Phase 0 · Pre-launch. Commercial activity has not commenced.
BreachDuty ← Back to site

Terms of Service

Effective Date: August 8, 2026 · Version 1.0

These Terms of Service ("Terms") form a binding agreement between Ellis Intelligence LLC, a Colorado limited liability company doing business as BreachDuty ("BreachDuty", "we", "us"), and the firm or company subscribing to or using the Service ("Customer", "you").

The Service is intended for use by businesses managing a data-breach notification workflow — a company handling its own incident, or a breach-coach, privacy-attorney, incident-response firm, or managed-service provider handling notifications for its client companies. The Service is not for use by consumers, and individuals who receive breach notices are not users of the Service.

1. The service

1.1 BreachDuty is a software-as-a-service application that runs the mapping and timing side of a company's data-breach notification workflow: an incident-intake wizard (data classes, affected populations per state, discovery date), an Obligation Atlas that maps per-jurisdiction notification obligations with regulator overlays, statutory deadline clocks, a versioned and cited statute library, and an audit log with a chain-of-custody export and a sealed obligation-map PDF. Every obligation the Service presents carries its statutory citation. The Service is an obligation-map-and-timing-clock tool: it does not draft, assemble, or send breach-notification content; the Customer's own counsel originates, drafts, and sends every notice itself, through its own systems.

1.2 Tier-specific features and limits are described in the Engagement SOW; current pricing for each tier is presented in the Order Form before you accept it. Tiers: Direct (a mid-market company running its own incidents, priced by covered-state count and incidents per year) and White-label (a firm that brands the client-facing intake for its client companies under nested tenancy; branding does not extend to notice content, which BreachDuty does not generate).

1.3 Business use only. The Service is intended for use by a Customer's authorized workforce members — or, for a white-label Customer, by the firm's authorized personnel acting for its client companies — for internal breach-notification workflow purposes.

1.4 BreachDuty is software, not a law firm, lawyer, or compliance authority. BreachDuty is a software vendor providing a mapping, timing-clock, and record-keeping tool. BreachDuty does not practice law, does not render legal determinations, and does not decide whether or what any Customer must notify. BreachDuty does not:

1.5 BreachDuty is not a breach-detection, forensics, or consumer-identity service. BreachDuty processes the incident metadata the Customer's team enters. It does not detect breaches, perform forensic investigation, scan systems, monitor for compromise, or provide identity-protection, credit-monitoring, or any other consumer-facing service. Consistent with §2.3, individuals who receive notices are never entered into the Service as recipient records; they are neither customers, users, nor account holders of BreachDuty.

1.6 The Customer and its counsel decide. The Service maps obligations and runs the clocks. It does not draft notices — the Customer, through its own counsel, originates, drafts, and sends every notice through its own systems. The Customer is responsible for the accuracy of the facts it enters (data classes, affected-population counts per state, discovery date) and for the notice content and the legal judgment applied to it. Your counsel makes the call and sends the notice; BreachDuty helps make sure it happens on time and on the record.

2. Account, firms, and client companies

2.1 Account creation requires an authorized representative of the Customer entity.

2.2 Nested tenancy. The Service is nested multi-tenant. A white-label firm is a tenant whose client companies are second-tier records within that tenant; a direct Customer is simply a tenant with a single company (itself). Every tenant-scoped read and write routes through company-scoped isolation helpers that require both the tenant identifier and the company identifier, so one company's incident, obligation, and notice data never crosses to another company's — within a firm or across firms.

2.3 No individual consumer records. Consistent with §1.1–§1.6, the Service does not draft, assemble, or send notices, so it does not collect or store any individual consumer's name or contact information. The Customer enters affected-population counts per jurisdiction (§1.1) to compute notification obligations; any consumer who receives a notice does so entirely through the Customer's own systems, outside BreachDuty. No consumer holds credentials, authenticates, or is a "User" of the Service, and no consumer is offered, or receives, any account, portal, identity-protection, or credit-monitoring service through BreachDuty.

3. Subscriptions, pricing, billing

3.1 Subscriptions are self-serve and card-only. Direct tiers are billed monthly, banded by covered-state count and incidents per year; the White-label tier is a self-serve annual subscription. Current pricing is presented in the Order Form before checkout (§1.2). There is no invoice or net-30 billing, no negotiated tier, and no per-incident fee — the subscription covers the Customer's ongoing use of the workflow during the billing period.

3.2 30-day notice for material pricing changes.

3.3 Billing via Stripe. Stripe currently runs in TEST mode only; no live charge path is reachable until the separate live-Stripe launch gate is satisfied.

3.4 Taxes. Sales, use, VAT, and similar taxes we are required to collect are collected and remitted through Stripe Tax, our payment processor's tax-collection service. This is the same mechanism for every brand in the portfolio; no brand collects tax outside Stripe Tax.

3.5 Refunds. Fees are non-refundable for the current billing period except pro rata on our material breach or on discontinuation under §12; any refund is paid within 30 days after the effective date of termination.

3.6 The Service tracks statutory deadlines as a convenience. The Service computes and tracks per-obligation statutory deadlines and sends reminders ahead of each (§8). The Customer remains solely responsible for meeting its own notification deadlines and any regulatory, contractual, or carrier-imposed obligation; the reminders are a courtesy, not a substitute for the Customer's and its counsel's own diligence.

4. Customer data; nested tenancy

4.1 Ownership. As between us, you own all Customer Data you submit ("Customer Data"), including your company and client-company identities, incident metadata, affected-population counts, obligation maps, and the audit and chain-of-custody records the Service generates for you. The Service does not require or store notice content or individual consumer identity/contact records.

4.2 License to us. You grant us a limited license to host, store, transmit, display, and process Customer Data solely to provide the Service (including mapping obligations, computing deadlines, tracking the notice clock, generating the sealed obligation-map PDF and chain-of-custody export, and managing reminders and statute change-notices).

4.3 No training / no selling. We do not sell or share Customer Data, and we do not use it to train any model or to improve a Service used by other customers. See our Privacy Policy.

4.4 Nested per-tenant, per-company isolation. Each firm is one tenant; each client company is a company-scoped record within it; a direct Customer is a tenant with one company. Every tenant-scoped read and write routes through company-scoping helpers that require both the tenant and company identifiers so no company can access another company's data. There is no public, unauthenticated surface that exposes any tenant, company, or consumer data — the tamper-evident record and its exports (§7) are disclosed only to the Customer, who controls onward sharing.

5. Acceptable use

Our Acceptable Use Policy, published standalone at breachduty.com/acceptable-use, applies in addition to this §5.

5.1 No reverse engineering, no scraping, no building a competing product from the Service, no resale.

5.2 No misrepresentation of a legal determination or certification. You will not represent to any party (a regulator, an attorney general, a consumer, an auditor, an insurer, or any other party) that BreachDuty has determined, certified, or legally opined on your notification obligations, deadlines, or compliance, or that a deadline or obligation the Service computed is itself legal advice. The obligation map is a cited software output for your counsel to confirm; it is not an assessment, certification, or legal opinion by BreachDuty.

5.3 BreachDuty is not a substitute for counsel. You will not use the Service as a replacement for your own legal counsel's judgment. The Service is a workflow and record tool; your counsel decides whether and what to notify.

5.4 Notice origination and delivery. The Service does not generate, assemble, or deliver breach-notification content. Any pre-notification or final breach notice is originated, drafted, assembled, and delivered by you or your Client Companies, through your own systems and your own counsel's review — not by us. BreachDuty never sends, transmits, or delivers anything to any regulator, attorney general, or consumer, and you will not attempt to configure, integrate, or use the Service to make it send, transmit, or deliver a notice on your behalf. This non-involvement in delivery is a scope boundary, not a legal guarantee about the notice you send — it does not represent that the notice content, the underlying obligation determination, or the statute entry it relies on has been reviewed or endorsed by counsel. Because your notice reaches a regulator, attorney general, or consumer — a party outside your control once delivered — this exposure carries higher consequence than a general product safeguard, and your and your counsel's review obligation under §1.6 and §6.1 applies in full: the fact that BreachDuty does not touch the send does not shift responsibility for the notice — which your counsel drafts, assembles, and delivers — to us.

6. Service outputs, accuracy, and disclaimers

6.1 Cited software output, not a legal determination. The obligation map, computed deadlines, and regulator overlays the Service produces are software outputs computed from the facts you enter against a versioned statute library, each shown with its statutory citation. The Service does not generate, draft, or output breach-notification content. These outputs are not legal advice, a legal determination, a compliance certification, or a substitute for your counsel's judgment. You are solely responsible for the accuracy of the facts you enter and, together with your counsel, for whether and what to notify, and for drafting, assembling, and delivering every notice.

6.2 No guarantee of compliance. BreachDuty does not guarantee compliance with any law and does not guarantee that any obligation, deadline, regulator overlay, or notice the Service produces is correct, complete, current, or sufficient for your actual facts or for any regulator's, attorney general's, or court's requirements. Your obligations depend on facts only you and your counsel can assess.

6.3 The correctness discipline. Each deadline is computed from the statute version in force on the incident's discovery date. Statute content is effective-date-versioned; a statute amendment writes a new versioned entry and never overwrites a prior one, re-computation is explicit and logged, reminders fire exactly once, and amendment change-notices are sent to affected tenants (§8). Statute content is maintained on a per-release review cadence with independent counsel validation before any statute surface goes live; content is not represented as counsel-validated until that review is complete. This discipline reduces, but does not eliminate, the risk of a stale or incorrect entry, and does not shift the responsibility in §6.1–§6.2.

6.4 Implementation and judgment are the Customer's responsibility. The Service documents and schedules the notification workflow from what the Customer's team enters. Actual compliance depends on the Customer acting — verifying the facts, obtaining its counsel's decision, and drafting and sending notices on time through its own systems. BreachDuty does not investigate the incident, decide the legal question, or draft, assemble, or send anything on the Customer's behalf.

7. The tamper-evident record, sealed obligation-map PDF, and chain-of-custody export

7.1 Every material step in the workflow — incident opened, populations set, obligation computed, notice sent (self-reported by the Customer, since the Service does not itself draft, assemble, or send any notice), clock warning, incident closed — is written to a canonical, tamper-evident audit spine under the Customer's tenant.

7.2 The Customer can export a sealed obligation-map PDF (the incident's obligation map with running clocks and citations) and a chain-of-custody export of the full audit spine. These are data-integrity and record-keeping mechanisms: they document, timestamp, and preserve what the Customer's team did and when. They do not constitute a legal determination, certification, or endorsement by BreachDuty, and they do not represent that any obligation or deadline is correct as a matter of law.

7.3 There is no public, unauthenticated verification surface. The sealed record and its exports are disclosed to the Customer only. The Customer decides whether, and with whom (its counsel, a regulator, an insurer, an auditor), to share them; once shared or exported, a copy is the Customer's own.

7.4 A sealed obligation-map PDF, once generated, is retained as a record of the obligation map as it stood at seal time. If the incident's facts change and the map is recomputed, a new record is generated; the prior record is retained as a superseded record, not silently altered.

8. Deadline clocks, reminders, and statute change-notices

8.1 For each triggered obligation, the Service computes a statutory deadline from the statute version in force on the discovery date and sends reminders ahead of it, business-day- and holiday-shifted, firing exactly once. Each reminder is a courtesy notification; the Customer remains responsible for meeting its own obligations on schedule.

8.2 When a statute is amended, the Service writes a new effective-date-versioned entry (never overwriting the prior one) and can send an amendment change-notice to affected tenants. The Service does not detect breaches, monitor the Customer's systems, or independently discover a change in the Customer's facts; the Customer is responsible for keeping the incident facts current and for initiating re-computation when its facts change.

9. Intellectual property

9.1 We own the Service and its contents, including the statute library. BreachDuty does not maintain a notice-letter template set. You own your Customer Data, including your incident, obligation, and notice content.

9.2 The statute library is authored content owned by BreachDuty; the Customer receives a license to use it within the Service under its subscription, not to redistribute or resell it.

10. Disclaimer of warranties

THE SERVICE IS PROVIDED "AS IS." WE DISCLAIM ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING WARRANTIES OF FITNESS FOR A PARTICULAR PURPOSE, ACCURACY, AND NON-INFRINGEMENT. WE DO NOT WARRANT THAT THE STATUTE LIBRARY IS CURRENT, COMPLETE, OR CORRECT FOR EVERY JURISDICTION AT EVERY MOMENT, THAT ANY COMPUTED DEADLINE OR OBLIGATION IS CORRECT AS A MATTER OF LAW, OR THAT THE SERVICE'S OUTPUTS WILL SATISFY ANY LAW, REGULATOR, ATTORNEY GENERAL, OR COURT. THE SERVICE IS NOT A SUBSTITUTE FOR LEGAL COUNSEL.

11. Limitation of liability

TO THE EXTENT PERMITTED BY APPLICABLE LAW, OUR AGGREGATE LIABILITY ARISING FROM OR RELATED TO THE SERVICE WILL NOT EXCEED THE FEES YOU PAID IN THE TWELVE MONTHS PRECEDING THE CLAIM. IN NO EVENT ARE WE LIABLE FOR INDIRECT, CONSEQUENTIAL, SPECIAL, INCIDENTAL, OR PUNITIVE DAMAGES, INCLUDING ANY FINDING, INQUIRY, INVESTIGATION, PENALTY, FINE, OR ENFORCEMENT ACTION BY ANY REGULATORY, ADMINISTRATIVE, OR ENFORCEMENT BODY OF ANY KIND — INCLUDING WITHOUT LIMITATION ANY STATE ATTORNEY GENERAL, STATE REGULATOR, OR FEDERAL AGENCY — ARISING UNDER ANY BREACH-NOTIFICATION STATUTE OR OTHER APPLICABLE LAW OR REGULATION, ANY MISSED DEADLINE, OR ANY LIABILITY ARISING FROM THE CUSTOMER'S OR ITS COUNSEL'S NOTIFICATION DECISIONS OR FROM RELIANCE ON A STATUTE ENTRY, OBLIGATION, OR DEADLINE THE SERVICE PRODUCED. THIS CARVE-OUT IS STATED AS BROADLY AS POSSIBLE AND APPLIES UNIFORMLY REGARDLESS OF THE SPECIFIC STATUTE, REGULATION, OR REGULATORY OR ENFORCEMENT BODY INVOLVED; A PARTY ASSERTING THAT THIS CARVE-OUT DOES NOT APPLY TO A PARTICULAR CLAIM, STATUTE, OR REGULATORY OR ENFORCEMENT BODY BEARS THE BURDEN OF ESTABLISHING THAT, RATHER THAN US BEARING THE BURDEN OF HAVING DISCLAIMED EACH ONE INDIVIDUALLY. WE APPLY THIS FORMULATION UNIFORMLY ACROSS OUR TEMPLATE LIBRARY RATHER THAN TAILORING IT PER STATUTE.

11.1 Indemnification — stated in the contract you execute. Both indemnities — ours for IP infringement and yours — are stated in full on the face of §7 of the BreachDuty Engagement & Tiers SOW, together with the claim procedure. That §7 is the indemnification block carried on the face of the click-signed Order Form you accept at either tier, rendered above the agree control. Those provisions govern; this §11.1 is a cross-reference and does not restate them. These Terms state no indemnification obligation separate from, additional to, or narrower than SOW §7, and nothing in these Terms enlarges or limits it. The liability cap stated above in this §11 does not apply to either party's obligations under SOW §7.

12. Term and termination

12.1 These Terms continue until the subscription is canceled or terminated. Cancellation takes effect at the end of the current billing period.

12.2 We may terminate for material breach of these Terms (including misrepresentation of a legal determination or certification status under §5.2, or an attempt to auto-send under §5.4), with 10 days' written notice (email to the account or billing contact, deemed given when sent; the period runs from the send date) unless the breach is incurable.

12.3 On termination, Customer Data (including obligation maps, notice records, and audit exports) is available for export for 30 days, then deleted. Sealed obligation-map PDFs and chain-of-custody exports the Customer downloaded before deletion remain the Customer's own records; our copy is deleted per this schedule.

13. Governing law; disputes

Governed by Colorado law. Disputes are resolved by binding arbitration administered by JAMS in Boulder County, Colorado, except that either party may seek injunctive relief in a Colorado court. Each party waives any right to a jury trial and to participation in any class, collective, or representative proceeding.

14. Updates

30 days' email notice to the Customer billing contact for material changes. Notice is deemed given when sent; the 30-day period runs from the send date, and failure to read a notice does not extend it. Continued use after the effective date constitutes acceptance.

15. Contact

[email protected] — legal
[email protected] — privacy

BreachDuty is a product of Ellis Intelligence LLC. BreachDuty is software, not a law firm, lawyer, or compliance authority; this is general information, not legal advice — your own counsel decides whether and what to notify. See also our Privacy Policy. Questions about this document? Email [email protected].