These Terms of Service (the “Terms”) govern access to and use of the Incendium platform and related services provided by Incendium AI Ltd, a company registered in England and Wales under company number 12277864, with its registered office at 27 Old Gloucester Street, London, United Kingdom, WC1N 3AX (“Incendium”, “Company”, “we”, “us” or “our”).
These Terms form a legally binding agreement between Incendium and the individual or entity that creates an account, purchases a subscription, or otherwise accepts these Terms (“Client”, “you” or “your”).
If you accept these Terms on behalf of a company or other organisation, you represent that you have authority to bind that organisation.
1. Commercial Use and Eligibility
1.1. The Service is intended for ecommerce businesses, business-to-business organisations, agencies, sole traders and other commercial or professional users.
1.2. By accepting these Terms, you confirm that you are acting wholly or mainly for purposes relating to your trade, business, craft or profession and not for personal, family or household purposes as a consumer.
1.3. The Service is not offered for personal, family or household use.
2. Acceptance and Effective Date
2.1. These Terms become effective when you first indicate acceptance through the Incendium platform, including by selecting a checkbox, clicking a button or other control that states that you accept or agree to these Terms, activating or purchasing a subscription where these Terms are clearly presented, or logging in after being shown a conspicuous notice that logging in constitutes acceptance of these Terms together with a reasonably accessible link to them (the “Effective Date”).
2.2. If you accept these Terms through another part of the Platform, an Order, an onboarding flow or an integration flow, that acceptance applies to your access to and use of the Service generally unless the relevant acceptance mechanism expressly states otherwise.
2.3. You may not use the Service if you do not agree to these Terms.
2.4. Where Incendium requires renewed acceptance following a material update to these Terms, continued access may be suspended until that acceptance is provided.
3. The Service
3.1. Incendium provides a proprietary software-as-a-service platform available through incendium.ai and related domains, applications and integrations (the “Platform”).
3.2. The Platform may include analytics, attribution, reporting, optimisation, experimentation, personalisation, data processing, integrations, artificial intelligence, automation, recommendations and related functionality, together with any support or professional services specifically included in your subscription or order (collectively, the “Service”).
3.3. The exact features, usage allowances, service levels, websites, accounts, data retention periods, support entitlements, expressly agreed service guarantees and other plan-specific inclusions applicable to you are those shown on the applicable pricing page, checkout page, subscription page, order form, service agreement or statement of work at the time of purchase (each an “Order”).
3.4. If there is a conflict between these Terms and an Order signed or expressly accepted by both parties, the Order will prevail only to the extent of that conflict.
3.5. Incendium may improve, modify or replace features of the Service from time to time, provided that it does not materially reduce the core functionality of a paid Service during an active paid subscription period without reasonable notice.
4. Accounts
4.1. You must provide accurate, complete and current account information.
4.2. You are responsible for:
- maintaining the confidentiality and security of your login credentials;
- all activity carried out through your account;
- ensuring that authorised users comply with these Terms; and
- notifying Incendium promptly if you become aware of unauthorised access, compromise or misuse.
4.3. You must not share individual login credentials except where the applicable plan expressly permits shared access.
4.4. Incendium may require additional authentication, password resets or other reasonable security measures where we believe an account may be compromised.
5. Licence and Permitted Use
5.1. Subject to these Terms and payment of all applicable Charges, Incendium grants you a limited, non-exclusive, non-transferable, non-sublicensable right during the subscription term to access and use the Service for your internal business purposes and, where your plan permits agency use, for the benefit of authorised End Clients.
5.2. Except where expressly permitted in writing, you must not:
- copy, modify, reproduce, distribute, sell, lease, sublicense or commercially exploit the Platform;
- reverse engineer, decompile, disassemble or attempt to discover source code or underlying algorithms, except to the extent such restriction is prohibited by law;
- circumvent or attempt to circumvent security, usage, technical or billing controls;
- access the Service for the primary purpose of building or benchmarking a competing product;
- use automated means to scrape or extract data from the Platform other than through functionality or APIs expressly made available by Incendium;
- introduce malicious code, harmful content or material designed to interfere with the Service;
- use the Service unlawfully or in a manner that infringes the rights of another person; or
- permit any third party to use the Service except as expressly authorised under your plan or these Terms.
6. Usage Limits
6.1. Your subscription may be subject to limits including pageviews, events, revenue, websites, stores, users, data volume, API requests, storage, retention, artificial-intelligence usage or other consumption measures specified in your Order.
6.2. You are responsible for monitoring your usage.
6.3. If you approach or exceed an applicable limit, Incendium may, where reasonably practicable:
- notify you;
- offer an upgrade or additional capacity;
- charge agreed overage fees;
- limit or pause affected functionality; or
- suspend collection or processing until the next billing period or until additional capacity is purchased.
6.4. Where data storage or retention limits are exceeded and you do not upgrade or take corrective action after reasonable notice, Incendium may archive, restrict or delete data exceeding the applicable limit, to the extent permitted by law.
7. Charges, Billing and Taxes
7.1. Subscription fees and other charges (the “Charges”) are those shown in your Order.
7.2. Unless otherwise stated in the Order:
- subscription Charges are billed in advance;
- subscriptions renew automatically for successive periods equal to the original billing period;
- Charges are payable in the currency displayed at checkout or in the Order; and
- Charges exclude VAT, sales tax, withholding tax and similar taxes, which will be added where applicable.
7.3. By providing a payment method, you authorise Incendium and its payment providers to collect Charges when due.
7.4. If payment fails, Incendium may suspend the Service until payment is successfully processed.
7.5. Incendium may terminate the affected subscription if an overdue amount remains unpaid for 15 days after notice of failed payment.
7.6. Any billing dispute must be raised promptly and, where practicable, within 30 days of the relevant charge.
7.7. Except where required by law or expressly agreed otherwise, Charges already paid are non-refundable and cancellations take effect at the end of the current paid subscription period.
8. Renewal and Cancellation
8.1. Your subscription will automatically renew unless cancelled before the next renewal date through the Platform or by another cancellation method made available by Incendium.
8.2. Cancellation does not normally take effect immediately. Unless your Order states otherwise, you will retain access until the end of the subscription period already paid for.
8.3. Incendium may change subscription Charges for a future renewal period by giving at least 30 days' notice before the new price takes effect.
8.4. If you do not agree to a price change, you may cancel before the new price takes effect.
9. Customer Data
9.1. “Customer Data” means data, information, content or material submitted to, collected through, imported into or otherwise made available to the Service by or on behalf of you, including website, ecommerce, marketing, customer, transaction, account, event and campaign data.
9.2. As between the parties, you retain ownership of Customer Data.
9.3. You grant Incendium and its authorised subprocessors a non-exclusive right to host, copy, transmit, process, analyse, transform and otherwise use Customer Data only as reasonably necessary to:
- provide, maintain, secure and support the Service;
- comply with your instructions;
- prevent fraud, abuse and security incidents;
- comply with applicable law; and
- exercise rights expressly granted under these Terms.
9.4. You are responsible for the accuracy, quality, legality and origin of Customer Data and for ensuring that you have all rights, permissions, notices, consents and lawful bases necessary for Incendium to process it.
9.5. Unless Incendium has expressly approved the relevant processing in a written Order, you must not submit to, collect through or configure the Service to process:
- special-category Personal Data under the UK GDPR or EU GDPR;
- health, medical, biometric or genetic information;
- full payment-card numbers, card verification codes, payment authentication credentials or other data subject to PCI DSS, except for tokens or limited payment information processed through an integration expressly supported by Incendium; or
- Personal Data relating to children, meaning individuals under 16 years of age for the purposes of this Section.
9.6. Any approval under Section 9.5 may be subject to additional technical, security, compliance, pricing and contractual requirements specified by Incendium.
10. Aggregated and De-Identified Data
10.1. Incendium may generate aggregated, anonymised or de-identified information derived from use of the Service and Customer Data, provided that such information does not reasonably identify you, an End Client or any individual.
10.2. Incendium may use such information for:
- benchmarking;
- statistical analysis;
- research;
- service improvement;
- performance analysis;
- security;
- product development; and
- development and improvement of machine-learning and artificial-intelligence systems.
10.3. Incendium owns all rights in aggregated, anonymised and de-identified information that no longer identifies you, an End Client or an individual.
10.4. Incendium will not use identifiable Customer Data or Google User Data to create, train or improve a general-purpose or shared machine-learning or artificial-intelligence model. This does not prevent Incendium from processing Customer Data to provide a customer-facing artificial-intelligence feature in accordance with your documented instructions, or from using aggregated, anonymised or de-identified information as permitted by this Section.
11. Data Protection and Privacy
11.1. Each party will comply with applicable data protection, privacy, electronic communications, cookie, consent and marketing laws that apply to its activities.
11.2. Depending on the processing involved, this may include the UK GDPR, EU GDPR, Data Protection Act 2018, PECR, ePrivacy rules, CCPA/CPRA, the Australian Privacy Act 1988 (Cth), the Australian Privacy Principles and equivalent laws.
11.3. Where Incendium processes Personal Data on your behalf as a processor or service provider, the Data Processing Addendum in Appendix 1 forms part of these Terms.
11.4. You are responsible for ensuring that your use of the Service, and any use on behalf of an End Client:
- has a lawful basis;
- is covered by appropriate privacy notices;
- uses consent-management tools appropriately;
- obtains and maintains any consent required by law;
- honours applicable opt-out or objection rights; and
- otherwise complies with applicable privacy and electronic-communications laws.
11.5. Incendium is not responsible for determining whether your particular configuration, tracking implementation, marketing activity or legal basis is compliant with laws applicable to you.
11.6. For account administration, billing, security, fraud and abuse prevention, service telemetry, support correspondence, legal compliance and the creation and use of aggregated, anonymised or de-identified information, Incendium may act as an independent controller. Such processing is governed by the Privacy Policy and applicable law.
11.7. If applicable law determines that the parties are joint controllers for a specific processing activity, the parties will cooperate in good faith to document and allocate the responsibilities required by that law. Nothing in these Terms predetermines a party's role contrary to the facts of the relevant processing.
12. Agency and End Client Use
12.1. If your subscription permits you to use the Service for customers or clients of your business (“End Clients”), you remain responsible to Incendium for all activity carried out on behalf of those End Clients.
12.2. You must ensure that each End Client has granted all permissions and rights necessary for you to connect its websites, stores, advertising accounts, customer data and other systems to the Service.
12.3. You are responsible for ensuring that each End Client's use of the Service and collection, disclosure, transfer and processing of data complies with applicable law.
12.4. Unless Incendium enters into a separate agreement directly with an End Client, Incendium has no contractual relationship with that End Client.
12.5. An agreement between you and an End Client does not reduce or modify your obligations to Incendium.
13. Customer Indemnity
13.1. To the fullest extent permitted by law, you will indemnify and hold harmless Incendium and its officers, employees and affiliates from third-party claims, regulatory claims, losses, liabilities, damages, fines and penalties to the extent lawfully recoverable, and reasonable external legal costs arising out of or relating to:
- Customer Data supplied or made available by you;
- your or an End Client's unlawful collection, disclosure, use or processing of data;
- your breach of Sections 5, 9, 11 or 12;
- your infringement of third-party intellectual-property, privacy or other rights; or
- your or an End Client's misuse of the Service.
13.2. The indemnity in this Section does not apply to the extent the relevant claim was caused by Incendium's own breach of these Terms or applicable law.
13.3. Incendium will provide reasonable notice of an indemnified claim and reasonable cooperation at your cost. You may not settle a claim in a manner that admits liability by Incendium or imposes non-monetary obligations on Incendium without Incendium's prior written consent.
14. Intellectual Property
14.1. Incendium and its licensors retain all rights, title and interest in and to:
- the Platform;
- software, source code, object code and algorithms;
- models, methodologies, frameworks and scoring systems;
- templates, interfaces and workflows;
- documentation;
- know-how, trade secrets and inventions;
- aggregated and de-identified information;
- improvements and derivative works; and
- all related intellectual-property rights (collectively, “Incendium IP”).
14.2. No rights in Incendium IP are transferred to you except for the limited licence expressly granted under these Terms.
14.3. Where Incendium provides reports, recommendations, analyses, presentations or other outputs specifically for you as part of the Service, you may use those outputs for your internal business purposes.
14.4. Unless an Order expressly states otherwise, Incendium retains ownership of underlying templates, systems, methodologies, reusable materials, know-how and tools used to create those outputs.
14.5. If a separately agreed professional-services Order expressly provides that ownership of a bespoke deliverable transfers to you, that transfer does not include Incendium IP, pre-existing materials, generic know-how, reusable components or third-party materials.
15. Feedback
15.1. If you provide suggestions, ideas or feedback regarding the Service, you grant Incendium a perpetual, worldwide, royalty-free right to use that feedback without restriction or obligation, provided that Incendium does not publicly identify you as its source without permission.
16. Third-Party Services and Integrations
16.1. The Service may connect with or depend on third-party platforms, APIs, hosting providers, payment processors, ecommerce platforms, advertising platforms, analytics providers, telecommunications providers and other external services (“Third-Party Services”).
16.2. Third-Party Services are not controlled by Incendium and may change, restrict, suspend or discontinue functionality at any time.
16.3. Incendium is not responsible for:
- downtime, faults or acts or omissions of a Third-Party Service;
- changes to a third-party API, platform, policy or data model;
- inaccurate, delayed or incomplete information supplied by a Third-Party Service;
- loss caused by suspension or termination of your third-party account; or
- third-party terms, charges or compliance obligations.
16.4. Your use of a Third-Party Service remains subject to that provider's terms and policies.
17. Google API Data
17.1. Where Incendium receives information from Google APIs (“Google User Data”), Incendium's access, use, storage and transfer of that information will comply with the Google API Services User Data Policy, including applicable Limited Use requirements.
17.2. Incendium will access and use Google User Data only to provide or improve user-facing features that are prominent in the Service and that the relevant user has requested or authorised.
17.3. Incendium will not use or transfer Google User Data for personalised advertising, advertising profiles, retargeting or other advertising purposes prohibited by the Google API Services User Data Policy.
17.4. Incendium will not permit a person to read Google User Data except where the user has given affirmative permission for specific data, where access is reasonably necessary for security or legal compliance, or where the data has first been aggregated and de-identified in accordance with the Google API Services User Data Policy.
17.5. Incendium may transfer Google User Data only where permitted by the Google API Services User Data Policy, including to provide or improve requested features, for security purposes, to comply with applicable law, or as part of a transaction permitted by that policy and subject to appropriate protections.
17.6. Further information about Incendium's handling of Google User Data is provided in the Privacy Policy.
18. Analytics, Attribution, Recommendations and AI Outputs
18.1. The Service provides analytical, statistical, attributional, predictive, optimisation and artificial-intelligence functionality.
18.2. Outputs may depend on incomplete, delayed, modelled, sampled, probabilistic or third-party data.
18.3. Except to the extent expressly provided in an Order or a separate written service guarantee accepted by Incendium (a “Specific Service Guarantee”), attribution models, forecasts, scores, recommendations, benchmarks, estimated values, artificial-intelligence outputs and similar information are provided as analytical tools and are not guarantees of:
- revenue;
- profit;
- advertising performance;
- conversion performance;
- customer behaviour;
- legal compliance;
- future results; or
- any particular commercial outcome.
18.4. You remain responsible for business, financial, marketing, advertising, operational and legal decisions made using information from the Service.
18.5. You should independently assess material decisions and should not treat automated recommendations or AI-generated outputs as professional legal, financial, accounting or other regulated advice.
19. Beta, Preview and Experimental Features
19.1. Incendium may make beta, preview, experimental, early-access or similar features available from time to time.
19.2. Such features may be incomplete, changed or discontinued at any time and may be subject to additional terms.
19.3. Unless expressly stated otherwise, beta or experimental functionality is provided without commitments regarding availability, accuracy, performance, support or continued release.
20. Availability, Security and Support
20.1. Incendium will use commercially reasonable efforts to operate the Service reliably and securely.
20.2. Unless an applicable Order or service-level agreement expressly states otherwise, Incendium does not guarantee that the Service will:
- be uninterrupted;
- be error-free;
- be available at all times;
- be completely secure; or
- meet any particular uptime target.
20.3. Incendium may suspend access where reasonably necessary for:
- maintenance;
- security;
- prevention of abuse;
- legal compliance;
- non-payment;
- excessive usage; or
- protection of the Service, Incendium, you or other customers.
20.4. Where reasonably practicable, Incendium will provide advance notice of planned material interruptions.
21. Data Retention, Export and Deletion
21.1. Data retention periods are determined by your Order, plan and applicable product configuration.
21.2. You are responsible for exporting data you wish to retain before the end of your subscription or applicable retention period and, where necessary, using the limited post-termination export right in Section 21.3.
21.3. After termination, Incendium may restrict interactive access to the Service immediately. For 30 days after termination, you may make a written request for Incendium to provide a reasonable opportunity to use then-current standard export functionality or, where reasonably available, to provide Customer Data in Incendium's then-current standard export format. This limited right does not require Incendium to reactivate the Service, provide continued interactive access or perform custom export work. Incendium may refuse or limit an export to the extent required by law or reasonably necessary to address a material security, confidentiality or integrity risk.
21.4. Incendium may permanently delete Customer Data after that 30-day period, unless:
- a different retention period is stated in the Order;
- applicable law requires longer retention; or
- the parties agree otherwise in writing.
21.5. Incendium may retain limited account, billing, security, audit and legal records where required or reasonably necessary for legitimate business or legal purposes.
22. Backup and Data Loss
22.1. Incendium will maintain reasonable technical and organisational measures designed to protect Customer Data.
22.2. No online service can guarantee against all loss, corruption, unauthorised access or service interruption.
22.3. To the fullest extent permitted by law, Incendium is not responsible for loss, alteration or corruption of Customer Data caused by:
- you;
- an End Client;
- a Third-Party Service selected or controlled by you;
- failure to remain within applicable plan or storage limits; or
- events outside Incendium's reasonable control.
22.4. Where Customer Data is lost or damaged due to an incident within systems controlled by Incendium, Incendium's primary obligation will be to use reasonable commercial efforts to restore available data from the most recent usable backup, where technically feasible.
23. Confidentiality
23.1. “Confidential Information” means non-public information disclosed by one party to the other that is identified as confidential or that reasonably should be understood to be confidential because of its nature or the circumstances of disclosure.
23.2. Confidential Information includes non-public product information, customer information, supplier information, pricing, business plans, technology, testing data, research, security information, trade secrets and Customer Data.
23.3. Each receiving party will:
- use Confidential Information only as necessary to perform or receive the Service;
- protect it using at least reasonable care;
- disclose it only to personnel, professional advisers, affiliates and subcontractors who need to know it and are subject to appropriate confidentiality obligations; and
- not disclose it to any other third party except as permitted by these Terms or required by law.
23.4. Confidentiality obligations do not apply to information that the receiving party can demonstrate:
- was lawfully known without restriction before disclosure;
- becomes public through no breach by the receiving party;
- is lawfully received from a third party without confidentiality restriction; or
- is independently developed without use of the disclosing party's Confidential Information.
23.5. If disclosure is required by law, the receiving party may disclose the minimum legally required amount and, where legally permitted, will provide reasonable prior notice.
23.6. The obligations in this Section continue for five years after termination, except that obligations relating to trade secrets continue for so long as the information remains a trade secret under applicable law.
24. Publicity
24.1. Incendium will not publish a customer case study, use your name or logo as a customer endorsement, or publicly disclose confidential performance results without your prior written permission.
24.2. This does not prevent Incendium from making disclosures required by law or from using aggregated and de-identified information as permitted under Section 10.
25. Warranties
25.1. Each party warrants that it has authority to enter into these Terms.
25.2. Incendium warrants that it will provide the Service with reasonable skill and care.
25.3. Except as expressly stated in these Terms, and to the fullest extent permitted by law, all warranties, conditions and other terms implied by statute, common law or otherwise are excluded.
25.4. The Service is otherwise provided on an “as is” and “as available” basis.
26. Limitation of Liability
26.1. Nothing in these Terms excludes or limits liability to the extent that such liability cannot lawfully be excluded or limited, including liability for:
- death or personal injury caused by negligence;
- fraud or fraudulent misrepresentation; or
- any other liability that applicable law prohibits from being excluded or limited.
26.2. Subject to Section 26.1, neither party will be liable to the other, whether in contract, tort (including negligence), breach of statutory duty, misrepresentation or otherwise, for:
- loss of profit;
- loss of revenue;
- loss of business;
- loss of anticipated savings;
- loss of opportunity;
- loss of goodwill;
- wasted expenditure;
- loss, corruption or destruction of data; or
- any indirect, special or consequential loss, in each case arising out of or in connection with the Service or these Terms, whether or not foreseeable.
26.3. Without limiting Section 26.2, Incendium will not be liable for losses arising from:
- a decision made in reliance on analytics, attribution, reporting, recommendations or AI outputs;
- inaccurate, delayed or incomplete data supplied by you or a Third-Party Service;
- interruption, suspension, failure or change of a Third-Party Service;
- unauthorised access caused by your failure to secure credentials or systems under your control;
- use of the Service contrary to documentation, these Terms or Incendium's reasonable instructions; or
- events outside Incendium's reasonable control.
26.4. Subject to Sections 26.1 and 26.5, the total aggregate liability of Incendium arising out of or in connection with the Service, these Terms and all applicable Orders, whether in contract, tort (including negligence), breach of statutory duty, misrepresentation or otherwise, will not exceed the total Charges paid or payable by you to Incendium during the 12 months immediately preceding the event giving rise to the claim.
26.5. Nothing in this Section limits:
- your obligation to pay Charges properly due;
- liability arising from your infringement or misappropriation of Incendium IP; or
- liability under your indemnity obligations to the extent such limitation is prohibited or expressly stated not to apply in an applicable Order.
26.6. The parties agree that the limitations and exclusions in this Section are reasonable having regard to the nature and price of the Service and the availability of insurance and alternative services.
27. Suspension and Termination
27.1. You may cancel a subscription in accordance with Section 8. Incendium may elect not to renew a subscription by giving reasonable notice before the next renewal date.
27.2. Incendium may suspend or terminate the Service immediately, or on such notice as is reasonable in the circumstances, if:
- you fail to pay Charges when due;
- you materially breach these Terms;
- your use presents a security, legal or operational risk;
- your use may cause harm to Incendium, the Service, another customer or a third party;
- you become insolvent or cease carrying on business; or
- Incendium is required to do so by law or a competent authority.
27.3. If a material breach is capable of remedy, Incendium will ordinarily provide a reasonable opportunity to remedy it before termination, unless immediate action is reasonably necessary.
27.4. You may terminate these Terms if Incendium commits a material breach that remains unremedied for 14 days after receiving written notice describing the breach.
27.5. On termination:
- your right to interactive access to the Service ends, subject to the limited export and return rights in Section 21 and Appendix 1;
- outstanding Charges become immediately due;
- data will be handled in accordance with Section 21 and Appendix 1; and
- provisions intended by their nature to survive will continue, including Sections relating to payment, intellectual property, confidentiality, indemnities, liability, data, governing law and dispute resolution.
28. Force Majeure
28.1. Neither party will be liable for delay or failure to perform caused by events beyond its reasonable control, including natural disasters, severe weather, war, terrorism, civil disorder, labour disputes, internet or telecommunications failures, government action, widespread cloud or infrastructure failures, or failures of material third-party providers.
28.2. The affected party will use reasonable efforts to mitigate the impact.
28.3. If a Force Majeure Event materially prevents the Service for more than 60 consecutive days, either party may terminate the affected subscription by written notice.
29. Changes to These Terms
29.1. Incendium may update these Terms from time to time.
29.2. If a change is material, Incendium will provide reasonable advance notice, normally at least 30 days, through the Platform, by email, or by another reasonable method.
29.3. Changes required by law, regulation, security necessity or urgent operational circumstances may take effect sooner.
29.4. If a material change materially reduces your contractual rights or materially increases your obligations during a prepaid subscription period, you may terminate the affected subscription before the change takes effect by giving notice to Incendium. Incendium will refund the Charges prepaid for the unused portion of the terminated subscription period, calculated from the effective date of termination.
29.5. Section 29.4 does not apply to a change that is required by law, necessary to address an urgent security or abuse risk, or made at your request, provided that Incendium limits the change to what is reasonably necessary in the circumstances.
29.6. Continued use of the Service after the effective date of updated Terms constitutes acceptance to the extent permitted by law and only where reasonable notice of the update and access to the updated Terms have been provided. Incendium may require affirmative re-acceptance of material changes.
30. Notices
30.1. Operational and account notices may be given through the Platform, by email, or using contact details associated with your account.
30.2. You are responsible for keeping your contact details current.
30.3. Formal legal notices to Incendium must be sent to its registered office stated at the beginning of these Terms and may also be sent through any legal-notice contact method published on the Incendium website.
30.4. Formal notices to you may be sent to the primary account email address or registered business address associated with your account.
31. Assignment
31.1. You may not assign, transfer or novate these Terms without Incendium's prior written consent, not to be unreasonably withheld.
31.2. Incendium may assign, transfer or novate these Terms to an affiliate or in connection with a merger, reorganisation, financing, sale of assets, sale of business or change of control, provided that doing so does not materially reduce your rights under an active paid subscription.
32. Relationship of the Parties
32.1. The parties are independent contractors.
32.2. Nothing in these Terms creates a partnership, joint venture, employment, fiduciary or agency relationship between the parties.
32.3. Neither party may bind the other except where expressly authorised in writing.
33. Entire Agreement and Order of Precedence
33.1. These Terms, together with applicable Orders, Appendix 1, and any documents expressly incorporated by reference, form the entire agreement between the parties regarding the Service and replace prior agreements, proposals and representations relating to the same subject matter.
33.2. Each party acknowledges that it has not relied on any statement not expressly included in the agreement, except that nothing in this Section excludes liability for fraud or fraudulent misrepresentation.
33.3. In the event of conflict, the following order of precedence applies unless expressly agreed otherwise:
- a Specific Service Guarantee, but only in relation to the guarantee it expressly provides;
- a signed or expressly accepted Order;
- Appendix 1, but only in relation to processing of Personal Data;
- these Terms; and
- product documentation or policies incorporated by reference.
34. No Waiver
34.1. A failure or delay to exercise a right does not waive that right.
34.2. A waiver is effective only if made in writing and applies only to the specific circumstance for which it is given.
35. Severability
35.1. If any provision of these Terms is held invalid, unlawful or unenforceable, it will be modified to the minimum extent necessary to make it enforceable or, if that is not possible, severed.
35.2. The remaining provisions will continue in full force.
36. Third-Party Rights
36.1. Except as provided in Section 36.2, a person who is not a party to these Terms has no right to enforce any provision under the Contracts (Rights of Third Parties) Act 1999.
36.2. Incendium's officers, employees and affiliates identified in Section 13.1 may enforce Section 13 under the Contracts (Rights of Third Parties) Act 1999. Their rights are subject to all relevant terms, limitations and defences in these Terms. The parties may rescind or vary these Terms without the consent of any such person.
37. Governing Law and Jurisdiction
37.1. These Terms and any non-contractual obligations arising out of or in connection with them are governed by the laws of England and Wales.
37.2. The courts of England and Wales have exclusive jurisdiction to settle disputes arising out of or in connection with these Terms, subject to either party's right to seek urgent interim or injunctive relief in any court of competent jurisdiction.
37.3. Nothing in these Terms excludes, restricts or modifies any consumer guarantee, right or remedy under the Australian Consumer Law that cannot lawfully be excluded, restricted or modified.
37.4. Where the Australian Consumer Law applies to a supply of services that are not services of a kind ordinarily acquired for personal, domestic or household use or consumption, and it is fair and reasonable and otherwise lawful to do so, Incendium's liability for failure to comply with an applicable guarantee is limited, at Incendium's option, to supplying the services again or paying the cost of having the services supplied again.
38. Contact
Questions about these Terms may be submitted through the contact methods published on the Incendium website.
Appendix 1: Data Processing Addendum
This Data Processing Addendum (“DPA”) forms part of the Incendium Terms of Service where Incendium processes Personal Data on behalf of the Client.
1. Definitions
For this DPA:
Applicable Data Protection Law means all data protection and privacy laws applicable to the relevant processing, which may include the UK GDPR, EU GDPR, Data Protection Act 2018, PECR, CCPA/CPRA, the Australian Privacy Act 1988 (Cth), the Australian Privacy Principles and equivalent laws.
Controller, Processor, Data Subject, Personal Data, Personal Data Breach and Processing have the meanings given under applicable data protection law.
Subprocessor means a third party appointed by Incendium to process Personal Data on behalf of the Client.
Capitalised terms not defined in this DPA have the meanings given in the Terms.
2. Roles of the Parties
2.1. Where Incendium processes Personal Data on behalf of the Client, the Client acts as Controller and Incendium acts as Processor, unless applicable law characterises the relationship differently.
2.2. Where the Client acts as a processor for an End Client, the Client appoints Incendium as its subprocessor and confirms that it is authorised to do so.
2.3. The Client determines the purposes of processing and remains responsible for:
- establishing a lawful basis;
- providing required notices;
- obtaining required consents;
- issuing lawful processing instructions; and
- complying with its obligations as Controller or processor.
3. Subject Matter and Details of Processing
3.1. Subject matter: processing necessary to provide the Service.
3.2. Duration: for the term of the applicable subscription plus any limited retention period permitted by the Terms or required by law.
3.3. Nature of processing: collection, recording, organisation, storage, structuring, retrieval, consultation, analysis, attribution, segmentation, transmission, export, deletion and other processing necessary to provide the Service.
3.4. Purposes: providing analytics, attribution, reporting, optimisation, experimentation, personalisation, integrations, account functionality, support, security and related features selected or configured by the Client.
3.5. Categories of Data Subjects: may include the Client's and End Clients':
- website visitors;
- prospects;
- customers;
- users;
- employees;
- contractors; and
- other individuals whose data is submitted to or collected through the Service.
3.6. Types of Personal Data: may include:
- online identifiers;
- device and browser information;
- IP-derived or pseudonymous identifiers;
- website and application activity;
- marketing interactions;
- campaign and attribution data;
- ecommerce orders and transaction information;
- account and contact information;
- product interests;
- conversion activity; and
- other Personal Data the Client instructs Incendium to process.
3.7. The Service is not intended for the routine processing of special-category or highly sensitive Personal Data unless Incendium has expressly agreed to such processing in writing.
4. Processing Instructions
4.1. Incendium will process Personal Data only:
- to provide the Service;
- on documented instructions from the Client;
- as otherwise expressly permitted by the agreement; or
- where required by applicable law, in which case Incendium will inform the Client of the legal requirement before processing unless that law prohibits the information on important grounds of public interest.
4.2. The Terms, the Client's configuration of the Service and authorised support requests constitute documented instructions.
4.3. If Incendium reasonably believes an instruction infringes Applicable Data Protection Law, it will immediately inform the Client and may suspend only the affected processing until the issue is resolved.
5. Confidentiality
5.1. Incendium will ensure that persons authorised to process Personal Data are subject to appropriate confidentiality obligations.
6. Security
6.1. Incendium will maintain appropriate technical and organisational measures designed to provide a level of security appropriate to the risk.
6.2. Measures may include, as appropriate:
- access controls;
- encryption or pseudonymisation;
- data minimisation;
- resilience and availability controls;
- backup and recovery processes;
- logging and monitoring;
- vulnerability and security management; and
- periodic review of security controls.
6.3. Security measures may evolve over time as technology, risk and the Service develop, provided that Incendium does not materially reduce the overall level of protection during an active subscription.
6.4. Incendium maintains more detailed security and technical and organisational measures documentation. Relevant portions will be made available to the Client on reasonable request, subject to appropriate confidentiality, access-control and security restrictions. Incendium may provide the documentation through a controlled review process or under a non-disclosure agreement where reasonably necessary to protect the security of the Service and other customers.
7. Subprocessors
7.1. The Client gives Incendium general written authorisation to appoint Subprocessors to support delivery of the Service.
7.2. Incendium's current material Subprocessors are identified in Schedule 1 to this DPA. Incendium may also maintain the list through a page, document or other location made available to the Client.
7.3. Incendium will appoint each Subprocessor under a written agreement that imposes the same data-protection obligations required by Article 28 of the UK GDPR or EU GDPR, as applicable, or obligations that provide an equivalent level of protection for the Personal Data. The Subprocessor agreement need not reproduce the commercial terms of the agreement between Incendium and the Client.
7.4. Incendium will provide reasonable advance notice of an intended addition or replacement of a material Subprocessor through the Platform, by email, or through a stable webpage or document made available to the Client. If an urgent change is reasonably necessary for security, legal compliance, service availability or provider discontinuation and advance notice is not reasonably practicable, Incendium will provide notice as soon as reasonably practicable.
7.5. If the Client reasonably objects to a new Subprocessor on genuine data-protection grounds, the parties will work in good faith to find a commercially reasonable solution. If no reasonable solution is available, either party may terminate the affected Service.
7.6. Incendium remains responsible for the performance of its Subprocessors to the extent required by applicable law.
8. Data Subject Requests
8.1. If Incendium receives a request directly from a Data Subject relating to Personal Data processed on behalf of the Client, Incendium will, where appropriate:
- direct the request to the Client;
- notify the Client; and
- provide reasonable assistance taking into account the nature of processing and information available to Incendium.
8.2. Incendium will not independently respond to a Data Subject request on the Client's behalf unless instructed by the Client or required by law.
9. Assistance and Compliance
9.1. Taking into account the nature of processing and information available to Incendium, Incendium will provide reasonable assistance with:
- Data Subject rights;
- data-protection impact assessments;
- consultations with supervisory authorities;
- security obligations; and
- other processor obligations imposed by applicable law.
9.2. Where assistance requires material work beyond normal operation of the Service, Incendium may charge reasonable fees after notifying the Client in advance.
10. Personal Data Breach
10.1. Incendium will notify the Client without undue delay after becoming aware of a Personal Data Breach affecting Personal Data processed on behalf of the Client.
10.2. Where available, the notice will include information reasonably necessary for the Client to comply with applicable breach-notification obligations, including:
- the nature of the breach;
- affected categories of Data Subjects and records;
- likely consequences; and
- measures taken or proposed to address and mitigate the breach.
10.3. Incendium's notification of a breach does not constitute an admission of fault or liability.
11. International Transfers
11.1. Incendium uses regional core application environments. The primary application database, application storage and backups for Clients provisioned in the United Kingdom or European Economic Area region are hosted in Frankfurt, Germany. The equivalent systems for Clients provisioned in the United States region are hosted in the United States, and the equivalent systems for Clients provisioned in the Australian region are hosted in Australia.
11.2. Limited Personal Data may also be processed by authorised Subprocessors for edge delivery, network security, error monitoring, transactional email, AI functionality or support correspondence. Such processing may occur in other locations used by the relevant Subprocessor. Incendium will use available regional controls where reasonably appropriate and will implement any transfer mechanism and assessment required by Applicable Data Protection Law before making a restricted international transfer.
11.3. Before Incendium initiates a restricted international transfer that is not covered by an adequacy decision or another lawful exception, Incendium will ensure that the applicable lawful transfer mechanism is in place and complete any assessment required by Applicable Data Protection Law. The mechanism may include:
- an adequacy decision;
- the European Commission Standard Contractual Clauses;
- the UK International Data Transfer Addendum;
- the UK International Data Transfer Agreement; or
- another legally recognised transfer mechanism.
11.4. Where Incendium initiates a restricted transfer to a Subprocessor, Incendium will enter into the applicable European Commission Standard Contractual Clauses, UK International Data Transfer Addendum or UK International Data Transfer Agreement directly with that Subprocessor, or ensure that another lawful transfer mechanism applies, before the restricted transfer begins. Incendium will provide information about the relevant mechanism on reasonable request, subject to appropriate confidentiality and security restrictions.
11.5. Where the Client initiates a restricted transfer directly to Incendium and a transfer mechanism is required, the parties will complete the applicable European Commission Standard Contractual Clauses, UK International Data Transfer Addendum, UK International Data Transfer Agreement or other lawful mechanism before that transfer begins.
11.6. Nothing in this Section authorises a restricted transfer before the required mechanism, transfer details, assessment and any necessary supplementary measures are in place.
12. CCPA/CPRA and Similar Laws
12.1. Where Incendium processes Personal Data subject to laws that use the concepts of a service provider, contractor or processor, Incendium will act in that capacity to the extent required by law.
12.2. Incendium will not sell or share Personal Data processed on behalf of the Client except where expressly instructed by the Client and legally permitted.
12.3. Incendium will use such Personal Data only for the business purposes described in the agreement or as otherwise permitted by applicable law.
12.4. Incendium will not retain, use or disclose such Personal Data outside the direct business relationship with the Client or for a commercial purpose other than the business purposes specified in the agreement, except as permitted by applicable law.
12.5. Incendium will not combine such Personal Data with Personal Data received from or on behalf of another person, or collected from Incendium's own interaction with an individual, except where the combination is expressly permitted by applicable law.
12.6. Incendium will comply with applicable obligations and provide the level of privacy protection required of a service provider, contractor or processor. The Client may take reasonable and appropriate steps to verify compliance and to stop and remediate unauthorised use of Personal Data.
12.7. Incendium will notify the Client if it determines that it can no longer comply with its obligations under this Section or applicable law.
13. Audits and Information
13.1. Incendium will make available information reasonably necessary to demonstrate compliance with its processor obligations.
13.2. Incendium will allow for and contribute to audits and inspections by the Client or an independent auditor appointed by the Client to the extent required by Applicable Data Protection Law. For a routine audit, Incendium may first satisfy the request through current independent audit reports, certifications, security summaries, questionnaires or other relevant compliance documentation where these reasonably demonstrate compliance.
13.3. The Client may request no more than one routine audit in any 12-month period, unless:
- a regulator requires otherwise;
- a material Personal Data Breach has occurred; or
- the Client has reasonable grounds to believe Incendium is materially non-compliant.
13.4. Audits must:
- be conducted during normal business hours;
- minimise disruption;
- protect other customers' confidential information and security;
- be subject to appropriate confidentiality obligations; and
- use independent third-party reports or certifications where reasonably sufficient.
13.5. The Client will bear its own audit costs and Incendium may charge reasonable costs for material assistance beyond standard compliance documentation, unless the audit identifies a material breach of this DPA by Incendium. Nothing in this Section limits an audit or inspection right that cannot lawfully be restricted.
14. Return and Deletion
14.1. On termination of the Service and at the Client's choice communicated before the end of the 30-day post-termination period in Section 21 of the Terms, Incendium will return Personal Data processed on the Client's behalf using Incendium's then-current standard export functionality or format where technically available, or delete that Personal Data and existing copies, unless applicable law requires retention. If return is selected, Incendium may retain the Personal Data only for as long as reasonably necessary to complete the return and will then delete it in accordance with this Section. If the Client does not communicate a choice during that period, Incendium may securely delete the Personal Data.
14.2. Personal Data stored in backups may remain until overwritten through normal backup cycles where immediate deletion is not technically practicable, provided it is put beyond ordinary use, remains protected, is not restored except where reasonably necessary for disaster recovery, and is deleted through the applicable backup-retention cycle.
15. Conflict
15.1. If this DPA conflicts with the main body of the Terms regarding processing of Personal Data, this DPA will prevail to the extent of that conflict.
Schedule 1: Current Subprocessors
| Provider | Processing purpose |
|---|---|
| Akamai / Linode | Regional cloud hosting and infrastructure, managed databases, storage and backups. |
| Cloudflare | Edge delivery, content delivery, network and security processing, and Cloudflare Workers AI inference where enabled. |
| Sentry | Error monitoring and diagnostic processing. |
| Twilio SendGrid | Transactional email delivery. |
| Google Workspace | Hosting and handling customer-support email correspondence. |
Customer support is provided by email. Incendium does not use a separate customer-support ticketing platform.