The agreement between your organisation and Harman AJ Ltd for using SafeHanded. SafeHanded is provided to businesses only.
1.1 These Customer Terms ("Terms") are an agreement between Harman AJ Ltd, a company registered in England and Wales under company number 17412886 whose registered office is at Office 1575, 60 Tottenham Court Road, Fitzrovia, London W1T 2EW ("we", "us", "our"), and the organisation that creates or uses a SafeHanded account ("you", "your", the "Customer").
1.2 Business use only. SafeHanded is provided only to businesses, public bodies, charities and other organisations, for use in the course of their business. It is not offered to consumers. By accepting these Terms you confirm that you are acting for an organisation and not as a consumer, and that you have authority to bind that organisation.
1.3 You accept these Terms when you create an organisation, tick the acceptance box, sign an order form that refers to them, or use the service, whichever happens first.
1.4 The agreement consists of these Terms, our Acceptable Use Policy, our Data Processing Agreement (the "DPA") and any order form we sign with you. If they conflict, this order applies: (a) a signed order form, but only where it expressly says it overrides these Terms; (b) the DPA, for anything about personal data; (c) these Terms; (d) the Acceptable Use Policy.
1.5 In these Terms, "Customer Data" means data you or your users put into the service, including requests, shares, encrypted payloads, attachments, ticket references, branding, settings and audit records. "Users" means the people you permit to use your account, such as technicians, administrators and auditors. "Subjects" means the people you send requests or shares to.
2.1 SafeHanded is a hosted service for requesting, receiving and sending credentials and other sensitive information, with encryption in the sender's browser, ticket-linked lifecycles, purging and an audit trail, as described in our documentation.
2.2 We may change, improve or withdraw features. We will not make a change that materially reduces the security of the service or removes a core feature of a paid plan during your current billing period without giving you at least 30 days' notice. Plan limits and included features are also protected by clause 6.9. If such a change materially disadvantages you, you may end your subscription and we will refund prepaid fees for the unused period.
2.3 Preview features. Features marked "preview" or "beta" are provided as they are, may change or be withdrawn, and are excluded from any service-level commitment.
2.4 Availability. We aim to keep SafeHanded available at all times but do not guarantee uninterrupted service except under a signed service-level agreement. We will try to schedule maintenance outside UK business hours and give advance notice of planned downtime that we expect to be significant.
3.1 You must give accurate information when you create your account and keep your billing and administrator contact details up to date.
3.2 Users sign in with passkeys or through an identity provider you configure. You are responsible for deciding who has access, for their roles, for removing access promptly when someone leaves, and for everything done under your account and API keys.
3.3 Tell us straight away at security@safehanded.com if you believe your account has been accessed without authority.
3.4 Managed service providers. If you use SafeHanded to support your own clients, you do so as our customer: your clients are not party to this agreement and have no account with us. You are responsible for having your clients' authority to handle their users' data and credentials, and for your clients' use of any client-facing features.
4.1 SafeHanded encrypts secrets in the browser to keys held by your Users. We store only ciphertext and do not hold any key that can decrypt it.
4.2 This means we cannot read, recover or restore a secret for you. If every key able to decrypt a secret is lost, for example because a User's passkeys are lost and no organisation recovery key was set up or kept, that secret cannot be recovered by anyone, including us. You are responsible for enrolling enough passkeys and for setting up and safely storing your organisation recovery key.
4.3 Secrets are purged when a request is completed, expires, is revoked or its linked ticket closes, according to the rules you configure. A purged secret cannot be restored.
4.4 We are not liable for any loss caused by a secret being unrecoverable or purged in the circumstances described in this section 4.
5.1 You must use the service in line with these Terms, the Acceptable Use Policy and the law.
5.2 You are responsible for Customer Data, and for having a lawful basis and any notices or authority needed to send requests and shares to Subjects and to process their personal data.
5.3 You must not put special-category personal data, or data about criminal convictions, into any field of the service that is not end-to-end encrypted.
5.4 You must not use the service if you, or anyone who owns or controls you, is the subject of UK, EU, UN or US sanctions, or in a way that would put us in breach of sanctions or export-control law.
6.1 Plans. Our plans, their prices, included technicians and limits are shown on our pricing page and in your account. Any custom plan we agree with you is priced in an order form.
6.2 Free plan. The Free plan costs nothing and is subject to its limits. We may change or withdraw the Free plan on 30 days' notice.
6.3 Trial. We may offer a free trial of a paid plan. At the end of the trial your organisation moves to the plan you choose, or to the Free plan if you choose none. Moving plans does not delete Customer Data, but features and limits outside your new plan stop applying.
6.4 Billing. Paid plans are billed in advance, monthly or annually, in pounds sterling, through our payment provider Stripe. Fees exclude VAT and other applicable taxes, which we will add where required. Adding technicians during a billing period is charged pro rata; removing them credits the unused portion against future invoices.
6.5 Renewal and cancellation. Subscriptions renew automatically for the same period until cancelled. You can cancel at any time in your account; cancellation takes effect at the end of the current billing period and your organisation then moves to the Free plan.
6.6 Price changes. We may change our prices by giving at least 30 days' notice. A change takes effect from your next renewal after the notice period ends.
6.7 Late payment. If a payment fails, we will tell you and retry it. If it remains unpaid 14 days after we notify you, we may move your organisation to the Free plan or suspend paid features until it is paid. We may charge interest on overdue invoiced amounts under the Late Payment of Commercial Debts (Interest) Act 1998.
6.8 Refunds. Fees are non-refundable except where these Terms say otherwise or the law requires.
6.9 Changes to limits and features. We will not remove a feature included in your paid plan, or reduce one of its limits, during your subscription. If we reduce a limit on a paid plan, the change reaches an existing subscription only at a renewal that falls at least 12 months after we tell your organisation's owners, and you may cancel before it applies. Changes that give you more apply straight away. Every plan is subject to our published service limits, which protect the service for all customers; "unlimited" on a plan means no monthly count, not that those limits do not apply. This clause does not affect our rights under clause 14 or the Acceptable Use Policy.
7.1 You own Customer Data. You grant us a non-exclusive licence to host, copy, transmit and process it only as needed to provide, secure and support the service, and to comply with the law.
7.2 When we process personal data on your behalf, we do so as your processor under the DPA, which forms part of this agreement without needing to be signed. Our own processing as a controller, for example of account and billing contacts, is described in our Privacy Policy.
7.3 We may use counts and measurements of how the service is used, which do not identify you, your Users or any Subject, to operate, secure and improve SafeHanded.
7.4 We will not use your name or logo in our marketing without your written permission.
8.1 You can connect SafeHanded to services you choose, such as your helpdesk or PSA, identity provider, mail server, SMS account or SIEM. Those services are provided by third parties under their own terms, act on your instructions, and are not our sub-processors. We are not responsible for them, or for changes they make that affect an integration.
8.2 You must have the right to connect each service and to let SafeHanded use the credentials you give it.
9.1 Each party will keep the other's confidential information confidential, use it only for this agreement, and disclose it only to its personnel, advisers and subcontractors who need it and are bound by similar duties, or where the law requires.
9.2 This does not apply to information that is or becomes public other than through a breach of this clause, was already lawfully known to the receiving party, or is independently developed.
10.1 We and our licensors own all rights in SafeHanded, its software, documentation and brand. We grant you a non-exclusive, non-transferable right during the agreement for your Users to use the service for your business purposes.
10.2 If you send us suggestions or feedback, we may use them without obligation to you.
11.1 We warrant that, on paid plans, the service will perform materially as described in the documentation and that we will provide it with reasonable skill and care. If it does not, tell us and we will use reasonable efforts to correct it. If we cannot do so within a reasonable time, you may end your subscription and we will refund prepaid fees for the unused period. This is your only remedy for breach of this warranty.
11.2 Except as set out in these Terms, the service is provided "as is" and all other warranties, conditions and terms, whether implied by statute, common law or otherwise, are excluded to the extent the law allows. We do not warrant that the service will be uninterrupted or error-free, or that it will meet requirements you have not told us about in writing.
12.1 Nothing in this agreement limits or excludes liability for death or personal injury caused by negligence, fraud or fraudulent misrepresentation, or any other liability that cannot be limited or excluded by law. Nothing limits your obligation to pay fees.
12.2 Neither party is liable for any loss of profits, revenue, business, goodwill or anticipated savings, or for any indirect or consequential loss, however arising.
12.3 We are not liable for loss or corruption of data except for our obligation to use reasonable efforts to restore it from our most recent backup, and in no case for secrets that are unrecoverable or purged as described in section 4.
12.4 Subject to sections 12.1 to 12.3, each party's total liability arising out of or in connection with this agreement, whether in contract, tort (including negligence), breach of statutory duty or otherwise, in any 12-month period starting on the date you first accepted these Terms, is limited to the fees paid and payable by you under this agreement in the 12 months before the event giving rise to the claim. If you have paid no fees in that period, our total liability is limited to £100.
12.5 The limits in section 12.4 apply to all claims together, including claims under the DPA, and do not apply to your liability under section 13.
13.1 You will indemnify us against any third-party claim, and the reasonable losses and costs arising from it, to the extent it results from Customer Data, from your or your Users' breach of the Acceptable Use Policy, or from your sending requests or shares without the authority or lawful basis section 5.2 requires.
13.2 We will tell you promptly about any such claim, let you control its defence and settlement (provided you do not admit fault on our behalf without our consent), and give reasonable help at your cost.
14.1 We may suspend access to all or part of the service, for the whole organisation or a single User, API key, request or share, if we reasonably believe that: (a) it is needed to protect the service, other customers or Subjects from a security threat; (b) you or your Users are seriously breaching the Acceptable Use Policy; (c) the law requires it; or (d) payment is overdue as described in section 6.7.
14.2 We will limit a suspension to what is reasonably needed, tell you the reason where the law and security allow, and restore access once the cause is resolved.
15.1 This agreement starts when you accept these Terms and continues until ended under this section.
15.2 You may end it at any time by cancelling any paid subscription and asking us, at support@safehanded.com, to close your organisation.
15.3 We may end it on 30 days' written notice, in which case we will refund prepaid fees for the unused period.
15.4 Either party may end it immediately by written notice if the other: (a) commits a material breach that is not capable of remedy, or is not remedied within 30 days of being notified; or (b) becomes insolvent, enters administration or liquidation, makes an arrangement with its creditors, or suffers anything equivalent in any jurisdiction.
15.5 When the agreement ends, your right to use the service ends. You have 30 days to export anything you want to keep, such as your audit log. After that we delete Customer Data from the live service, and it falls out of our backups within 30 days, except where the law requires us to keep it.
15.6 Sections that by their nature should survive, including 4, 7.1, 9, 12, 13 and 17, survive the end of the agreement.
16.1 We may update these Terms. We will publish the new version on this page with its effective date and, for changes that materially affect you, give at least 30 days' notice by email to your organisation's owners.
16.2 If you object to a material change, you may end your subscription before it takes effect and we will refund prepaid fees for the period after that date. Otherwise the new version applies from its effective date. Changes required by law or made to address a security risk may take effect sooner.
17.1 Force majeure. Neither party is liable for delay or failure caused by events beyond its reasonable control, other than your obligation to pay.
17.2 Subcontractors. We may use subcontractors and sub-processors to provide the service and remain responsible for them.
17.3 Assignment. You may not transfer this agreement without our written consent, which we will not unreasonably withhold. We may transfer it to a successor to all or substantially all of the SafeHanded business, and will tell you if we do.
17.4 Notices. We send notices by email to your organisation's owners or billing contact. You send notices by email to support@safehanded.com. An email notice is received when sent, unless the sender receives a delivery failure.
17.5 Entire agreement. This agreement is the whole agreement between us about its subject matter and replaces earlier discussions. Neither party has relied on any statement not set out in it, but nothing limits liability for fraud.
17.6 Other terms. Terms in your purchase orders or procurement documents do not apply, even if we acknowledge them, unless we agree in a signed order form.
17.7 Third parties. No one other than you and us has any right to enforce this agreement under the Contracts (Rights of Third Parties) Act 1999.
17.8 Waiver and severance. A delay in enforcing a right is not a waiver of it. If any part of this agreement is found unenforceable, the rest remains in force.
17.9 Relationship. Nothing in this agreement creates a partnership, joint venture or agency.
17.10 Law and courts. This agreement, and any dispute arising from it, is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction.