Terms of Use

1. Service and Owner

1.1. "ATTACK SIMULATOR" (hereinafter, the "Service") is a digital service that can be accessed via the www.attacksimulator.com website (hereinafter, the "Website") that offers any client that subscribes to it (hereinafter, the "Subscriber") the ability to simulate believable cyberattacks of different types, also known as attack campaigns (including, but not limited to, ransomware, spam, phishing and malware), with the purpose of establishing: (i) the computer security skill level of the Subscriber's employees and the users' detection effectiveness; and (ii) the training required by his qualified personnel to prevent and recognize the attacks, thereby maintaining a secure environment and preventing and/or minimizing the hazards that these types of attacks may cause on the Subscriber's environment. The Service comprises the web pages, servers, programs and any other component and/or element that composes it, as well as (i) the technical information, installation manuals, instructions for use or any other documentation related to the Service; (ii) the images, photographs, sounds or other proprietary files; and (iii) any Service version, update, modification and/or upgrade.

1.2. The Service is owned by ATTACK SIMULATOR S.R.L. (hereinafter, the "Owner"), a Romanian entity registered under J12/127/2021 with tax identification number RO43550687, whose place of business is at 6 Augustin Presecan Street, Romania, website www.attacksimulator.com, phone +40 750 400 967, and e-mail contact@attacksimulator.com.

1.3. These terms and conditions of use ("Terms of Use"), along with the "Subscription Service License," are binding for Subscribers hiring the Service, who will be required to accept them before hiring the Service, as well as for the Users associated with the Subscriber's account, who shall be informed of these Terms of Use for their express acceptance prior to the use of the Service.

2. Service Subscription and Categories

2.1. In order to access and use the Service, the Subscriber will be first required to subscribe to any of the Service Plans provided, whose duration shall be as set forth herein and/or as per the specific conditions of the Subscriber's subscription, when applicable. The Service allows Subscribers to choose among the following Service Plans:

• INTENSIVE ATTACK SIMULATOR, whose duration is three (3) months.

• CONTINUOUS EDUCATION PROGRAM, monthly service with a custom-tailored duration depending on the specific conditions of the Subscriber's subscription.

• PERSONALIZED TRAINING, which is the most complete subscription category and enables the Service's features, including its duration, to be personalized, depending on the specific conditions of the Subscriber's subscription.

2.2. Each Service Plan will have a specific price that those interested in hiring the Service may see at any moment on the Website, along with the specifications and characteristics of each of them.

2.3. All Service Plans offer the following features:

• Subscriber's account maintenance and management, including the creation and assignment of user accounts and permission management;

• design and programming of simulated cyberattack campaigns to be directed exclusively at those employees of the Subscriber that have been previously marked for that purpose in their account;

• assignment of a unique identifier for each of the Subscriber's campaigns, to facilitate their management and an adequate rendering of the Service;

• customer service to address everyday inquiries about the use of the platform; and • technical support in case of incidents related to the platform.

2.4. The Owner expressly reserves the right to perform any modification to the Service, specifically including the development and deployment of new functionalities, and the modification, adaptation and/or elimination of current Service characteristics and functionalities. Furthermore, the Owner reserves the right to set new prices for the Service, after prior notice to the Subscribers, as well as to modify and/or add categories and Service Plans.

3. Subscribers and Users

3.1. Any person, organization or company that hires the Service shall be deemed to be a Subscriber. The Subscriber may create one or more user accounts and assign them to each natural person, who, under the Subscriber's coordination, authorization and direction, may access and use the Service as per its purposes (hereinafter, the "User").

3.2. In order to register his account, the Subscriber shall be required to complete the form for that purpose found in the Website. The Subscriber shall be required to have a valid e-mail account to receive the Service License, as well as any messages or notifications necessary for the proper functioning of the Service.

3.3. During the registration process, the Subscriber will provide the information used to authenticate his account, which he may use to access the Service. Once registered, the Subscriber will need to create the User accounts linked to his account, once again specifying the passwords for each of them.

3.4. The Subscriber and/or Users will be the ones who will provide the Service Owner with the information of the Subscriber's employees that each of the simulated cyberattack campaigns hired by the Subscriber pursuant to the Service will be directed to, specifying, among others, their names and surnames, e-mails and the name of the department they belong to, for each of them. It is the sole and exclusive responsibility of the Subscriber to have the proper authorization to do so by any of the employees affected by the performance of the hired Service.

3.5. When completing the registration process, the Subscriber will acknowledge and accept these Terms of Use, and he is bound to, and agrees to, notify these terms and conditions to all of the Users that he links to his account, by means of the procedure in place for that purpose within the Service, as well as to obtain their express acceptance of them before providing them access to the use of the Service.

3.6. Any provided information for the Subscriber, the linked Users or the Subscriber's employees that may be targeted by the campaigns performed pursuant to the Service shall be accurate, truthful, current and complete, and it shall be the responsibility of the Subscriber to keep them updated at all times. The Subscriber and the Users shall be responsible for the safekeeping of their identifiers, passwords or any other Service identification and access information, and shall be liable for any damages that may result from their improper use, assignment, disclosure or loss.

3.7. Account Eligibility and Company Affiliation

3.7.1. Company Affiliation Requirement: All User accounts created and linked to the Subscriber's account must belong to individuals who are employees, contractors, or otherwise officially affiliated with the Subscriber's organization (the "Parent Company"). The Service is intended exclusively for use by personnel within the Subscriber's organizational structure.

3.7.2. Verification of Affiliation: The Subscriber represents and warrants that all Users granted access to the Service are legitimately affiliated with the Parent Company and have been properly authorized to participate in cybersecurity training and simulation exercises. The Subscriber must maintain documentation of such authorization and affiliation.

3.7.3. Prohibited External Access: Under no circumstances may the Subscriber create accounts for, or grant access to, individuals who are not affiliated with the Parent Company, including but not limited to: a) Employees of other organizations b) Independent contractors not working for the Parent Company c) Personal contacts or family members d) Former employees who are no longer affiliated with the Parent Company e) Third-party vendors or partners (unless specifically contracted to the Parent Company)

3.8. Compliance Monitoring and Reporting

3.8.1. Ongoing Compliance: The Subscriber agrees to maintain ongoing compliance with the company affiliation requirements and to promptly notify the Owner of any changes in User employment status or company affiliation.

3.8.2. Monitoring Rights: The Owner reserves the right to monitor account usage patterns, email domains, and other indicators to detect potential violations of the company affiliation requirement.

3.8.3. Reporting Obligations: The Subscriber must immediately report any suspected unauthorized access or use of the Service by non-affiliated individuals and cooperate fully with any investigation.

4. Use of the Service

4.1. The Subscriber and the linked Users may only use the Service as per the functionality intended by the Owner, and shall, under all circumstances, be liable for the use of the Service. Furthermore, the Subscriber and the Users agree to use any of the components and/or elements that compose the Service adequately and in an acceptable manner. The Subscriber and the Users agree to refrain from using the Service in a way other than that which is implied by its purpose, including, but not limited to, introducing computer viruses on the network, using user accounts from others and/or carrying out any wrongful or unlawful act, and/or any act that is contrary to public order and good faith. In addition, they shall refrain from using the Service in a way that may be damaging to the rights and interests of the Owner or third parties, or than may in any way damage or hinder the image or reputation of the Owner, or prevent the normal use or enjoyment of the Service.

4.2. The Subscriber and the Users shall refrain from using the Service for purposes that include, but are not limited to: a) harassing or disturbing third parties and/or violate their intimacy and privacy; b) steal the identity of other users or third parties; c) spy on other users or third parties; d) disclose the location of other users to third parties; e) undermine the reputation, image and honor of other users or third parties; f) advertisement, with the purpose of promoting products, services or activities of third parties or their own; g) reverse engineering, decompiling, or attempting to derive the source code of the Service; h) using the Service to conduct actual cyberattacks or malicious activities; i) sharing, selling, or distributing simulation templates or attack methodologies to unauthorized parties.

4.3. The Subscriber and the Users agree to comply with all provisions contained herein, as well as in any notice, usage guidelines and instructions provided by the Owner and that are accessible to them, in relation to the use of the Service.

4.4. Enforcement and Penalties

4.4.1. Violation Detection: In the event that unauthorized accounts (accounts belonging to individuals not affiliated with the Parent Company) are detected, or any other use of the Service contrary to these Terms of Use is identified, the Owner reserves the right to implement the following enforcement measures.

4.4.2. Immediate Penalties for Unauthorized Account Creation:

a) First Offense: Immediate suspension of the unauthorized account(s) and written warning to the Subscriber, plus mandatory review of all User accounts within 48 hours to verify company affiliation and requirement to provide documentation proving affiliation of all Users.

b) Account Audit: Comprehensive review of all account activities and user verification documentation.

4.4.3. Escalated Penalties for Repeat Violations:

a) Second Offense: Temporary suspension of the entire Subscriber account for seven (7) days, monetary penalty equivalent to 50% of the monthly subscription fee, and mandatory compliance training for the Subscriber's account administrators.

b) Third Offense: Immediate termination of the Service subscription without refund, permanent ban from creating new accounts, and potential legal action for breach of contract.

4.4.4. Severe Violations: For egregious violations involving multiple unauthorized accounts or suspected misuse for competitive intelligence or other malicious purposes: immediate permanent termination of Service, full forfeiture of any prepaid subscription fees, pursuit of legal remedies including damages and injunctive relief, and reporting to relevant authorities if criminal activity is suspected.

4.4.5. Additional Enforcement Rights: The Owner reserves the right to implement enhanced monitoring and verification procedures, require additional documentation of User affiliation at any time, conduct periodic audits of account usage and User verification, and modify access permissions and features based on compliance history.

5. Acceptable Use and Ethical Guidelines

5.1. Legitimate Business Purpose: The Service shall only be used for legitimate cybersecurity training, awareness, and assessment purposes within the Subscriber's organization. The Service is not intended for, and shall not be used for, any form of actual cyberattack or malicious activity.

5.2. Employee Consent and Awareness: The Subscriber must ensure that all targeted employees have been properly informed about the cybersecurity training program and have provided appropriate consent for participation in simulated attack scenarios.

5.3. Industry Standards Compliance: The Subscriber agrees to use the Service in compliance with applicable industry standards and regulations, including but not limited to ISO 27001, NIST Cybersecurity Framework, and relevant data protection laws.

5.4. Responsible Disclosure: Any vulnerabilities or security issues discovered through the use of the Service must be reported immediately to the appropriate internal security teams and not disclosed to unauthorized parties.

6. Data Security and Incident Response

6.1. Security Standards: The Owner implements industry-standard security measures to protect all data processed through the Service, including encryption in transit and at rest, access controls, and regular security assessments.

6.2. Incident Response: In the event of a security incident affecting the Service, the Owner will notify affected Subscribers within 72 hours and provide detailed information about the incident, its impact, and remediation measures.

6.3. Data Breach Notification: The Owner maintains a formal incident response plan and will assist Subscribers in meeting their regulatory notification requirements in the event of a data breach.

6.4. Security Audits: The Owner undergoes regular third-party security audits and maintains relevant security certifications. Audit reports may be made available to Subscribers upon request and execution of appropriate non-disclosure agreements.

7. Service Level Agreement (SLA)

7.1. Availability: The Owner commits to maintaining Service availability of at least 99.5% measured monthly, excluding scheduled maintenance windows.

7.2. Performance Standards: The Service will maintain response times of less than 3 seconds for standard operations under normal load conditions.

7.3. Scheduled Maintenance: The Owner will provide at least 48 hours advance notice for scheduled maintenance that may affect Service availability.

7.4. Support Response Times:

    • Critical issues: 4 hours
    • High priority issues: 12 hours
    • Standard inquiries: 24-48 hours

7.5. Service Credits: In the event of failure to meet availability commitments, Subscribers may be eligible for service credits as outlined in the Service Level Agreement addendum.

8. Pricing and Payment Method

8.1. The subscription to the Service shall be activated upon the payment of the first instalment for the category chosen by the Subscriber at the moment of registration. The subscription shall remain active as long as the Subscriber pays the agreed-upon instalments, as per the corresponding payment period. The Owner will publish any information related to the various categories and Service Plans offered, including the corresponding subscription prices, on the Website.

8.2. The Provider commissions the collection of the instalments to a payment gateway service provider. The Service shall manage the collection of the amount for the first instalment of the subscription, corresponding to the selected category, as well as the collection of the subsequent periodic instalments, through the aforementioned payment gateway. In this payment gateway, the Subscriber may opt to perform the payment for the total of the corresponding instalment by any of the following payment methods: a) credit or debit card; b) bank transfer; c) PayPal; d) other systems that may be defined in the future.

8.3. Billing and Invoicing: The Owner will provide detailed invoices for all charges, including breakdowns of services used and applicable taxes. Invoices will be delivered electronically unless otherwise requested.

8.4. Late Payment: Accounts with payments more than 30 days overdue may be subject to service suspension. A reinstatement fee may apply for reactivation of suspended accounts.

8.5. Refunds and Cancellations: Refunds are provided on a pro-rated basis for cancelled subscriptions, subject to the cancellation terms outlined in Section 15.

9. Intellectual and Industrial Property Rights

9.1. All components and/or elements that compose the Service, including, but not limited to, the software, source code, designs, interfaces, patents, trademarks, logotypes and any other components and/or elements are protected by intellectual and industrial property rights owned by the Owner, whether as a result of being the original owner of such rights, or by having the appropriate authorizations or licenses by their third party owners for their use as part of the Service. None of the aforementioned components and/or elements that compose the Service may be used beyond the terms set forth in the Service License.

9.2. The Subscriber and the Users shall refrain from circumventing any measure or device put in place to guarantee the intellectual and industrial property rights of any of the components and/or elements of the Service.

9.3. Subscriber-Generated Content: Any custom configurations, templates, or reports created by the Subscriber remain the property of the Subscriber, subject to the Owner's rights to use such content solely for providing the Service.

9.4. Third-Party Content: The Service may include third-party content or integrations. Use of such content is subject to the applicable third-party license terms.

10. Privacy Policy

10.1. All personal data of the Subscriber and the Users linked to his account, whether collected at the time of the account registration, or during the use of the Service, will be added to a database owned by the Owner, who shall be the data controller, with the purpose of being used for the management and rendering of the Service, as well as, if expressly agreed by the interested party and separately from his consent to the collection of his data for such purpose, for the sending of any advertisement message related to its products and/or services. The Owner shall process the data solely for the purposes consented to by the interested parties, in a lawful, trustworthy and transparent manner, and agrees to comply with all obligations set forth by the personal data protection laws in effect (hereinafter, the "Data protection laws").

10.2. The interested parties may exercise, at any time, the rights that they are legally entitled to; in particular, the rights to access, rectify, delete and object, as well as the rights to erasure, limitation and portability, by sending an e-mail at contact@attacksimulator.com, duly identifying themselves and clearly specifying the purpose of their request. Under all circumstances, given that the effective performance of the Service requires counting with the aforementioned personal data of the Subscriber and the Users linked to his account, the request to delete the data shall result in the termination of the subscription to the Service and the deletion of his account, except in the event that such deletion is limited to the sending of advertising messages.

10.3. Furthermore, the Owner shall process the personal data of the Subscriber's employees provided by the Subscriber as a Data Processor, with the sole purpose of rendering the Service. This processing shall be performed on behalf of the Subscriber and as per his instructions and mandate. The Subscriber is obligated, and agrees, to previously obtain the express authorization of the employees whose data he provides to the Owner for the rendering of the Service, so that it can process the aforementioned data for the aforestated purposes, and in all circumstances, the Subscriber shall be solely and exclusively liable for the failure to be duly authorized by the employees, and the Owner shall be held harmless from any claim that may result from such noncompliance.

10.4. The Owner shall be authorized to subcontract the following providers for the performance of the service, if applicable, who shall act as data processors, with the purpose of individually rendering the corresponding services below:

• Amazon Web Services – database storage services

• Sendgrid – Mass mailing service used for the transfer of the simulated attacks

• Digital Ocean / Hetzner – hosting service for the web pages related to the simulated attacks

10.5. A third party to whom the Owner commissions the rendering of payment services, and who will be the only party responsible before the Subscriber for both the rendering of the service itself and for the processing of the personal data necessary for that purpose, including the corresponding banking information, shall handle the collection of the instalments corresponding to the acquired subscription, based on the hired category. This payment service shall include access to a payment gateway to which the Service will connect during the registration procedure for the collection of the first instalment corresponding to the hired category, as well as the collection of subsequent periodic instalments. The Owner will, at no time, store or have access to the banking information or other personal data provided by the Subscriber at the moment of making the payment through the aforementioned service, rendered by a third party, other than receiving the confirmation of the payment made by the Subscriber and the corresponding amount. To see the details of the processing of this personal data, the Subscriber may see the information provided by the owner of the payment service, who will be duly identified upon completing the subscription.

10.6. The personal data provided by the Subscriber and the Users linked to his account shall be accurate, truthful and current, and it shall be their exclusive responsibility to keep them updated at all times. Failure to do this shall result in them being liable for any damages that may arise as a result. Furthermore, the Subscriber and the Users linked to his account shall be responsible for the proper safekeeping of their respective identifiers, passwords or any other data used for identification and/or access to the Service, and they shall be liable for their improper use, assignment, disclosure or loss.

10.7. The Owner agrees to, at all times, care for the security and the compliance with the Data Protection Laws. For this purpose, it shall adopt the necessary technical and organizational security measures that are appropriate and sufficient, based on the characteristics of the processing, the type of data processed and the technology employed in the rendering of the Service, with the purpose of guaranteeing the data security, ensure its confidentiality, and prevent its undue processing, damage or loss. Furthermore, the Owner shall also make sure that the providers that intervene in the rendering of the Service as data processors adopt the necessary security measures, previously verifying that the specifications of their respective services allow it to guarantee the fulfilment of such commitment. In any event, the Owner shall provide the Subscriber with any information requested in relation to the purpose and lawfulness of the processing, the interested party and the personal data affected by such processing, the duration of its storage, and the rights that he may be entitled to, including the right to withdraw the consent to the processing, as well as file, when applicable, a claim before the control authority.

10.8. The Owner shall keep a record of all the personal data processing performed for the purposes of the rendering of the Service, informing its contact information and that of the data processors hired, if any, and specifying the nature and category of the data processed and the security measures implemented. In the event of any incident, or if any breach were detected in relation to the security of the personal data being processed, the Owner shall act immediately to prevent, reduce or minimize its effects, as well as to remedy or modify whatever is necessary and, if applicable, it shall notify the local Data Protection Agency within the established period.

10.9. Upon termination of the subscription for any reason, the Owner shall immediately destroy or, when applicable, return the personal data of the Subscribers and the Users linked to his account to the interested parties, and shall under no circumstance have the obligation to store them.

10.10. Any future modification to this Privacy policy shall be duly notified through the Service's Website.

11. Export Control and Compliance

11.1. Export Control Laws: The Subscriber acknowledges that the Service may be subject to export control laws and regulations. The Subscriber agrees to comply with all applicable export control laws and will not export, re-export, or transfer the Service to prohibited countries, entities, or individuals.

11.2. Regulatory Compliance: The Subscriber represents that its use of the Service complies with all applicable laws and regulations in its jurisdiction, including but not limited to cybersecurity, data protection, and employment laws.

11.3. Industry-Specific Requirements: Subscribers in regulated industries (healthcare, finance, government) acknowledge their responsibility to ensure compliance with industry-specific regulations and standards.

12. Service Security

12.1. The Owner shall not be obligated to control the presence of any virus, worm or any other computer element that may be harmful, destructive or hazardous in the equipment and computer resources of the Subscriber, his employees and other Users linked to his account. It is the responsibility of the Subscriber to have in place and implement the adequate tools for the detection, protection and disinfection of malware or any computer program that may result harmful or destructive or hazardous on his equipment and computer resources, including those of his employees and of the Users linked to his account. Consequently, the Owner shall, under no circumstance, be liable for any damages to the equipment and computer resources of the Subscriber, his employees and the Users linked to his account.

13. Cookie Policy

13.1. The Owner uses cookies with the purpose of collecting information about the use of the Service via the Website. The cookies are storage and data recovery mechanisms that are installed in the Subscriber's and the Users' computers for the purpose outlined herein, and to provide them with a better browsing experience.

13.2. Use of the Service implies that the Subscriber and the linked Users consent to the installation of cookies on their computers or devices for the purposes stated herein. Their refusal to using cookies may result on the use of the Service being affected, or for certain features to stop being operational, or even for it to be impossible to render the Service.

Types and purposes of cookies in use: a. Technical cookies: they enable the navigation of the Website and the use of the different options or services it offers, such as controlling the traffic and data transfer, identifying the session, accessing restricted access sections, remembering the items contained in an order, performing an order's purchasing process, completing a registration or event participation request, using security features during navigation, storing contents for the publishing of videos or sound, or sharing contents through social networks. b. Personalization cookies: they enable access to the Service with certain general predefined characteristics based on a series of criteria from the User's terminal, such as, for example, the language, the type of browser used to access the Service, the regional configuration from which the Service is accessed, etc. c. Analytical cookies: they are used by the Owner, or owned by third parties, and they allow whoever is in charge of them to track and analyze the behavior of the Subscriber and the Users of the Website linked to the Service. The information collected by this type of cookie is used to measure the activity in websites, applications or platforms, and to make navigation profiles for the users of those sites, applications and platforms with the purpose of introducing improvements based on the analysis data of the usage that users give to the Service. d. Advertising cookies: the allow for an effective management of advertising spaces included in the Service, including the garnishment of navigation profiles that allow for the collection of information related to the Subscriber's and Users' behavior, enabling the content of the advertisement to be tailored to them.

Cookie configuration: During the navigation of the Service's Website, the Subscriber and the Users have the option to allow, block or delete the cookies installed on their computer by configuring the options in the browser they use. The instructions to configure the use of cookies in the browser can be seen in the following links:

Chrome: https://support.google.com/chrome/answer/95647

Safari: https://support.apple.com/kb/ph21411

Firefox: https://support.mozilla.org/en-US/kb/delete-cookies-remove-info-websites-stored

Internet Explorer: https://support.microsoft.com/en-us/help/17442/windows-internet-explorer-delete-manage-cookies#ie=ie-11

In case another browser is used, the Subscriber and the Users may obtain information on configuring the use of cookies in their computers through their browsers' help. In case they need help to configure the cookies in the aforementioned browser, the Subscriber and the Users may send an e-mail at contact@attacksimulator.com, and the Owner will promptly contact them.

Changes: If deemed appropriate, the Owner may modify this cookie policy, and it shall be the responsibility of the Subscriber and the Users to periodically read the policy in effect at any given time.

14. Transfer of Confidential Information through the Service

14.1. Any information submitted by the Subscriber and/or his linked Users through the Service shall be treated as confidential and with due respect. Notwithstanding the foregoing, the Owner may delete that information when it considers it to be inappropriate or offensive, or it may allow access to the aforementioned information to the Courts and Authorities with Jurisdiction that so request it, as long as said access is in compliance with applicable laws.

14.2. The Owner may send messages for advertising purposes to the Subscriber and his linked Users as long as a prior authorization exists for that purpose, and solely in relation to its own products and/or services.

15. Technological Limitations

15.1. As a result of the performance of maintenance work, in specific cases there may be temporary interruptions to the Service. Furthermore, the Owner notifies that, in addition to the aforestated, a great variety of factors exist that may affect the functioning of the Service, including, but not limited to, environmental conditions, network saturation, connectivity, third-party software, etc.

16. Links to the Website

16.1. The Subscriber and/or his linked Users may establish links that lead to contents on the Website in third-party websites and applications, as long as, based on the way in which the link is implemented, it is evident that it links to a website other than the one in which the aforementioned link is located.

16.2. Under no circumstance may links be included in a website or application which contains wrongful or unlawful contents, or contents that are contrary to good faith. Furthermore, such links may not be added to websites or applications with strongly sexual or violent contents. In addition, links may not be added to websites or applications whose contents include, but are not limited to, xenophobic, discriminatory or pornographic contents, or contents that in any way go against people's dignity.

17. Service Improvements

17.1. With the purpose of improving the Service, the Owner may, at its own discretion, at any time and without prior notice, modify any component and/or element of the Service or its operation, technical and usage conditions.

17.2. Furthermore, the Subscriber and/or the Users may suggest any modifications they deem useful to the Owner with the purpose of improving the Service, as well as obtain any additional information or have their inquiries, complaints or suggestions addressed, by contacting the Owner via the Website. This shall, however, imply no obligation whatsoever for the Owner.

18. Business Continuity and Disaster Recovery

18.1. Backup and Recovery: The Owner maintains comprehensive backup systems and disaster recovery procedures to ensure Service continuity and data protection.

18.2. Business Continuity Plan: In the event of a major disruption, the Owner will implement its business continuity plan to restore Service operations as quickly as possible.

18.3. Data Recovery: The Owner commits to maintaining the ability to recover Subscriber data from backups in the event of data loss or corruption.

19. Limitation of Liability and Disclaimers

19.1. The Owner shall not be liable for any decision taken by the Subscriber as a consequence of the rendering of the Service, or for any damages that may result from them, either to the Subscriber or to third parties.

19.2. The Owner shall, moreover, not be liable for the speed, the navigation quality and the use and access to the Service, which shall depend on the technical conditions agreed upon with their service providers. Therefore, the Owner shall not be liable for the inability to access the Service, or for the discontinuation or cancellation of such access, or for issues with the connection to the communications network used by the Subscriber and/or Users linked to his account to access the Service, or for failures caused by third-parties. It shall, furthermore, not be liable for the continuation and availability of the Service when this cannot be guaranteed for causes not attributable to the Owner.

19.3. Limitation of Damages: The Owner's total liability to the Subscriber for any and all damages, losses, and causes of action shall not exceed the total amount paid by the Subscriber for the Service during the twelve (12) months preceding the event giving rise to liability.

19.4. Consequential Damages: Under no circumstances shall the Owner be liable for any indirect, incidental, special, consequential, or punitive damages, including but not limited to loss of profits, data, or business interruption.

20. Indemnification

20.1. Subscriber Indemnification: The Subscriber agrees to indemnify, defend, and hold harmless the Owner from and against any and all claims, damages, losses, costs, and expenses arising from or relating to the Subscriber's use of the Service, violation of these Terms of Use, or infringement of any third-party rights.

20.2. Scope of Indemnification: This indemnification includes but is not limited to legal fees, court costs, and damages awarded against the Owner as a result of the Subscriber's actions or omissions.

21. Duration and Termination

21.1. These Terms of Use shall remain in effect during the entire time that the Subscriber maintains an active subscription to the Service, by maintaining the registered account and using the Service himself and/or having his linked Users use the Service, until the Subscriber otherwise terminates the aforementioned account.

21.2. The Owner reserves the right to deny or terminate access to the Service and the services provided through it, if any, to any Subscriber and/or User that fails to comply with these Terms of Use.

21.3. Termination for Convenience: Either party may terminate the subscription with thirty (30) days written notice. Pro-rated refunds will be provided for prepaid periods.

21.4. Termination for Cause: The Owner may immediately terminate the Service for material breach of these Terms of Use, non-payment, or violation of applicable laws.

21.5. Effect of Termination: Upon termination, all access to the Service will cease, and the Subscriber's data will be deleted in accordance with the data retention policy.

22. Modification to the Terms of Use

22.1. The Owner reserves the right to modify these Terms of Use at any moment with thirty (30) days prior notice to Subscribers via email and posting on the Website.

22.2. Under all circumstances, before hiring and/or using the Service, the Subscriber and the Users linked to his account shall be required to accept the Terms of Use in effect at the time, which will be at their disposal.

22.3. Continued Use: Continued use of the Service following notification of changes constitutes acceptance of the modified Terms of Use.

23. Written Notifications

23.1. By accepting these General Terms of Use, the Subscriber and the Users agree for most communications with the Owner to be carried out by electronic means. The Owner will preferably contact the

E-mail
By sending an e-mail at contact@attacksimulator.com

Phone number
By calling +40 750 400 967