obligations without the other's prior written consent, except that either party may assign this Agreement in its entirety in connection with a merger, acquisition, reorganization, or sale of all or substantially all of its assets.

### 11.5. Force majeure

Neither party is liable for any failure or delay in performance (other than payment obligations) caused by events beyond its reasonable control and occurring without its fault or negligence. If such an event continues for more than sixty (60) days, either party may terminate the affected subscription by written notice, and CentralCSP will refund, on a pro-rata basis, any prepaid fees covering the period after termination.

### 11.6. Entire agreement and order of precedence

This Agreement, including the Privacy Policy, the DPA, the SLA, and all Order Forms, is the entire agreement between the parties and supersedes all prior agreements concerning its subject matter. In the event of any conflict among these documents, the order of precedence is: (1) the applicable Order Form, (2) the Data Processing Agreement, which prevails on matters of data protection only, (3) the SLA, which prevails on matters of service availability only, and (4) these Terms of Service.

### 11.7. Modifications to these Terms

CentralCSP may modify these Terms. For material changes we will give the Customer at least thirty (30) (calendar) days' notice before the change takes effect, through the Service's interface, by email to the address associated with the account, or by other reasonable means, and will update the "Last updated" date on this page.

If the Customer does not accept a material change, it may terminate its subscription without penalty by written notice given before the change takes effect, and CentralCSP will refund, on a pro-rata basis, any prepaid fees covering the period after termination. Continued use of the Service after the effective date of a change constitutes acceptance of the modified Terms.

### 11.8. Severability

If any provision of this Agreement is held to be invalid, unlawful, unenforceable, or _réputée non écrite_ by a court or other competent authority, that provision shall be modified to the minimum extent necessary to make it valid and enforceable while preserving the parties' original intent, or, if that is not possible, severed. In either case the remaining provisions of this Agreement remain in full force and effect.

### 11.9. No waiver

No failure or delay by either party in exercising any right or remedy under this Agreement operates as a waiver of it, and no single or partial exercise of any right or remedy prevents any further exercise of it or of any other right or remedy. A waiver is effective only if given in writing and is limited to the specific instance and purpose for which it is given.

### 11.10. Independent contractors

The parties are independent contractors. Nothing in this Agreement creates a partnership, joint venture, agency, franchise, employment, or fiduciary relationship between them, and neither party has authority to bind the other or to incur any obligation on the other's behalf.

### 11.11. Language

These Terms are drafted in English, which is the authoritative and legally binding version. Any translation (for example the French version) is provided for convenience only. In the event of any conflict, ambiguity, or divergence between the English version and a translated version, the English version prevails and governs.

## 12\. Contact Information

For questions about these Terms or for legal notices, contact us at:

-   Company: CentralSaaS, _société par actions simplifiée_ (SAS), operating the CentralCSP service
-   Registered office: 1 Allée des Frênes, 38240 Meylan, France
-   RCS: Grenoble **927 890 756**
-   Contact: [contact@centralcsp.com](mailto:contact@centralcsp.com)

Full statutory information (share capital, SIRET, VAT number, hosting) is available on our [Legal Notice](https://centralcsp.com/en/legal/mentions-legales/) page.

---

Available in: [en](https://centralcsp.com/en/legal/terms/), [fr](https://centralcsp.com/fr/legal/terms/)
