LAGAN CYBER
Legal register — document 02

Terms

The terms on which WESTPORT CYBER LIMITED, trading as Lagan Cyber, provides this website, the private early-access platform and any application we later publish.

Effective date: 5 August 2026 · Version 1.0 · WESTPORT CYBER LIMITED · Company No. NI741244 · Governing law: Northern Ireland

Which parts apply to you

Part A applies to everyone who uses this website. Part B applies to organisations that use the platform, including under early access, and is a business-to-business agreement. Part C is a consumer end-user licence for any application we publish and applies only where you are a consumer acting outside your trade, business, craft or profession.

Nothing in Part B or Part C removes rights you have under the Consumer Rights Act 2015 if you are a consumer.

01 Definitions

In these terms:

  • “Agreement” means these terms together with any Order and any document expressly incorporated by them.
  • “App” means any mobile or desktop application we publish under the name Lagan Cyber.
  • “Authorised User” means an individual permitted by you to use the Services under your account.
  • “Connected Environment” means a cloud tenant, subscription or directory that you authorise us to read, such as a Microsoft 365, Entra ID, Azure or Google Workspace tenant.
  • “Customer Data” means all data you or your Authorised Users submit to the Services, and all configuration data and metadata we read from a Connected Environment, including Evidence Records generated from it.
  • “Evidence Record” means a record produced by the Services describing the result of a check, assertion or attestation.
  • “Early Access” means access to the Services before general release, as described in clause 6.
  • “Order” means an order form, written quotation, subscription confirmation or early-access confirmation accepted by both parties.
  • “Services” means the Lagan Cyber platform and any related services described in an Order.
  • “Site” means the website at lagancyber.co.uk and its subdomains.
  • “we”, “us”, “our” means WESTPORT CYBER LIMITED, company number NI741244, trading as Lagan Cyber.
  • “you”, “your” means the person or organisation using the Site or the Services.

References to statutes include any amendment or re-enactment. Headings do not affect interpretation. “Including” means “including without limitation”. A “working day” is a day other than a Saturday, Sunday or public holiday in Northern Ireland.

02 About us and these terms

WESTPORT CYBER LIMITED is a private company limited by shares registered in Northern Ireland, company number NI741244, whose registered office is 125 Jordanstown Road, Newtownabbey, Northern Ireland, BT37 0NT. We trade as Lagan Cyber. Contact: hello@lagancyber.co.uk.

By using the Site you accept Part A. By using the Services you accept Parts A and B. By installing or using an App as a consumer you accept Parts A and C. If you do not accept them, do not use the Site, the Services or the App.

Where you accept these terms on behalf of an organisation, you confirm you have authority to bind that organisation, and “you” means that organisation.

03 Website use (Part A)

The Site is provided free of charge and for information. We may change or withdraw any part of it at any time without notice.

Content on the Site — including framework coverage figures, control counts, specimen records and roadmap statements — is provided for general information about our intentions and our build state at the date shown. It is not professional, legal, regulatory, security or compliance advice, and it is not an offer capable of acceptance. Do not act on it without taking your own advice on your own circumstances.

Specimen Evidence Records shown on the Site are labelled as illustrative and are invented. They do not relate to any real organisation, tenant or scan.

You must not use the Site to attempt to gain unauthorised access, to introduce malicious code, to scrape it at a rate that degrades it for others, or to do anything unlawful. You must not frame the Site or present its content as your own. You may link to the Site provided you do so fairly and do not suggest an association or endorsement that does not exist.

We take reasonable care over the Site’s content but do not warrant that it is accurate, complete or up to date, and to the fullest extent permitted by law we exclude liability for reliance placed on it. Clause 20 applies.

04 Structure and order of precedence

The Agreement comprises, in descending order of precedence where there is a conflict: (a) any Order signed or confirmed in writing by both parties; (b) any data processing terms incorporated by clause 14; (c) these terms; (d) any documentation we provide. A purchase order, supplier portal condition or standard purchasing term issued by you does not form part of the Agreement and has no effect, even if we acknowledge it.

05 The services

The Services read the configuration of your Connected Environments on a read-only basis, compare what they find against our control library, map results to control frameworks, and produce Evidence Records. Where the relevant control domain exists, the Services also hold policy documents, supplier questionnaire responses and security training records that you submit.

5.1 What the Services are not

You acknowledge and agree that:

  1. we are not a certification body, accredited assessor, auditor, or a UKAS-accredited or IASME-licensed organisation, and nothing we produce is a certificate, a certification, an accreditation, a formal assurance opinion or a statement of conformity;
  2. use of the Services does not guarantee that you will pass any audit, obtain any certification, satisfy any regulator, obtain any insurance, or win any tender;
  3. the Services are not a managed security service, a security operations centre, an intrusion detection or monitoring service, an incident response service, or a penetration testing service, and must not be relied on as any of those;
  4. the Services do not provide legal or regulatory advice, and our mapping of controls to frameworks is our own interpretation and carries no endorsement from any framework publisher;
  5. we have no write access to your Connected Environments and cannot remediate any finding. Remediation is your responsibility;
  6. a check result is a point-in-time reading and says nothing about the state of your environment before or after the moment of collection.

5.2 Changes to the Services

We may modify the Services from time to time, including adding, changing or removing checks and framework mappings. We will not make a change that materially reduces core functionality during a paid subscription term without giving you at least 30 days’ notice; if such a change materially and adversely affects you, you may terminate the affected Services on notice and receive a pro-rata refund of prepaid fees.

06 Early access and pre-release software

At the date of these terms the Services are pre-launch and are offered only under Early Access. This clause prevails over any other clause in relation to Early Access.

  1. Early Access software is pre-release. It is incomplete, may contain defects, may produce incorrect results, and may become unavailable without notice.
  2. Early Access is provided free of charge and “as is”. Clause 18 (warranties) does not apply to Early Access, and there is no service level, uptime commitment, support commitment or response time.
  3. We may change, suspend or withdraw Early Access, or any feature within it, at any time and without liability. We may discontinue the Services entirely.
  4. You must not rely on Early Access output as your sole or primary evidence for any audit, regulatory submission, insurance application or tender response. Verify independently.
  5. Either party may terminate Early Access at any time on written notice, with immediate effect and without cause. On termination clause 17 applies.
  6. Our data protection obligations under clause 14 apply in full to Early Access. Nothing in this clause reduces them.
  7. Our obligations of confidentiality under clause 13 apply in full to Early Access.

We would rather say this plainly than have you discover it later: connecting a production tenant to unfinished software is a decision you should take with your eyes open, and if you would prefer to wait for general release, that is a sensible choice and we will not press you.

07 Accounts and credentials

You are responsible for your account and for all activity under it. You must keep credentials confidential, enable multi-factor authentication where offered, ensure each Authorised User has their own credentials, not share logins between individuals, and promptly remove Authorised Users who no longer need access.

Tell us immediately at hello@lagancyber.co.uk if you suspect unauthorised access. We may suspend an account immediately where we reasonably believe it is compromised, and will tell you as soon as practicable.

You are responsible for your Authorised Users’ acts and omissions in connection with the Services as if they were your own.

08 Connecting your cloud tenants

To use the posture-scanning features you must authorise us to read a Connected Environment. You warrant that you have the right and authority to grant that authorisation, and that doing so does not breach any agreement between you and your cloud provider or any third party.

We will request only read-only, least-privilege scopes. The current scope list is published on our evidence page. We will not request a wider scope without first notifying you, and any wider scope requires your own act of consent in your identity provider.

You may revoke our access at any time from your own administrative console, without notice to us and without our involvement. Revocation stops scanning immediately. Revocation does not delete Evidence Records already generated; clause 17 and the privacy notice deal with deletion.

You are responsible for ensuring that connecting a Connected Environment is lawful in your organisation, including where that environment contains personal data of your staff, and for informing your staff where you are required to.

09 Acceptable use

You must not, and must not permit anyone else to:

  1. use the Services to scan, assess or read any environment you do not own or are not authorised to assess;
  2. use the Services unlawfully, fraudulently, or in breach of any third party’s rights;
  3. upload malicious code, or content that is unlawful, defamatory or infringing;
  4. attempt to gain unauthorised access to the Services, other customers’ data, or our infrastructure;
  5. probe, scan or test the vulnerability of the Services, or breach any security or authentication measure, except with our prior written consent — responsible disclosure under the process on our status page is welcome and does not require consent to report, but active testing does;
  6. reverse engineer, decompile or disassemble any part of the Services except to the extent that restriction is prohibited by law;
  7. copy, resell, sublicense, rent or provide the Services to a third party as a service bureau, except as expressly permitted in an Order;
  8. use the Services or their output to represent to any third party that you hold a certification you do not hold, or that any output constitutes certification;
  9. use automated means to extract data from the Services at a rate that degrades them, or circumvent rate limits;
  10. remove or obscure proprietary notices.

Breach of this clause is a material breach and may result in immediate suspension under clause 16.

10 Your responsibilities

You are responsible for: the accuracy and legality of Customer Data you submit; obtaining any consent or giving any notice required in your organisation before connecting an environment or enrolling staff; your own security posture and the remediation of any finding; deciding whether output is fit for the use you put it to; maintaining your own records independently of the Services; and complying with all laws applicable to your business, including any framework or regulatory obligation you are subject to.

You are responsible for making and keeping your own copies of anything you need. We are not an archive of record.

11 Intellectual property

11.1 Our pre-existing rights

All intellectual property rights in the Site, the Services, the App, our control library, our check definitions, our framework mappings, our documentation, our policy templates and the Lagan Cyber name and marks are and remain owned by us or our licensors. Nothing in the Agreement transfers any of them to you.

11.2 Your pre-existing rights

All intellectual property rights in Customer Data, and in any material you owned before the Agreement, remain yours. Nothing in the Agreement transfers them to us.

11.3 Licence to you

Subject to the Agreement and to payment of any fees, we grant you a non-exclusive, non-transferable, revocable licence, for the term, to use the Services and to use, copy and internally distribute their output — including Evidence Records and reports — within your organisation and to your auditors, insurers, regulators and prospective customers for the purpose of evidencing your own security and compliance position.

11.4 Deliverables

Where an Order provides for us to create a bespoke deliverable specifically for you, ownership of intellectual property rights in that deliverable is as stated in the Order. In the absence of a statement, we own it and grant you a perpetual, irrevocable, non-exclusive, royalty-free licence to use it for your internal business purposes. In either case we retain ownership of all pre-existing materials, tools, know-how and generic components used to create it, and of any general skills or knowledge we acquire.

11.5 Third-party framework material

Framework names, control identifiers and requirement text belong to their publishers — ISO, the NCSC, IASME, the EU institutions, NIST and others. We use them descriptively for interoperability. We have no affiliation with, endorsement from, or licence to sublicense the underlying standards, and you must obtain your own copy of any standard from its publisher. Our mapping is our own work.

11.6 Feedback

If you give us feedback or suggestions, you grant us a perpetual, irrevocable, worldwide, royalty-free licence to use them without obligation or attribution. You are not obliged to give feedback, and none of your Customer Data is feedback.

12 Your data and the licence you give us

You grant us a non-exclusive, worldwide, royalty-free licence to host, store, process, transmit and display Customer Data solely to the extent necessary to provide the Services to you, to support you, and to comply with law. That licence ends when the Agreement ends, save as needed to complete deletion or return.

We will not use Customer Data for our own purposes. In particular we will not use it to build benchmarks, industry reports, threat intelligence, marketing material or training data for machine-learning models, and we will not disclose findings from your environment to any other customer. This is a contractual commitment, not a policy statement we can quietly change.

We may generate and use aggregate operational metrics that contain no Customer Data and cannot identify you — for example the total number of scans our infrastructure ran in a month — for capacity planning and billing.

13 Confidentiality

Each party may receive confidential information of the other. Confidential information means information disclosed in connection with the Agreement that is identified as confidential or that a reasonable person would understand to be confidential from its nature or the circumstances. Your security findings, posture data and Evidence Records are your confidential information. Our non-public product plans, control library and pricing are ours.

Each party will keep the other’s confidential information confidential, use it only for the Agreement, disclose it only to those of its personnel and professional advisers who need it and who are bound by equivalent obligations, and protect it with at least reasonable care.

These obligations do not apply to information that is or becomes public other than by breach, was lawfully known without restriction before disclosure, is independently developed without use of the confidential information, or is lawfully received from a third party without restriction. A party may disclose confidential information where required by law, regulation or court order, giving the other party reasonable prior notice where lawful and disclosing only what is required.

These obligations continue for five years after the Agreement ends, and indefinitely for anything that is a trade secret or that constitutes personal data.

14 Data protection

Each party will comply with applicable data protection law, meaning the UK GDPR, the Data Protection Act 2018 and PECR, and where applicable the EU GDPR.

In relation to Customer Data, you are the controller and we are the processor. Our Article 28 commitments — documented instructions, confidentiality, security, sub-processing and change notification, assistance with data subject rights, assistance with Articles 32 to 36, deletion or return, audit rights, and breach notification to you within 24 hours — are set out in full in section 17 of our privacy notice and are incorporated into the Agreement by reference as if set out here. Our sub-processor list is at section 18, and we will give at least 30 days’ notice before adding or replacing a sub-processor.

In relation to your account details, your contacts and our own security logging, we are the controller, as described in the privacy notice.

You warrant that you have a lawful basis for the processing you instruct us to carry out, that you have given any notices required to your staff and to individuals at your suppliers, and that your instructions will not put us in breach of data protection law.

Where an Order requires a separate signed data processing agreement, that agreement prevails over this clause to the extent of any conflict.

15 Fees, payment and late payment

Early Access is free and no fees are payable. This clause applies once the Services are offered on a paid basis under an Order.

  1. Fees are as stated in the Order. Unless the Order says otherwise, fees are payable annually in advance.
  2. All fees are exclusive of VAT, which we will add at the applicable rate.
  3. Invoices are payable within 30 days of the invoice date, in pounds sterling, by bank transfer or by the payment method stated in the Order, without set-off, counterclaim or deduction except as required by law.
  4. You must tell us of any disputed invoice within 15 days of the invoice date, giving reasons. You must pay the undisputed balance on time. We will not treat a genuinely disputed amount as overdue while we resolve it in good faith.
  5. Late payment. Where the Agreement is a commercial contract within the meaning of the Late Payment of Commercial Debts (Interest) Act 1998, we are entitled to statutory interest on overdue sums at 8% above the Bank of England base rate, together with fixed compensation under section 5A of that Act and our reasonable costs of recovering the debt. We may instead claim interest at 4% above base rate under the Agreement; we will not claim both on the same sum.
  6. We may suspend the Services on 14 days’ written notice if an undisputed invoice remains unpaid, and may terminate under clause 16.
  7. Fees are non-refundable except where these terms expressly provide otherwise.
  8. We may increase fees on renewal by giving at least 60 days’ notice before the renewal date. If you do not accept an increase, you may decline renewal.
  9. Where a subscription is billed through an app store, clause 31 applies and the store’s payment and refund terms govern the transaction.

16 Term, suspension and termination

16.1 Term

The Agreement starts when you first use the Services and continues for the term in the Order, renewing for successive periods of the same length unless either party gives notice not to renew at least 30 days before the end of the current term. Early Access continues until terminated under clause 6.

16.2 Suspension

We may suspend the Services, or an Authorised User’s access, immediately where: there is a security incident or a credible threat to the Services or other customers; we are required to by law; you are in material breach of clause 9; or an undisputed invoice is more than 14 days overdue and we have given notice. We will limit suspension to what is necessary, tell you as soon as reasonably practicable, and restore access promptly once the cause is resolved.

16.3 Termination for cause

Either party may terminate immediately on written notice if the other commits a material breach that is irremediable, or that is remediable and is not remedied within 30 days of written notice, or if the other becomes insolvent, has an administrator or receiver appointed, enters into an arrangement with creditors, ceases to carry on business, or suffers an equivalent event in any jurisdiction.

16.4 Termination for convenience

You may terminate a paid subscription with effect from the end of the then-current term by giving 30 days’ notice. Either party may terminate Early Access at any time under clause 6.

16.5 Termination by us on notice

We may terminate a paid subscription on 90 days’ written notice if we withdraw the Services generally, refunding a pro-rata share of prepaid fees for the unused period.

17 Effect of termination

On termination: your right to use the Services ends; you must pay all sums due to the date of termination; each party returns or destroys the other’s confidential information on request, subject to legal retention obligations and to routine backup cycles.

We will make an export of your Customer Data available for 30 days after termination, in JSON and CSV. After that period we delete Customer Data from live systems, with backups purging within 35 days, unless you instruct return or earlier deletion. You may ask for deletion sooner and we will comply.

Clauses that by their nature should survive do so, including clauses 1, 11, 12 (in respect of deletion), 13, 14, 17, 19, 20, 21, 26, 27, 28, 30 and 31.

18 Warranties

We warrant that: we have the right to enter into the Agreement; we will provide the Services with reasonable skill and care in accordance with good industry practice; the Services will materially conform to their documentation; we will not knowingly introduce malicious code; and we will comply with applicable law in providing the Services.

If the Services do not materially conform to their documentation, tell us. Our obligation, and your exclusive remedy for that non-conformity, is that we will use reasonable endeavours to correct it within a reasonable time or, if we cannot, refund fees paid for the affected period.

You warrant that you have the right and authority to connect each Connected Environment and to submit Customer Data, and that doing so does not infringe any third party’s rights or breach any law.

The warranties in this clause do not apply to Early Access, which is provided “as is” under clause 6.

19 Disclaimers

Except as expressly stated in clause 18, and to the fullest extent permitted by law, all warranties, conditions and terms implied by statute or common law are excluded from the Agreement.

We do not warrant that the Services will be uninterrupted or error free, that every misconfiguration in your environment will be detected, that a check result is correct in every case, or that use of the Services will result in any certification, audit outcome, regulatory outcome, insurance outcome or commercial outcome. Detection is limited to the checks we have written, running against the environments you have connected, at the times they ran.

We are not a certification body. No output of the Services is a certificate. We do not hold ISO 27001, SOC 2 or Cyber Essentials certification ourselves and do not represent that we do.

Nothing in this clause limits the warranties we do give, or limits liability that cannot be limited under clause 20.

20 Limitation of liability

Read this clause

It limits what we pay if something goes wrong, and it is one of the reasons the Services can be offered at the price they are. Some liabilities can never be excluded, and clause 20.1 lists them.

20.1 Liability we never exclude

Nothing in the Agreement excludes or limits either party’s liability for: death or personal injury caused by negligence; fraud or fraudulent misrepresentation; any liability under section 12 of the Sale of Goods Act 1979 or section 2 of the Supply of Goods and Services Act 1982 (title); any liability that cannot lawfully be excluded or limited, including under the Consumer Rights Act 2015 where you are a consumer; or your obligation to pay sums properly due.

20.2 Excluded losses

Subject to clause 20.1, neither party is liable to the other, whether in contract, tort (including negligence), breach of statutory duty or otherwise, for: loss of profit; loss of revenue; loss of anticipated savings; loss of business or business opportunity; loss of goodwill or reputation; loss of contract; the cost of obtaining a certification or of a failed audit; regulatory fines or penalties imposed on you (except to the extent they result from our breach of clause 14); or any indirect or consequential loss.

20.3 The cap

Subject to clauses 20.1 and 20.4, each party’s total aggregate liability arising out of or in connection with the Agreement in any 12-month period is limited to the greater of (a) the total fees paid or payable by you under the Agreement in the 12 months immediately before the event giving rise to the claim, and (b) £5,000.

Where the Services are provided under Early Access, no fees are payable, and our total aggregate liability is limited to £5,000. We state that plainly rather than leaving you to work out that a percentage of nothing is nothing.

20.4 Data protection liability

Liability arising from a breach of clause 14 or of our Article 28 obligations is subject to a separate aggregate cap equal to the greater of the fees paid in the preceding 12 months and £25,000. Nothing in the Agreement limits either party’s liability to a data subject or to a supervisory authority under data protection law, or affects the allocation of liability between controller and processor under Article 82 UK GDPR.

20.5 Mitigation and time limit

Each party must take reasonable steps to mitigate its loss. No claim may be brought more than 12 months after the party bringing it became aware, or ought reasonably to have become aware, of the circumstances giving rise to it, except for claims for non-payment.

20.6 Allocation of risk

The parties agree that these limits are reasonable having regard to the fees payable, the nature of the Services, the fact that you retain responsibility for your own security and compliance, and each party’s ability to insure.

21 Indemnities

21.1 Our indemnity

We will indemnify you against damages and costs finally awarded by a court, or agreed in settlement with our written consent, in respect of a third-party claim that your permitted use of the Services infringes that third party’s UK intellectual property rights. This does not apply to a claim arising from Customer Data, from your use of the Services other than in accordance with the Agreement, from modification of the Services by anyone other than us, or from combination with anything we did not supply. If a claim arises we may, at our option, procure the right for you to continue, modify the Services to be non-infringing, or terminate the affected Services and refund prepaid fees for the unused period.

21.2 Your indemnity

You will indemnify us against damages and costs finally awarded, or agreed in settlement with your written consent, in respect of a third-party claim arising from Customer Data, from your connection of an environment you were not authorised to connect, or from your breach of clause 9.

21.3 Conditions

Each indemnity is conditional on the indemnified party notifying the other promptly, not admitting liability, giving the indemnifying party conduct of the defence and settlement, and giving reasonable assistance at the indemnifying party’s cost. The indemnifying party may not settle in a way that imposes an obligation on the indemnified party without consent. The caps in clause 20.3 apply to the indemnities in this clause.

22 Force majeure

Neither party is liable for failure or delay in performing its obligations caused by an event beyond its reasonable control, including act of God, flood, fire, war, terrorism, civil disorder, epidemic, industrial action affecting a third party, failure of a utility or telecommunications network, cyber attack against a third party on which the affected party depends, or the act of a government or regulator. The affected party must notify the other, mitigate, and resume as soon as reasonably possible. If the event continues for more than 60 days, either party may terminate on written notice, and we will refund prepaid fees for services not provided. This clause does not excuse an obligation to pay sums already due.

23 Subcontracting and assignment

We may subcontract performance of the Services, including to the sub-processors listed in the privacy notice, but remain fully responsible to you for subcontracted performance as if we had performed it ourselves. Sub-processor changes follow the notice procedure in clause 14.

Neither party may assign, transfer or otherwise deal with its rights or obligations without the other’s prior written consent, not to be unreasonably withheld or delayed, except that either party may assign the whole Agreement to a successor in connection with a merger, reorganisation or sale of all or substantially all of its assets or of the business to which the Agreement relates, on written notice to the other.

24 Variation

We may vary these terms. For a variation that materially and adversely affects you, we will give at least 30 days’ written notice before it takes effect, and if you do not accept it you may terminate the affected Services before the effective date and receive a pro-rata refund of prepaid fees. Other variations, including corrections and clarifications, take effect on publication with the effective date updated.

No variation to an Order is effective unless agreed in writing by both parties.

25 Entire agreement

The Agreement constitutes the entire agreement between the parties in relation to its subject matter and supersedes all previous agreements, understandings and representations, whether written or oral. Each party acknowledges that in entering into the Agreement it does not rely on any statement, representation, assurance or warranty not set out in the Agreement. Nothing limits liability for fraudulent misrepresentation. This clause does not apply where you are a consumer.

26 Third-party rights

A person who is not a party to the Agreement has no right under the Contracts (Rights of Third Parties) Act 1999 to enforce any of its terms. The parties may vary or rescind the Agreement without the consent of any third party. Clause 31.8 records the limited position of Apple and Google in relation to an App EULA.

27 Notices

Notices under the Agreement must be in writing. Notices to us go to hello@lagancyber.co.uk or by post to WESTPORT CYBER LIMITED, 125 Jordanstown Road, Newtownabbey, Northern Ireland, BT37 0NT. Notices to you go to the email address of your nominated contact or to your registered office.

A notice by email is deemed received at the time of transmission, or if transmitted outside working hours, at 9.00 am on the next working day, provided no delivery failure is received. A notice sent by pre-paid first class post is deemed received at 9.00 am on the second working day after posting. This clause does not apply to the service of proceedings.

28 Severability and waiver

If any provision is or becomes invalid, illegal or unenforceable, it is deemed modified to the minimum extent necessary to make it valid, legal and enforceable; if that is impossible, the provision is deemed deleted and the rest of the Agreement is unaffected.

No failure or delay in exercising a right waives it. A single or partial exercise does not prevent further exercise. A waiver is effective only if in writing and applies only to the circumstances for which it is given.

29 Complaints

If you are unhappy with the Services or with how we have dealt with you, write to hello@lagancyber.co.uk with the subject “Complaint”. We acknowledge within five working days and aim to respond substantively within 20 working days, or tell you why we need longer and when to expect a reply. Complaints are handled by a director.

If we cannot resolve a dispute between us, both parties will consider in good faith whether mediation would help before starting proceedings. Nothing in this clause prevents either party from seeking urgent injunctive relief, and it does not affect your right to complain to the Information Commissioner about a data protection matter — see the privacy notice.

30 Governing law and jurisdiction

The Agreement, and any dispute or claim arising out of or in connection with it or its subject matter or formation (including non-contractual disputes or claims), is governed by and construed in accordance with the law of Northern Ireland.

The parties irrevocably agree that the courts of Northern Ireland have exclusive jurisdiction to settle any such dispute or claim.

If you are a consumer, this clause does not deprive you of the protection of the mandatory law of your country of habitual residence, and you may bring proceedings in the courts of the part of the United Kingdom in which you live.

31 Consumer app EULA (Part C)

Status

We do not currently publish any App. This Part is stated in advance so that its terms are on the record before anything is published. It applies only where you are a consumer — an individual acting wholly or mainly outside your trade, business, craft or profession. If you use an App for work, Part B applies instead.

31.1 Licence

We grant you a personal, non-exclusive, non-transferable, revocable licence to install and use the App on devices you own or control, for your personal use, in accordance with the store rules of the platform you obtained it from. We do not sell you the App; we license it.

31.2 Restrictions

You must not copy the App except as part of normal use or backup, rent, lend, sell or sublicense it, or reverse engineer, decompile or disassemble it except to the extent permitted by law, including your rights under sections 50B and 50BA of the Copyright, Designs and Patents Act 1988.

31.3 Your consumer rights

Under the Consumer Rights Act 2015, digital content must be of satisfactory quality, fit for a particular purpose you made known, and as described. If it is not, you may be entitled to a repair or replacement, a price reduction, or a refund. If defective digital content damages a device or other digital content and we have not used reasonable care and skill, you may be entitled to repair or compensation. Nothing in these terms affects those rights.

31.4 Store-billed subscriptions

Where the App offers a subscription billed through the App Store or Google Play, the store is the merchant of record and processes payment under its own terms. Subscriptions renew automatically at the then-current price unless cancelled at least 24 hours before the end of the current period. You manage and cancel a store-billed subscription in your Apple or Google account settings — we cannot cancel it for you. Refunds for store-billed purchases are handled under the store’s own refund policy; we will support a reasonable request but cannot process the refund ourselves.

Cancelling a subscription is not the same as deleting your account. To delete your account and data, use the in-app path at Settings → Account → Delete account or email hello@lagancyber.co.uk. We complete deletion within 30 days. See section 31 of the privacy notice.

31.5 Cancellation and the 14-day cooling-off period

Where you buy a subscription or digital content from us at a distance as a consumer, you normally have 14 days from the day after the contract is concluded to cancel without giving a reason, under the Consumer Contracts (Information, Cancellation and Additional Charges) Regulations 2013. To cancel, tell us clearly — an email to hello@lagancyber.co.uk is enough.

31.6 Immediate supply and waiver of the cancellation right

Digital content is normally supplied immediately. Where you ask us to begin supplying it during the 14-day period, we will ask you to acknowledge, before supply begins, that: (a) you expressly request immediate supply; and (b) you acknowledge that you will lose your right to cancel once supply has begun. That is the effect of regulation 37(1) of the 2013 Regulations. If you do not give that acknowledgement, supply starts after the 14 days.

Where the purchase is billed by an app store, the store’s own cancellation and refund process applies in addition, and in practice is usually the faster route.

31.7 Updates and availability

We may issue updates, and your device may install them automatically. We may stop supporting an operating system version that is no longer maintained by its vendor. If we discontinue an App we will give reasonable notice and, where you have paid for an unexpired period, a pro-rata refund.

31.8 App stores

Where you obtain an App from the App Store or Google Play, this EULA is between you and us, not between you and Apple or Google. The store operator is not responsible for the App or its content and has no obligation to provide maintenance or support. To the extent the store’s rules require it, the store operator and its subsidiaries are third-party beneficiaries of this EULA and may enforce it against you. Any claim relating to the App is directed to us, not to the store operator, except for a claim about the store’s own payment processing.

31.9 Alternative dispute resolution

We do not currently subscribe to an alternative dispute resolution scheme. If we cannot resolve a complaint through clause 29, you retain the right to take a claim to court and, for a data protection matter, to complain to the Information Commissioner.

← Back to Lagan Cyber