These Terms of Service (the "Terms") govern the use of the nocert.io platform (the "Service") operated by Perspective Analytics SAS, a société par actions simplifiée registered in France under RCS Saint-Nazaire 988 270 757, with registered office at 2 rue du Général de Gaulle, 44290 Guémené-Penfao, France ("nocert", "we", "us", "our").
By creating an account or using the Service, you ("Customer", "you", "your") accept these Terms and the Data Processing Agreement in full. If you do not accept these Terms, do not create an account or use the Service.
Effective date: 20 April 2026
1. Definitions
- Service: the nocert.io certificate monitoring platform, including its web interface, API, and the Sentinel agent software.
- Sentinel: the open-source agent software distributed by nocert under the Apache License, Version 2.0 (Apache-2.0) and deployable by the Customer on its own infrastructure to perform internal certificate discovery. Use of the Sentinel is governed by Apache-2.0. A complete source archive accompanies each Sentinel release and is downloadable from the Service's authenticated web interface.
- Customer Data: any data submitted by the Customer to the Service or collected by a Sentinel deployed on the Customer's infrastructure, including certificate metadata, hostnames, IP addresses, user information, authentication events, and audit logs.
- Personal Data: has the meaning given in Article 4(1) of Regulation (EU) 2016/679 (GDPR).
- Confidential Information: as defined in Section 12 of these Terms.
- Trade Secrets: Confidential Information meeting the cumulative criteria of Article L151-1 of the French Code de commerce (transposing Directive (EU) 2016/943).
- Plan: a paid tier of the Service (currently Pro, Business, or Custom), as described at nocert.io/pricing.
- Trial: the free evaluation period provided under Section 4.
- Read-only Mode: state of the account in which certificate discovery, alerting, notifications, and creation or modification of configuration are suspended, and in which the Customer retains read access to the core certificate and endpoint inventory. Plan-specific capabilities, including Compliance details and audit evidence exports, remain unavailable unless an eligible paid Plan is active.
- DPA: the Data Processing Agreement published at nocert.io/legal/dpa, which forms an integral part of the contractual relationship between the parties.
- Sub-processors: the third parties engaged by nocert to process Customer Data on its behalf, listed and maintained up to date in the DPA.
- Switching: the process, within the meaning of Chapter VI (Articles 23 to 31) of Regulation (EU) 2023/2854 (the "Data Act"), by which the Customer transfers its data and activity from the Service to a third-party service.
- Plateforme Agréée (or "PA", formerly Plateforme de Dématérialisation Partenaire or PDP), a platform certified by the French Direction générale des Finances publiques to issue, receive, and transmit electronic invoices within the French e-invoicing framework established by Article 289 bis of the Code général des impôts.
2. Scope, Acceptance, and Electronic Communications
Scope. These Terms govern any access to or use of the Service, whether free of charge (Trial) or under a paid Plan. They are accepted by the Customer at the time of account creation through an explicit checkbox and apply throughout the entire duration of the relationship between the parties.
Version accepted. The accepted version of the Terms is the version in force on the date the Customer creates the account, subject to modifications governed by Section 17.
Dual acceptance. Acceptance of these Terms is given through a checkbox distinct from the checkbox accepting the DPA, in accordance with Article 28 of the GDPR.
Electronic communications. The Customer consents to receive all contractual communications (including notices of modification, invoices, suspension warnings, termination notices, and similar communications) by email at the address registered on the account, or through the in-platform notification system. Electronic communications have the same legal effect as paper communications under Article 1366 of the French Code civil.
3. Customer Eligibility and Professional Declaration
Eligibility. The Service is strictly reserved for legal entities and natural persons acting within the scope of their professional activity.
Nature of the contract. The contract is concluded at a distance through the Service's online subscription interface. It is not a contrat conclu hors établissement within the meaning of Article L221-1 of the French Code de la consommation. Consequently, Article L221-3 of the same Code, which extends certain consumer protections to small professionals (five or fewer employees, where the contract is both concluded hors établissement and falls outside the main activity), does not apply.
Professional declaration. By creating an account, the Customer expressly declares and warrants, through a dedicated checkbox distinct from the Terms acceptance checkbox, that:
- it has the status of a professional, or of a legal entity acting for purposes that fall within its professional, commercial, industrial, artisanal, liberal, or agricultural activity;
- it enters into the contract within the scope of that professional activity; and
- it has the linguistic capacity to read and understand these Terms in English, which is the working language of the contract between the parties.
Consumer regime not triggered. Given the nature of the contract (distance contract, not hors établissement) and the professional quality of the Customer, the consumer protections provided by the French Code de la consommation are not triggered, including the fourteen (14) day right of withdrawal set out in Article L221-18 and the extensions set out in Article L221-3. If this factual declaration proves inaccurate, the applicable consumer protections shall apply regardless of these Terms; the Customer remains liable under these Terms for any misrepresentation.
Non-professional legal entities. Certain legal entities, in particular associations, syndicats de copropriétaires, and similar non-profit structures, may retain "non-professionnel" status within the meaning of the preliminary article of the Code de la consommation irrespective of this declaration. Such customers are invited to contact nocert before subscribing in order to establish whether the Service is appropriate for their situation.
Professional identifiers. A SIRET number, intra-Community VAT number, or equivalent professional identifier shall be provided before activation of a paid Plan, for the purpose of compliant invoicing under Articles 289 et seq. of the French Code général des impôts and Directive 2006/112/EC. Such identifiers are not required during the Trial.
Verification. nocert reserves the right to suspend or terminate without notice any account whose professional status cannot be verified.
4. Account Registration and Free Trial
Registration. The Customer creates an account by providing the information required by the account creation form (including an email address, a password, and the company information for billing purposes) and by accepting these Terms and the DPA through the two distinct checkboxes described in Sections 2 and 3.
Automatic Business Trial. Upon account creation, the Customer’s newly created organization automatically receives a full Business Trial of fourteen (14) calendar days. No payment card is required. All Business Plan features are available during the Trial, within the applicable usage limits.
End of Trial. At the end of the Trial (day D+14, where D is the date of account creation), if no paid Plan has been activated, the account is placed in Read-only Mode (as defined in Section 1).
Read-only period after Trial. The account remains in Read-only Mode for a fixed period of sixty (60) calendar days, until day D+74. During this period, the Customer may activate a paid Plan at any time and may continue to retrieve the core inventory through the read-only interfaces then available, or request a portability export under Section 16.
Deletion at D+74. If no paid Plan has been activated by day D+74, the account and all associated Customer Data are deleted from production systems on that date. A final reminder email is sent at day D+67; non-delivery of this email (for example due to a bounce or a full mailbox) does not delay deletion at D+74. Backups containing Trial Customer Data are purged within ninety (90) days from D+74, consistent with the backup-purge regime in Section 16.
Customer responsibility. The Customer is responsible for all activity carried out under its account, for the security of its credentials, and for the appropriate configuration of multi-factor authentication where available.
5. Pricing, Billing, Invoicing, and Refunds
Plans and pricing. The Service is offered under several paid Plans. Current prices and included features are published at nocert.io/pricing. Prices are expressed in euros (EUR) or US dollars (USD), depending on the Customer's selection at the time of subscription, exclusive of VAT or equivalent sales tax. VAT is applied where required by law; reverse-charge applies to Customers established in another EU Member State who provide a valid intra-Community VAT identification number. For Customers paying in a currency other than that selected at subscription, currency conversion is performed by Stripe at the rate applicable on the day of the transaction.
Billing options. The Customer may choose between:
- Monthly billing, no commitment: automatic monthly charge through Stripe, no minimum commitment period.
- Annual prepaid billing with the discount shown on the pricing page: single upfront charge at subscription activation for a twelve (12) month period.
Payment method. All payments are processed through Stripe. The Customer authorises nocert and Stripe to charge the payment method registered on the account according to the selected billing option.
Plan changes.
- Upgrades are effective immediately. For monthly subscriptions, the difference is charged pro-rata against the remaining days of the current billing cycle. For annual subscriptions, the additional amount is charged pro-rata against the remaining days of the current prepaid period, the annual discount continuing to apply to the upgrade value.
- Downgrades take effect at the end of the current billing cycle (monthly) or at the end of the current prepaid period (annual).
Price changes. nocert may modify prices with at least thirty (30) days' written notice sent to the email address registered on the account. Price changes do not apply to the remaining prepaid period of an annual subscription.
No refund on annual cancellation, with exceptions. The discount attached to annual prepaid subscriptions is consideration for the Customer's financial commitment over twelve (12) months. Consequently, no refund is due in the event of termination at the Customer's initiative during the prepaid period, except in the following cases:
- a material breach by nocert giving rise to the Customer's right to terminate under Section 6;
- the exercise by the Customer of its Switching right under Chapter VI of the Data Act (Section 16 below); in that case, nocert shall refund the unused prepaid period on a pro-rata basis so that no-refund clauses do not constitute an obstacle to switching within the meaning of Article 23 of the Data Act;
- a refusal of a modification to these Terms under the conditions set out in Section 17;
- the exercise of a validly applicable statutory right.
In other cases, the Customer retains access to the Service until the end of the paid period.
Invoicing: general requirements. Invoices are issued through Stripe and accessible by the Customer at any time through the account billing section. Invoices include all mentions required by Article 242 nonies A of Annex II to the French Code général des impôts and by Directive 2006/112/EC.
Invoicing: French e-invoicing reform. In accordance with Article 289 bis of the French Code général des impôts and the French e-invoicing reform:
- from 1 September 2026, French-established Customers are required to receive electronic invoices through a certified Plateforme Agréée. nocert issues and transmits its invoices through Tiime, a Plateforme Agréée officially registered by the Direction générale des Finances publiques;
- from 1 September 2027 at the latest, as a small or medium-sized enterprise within the meaning of the reform, nocert shall also issue invoices in the structured format prescribed by the reform (Factur-X, UBL or CII), through Tiime, including the mandatory new mentions (buyer's SIREN, delivery address where different from billing, transaction category (livraison de biens / prestation de services / mixte) and VAT option);
- French-established Customers are required to designate and keep up to date their own Plateforme Agréée in the Annuaire of the Portail Public de Facturation (PPF), and to notify nocert without delay of any change.
Late payment. Any unpaid invoice is subject, without prior notice, to late-payment interest at the ECB refinancing rate increased by ten (10) percentage points, together with a fixed recovery indemnity of EUR 40 per invoice pursuant to Articles L441-10 and D441-5 of the French Code de commerce. Where recovery costs actually incurred exceed this fixed indemnity, nocert reserves the right to claim further justified indemnification.
6. Term, Termination, and Survival
Term of the contract. The contract begins at account creation and continues for:
- a renewable one (1) month period for monthly subscriptions, tacitly renewed unless terminated in accordance with the below;
- a twelve (12) month period for annual prepaid subscriptions, tacitly renewed for successive twelve (12) month periods unless terminated in accordance with the below.
Ordinary termination by the Customer. The Customer may terminate its subscription at any time through the account settings. Termination takes effect:
- for monthly subscriptions, at the end of the current billing cycle;
- for annual prepaid subscriptions, at the end of the current prepaid period.
Termination by the Customer for material breach by nocert. The Customer may terminate the contract with immediate effect, by written notice served by email to or by registered letter, in the event of a material breach of these Terms by nocert that has not been remedied within fifteen (15) days of a formal notice of breach (mise en demeure).
Termination by nocert. Where the Customer has committed a material breach of these Terms, nocert shall serve a formal notice of breach (mise en demeure) granting the Customer fifteen (15) days to remedy the breach. If the breach is not remedied within that period, nocert may terminate the Customer's subscription by serving a further written notice of termination taking effect thirty (30) days after its service. nocert may terminate without notice in the event of a serious breach.
Material breach: non-exhaustive examples. The following are considered material breaches: repeated or prolonged non-payment beyond the cure period set in Section 7; breach of Section 9 (Acceptable Use, Scanning Authorisation, and Export Controls); breach of Section 11 (Customer Data licence); breach of confidentiality (Section 12).
Serious breach: non-exhaustive examples. The following are considered serious breaches justifying termination without notice: fraud; use of the Service for illegal purposes; conduct that threatens the integrity or security of the Service, of other customers, or of third-party infrastructure; violation of sanctions or export-control regulations identified in Section 9.
Effects of termination. Upon the effective date of termination, a nocert-hosted deployment is placed in Read-only Mode. For self-hosted deployments, nocert-controlled account and service components are placed in Read-only Mode where applicable; the Customer remains in control of its own infrastructure. The conditions applicable to the post-termination period, restitution, Switching, and deletion of Customer Data are set out in Section 16. This applies to all forms of termination, including termination following payment default under Section 7, subject to the specific conditions set out in Section 16 for terminations based on non-payment.
Survival. The following Sections survive termination of the contract, in proportion to their nature: Section 10 (Intellectual Property, Feedback, and Reserved Rights), Section 11 (Customer Data Licence, to the extent necessary for lawful restitution), Section 12 (Confidentiality and Trade Secrets, for the durations specified therein), Section 13 (Personal Data Protection, to the extent the DPA imposes post-termination obligations), Section 14 (Limitation of Liability and Customer Indemnification), Section 16 (Data Portability, Switching, and Deletion, during the applicable periods), Section 18 (Governing Law and Jurisdiction), and Section 20 (General Provisions).
7. Payment Defaults
Retry period. In the event of a payment failure, nocert, through Stripe, will automatically retry the charge for a period of fourteen (14) calendar days. During this period, the Service remains fully operational. Reminder emails are sent to the address registered on the account.
Suspension. If the payment has not been successfully processed at the end of this retry period, the account is suspended: the nocert-hosted Service, and any nocert-controlled components of a self-hosted deployment, are placed in Read-only Mode where applicable. Customer Data held in nocert-controlled systems remains accessible for consultation and for a portability request under Section 16.
Automatic termination. Without regularisation of the outstanding amounts within an additional thirty (30) calendar days following suspension, the contract is automatically terminated. Data retention, restitution, Switching, and deletion follow Section 16, subject to the specific conditions applicable to terminations for non-payment.
Late-payment interest and recovery indemnity. The late-payment regime set out in Section 5 applies to all unpaid invoices.
8. Service Availability, Beta Features, and Disclaimers
Best-effort operation. The Service is provided on a best-effort basis. No availability guarantee, no service level commitment, and no service credit is included in the Pro or Business Plans. Formal availability commitments ("SLA") may be negotiated individually under a Custom Plan, on the terms set out in the corresponding individual agreement.
Nature of obligations. nocert's obligations under these Terms and the related Documentation are obligations of means (obligations de moyens) and not obligations of result (obligations de résultat). nocert undertakes to deploy the care, skill, and diligence reasonably expected from a competent professional in the field of certificate intelligence and TLS monitoring, but does not warrant the exhaustiveness, accuracy, completeness, or timeliness of the information, alerts, scores, or indicators produced by the Service.
Scheduled maintenance. Scheduled maintenance windows are communicated in the platform interface within a reasonable timeframe.
Beta features. nocert may designate certain features as "Beta", "Preview", "Alpha", or "Experimental". Beta features are provided "as-is", without warranty of any kind, and may be modified, suspended, or discontinued at any time without notice. The limitation of liability in Section 14 applies to beta features; any availability or service-level commitment is expressly excluded for beta features.
Third-party services. The Service relies on third-party infrastructure (including OVHcloud for hosting, Cloudflare for edge delivery, Stripe for payment processing, and email delivery providers listed in the DPA). nocert is not liable for the availability, performance, or acts and omissions of such third-party services, without prejudice to Section 15 (Force Majeure).
Discovery disclaimer. Certificate discovery performed by the Service, whether through public enumeration, Sentinel-based local scanning, or DNS zone import, is provided on a best-effort basis and is not warranted to be exhaustive. The Customer remains solely responsible for maintaining its own certificate inventory of record.
Compliance scoring disclaimer. Compliance scores, reports, and alignment indicators produced by the Service (including but not limited to TLS compliance scores, post-quantum readiness indicators, and framework alignment reports relating to PCI-DSS, ISO 27001, NIS2, or ANSSI) are provided for informational purposes only. They do not constitute legal advice, regulatory certification, audit opinion, or guarantee of compliance with any framework. The Customer remains responsible for its own compliance assessments.
No operational-impact liability. The Service provides information, alerts, and recommendations. The Customer remains solely responsible for any operational decisions, configuration changes, or remediation actions made in response. nocert shall not be liable for any operational impact, downtime, or loss resulting from such Customer decisions, save in case of nocert's wilful misconduct (dol) or gross negligence (faute lourde).
9. Acceptable Use, Scanning Authorisation, and Export Controls
Intended purpose. The Service and the Sentinel agent are designed, marketed, and provided solely for the monitoring by a Customer of infrastructure that the Customer owns or controls, or for which the Customer holds an explicit authorisation from the owner. Any other use is strictly prohibited.
General prohibitions. The Customer agrees not to:
- use the Service to scan, monitor, or probe infrastructure that the Customer does not own or for which it does not have the explicit authorisation of the owner;
- attempt to reverse-engineer, decompile, or extract the source code of the Service, except to the extent expressly permitted by applicable law (notably Article L122-6-1 IV of the French Code de la propriété intellectuelle);
- share account credentials or allow access to the Service by unauthorised third parties;
- use the Service to conduct activities that violate applicable laws or regulations, or to produce, store, or transmit illegal content;
- circumvent the technical usage limits of the Service or interfere with its proper operation;
- publish benchmarks, performance comparisons, or competitive analyses of the Service without the prior written consent of nocert.
Scanning authorisation: Customer representation and warranty. The Customer represents and warrants that all hosts, domains, IP addresses, and infrastructure targets submitted to the Service for monitoring are either owned by the Customer or subject to a written authorisation from their owner permitting discovery and monitoring by the Service. The Customer shall retain reasonable evidence of such authorisation for a minimum of five (5) years and shall produce it to nocert upon reasonable written request in the event of a dispute. This warranty is intended to support, without prejudice to, the criminal framework established by Articles 323-1 et seq. of the French Code pénal (including Article 323-3-1 on the provision of means).
API rate limits. nocert may implement and enforce rate limits and fair-use policies on the API. nocert may suspend API access in the event of repeated or egregious breaches, with prior notice where practicable.
Sanctions. The Customer represents and warrants that neither the Customer nor any of its beneficial owners, authorised users, or end users are included in:
- any sanctions list maintained by the European Union (including the EU Consolidated Financial Sanctions List);
- the sanctions lists maintained by the United Nations;
- the French asset-freeze register maintained by the Direction générale du Trésor (Registre national des personnes et entités faisant l'objet d'une mesure de gel) under Article L562-1 et seq. of the Code monétaire et financier;
- the sanctions lists maintained by the United Kingdom (OFSI) and the United States (OFAC).
The Customer further warrants that it will not use the Service in or from any jurisdiction subject to comprehensive embargoes and will not permit any listed person to access or use the Service. The Customer undertakes to notify nocert without delay of any change affecting this representation.
Dual-use and export controls. The Sentinel agent software may fall within the scope of Regulation (EU) 2021/821 on the control of exports, brokering, technical assistance, transit, and transfer of dual-use items. The Customer represents and warrants that it shall not export, re-export, or use the Sentinel in breach of that Regulation, nor deploy the Sentinel in destinations subject to comprehensive export restrictions.
Cryptography (ANSSI). The Service and the Sentinel implement cryptographic functionality within the meaning of Article 30 of French Law n° 2004-575 (LCEN). nocert undertakes to make any declarations and formalities required of it under the applicable ANSSI regime. The Customer undertakes to comply with any applicable declaration or authorisation requirements in its own jurisdiction, and shall not re-export the Service or the Sentinel outside the European Union without first verifying compliance with applicable cryptographic export controls.
Consequences of breach. Any breach of this Section constitutes a material breach of these Terms and may give rise to immediate suspension or termination under Section 6, without prejudice to any right to damages or to the Customer indemnification set out in Section 14.
10. Intellectual Property, Feedback, and Reserved Rights
nocert intellectual property. The Service, including its source code (excluding the open-source Sentinel software, which is governed by its own licence), design, technical documentation, trademarks, logos, and all associated intellectual property rights, remains the exclusive property of Perspective Analytics SAS or its licensors.
Limited licence to the Customer. nocert grants the Customer, for the duration of the contract, a non-exclusive, non-transferable, non-sublicensable right to use the Service, strictly limited to the Customer's internal business needs.
Feedback. Any suggestion, recommendation, improvement proposal, error report, or other feedback provided by the Customer in relation to the Service ("Feedback") may be used by nocert without restriction and without compensation to the Customer. The Customer grants nocert a perpetual, worldwide, royalty-free, irrevocable licence to use, reproduce, modify, and incorporate the Feedback into the Service or any other product or service of nocert. For the avoidance of doubt, this licence does not extend to Customer Data.
Publicity. nocert may identify the Customer by name and logo as a reference customer on its website, marketing materials, and commercial presentations, in accordance with the Customer's brand guidelines where these have been published by the Customer or communicated to nocert in writing.
Where the Customer is a natural person acting in a professional capacity, this processing is based on nocert's legitimate interest (Article 6(1)(f) GDPR); the Customer retains the right to object under Article 21 GDPR.
The Customer may in all cases opt out at any time by written notice to ; nocert shall remove the identification within a reasonable time from such notice.
Reserved rights. All rights not expressly granted by these Terms are reserved. No licence or right of any kind is granted by implication, estoppel, or otherwise.
11. Customer Data Ownership and Licence
Ownership. The Customer retains full ownership of all Customer Data.
Limited licence to nocert. The Customer grants nocert, for the sole duration of the contract and for the sole purpose of operating the Service, a non-exclusive, non-transferable licence, strictly limited to what is necessary to: host Customer Data, process it for the purposes of certificate discovery, monitoring, alerting, compliance scoring, audit logging, user authentication, produce reports to the Customer, and return data at the end of the contract.
Prohibited uses. nocert expressly undertakes:
- not to use Customer Data to train, fine-tune, or evaluate any artificial intelligence or machine-learning model, whether proprietary or third-party;
- not to resell, rent, or otherwise monetise Customer Data;
- not to use Customer Data for commercial purposes unrelated to the Service;
- not to disclose Customer Data to third parties other than the Sub-processors listed in the DPA, which are bound by equivalent confidentiality and security obligations.
Anonymised aggregates. Anonymised and aggregated statistics may be produced for product improvement purposes, provided that they do not permit the re-identification of the Customer or of any natural person.
12. Confidentiality and Trade Secrets
Obligation. Each party undertakes to preserve the confidentiality of information belonging to the other party identified as confidential, or which by its nature or the context of its disclosure should reasonably be considered as such ("Confidential Information").
Customer Confidential Information includes in particular hostnames, IP addresses, network topology, certificates, network configuration, and any element relating to the Customer's internal infrastructure.
nocert Confidential Information includes in particular the technical architecture, algorithms, non-public source code, and non-published commercial elements.
Trade Secrets. The parties acknowledge that certain Confidential Information may constitute Trade Secrets within the meaning of Article L151-1 of the French Code de commerce, benefiting from the protective regime set out in Articles L151-1 et seq., including the specific remedies in case of misappropriation.
Permitted use. Confidential Information may only be used for the purposes of performing the contract. It may not be disclosed to third parties without prior written authorisation, with the exception of Sub-processors listed in the DPA and subject to equivalent obligations.
Duration. This obligation remains in force for the entire duration of the contract and for five (5) years following its termination. Trade Secrets remain protected for as long as they meet the criteria of Article L151-1.
Exclusions. Information is excluded from this obligation if it: (i) is public without fault of the receiving party; (ii) was already lawfully known before disclosure; (iii) was lawfully obtained from a third party not bound by a confidentiality obligation; (iv) was developed independently; or (v) must be disclosed pursuant to a legal or judicial obligation, subject to prior notice to the other party to the extent permitted by law. For the avoidance of doubt, anonymised and aggregated data processed under Section 3 of the Data Processing Agreement, which no longer identifies the Customer or any natural person, does not constitute Confidential Information for the purposes of this Section.
13. Personal Data Protection
The processing of Personal Data is governed by:
- the Privacy Policy at nocert.io/legal/privacy, for processing in which nocert acts as controller (account data, usage logs);
- the Data Processing Agreement (DPA) at nocert.io/legal/dpa, for processing in which nocert acts as processor on behalf of the Customer (Customer infrastructure data collected via the Service and Sentinels), in accordance with Article 28 of the GDPR.
The DPA in force on the date of acceptance of these Terms forms an integral part of the contractual relationship. Modifications of the DPA are governed by the same notice regime as Section 17, unless a shorter notice is required by a change of law, a sub-processor change managed under the DPA's specific notice procedure, or a transfer-mechanism substitution under Section 9 of the DPA.
14. Limitation of Liability and Customer Indemnification
Cap. To the maximum extent permitted by applicable law, nocert's total liability towards the Customer, all causes and heads of damage combined, is limited to the total amount of fees actually paid by the Customer to nocert in respect of the twelve (12) months preceding the event giving rise to liability, subject to the following adjustments:
- where the fees actually paid during that period are lower than EUR 6,000 (in particular shortly after paid activation), the cap is raised to a minimum floor of EUR 6,000; and
- for Pro and Business Plans, the cap shall not in any event exceed an absolute maximum of EUR 30,000. For contracts under a Custom Plan, the parties may agree on a different absolute cap in the corresponding individual agreement.
Mandatory carve-outs. This limitation does not apply in case of:
- wilful misconduct or fraud (dol, fraude);
- gross negligence (faute lourde);
- bodily injury;
- intentional breach of the GDPR, and liability toward data subjects under Article 82 GDPR where such liability cannot be capped by contract;
- infringement of intellectual property rights of a third party;
- any other liability which, under applicable public-order rules of French law, cannot be capped.
Faurecia safeguard. In accordance with Articles 1170 and 1231-3 of the French Code civil and the case law arising from Cass. com. 22 October 1996 (Chronopost) and Cass. com. 29 June 2010 (Faurecia II), this cap shall not apply where, considered in light of the price paid and the nature of the breach, it would be so low as to contradict the scope of the essential obligation of the contract.
Additional processor-specific carve-outs. Additional carve-outs applicable to nocert's obligations as Processor under the GDPR are set out in Section 13 of the DPA.
Data loss. Loss of Customer Data directly caused by nocert's failure to comply with the backup and retention obligations set out in the DPA is treated as a direct damage and is subject to the cap set out above. Consequential losses resulting from such data loss, including loss of revenue, loss of profit, loss of chance, or business interruption, are indirect damages within the meaning of the paragraph below and are excluded.
Indirect damages. nocert shall under no circumstances be liable for indirect damages, in particular: loss of revenue, loss of profit, loss of chance, loss of image or reputation, or damages suffered by third parties.
Acknowledgement. The Customer acknowledges that this limitation reflects a balanced allocation of risks between the parties, negotiated in consideration of the price of the Service.
Customer indemnification. The Customer shall indemnify, defend, and hold harmless (tenir quitte et indemne) nocert, together with its affiliates, officers, and employees, against any third-party claim, proceeding, judgment, or settlement (and against the amounts actually paid by nocert in respect of damages awarded, costs of legal proceedings, and reasonable legal fees subject to the judge's discretion under Article 700 of the French Code de procédure civile) arising from or in connection with:
- the Customer's breach of the scanning authorisation warranty set out in Section 9;
- the Customer's breach of the sanctions, dual-use, or cryptographic export-control representations set out in Section 9;
- content submitted by the Customer to the Service in breach of applicable law;
- the Customer's fraudulent, wilful, or grossly negligent acts or omissions;
- the Customer's breach of any other representation or warranty set out in Section 9.
Defence control. nocert shall notify the Customer without undue delay of any claim covered by this indemnification. nocert shall retain control of its own defence and may select its counsel. The Customer shall cooperate reasonably in the defence, including by providing information and assistance. nocert shall not settle a claim without the Customer's prior consent where settlement imposes non-financial obligations on the Customer; such consent shall not be unreasonably withheld.
15. Force Majeure
Neither party shall be liable for any failure to perform its obligations resulting from a case of force majeure within the meaning of Article 1218 of the French Code civil, satisfying the cumulative conditions of externality, unforeseeability, and irresistibility.
Events that may constitute, depending on the circumstances, a case of force majeure include, without limitation: natural disasters, acts of war or terrorism, epidemics, decisions by public authorities rendering performance of the contract impossible, prolonged interruptions of telecommunications networks, or large-scale cyberattacks. An interruption of a third-party infrastructure provider (including OVHcloud, Cloudflare, or Stripe) does not in itself constitute force majeure unless the cumulative conditions of Article 1218 are met.
The affected party shall notify the other within a reasonable time. If the impediment persists for more than sixty (60) consecutive days, either party may terminate the contract without compensation by registered letter.
16. Data Portability, Switching, and Deletion
Data portability. The Customer may request an export of Customer Data at any time by writing to . Subject to applicable law and the scope of Customer Data held by nocert, the export is provided without undue delay in a structured, commonly used, and machine-readable format then supported by the Service. This portability process is separate from the five in-product Compliance evidence datasets, whose availability remains subject to the Business or Custom Plan entitlement.
Switching (Data Act). In accordance with Chapter VI (Articles 23 to 31) of Regulation (EU) 2023/2854 (the "Data Act"), the Customer has the right to switch to another provider at any time. Upon written request sent to :
- the mandatory notice period preceding the initiation of Switching shall not exceed two (2) months, as permitted by Article 25(2)(a) of the Data Act;
- the transitional period during which the Service remains available to the Customer for export and access shall not exceed thirty (30) calendar days from the end of the notice period, as permitted by Article 25(2)(a);
- where the 30-day transitional period is technically unfeasible, nocert shall notify the Customer within fourteen (14) working days of the Switching request and propose an alternative transitional period not exceeding seven (7) months, together with a written justification, in accordance with Article 25(2)(d) of the Data Act;
- the Customer may, at its discretion, extend the transitional period once for a duration it considers appropriate, up to a maximum of seven (7) months, in accordance with Article 25(2)(e) of the Data Act;
- nocert shall cooperate in good faith with the Customer and, where applicable, with the receiving service provider, in accordance with Article 27 of the Data Act, including by providing documentation on data formats, categories, and relevant dependencies on the Service's environment;
- from 12 January 2027, Switching shall be carried out free of charge, in accordance with Article 29 of the Data Act. Before that date, any cost-based switching charges shall be reasonable and non-discriminatory and shall not exceed the costs actually incurred.
Switching is unconditional. The Switching right described above is granted irrespective of any outstanding amounts owed by the Customer or of the cause of termination, in accordance with Articles 23 and 27 of the Data Act. Outstanding amounts (unpaid invoices, late-payment interest, recovery indemnities) remain due and are pursued by nocert as separate debt-recovery claims, including, where appropriate, dunning, debt-collection, or judicial recovery. Such recovery actions do not affect the Customer's right to initiate and complete the Switching process described above.
Transparency. In accordance with Article 26 of the Data Act, nocert provides on written request the procedures, methods, and formats then available for Switching, together with known technical limitations or restrictions and relevant data-structure or interoperability information. nocert undertakes to keep this information up to date.
Deployment scope. The read-only and deletion commitments below apply to Customer Data held in systems controlled by nocert. For self-hosted deployments, the Customer remains responsible for Customer Data held solely in Customer-controlled infrastructure. nocert deletes copies under its control from production within thirty (30) days after termination and from backups within ninety (90) days after termination.
Post-termination read-only period. Upon termination of a nocert-hosted deployment, the account is placed in Read-only Mode for thirty (30) calendar days. During this period, the Customer may request and retrieve a portability export and, where applicable, carry out the Switching process described above.
Deletion from production. At the end of the post-termination read-only period (and, where applicable, at the end of the Switching transitional period), Customer Data for nocert-hosted deployments is deleted from nocert-controlled production systems within thirty (30) days. The self-hosted timeline is specified in the deployment scope paragraph above.
Deletion from backups. Backups controlled by nocert are purged according to the standard backup retention cycle, within a maximum of ninety (90) days from the effective date of termination.
Legal retention obligations. Notwithstanding the foregoing, certain data may be retained beyond these periods solely to the extent necessary to comply with legal retention obligations, including accounting obligations under Article L123-22 of the French Code de commerce (ten years) and tax obligations under Article L102 B of the French Livre des procédures fiscales (six years for supporting documents). Data retained under this provision is not further processed.
17. Modifications to the Terms
nocert may modify these Terms at any time. Material changes will be notified to the Customer by email sent to the address registered on the account, or through the in-platform notification system, at least thirty (30) days before their effective date.
"Material changes" include, without limitation, changes affecting pricing structure, billing mechanisms, liability, data handling, termination conditions, or other substantive rights and obligations of the parties.
Continued use of the Service after the effective date of the modifications constitutes acceptance of the new Terms by the Customer. If the Customer does not accept the modifications, it may terminate its subscription with effect on the effective date of the modification by written notice to before that date, by exception to Section 6. In such case, the Customer benefits from a pro-rata refund for the unused prepaid period (annual subscriptions only), by exception to Section 5.
18. Governing Law and Jurisdiction
These Terms are governed by French law.
Customers established in the European Union. Any dispute relating to the formation, performance, or interpretation of these Terms shall be submitted to the exclusive jurisdiction of the courts of Saint-Nazaire, France, including in the event of multiple defendants, summary proceedings, or third-party claims. This clause is established in accordance with Article 25 of Regulation (EU) 1215/2012 (Brussels I bis).
Customers established outside the European Union. The parties shall endeavour to resolve any dispute amicably. Failing amicable resolution, and subject to mandatory rules of jurisdiction that may apply, the dispute shall be submitted to the courts of Saint-Nazaire, France. For contracts under a Custom Plan with an annual commitment exceeding EUR 50,000 excluding VAT, the parties may agree on a separate arbitration clause (ICC Paris or equivalent) set out in the Custom Plan individual agreement.
19. Regulatory Customers (DORA, NIS2)
Customer representation. The Customer represents and warrants that, if it is a financial entity subject to Regulation (EU) 2022/2554 (DORA) or an essential or important entity within the meaning of Directive (EU) 2022/2555 (NIS2) as transposed into applicable national law, it has contacted nocert at prior to subscribing to a Plan, in order to negotiate appropriate regulatory-compliant addenda under a Custom Plan.
Consequence. Subscription to the Pro or Business Plan by a DORA financial entity or an essential/important entity under NIS2 without such prior disclosure constitutes a material breach of these Terms. The standard Terms are not designed to satisfy the specific contractual requirements of DORA (in particular Article 30 of DORA) or of NIS2.
20. General Provisions
Notices. Any notice under these Terms is validly given by email to for nocert, and to the email address registered on the account for the Customer, unless otherwise specified (notably for termination for material breach, where registered letter is also permitted).
Assignment. The Customer may not assign these Terms without the prior written consent of nocert. nocert may assign the contract in the context of a merger, acquisition, or sale of all or part of its assets, subject to prior notice to the Customer.
Independence of the parties. The parties are independent contractors. These Terms do not create any partnership, joint venture, employment, or agency relationship.
Severability. If any provision of these Terms is held invalid or unenforceable, the remaining provisions shall remain in full force and effect. The invalid provision shall be replaced by a valid provision producing an economic effect as close as possible to that of the invalid provision.
Entire agreement. These Terms, together with the Privacy Policy, the DPA, and, where applicable, the Custom Plan individual agreement, constitute the entire agreement between the parties regarding the Service and supersede any prior agreement, written or oral, on the same subject. Prices and Plan features published at nocert.io/pricing are incorporated by reference for the purposes of Section 5.
Order of precedence. In the event of conflict between these Terms and an individual Custom Plan agreement, the Custom Plan agreement prevails on the matters it expressly addresses. In the event of conflict on a matter relating to Personal Data, the order of precedence set out in Section 15 of the DPA applies.
No waiver. The failure of a party to enforce any provision of these Terms at any given time shall not be construed as a waiver of its right to enforce that provision at a later time.
Language. These Terms have been drafted in English and the English version is the only legally binding version. Any translation that nocert may provide for convenience does not have legal effect; in case of discrepancy, the English version prevails. The Customer expressly acknowledges that, as a professional, it has the linguistic capacity to read and understand these Terms in English, and agrees that English is the working language of the contract. The use of English is agreed between professionals in accordance with the circulaire du 19 mars 1996 on the application of loi n° 94-665 du 4 août 1994.
Contractual limitation period. By exception to Article 2224 of the French Code civil and pursuant to Article 2254 of the same Code, any action arising from these Terms or from the use of the Service shall be brought within twelve (12) months from the date on which the claimant became aware, or should reasonably have become aware, of the facts giving rise to the claim, save for public-order rules of French law that prohibit such reduction (in particular, the statutory regime of latent defects under Article 1648 of the Code civil retains its own limitation period).
21. Contact
For any question relating to these Terms, the Customer may contact nocert at: