Terms of Service
- Version
- TERMS_2026_09_V1
- Effective
- 2026-09-13
Subscription Agreement for CyberWave Sentinel and related services
| Field | Value |
|---|---|
| Legal entity | CYBER WAVE INC. |
| Version | TERMS_2026_09_V1 |
| Effective date | 2026-09-13 |
| Contact | support@cyberwave.ca |
Preamble
These Terms of Service (the "Terms") form an agreement between you and CYBER WAVE INC., a corporation existing under the laws of Ontario, Canada (Ontario Corporation Number 1000780137), located in Markham, Ontario, Canada ("CyberWave", "we", "us" or "our"). CyberWave provides CyberWave Sentinel, a cybersecurity readiness, governance and evidence platform, with reporting, cyber-insurance readiness and advisory services. These Terms govern your use of all of it.
Four terms are stated here rather than buried, because they are the ones customers are most often surprised by.
- A free trial does not become a paid subscription. A 14-day free trial of the plan you select (Essentials or Full Platform), with no payment card required, no charge and no automatic conversion. Continuing after the trial means choosing a paid subscription. Your data is not deleted because a trial ended (§6).
- Paid subscriptions renew automatically until you cancel, and cancellation takes effect at the end of the period you have already paid for (§9).
- Section 32 limits what either party can recover — both the kinds of loss and the amount.
- CyberWave does not certify compliance and does not sell insurance. We help you get ready (§27, §28).
1 Definitions
"Account" — the credentials and profile through which an individual accesses the Services. "Add-On" — an optional item purchased in addition to a Plan, including additional user seats. "Administrator" — an Authorized User designated by the Customer to manage its Workspace, including users and billing. "Agreement" — these Terms with each document listed in §40.1. "AI Features" — features that generate, draft, summarise, analyse or narrate content using a large language model (§14). "AI Output" — content returned by an AI Feature in response to an Input. "Applicable Law" — the laws, regulations and binding regulatory requirements applying to a party in performing the Agreement. "Authorized User" — an individual the Customer permits to access the Services under its Workspace, including employees and contractors.
"Customer", "you", "your" — the organisation that accepts these Terms, on whose behalf the Services are used and which is responsible for the Fees.
"Customer Data" — all data, content, files and records the Customer or an Authorized User submits to, uploads to, generates within, or directs the Services to receive, including policies, evidence files, control records, risk registers, vendor records, assessment responses, Inputs and AI Output stored in the Workspace, and any Personal Information within them.
"Documentation" — the product documentation, in-product help and guides CyberWave makes generally available. "DPA" — the CyberWave Data Processing Addendum published in the Legal Centre. "Fees" — amounts payable for the Services, as published on the pricing page or stated in an Order Form. "Included Users" — the number of Authorized Users included in a Plan (§5.1). "Input" — content an Authorized User submits to an AI Feature, with the grounding context assembled from that Customer's own records for that request (§14.2). "Order Form" — a written or electronic ordering document, including a self-service checkout confirmation, identifying the Plan, term, Fees and Add-Ons purchased. "Personal Information" — information about an identifiable individual, as that term is used in Canadian privacy legislation. "Plan" — a subscription tier described in §7.1. "Professional Services" — advisory, implementation, review or managed services, including Managed vCISO services and the Cyber Insurance Submission Pack. "Services" — CyberWave Sentinel, the Documentation, the Professional Services and any other service CyberWave provides under the Agreement. "Subprocessor" — a third party engaged by CyberWave that processes Customer Data in providing the Services, as listed in the published Subprocessors document. "Subscription Period" — the monthly or annual period for which a Plan has been purchased, and each renewal of it. "Third-Party Service" — a product or service not provided by CyberWave that the Customer elects to connect to or use with the Services. "Trial" — access to a Plan at no charge under §6. "Workspace" — the Customer's tenant within Sentinel: the logically isolated environment holding its Customer Data.
"Confidential Information" is defined in §16.1, "Feedback" in §20.1, "Aggregated De-identified Data" in §13.4, "Claim" in §31.1 and "Force Majeure Event" in §33.1.
2 Acceptance and authority
2.1 Formation. You accept these Terms by completing the acceptance step at signup, by executing an Order Form, or by accessing or using the Services. Ontario's Electronic Commerce Act, 2000 recognises acceptance expressed by clicking a place on a screen and provides that a contract is not unenforceable by reason only of being electronic. The Agreement forms when you complete that step; access begins when CyberWave provisions your Workspace.
2.2 You accept for an organisation. By accepting you represent and warrant that: (a) you are of legal age to enter a binding contract; (b) you are acquiring and using the Services for business or professional purposes and not for personal, family or household purposes; (c) you have authority to bind the organisation identified in your Account, which is the Customer; and (d) the information you give about that organisation is accurate. If you lack that authority, do not accept these Terms.
2.3 Mandatory consumer law prevails. These Terms are written for business customers. If, despite §2.2, mandatory consumer protection or other mandatory law applies and gives you rights these Terms would reduce, that law prevails to the extent of the conflict and the rest of the Agreement continues to apply. Nothing here excludes a right that cannot lawfully be excluded.
2.4 Correcting errors before you are charged. Before a purchase completes, the Services present a confirmation of the Plan, billing frequency, Included Users, Add-Ons and total amount, with a means of going back to correct it.
2.5 Language. These Terms are provided in English. Where Applicable Law requires a French version for a particular customer, that version must be made available and remitted before acceptance, and CyberWave will not charge for producing it.
3 The Services
3.1 What Sentinel does. Sentinel holds a control register with named owners, an evidence library with status and expiry tracking, a risk register and action tracking, an assessment programme, a cyber-insurance readiness workspace, executive and board reporting, and AI assistance for drafting and review. Which of these you get depends on your Plan.
3.2 What Sentinel is not. CyberWave does not certify compliance and does not issue audit opinions; does not guarantee compliance with any framework, standard, contract or law; does not replace independent auditors, certification bodies or legal counsel; is not an insurer or an insurance broker, does not bind coverage, and does not guarantee coverage, premium, claim payment or insurer acceptance; does not operate a security operations centre or provide 24/7 monitoring; does not provide managed detection and response, incident response retainers, penetration testing or forensics; and does not provide emergency incident response, except where a signed Statement of Work expressly provides it. Framework references in the Services — including to ISO/IEC 27001:2022, SOC 2, NIST CSF 2.0 and CIS Controls v8.1 — are informational readiness mappings, not audits, certifications or assurances of conformity.
3.3 Changes to the Services. CyberWave may modify and improve the Services but will not make a change that materially degrades the core functionality of a Plan during a Subscription Period already paid for. Where a material feature is discontinued, §37 governs notice and remedy.
3.4 Beta and preview features. Features identified as beta, preview, early access or experimental are provided as-is and as-available for evaluation, carry no warranty, support or service-level commitment, may be changed or withdrawn at any time, and are excluded from §29.2. Liability for them is limited by §32.
3.5 Support. Support is provided by email to support@cyberwave.ca. These Terms commit CyberWave to no response time, uptime level or service credit. Any such commitment applies only if stated in an Order Form or in a service-level document the Agreement incorporates.
4 Account registration
4.1 Accurate information. You must provide accurate, current and complete registration information — including the organisation's legal or operating name, the Administrator's contact details and the billing contact — and keep it current.
4.2 Administrators. At least one Authorized User must be an Administrator. An Administrator acts for the Customer and may add and remove Authorized Users, change Plan and Add-On selections, cancel, export Workspace data and request deletion. CyberWave may treat instructions given through an Administrator's Account as the Customer's instructions.
4.3 Credentials and access. You are responsible for keeping credentials confidential, for ensuring they are not shared, and for all activity under your Workspace. Notify CyberWave promptly at support@cyberwave.ca if you become aware of unauthorised access.
4.4 Workspaces, and registrations we may decline. Each Customer is provisioned one Workspace unless CyberWave agrees otherwise in writing; Workspaces are isolated as described in §17.2. CyberWave may decline a registration or require further verification where the information is inconsistent, where it appears to be an attempt to obtain repeated Trials, or where CyberWave reasonably believes it breaches §21 or Applicable Law.
5 Authorized Users and seats
5.1 Included Users.
| Plan | Included Users | Note |
|---|---|---|
| Essentials | 2 | |
| Full Platform | 5 | |
| Managed vCISO Lite | 5 | The CyberWave advisor does not use an Included User seat. |
| Managed vCISO | Agreed in a Statement of Work | Scope, users, hours and cadence are agreed in a Statement of Work. |
| Custom | As agreed | Scoped with you by agreement. |
5.2 Additional seats.
| Add-On | Users | Monthly | Annual |
|---|---|---|---|
| Additional user | 1 user | US$19 | US$205.20 |
| 5-user pack | 5 users | US$79 | US$853.20 |
| 10-user pack | 10 users | US$149 | US$1,609.20 |
Amounts are in US dollars and exclude taxes (§8.3). Annual amounts are the published annual totals charged, not a derived multiple of the monthly amount.
5.3 Seats are per named individual. A seat is for one named individual. Credentials must not be shared and a seat must not be used concurrently by more than one person. A seat may be reassigned when the original individual no longer needs access.
5.4 Staying within your seats. You must not permit more Authorized Users than the total of your Included Users and purchased seat Add-Ons; if you exceed that total you must purchase sufficient Add-Ons. CyberWave may notify you of the excess and, if it is unresolved 30 days after that notice, invoice the applicable Add-On Fees for the excess for the remainder of the Subscription Period, prorated.
5.5 Responsibility. You are responsible for your Authorized Users' compliance with the Agreement and for their acts and omissions as if they were your own.
6 Free trials
6.1 What the Trial is. CyberWave offers a 14-day free trial of the Plan you select, Essentials or Full Platform. No payment card is required. No charge is made. The Trial does not convert to a paid subscription automatically. A Trial is not a paid Plan and includes no Fees. Managed vCISO Lite, Managed vCISO and Custom are not offered on a Trial basis.
6.2 Start and end. The Trial begins when CyberWave provisions your Workspace and runs for 14 consecutive days, ending earlier if you purchase a paid subscription.
6.3 No payment obligation. No payment obligation of any kind arises until you expressly purchase a paid subscription by completing a purchase in the Services or executing an Order Form. CyberWave will not require payment details as a condition of a Trial, will not charge you at the end of a Trial, and will not place you on a paid Plan unless you choose one.
6.4 When the Trial ends. Continuing to use the Services after the Trial means choosing a paid subscription. Your Customer Data is not deleted because a Trial ended. It continues to be held and governed by §12, §17, §18 and §25, and if you later purchase, your existing Workspace and Customer Data remain available to you.
6.5 One Trial, and abuse controls. A Trial is available once per eligible Customer. CyberWave may decline, limit or end a Trial where it reasonably believes the Trial is being used to obtain repeated or extended free access — for example through multiple registrations for the same organisation — or where §21 or Applicable Law is being breached, or where security or legal reasons require it. Notice will be given where practicable.
6.6 Provided as-is. During a Trial the Services are provided as-is and as-available: §29.2 does not apply, CyberWave has no obligation under §31.3, and no support or service-level commitment applies. Liability is limited by §32. An Administrator can export Customer Data during a Trial under §25.1.
7 Paid subscriptions
7.1 Plans and prices.
| Plan | Monthly | Annual | Included Users | Trial | Self-service |
|---|---|---|---|---|---|
| Essentials | US$99 | US$1,069.20 | 2 | 14 days | Yes |
| Full Platform | US$249 | US$2,689.20 | 5 | 14 days | Yes |
| Managed vCISO Lite | US$999 | US$11,388.60 | 5 (the CyberWave advisor does not use a seat) | None | No — purchased through a sales conversation |
| Managed vCISO | From US$2,499 | Scoped in a Statement of Work | Agreed in a Statement of Work | None | No — contact sales |
| Custom | Scoped by agreement | Scoped by agreement | As agreed | None | No — contact sales |
All amounts are in US dollars (USD) and exclude taxes (§8.3). Annual amounts are the published annual totals charged for the Subscription Period; they are stated, not derived. "From US$2,499" means a Managed vCISO engagement starts at that monthly amount; its scope, users, hours and cadence are agreed in a Statement of Work.
7.2 Service items. The Cyber Insurance Submission Pack is a one-time service priced at US$499 — an evidence and questionnaire package assembled from your Workspace. It is not sold through self-service checkout; it is arranged by contacting CyberWave, and it is Professional Services for the purposes of §26.
7.3 What a subscription grants. Subject to the Agreement and payment of the Fees, CyberWave grants the Customer a non-exclusive, non-transferable, non-sublicensable right for its Authorized Users to access and use the Services during the Subscription Period for the Customer's internal business purposes.
7.4 Price changes, and the published price. CyberWave may change published prices; a change does not affect a Subscription Period already purchased, and §9.4 governs renewals. The price published for a Plan is the price at which it can actually be purchased: CyberWave does not add mandatory non-tax charges later in the purchase flow, taxes are addressed in §8.3, and Add-Ons are genuinely optional.
8 Fees, taxes and payment
8.1 Fees and billing. You agree to pay the Fees for the Plan and Add-Ons purchased, at the prices published at the time of purchase or stated in an Order Form. Fees are charged in advance: monthly Plans at the start of each monthly period, annual Plans at the start of each annual period. One-time service items are invoiced as agreed.
8.2 Payment method and card data. Payments for paid subscriptions are processed by CyberWave's payment processor, Stripe. Card details are entered directly with the processor and do not reach CyberWave's systems. You authorise CyberWave and its processor to charge your designated payment method for Fees as they fall due, including on renewal, until cancelled.
8.3 Taxes. Fees are exclusive of taxes. You are responsible for all sales, use, value-added, goods and services, harmonised sales and similar taxes arising from the Agreement, excluding taxes on CyberWave's net income. Where CyberWave must collect a tax it is added to the invoice; exemptions require valid documentation before the charge.
8.4 Late payment. If undisputed amounts are not paid when due, CyberWave may suspend under §22 after notice.
8.5 Failed payments. If a scheduled charge fails, CyberWave retries it and notifies the billing contact. Access continues during the retry window with a payment warning shown. If payment ultimately fails, the Workspace becomes read-only and the subscription follows the cancellation path in §9.
8.6 Disputes and set-off. Notify CyberWave in writing within 15 days of an invoice you dispute in good faith, identifying the amount and the basis; you must pay the undisputed portion when due, and CyberWave will not suspend for non-payment of a good-faith disputed amount while the parties work diligently to resolve it. Otherwise Fees are payable without set-off, deduction or withholding.
8.7 Refunds. Fees are non-refundable once paid, except as expressly provided in the following places and nowhere else:
| Route | Where |
|---|---|
| Billing error by CyberWave or its payment processor | §8.8 |
| Customer terminates for CyberWave's uncured material breach | §23.4 |
| Customer terminates because a non-conformity with the performance warranty is not corrected | §29.3 |
| CyberWave terminates for convenience or discontinues the Services | §23.5 |
| Customer terminates after a materially adverse change to these Terms | §37.4 |
| Customer terminates after an unresolved Subprocessor objection | §18.4 |
| CyberWave elects termination-and-refund under the IP indemnity | §31.4 |
| A refund CyberWave expressly approves in writing | — |
| A refund required by Applicable Law | §2.3 |
A refund is of Fees prepaid for the unused remainder of the then current Subscription Period, calculated from the effective date of termination, unless a specific clause states otherwise.
8.8 Billing errors. Notify CyberWave within 60 days of a charge you believe is incorrect. Where CyberWave confirms an error it will refund or credit the amount.
9 Renewal and cancellation
9.1 Automatic renewal. Unless cancelled, a subscription renews automatically at the end of each Subscription Period for a further period equal to the expiring period, up to a maximum of 12 months. Monthly renews monthly; annual renews annually.
9.2 Cancelling. You may cancel at any time. Cancellation disables the next renewal; it does not end the period already paid for. Where CyberWave makes self-service cancellation available in the Services (Billing → Manage), you may cancel there without contacting support. You may in any event cancel by emailing support@cyberwave.ca from an Administrator's address, and CyberWave will action and confirm it in writing.
9.3 Effect. Cancellation takes effect at the end of the current Subscription Period and access continues until then. No further Fee is charged for any period beginning after the cancellation takes effect. Fees already paid for the current period are not refunded except through a route listed in §8.7.
9.4 Renewal price changes and reminders. CyberWave will give at least 30 days' written notice before a price change takes effect on renewal; if you do not accept it you may cancel under §9.2 before the renewal date and the change will not be charged. A price change never applies retroactively. CyberWave will send a reminder to the billing contact before an annual subscription renews, stating the renewal date and the amount.
10 Plan changes and add-ons
10.1 Upgrades and downgrades. An upgrade takes effect immediately; you are charged the prorated difference for the remainder of the current Subscription Period and the higher Plan's entitlements become available. A downgrade takes effect at the end of the current Subscription Period, so you keep what you paid for until then. A downgrade does not delete Customer Data: data in modules the lower Plan does not include is retained and becomes read-only, and re-upgrading restores access.
10.2 Seat and usage Add-Ons. Seats may be added at any time, charged prorated for the remainder of the period; removing seats takes effect at the end of the current period. Use of AI Features is metered against a monthly AI credit allowance that depends on the Plan, and an AI request is declined when the remaining allowance is too low for it. There is no automatic overage charge for AI usage. Where CyberWave offers extra AI usage, it is an optional purchase that an Administrator chooses to make; the terms of purchase are presented at the point of sale, and usage purchased and consumed is not refundable.
10.3 Order Forms. Where an Order Form states different change mechanics for a negotiated subscription, the Order Form prevails under §40.2.
11 Customer responsibilities
11.1 Your decisions. The Services support your security, governance and readiness programme; they do not run it. You remain responsible for your security decisions, control implementation, risk acceptance, remediation, policy approval, regulatory filings and disclosures, and for engaging auditors, certification bodies, brokers, insurers and legal counsel where needed.
11.2 Lawful basis. You represent that you have the rights, consents and lawful authority necessary for CyberWave and its Subprocessors to process Customer Data as the Agreement contemplates, including any Personal Information in it, and that your instructions do not require CyberWave to act unlawfully.
11.3 Data you must not upload. You must not upload: (a) payment card data, other than the billing information collected by the payment processor; (b) personal health information, government identifiers, biometric data or other sensitive Personal Information, unless CyberWave has agreed in writing that the Services may be used for that purpose; (c) material you are not permitted to disclose to CyberWave; or (d) malicious code. If you need to hold a category listed above, ask first. The answer may be no.
11.4 Review, records and representations. AI Features are assistive: you must review AI Output before relying on it (§14.4). The Services are not your system of record and are not a backup or archival service, so retain your own copies of material critical to your operations; an Administrator can export Workspace data under §25.1. Where you use output from the Services with an insurer, broker, auditor, certification body, customer or regulator, you remain responsible for the completeness and truthfulness of what you present. CyberWave does not verify the accuracy of Customer Data you submit.
11.5 Access hygiene. You are responsible for provisioning and de-provisioning Authorized Users promptly, for the security of your own devices and networks, and for configuring the access controls the Services make available.
12 Customer Data
12.1 You own your data. As between the parties, the Customer retains all right, title and interest in and to Customer Data, including all intellectual property rights in it. Nothing in the Agreement transfers ownership to CyberWave. CyberWave acquires no ownership of, and claims no rights in, your policies, evidence, control records, assessment responses, risk registers or reports.
12.2 The limited rights CyberWave receives. The Customer grants CyberWave a non-exclusive, worldwide, royalty-free right, during the term and for the limited period afterwards described in §25, to host, store, copy, transmit, process, secure, back up, display, index, format and render Customer Data, and to analyse it at the Customer's instruction or on the Customer's behalf, in each case solely to the extent reasonably necessary to provide, maintain, secure, support, troubleshoot and operate the Services for that Customer, and for no other purpose. CyberWave may exercise these rights through its Subprocessors, subject to §18.
12.3 What this licence is not. §12.2 is not a general or unrestricted licence. It does not permit CyberWave to use Customer Data to develop or market products or services other than the Services provided to that Customer, to disclose it other than as the Agreement permits, to sell or rent it, to share it for advertising purposes, or to train or fine-tune any artificial intelligence model. §13 and §14 state exhaustively the additional uses CyberWave makes of Customer Data.
12.4 Accuracy, and deletion by you. You are responsible for the accuracy, quality, legality and content of Customer Data and for the means by which you acquired it. You may delete records and files at any time; §25 describes what happens to copies, what happens in backups, and the records CyberWave keeps.
13 CyberWave's use of Customer Data
13.1 Permitted purposes, exhaustively. CyberWave uses Customer Data only to: (a) provide, maintain and operate the Services for the Customer; (b) respond to a support request or resolve a fault affecting the Customer; (c) detect, investigate, prevent and respond to security incidents, fraud, abuse and breaches of §21; (d) meter and account for usage, including AI Feature usage, for billing and entitlement purposes; (e) comply with Applicable Law and respond to lawful, valid legal process; and (f) produce Aggregated De-identified Data as §13.4 permits.
13.2 Human access, stated honestly. A small number of authorised CyberWave personnel can access Customer Data where necessary for a purpose in §13.1(a)–(c) — to operate the platform, resolve a fault or support request, or investigate a security or abuse concern. CyberWave does not access Customer Data to browse it, to assess the Customer's security posture for CyberWave's own purposes, or for marketing.
13.3 No advertising or analytics technology in the Services. Neither the Sentinel application nor the CyberWave website sets any analytics, advertising or tracking cookie or loads any analytics, advertising or tracking script, and the Services send no Customer Data to any analytics or advertising provider. The application uses essential authentication session cookies, browser local storage for interface state, and a service worker that keeps an offline page cache, as described in the Cookie Notice. Application errors are recorded in CyberWave's own database rather than sent to a third-party error-tracking service. This is CyberWave's current practice; if it changes, the Privacy Policy, Cookie Notice and Subprocessors document will be updated before the change takes effect.
13.4 Aggregated De-identified Data. CyberWave may create and use Aggregated De-identified Data, meaning data derived from operation of the Services that: (a) has been aggregated with data from other customers, or across a sufficient number of records that individual records cannot be distinguished; (b) has had all identifiers of the Customer, its Authorized Users and any individual removed; (c) is not reasonably capable of being used, alone or with other information reasonably available to CyberWave, to identify an individual, to identify the Customer, or to reconstruct Customer Data; and (d) is not presented or disclosed in any manner that identifies the Customer. CyberWave may use it to operate, secure, measure and improve the Services and to produce aggregate statistics. Pseudonymised, tokenised, hashed or otherwise re-identifiable Customer Data is not Aggregated De-identified Data and is not treated as anonymous. It may not be used to train or fine-tune any artificial intelligence model. Customer Data remains Customer Data, subject to §12 and §16, in every form in which CyberWave holds it.
13.5 No sale of Customer Data. CyberWave does not sell Customer Data or Personal Information and does not disclose it for consideration to a third party for that third party's own purposes.
14 AI Features
14.1 What they are. Sentinel includes optional AI assistance for drafting, review, summarisation, report narrative and insights. AI Features are assistive, operate when an Authorized User invokes them, and are metered against the Plan's monthly AI credit allowance (§10.2).
14.2 Which provider, what is sent, and what is stored. AI Features are provided using the Anthropic Messages API, which CyberWave calls from its servers and never from the browser. When an Authorized User invokes an AI Feature: (a) the request is authorised and the Authorized User's Workspace is resolved on the server; (b) grounding context is assembled from that Customer's own records only — the item the Authorized User asked about and, often, a summary of the Workspace such as record names, statuses, counts and saved answers — with tenant scoping enforced by PostgreSQL row-level security and server-side authorisation, not by the prompt; (c) the assembled Input is sent to Anthropic, which processes it in the United States; (d) the AI Output is returned to the Authorized User; and (e) usage is recorded for metering. No AI model reads uploaded evidence files, which receive text extraction and keyword classification only; policy review sends the policy text, and contract review sends the pasted contract text, to the AI provider.
CyberWave stores each AI result in the Customer's Workspace: the AI Output, a short summary, and a short excerpt or label of the request of up to 300 characters. CyberWave also records a short excerpt of the request in an append-only audit log (§25.6). Some AI Features write AI Output directly into Workspace records — for example vendor and contract summaries and evidence review notes. Stored AI results and AI Output written into Workspace records are Customer Data.
14.3 Ownership of AI Output. As between the parties, the Customer owns AI Output generated in its Workspace, and AI Output stored in the Workspace is Customer Data. CyberWave claims no ownership of it.
14.4 What AI Features are not. AI Features are assistive. AI Output may contain errors and does not replace professional judgement. You remain responsible for decisions made using it, and AI Output must be reviewed before it is relied on. CyberWave does not warrant that AI Output is accurate, complete, current, original or non-infringing, or that it is unique — another customer may receive similar output for a similar request. AI Output is not legal, audit, actuarial, underwriting or accounting advice.
14.5 CyberWave does not train models on your content. CyberWave does not use Customer Data, Inputs or AI Output to train, retrain or fine-tune any artificial intelligence model, and does not export Customer Data for model development. No training or fine-tuning pipeline exists in the Services and no such export path exists.
14.6 The provider-side position. Customer Data is submitted to the AI provider only to the extent included in an Input for the purpose of fulfilling the Authorized User's request. The AI provider's own use and retention of content it receives are governed by the AI provider's terms.
14.7 Your obligations. You must not use AI Features or AI Output to develop, train, evaluate or improve a competing artificial intelligence model or product, must not submit as an Input material you lack the rights to submit, and must not attempt to circumvent any content filter, safety control or rate limit.
14.8 No AI output indemnity. CyberWave does not indemnify the Customer against a claim that AI Output infringes a third party's rights. §31.3 is limited to the Services and expressly excludes AI Output.
14.9 The AI Features Notice. The AI Features & Data Use Notice describes the same data flow in more detail and is incorporated into the Agreement. If it conflicts with this §14, this §14 prevails.
15 Integrations and third-party services
15.1 Your choice, and what CyberWave is responsible for. Whether to connect a Third-Party Service is the Customer's decision, and its use is governed by that provider's own terms and privacy practices, not by this Agreement. CyberWave is not responsible for a Third-Party Service, its availability, security or accuracy, or any act or omission of its provider. Where the Customer directs the Services to transmit Customer Data to a Third-Party Service, that transmission is at the Customer's instruction, and CyberWave's obligations under §16, §17 and the DPA do not extend to that provider's own processing.
15.2 Current state. The integration features in Sentinel today are connection templates and configuration only. They do not establish a live connection to any external identity, endpoint, service-management or productivity platform, and webhooks and API keys are disabled. The Subprocessors document lists the providers that actually receive Customer Data; providers appearing in the product only as integration templates are not Subprocessors and are not listed as such.
15.3 Changes. If a Third-Party Service provider changes or discontinues its service or interfaces and an integration becomes unavailable, CyberWave is not in breach, and §3.3 and §37 govern any resulting change to the Services.
16 Confidentiality
16.1 Definition and exclusions. "Confidential Information" means non-public information disclosed by one party (the "Discloser") to the other (the "Recipient") in connection with the Agreement that is identified as confidential or that a reasonable person would understand to be confidential. Customer Data is the Customer's Confidential Information; the Services, the Documentation, CyberWave's non-public security information and its non-published pricing are CyberWave's; the terms of a negotiated Order Form or Statement of Work are confidential to both parties. Confidential Information does not include information that (a) is or becomes public other than through a breach of the Agreement, (b) the Recipient held before disclosure without a duty of confidence, (c) the Recipient receives from a third party without a duty of confidence, or (d) the Recipient independently develops without using the Discloser's Confidential Information.
16.2 Obligations. The Recipient will use the Discloser's Confidential Information only to perform or exercise its rights under the Agreement; protect it with at least the care it applies to its own confidential information of similar sensitivity, and never less than reasonable care; and not disclose it except to personnel, professional advisers and Subprocessors who need it for a permitted purpose and are bound by obligations no less protective. The Recipient remains responsible for their compliance.
16.3 Compelled disclosure. The Recipient may disclose where required by Applicable Law or valid legal process provided that, unless legally prohibited, it gives the Discloser prompt notice sufficient to seek protective relief, discloses only what is required, and continues to treat the information as confidential for all other purposes.
16.4 Duration, return and destruction. These obligations apply during the term and for three years afterwards, except that obligations in respect of Customer Data and trade secrets continue for as long as the information remains confidential. On written request after termination the Recipient will return or destroy the Discloser's Confidential Information, except for copies in routine backups or where retention is required by Applicable Law; retained copies remain subject to this §16 until deleted. §25 governs Customer Data specifically.
17 Security
17.1 CyberWave's commitment. CyberWave will implement and maintain administrative, technical and physical safeguards designed to protect Customer Data against unauthorised access, use, disclosure, alteration and destruction, appropriate to the nature of the data and the risk. CyberWave will not materially reduce the protection provided by the measures described in §17.2 during a Subscription Period.
17.2 Measures and processing locations presently in place.
| Measure | Position |
|---|---|
| Tenant isolation | Each Customer's data is held in its own Workspace. Isolation is enforced by PostgreSQL row-level security together with server-side authorisation — not by client-side logic and not by prompt construction. |
| Primary storage location | The database, authentication and file storage services (Supabase) are hosted in Canada (ca-central-1). |
| Application processing | Application hosting and compute (Vercel) run in the United States. Data in a request is processed there before reaching the Canadian database. |
| AI processing | Inputs sent to an AI Feature are processed in the United States by the AI provider (Anthropic), which CyberWave calls from its servers and never from the browser. |
| Email delivery | Application email, including account emails such as sign-up confirmation and password reset, is sent through a provider (Resend) in the United States. |
| Payment data | Payments for paid subscriptions are processed by Stripe. Card details are entered directly with the payment processor and do not reach CyberWave's systems. |
| Support mailbox | Email sent to support@cyberwave.ca is held in a Microsoft 365 mailbox provided through GoDaddy and may be processed outside Canada. |
| Analytics and advertising | None. No analytics, advertising or tracking cookie is set and no analytics, advertising or tracking script is loaded, on the website or in the application. |
| Error monitoring | Application errors are recorded in CyberWave's own database, not sent to a third-party service. |
| Transport security | The Services are provided over encrypted connections (HTTPS). |
17.3 CyberWave does not claim that all data stays in Canada. The accurate statement is that the database, authentication and file storage services that hold Customer Data are hosted in Canada, while application hosting and compute, AI Features and email delivery use providers in the United States, payment processing involves a provider that may process data in the United States, and email sent to CyberWave's support mailbox may be processed outside Canada. The Privacy Policy, DPA and Subprocessors document state where each provider processes.
17.4 Your responsibilities. Security depends on both parties. You are responsible for the matters in §4.3, §11.3 and §11.5 and for configuring the access controls the Services make available.
17.5 Security incidents. Where CyberWave becomes aware of a security incident affecting Customer Data it will notify the Customer without undue delay and provide the information reasonably available to it so the Customer can assess its own obligations. Timing, content and the allocation of regulator-facing and individual-facing notification duties are set out in the DPA. Notifying or responding to an incident is not an admission of fault or liability.
18 Privacy, DPA and subprocessors
18.1 The Privacy Policy and the DPA. The Privacy Policy describes how CyberWave handles Personal Information. Where CyberWave processes Personal Information on the Customer's behalf, the DPA applies, is incorporated into the Agreement, and prevails over these Terms to the extent of any conflict on its subject matter.
18.2 The Canadian framework. Canadian federal private-sector privacy law does not divide parties into controllers and processors; obligations follow control of the information and the purposes for which it is handled. The DPA allocates responsibility on that basis: for Personal Information the Customer places in its Workspace, the Customer determines the purposes and CyberWave processes on the Customer's behalf and on its instructions.
18.3 Subprocessors and notice of change. CyberWave uses Subprocessors to provide the Services. Their identity, role, the data each can access and where each processes are published in the Subprocessors document, which lists only providers that actually receive Customer Data; providers that are not active in the Services are not listed. CyberWave will publish an addition or replacement in the Subprocessors document and give at least 30 days' notice under §36.1 before a new Subprocessor begins processing Customer Data — except where a replacement is required urgently for security, legal or service-continuity reasons, in which case notice will be given as soon as practicable.
18.4 Objecting. Within 30 days of notice the Customer may object on reasonable grounds relating to the protection of Personal Information, by written notice explaining the grounds, and the parties will discuss it in good faith. If unresolved, CyberWave will elect either to not appoint that Subprocessor for the Customer's data, or to permit the Customer to terminate the affected Services without liability to either party, with a pro-rata refund of Fees prepaid for the unused remainder of the Subscription Period. The objection right is a termination remedy, not a veto over CyberWave's infrastructure.
18.5 Cross-border processing. The Customer acknowledges the processing locations in §17.2 and §17.3. Transfer to a service provider for processing does not change the Customer's own accountability for the information. CyberWave cannot, and does not represent that it can, prevent a lawful order of a foreign authority from reaching data held by a provider in that jurisdiction.
19 Intellectual property
19.1 CyberWave's rights. CyberWave and its licensors own the Services and all intellectual property rights in them, including the software, interfaces, Documentation, questionnaire libraries, framework mappings, control catalogues, scoring and readiness methodologies, and all modifications and improvements. No rights are granted except those expressly stated in the Agreement.
19.2 Restrictions. You must not, and must not permit any person to: (a) copy, modify, translate or create derivative works of the Services except as the Services expressly permit; (b) reverse engineer, decompile or disassemble the Services or attempt to derive their source code, except to the extent Applicable Law permits notwithstanding this restriction; (c) rent, lease, resell, sublicense, time-share or provide the Services as a service bureau, except as an Order Form permits; (d) remove or obscure a proprietary notice; (e) use the Services to build a competing product or service; (f) circumvent an access control, usage limit, rate limit or security measure; or (g) access the Services other than through the interfaces CyberWave provides.
19.3 Templates and marks. Where the Services provide a template and the Customer populates it, the populated document is Customer Data and the Customer may use it for its own business purposes without restriction; the underlying template, and the framework mapping or methodology it reflects, remain CyberWave's Confidential Information and property and must not be extracted, redistributed or made available to a third party as a template. Neither party may use the other's name, logo or trade marks without prior written consent, except that CyberWave may identify the Customer as a customer where the Customer has expressly agreed.
20 Feedback
20.1 Feedback. "Feedback" means a suggestion, comment, enhancement request, idea, recommendation or bug report about the Services that the Customer or an Authorized User voluntarily provides. The Customer grants CyberWave a perpetual, irrevocable, worldwide, royalty-free right to use, reproduce, modify and incorporate Feedback into the Services and CyberWave's other products, without obligation, attribution or compensation.
20.2 What Feedback is not. Feedback does not include Customer Data or the Customer's Confidential Information, and §20.1 grants CyberWave no rights in either. Information does not become Feedback merely because it appears in, or is attached to, a support request, a bug report or a conversation with CyberWave personnel. Where the Customer provides Customer Data or Confidential Information to help reproduce or resolve an issue, that material remains subject to §12, §13 and §16 and may be used only for the purpose for which it was provided. The Customer is under no obligation to provide Feedback.
21 Acceptable use
21.1 The Acceptable Use Policy. The CyberWave Acceptable Use Policy applies to all use of the Services and is incorporated into the Agreement. CyberWave may update it; §37 governs notice, prior versions are retained as §37.5 describes, and a change that materially expands the Customer's obligations is a material change for the purposes of §37.
21.2 Core prohibitions. Without limiting that policy, you must not, and must not permit any person to, use the Services to: (a) break Applicable Law, infringe a third party's rights, or misappropriate a third party's confidential information or trade secrets; (b) upload or transmit malicious code, or interfere with the integrity, security or availability of the Services or another customer's Workspace; (c) attempt to access data, a Workspace or an account you are not authorised to access, or to test, probe or scan the Services except under CyberWave's Responsible Disclosure Policy or with prior written consent; (d) exceed your seats other than as §5.4 permits, or share credentials between individuals; (e) impersonate a person or misrepresent an affiliation; (f) produce a document or report that misrepresents the Customer's security posture to an insurer, auditor, regulator, customer or other third party; (g) develop, train or evaluate a competing artificial intelligence model or product using the Services, Inputs or AI Output; or (h) resell, redistribute or provide access to the Services to a third party except as an Order Form permits.
22 Suspension
22.1 When CyberWave may suspend. CyberWave may suspend the Services, a Workspace, an Account or a feature where: (a) there is a material risk to the security, integrity or availability of the Services or another customer's data; (b) the Customer or an Authorized User is in breach of §21; (c) the use is or appears to be unlawful, or Applicable Law or valid legal process requires suspension; (d) Fees remain unpaid after the notice contemplated by §8.4 or §8.5; or (e) CyberWave reasonably believes the Account has been compromised.
22.2 Scope, notice and restoration. A suspension will be no broader and no longer than CyberWave reasonably considers necessary. CyberWave will give notice before suspending and, where circumstances permit, an opportunity to remedy; where advance notice is not practicable — in particular under §22.1(a) or (e) — notice will be given as soon as practicable afterwards. Access is restored promptly once the ground is resolved.
22.3 Effect. A suspension is not a termination and does not relieve the Customer of its obligation to pay Fees for the Subscription Period. Where CyberWave suspends without a ground in §22.1, the Customer's remedies are those in §29.3 and §32. The read-only state in §8.5 is a consequence of non-payment rather than a suspension under this §22, and Customer Data remains available for export under §25.1 while a Workspace is read-only.
23 Term and termination
23.1 Term. The Agreement begins when you accept these Terms and continues until every Subscription Period and Trial has ended and the Agreement is terminated under this §23. The Customer may end its subscription by cancelling under §9.2, and the Agreement terminates when the last Subscription Period ends.
23.2 Termination for cause. Either party may terminate the Agreement, or the affected Services, by written notice if the other materially breaches the Agreement and fails to cure within 30 days after written notice describing the breach. Either party may terminate immediately if the other becomes insolvent, makes an assignment for the benefit of creditors, has a receiver appointed, or files or has filed against it a bankruptcy or liquidation proceeding not dismissed within 60 days.
23.3 Immediate termination for serious breach. CyberWave may terminate immediately on written notice where the Customer breaches §19.2 or §21.2(a), (b), (c) or (f), or where continued provision would require CyberWave to break Applicable Law.
23.4 Refund on the Customer's termination for cause. If the Customer terminates under §23.2 for CyberWave's uncured material breach, CyberWave will refund Fees prepaid for the unused remainder of the then current Subscription Period.
23.5 CyberWave's termination for convenience. CyberWave may terminate for convenience, or discontinue the Services generally, on not less than 60 days' written notice, and will refund Fees prepaid for the unused remainder of the then current Subscription Period. The Customer may export Customer Data under §25.1 until the termination takes effect.
23.6 Trials. Either party may end a Trial at any time, subject to §6.5.
24 Effect of termination
24.1 Access, amounts and licences. On termination or expiry, the right of the Customer and its Authorized Users to access and use the Services ends. Termination does not relieve either party of an obligation accrued before the effective date, and Fees for a Subscription Period that has begun remain payable, subject to §8.7. The rights in §7.3 and the licence in §12.2 end, except to the extent CyberWave must continue to hold Customer Data to perform §25 or to comply with Applicable Law.
24.2 Survival. The following survive: §1; §8 as to accrued amounts; §11.4; §12.1; §13 as to data still held; §16; §19; §20; §24; §25; §28; §30; §31; §32; §34; §36; §38; §39; §40; §41; §42; and any other provision that by its nature is intended to survive.
25 Data export, retention and deletion
This section separates two things often wrongly promised together: removing data from the systems that serve it, and removing data from backups. They have different timelines, and stating them as one absolute would be false.
25.1 Export during the subscription. During a Subscription Period or a Trial, an Administrator can export Workspace data from within the Services.
25.2 Export before termination or expiry. Because access to the Services ends on termination or expiry (§24.1), the Customer should export the Customer Data it wishes to keep under §25.1 before termination or expiry takes effect.
25.3 Deletion by the Customer. An Administrator or permitted Authorized User may delete records and files in the Services at any time. Deleting an item does not remove every copy of it: backups are described in §25.5, the records CyberWave keeps are described in §25.6, and AI Output that an AI Feature wrote into another Workspace record (§14.2) remains in that record until that record is deleted too. An individual Authorized User may request deletion of their own Account; that does not delete the Customer's Workspace or Customer Data, which belong to the Customer.
25.4 Deletion of a Workspace. Whole-Workspace deletion is not available as a self-service action in the product. A Customer may request deletion of its Workspace by contacting CyberWave at support@cyberwave.ca, and CyberWave acts on a verified written request from an Administrator. On such a request CyberWave will confirm the scope, remind the Customer to export any Customer Data it wishes to keep, delete the Workspace's records and stored files from the active systems, deactivate the associated Accounts, cancel the subscription, and confirm completion in writing with the date.
25.5 Backups. CyberWave's database platform maintains managed backups, and deleting data from the active systems does not immediately remove it from backups taken before the deletion. Backup copies (a) are retained for the period determined by CyberWave's backup configuration; (b) remain subject to §16 and §17 while retained; (c) are not used for any purpose other than restoring the Services; and (d) are not further processed, and are overwritten or expire as the backup cycle rolls forward.
25.6 Records CyberWave keeps.
| Record | Why | Effect of a deletion request |
|---|---|---|
| Legal acceptance records — document id, version, timestamp, acting user | The record exists to evidence what was agreed and when. Append-only by design. | Retained. |
| Billing and financial records, including invoices held by the payment processor | Statutory retention for financial records; dispute resolution. | Retained for the statutory period. |
| Platform audit and administrative logs | Security and accountability. The logs are append-only and record that an action occurred; for AI requests they also contain a short excerpt of the request (§14.2). | Retained. |
| Support correspondence | Handling the Customer's own requests. | Deleted on request where retention is not required. |
25.7 Trials and legal holds. Customer Data is not deleted because a Trial ended (§6.4). CyberWave may suspend a deletion where Applicable Law or valid legal process requires preservation, and will say so where permitted.
26 Professional Services and Managed vCISO
26.1 What they are. CyberWave offers Managed vCISO Lite, Managed vCISO and the Cyber Insurance Submission Pack. Managed vCISO Lite provides the Full Platform together with a named CyberWave advisor on a scheduled advisory cadence, including risk and roadmap review and executive reporting support, and is purchased through a sales conversation rather than self-service checkout. On Managed vCISO Lite, the CyberWave advisor does not use an Included User seat. Managed vCISO is a deeper engagement whose scope, users, hours and cadence are agreed in a Statement of Work.
26.2 The boundary. Managed vCISO is an advisory service. It does not include security operations centre services or 24/7 monitoring, managed detection and response, incident response retainers, penetration testing, forensics, legal representation, insurance brokerage, or certification or audit opinions, and it does not include emergency incident response unless a signed statement of work expressly provides it. Your management retains decision authority. An advisor advises; the Customer decides, approves and implements. No CyberWave advisor becomes an officer, director or employee of the Customer, assumes a statutory or fiduciary office of the Customer, or accepts a duty the Customer owes to a third party.
26.3 Statements of Work and cooperation. A Statement of Work states scope, deliverables, assumptions, schedule, dependencies, fees and any acceptance process, and where it conflicts with these Terms for the engagement it covers it prevails — except §32, which applies to Professional Services as well as to the subscription. Professional Services depend on the Customer's timely provision of information, access, decisions and personnel, and CyberWave is not responsible for a delay or shortfall caused by their absence.
26.4 Scheduling. Advisory sessions are scheduled by agreement.
26.5 Deliverables and the Schedule. On payment, a written deliverable prepared for the Customer under a Statement of Work is the Customer's property and may be used for its internal business purposes. CyberWave retains ownership of its pre-existing materials, methodologies, templates and know-how, and of any general improvement to them, and may reuse them. The Professional Services Schedule is incorporated into the Agreement in respect of Professional Services.
27 Cyber insurance readiness
27.1 What CyberWave does. CyberWave helps you prepare for underwriting and security questions, organise evidence, identify possible gaps and plan remediation. CyberWave is not an insurer or an insurance broker, does not bind coverage, does not interpret policy coverage as legal advice, and does not guarantee coverage, premium reduction, claim payment or insurer acceptance. You remain responsible for complete and truthful representations to your insurer or broker.
27.2 Readiness output is not an underwriting decision. A readiness score, gap list, broker package, underwriter package or submission pack reflects the Customer Data provided and CyberWave's readiness methodology. It is not an insurance application, binder, quote, coverage opinion or representation to any insurer. Only the Customer, or its licensed broker, makes representations to an insurer.
27.3 Your disclosure duty is yours. The Customer is solely responsible for the accuracy and completeness of what it discloses to an insurer or broker, including where it uses material generated in the Services. If Customer Data is inaccurate or incomplete, output derived from it will be too. The Cyber Insurance Readiness Disclaimer is incorporated into the Agreement.
28 Compliance and readiness disclaimers
28.1 The core statement. Sentinel supports readiness, governance, assessment, evidence organisation and control management. CyberWave does not certify compliance, issue audit opinions, guarantee compliance, or replace independent auditors, certification bodies or legal counsel. Framework references are informational readiness mappings.
28.2 Scores and indicators. The Sentinel Score, readiness percentages, maturity levels and similar indicators are internal management indicators calculated from Customer Data using CyberWave's methodology. They are not certifications, ratings, audit conclusions or attestations, are not endorsed by any standards or certification body, and no third party is obliged to accept them.
28.3 No professional advice, and no guaranteed outcome. Nothing in the Services, the Documentation or any AI Output is legal, audit, actuarial, accounting, tax or insurance advice; where a decision has legal or regulatory consequences, obtain advice from a qualified professional. CyberWave does not warrant that using the Services will result in compliance with any framework, standard, contract or law; in a successful audit, certification or assessment; in insurance coverage, a particular premium or a claim outcome; or in the prevention of a security incident.
29 Warranties
29.1 Mutual. Each party warrants that it has the capacity and authority to enter into and perform the Agreement and will comply with Applicable Law in doing so, including anti-bribery, anti-corruption, privacy and data protection law applicable to its own activities.
29.2 CyberWave's performance warranty. CyberWave warrants that during a paid Subscription Period the Services will perform materially in accordance with the Documentation. This does not apply to a Trial, a beta or preview feature, AI Output, a Third-Party Service, or a failure caused by the Customer's misuse, the Customer's environment or network, or an unauthorised modification.
29.3 Remedy. If the Services do not conform to §29.2, the Customer must notify CyberWave with enough detail to reproduce the issue, and CyberWave will use commercially reasonable efforts to correct it. If CyberWave does not correct it, the Customer may terminate the affected Services on written notice and CyberWave will refund Fees prepaid for the unused remainder of the Subscription Period for those Services. This is the Customer's sole remedy and CyberWave's entire liability for breach of §29.2, without limiting §31 or §32.
29.4 Customer warranties. The Customer warrants that it has the rights and authority described in §11.2, that Customer Data does not infringe a third party's rights, and that its use complies with §21.
30 Disclaimer of warranties
30.1 The disclaimer. Except as expressly stated in §29, and to the maximum extent permitted by Applicable Law, the Services are provided "as is" and "as available", and CyberWave disclaims all other representations, warranties, conditions and terms, whether express, implied, statutory or arising from a course of dealing or usage of trade, including any implied warranty or condition of merchantability, merchantable quality, fitness for a particular purpose, durability, title and non-infringement.
30.2 In particular. CyberWave does not warrant that the Services will be uninterrupted, timely, secure or error-free; that every defect will be corrected; that the Services will meet the Customer's requirements; that AI Output will be accurate, complete, current, original or non-infringing; that data transmitted over the internet will be free from interception, loss or corruption; or that the outcomes in §28.3 will be achieved.
30.3 No service level unless stated. These Terms contain no availability commitment, uptime percentage, support response time or service credit. Any such commitment applies only if stated in an Order Form or in a service-level document the Agreement incorporates.
30.4 Savings. Nothing in this §30 excludes or limits a warranty, condition, right or remedy that cannot be excluded or limited under Applicable Law. Where a term of this §30 is unenforceable for a particular customer or transaction, it is severed to that extent only.
31 Indemnification
31.1 "Claim". In this §31 a "Claim" is a demand, action or proceeding brought by a third party other than the other party, its affiliates or its Authorized Users.
31.2 The Customer's indemnity. The Customer will defend CyberWave against any Claim arising out of or relating to: (a) Customer Data, including a Claim that it infringes or misappropriates a third party's intellectual property or privacy rights, or that its collection or use was unlawful; (b) the Customer's or an Authorized User's use of the Services in breach of the Agreement, the Acceptable Use Policy or Applicable Law; (c) a representation or disclosure the Customer makes to an insurer, broker, auditor, certification body, regulator or customer, including one relying on material produced in the Services; or (d) a Third-Party Service the Customer elects to use or connect. The Customer will indemnify CyberWave against damages, costs and reasonable legal fees finally awarded in that Claim, or agreed by the Customer in settlement of it.
31.3 CyberWave's indemnity. CyberWave will defend the Customer against any Claim alleging that the Customer's use of the Services in accordance with the Agreement infringes (a) an issued patent in a country party to the Patent Cooperation Treaty, (b) a registered trade mark, or (c) a registered copyright, and will indemnify the Customer against damages, costs and reasonable legal fees finally awarded in that Claim, or agreed by CyberWave in settlement of it.
31.4 Exclusions and CyberWave's election. CyberWave has no obligation under §31.3 for a Claim arising from: Customer Data; AI Output; a Third-Party Service; a modification not made by CyberWave; combination or use with a product, service, data or process not provided by CyberWave where the Services alone would not infringe; continued use after CyberWave has provided a non-infringing modification or replacement; use of a superseded release where a current release would have avoided the Claim; or use other than in accordance with the Agreement and the Documentation. Where such a Claim arises or is reasonably likely, CyberWave may, at its option, (a) procure the right for the Customer to continue, (b) modify or replace the affected part so it is non-infringing while remaining materially equivalent in function, or (c) if neither is commercially reasonable, terminate the affected Services on written notice and refund Fees prepaid for the unused remainder of the Subscription Period. §31.3 and this §31.4 are the Customer's sole and exclusive remedy for a Claim of the kind described in §31.3.
31.5 Procedure. The indemnified party must give prompt written notice of the Claim (a delay relieves the indemnifying party only to the extent it is prejudiced), give the indemnifying party sole control of the defence and settlement, and provide reasonable cooperation at the indemnifying party's expense. The indemnifying party must not settle in a way that imposes an obligation or an admission of liability on the indemnified party without its written consent. The indemnified party may participate at its own expense with its own counsel.
32 Limitation of liability
This section limits what each party can recover from the other. It limits the kinds of loss that can be claimed and it limits the amount. Read it before you accept these Terms.
32.1 Excluded types of loss. To the maximum extent permitted by Applicable Law, and except as §32.6 provides, neither party is liable to the other for (a) indirect, special, incidental, consequential, exemplary or punitive damages; (b) lost profits, lost revenues, lost sales or lost business, whether characterised as direct or indirect; (c) loss of goodwill or reputation, loss of anticipated savings, or business interruption; (d) loss, corruption, unavailability or unauthorised disclosure of data, or the cost of recovering or reconstructing it; or (e) the cost of procuring substitute goods or services — in each case however caused, whether the claim arises in contract, tort (including negligence), breach of statutory duty, restitution or otherwise, whether or not the party was advised of the possibility in advance, and even if a remedy fails of its essential purpose.
32.2 General cap. Subject to §32.3, §32.5 and §32.6, each party's total aggregate liability arising out of or relating to the Agreement will not exceed the total Fees paid or payable by the Customer under the Agreement in the 12 months immediately preceding the first incident giving rise to the liability. Multiple claims do not increase the cap, and the lookback runs from the first incident, not from the date a claim is made.
32.3 One cap. Fees for Professional Services and for the subscription count towards the same cap, and there is a single aggregate cap rather than one per Order Form, unless an Order Form expressly states otherwise.
32.5 Confidentiality and security. Liability arising from a party's breach of §16 in respect of the other party's Customer Data, of §17, or of the DPA is subject to the cap in §32.2.
32.6 Liabilities that are not capped. §32.1, §32.2 and §32.5 do not limit (a) either party's indemnification obligations under §31; (b) liability for infringement or misappropriation of the other party's intellectual property rights; (c) liability for breach of §16, except in respect of the other party's Customer Data, which is subject to §32.5 instead; (d) the Customer's obligation to pay Fees due; or (e) any liability that cannot be excluded or limited under Applicable Law.
32.7 Savings and severance. Nothing in this §32 limits liability to the extent it cannot be limited under Applicable Law. If any part of this §32 is unenforceable, that part is severed and the remainder applies to the greatest extent permitted, with liability limited to the greatest extent permitted rather than becoming unlimited.
32.9 Basis of the bargain. The parties agree that the limitations in this §32 are a fundamental basis of the bargain, are reflected in the Fees, and apply notwithstanding any other provision of the Agreement.
33 Force majeure
33.1 Definition. A "Force Majeure Event" is an event beyond a party's reasonable control, including a natural disaster, fire, flood, severe weather, epidemic or pandemic, war, act of terrorism, civil unrest, act of government, labour dispute not involving that party's own workforce, failure of a public telecommunications or power network, and a widespread failure of internet infrastructure or of a cloud platform the party does not control.
33.2 Effect, and what is not a Force Majeure Event. Neither party is liable for a failure or delay in performing an obligation — other than an obligation to pay amounts due for Services already provided — to the extent caused by a Force Majeure Event, provided the affected party notifies the other promptly and uses reasonable efforts to mitigate and resume performance. A failure within a party's reasonable control is not a Force Majeure Event: in particular, CyberWave may not rely on this §33 for a failure to maintain the security measures in §17, and neither party may rely on it for a shortage of funds.
34 Export and sanctions
34.1 Compliance and representations. Each party will comply with the export control and economic sanctions laws applying to it in connection with the Agreement, including Canadian export control and sanctions legislation and, where applicable, those of other jurisdictions. The Customer represents and warrants that (a) neither it nor any Authorized User is a person with whom dealings are prohibited under applicable sanctions law, and it is not owned or controlled by such a person; (b) it will not permit access from a jurisdiction subject to comprehensive sanctions where that access would be prohibited; and (c) it will not use the Services for a purpose prohibited by applicable export control law.
34.2 CyberWave's rights. CyberWave may suspend or terminate under §22 or §23.3 where it reasonably believes continued provision would breach export control or sanctions law, or where it is required to do so.
35 Assignment
35.1 Assignment. The Customer may not assign or transfer the Agreement or any right or obligation under it without CyberWave's prior written consent, except that it may assign the Agreement in its entirety, on written notice, to a successor in connection with a merger, reorganisation, or sale of all or substantially all of its assets or voting securities, provided the successor is not a competitor of CyberWave and assumes the Customer's obligations. CyberWave may assign the Agreement in its entirety, on written notice, to an affiliate or to a successor in connection with a merger, reorganisation, or sale of all or substantially all of its assets or business relating to the Services, provided the assignee assumes CyberWave's obligations.
35.2 Effect. A purported assignment in breach of §35.1 is void. The Agreement binds and benefits permitted successors and assigns.
36 Notices
36.1 Notices to the Customer. CyberWave gives notice by email to the Administrator and billing contact addresses in the Account, and may in addition give notice in the Services. The Customer designates those addresses as the electronic addresses at which it receives notices under the Agreement and must keep them current. A notice sent to a designated address is deemed received when it enters an information system the Customer uses for that type of information and becomes capable of being retrieved, and in any event 24 hours after transmission unless CyberWave receives a delivery failure.
36.2 Notices to CyberWave. Notices to CyberWave under these Terms are given by email to support@cyberwave.ca, with the topic in the subject line. A notice of termination, of a dispute, of a claim for indemnification, or of the commencement of legal proceedings must be clearly identified in the subject line as a legal notice, and CyberWave will acknowledge receipt of such a notice in writing.
36.3 Electronic communication and retainability. The parties consent to transacting and receiving notices electronically, and nothing in this §36 affects a requirement of Applicable Law that a notice be given in a particular form. CyberWave will make these Terms, each prior version, and each Order Form or purchase confirmation available in a form the Customer can access, copy, print and save, and will not hinder printing or storage.
37 Changes to these Terms
37.1 No retroactive change. CyberWave may amend these Terms. An amendment applies prospectively only. No amendment applies retroactively to conduct, a claim, or a Subscription Period that has already occurred, and no amendment reduces a right the Customer has already accrued.
37.2 What may change. CyberWave may change these Terms and the incorporated policies — the Acceptable Use Policy, the AI Features & Data Use Notice, the Professional Services Schedule, the Cyber Insurance Readiness Disclaimer, the Subprocessors document and the Documentation — to reflect a change in the Services, in Applicable Law, in a Subprocessor, or in CyberWave's practices. Fees change only as §7.4 and §9.4 provide; Subprocessors only as §18.3 provides.
37.3 Notice. For a material change, CyberWave will give at least 30 days' notice before it takes effect, by email to the Administrator and by publishing the new version in the Legal Centre with a new version identifier and effective date. For a non-material change — a typographical correction, a clarification that does not alter meaning, or an updated contact detail — CyberWave will publish the updated version without advance notice.
37.4 Your remedy for a materially adverse change. If a material change is materially adverse to the Customer, the Customer may terminate the affected Services by written notice given before the change takes effect, and CyberWave will refund Fees prepaid for the unused remainder of the then current Subscription Period. CyberWave does not rely on silence or continued use to impose a materially adverse change: for such a change CyberWave will either obtain the Customer's acceptance or make this termination right available.
37.5 Re-acceptance and prior versions. Where a change materially alters the Customer's rights or obligations, or where a new consent record is required, CyberWave will present the new version for acceptance and record it against the new version identifier; continued use after the effective date constitutes acceptance only of a change for which re-acceptance is not required. CyberWave retains every published version of these Terms and of each incorporated policy with its version identifier and effective date, and makes prior versions available in the Legal Centre. The version a Customer accepted continues to govern until a later version takes effect for that Customer under this §37.
38 Governing law
38.1 Governing law. The Agreement, and any dispute arising out of or in connection with it, is governed by the laws of the Province of Ontario and the federal laws of Canada applicable therein, without regard to conflict of laws rules that would apply another jurisdiction's law. The United Nations Convention on Contracts for the International Sale of Goods does not apply. This section does not displace a mandatory rule of the law of the Customer's own jurisdiction that applies regardless of the parties' choice of law.
39 Dispute venue
39.1 Discuss first. Before commencing proceedings a party will give the other written notice describing the dispute and the relief sought, and the parties will attempt in good faith to resolve it through discussion between people with authority to settle, for 30 days from that notice. This does not apply where a party seeks urgent injunctive or equitable relief, and it does not extend or suspend any limitation period.
39.2 Venue. Subject to §39.1 and §39.3, the parties submit to the exclusive jurisdiction of the courts of the Province of Ontario, sitting in Toronto, and each waives any objection to that venue on the basis of inconvenient forum.
39.3 Injunctive relief. Either party may apply to a court of competent jurisdiction in any jurisdiction for interim or permanent injunctive or equitable relief to protect its intellectual property rights or Confidential Information, or to prevent a breach of §19 or §21.
39.4 No arbitration is imposed. These Terms do not require arbitration, do not waive either party's right to bring a proceeding in court, and do not waive any right to participate in a class proceeding.
40 Entire agreement and order of precedence
40.1 The Agreement. The Agreement consists of these Terms together with each Order Form and Statement of Work; the DPA; the Acceptable Use Policy; the AI Features & Data Use Notice; the Professional Services Schedule; the Cyber Insurance Readiness Disclaimer; the Subprocessors document; and the Documentation.
40.2 Order of precedence. Where there is a conflict, the following order applies, highest first.
| Rank | Document | Scope |
|---|---|---|
| 1 | A signed Order Form or Statement of Work | For the subject matter it expressly covers, except §32, which always applies. |
| 2 | The DPA | For the processing of Personal Information. |
| 3 | These Terms | Generally. |
| 4 | The Acceptable Use Policy, AI Features & Data Use Notice, Professional Services Schedule, Cyber Insurance Readiness Disclaimer and Subprocessors document | For their subject matter, subject to §14.9. |
| 5 | The Documentation | Descriptive; it creates no rights or obligations beyond those above. |
40.3 Purchase orders and entire agreement. A term in a Customer purchase order, vendor portal, supplier registration form or similar document has no effect and does not bind CyberWave, even if CyberWave acknowledges or accepts the document. The Agreement is the entire agreement on its subject matter and supersedes all prior proposals, quotations, presentations, marketing statements, representations and understandings on that subject matter, and neither party relies on any statement not set out in the Agreement. Nothing in this §40.3 limits liability for fraud or fraudulent misrepresentation.
41 Severability and waiver
41.1 Severability. If a provision is held invalid, illegal or unenforceable it will, where possible, be read down or reduced so as to be valid while preserving the parties' intent as closely as possible; where that is not possible it will be severed. In either case the remaining provisions continue in full force, and §30.4 and §32.7 apply in addition where relevant.
41.2 Waiver and remedies. A waiver of a provision or of a breach is effective only if in writing and signed by the waiving party; a failure or delay in exercising a right is not a waiver of it, and a waiver on one occasion is not a waiver on any other. Except where the Agreement states that a remedy is sole and exclusive, the parties' rights and remedies are cumulative and in addition to any other available at law or in equity.
42 Relationship of the parties
42.1 Independent parties. The parties are independent contractors. The Agreement creates no partnership, joint venture, agency, franchise, fiduciary or employment relationship, and neither party may bind the other or hold itself out as able to do so.
42.2 No third-party beneficiaries, and advisors. The Agreement is for the benefit of the parties only and confers no right on any other person, except that an indemnified affiliate, officer, director or employee may enforce an indemnity given in its favour under §31 through the party that obtained it. §26.2 applies to any CyberWave advisor providing Professional Services: an advisor acts for CyberWave in providing services to the Customer and holds no office of, and no employment relationship with, the Customer.
43 Electronic acceptance
43.1 How acceptance is recorded. When you accept these Terms, CyberWave records an acceptance containing the document identifier, the exact version string accepted, the date and time, and the identity of the accepting Authorized User. That record is retained as evidence of what was agreed and when, and is retained even where other data is deleted (§25.6). Each version carries a stable, opaque version identifier: it is the link between an acceptance record and the exact text accepted, so it is never reformatted or reused. You may request a copy of your acceptance record and of the version you accepted at any time by emailing support@cyberwave.ca.
43.2 Presentation at acceptance. These Terms and the Privacy Policy are presented or linked immediately adjacent to the acceptance control, in a form that can be read, printed and saved before acceptance, and acceptance requires an affirmative action that is not pre-selected.
44 Contact
| Purpose | How to reach us |
|---|---|
| Support, billing and general enquiries | support@cyberwave.ca |
| Privacy enquiries and requests | CyberWave's privacy contact at support@cyberwave.ca (subject: Privacy) |
| Security and vulnerability reports | support@cyberwave.ca (subject: Security) |
| Abuse reports | support@cyberwave.ca (subject: Abuse) |
| Legal notices under §36.2 | support@cyberwave.ca (subject: Legal notice) |
| Legal documents, including prior versions | The CyberWave Legal Centre |
CYBER WAVE INC., a corporation existing under the laws of Ontario, Canada (Ontario Corporation Number 1000780137), located in Markham, Ontario, Canada, trading as CyberWave.