Terms of Service · Effective Risk Management

Terms of Service.

Draft · Pending review
This is a draft pending legal review. The content reflects MaturityOne's actual operational and security commitments as published on the Trust & Security page, but is not yet a final or legally-binding document. Specific clauses requiring counsel input - particularly limitation of liability, indemnification, governing law, and dispute resolution - are marked inline. Enterprise customers will typically transact under a negotiated Master Services Agreement (MSA) and Order Form, which prevail over these Terms.
- Last updated27 April 2026
- EffectivePending review
- VersionDraft 0.1
- EntityEffective Risk Management Pty Ltd
- Section 01

Acceptance and scope

These Terms of Service ("Terms") govern access to and use of the MaturityOne platform, websites, and associated services (the "Service") provided by Effective Risk Management Pty Ltd ("we", "us", "our"). By accessing or using the Service, the customer organisation and authorised users agree to be bound by these Terms.

For enterprise customers, these Terms are typically supplemented or superseded by a Master Services Agreement (MSA) or Order Form negotiated between the parties. Where an executed MSA or Order Form conflicts with these Terms, the MSA or Order Form prevails with respect to the parties to that agreement. Legal review required Order-of-precedence language must be confirmed by counsel.

- Section 02

Definitions

For the purpose of these Terms:

  • "Customer" means the organisation that has subscribed to the Service.
  • "Authorised User" means an individual employee, contractor, or agent of the Customer who has been provisioned access to the Service by the Customer.
  • "Customer Data" means all information, data, content, and materials submitted by the Customer or its Authorised Users to the Service, including assessment responses, evidence, comments, and configuration.
  • "Output" means the assessment scores, cross-domain cascade calculations, reports, dashboards, and other materials generated by the Service from Customer Data.
  • "Subscription Term" means the term of a Customer's subscription as set out in the relevant Order Form.
  • "Documentation" means the user-facing product documentation made available to the Customer.

Legal review required The complete defined-terms list, including any Australian Consumer Law-specific definitions, must be confirmed by counsel.

- Section 03

Account and access

Customer access to the Service is provided on a per-tenant basis. Within each Customer tenant, Authorised Users are provisioned by the Customer and assigned roles (Admin, Assessor, Reviewer, Executive) using the Service's role-based access control framework.

The Customer is responsible for: maintaining the confidentiality of all credentials and access tokens; promptly deactivating Authorised Users who no longer require access; using Single Sign-On (SAML 2.0 or OIDC) where supported by the Customer's identity provider; and enforcing multi-factor authentication where appropriate.

We will provide reasonable assistance to the Customer in respect of access management, but the Customer is the controller of its own tenant's access framework.

- Section 04

Customer responsibilities

The Customer is responsible for:

  • Lawful use. Ensuring that its use of the Service complies with all applicable laws, regulations, and industry codes, including the laws of the Customer's jurisdiction.
  • Authorised User conduct. The acts and omissions of all Authorised Users in the Customer's tenant, as if they were the acts and omissions of the Customer.
  • Customer Data accuracy. The accuracy, completeness, and lawfulness of Customer Data submitted to the Service.
  • Third-party rights. Ensuring that Customer Data does not infringe the intellectual property, privacy, or other rights of any third party.
  • Internal authorisation. Ensuring that any individual or entity granted access to the Service through the Customer's tenant has appropriate internal authorisation.
- Section 05

Acceptable use

The Customer and its Authorised Users must not, and must not permit any third party to:

  • Use the Service for any unlawful purpose, or in violation of any applicable law or regulation.
  • Attempt to reverse-engineer, decompile, or otherwise derive the source code of the Service, except where expressly permitted by applicable law.
  • Probe, scan, or test the vulnerability of the Service except under our published Responsible Disclosure program.
  • Interfere with or disrupt the Service, its security controls, or other customers' use of the Service.
  • Upload Customer Data containing malicious code, or use the Service to transmit malicious code to any third party.
  • Use the Service to harvest or process personal information unlawfully, or in breach of any applicable privacy law.
  • Resell, sublicense, or distribute access to the Service to any third party except as expressly permitted in writing by us.

Material breach of this Acceptable Use clause may result in suspension of access pending investigation, and termination of the subscription where the breach is not remedied.

- Section 06

Customer data and ownership

Customer Data belongs to the Customer. The Customer retains all right, title and interest in and to Customer Data. We claim no ownership over Customer Data.

The Customer grants us a limited, non-exclusive, royalty-free licence to access, use, copy, store, transmit, and process Customer Data solely for the purpose of providing and improving the Service for the Customer.

What we do not do with Customer Data

We do not sell Customer Data. We do not licence Customer Data to third parties. We do not use Customer Data to train third-party AI models. We do not use Customer Data to serve advertisements.

Aggregate benchmarking

Where the Customer explicitly opts in, we may use Customer Data in fully-anonymised and aggregated form to produce benchmarking statistics for the broader customer base. Individual customer data is never identifiable in benchmarking output, and the Customer may withdraw opt-in at any time.

On termination

On termination of the subscription, we will provide a full export of Customer Data in standard formats (JSON, CSV, XLSX, PDF) within 30 days of termination, and delete Customer Data from production systems within 60 days, with backups expiring on the standard 35-day rolling cycle.

- Section 07

Service availability

We will use commercially reasonable efforts to make the Service available with high uptime. Legal review required Specific Service Level Agreement commitments - including uptime percentage, scheduled maintenance windows, service credit calculations, and exclusions - to be confirmed by counsel and reflected in the relevant Order Form.

Disaster recovery objectives published on the Trust & Security page: Recovery Time Objective (RTO) of 4 hours; Recovery Point Objective (RPO) of 15 minutes. Disaster recovery testing is conducted quarterly with documented results.

Scheduled maintenance is conducted outside Australian business hours where practicable, with notice published in the Service.

- Section 08

Fees and billing

Fees for the Service are set out in the relevant Order Form. All fees are quoted in Australian Dollars (AUD) unless otherwise specified, and are exclusive of any applicable Goods and Services Tax (GST) or equivalent, which will be added where applicable.

Subscriptions are billed annually in advance unless otherwise agreed in writing. Payment terms are 30 days from invoice date. Legal review required Late payment terms, interest rates, and suspension thresholds to be confirmed by counsel.

Fees may be revised on subscription renewal with at least 60 days written notice prior to the renewal date. Legal review required Renewal pricing change protocols to be confirmed by counsel.

- Section 09

Term and termination

The Subscription Term is set out in the relevant Order Form. Subscriptions automatically renew for successive periods of the same length unless either party provides notice of non-renewal at least 30 days prior to the renewal date. Legal review required Auto-renewal terms must be confirmed by counsel and reflected in the Order Form.

Termination for cause

Either party may terminate the subscription for material breach by the other party, where the breach is not remedied within 30 days of written notice. Legal review required Specific cause-termination triggers and cure periods to be confirmed by counsel.

On termination

On termination for any reason: the Customer's access to the Service ceases at the end of the paid Subscription Term (or immediately on cause termination); we provide a Customer Data export per Section 06 above; outstanding fees become payable; and the surviving sections (Confidentiality, Limitation of Liability, Indemnification, Governing Law) continue to apply.

- Section 10

Confidentiality

Each party may disclose Confidential Information to the other in the course of the engagement. Confidential Information includes Customer Data, our pricing, technical architecture, security documentation, trust pack contents, and any information marked or reasonably understood to be confidential.

Each party will: use the other's Confidential Information only for the purpose of the engagement; protect it with at least the same care it uses to protect its own confidential information (and no less than reasonable care); and not disclose it to third parties except: (a) to its personnel and professional advisors with a need to know, who are bound by equivalent confidentiality obligations; (b) to authorised sub-processors under written Data Processing Agreements; or (c) where required by law, regulator request, or court order.

Confidentiality obligations survive termination of the subscription for a period of five (5) years, except for trade secrets and Customer Data, which remain confidential indefinitely. Legal review required Survival periods and exceptions to be confirmed by counsel.

- Section 11

Warranties and disclaimers

We warrant that the Service will substantially conform to the published Documentation and will be provided with reasonable skill and care.

To the maximum extent permitted by applicable law, the Service is provided "as is" and "as available". We disclaim all other warranties, express or implied, including but not limited to implied warranties of merchantability, fitness for a particular purpose, and non-infringement, except where such warranties cannot be excluded under applicable law.

Australian Consumer Law. Where the Customer is a "consumer" under the Australian Consumer Law (Schedule 2 to the Competition and Consumer Act 2010 (Cth)), nothing in these Terms excludes, restricts, or modifies any consumer guarantee, right, or remedy that cannot be excluded, restricted, or modified by law. Legal review required Specific Australian Consumer Law disclosure language to be confirmed by counsel.

- Section 12

Limitation of liability

Legal review required The full text of this section - including aggregate liability caps (typically expressed as a multiple of fees paid in the preceding 12 months), exclusions for indirect / consequential / special damages, carve-outs for breach of confidentiality and indemnification obligations, and Australian Consumer Law non-excludable rights - must be drafted and confirmed by counsel.

- Placeholder structure for counsel reference:

  1. Aggregate liability cap (excluding excepted claims).
  2. Exclusion of indirect and consequential losses.
  3. Excepted claims (breach of confidentiality, indemnification obligations, gross negligence, wilful misconduct).
  4. Australian Consumer Law non-excludable rights preservation.
  5. Customer's sole and exclusive remedy framework.
- Section 13

Indemnification

Legal review required Indemnification provisions - including our IP indemnification obligations to the Customer, the Customer's indemnification obligations to us in respect of Customer Data and Authorised User conduct, defence and control of claims, settlement consent rights, and notice and cooperation obligations - must be drafted and confirmed by counsel.

- Placeholder structure for counsel reference:

  1. Our IP indemnification of the Customer (subject to standard exclusions).
  2. Customer indemnification of us for Customer Data, Authorised User conduct, and breach of Acceptable Use.
  3. Notice, defence, and cooperation framework.
  4. Settlement consent and approval requirements.
- Section 14

Intellectual property

We retain all right, title, and interest in and to the Service, including the platform software, the maturity model content, the cross-domain cascade methodology, the assessment frameworks, the documentation, and all related intellectual property.

The Customer is granted a limited, non-exclusive, non-transferable, non-sublicensable right to access and use the Service for its internal business purposes during the Subscription Term, in accordance with these Terms and any applicable Order Form.

Customer Data and Output. The Customer retains ownership of Customer Data. Output generated by the Service from Customer Data is owned by the Customer to the extent it consists of Customer Data and assessment scoring derived from it; the underlying scoring methodology, calculation logic, and benchmarking framework remain our intellectual property.

Feedback, suggestions, and feature requests provided by the Customer are non-confidential and may be incorporated into the Service without obligation. Legal review required Feedback assignment language to be confirmed by counsel.

- Section 15

Governing law

These Terms are governed by the laws of Victoria, Australia. Legal review required Jurisdiction, venue, dispute resolution mechanism (mediation, arbitration, litigation), and any carve-outs for injunctive relief must be confirmed by counsel.

For Customers based outside Australia, additional jurisdiction-specific terms may apply as set out in the relevant Order Form. Legal review required APAC, Middle East, and South Asia jurisdiction-specific provisions to be confirmed by counsel.

- Section 16

General

  • Entire agreement. These Terms, together with the Privacy Policy, Cookie Policy, Trust & Security commitments, and any executed Order Form or MSA, constitute the entire agreement between the parties in respect of the Service.
  • Severability. If any provision of these Terms is held to be unenforceable, the remaining provisions continue in full force and effect.
  • No waiver. A failure to enforce any right under these Terms does not constitute a waiver of that right.
  • Assignment. Neither party may assign these Terms without the other party's prior written consent, except: (a) we may assign to a successor entity in connection with a merger, acquisition, or asset sale; or (b) the Customer may assign to a successor entity in connection with the same. Legal review required Assignment provisions to be confirmed by counsel.
  • Force majeure. Neither party is liable for delay or failure to perform caused by circumstances beyond its reasonable control. Legal review required Specific force majeure clauses to be confirmed by counsel.
  • Notices. Notices under these Terms must be sent in writing to the addresses on file. Legal review required Notice protocols and acceptable methods to be confirmed by counsel.
- Section 17

Contact

For questions about these Terms, or to discuss a Master Services Agreement or Order Form:

  • Email: contact@effectiverm.com with subject line "Terms"
  • Postal: Effective Risk Management Pty Ltd, Melbourne, Australia. Legal review required Full registered address to be inserted by counsel.