Phase 0 · Pre-launch. Commercial activity has not commenced.
BreachDuty ← Back to site

Terms of Service

Effective Date: August 8, 2026 · Version 1.0


Effective Date: Phase-0 (pre-launch); commercial activity has not commenced.

These Terms of Service ("Terms") form a binding agreement between Ellis Intelligence LLC, a Colorado limited liability company doing business as BreachDuty ("BreachDuty", "we", "us"), and the customer subscribing to or using the Service ("Customer", "you").

The Service is for use by businesses — including businesses and firms managing a data-breach notification workflow — a company handling its own incidents, or a breach-coach, privacy-attorney, incident-response firm, or managed-service provider handling notifications for its client companies. The Service is not for use by consumers.


1. The Service

1.1 BreachDuty is a software-as-a-service application that runs the mapping and timing side of a company's data-breach notification workflow: an incident-intake wizard (data classes, affected populations per state, discovery date), an Obligation Atlas that maps per-jurisdiction notification obligations with regulator overlays, statutory deadline clocks, a versioned and cited statute library, and an audit log with a chain-of-custody export and a sealed obligation-map PDF. Every obligation the Service presents carries its statutory citation. The Service is an obligation-map-and-timing-clock tool: it does not draft, assemble, or send breach-notification content; the Customer's own counsel originates, drafts, and sends every notice itself, through its own systems.

1.2 Tier-specific features and limits (including any request-volume or usage bands) are described at breachduty.com/pricing. Tier names, and the figures behind them, live on that page and are never restated in these Terms. Tiers: Direct ($199–499/mo, banded by covered-state count and incidents per year) and White-label ($4,990/yr, annual). Figures live at breachduty.com/pricing and are never restated here.

1.3 Business Use Only. The Service is intended for use by businesses for business purposes.

1.4 BreachDuty Is Software, Not a Law Firm, Lawyer, or Compliance Authority. BreachDuty is a software vendor providing a mapping, timing-clock, and record-keeping tool. BreachDuty does not practice law, does not render legal determinations, and does not decide whether or what any Customer must notify. BreachDuty does not: - Provide legal advice, or an opinion on whether a given incident triggers a notification obligation in any jurisdiction — the Service presents a cited, statute-linked checklist for the Customer's counsel to confirm - Act as the Customer's attorney, breach coach, incident-response facilitator, or compliance officer - Form an attorney-client or advisory relationship with the Customer or with any consumer who receives a notice - Guarantee compliance with any law, or that any obligation, deadline, or notice the Service produces is correct, complete, or sufficient for the Customer's actual facts - Determine the Customer's legal obligations — the obligation map is a software output computed from the facts the Customer enters against a versioned statute library, always shown with its citation, for the Customer's counsel to review - Draft, assemble, or send any notice, to any regulator, attorney general, or consumer. BreachDuty is scoped to the Obligation Atlas and timing clock only: the Service does not include or generate breach-notification content — the notice the Customer's own counsel drafts, assembles, and sends is its own artifact, not a Service artifact

1.5 BreachDuty Is Not a Breach-Detection, Forensics, or Consumer-Identity Service. BreachDuty processes the incident metadata the Customer's team enters. It does not detect breaches, perform forensic investigation, scan systems, monitor for compromise, or provide identity-protection, credit-monitoring, or any other consumer-facing service. Because BreachDuty is scoped to the Obligation Atlas and timing clock only, individuals who receive notices are never entered into the Service as recipient records; they are neither customers, users, nor account holders of BreachDuty.

1.6 The Customer and Its Counsel Decide. The Service maps obligations and runs the clocks. Because BreachDuty is scoped to the Obligation Atlas and timing clock only, it does not draft notices — the Customer, through its own counsel, originates, drafts, and sends every notice through its own systems. The Customer is responsible for the accuracy of the facts it enters (data classes, affected-population counts per state, discovery date) and for the notice content and the legal judgment applied to it. Your counsel makes the call and sends the notice; BreachDuty helps make sure it happens on time and on the record.

2. Account

2.1 Account creation requires an authorized representative of the Customer entity.

2.2 Each seat is for a single named individual. Seat-sharing is prohibited.

3. Subscriptions, Pricing, Billing

3.1 Direct is a monthly, self-serve card subscription; White-label is a self-serve annual card subscription. No invoice/net-30 billing and no negotiated tier in v1.

3.2 Pricing at breachduty.com/pricing. 30-day notice for material changes.

3.3 Billing via Stripe.

3.5 Refunds. Monthly fees are non-refundable for the current period except pro rata on our material breach or on discontinuation under §10.

3.6 No Service-Level Credits or Refunds. The Service carries no uptime or response-time commitment. No service credit, fee credit, refund, or other remedy arises from any delay, outage, missed response target, or unmet support expectation. The §12.1 limited-warranty remedy and the §10.2 pro-rata refund on our own discontinuation remain the only remedies.

4. Customer Data; Nested Tenancy — a white-label firm is a tenant whose client companies are company-scoped records within it; a direct Customer is a tenant with one company

4.1 Ownership. As between us, you own all Customer Data you submit ("Customer Data"), including your company and client-company identities, incident metadata, affected-population counts, obligation maps, and the audit and chain-of-custody records the Service generates for you. Because BreachDuty is scoped to the Obligation Atlas and timing clock only, the Service does not require or store notice content or individual consumer identity/contact records.

4.2 License to Us. You grant us a limited license to host, store, transmit, display, and process Customer Data solely to provide the Service (including mapping obligations, computing deadlines, tracking the notice clock, generating the sealed obligation-map PDF and chain-of-custody export, and managing reminders and statute change-notices).

4.3 No Training / No Selling. We do not sell or share Customer Data, and we do not use it to train any model or to improve a Service used by other customers. See our Privacy Policy.

4.4 Nested Per-Tenant, Per-Company Isolation. Each firm is one tenant; each client company is a company-scoped record within it; a direct Customer is a tenant with one company. Every tenant-scoped read and write routes through company-scoping helpers that require both the tenant and company identifiers so no company can access another company's data. There is no public, unauthenticated surface that exposes any tenant, company, or consumer data — the tamper-evident record and its exports are disclosed only to the Customer, who controls onward sharing.

5. Acceptable Use

5.1 No reverse engineering, no scraping, no building a competing product from the Service, no resale.

5.2 No Misrepresentation of a Legal Determination or Certification. You will not represent to any party (a regulator, an attorney general, a consumer, an auditor, an insurer, or any other party) that BreachDuty has determined, certified, or legally opined on your notification obligations, deadlines, or compliance, or that a deadline or obligation the Service computed is itself legal advice. The obligation map is a cited software output for your counsel to confirm; it is not an assessment, certification, or legal opinion by BreachDuty.

5.3 BreachDuty Is Not a Substitute for Counsel. You will not use the Service as a replacement for your own legal counsel's judgment. The Service is a workflow and record tool; your counsel decides whether and what to notify.

6. Service Outputs, Accuracy, and Disclaimers

6.1 Cited Software Output, Not a Legal Determination. The obligation map, computed deadlines, and regulator overlays the Service produces are software outputs computed from the facts you enter against a versioned statute library, each shown with its statutory citation. The Service does not generate, draft, or output breach-notification content. These outputs are not legal advice, a legal determination, a compliance certification, or a substitute for your counsel's judgment. You are solely responsible for the accuracy of the facts you enter and, together with your counsel, for whether and what to notify, and for drafting, assembling, and delivering every notice.

6.2 No Guarantee of Compliance. BreachDuty does not guarantee compliance with any law and does not guarantee that any obligation, deadline, regulator overlay, or notice the Service produces is correct, complete, current, or sufficient for your actual facts or for any regulator's, attorney general's, or court's requirements. Your obligations depend on facts only you and your counsel can assess.

6.3 The Correctness Discipline. Each deadline is computed from the statute version in force on the incident's discovery date. Statute content is effective-date-versioned; a statute amendment writes a new versioned entry and never overwrites a prior one, re-computation is explicit and logged, reminders fire exactly once, and amendment change-notices are sent to affected tenants (§8). Statute content is maintained on a per-release review cadence with independent counsel validation as a launch and per-release gate; until that gate clears, no statute surface is live and nothing is represented as counsel-validated. This discipline reduces, but does not eliminate, the risk of a stale or incorrect entry, and does not shift the responsibility in §6.1-6.2.

6.4 Implementation and Judgment Are the Customer's Responsibility. The Service documents and schedules the notification workflow from what the Customer's team enters. Actual compliance depends on the Customer acting — verifying the facts, obtaining its counsel's decision, and drafting and sending notices on time through its own systems. BreachDuty does not investigate the incident, decide the legal question, or draft, assemble, or send anything on the Customer's behalf.

6.5 No Autonomous Action. BreachDuty takes no autonomous action of its own: it does not generate, assemble, transmit, or send breach-notification content, and it will never send, transmit, or deliver a notice to any regulator, attorney general, or consumer on your behalf. Because a sent notice reaches a party outside your control once delivered, this is treated with our strictest no-autonomous-action posture — every notice-drafting, approval, and delivery step remains a Customer and Customer-counsel action, never a Service action.

7. The Tamper-Evident Record, Sealed Obligation-Map PDF, and Chain-of-Custody Export

7.1 Every material step in the workflow — incident opened, populations set, obligation computed, notice sent (self-reported by the Customer, since the Service does not itself draft, assemble, or send any notice), clock warning, incident closed — is written to a canonical, tamper-evident audit spine under the Customer's tenant.

7.2 The Customer can export a sealed obligation-map PDF (the incident's obligation map with running clocks and citations) and a chain-of-custody export of the full audit spine. These are data-integrity and record-keeping mechanisms: they document, timestamp, and preserve what the Customer's team did and when. They do not constitute a legal determination, certification, or endorsement by BreachDuty, and they do not represent that any obligation or deadline is correct as a matter of law.

7.3 There is no public, unauthenticated verification surface. The sealed record and its exports are disclosed to the Customer only. The Customer decides whether, and with whom (its counsel, a regulator, an insurer, an auditor), to share them; once shared or exported, a copy is the Customer's own.

7.4 A sealed obligation-map PDF, once generated, is retained as a record of the obligation map as it stood at seal time. If the incident's facts change and the map is recomputed, a new record is generated; the prior record is retained as a superseded record, not silently altered.

8. Intellectual Property

8.1 Service IP. We own the Service and its contents, including the statute library. Because the Service is scoped to the Obligation Atlas and timing clock only, BreachDuty does not maintain a notice-letter template set. The statute library is authored content owned by BreachDuty; the Customer receives a license to use it within the Service under its subscription, not to redistribute or resell it. No rights are granted except as expressly set forth.

8.2 Feedback. Standard perpetual-license grant on feedback.

8.3 Customer References. We may identify you as a customer (name, logo) on the customers page unless you opt out.

8.4 IP & Assignment Rider. An IP & Assignment Rider addressing ownership and assignment of intellectual property is incorporated by reference into these Terms and controls over this §8 and over §15.4 on the subjects within its scope.

8.5 Present assignment of Derivative IP. To the extent any Derivative IP would otherwise vest in Customer — by operation of law, under any work-made-for-hire or commissioned-work doctrine, because Customer's use, Inputs, or Feedback contributed to it, or on any other basis — Customer hereby irrevocably and presently assigns to Company all right, title, and interest in and to that Derivative IP, effective automatically upon its creation and without further action or consideration.

9. Privacy and Data Processing

9.1 Privacy Policy at breachduty.com/privacy. We are the controller for marketing-site visitors and Customer account/billing contacts, and the processor for the compliance data you place under your tenant. Where the Data Processing Addendum and these Terms conflict as to the processing of Customer Data, the DPA controls; this Privacy Policy is a notice, not a contracting instrument.

10. Suspension and Termination

10.1 By You. Cancel anytime; effective at the end of the paid monthly period. 10.2 By Us. Material breach, violation of §5 (Acceptable Use), or non-payment. 30 days' notice with pro rata refund for any discontinuation we initiate, paid within 30 days after the effective date of termination. 10.3 Effect. Customer Data deleted within 30 days of termination unless retention is required by law or export is requested. 10.4 Survival. Sections 4 (data), 6 (outputs/disclaimers), 8 (IP), 11 (Confidentiality), 12 (Warranties), 13 (Liability), 14 (Indemnification), 15 (General) survive.

11. Confidentiality

Treat all Customer Data as confidential information; standard confidentiality commitments; 5-year survival; trade-secret indefinite.

12. Warranties and Disclaimers

12.1 Limited Warranty. The Service performs substantially per documentation. Exclusive remedy: repair or pro rata refund.

12.2 Disclaimer. EXCEPT AS EXPRESSLY SET FORTH IN §12.1, THE SERVICE IS PROVIDED "AS IS." WE DISCLAIM ALL OTHER WARRANTIES, EXPRESS OR IMPLIED, INCLUDING WARRANTIES OF FITNESS FOR A PARTICULAR PURPOSE, ACCURACY, AND NON-INFRINGEMENT. WE DO NOT WARRANT THAT THE STATUTE LIBRARY IS CURRENT, COMPLETE, OR CORRECT FOR EVERY JURISDICTION AT EVERY MOMENT, THAT ANY COMPUTED DEADLINE OR OBLIGATION IS CORRECT AS A MATTER OF LAW, OR THAT THE SERVICE'S OUTPUTS WILL SATISFY ANY LAW, REGULATOR, ATTORNEY GENERAL, OR COURT.

12.3 No Warranty Re Compliance or Legal Outcome. We do not warrant that any obligation, deadline, regulator overlay, or notice the Service produces is correct, complete, current, or sufficient for your actual facts, or that use of the Service will result in compliance with any law, regulator, attorney general, or court requirement.

13. Limitation of Liability

13.1 TO THE MAXIMUM EXTENT PERMITTED BY LAW, NEITHER PARTY WILL BE LIABLE FOR INDIRECT, INCIDENTAL, CONSEQUENTIAL, SPECIAL, OR PUNITIVE DAMAGES, INCLUDING LOST PROFITS, LOST REVENUE, LOST DATA, OR ANY DAMAGES ARISING FROM A FAILED CONTRACT, DISQUALIFIED BID, REGULATORY ACTION, OR FCA PROCEEDING, EVEN IF ADVISED.

13.2 OUR TOTAL CUMULATIVE LIABILITY ARISING FROM OR RELATED TO THESE TERMS OR THE SERVICE WILL NOT EXCEED THE FEES YOU PAID US IN THE TWELVE MONTHS PRECEDING THE CLAIM.

13.3 No Liability for Regulatory or Enforcement Outcomes. We are not liable for any finding, inquiry, investigation, penalty, fine, or enforcement action by any regulatory, administrative, or enforcement body of any kind — including without limitation any state attorney general, state regulator, or federal agency — arising under any breach-notification statute or other applicable law or regulation, any missed deadline, or any liability arising from the Customer's or its counsel's notification decisions or from reliance on a statute entry, obligation, or deadline the Service produced. This carve-out is stated as broadly as possible and applies uniformly regardless of the specific statute, regulation, or regulatory or enforcement body involved; a party asserting that this carve-out does not apply to a particular claim, statute, or regulatory or enforcement body bears the burden of establishing that, rather than us bearing the burden of having disclaimed each one individually.

14. Indemnification

14.1 Stated in the contract you execute. Both indemnities — ours for IP infringement and yours — are stated in full on the face of §7 of the BreachDuty Engagement & Tiers SOW (breachduty.com/sow, "7. Indemnification — the executed-instrument provision"), together with the claim procedure. That §7 is the indemnification block carried on the face of the click-signed Order Form you accept at either tier, rendered above the agree control. Those provisions govern; this §14.1 is a cross-reference and does not restate them.

14.2 No separate indemnity. These Terms state no indemnification obligation separate from, additional to, or narrower than SOW §7, and nothing in these Terms enlarges or limits it. Where these Terms refer to the §14 indemnity (§10.4 survival), the reference is to SOW §7.

15. General Provisions

15.1 Governing Law. Colorado. The United Nations Convention on Contracts for the International Sale of Goods ("CISG") does not apply. 15.2 Disputes. Binding arbitration via JAMS in Boulder County, CO. Each party waives any right to a jury trial and to participation in any class, collective, or representative proceeding. Either party may seek injunctive relief in court for §5, §6, §8, or §11 breaches. 15.3 Notices, Force Majeure, Entire Agreement, Modifications (30-day), Severability, No Waiver, Independent Contractors. Standard. Written notice under these Terms (email to the billing contact or in-product notice) is deemed given when sent or first displayed; any notice period runs from that date, and failure to read a notice does not extend it. 15.4 Assignment; Change of Control. You may not assign, delegate, or transfer these Terms, in whole or in part, whether by operation of law, merger, or change of control, without our prior written consent; any attempted assignment in violation of this sentence is void. We may, without your consent and without notice except as any applicable data-protection law requires, assign or transfer these Terms and all of our rights and obligations under them, in whole or in part, (a) to a successor or acquirer in connection with a merger, acquisition, or sale of substantially all of our business or assets, or (b) to an affiliate, subsidiary, or newly formed entity in connection with a corporate conversion, reorganization, or contribution or drop-down of assets undertaken to effect a sale, reorganization, or transfer of the specific business line or product to which these Terms relate. Upon such an assignment, all of our rights under these Terms pass to the assignee, the assignee assumes our obligations arising after the assignment, and your continued use of the Service constitutes acknowledgment of the assignee as "BreachDuty" going forward. A change in our ownership, control, equity holders, or entity form is not a breach of, default under, or ground to terminate, suspend, renegotiate, or re-price these Terms, and does not trigger any right of termination, consent, first refusal, most-favored-nation, audit, or refund on your part. This §15.4 controls over any contrary term in a Customer purchase order or procurement addendum.

15.5 Regional and Supplemental Terms. No jurisdiction-specific supplemental term applies today. Where a supplemental jurisdiction-specific term applies, it controls over a conflicting general term of these Terms for that jurisdiction only.


16. Updates

30 days' email notice to the Customer billing contact for material changes. Notice is deemed given when sent; the 30-day period runs from the send date, and failure to read a notice does not extend it. Continued use after the effective date constitutes acceptance.

Contact

BreachDuty — Ellis Intelligence LLC Email: legal@ellisintel.com Address: 1500 N Grant St, Ste N, Denver, CO 80203, USA


BreachDuty is a product of Ellis Intelligence LLC. BreachDuty is software, not a law firm, lawyer, or compliance authority; this is general information, not legal advice — your own counsel decides whether and what to notify. See also our Privacy Policy. Questions about this document? Email legal@ellisintel.com.