Skip to content
VITROVAULT
An INKASEC service
Trust Centre Pricing Security Articles FAQ
Sign in Start free

Legal

Terms and Conditions of Service

VitroVault Trust Centre, a service of INKASEC Ltd. These Terms incorporate the Data Processing Agreement (clause 13 and Schedule 1).

Version 1. Effective date: 27 August 2026.

Background

1. INKASEC Ltd provides VitroVault, a hosted trust centre service through which a supplier presents its security and compliance documentation to the buyers who need to see it, keeps that presentation current, and controls who may access what (the “Service”).

2. The Service is a documentary demonstration and presentation service. It presents what your documentation establishes. It is not an audit, a certification, or any form of assurance that a security control exists or operates, and nothing presented through the Service is a statement by INKASEC about your security posture. Clause 16 (Nature and Limits of the Service) applies to the whole of these Terms.

3. These Terms govern the relationship between INKASEC and the supplier operating a trust page. Visitors who view a trust page are not party to these Terms; their access is governed by the notices and agreements presented to them on the trust page, including the Standard NDA where applicable.

4. By accepting these Terms at registration, by the affirmative act described in clause 2.2 and before any materials are uploaded or any trust page is created, you agree to be bound by them, including the Data Processing Agreement in clause 13 and Schedule 1. If you do not agree, you must not use the Service.

5. You must be at least 18 years old and authorised to bind the organisation on whose behalf you use the Service.

1. Definitions and Interpretation

1.1 In these Terms, unless the context requires otherwise:

  • “INKASEC”, “we”, “us”, “our” means INKASEC Ltd, a company registered in England and Wales (company number 10566243), with its registered office at 138 Deans Lane, Edgware, HA8 9NR, United Kingdom. VitroVault is an INKASEC service.
  • “Supplier”, “Customer”, “you”, “your” mean the organisation that operates a trust page under these Terms and the individuals who accept these Terms and act on its behalf. The organisation is the Customer; individuals are its Authorised Users.
  • “Authorised User” means an individual authorised by the Customer to use the Service under the Customer’s organisation account, in the roles made available for the Customer’s tier (administrator, contributor, reviewer).
  • “Administrator” means an Authorised User holding the administrator role. Only Administrators may accept these Terms or a new version of them on the Customer’s behalf, cancel or change a subscription, elect what happens to the Trust Centre at the end of a term, or close the Trust Centre. We send notices to Administrators (clause 19.8).
  • “Trust Page” means the buyer-facing page or pages presenting your Published Materials, hosted by the Service on a VitroVault subdomain or, where your tier includes it, on your own domain.
  • “Trust Centre” means your Trust Page together with your Demonstration Set, Published Materials, Event Log and the other data the Service holds for your organisation.
  • “Visitor” means any person who views a Trust Page or takes part in an access or NDA ceremony on it, including a buyer’s security or procurement reviewer.
  • “Supplier Materials” means the documents and information you upload to or supply through the Service, including policies, standards, certificates, reports and supporting documentation, and the descriptive content of your Trust Page.
  • “Published Materials” means the subset of Supplier Materials and derived items (including any coverage view you choose to publish) that you have published to your Trust Page. Published Materials are held in a separate published store and are published only by your explicit action.
  • “Demonstration Set” means the bounded set of Supplier Materials that the Service holds to map, check, present, and keep your documentation current. The Service is not an archive, and the Demonstration Set is not a system of record.
  • “Standard NDA” means the standard-form non-disclosure agreement we make available for use on Trust Pages, entered into between you and a Visitor through the click-through ceremony, in the version presented at acceptance.
  • “Custom NDA” means a non-disclosure or similar agreement on your own terms that you upload for use with named Visitors. The Free tier uses the Standard NDA only; the Plus tier includes one Custom NDA and the Managed tier includes up to five.
  • “Event Log” means the append-only record of events relating to your Trust Page, including publication, access grants and revocations, NDA acceptances, views and downloads, together with the identity-assurance level recorded for each acceptance. The Event Log is your record and is deleted with your Trust Centre (clause 15.4); it is distinct from our platform records (clause 13.7).
  • “Evidence Pack” means the standalone export file the Service produces for a Visitor’s acceptance and access history, readable without the Service.
  • “Kept-Current Mark” means the mark displayed on a Trust Page on the Managed tier indicating that the Service maintains the page’s currency, as described in clause 7.
  • “Powered-by Badge” means the VitroVault attribution badge displayed in the footer of Trust Pages on the Free and Plus tiers.
  • “SQR Service” means the INKASEC security questionnaire response service, provided under its own terms and conditions, as described in clause 9.
  • “Tier” means the service tier applicable to your account (Free, Plus or Managed), with the entitlements published for that tier from time to time.
  • “Subscription Term” means each annual period for which a Plus or Managed subscription has been paid.
  • “Wind-Down Period” means the 30-day period described in clause 5.4 that follows a failed renewal payment.
  • “Closure” means the permanent closure and erasure of your Trust Centre under clause 15.4, and “close” and “closed” are read accordingly.
  • “Data Processing Agreement” or “DPA” means clause 13 together with Schedule 1.

2. The Service and How It Works

2.1 The Service enables you to: (a) host your conformance documentation in a Demonstration Set; (b) publish a Trust Page presenting your Published Materials to Visitors; (c) control Visitor access through three access levels (public, on request, and NDA-gated); (d) where your tier includes it, present a coverage view mapping your documentation to the expected areas of supported standards; and (e) on the Managed tier, have the currency of your presentation maintained through the managed cadence described in clause 7.

2.2 Acceptance before service: these Terms, including the DPA, are presented at registration and must be accepted before any Supplier Materials are uploaded and before any Trust Page is created. Acceptance is by the affirmative act of ticking a box on the registration form that is not pre-ticked; the form cannot be completed without it. Where your organisation account already exists because you use another INKASEC service (clause 9.2), or where for any other reason no acceptance is on record, the console asks for the same affirmative act before any other action and cannot be dismissed until it is given. We record the version of these Terms accepted, the date and time, the identity of the accepting user, the network address from which acceptance was given and whether it was given on the registration form or in the console, and we keep that record in our platform records (clause 13.7). We email the accepting user a copy of the version you accepted. The version you accept is the version we have published at the time; you or any software acting for you cannot choose a different version. When we issue a new version, we will ask an Administrator to review and accept it on next sign-in (clause 19.3); only an Administrator can accept on the Customer’s behalf, and an earlier acceptance remains on record.

2.3 Publication is always your action. Nothing you upload is visible to any Visitor until you publish it, and the published store is separate from your working materials. You choose the access level of each published document, and you may unpublish at any time.

2.4 Coverage view: where your tier includes it, the Service can present, for a supported standard, whether a named document addresses each expected area. Coverage is presented in binary form only: an area is addressed by a named document, or it is not. The Service does not present percentages, grades, ratings or any judgement of quality. Two labels exist and are always distinguished: (a) “Declared”, meaning you have mapped the document to the area yourself; and (b) “Assessed” (Managed tier), meaning the Service has checked, on a documentary basis, that the named document addresses the area. An Assessed label is a documentary check of your documentation only; clause 16 applies to it in full. Publishing a coverage view to Visitors is your explicit choice and is off by default.

2.5 The Service names the kinds of documents buyers commonly expect to see and suggests an access-level placement for each. It never supplies policy templates, standard texts or model documents. Everything demonstrated through the Service is your own documentation.

2.6 The Service does not monitor live systems, collect operational evidence, or generate drift alerts. Currency is maintained through the managed process in clause 7, from the documents you supply.

2.7 We may decline to make the Service available for particular content or use in accordance with clause 4 (Acceptable Use).

3. Your Responsibilities

3.1 You are responsible for the accuracy, completeness, lawfulness and adequacy of the Supplier Materials, and for ensuring you have the right to supply them to us and to publish those you choose to publish. The Service is not an archive and holds a single copy of each document (Schedule 1, paragraph C.6); you retain your own master copies.

3.2 You are responsible for reviewing everything before you publish it. Published Materials, including any published coverage view, are your representations to your Visitors, not ours. You must not publish anything you know or ought to know to be inaccurate, and you must not use the Service to misrepresent your security posture.

3.3 You are responsible for choosing the access level of each published document. The suggested placements are for guidance only; you decide, and you bear the consequences.

3.4 The Customer is responsible for deciding who is an Authorised User, for removing users who should no longer have access, and for the acts and omissions of each Authorised User as if they were its own. Each Authorised User must keep their credentials secure, and the Customer is responsible for activity under its account. Where your tier includes reviewer approval of publication, that internal control does not transfer any responsibility for published content to us.

3.5 You are responsible for keeping your organisation’s details on the Trust Page accurate, and for responding to the refresh prompts described in clause 7 if you wish your page to remain current.

3.6 You must keep at least one Administrator with a working email address on your account at all times. We send every notice under these Terms, including renewal reminders and the Wind-Down Period notices in clause 5.4, to Administrators’ email addresses. Where you have completed a paid checkout, we may also use the billing telephone number and address you provided to the payment processor to contact you for reasonable clarifications, but we will give notice by email (clause 19.8).

4. Acceptable Use and Content Policy

4.1 The Service exists to host and present conformance documentation: your security and compliance policies, standards, certificates, reports, and directly supporting materials. You must not use the Service to host or distribute materials outside that purpose. In particular, you must not use the Service as a general file store, a document distribution channel, or a substitute for a data room.

4.2 You must not: (a) impersonate another organisation or misrepresent your identity on a Trust Page; (b) publish unlawful content, infringing, or deceptive; (c) generate or procure scripted, automated or otherwise non-genuine NDA signings, access requests or page traffic; or (d) attempt to access another customer’s data or interfere with the operation of the Service.

4.3 Fair use: NDA signings, Visitor access and analytics are not artificially capped, on the basis that they reflect genuine buyer activity. We may apply proportionate technical limits where activity is inconsistent with genuine use.

4.4 Every Trust Page carries a “report a concern” mechanism. We operate a takedown process: where we reasonably believe that content or a page breaches this clause or applicable law, we may unpublish the content or suspend the page, explain why, and allow you to respond, save where the law or the seriousness of the matter requires immediate action.

4.5 We may verify organisation details presented on Trust Pages and may decline or withdraw pages where identity cannot reasonably be established.

5. Charges, Tiers, Payment and Non-Payment

5.1 The Service is offered in the Tiers published from time to time. The Free tier is provided at no charge. The Plus and Managed tiers are paid annual subscriptions at the prices published from time to time, excluding VAT. VAT is added where applicable.

5.2 Payment is processed by our third-party payment processor, Stripe (https://stripe.com). We do not store your full card details. We determine entitlements based on our records, not the payment processor’s. The payment processor collects a billing telephone number and address at checkout. We hold them as billing contact details under the Privacy Notice and may use them to contact you about your account for reasonable clarifications; they are not a channel for notice under these Terms (clause 19.8). Free-tier customers who have not completed a checkout will not have given them.

5.3 Renewal and cancellation: your subscription renews automatically at the end of each Subscription Term at the then-current published price. Thirty days before each renewal, we will email your Administrators the renewal date and the basis of the amount. You may cancel at any time before renewal. Cancellation takes effect at the end of the Subscription Term already paid for, never earlier, and may be reversed at any time until that date. When you cancel, you must elect what happens to your Trust Centre at the end of the term: it either continues on the Free tier (clause 15.6) or is closed (clause 15.4). Neither option is preselected, and you can't confirm cancellation without making an election. Statutory cancellation rights, where applicable, are unaffected.

5.4 Non-payment: if a renewal payment fails, that is not a cancellation and your Trust Page stays published. Once the payment processor’s retry process has concluded without payment, we will email your Administrators that the renewal has failed, and again each week for 30 days; four notices in all, the last stating that it is the final notice. That period is the Wind-Down Period. Throughout it you may pay the renewal, in which case the subscription continues, or make the election in clause 5.3 to continue on the Free tier or to close. If you have done neither by the end of the Wind-Down Period, you are treated as having elected to close, and your Trust Centre is closed under clause 15.4 at that point. The Wind-Down Period is also your export window (clause 15.5). Silence ends the account only in this way and only after those notices.

5.5 Refunds and proration: except as required by law, subscription charges are non-refundable once the Subscription Term has begun; no part of a term is refunded or credited on cancellation, downgrade or closure, and nothing is prorated. On an upgrade under clause 5.7, the remainder of the old term is forfeited.

5.6 The Free tier: we may change the features of the Free tier, or withdraw it, on not less than 30 days’ notice to your Administrators. We will not delete your data on withdrawal without that notice and the opportunity to export it during that period (clause 15.5).

5.7 Changing tier: you may move between the paid tiers from the console. Moving up takes effect immediately at the full published price of the new tier and starts a new Subscription Term from that day; the unused part of the old term is not credited, and the console tells you so before you confirm. Moving down takes effect at the end of the current Subscription Term: nothing is charged or credited at the time, the next invoice is for the lower tier, and you may reverse the change at any time until the term ends. When moving down from Managed to Plus, if you have more than one Custom NDA in use, you choose which one remains in use; the others are retained, not deleted.

5.8 Optional services (for example, done-for-you document maintenance or single-tenant deployment under clause 14) are charged separately as agreed in writing.

6. Tier Entitlements, the Badge and Users

6.1 The entitlements of each Tier (including document allowances, user roles and numbers, custom domain availability, coverage view type, and Managed features) are as published from time to time. Allowances exist to keep the Service within its purpose (clause 4.1), not to meter genuine buyer activity.

6.2 Powered-by Badge: Trust Pages on the Free and Plus tiers display the Powered-by Badge in the page footer. Display of the badge is a condition of those tiers. On the Managed tier, the badge is optional.

6.3 Users and roles: the Customer may authorise the number and roles of Authorised Users included in its Tier. On the Managed tier, publication and access grants use a two-person control: the person approving a publication must be different from the person who drafted it. This is an internal control of the Service; clause 3.4 applies.

6.4 Custom domain: where your Tier includes it, you may serve your Trust Page from your own domain by pointing a DNS record you control at the Service. You are responsible for your DNS configuration and for your right to use the domain. The domain continues to resolve to your Trust Page for as long as your Trust Page exists, including on the Free tier. On Closure, it stops resolving, and only you can repoint it.

6.5 Changing tier: clause 5.7 governs when a change takes effect and what is charged; clause 15.6 describes the effect of moving to the Free tier.

7. Managed Currency and the Kept-Current Mark

7.1 On the Managed tier, the Service maintains a per-standard cadence for your Demonstration Set: it tracks the review rhythms relevant to your supported standards and your documents, prompts you when a document is due for refresh, re-checks coverage when you refresh, and re-presents your Trust Page accordingly.

7.2 Our commitment under this clause is to operate that cadence: to track, prompt, re-check and re-present. Refreshing the underlying documents is and remains your responsibility. The Service cannot and does not keep your documentation current on your behalf unless you have separately purchased a done-for-you service under clause 5.8.

7.3 The Kept-Current Mark is displayed on your Trust Page while your Managed cadence is current. If items fall overdue, the Mark is withdrawn automatically, and your Trust Page shows only the date of the last update until you refresh the overdue items. The Mark reflects the state of the cadence and nothing else; it is never displayed contrary to that state.

7.4 Every Trust Page, on every Tier, displays the date of last update.

7.5 The Kept-Current Mark indicates that the page is maintained through the Service. It is not a certification, an audit outcome, or any statement by us about your security posture, and you must not describe or use it as such.

8. Visitor Access, NDAs and the Event Log

8.1 Three access levels are available for Published Materials: (a) public, available to any Visitor; (b) on request, available after the Visitor verifies an email address and you approve the request; and (c) NDA-gated, available after the Visitor completes the applicable NDA ceremony.

8.2 Standard NDA: the Standard NDA is a standard-form agreement made available by us for your convenience, entered into between you and the Visitor through the click-through ceremony on your Trust Page. We are not a party to it; we present it, record its acceptance (including the timestamp, IP address, NDA version, and the identity-assurance level used), and enforce the resulting access within the Service. The agreement a Visitor accepts on your Trust Page is between you and the Visitor, not between you and us.

8.3 Custom NDA (one on the Plus tier, up to five on the Managed tier): you may use your own non-disclosure paper for named Visitors. Custom NDAs work on a named-recipient basis: you designate the counterparty’s email address, the Visitor verifies control of that mailbox with a fresh code each session, and acceptance is by a typed-signature ceremony, with your approval before access is granted. Your Custom NDA is your legal document: you are responsible for its content, suitability and enforceability, and nothing we do in presenting it or recording its acceptance is legal advice or a warranty of enforceability.

8.4 Access constraints: where your Tier includes them, you may set constraints on grants, such as expiry and download tracking, and you may revoke a grant at any time. Revocation ends future access; it does not retrieve copies already lawfully obtained.

8.5 Event Log: The Service keeps an append-only Event Log for your Trust Page from its creation, at the same quality on every Tier. You may export it at any time while your Trust Centre exists, and each Visitor’s Evidence Pack is a standalone file that remains readable without the Service. The Event Log is designed for you and your Visitors to rely on as an accurate record of ceremonies and access while it exists; it is deleted with your Trust Centre on Closure (clause 15.4), and the exported Evidence Pack is the durable record. Clause 13.7 addresses retention and erasure requests.

8.6 Visitors do not create accounts. Visitor identity assurance is proportionate to what is being accessed, from anonymous public viewing, through verified email, to the named-recipient ceremony for Custom NDAs, and the assurance level used is recorded with each acceptance.

9. Relationship with the SQR Service

9.1 The Service and the SQR Service are separate INKASEC services, each governed by its own terms. Accepting one service’s terms does not constitute acceptance of the other’s: each service’s terms must be reviewed and accepted before that service begins, even if you already use the other, and acceptance is recorded per service and per terms version.

9.2 One identity: if you use both services, you use them under one shared account identity and one organisation. Signing up to the Service with an email address already registered with the SQR Service adds this Service to your existing identity; it does not create a second account. Your payment identity (including saved payment method and VAT details) is shared across both services, but each service issues its own invoices and holds its own entitlements. A payment method saved or pre-authorised with the payment processor for either service may be charged for the other service’s subscription, but only for charges you have confirmed in that service’s console.

9.3 Promotion from the SQR Service: at your election, the evidence documents from an SQR engagement may be promoted into your Demonstration Set in one explicit step, with provenance recorded. On promotion, the copy held by this Service becomes the maintained master, governed by these Terms and independent of the copy (if any) held under the SQR Service’s terms. Deleting materials in one service does not delete the independently governed copy in the other.

9.4 Answer reuse: where you use the SQR Service after promotion, it may, at your election, draw on your maintained Demonstration Set rather than on materials retained under the SQR terms, so that answers are produced from your current documents.

9.5 Independence of the services: Closure of your Trust Centre, or deletion of your data in one service, does not close your account with, suspend, or delete your data from the other, and does not remove your sign-in. Your shared identity persists as long as either service remains active. A request to erase the shared identity is a separate, cross-service action, subject in each service to the retention requirements in its terms (in this Service, clause 13).

9.6 When you convert an SQR Bundle to this Service, any onboarding benefit is as described in the SQR terms and the published offer at the time of conversion.

10. Intellectual Property and Licences

10.1 You retain all rights in your Supplier Materials. You grant us a non-exclusive licence to host, process, reproduce and display them only to the extent necessary to provide the Service, including serving your Published Materials to Visitors in accordance with the access levels you set.

10.2 You grant us, for the duration of your use of the Service, a non-exclusive licence to display your name, logo and chosen accent colour on your Trust Page and within the Service for the purpose of presenting your Trust Page as yours. We will not use your name or logo for our own marketing without your consent.

10.3 We grant you, for the duration of the relevant entitlement, a non-exclusive, non-transferable licence to display the Powered-by Badge and (on the Managed tier, while current) the Kept-Current Mark on your Trust Page as rendered by the Service. You must not display the Mark or Badge anywhere else, alter them, or use them in any way that suggests certification, audit or assurance by us. The licence to the Mark ends automatically when it is withdrawn under clause 7.3 or your Managed subscription ends.

10.4 We retain all rights in the Service, including its software, the expectation-sets, checklists, cadence logic and presentation, which are and remain our property (or that of our licensors). You must not copy, scrape, reverse-engineer or extract them.

11. Availability and Support

11.1 We aim to make the Service available, but do not guarantee uninterrupted or error-free operation, and no service level applies unless separately agreed in writing. Published Trust Pages are served as static content, which is resilient by design, and dynamic ceremonies may be briefly unavailable during maintenance.

11.2 Support is provided by email, by a person, on every Tier, at the address published on our website. Onboarding assistance is included on the Managed tier. We do not commit to a response time unless separately agreed in writing.

11.3 We may carry out maintenance and may modify features on reasonable notice where practicable. Clause 5.6 applies to the Free tier.

12. Confidentiality

12.1 Each party may receive the other’s confidential information. Your unpublished Supplier Materials are your confidential information. Materials you publish at the public access level are, by your choice, not confidential; materials you publish behind request or NDA gates remain confidential and are disclosed only under the access model you configure.

12.2 Each party shall keep the other’s confidential information confidential, use it only to perform or receive the Service, and not disclose it except to those who need to know it and are bound by equivalent obligations, or as required by law.

12.3 This clause does not apply to information that is or becomes public through no breach, was lawfully known before disclosure, or is independently developed.

13. Data Protection and Data Processing Agreement

13.1 This clause and Schedule 1 together are the Data Processing Agreement between you and us. They form part of these Terms, are accepted with them under clause 2.2, and are versioned with them. Both parties shall comply with the applicable data protection legislation, being the UK GDPR, the Data Protection Act 2018 and, where relevant, the EU GDPR, in each case as amended or replaced from time to time (the “Data Protection Legislation”). Terms defined in the Data Protection Legislation have the same meaning here.

13.2 Residency: the Service stores and processes Supplier Materials within the EU (Ireland) region of our cloud infrastructure provider. Published Trust Page content and the site’s static assets are delivered to Visitors through the provider’s content delivery network, restricted to edge locations in Europe; gated documents are not delivered that way and are served only from the EU (Ireland) region through expiring signed links. We will not transfer Supplier Materials outside the EEA or the United Kingdom except under a lawful transfer mechanism, and we will tell you if we propose to do so. Clause 14 addresses single-tenant deployments in other regions at your request.

13.3 Processing on your behalf: Supplier Materials primarily consist of business documentation. To the extent they, or your Authorised Users’ account data, contain Personal Data, you are Controller, and we are Processor. Schedule 1 sets out the subject matter, duration, nature, and purpose of the processing, and the types of Personal Data and categories of data subjects. As Processor we shall: (a) process the Personal Data only on your documented instructions, which are these Terms and your use of the Service’s functions, unless required by law to do otherwise, in which case we will tell you first unless the law prevents it; (b) ensure that persons authorised to process it are bound by confidentiality; (c) implement the technical and organisational measures in Schedule 1 and any others appropriate to the risk; (d) engage sub-processors only under written terms imposing equivalent obligations, maintain the list in Schedule 1, and give you notice of any intended change so that you may object on reasonable grounds; (e) taking into account the nature of the processing, assist you by appropriate technical and organisational measures in responding to data subject requests and, so far as reasonably possible, in meeting your obligations under Articles 32 to 36; (f) at your choice, delete or return the Personal Data at the end of the provision of the Service, as clause 15 provides, and delete existing copies unless the law requires storage; (g) make available all information necessary to demonstrate compliance with this clause and allow for and contribute to audits, including inspections, conducted by you or an auditor mandated by you, on reasonable notice and not more than once a year unless required by a supervisory authority or following a Personal Data breach; and (h) notify you without undue delay after becoming aware of a Personal Data breach affecting your Personal Data, with the information you need to meet your own notification obligations.

13.4 Visitor data: the ceremonies on your Trust Page collect Visitor Personal Data (such as name, company, role, email address and IP address) to operate access control and to create the acceptance and access records you and your Visitors rely on. The Supplier is the Controller of Visitor Personal Data collected through its Trust Page ceremonies, and we are the Processor; clause 13.3 and Schedule 1 apply. We act as an independent Controller only for our platform records under clause 13.7. Where you give us the address of your own privacy notice, your Trust Page links it, so that a Visitor giving you their details can read the practices of the organisation that is the Controller of them.

13.5 Retention (the Demonstration Set): the Service holds a bounded Demonstration Set, not an archive. Your Supplier Materials and Published Materials are retained while your Trust Centre exists and are permanently erased on Closure in accordance with clause 15. You may delete individual materials at any time, and deletion includes internal working data derived from them.

13.6 Deletion authority: deletion of the Customer’s data is an act of the organisation, exercised through an Administrator. An individual Authorised User’s departure is an offboarding event (their access is revoked and their Personal Data is handled in accordance with the Privacy Notice); it is never, by itself, a deletion of the organisation’s Trust Page or Demonstration Set.

13.7 The Event Log, our platform records, and erasure: two records exist and are treated differently. (a) The Event Log is yours. It is append-only by design and its acceptance records exist to be relied on by you and by Visitors while your Trust Centre exists. Where erasure of Personal Data is requested by you, by an Authorised User or by a Visitor, we will honour it in respect of the Demonstration Set and account data, but acceptance and access records in the Event Log are retained for 18 months from the event, or until Closure if earlier, based on our and your legitimate interests in the integrity of records that may be needed to establish, exercise or defend legal claims, with access to them restricted to that purpose. On Closure, we delete the Event Log with the rest of your Trust Centre, and it is not recoverable; export it, or the Evidence Packs you need, before then. (b) Our platform records are ours and survive Closure. They are limited to the record of your acceptance of these Terms and each version of them (clause 2.2), the transaction records in clause 13.8, our operational and security logs in clause 13.9, the hash anchors of your Event Log described in Schedule 1 paragraph C.4 (which contain no content and are kept for seven years), and the record of the Closure itself (when, by whom or by which election, and that it was carried out). We hold them as Controller; you cannot retrieve them through the Service, and they are not a copy of your Trust Centre.

13.8 Transaction records: we are required by law to retain financial and transaction records (invoice, customer identity, what was purchased and when) for a minimum of 7 years. This obligation overrides erasure for those records only, and we retain only the minimum metadata.

13.9 Operational and security logs: we retain operational and security logs (which may include IP addresses and event data) based on our legitimate interests in securing and operating the Service and preventing misuse, for up to 18 months, after which they are deleted or anonymised.

13.10 Automated processing: where the Managed tier’s coverage checking uses third-party large language model services, we use providers that process the data within the agreed region and do not use your materials to train their models, on terms consistent with this clause, and they are listed as sub-processors in Schedule 1.

13.11 The Privacy Notice, available on our website, explains how we handle Personal Data as Controller. It is a separate document and does not form part of these Terms; if it conflicts with this clause regarding our obligations to you, this clause prevails.

14. Single-Tenant Deployment (On Demand)

14.1 The Service is provided by default as a shared, multi-tenant platform in the EU (Ireland) region, with customer data logically separated per organisation. That default is the Service described in these Terms.

14.2 On request, and subject to a separate written order and separate charges, we may provide the Managed tier as a single-tenant deployment: a dedicated instance of the Service for your organisation, in an agreed supported cloud region. Where agreed, the order will state the region, the residency commitments that replace clause 13.2 for that deployment, the charges, the term, and any variations to service management and support.

14.3 Unless and until such an order is agreed, nothing in these Terms entitles you to a single-tenant deployment, and all references to the Service are to the shared platform.

15. Suspension, Termination, Closure and What Happens to Your Trust Centre

15.1 Either party may terminate for the other’s material breach not remedied within 30 days of notice, or immediately if the other becomes insolvent. We may suspend or unpublish under clause 4.4 (takedown), and may suspend for serious or persistent breach of clause 4 pending resolution. If we terminate under this clause, we will give you at least 30 days from notice to export (clause 15.5) before Closure, unless the law or the seriousness of the matter requires immediate action.

15.2 Ending a paid subscription: clause 5.3 (cancellation), clause 5.4 (non-payment) and clause 5.7 (moving down) govern when a paid subscription ends or changes and the election you make when it does. In each case, the Trust Centre either continues on the Free tier under clause 15.6 or is closed under clause 15.4, and either way nothing happens to your Trust Page before the end of the Subscription Term already paid for or, on non-payment, before the end of the Wind-Down Period.

15.3 Closing at your request: an Administrator may close your Trust Centre at any time from the console, or by written notice to us. Closure elected on cancellation takes effect at the end of the Subscription Term; closure requested from the console outside a cancellation, including on the Free tier, takes effect when you complete the confirmation on the closure screen. The closure screen states what happens and what survives before you confirm.

15.4 Effect of Closure: when Closure takes effect, your Trust Page and every page and document in your Trust Centre, including your Demonstration Set, Published Materials and Event Log, are permanently erased; Visitor access ends; your VitroVault addresses stop resolving, and any custom domain stops resolving until you repoint it. Erasure is immediate and irreversible. There is no archive, no grace copy and no restoration, and we cannot recover a closed Trust Centre for you on request; the continuity backups described in Schedule 1, paragraph C.6 are not used for that purpose. What survives: your sign-in and any other INKASEC service (clause 9.5), and our platform records under clauses 13.7(b) and 13.8, which are not a copy of your Trust Centre.

15.5 Export: your Supplier Materials, your Event Log, and each Visitor’s Evidence Pack are exportable from the console at any time while your Trust Centre exists. Where Closure follows a cancellation, the export window is the remainder of the Subscription Term. Where Closure follows non-payment, the export window is the Wind-Down Period, running from the first failed-renewal notice under clause 5.4. Where we terminate under clause 15.1 or withdraw the Free tier under clause 5.6, the export window is the notice period stated there. No export is possible after Closure.

15.6 Effect of moving to the Free tier: where your Trust Centre continues on the Free tier at the end of a Subscription Term, your Trust Page, its documents, its published versions, every acceptance by a Visitor and the whole Event Log remain. What is withdrawn is what the paid tier provided: any published Assessed coverage view is removed from your Trust Page (a Declared view may remain where the tier supports it), the Kept-Current Mark is withdrawn, machine credentials issued for the Service are revoked, and Custom NDAs cease to be available for new acceptances (their text is retained, not deleted, and the Standard NDA applies). The Powered-by Badge applies. Your custom domain is not touched and continues to resolve to your Trust Page. Existing NDA acceptances and the Event Log are unaffected.

15.7 Accrued rights survive termination and Closure, as do clauses intended to survive (including clauses 10, 12, 13, 16, 17 and 18).

16. Nature and Limits of the Service

16.1 The Service is a documentary demonstration and presentation service. It does NOT, and does not purport to: (a) audit, certify, accredit or provide assurance of your information security, your controls, or your conformance with any standard, law or regulation; (b) verify, test or confirm that any control described in your documentation exists, operates or is effective in practice; (c) constitute legal, regulatory, audit, insurance or professional advice, including in relation to any NDA used through the Service; or (d) promise that any Visitor, buyer, auditor, insurer or regulator will accept your Trust Page or your documents in place of their own process.

16.2 Everything presented on a Trust Page is derived from and limited to your own documentation and your own statements. A coverage view, whether Declared or Assessed, states only that a named document addresses, or does not address, an expected area on a documentary basis. It is not a statement about your practice, and an unaddressed area is a statement about documentation, not about the absence of a control.

16.3 The Kept-Current Mark and the Powered-by Badge are statements about the operation of the Service, not about your security posture.

16.4 As between you and us, your Trust Page carries your representations. We make no representation to any Visitor about you, and nothing in the Service is INKASEC vouching for you to a counterparty.

16.5 We do not warrant the accuracy, adequacy or fitness of your Supplier Materials, and you are responsible for everything you publish.

17. Limitation of Liability

17.1 Nothing in these Terms excludes or limits liability for death or personal injury caused by negligence, for fraud or fraudulent misrepresentation, or for any liability that cannot lawfully be excluded.

17.2 Subject to clause 17.1, we are not liable for: (a) any indirect or consequential loss; (b) loss of profit, revenue, business, goodwill or anticipated savings; (c) any loss arising from content you published, from your choice of access level, or from inaccurate or incomplete Supplier Materials; (d) any decision made by you or any third party (including any Visitor or buyer) in reliance on your Trust Page or its contents; (e) the acts or omissions of any Visitor, including any breach by a Visitor of an NDA; or (f) any loss of data that you could have exported during an export window under clause 15.5 and did not.

17.3 Subject to clause 17.1, our total aggregate liability arising out of or in connection with the Service, whether in contract, tort (including negligence) or otherwise, shall not exceed the total charges paid by you to us for the Service in the twelve months preceding the event giving rise to the claim or, where you are on the Free tier and have paid no charges, £1.

17.4 You acknowledge that the charges (and, for the Free tier, the absence of charges) reflect the allocation of risk in these Terms and that the limits in this clause are reasonable.

18. Indemnity

18.1 You shall indemnify us against losses, claims and reasonable costs arising from: (a) your breach of these Terms, including clause 4; (b) the Supplier Materials and Published Materials, including any claim that they infringe a third party’s rights, are unlawful, or misrepresent your position; (c) any claim by a Visitor or other third party arising from your Trust Page, your NDAs or your access decisions; or (d) any decision made by a third party in reliance on your Trust Page.

19. General

19.1 Force majeure: neither party is liable for delay or failure caused by events beyond its reasonable control.

19.2 Entire agreement: these Terms, including Schedule 1 (together with any written order under clause 14, any tier-specific terms, and the published price schedule and tier entitlements they reference) constitute the entire agreement between the parties regarding the Service and supersede all prior arrangements.

19.3 Variation: We may amend these Terms on reasonable notice. When we issue a new version, each Administrator is asked to review and accept it on the next sign-in; we issue a version only for material changes. Acceptance of a new version is recorded as in clause 2.2 and does not remove the record of earlier acceptances. Continued use of the Service after the effective date constitutes acceptance. Changes materially adverse to an active paid subscription take effect from its next renewal unless required sooner by law.

19.4 Assignment: you may not assign without our consent; we may assign to a successor of our business.

19.5 These Terms create no partnership or agency, and nothing in them makes us a party to any contract between you and a Visitor.

19.6 Third parties: a person who is not a party to the contract has no rights under the Contracts (Rights of Third Parties) Act 1999 to enforce these Terms.

19.7 Waiver and severance: failure to enforce is not a waiver; if any provision is invalid, the rest continues in force.

19.8 Notices: notices to us must be sent to info@inkasec.co.uk. Every notice to you under these Terms is sent by email to the email addresses of your Administrators as held on your account at the time of sending, and is treated as served when sent. Under clause 3.6, you are responsible for keeping those addresses current. We do not give notice by post or telephone. We may use a billing telephone number or address held by the payment processor to contact you about reasonable clarifications, but that contact is not notice under these Terms.

19.9 Governing law and jurisdiction: these Terms are governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction, save that we may seek injunctive relief in any jurisdiction.

Schedule 1: Data Processing Particulars

Part A: Description of processing

A.1 Subject matter: the hosting, presentation and access control of the Customer’s conformance documentation through the Service, and the operation of the Customer’s Trust Page ceremonies.

A.2 Duration: from acceptance of these Terms until Closure, plus the retentions in clauses 13.7 to 13.9.

A.3 Nature and purpose: storage, organisation, presentation, access control, coverage checking (Managed tier), export, and deletion, for the purpose of providing the Service.

A.4 Types of Personal Data: (i) Authorised Users: name, business email address, role, sign-in and activity data, IP address; (ii) Personal Data incidentally contained in Supplier Materials, such as names of document owners, approvers and auditors; (iii) Visitors: name, company, role, email address, IP address, acceptance and access records, identity-assurance level.

A.5 Categories of data subject: the Customer’s Authorised Users; individuals named in Supplier Materials; Visitors to the Customer’s Trust Page.

Part B: Sub-processors

B.1 The sub-processors engaged in providing the Service are:

Sub-processorLocationPurposeWhat it receives
Amazon Web Services EMEA SARLEU (Ireland), eu-west-1The whole hosting platform: storage of Supplier Materials and Published Materials, the database holding your account, page and Event Log records, the application runtime, identity and sign-in, and the encryption key serviceAll Supplier Materials, Published Materials, Authorised User account data, Visitor ceremony records and Event Log entries
Stripe Payments Europe LtdIreland, with transfers to the United States under the transfer mechanism in Stripe’s termsPaymentThe billing name, email address, telephone number and address, card details, and the identifier of the organisation the payment is for.

B.2 We will give you notice of any intended addition or replacement, as clause 13.3(d) provides.

VitroVault, an INKASEC service · vitrovault.com Pricing · Security · Articles · FAQ · Contact · Terms and Conditions of Service · Privacy Notice · © 2026 INKASEC