These Terms of Service ("Terms") govern access to and use of ESGTrack (the "Service"), operated by [LEGAL ENTITY NAME] ("we," "us," "our"). By creating an account, or by having an account created on your organization's behalf following a signed order form or agreement, you ("Customer," "you") agree to these Terms.
You're responsible for the accuracy of the information used to set up your account, for keeping your login credentials confidential, and for all activity that happens under your account. Tell us immediately if you suspect unauthorized access.
Accounts may be created two ways: (a) self-service signup, in which case acceptance of these Terms happens at signup, or (b) provisioning by our team following a separately signed order form or master services agreement, in which case that signed agreement governs and these Terms apply to the extent it doesn't say otherwise.
Your plan, the frameworks (BRSR, CSRD, ISSB, or Generic tracking) enabled for your account, the number of users, and the term of access are as set out in your order form or as configured by our team following your signed agreement. We reserve the right to suspend access for non-payment or breach of these Terms, with notice where practicable.
You own the data you enter into the Service — your disclosures, metrics, evidence documents, and reports ("Customer Data"). We process it only to provide the Service to you, as described in our Privacy Policy and Data Processing Agreement. You can export your Customer Data at any time during your subscription, and for a reasonable period after termination — see Section 8.
You agree not to: use the Service to store or process data you don't have the right to process (including personal data of your employees or third parties without a lawful basis); attempt to breach the Service's security, including by circumventing rate limits, access controls, or tenant isolation; use the Service to build a competing product; or resell or white-label the Service without a separate written agreement permitting it.
The Service helps you collect, organize, and assemble ESG and sustainability disclosure data, and generates documents formatted to resemble regulatory filing structures (e.g. SEBI's BRSR Annexure I format, or a CSRD-style Sustainability Statement). These generated documents are drafting aids, not certified or compliant filings. Whether a given report satisfies your actual regulatory obligations — including its accuracy, completeness, and compliance with the specific rules applicable to your reporting year and jurisdiction — remains your responsibility, and we recommend review by your company secretary, auditor, or other qualified advisor before you rely on or file any report generated through the Service.
We own the Service itself — its software, design, and underlying technology. You own your Customer Data. Nothing here transfers ownership of one to the other.
To the maximum extent permitted by law, our aggregate liability arising out of or related to the Service is limited to the amount you paid us in the 12 months preceding the claim. We are not liable for indirect, incidental, or consequential damages, including regulatory penalties arising from your use (or non-use) of the Service's outputs. [This section requires jurisdiction-specific legal review — liability limitations that are enforceable in one jurisdiction may not be in another, and consumer-protection or data-protection law may override contractual limitations in some cases.]
Either party may terminate as set out in a signed order form or agreement, or, absent one, with 30 days' written notice. On termination, your access ends, but we'll make your Customer Data available for export for [30/60/90] days afterward, after which it may be deleted per our data retention practices (see Privacy Policy).
We may update these Terms from time to time. Material changes will be notified to account administrators by email or in-app notice before taking effect.
[To be completed based on where your entity is incorporated and where your primary customer base sits — this determines both the governing law clause and which data protection regime(s) apply as a baseline, e.g. India's DPDP Act 2023 if incorporated in India, GDPR considerations if serving EU customers regardless of incorporation.]
Questions about these Terms: [LEGAL/SUPPORT EMAIL ADDRESS].