Terms of Use
Please read these terms carefully before using Endaxi Brief.
Last updated: June 2026
Endaxi AIG — Software as a Service
IOLIS Ltd (Company no. 11968202) | 28 June 2026 | Version 1.0
These Terms of Service (“Terms”) govern your access to and use of Endaxi AIG, a software as a service platform operated by IOLIS Ltd, a company registered in England and Wales with company number 11968202 (“we”, “us”, “our”). By subscribing to or using Endaxi AIG, you agree to be bound by these Terms. If you are accepting on behalf of an organisation, you represent and warrant that you have authority to bind that organisation.
1. Definitions
In these Terms, the following definitions apply:
- “Agreement” means these Terms together with your Order, our Privacy Policy, and the Data Processing Agreement.
- “Customer” means the individual or organisation that has subscribed to the Service.
- “Order” means a subscription confirmation, invoice, or other written record of the plan and fees you have agreed to pay.
- “Service” means the Endaxi AIG software as a service platform, including all modules, features, dashboards, exports, and APIs made available under your subscription plan.
- “Subscription Plan” means the Starter, Growth, or Professional plan (or such other plans as we may offer) as set out in your Order, including the applicable volume limits and features.
- “Users” means individuals authorised by the Customer to access and use the Service under the Customer’s subscription.
- “Customer Data” means all data, content, and information submitted to or generated by the Customer or its Users through the Service, including AI system records, risk assessments, compliance artefacts, and audit logs.
- “Intellectual Property Rights” means all patents, copyrights, database rights, trademarks, trade secrets, and all other intellectual property rights, whether registered or unregistered.
- “Documentation” means any user guides, help content, and regulatory references made available by us in connection with the Service.
2. Subscription and Access
2.1 Grant of Access
Subject to the terms of this Agreement and payment of the applicable fees, we grant the Customer a non-exclusive, non-transferable, limited right to access and use the Service during the Subscription Term, solely for the Customer’s internal compliance and governance purposes and in accordance with the applicable Subscription Plan.
2.2 Subscription Plans and Volume Limits
Your right to use the Service is subject to the volume limits set out in your Subscription Plan, including limits on the number of AI systems, Users, vendors, and organisations (tenants). These limits are set out in the Order and on our pricing page. We reserve the right to suspend access to features or notify you if you exceed your plan limits. Exceeding limits does not create a right to continued access at the lower plan price.
2.3 User Accounts
The Customer is responsible for: (a) maintaining the confidentiality of account credentials; (b) all activities that occur under its account; (c) ensuring that Users comply with these Terms; and (d) promptly notifying us of any unauthorised access or suspected security breach. User accounts are personal to the individual User and may not be shared or transferred.
2.4 Acceptable Use
The Customer must not, and must ensure its Users do not:
- use the Service for any unlawful purpose or in violation of any applicable laws or regulations;
- attempt to gain unauthorised access to any part of the Service, its infrastructure, or any connected systems;
- reverse engineer, decompile, disassemble, or otherwise attempt to derive the source code of the Service;
- copy, reproduce, modify, or create derivative works of the Service or its Documentation;
- sell, resell, sublicense, assign, or transfer access to the Service to any third party, other than Users within the Customer’s organisation (or, for Professional plan customers, within the Customer’s permitted client organisations);
- use the Service to transmit any malicious code, viruses, or other harmful content;
- use the Service in a manner that interferes with or disrupts the integrity or performance of the Service or its underlying infrastructure;
- use automated means (other than the documented API) to scrape or extract data from the Service.
3. Fees, Billing, and Payment
3.1 Subscription Fees
You agree to pay the fees set out in your Order. Fees are quoted in pounds sterling (GBP) exclusive of VAT. VAT will be charged where applicable in accordance with applicable law.
3.2 Billing
Annual subscriptions are billed in advance for the full 12-month term. Monthly subscriptions (where available) are billed monthly in advance. All fees are non-refundable except as expressly set out in these Terms or required by applicable law.
3.3 Late Payment
If any invoice is not paid by the due date, we reserve the right to: (a) charge interest on the overdue amount at 8% per annum above the Bank of England base rate, pursuant to the Late Payment of Commercial Debts (Interest) Act 1998; and (b) suspend access to the Service until the outstanding amount is paid in full.
3.4 Price Changes
We may change our subscription fees on not less than 60 days’ written notice. Price changes will take effect at the start of your next renewal period after the notice period has expired. If you do not wish to continue at the new price, you may cancel your subscription before the renewal date.
3.5 Taxes
The Customer is responsible for all taxes, duties, or levies arising from its subscription, other than taxes based on our net income. If the Customer is required by law to withhold or deduct any taxes from payments to us, the Customer must gross up payments so that we receive the full amount as if no withholding or deduction had been made.
4. Subscription Term and Cancellation
4.1 Initial Term
Annual subscriptions run for a period of 12 months from the date of the Order (“Initial Term”). Monthly subscriptions run on a rolling monthly basis from the subscription date with a minimum term of three months.
4.2 Renewal
Annual subscriptions will automatically renew for successive 12-month periods unless either party gives written notice of non-renewal not less than 30 days before the end of the then-current term. Monthly subscriptions may be cancelled with not less than one calendar month’s notice.
4.3 Cancellation by the Customer
You may cancel your subscription in accordance with clause 4.2. No refund will be given for any prepaid fees for the remaining portion of a subscription term, except where cancellation follows a material breach by us that has not been remedied within 30 days of written notice.
4.4 Cancellation or Suspension by Us
We may suspend or terminate your access to the Service immediately, without refund obligation, if: (a) you fail to pay any amount due and do not remedy the failure within 14 days of written notice; (b) you materially breach these Terms and (where the breach is capable of remedy) fail to remedy it within 30 days of written notice; (c) you become insolvent, enter administration, or make an arrangement with creditors; or (d) we are required to do so by applicable law or a court or regulatory order.
5. Customer Data and Intellectual Property
5.1 Ownership of Customer Data
The Customer retains all ownership and Intellectual Property Rights in Customer Data. We acquire no ownership interest in Customer Data by virtue of this Agreement.
5.2 Licence to Process Customer Data
The Customer grants us a limited, non-exclusive licence to process Customer Data solely for the purposes of providing the Service, including hosting, storing, displaying, and transmitting Customer Data to Users. We will not use Customer Data for any other purpose, including training machine learning models, without the Customer’s express written consent.
5.3 Data Export and Portability
The Customer may export Customer Data at any time during the Subscription Term via the platform’s export functions or, where applicable, the API. Following termination or expiry of the Agreement, we will retain Customer Data for 30 days, during which time the Customer may request a data export. After 30 days, Customer Data will be securely deleted in accordance with the Data Processing Agreement.
5.4 Our Intellectual Property
All Intellectual Property Rights in the Service, its Documentation, software, databases, and content (other than Customer Data) are and remain owned by us or our licensors. Nothing in this Agreement transfers any Intellectual Property Rights to the Customer. The Customer’s right to use the Service is limited to the licence granted in clause 2.1.
5.5 Feedback
If the Customer provides any feedback, suggestions, or ideas regarding the Service, the Customer grants us a perpetual, irrevocable, royalty-free licence to use such feedback for any purpose, including improving the Service, without obligation or compensation to the Customer.
6. Confidentiality
6.1 Confidential Information
Each party may have access to information that is confidential to the other party (“Confidential Information”). Confidential Information means any information designated as confidential, or which a reasonable person would consider confidential given the nature of the information and the circumstances of disclosure.
6.2 Obligations
Each party agrees: (a) to keep the other party’s Confidential Information confidential; (b) not to disclose it to any third party without prior written consent; and (c) to use it only for the purposes of this Agreement. These obligations do not apply to information that: (i) is or becomes publicly available through no fault of the receiving party; (ii) was already known to the receiving party before disclosure; (iii) is independently developed by the receiving party; or (iv) is required to be disclosed by law, court order, or regulatory authority, provided the receiving party gives reasonable prior notice where lawful.
6.3 Duration
Confidentiality obligations under this clause survive termination of this Agreement for a period of five years.
7. Availability and Support
7.1 Service Availability
We will use commercially reasonable efforts to make the Service available 24 hours a day, 7 days a week, excluding planned maintenance windows. We do not guarantee uninterrupted or error-free access. We will endeavour to provide not less than 48 hours’ notice of planned maintenance that is likely to result in significant service interruption.
7.2 Support
We will provide support in accordance with the Subscription Plan: (a) Starter and Growth: email support during UK business hours, with reasonable response times; (b) Professional: priority email support with a target first response of one business day, plus a named account contact and dedicated onboarding session. Support is provided in English only.
7.3 Updates and Changes
We may update, modify, or discontinue features of the Service at any time. We will give reasonable notice of material changes that are likely to materially and adversely affect the Customer’s use. Where we discontinue a material feature that the Customer relies on, the Customer may terminate the subscription and receive a pro-rated refund for the unused portion.
8. Warranties and Disclaimers
8.1 Our Warranties
We warrant that: (a) we have the right to enter into this Agreement and grant the rights described; (b) the Service will perform materially in accordance with its Documentation; and (c) we will provide the Service with reasonable care and skill.
8.2 Regulatory Information Disclaimer
The Service is a governance and compliance management tool. It assists organisations in organising, documenting, and tracking their AI governance activities. The Service does not constitute legal advice. The regulatory information, classification outputs, and compliance artefacts generated by the Service are provided for information and organisational purposes only. We make no warranty that use of the Service will result in regulatory compliance, the successful outcome of any certification assessment, or the avoidance of regulatory penalty. The Customer remains solely responsible for its own compliance with applicable laws and regulations, including the EU AI Act and ISO/IEC 42001.
8.3 Disclaimer
Except as expressly stated in clause 8.1, the Service is provided “as is”. To the fullest extent permitted by applicable law, we disclaim all warranties, express or implied, including implied warranties of merchantability, fitness for a particular purpose, and non-infringement.
9. Liability
9.1 Neither party excludes liability for:
- death or personal injury caused by its negligence;
- fraud or fraudulent misrepresentation;
- any other liability that cannot be excluded or limited by law.
9.2 Exclusion of Consequential Loss
Subject to clause 9.1, neither party will be liable to the other for any: indirect, incidental, or consequential loss; loss of profits, revenue, or anticipated savings; loss of data or corruption of data (beyond the obligations in the Data Processing Agreement); loss of goodwill or reputation; or business interruption losses, in each case whether arising in contract, tort (including negligence), or otherwise, even if advised of the possibility of such losses.
9.3 Cap on Liability
Subject to clause 9.1, our total aggregate liability to the Customer arising under or in connection with this Agreement in any 12-month period will not exceed the total fees paid by the Customer under this Agreement in that same 12-month period.
9.4 Customer Liability
The Customer is responsible for ensuring that its use of the Service and its Customer Data complies with applicable laws, including data protection legislation. The Customer indemnifies us against any claims, losses, or costs (including reasonable legal costs) arising from: (a) Customer Data infringing any third-party rights; (b) the Customer’s breach of these Terms; or (c) the Customer’s breach of applicable law.
10. Data Protection
The processing of personal data in connection with the Service is governed by our Data Processing Agreement (“DPA”), which is incorporated into and forms part of this Agreement. A copy of the DPA is available on request and will be provided with all subscriptions. By entering into this Agreement, the Customer also agrees to the DPA. The key terms are: (a) the Customer is the data controller and we are the data processor in respect of personal data within Customer Data; (b) we will process personal data only on the Customer’s documented instructions; (c) we implement appropriate technical and organisational measures to protect personal data; and (d) Customer Data is hosted in the European Union (Helsinki, Finland). Full details are set out in the DPA.
11. Third-Party Services
The Service may use or integrate with third-party services or platforms (including email delivery and infrastructure providers). We are not responsible for the availability, accuracy, or terms of any third-party services. A list of our current sub-processors is maintained in our Data Processing Agreement and will be updated on reasonable notice of changes.
12. Force Majeure
Neither party will be in breach of this Agreement or liable for any failure or delay in performing its obligations if such failure or delay is caused by circumstances beyond its reasonable control, including acts of God, natural disasters, pandemics, acts of government, cyberattacks on third-party infrastructure, or failures of third-party internet or telecommunications providers. The affected party must notify the other promptly and use reasonable endeavours to mitigate the impact.
13. Governing Law and Disputes
13.1 Governing Law
This Agreement is governed by and construed in accordance with the laws of England and Wales.
13.2 Jurisdiction
Subject to clause 13.3, each party irrevocably agrees that the courts of England and Wales have exclusive jurisdiction to settle any dispute arising out of or in connection with this Agreement.
13.3 Dispute Resolution
Before commencing legal proceedings, the parties agree to attempt to resolve any dispute informally by escalating to senior representatives within 20 business days of written notice of the dispute. If unresolved after 30 business days, either party may commence formal proceedings.
14. General
14.1 Entire Agreement
This Agreement constitutes the entire agreement between the parties in relation to its subject matter and supersedes all prior representations, agreements, and understandings. Each party acknowledges that it has not relied on any representation not expressly set out in this Agreement.
14.2 Variation
We may update these Terms from time to time. We will give not less than 30 days’ written notice (including by email) of material changes. Continued use of the Service after the effective date of any change constitutes acceptance of the updated Terms.
14.3 Assignment
The Customer may not assign or transfer any rights or obligations under this Agreement without our prior written consent. We may assign this Agreement to an affiliate or in connection with a merger, acquisition, or sale of all or substantially all of our assets.
14.4 Severability
If any provision of this Agreement is found to be invalid or unenforceable, it will be modified to the minimum extent necessary to make it valid and enforceable. The remaining provisions will continue in full force and effect.
14.5 Waiver
Failure to enforce any provision of this Agreement does not constitute a waiver of the right to enforce it subsequently.
14.6 Notices
Notices under this Agreement must be in writing and sent by email to the address specified in the Order, or by post to the registered address of the relevant party. Notices sent by email are deemed received on the next business day after sending.
The parties are independent contractors. Nothing in this Agreement creates a partnership, joint venture, employment, or agency relationship.
14.7 Relationship of the Parties
Contact: [email protected] | IOLIS Ltd, Wales, United Kingdom, Company no. 11968202
Data Processing Agreement
Endaxi AIG — Between IOLIS Ltd and the Customer
IOLIS Ltd (Company no. 11968202) | 28 June 2026 | Version 1.0
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between IOLIS Ltd (“Processor”, “we”, “us”) and the Customer (“Controller”, “you”). It governs the processing of personal data by IOLIS Ltd on behalf of the Customer in connection with the Endaxi AIG service. By subscribing to Endaxi AIG, the Customer agrees to this DPA. Capitalised terms not defined here have the meanings given in the Terms of Service.
1. Definitions
- “Applicable Data Protection Law” means the UK GDPR and the Data Protection Act 2018, and to the extent applicable to Customer Data, the EU GDPR (Regulation (EU) 2016/679), together with any subordinate legislation and guidance issued thereunder.
- “Controller” means the Customer, as the entity that determines the purposes and means of the processing of Personal Data.
- “Processor” means IOLIS Ltd, as the entity that processes Personal Data on behalf of the Controller.
- “Personal Data” means any information within Customer Data that relates to an identified or identifiable natural person as defined in Applicable Data Protection Law.
- “Processing” has the meaning given in Applicable Data Protection Law and includes any operation performed on Personal Data.
- “Data Subject” means the natural person to whom Personal Data relates.
- “Sub-processor” means any third party engaged by the Processor to process Personal Data on the Controller’s behalf.
- “Standard Contractual Clauses” or “SCCs” means the standard contractual clauses adopted by the European Commission under Decision 2021/914 for the transfer of personal data to third countries.
- “Security Incident” means any accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Personal Data.
2. Roles and Scope of Processing
2.1 Roles
The Customer is the Controller and IOLIS Ltd is the Processor in respect of Personal Data within Customer Data processed through the Service.
2.2 Subject Matter
The subject matter of processing is the provision of the Service as described in the Terms of Service.
2.3 Nature and Purpose
Personal Data is processed for the purpose of enabling the Customer to use the Service, including storing AI system records, risk assessments, compliance artefacts, user activity, and audit logs. Processing activities include storage, retrieval, display, computation, and deletion.
2.4 Types of Personal Data
The types of Personal Data processed will depend on the Customer Data submitted. They may include: names and contact details of Users; names and contact details of AI system owners, technical owners, and executive sponsors; names of individuals referenced in risk assessments, FRIA records, and audit logs; IP addresses recorded in the audit log; and any other Personal Data the Customer chooses to include in its AI governance records.
2.5 Categories of Data Subject
Data Subjects may include: Users of the Service; employees or contractors of the Customer; named individuals in governance roles (e.g. Data Protection Officer, Business Owner); and individuals referenced in compliance documentation.
2.6 Duration
Processing continues for the duration of the Subscription Term. Following termination, Personal Data within Customer Data is retained for 30 days to allow data export and then securely deleted, unless a longer retention period is required by applicable law.
3. Controller Obligations
The Controller agrees to:
- ensure it has a lawful basis under Applicable Data Protection Law for the processing of Personal Data described in this DPA;
- ensure it has provided all required notices to and obtained all required consents from Data Subjects as required by Applicable Data Protection Law;
- ensure that Personal Data submitted to the Service is accurate and kept up to date;
- comply with its obligations as Controller under Applicable Data Protection Law, including responding to Data Subject requests;
- ensure that its instructions to the Processor comply with Applicable Data Protection Law.
4. Processor Obligations
4.1 Instructions
The Processor will process Personal Data only on the documented instructions of the Controller, as set out in this DPA and the Terms of Service, unless required to do so by applicable law. Where applicable law requires processing not covered by these instructions, the Processor will notify the Controller before processing (unless prohibited from doing so).
4.2 Confidentiality
The Processor will ensure that persons authorised to process Personal Data have committed to confidentiality or are under an appropriate statutory obligation of confidentiality.
4.3 Technical and Organisational Measures
The Processor will implement and maintain appropriate technical and organisational measures to protect Personal Data against Security Incidents, taking into account the nature of the processing and the risks involved. Current measures include:
- Argon2id hashing for all user passwords
- Email-based two-factor authentication on every login
- Invite-based user onboarding — no self-registration without admin authorisation
- Append-only audit logging of all governance actions (user, IP, timestamp, old/new values)
- Organisation-scoped data isolation — all queries filter by organisation ID
- HTTPS-only access with HSTS (max-age 63,072,000 seconds, includeSubDomains, preload)
- Content Security Policy: default-src ‘self’, frame-ancestors ‘none’
- CSRF protection via constant-time token comparison
- No raw SQL — all queries via SQLAlchemy ORM
- Jinja2 template autoescaping with no |safe filters on user content
- Bare-metal hosting in Helsinki, Finland — EU jurisdiction, physically isolated servers
- Secure cookies (SameSite=Strict, HTTPS-only in production)
4.4 Sub-processors
The Processor will not engage any Sub-processor to process Personal Data without the prior written authorisation of the Controller, save as provided in clause 4.5. Where a Sub-processor is engaged, the Processor will impose equivalent data protection obligations on it by written contract.
4.5 Current Sub-processors
The Controller provides general authorisation for the Processor to use the following Sub-processors, subject to clause 4.6:
| Sub-processor | Location | Purpose |
| Postmark (ActiveCampaign LLC) | USA | Transactional email delivery (account invitations, 2FA codes, password reset). No Customer Data content is included in transactional emails beyond the recipient email address and the specific token or code. |
4.6 Sub-processor Changes
The Processor will provide not less than 14 days’ prior written notice of any intended addition or replacement of Sub-processors. The Controller may object to a new Sub-processor on reasonable data protection grounds within 14 days of notice. If the parties cannot resolve the objection within a further 14 days, the Controller may terminate the Agreement without penalty, subject to receiving a pro-rated refund of prepaid fees.
4.7 Assistance to the Controller
The Processor will provide reasonable assistance to the Controller in connection with: (a) responding to Data Subject requests (access, rectification, erasure, portability, objection); (b) conducting data protection impact assessments; (c) notifying the relevant supervisory authority of Security Incidents; and (d) demonstrating compliance with Applicable Data Protection Law. Reasonable assistance beyond standard product functionality may be charged at our standard professional services rates.
5. Security Incidents
5.1 Notification
The Processor will notify the Controller without undue delay and in any event within 72 hours of becoming aware of a Security Incident affecting Personal Data processed under this DPA. Notification will include, to the extent known at the time: a description of the nature of the Security Incident; the categories and approximate number of Data Subjects affected; the categories and approximate volume of Personal Data records affected; the likely consequences of the Security Incident; and the measures taken or proposed to address the Security Incident.
5.2 Cooperation
The Processor will cooperate with the Controller and take such steps as reasonably required to investigate, remediate, and mitigate the effects of any Security Incident. The Controller is responsible for notifications to the relevant supervisory authority and Data Subjects under Applicable Data Protection Law.
6. Data Subject Rights
The Processor will maintain technical capabilities that allow the Controller to: (a) access, retrieve, correct, and delete Customer Data; (b) export Customer Data in machine-readable format; and (c) restrict processing of specific records. Where a Data Subject makes a request directly to the Processor relating to Personal Data processed under this DPA, the Processor will promptly refer the request to the Controller and will not respond to it independently.
7. Audits and Compliance Demonstration
The Processor will make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA. The Controller may, on not less than 30 days’ written notice and no more than once per 12-month period, conduct or commission an audit of the Processor’s processing activities related to this DPA. Audits must be conducted during normal business hours, must not unreasonably disrupt the Processor’s operations, and are subject to appropriate confidentiality obligations. The cost of any audit is borne by the Controller.
8. International Transfers
8.1 EU Hosting
Personal Data is hosted on bare-metal infrastructure in Helsinki, Finland (Hetzner Online GmbH), within the European Economic Area. No transfer of Personal Data to a third country (outside the EEA) is made by the Processor in the course of providing the Service, other than as described in clause 4.5 in relation to Sub-processors.
8.2 UK GDPR
For UK-established Customers, this DPA and the processing it describes are structured to comply with the UK GDPR and the Data Protection Act 2018. The Processor’s obligations mirror those required by the UK GDPR in relation to international transfers and processor obligations. To the extent that any transfer of UK Personal Data to an EEA-based processor (the Processor) requires any formal adequacy or transfer mechanism, the parties will cooperate to implement the appropriate mechanism.
8.3 Sub-processor Transfers
Where any Sub-processor processes Personal Data outside the EEA or UK (see clause 4.5), the Processor will ensure that appropriate safeguards are in place, including Standard Contractual Clauses or reliance on a UK adequacy regulation, as applicable.
9. Deletion and Return of Personal Data
On expiry or termination of the Agreement, the Processor will, at the Controller’s election: (a) return all Personal Data to the Controller in a machine-readable format within 30 days; or (b) securely delete all Personal Data within 30 days. The Processor will provide written confirmation of deletion upon request. Notwithstanding the foregoing, the Processor may retain Personal Data to the extent required by applicable law, provided that it continues to protect such data in accordance with this DPA.
10. Term and Precedence
This DPA is effective from the date the Customer subscribes to the Service and remains in force for the duration of the Agreement and the 30-day post-termination retention period. In the event of any conflict between this DPA and the Terms of Service, this DPA will prevail in relation to the processing of Personal Data. In the event of any conflict between this DPA and any applicable Standard Contractual Clauses, the Standard Contractual Clauses will prevail.
11. Governing Law
This DPA is governed by the laws of England and Wales. The parties submit to the exclusive jurisdiction of the courts of England and Wales for any dispute arising under this DPA, save that either party may seek interim or injunctive relief in any jurisdiction.
Annex A — Processing Activities Summary
| Controller | The Customer as identified in the Order |
| Processor | IOLIS Ltd, company no. 11968202, Wales, United Kingdom |
| Subject matter | Provision of the Endaxi AIG AI governance SaaS platform |
| Duration | Subscription Term plus 30-day post-termination retention period |
| Nature of processing | Storage, retrieval, display, computation, export, and deletion of Customer Data |
| Purpose of processing | Enabling the Customer to manage AI system governance, regulatory compliance, and risk management |
| Types of Personal Data | User names and email addresses; named individuals in governance roles; IP addresses in audit logs; any personal data the Customer includes in AI system records, risk assessments, or compliance artefacts |
| Categories of Data Subject | Users; Customer employees and contractors; named governance role holders; individuals referenced in compliance documentation |
| Hosting location | Helsinki, Finland (EU/EEA) |
| Retention on termination | 30 days, then secure deletion |
This DPA is entered into between IOLIS Ltd and the Customer. No separate signature is required; agreement is effected by the Customer’s subscription to the Service.
IOLIS Ltd — Wales, United Kingdom — Company no. 11968202 — legal@iolisarc.com
