Client Related Policies for Ethicontrol Platform
Fair usage policy
Why do we have a Fair Usage Policy?
Ethicontrol SaaS product is a multi-tenant service. This means that SaaS services are used concurrently by a number of subscribers. If a single customer places very high demands on the service then it is possible that this will affect the experience for other users.
The vast majority of our customers use their service considerately and their usage levels during peak hours don’t disproportionately affect the shared network and service capacity. Even though only a very small number of our customers may use the service inappropriately, their activity has the potential to affect the service for others.
Our Fair Use Policy manages the inappropriate use and makes sure the service can be used fairly by everyone.
Support
Support is typically provided free of charge as part of the Services we offer. To ensure that all customers have equal access to support, we may restrict or suspend access to support for any customer that consuming more support time, or logging more support issues than a typical customer with similar users and a similar subscription.
Storage
Within your SaaS environment you can store documents to record correspondence as well as data and transactions in the database. To make sure that there is enough storage for everyone, we may limit the amount of data you can save. By default it is 10 GB.
The amount of storage may depend on your type of contract and number of users. We've made sure that almost all customers have plenty of disk space when the solutions are used normally. You can always request the actual size of your data storage from our service desk. You can also free up more storage by removing data yourselves, or asking us to help you with our clean-up-service.
If we detect that your organisation structurally saves more data than we consider to be fair and normal, we'll contact you to discuss the situation. It's possible to expand your storage and, if appropriate we will only charge a maximum of the published and publicly available Microsoft Azure / AWS / Linode storage charge for the relevant storage solution plus 20%. At that point we'll contact you to discuss alternative storage options.
Network Traffic and Bandwidth
To prevent a negative effect of excessive network traffic on your user experience or that of others, we monitor the traffic. We compare your use to the average use of all our SaaS customers with the same contract. With normal use you don't have to worry about the network bandwidth available to you. If we detect a situation that could lead to a decrease in service, we will contact you to discuss the situation. In some situations, we can intervene by limiting the available bandwidth.
Amount of sent and received emails
To prevent spam, we use worldwide blacklists, and spam blockers among other things. To guarantee smooth email traffic from our SaaS products for you and our other customers, we monitor the mail servers.
Spam and blacklisting could happen when excessive amounts of emails are sent from the SaaS environments, for example. We maintain very broad margins based on the average use of our SaaS customers with similar contracts. With normal use, you won't notice a thing.
When we detect abnormal values that could negatively impact the service, we may limit the number of emails you can send, or take other action as appropriate. Before we do this, or in urgent situations immediately after doing so, we'll always contact you to discuss possible solutions.
Compute and Load
To prevent a negative effect of excessive use of compute resources, on your user experience or that of others, we monitor the compute resources.
We compare your use to the average use of all our SaaS customers with the same contract. With normal use you don't have to worry about the compute services available to you.
Where increased usage is caused by the normal growth of users and customers, we will scale the resources available. If we detect a situation that reflects abnormal use or that could lead to a decrease in service, we will contact you to discuss the situation. In some situations, we can intervene by limiting the available compute resource.
Urgent and Extreme Cases
In an urgent or extreme case, for example where services are likely to be significantly impacted, or where we believe your system or ours is under attack (a DDOS - denial of service attack for instance) or where we believe your system or ours has been compromised (for example a hacker or potential a security breach) we may stop the services, or temporarily block your access to them. Before we do this, or in urgent situations immediately after doing so, we'll always contact you to discuss possible solutions.
In some cases, even without an attack or breach, if your use of the services continues to impact other users, is expected to do so, or is generating costs to us that are not normal when compared to other customers on the same contract and make our service to you unprofitable to maintain, we may isolate your services from the multi-tenanted environments and pass the costs onto you. Before we do this, or in urgent situations immediately after doing so, we'll always contact you to discuss possible solutions.
Terms of use
Legal use only
The Customer shall not access, store, distribute or transmit any Viruses, or any material during the course of its use of the Services that:
(a) is unlawful, harmful, threatening, defamatory, obscene, infringing, harassing or racially or ethnically offensive;
(b) facilitates illegal activity;
(c) in a manner that is otherwise illegal or causes damage or injury to any person or property; and Ethicontrol reserves the right, without liability or prejudice to its other rights to the Customer, to disable the Customer’s access to any material that breaches the provisions of this clause.
Law enforcement
Ethicontrol shall fully co-operate with any law enforcement authorities or court order requesting or directing Ethicontrol to disclose the identity or locate anyone posting any material in breach of clause LEGAL USE clause.
Respect for intellectual property
The Customer shall not:
(a) except as may be allowed by any applicable law which is incapable of exclusion by agreement between the parties:
(i) and except to the extent expressly permitted under this Agreement, attempt to copy, modify, duplicate, create derivative works from, frame, mirror, republish, download, display, transmit, or distribute all or any portion of the Services or Product Description (as applicable) in any form or media or by any means; or
(ii) attempt to reverse compile, disassemble, reverse engineer or otherwise reduce to human-perceivable form all or any part of the Services; or
(b) access all or any part of the Services and Product Description in order to build a product or service which competes with the Services and/or the Product Description; or
(c) use the Services and/or Product Description to provide services to third parties; or
(d) license, sell, rent, lease, transfer, assign, distribute, display, disclose, or otherwise commercially exploit, or otherwise make the Services and/or Product Description available to any third party, or
(e) attempt to obtain, or assist third parties in obtaining, access to the Services and/or Product Description.
Unauthorised use prevention
The Customer shall use all reasonable endeavours to prevent any unauthorised access to, or use of, the Services and/or the Product Description and, in the event of any such unauthorised access or use, promptly notify Ethicontrol.
The rights provided under this Service Agreement are granted to the Customer only, and shall not be considered granted to any subsidiary or holding company of the Customer. Only one subscription to the Services may be activated by any company, person or other entity. Duplicate subscriptions for any company, person or entity shall be considered a material breach of the Service Agreement.
The Customer undertakes to ensure that all Users comply with this Agreement and acknowledge that Customer shall remain responsible and liable for the acts or omissions of all Users to the same extent as if Customer had carried out such acts or omissions itself.
Responsibility for the security of any usernames and passwords issued (including those of any Users) rests with Customer. If Customer has reason to believe that their credentials or User account details have been obtained by another without consent, the Customer should contact Ethicontrol immediately to suspend the account.
Data Breach Notification Policy
This policy defines what qualifies as a breach of user data, what actions will be taken in the event of user data exposure or compromise, and the timeline for action.
This policy applies to user data stored on Ethicontrol.com. It does not apply to self-hosted / on-premises instances or instances hosted with other providers than Ethicontrol.com
Data Classification - What information is covered by this policy
This policy covers "private user data" stored by Ethicontrol.com, and includes:
- Client's database
- Client's files
- Encrypted Passwords
- Private Email Addresses
Note: Ethicontrol.com does not store any "personally identifiable information" (PII) such as (i) Private Addresses, (ii) Credit Card Numbers, (iii) Bank Account Information, (iv) ID numbers (e.g. passport, driver's license, social security, national identification, etc.). Ethicontrol.com and subdomains also does not store any "personal health information" (PHI). Therefore, laws and regulations relating to PII and PHI do not apply.
What qualifies as a breach?
A breach of user data is the unintended or accidental exposure of private user data. This can be caused by accidents, misconfigurations, or malicious actions performed by an external attacker or team member.
An event is considered a data breach when there is evidence that private user data has been exposed to the public or to an untrusted third party.
Trusted third parties may have authorized access to user data under a signed Non-Disclosure Agreement (NDA). Such trusted third parties include but are not limited to:
- Cloud service providers
- Database consultants
- Security auditors
- Financial auditors
Some examples of a user data breach would include:
- Compromise of a database server that contains private user data with evidence that an attacker may have had access to or copied the data off-site.
- Compromise of an application server account that has access to private user data and evidence that the attacker has downloaded or accessed private data.
- Theft of a device known to contain private user data.
- Web application attack used to download a list of all user emails and encrypted passwords.
What is not considered a breach?
Examples of security incidents that would not be considered a breach of private user data:
- Compromise of an application server that does not contain or have access to private user data.
- Compromise of a team member application account that does not have access to private user data.
- Malware infection on a server or team member computer system that does not contain private user data.
- Compromise of non-sensitive user data such as login IP addresses, login history, project permissions.
- Unintentional disclosure of project names, group names, issue titles, or project or user metadata unless this data can cause damage to the user or their business.
- Discovery of a vulnerability that could have been used to compromise private data, but for which there is no evidence of exploitation.
- Theft of a team member's mobile device that does not contain private user data.
- Theft of a team member's private keys, tokens, or other credentials provided there is no evidence they were used to access private user data.
You can check out these common non-vulnerabilities that will not be considered as a breach.
Who will be notified in the event of a data breach
If Ethicontrol has detected evidence of a breach of Ethicontrol.com or Ethicontrol Hosted private user data, all affected users will be notified via the configured email address for their accounts. Emails will contain information on what data was exposed or compromised, when, and for how long (to the extent this information is available).
For a breach that exposes private data for a large number of users, the public will also be informed via the configured email addresses for their accounts, and additional means of communication will be considered (e.g. press release, the blog, etc.) on a case by case basis.
Notification timing
Ethicontrol will endeavor to notify users within 24 hours of breach discovery. This may be delayed when necessary to comply with requests by law enforcement.
Report security issue
We know how much work goes in to pen testing!
To avoid frustration, you can check out these common non-vulnerabilities that don't qualify for rewards.
Got a valid issue? Awesome! Please include:
- A summary of the problem
- A severity rating of 1 — 5 (1 being least severe, 5 being most ie. you can easily hijack, impersonate or access any other account or data)
- A PoC or breakdown of how to replicate the issue
- The operating system name and version as well as the web browsers name and version that you used to replicate the issue
Send to security (at) ethicontrol.com
Rewards
We're eternally grateful for all of those who put in hard work to identify weaknesses within Ethicontrol.
For reports that are not common non-vulnerabilities, we like to reward those who responsibly disclose vulnerabilities with an acknowledgement, swag or bounty money.
Whisky and biscuits can be also provided during one to one meeting.
Acknowledgements
We appreciate the work that goes into finding and disclosing security flaws in Ethicontrol and would like to thank the following individuals and organisations:
System requirements for users
Web intake users
- Computer and processor 1 gigahertz (GHz) or faster
- Memory 2 GB RAM
- Hard disk 3 GB available disk space
- Display - any screen resolution
- Operating system - for the best experience, use the latest version of any operating system.
- Browser - any
Incident and case management users
Computer and processor 1 gigahertz (GHz) or faster x86-bit or x64-bit processor with SSE2 instruction set
Memory 4 GB RAM
Hard disk 3 GB available disk space
Display - for the better experience use displays with resolution starting from 768 px width (medium sized tablets and bigger)
Operating system - any
Browser
- Chrome 21+ (recommended)
- Firefox 28+
- Edge 12+
- Safari 7+
- Opera 17+
- Android 6.0+
Internet Explorer is NOT supported.
Default SLA policy
Version: 30/05/2023
Service Level Terms
SaaS
The Services shall be available 99%, measured monthly, excluding holidays and weekends and scheduled maintenance. If the Customer requests maintenance during these hours, any uptime or downtime calculation will exclude periods affected by such maintenance. Further, any downtime resulting from outages of third-party connections or utilities or other reasons beyond the Company’s control will also be excluded from any such calculation. Customer's sole and exclusive remedy, and Company's entire liability, in connection with Service availability, shall be that for each period of downtime lasting longer than five hours, Company will credit Customer 5% of Service fees for each period of 30 or more consecutive minutes of downtime; provided that no more than one such credit will accrue per day.
Downtime shall begin to accrue as soon as Customer (with notice to Company) recognizes that downtime is taking place, and continues until the availability of the Services is restored. To receive downtime credit, the Customer must notify the Company in writing within 24 hours from the time of downtime, and failure to provide such notice will forfeit the right to receive downtime credit.
Such credits may not be redeemed for cash and shall not be cumulative beyond a total of credits for one (1) week of Service Fees in any one (1) calendar month in any event. The company will only apply a credit to the month in which the incident occurred. Company’s blocking of data communications or other Services by its policies shall not be deemed to be a failure of the Company to provide adequate service levels under this Agreement.
Call centre
Service Availability: The Call Center commits to a service availability of 99% uptime, excluding scheduled maintenance windows, which shall be communicated to the Client in advance.
Response Time: The Call Center shall ensure that 80% of calls are answered within 40 seconds (excluding automatic welcome messages).
Support
Our Support portal help.ethicontrol.com is available 24/7 and is multilingual. There is a Knowledge base with user manual articles. Users can create support tickets using chatbots, email, or support portals.
Besides, Help widgets are visible in the client user interface. The widgets are connected to the Support portal and our support team.
By default, we provide technical support during working hours from Monday to Friday. The standard support level is included in all tariff plans.
Our normal support level is up to 24h for the first response and up to 40h to resolve the issue. The exact timing should depend on the severity of the issue.
Suggested severity levels:
Emergency — impacts human wellbeing; Very High level of associated risk; Anything related to breach/loss of data.
Critical — clients cannot use/access the Ethicontrol platform or services; the phone line (or any other intake channel) is busy or not working. Major Service Outage – contributing to the loss of day-to-day business operations. Major interruption in the functionality, resulting in a capacity decrease of more than 70% (of the entire system).
Moderate — some Ethicontrol services are unavailable, but reporters/whistleblowers can still communicate with a client and the client’s users can access case management, respond to reporters, and document cases; some cases are inaccessible; workflows/statuses issues; access rights issues; notification/reminder/emails issues.
- Service outage resulting in loss of business operation
- Service incapacity requiring immediate action results in a capacity decrease of more than 30%.
- The defect does not fail but causes failures in some components
- Operation of an existing network, system, or services is severely degraded or significant aspects of hotline services are negatively affected by inadequate performance.
Low — everything else which does not require immediate or expedite resolution and can “wait” at least a week.
- No outage or loss of functionality of the component(s) or services
- Minimal operational impact.
- Operational performance of the network, system, or services is impaired while most of the hotline services remain functional.
The severity level is used to rank the service requests.
The service level commitment “Maximum response time” and “Maximum resolution time” are measured from the time a client contacts the Ethicontrol support or account manager (for critical issues).
Default Response objectives
| Incident Severity Definition (Helpdesk) | Response | Resolution | 
| Emergency | 4 business hours | 2-8 business Hrs. | 
| Critical | 8 business hours | 24 hours | 
| Medium | 16 business hours | 5 business days | 
| Low | 24 business hours | 10 business days | 
Escalation Management (Critical Incident)
- Alert appropriate client personnel that an emergency (critical incident) has occurred, which may require their urgent attention.
- Escalation process for clients – 
- 1st line of defence — Support portal, email support@ethicontrol.com.
- 2nd line of defence — Support engineer email supportteam@ethicontrol.com, which should deal with 90% of cases. CC — account manager.
- 3rd line of defence — Ethicontrol engineers. CC — CTO, account manager
- Ultimate escalation — CEO, CC — CTO, account manager
 
- Default Point of Contact — support@ethicontrol.com
Disclaimer for on-premise Solution
The Vendor accepts no responsibility for issues that are NOT the responsibility of the vendor and should be cared for by the Customer:
- Deficiencies/issues caused by the Customer infrastructure or Customer’s servers where Ethicontrol applications are hosted.
- Behaviour of Customer equipment, facilities, or applications. Customer network maintenance or any other issues within the Customer infrastructure
- Circuits provided by telephone companies or other common carriers
- Tampering of Ethicontrol applications either by customer, Customer’s agents, or by unauthorized third parties, including but not limited to property owners and their agents.
- Any external Internet supplier, Service Provider, or an Internet exchange point.
- The customer’s network is being compromised by unauthorized access.
- The deliverability of emails to recipients.
- The redundancy and continuity of the services.
- Acts of God, acts of nature, acts of civil or military authority, governmental actions, fires, civil disturbances, terrorism, and interruptions of power or transportation problems.
- Any delay or performance failure caused by Customer’s failure to perform any obligations under this Agreement.
The compliance with local data privacy and Information/IT Security rules, laws, and regulations applicable to federal government entities is the Customer's responsibility. The vendor accepts no responsibility for breaches of reporters’ anonymity or confidentiality for reasons that are under the control of the Customer's network and server infrastructure.
Feature development and change management policy
Version: 12/10/2024
Purpose
This policy defines the stages and classifications for feature development in our system, ensuring clarity and alignment between client needs and development capabilities.
Scope
The policy applies to all requests for new features, modifications, or enhancements within the Ethicontrol system. It outlines how features are assessed, prioritized, and implemented to effectively meet client requirements.
Definitions
- Feature Development: The process of designing, coding, testing, and implementing new functionalities or enhancements.
- Change Management: The structured approach to modifying existing features, systems, or processes to achieve a desired outcome.
- Critical Changes: Changes with a significant impact on operations, security, or compliance.
- Standard Changes: Pre-approved routine changes with minimal risk.
Policy Statement
1. Governance
- All feature development and change requests must align with the organization's strategic goals and compliance requirements.
- A designated Product Committee (CTO + CEO + Product) will oversee high-impact changes and feature development approvals.
2. Feature Development
- Requirement Gathering: All features must have documented business requirements, functional specifications, and success criteria.
- Agile Practices: Feature development must follow Agile or an approved project management methodology.
- Quality Assurance (QA): All features must undergo rigorous QA testing, including unit, integration, and user acceptance testing (UAT).
3. Change Management Process
- Initiation: Submit a change request using the designated Change Request Form or tool.
- Risk Assessment: Evaluate the change for potential risks to security, operations, or compliance.
- Approval: Obtain necessary approvals based on the change's impact and risk category (e.g., CAB for critical changes).
- Implementation: Follow a documented process to deploy changes in production, including rollback procedures.
- Documentation: Maintain detailed records of all changes, including configuration, testing results, and approvals.
4. Emergency Changes
- Emergency changes must follow a streamlined process with immediate notification to stakeholders and post-implementation review.
5. Training and Communication
- Train relevant staff how to use the updated systems or features before they are launched.
- Communicate changes to all stakeholders, including end users, with clear instructions and timelines.
6. Monitoring and Review
- Post-implementation reviews must be conducted to evaluate the success of feature deployments or changes.
- Continuous improvement practices should be followed to enhance the change management process.
Roles and Responsibilities
| Change Requestor | Submits the initial feature or change request with detailed requirements. | 
| Product Owner/Manager | Oversees feature prioritization and ensures alignment with business goals. | 
| Product committee | Reviews and approves critical changes; provides risk mitigation guidance. | 
| Development Team | Designs, develops, and tests features or changes. | 
| QA Team | Conducts testing to ensure the quality of functionalities or changes. | 
| Operations Team | Deploys changes to production and monitors systems post-implementation. | 
| End Users | Provide feedback on features or changes during UAT or post-implementation. | 
Compliance
Non-compliance with this policy may result in disciplinary actions, up to and including termination, and may impact contractual agreements with third parties.
References
- ISO/IEC 27001
- ITIL Change Management Framework
- Agile Development Guidelines
Policy Review and Updates
This policy will be reviewed annually or as needed to ensure alignment with organizational needs and regulatory requirements.
Feature Availability Classifications
| Status | Description | Next Steps | Timeline | 
| Available as is | The requested feature is already integrated into the system and meets client requirements without need for modifications. Consult - https://ethicontrol.com/en/pricing | Activate or configure the feature to align with your requirements. | Immediately available. | 
| Available with notice | The feature exists and is operational but requires specific client input or adjustments to align with client requirements. | Contact our team to initiate the setup process. | Available upon notice, pending mutual agreement on the necessary considerations. | 
| Available with adjustments | The feature is present but may require minor configuration changes to match client expectations. Adjustments are superficial (e.g., appearance or interface changes). | Our team will make the necessary changes during implementation at no additional cost. | Adjustments are completed during the initial setup phase with no added development effort. | 
| Low-Hanging fruit | The feature is not immediately available but can be implemented with minor development efforts, typically within a short timeframe (e.g., one month). | Discuss priorities with our team to schedule delivery. | Expected delivery within one month, depending on development schedules. | 
| Not available but feasible (Short-Term or Long-Term) | The feature is planned within the development roadmap. Acceleration may require additional investment. | Engage in a roadmap consultation to explore timelines and options for acceleration. | Development within 12–24 months or sooner if expedited. | 
| Not available, Not feasible | The feature does not align with the development strategy and is not planned for implementation within the foreseeable future. | Explore alternative solutions with our team. | No implementation is expected. | 
Development Process
1. Request Evaluation
- Analyze the request against the classification above.
- Assess feasibility based on technical, resource, and strategic considerations.
2. Backlog review
3. Prioritization by Product
- Features are prioritized using criteria such as:
- Strategic alignment.
- Client demand and impact.
- Development effort versus value.
 
- Priority of features already on our roadmap will rise due to other clients' requests.
4. Approval by CTO + CEO
5. Task assignments and sprint planning
6. Delivery to staging
7. Quality check by the Product and QA
8. Review by CTO
9. Release planning
10. Release
11. Final check
Exceptions and Custom Requests
We recognize unique needs that may fall outside standard classifications. Custom feature development or expedited delivery can be arranged on a case-by-case basis, subject to technical and resource constraints. These requests may incur additional fees.
Feature request decision tree
End-User License Agreement
Updated at January 1st, 2025
Ethicontrol Whistleblowing and Case Management hereby grants you access to (“the app”) and invites you to purchase the services offered here.
Definitions and key terms
To help explain things as clearly as possible in this Eula, every time any of these terms are referenced, are strictly defined as:
- Cookie: small amount of data generated by a website/app and saved by your web browser. It is used to identify your browser, provide analytics, remember information about you such as your language preference or login information.
- Company: when this policy mentions “Company,” “we,” “us,” or “our,” it refers to Ethicontrol OÜ , (Orumetsa tn 5/1-15 Maardu linn Harju maakond 74111), that is responsible for your information under this Eula.
- Country: where Ethicontrol Whistleblowing and Case Management or the owners/founders of Ethicontrol Whistleblowing and Case Management are based, in this case is Estonia
- Service: refers to the service provided by Ethicontrol Whistleblowing and Case Management as described in the relative terms (if available) and on this platform.
- Third-party service: refers to advertisers, contest sponsors, promotional and marketing partners, and others who provide our content or whose products or services we think may interest you.
- App/Application: Ethicontrol Whistleblowing and Case Management app, refers to the SOFTWARE PRODUCT identified above.
- You: a person or entity that is registered with Ethicontrol Whistleblowing and Case Management to use the Services.
Introduction
This End User License Agreement (the “Agreement”) is a binding agreement between you (“End User”,“you” or “your”) and Ethicontrol OÜ (“Company”, “we”, “us” or “our”). This Agreement governs the relationship between you and us, and your use of the Company Ethicontrol Whistleblowing and Case Management. Throughout this Agreement, End User and Company may each be referred to as a “Party” or collectively, the “Parties”.
If you are using the app on behalf of your employer or other entity (an “Organisation”) for whose benefit you utilise the app or who owns or otherwise controls the means through which you utilise or access the app, then the terms “End User”, “you”, and “your” shall apply collectively to you as an individual and to the Organisation. If you use, or purchase a license or to, the app on behalf of an Organisation, you hereby acknowledge, warrant, and covenant that you have the authority to 1) purchase a license to the app on behalf of the Organisation; 2) bind the Organisation to the terms of this Agreement.
By downloading, installing, accessing, or using the app you: (a) affirm that you have all of the necessary permissions and authorisations to access and use the app; (b) if you are using the app pursuant to a license purchased by an organisation, that you are authorised by that organisation to access and use the app(c) acknowledge that you have read and that you understand this agreement; (d) represent that you are of sound mind to enter into a binding agreement; and (e) accept and agree to be legally bound by the terms and conditions of this agreement.
If you do not agree to these terms, do not download, install, access, or use the software. if you have already downloaded the software, delete it from your computing device.
The Application is licensed, not sold, to you by Ethicontrol Whistleblowing and Case Management for use strictly in accordance with the terms of this Agreement.
License
Subject to the terms of this Agreement and, if applicable, those terms provided in the License Agreement, Ethicontrol Whistleblowing and Case Management grants you a limited, non-exclusive, perpetual, revocable, and non-transferable license to:
(a) download, install and use the Software on one (1) Computing Device (Server) per single user license that you have purchased and been granted. If you have multiple Computer Devices in which you wish to use the Software, you agree to acquire a license for the number of devices you intend to use;
(b) access, view, and use on such Computing Device the End User Provided Materials made available in or otherwise accessible through the Software, strictly in accordance with this Agreement, and any other terms and conditions applicable to such End User Provided Materials;
(c) receive updates and new features that become available during the one (1) year period from the date on which you purchased the license to the Software.
Restrictions
You agree not to, and you will not permit others to:
- License, sell, rent, lease, assign, distribute, transmit, host, outsource, disclose or otherwise commercially exploit the Application or make the Application available to any third party.
- Modify, make derivative works of, disassemble, decrypt, reverse compile or reverse engineer any part of the Application.
- Remove, alter or obscure any proprietary notice (including any notice of copyright or trademark) of Ethicontrol Whistleblowing and Case Management or its affiliates, partners, suppliers or the licensors of the Application.
Intellectual Property
All intellectual property rights, including copyrights, patents, patent disclosures and inventions (whether patentable or not), trademarks service marks, trade secrets, know-how and other confidential information, trade dress, trade names, logos, corporate names and domain names, together with all of the good will associated there with, derivative works and all other rights (collectively, “Intellectual Property Rights”) that are part of the Software that are otherwise owned by Ethicontrol Whistleblowing and Case Management shall always remain the exclusive property of Ethicontrol Whistleblowing and Case Management (or of its suppliers or licensors, if and when applicable). Nothing in this Agreement grants you (or any Organisation) a license to Ethicontrol Whistleblowing and Case Management’s Intellectual Property Rights.
You agree that this is Agreement conveys a limited license to use Ethicontrol Whistleblowing and Case Management’s Intellectual Property Rights, solely as part of the Software (and not independently of it), and only for the effective Term of the license granted to you hereunder. Accordingly, your use of any of Ethicontrol Whistleblowing and Case Management’s Intellectual Property Rights independently of the Software or outside the scope of this Agreement shall be considered an infringement of Ethicontrol Whistleblowing and Case Management’s Intellectual Property Rights. This shall not limit, however, any claim Ethicontrol Whistleblowing and Case Management may have for a breach of contract in the event you breach a term or condition of this Agreement. You shall use the highest standard of care to safeguard all Software (including all copies thereof) from infringement, misappropriation, theft, misuse or unauthorised access. Except as expressly granted in this Agreement, Ethicontrol Whistleblowing and Case Management reserves and shall retain all rights, title, and interest in the Software, including all copyrights and copyrightable subject matter, trademarks and trademark able subject matter, patents and patentable subject matter, trade secrets, and other intellectual property rights, registered, unregistered, granted, applied-for, or both now in existence or that may be created, relating to the thereto.
You (or the Organisation, if and as applicable) shall retain ownership of all Intellectual Property Rights in and to the work products that you create through or with the assistance of the Software.
Your Suggestions
Any feedback, comments, ideas, improvements or suggestions (collectively, "Suggestions") provided by you to Ethicontrol Whistleblowing and Case Management with respect to the Application shall remain the sole and exclusive property of Ethicontrol Whistleblowing and Case Management.
Ethicontrol Whistleblowing and Case Management shall be free to use, copy, modify, publish, or redistribute the Suggestions for any purpose and in any way without any credit or any compensation to you.
Modifications to Application
Ethicontrol Whistleblowing and Case Management reserves the right to modify, suspend or discontinue, temporarily or permanently, the Application or any service to which it connects, with or without notice and without liability to you.
Updates to Application
Ethicontrol Whistleblowing and Case Management may from time to time provide enhancements or improvements to the features/ functionality of the Application, which may include patches, bug fixes, updates, upgrades and other modifications ("Updates").
Updates may modify or delete certain features and/or functionalities of the Application. You agree that Ethicontrol Whistleblowing and Case Management has no obligation to (i) provide any Updates, or (ii) continue to provide or enable any particular features and/or functionalities of the Application to you.
You further agree that all Updates will be (i) deemed to constitute an integral part of the Application, and (ii) subject to the terms and conditions of this Agreement.
Term and Termination
This Agreement shall remain in effect until terminated by you or Ethicontrol Whistleblowing and Case Management.
Ethicontrol Whistleblowing and Case Management may, in its sole discretion, at any time and for any or no reason, suspend or terminate this Agreement with or without prior notice.
This Agreement will terminate immediately, without prior notice from Ethicontrol Whistleblowing and Case Management, in the event that you fail to comply with any provision of this Agreement. You may also terminate this Agreement by deleting the Application and all copies thereof from your computer.
Upon termination of this Agreement, you shall cease all use of the Application and delete all copies of the Application from your computer.
Termination of this Agreement will not limit any of Ethicontrol Whistleblowing and Case Management’s rights or remedies at law or in equity in case of breach by you (during the term of this Agreement) of any of your obligations under the present Agreement.
Indemnification
You agree to indemnify, defend and hold harmless Ethicontrol Whistleblowing and Case Management and its officers, directors, employees, agents, affiliates, successors, and assigns from and against any and all losses, damages, liabilities, deficiencies, claims, actions, judgments, settlements, interest, awards, penalties, fines, costs, or expenses of whatever kind, including reasonable attorneys’ fees, arising from or relating to: i) your use or misuse of the Software; ii) your failure to comply with any applicable law, regulation, or government directive; iii) your breach of this Agreement; or iv) your agreement or relationship with an Organisation (if applicable) or any third party. Furthermore, you agree that Ethicontrol Whistleblowing and Case Management assumes no responsibility for the information or content you submit or make available through this Software or the content that is made available to you by third parties.
No Warranties
The Application is provided to you "AS IS" and "AS AVAILABLE" and with all faults and defects without warranty of any kind. To the maximum extent permitted under applicable law, Ethicontrol Whistleblowing and Case Management, on its own behalf and on behalf of its affiliates and its and their respective licensors and service providers, expressly disclaims all warranties, whether express, implied, statutory or otherwise, with respect to the Application, including all implied warranties of merchantability, fitness for a particular purpose, title and non-infringement, and warranties that may arise out of course of dealing, course of performance, usage or trade practice. Without limitation to the foregoing, Ethicontrol Whistleblowing and Case Management provides no warranty or undertaking, and makes no representation of any kind that the Application will meet your requirements, achieve any intended results, be compatible or work with any other software, applications, systems or services, operate without interruption, meet any performance or reliability standards or be error free or that any errors or defects can or will be corrected.
Without limiting the foregoing, neither Ethicontrol Whistleblowing and Case Management nor any Ethicontrol Whistleblowing and Case Management’s provider makes any representation or warranty of any kind, express or implied: (i) as to the operation or availability of the Application, or the information, content, and materials or products included thereon; (ii) that the Application will be uninterrupted or error-free; (iii) as to the accuracy, reliability, or currency of any information or content provided through the Application; or (iv) that the Application, its servers, the content, or e-mails sent from or on behalf of Ethicontrol Whistleblowing and Case Management are free of viruses, scripts, trojan horses, worms, malware, time bombs or other harmful components.
Some jurisdictions do not allow the exclusion of or limitations on implied warranties or the limitations on the applicable statutory rights of a consumer, so some or all of the above exclusions and limitations may not apply to you.
Limitation of Liability
Notwithstanding any damages that you might incur, the entire liability of Ethicontrol Whistleblowing and Case Management and any of its suppliers under any provision of this Agreement and your exclusive remedy for all of the foregoing shall be limited to the amount actually paid by you for the Application.
To the maximum extent permitted by applicable law, in no event shall Ethicontrol Whistleblowing and Case Management or its suppliers be liable for any special, incidental, indirect, or consequential damages whatsoever (including, but not limited to, damages for loss of profits, for loss of data or other information, for business interruption, for personal injury, for loss of privacy arising out of or in any way related to the use of or inability to use the Application, third-party software and/or third-party hardware used with the Application, or otherwise in connection with any provision of this Agreement), even if Ethicontrol Whistleblowing and Case Management or any supplier has been advised of the possibility of such damages and even if the remedy fails of its essential purpose.
Some states/jurisdictions do not allow the exclusion or limitation of incidental or consequential damages, so the above limitation or exclusion may not apply to you.
Severability
If any provision of this Agreement is held to be unenforceable or invalid, such provision will be changed and interpreted to accomplish the objectives of such provision to the greatest extent possible under applicable law and the remaining provisions will continue in full force and effect.
Waiver
No failure to exercise, and no delay in exercising, on the part of either party, any right or any power under this Agreement shall operate as a waiver of that right or power. Nor shall any single or partial exercise of any right or power under this Agreement preclude further exercise of that or any other right granted herein. In the event of a conflict between this Agreement and any applicable purchase or other terms, the terms of this Agreement shall govern.
Amendments to this Agreement
Ethicontrol Whistleblowing and Case Management reserves the right, at its sole discretion, to modify or replace this Agreement at any time. If a revision is material we will provide at least 30 days' notice prior to any new terms taking effect. What constitutes a material change will be determined at our sole discretion.
By continuing to access or use our Application after any revisions become effective, you agree to be bound by the revised terms. If you do not agree to the new terms, you are no longer authorized to use the Application.
Governing Law
The laws of Estonia, excluding its conflicts of law rules, shall govern this Agreement and your use of the Application. Your use of the Application may also be subject to other local, state, national, or international laws.
Changes to this agreement
We reserve the exclusive right to make changes to this Agreement from time to time. Your continued access to and use of the app constitutes your agreement to be bound by, and your acceptance of, the terms and conditions posted at such time. You acknowledge and agree that you accept this Agreement (and any amendments thereto) each time you load, access, or use the app. Therefore, we encourage you to review this Agreement regularly.
If, within thirty (30) days of us posting changes or amendments to this Agreement, you decide that you do not agree to the updated terms, you may withdraw your acceptance to the amended terms by providing us with written notice of your withdrawal. Upon providing us with the written notice of the withdrawal of your acceptance, you are no longer authorised to access or use the app.
No Employment or Agency Relationship
No provision of this Agreement, or any part of relationship between you and Ethicontrol Whistleblowing and Case Management, is intended to create nor shall they be deemed or construed to create any relationship between you and Ethicontrol Whistleblowing and Case Management other than that of and end user of the app and services provided.
Equitable Relief
You acknowledge and agree that your breach of this Agreement would cause Ethicontrol Whistleblowing and Case Management irreparable harm for which money damages alone would be inadequate. In addition to damages and any other remedies to which Ethicontrol Whistleblowing and Case Management may be entitled, you acknowledge and agree that we may seek injunctive relief to prevent the actual, threatened or continued breach of this Agreement.
Headings
The headings in this Agreement are for reference only and shall not limit the scope of, or otherwise affect, the interpretation of this Agreement.
Geographic Restrictions
The Company is based in Estonia and provided for access and use primarily by persons located in Estonia, and is maintains compliance with Estonia laws and regulations. If you use the app from outside Estonia, you are solely and exclusively responsible for compliance with local laws.
Limitation of Time to File Claims
Any cause of action or claim you may have arising out of or relating to this agreement or the app must be commenced within one (1) year after the cause of action accrues, otherwise, such cause of action or claim is permanently barred.
Entire Agreement
The Agreement constitutes the entire agreement between you and Ethicontrol Whistleblowing and Case Management regarding your use of the Application and supersedes all prior and contemporaneous written or oral agreements between you and Ethicontrol Whistleblowing and Case Management.
You may be subject to additional terms and conditions that apply when you use or purchase other Ethicontrol Whistleblowing and Case Management’s services, which Ethicontrol Whistleblowing and Case Management will provide to you at the time of such use or purchase.
Contact Us
Don't hesitate to contact us if you have any questions about this Agreement.
- Via Email: support@ethicontrol.com
- Via this Link: https://help.ethicontrol.com