Important Notice
These Terms of Service ("Terms") govern access to and use of SecureCMS, a consent management and data governance platform provided by SecuredApp ("SecuredApp", "we", "us", or "our"). These Terms are intended as a commercial and product-level template and should be reviewed by the legal team of the contracting entity before execution or publication.
Where a Customer signs a separate order form, subscription agreement, master services agreement, data processing agreement, service-level agreement, or other written agreement with SecuredApp, that agreement will govern to the extent of any conflict with these Terms.
1. Definitions
- “SecureCMS”
- means the SecureCMS consent management, cookie management, data governance, API, SDK, dashboard, workflow, and related services provided by SecuredApp.
- “Customer”
- means the organization or legal entity that subscribes to or is authorized to use SecureCMS.
- “Authorized User”
- means an individual authorized by the Customer to access or use SecureCMS under the Customer's account.
- “Customer Data”
- means data, content, configurations, consent records, identifiers, policies, documents, requests, or other information submitted to or processed through SecureCMS by or on behalf of the Customer.
- “Documentation”
- means user guides, technical documentation, API documentation, configuration guidance, and other materials supplied by SecuredApp for SecureCMS.
- “Services”
- means the hosted or otherwise provided SecureCMS functionality made available under an applicable subscription, order form, or agreement.
2. Acceptance of Terms
By accessing or using SecureCMS, the Customer and its Authorized Users agree to these Terms. If an individual accepts these Terms on behalf of an organization, that individual represents that they have authority to bind the organization.
If the Customer does not agree to these Terms, it must not access or use SecureCMS.
3. Description of Services
SecureCMS provides configurable technology for consent and privacy operations. Depending on the subscription and configuration, the Services may include:
- Consent collection, recording, review, management, and withdrawal workflows.
- Consent receipts, consent records, purpose and policy version management.
- Cookie management, cookie categorization, vendor mapping, and consent enforcement functionality.
- Data catalogue and data governance capabilities.
- Data subject request, grievance, escalation, and workflow management.
- APIs, SDKs, webhooks, middleware, and consent enforcement integrations.
- Audit logs, reporting, dashboards, notifications, and administrative controls.
- Tenant, application, role-based access, API key, authentication, and configuration management.
Features may vary by plan, deployment model, technical configuration, and applicable order form.
4. Customer Account and Authorized Users
- The Customer is responsible for maintaining accurate account information and keeping administrative information current.
- The Customer is responsible for controlling access to its SecureCMS tenant and for all activity performed through its Authorized Users and credentials.
- Credentials, API keys, signing credentials, access tokens, and similar authentication mechanisms must be kept confidential and must not be shared except as authorized.
- The Customer must promptly disable accounts or credentials that are no longer authorized or are suspected of compromise.
- The Customer must notify SecuredApp promptly of known or reasonably suspected unauthorized access or security incidents involving SecureCMS credentials.
5. Customer Responsibilities
The Customer is responsible for:
- Determining the purposes and lawful basis for processing personal data through its use of SecureCMS.
- Providing appropriate privacy notices and obtaining valid consent where consent is required.
- Ensuring that its consent language, purposes, data catalogue, cookie configuration, retention settings, and integrations are accurate and lawful.
- Ensuring that personal data supplied to SecureCMS is collected and disclosed to SecuredApp lawfully.
- Configuring integrations, webhooks, APIs, SDKs, and enforcement mechanisms appropriately.
- Responding to Data Principal/Data Subject requests where the Customer is the responsible Data Fiduciary or controller.
- Maintaining appropriate internal access controls and security procedures for systems connected to SecureCMS.
- Ensuring that Authorized Users comply with these Terms and applicable law.
6. Privacy and Data Protection
The parties acknowledge that SecureCMS may process personal data on behalf of Customers. The roles of SecuredApp and the Customer depend on the specific processing activity. For Customer Data processed on the Customer's behalf, the Customer generally determines the purposes and means of processing and SecuredApp processes such data in accordance with documented instructions and the applicable agreement.
The SecureCMS Privacy Policy describes SecuredApp's own privacy practices. Customers should maintain their own privacy notices for processing performed through their SecureCMS implementation.
Where required, the parties should execute a separate Data Processing Agreement (DPA) addressing security, confidentiality, sub-processors, incident notification, deletion/return of data, audits, and other processor obligations.
7. Compliance with Indian Data Protection Requirements
SecureCMS is designed to support privacy and consent operations relevant to India's Digital Personal Data Protection Act, 2023 (DPDP Act) and applicable rules and regulations. SecureCMS is a technology platform and does not itself determine whether a Customer's particular processing activity complies with the DPDP Act or any other law.
The Customer remains responsible for its legal obligations as a Data Fiduciary, including determining appropriate purposes, providing required notices, obtaining valid consent where applicable, honoring rights, managing grievances, implementing retention and deletion requirements, and configuring SecureCMS accordingly.
Nothing in these Terms constitutes legal advice or a certification that the Customer's implementation is compliant.
8. Consent Manager Status
Unless expressly stated in a written agreement and supported by the required registration or authorization, SecureCMS and SecuredApp must not be represented as a registered Consent Manager under the DPDP Act and the Digital Personal Data Protection Rules, 2025. SecureCMS may provide consent management functionality without itself acting as a registered Consent Manager.
The notified DPDP Rules, 2025 establish specific requirements for entities seeking registration as Consent Managers. The Customer must not rely on the availability of SecureCMS functionality as evidence that SecuredApp or the Customer is a registered Consent Manager.
9. Customer Data
As between SecuredApp and the Customer, the Customer retains its rights in Customer Data. The Customer grants SecuredApp a limited, non-exclusive right to host, copy, transmit, store, modify as technically necessary, and otherwise process Customer Data solely to provide, secure, maintain, support, and improve the Services as permitted by the applicable agreement and law.
SecuredApp may generate operational metadata, logs, diagnostics, aggregated statistics, and de-identified or aggregated information relating to use of the Services, provided that such information is not used to identify individuals except as necessary for security, support, legal compliance, or service operation.
10. Personal Data Minimization
The Customer should configure SecureCMS to collect and process only personal data necessary for the stated purpose. Where the platform supports hashing, pseudonymization, or other data-minimization mechanisms, the Customer should use those mechanisms where appropriate.
A cryptographic hash or pseudonymous identifier may still be personal data where an individual can reasonably be identified using available means. Customers should therefore evaluate the legal status of their identifiers and configurations rather than assuming that hashing makes information anonymous.
11. Acceptable Use
The Customer and Authorized Users must not:
- Use SecureCMS for unlawful, fraudulent, deceptive, abusive, or unauthorized activities.
- Attempt to gain unauthorized access to SecureCMS, another customer's tenant, SecuredApp systems, or related infrastructure.
- Circumvent security controls, rate limits, tenant isolation, authentication mechanisms, or access restrictions.
- Reverse engineer, decompile, disassemble, or attempt to derive source code from SecureCMS except to the extent such restriction is prohibited by applicable law.
- Upload malware, ransomware, malicious scripts, destructive code, or content intended to disrupt the Services.
- Use SecureCMS to process personal data without an appropriate lawful basis or required authorization.
- Transmit more personal data through an API, webhook, SDK, or integration than is reasonably necessary for the configured purpose.
- Use SecureCMS to conduct security testing against third-party systems without authorization.
- Resell, sublicense, lease, or provide access to SecureCMS to third parties except as expressly permitted by the applicable agreement.
- Remove proprietary notices or attempt to misrepresent ownership of SecureCMS.
12. APIs, SDKs, Webhooks and Integrations
SecureCMS may expose APIs, SDKs, webhooks, middleware, and integration interfaces. Their use is subject to applicable technical documentation, authentication requirements, rate limits, security requirements, and plan limitations.
The Customer is responsible for the security of API keys, client credentials, webhook secrets, certificates, and integration credentials under its control. The Customer is responsible for validating inbound webhook authenticity where SecuredApp provides verification mechanisms.
13. Third-Party Services
SecureCMS may integrate with or depend on third-party services such as identity providers, cloud infrastructure providers, communications providers, analytics services, security services, and other external systems. Third-party services may be subject to separate terms and privacy policies. SecuredApp is not responsible for third-party services that are outside its reasonable control.
14. Intellectual Property
SecureCMS, including its software, source code, object code, architecture, interfaces, documentation, designs, trademarks, logos, and related intellectual property, is owned by or licensed to SecuredApp and is protected by applicable intellectual property laws. Except for the limited rights expressly granted under these Terms or an applicable agreement, no rights are granted to the Customer in SecureCMS or SecuredApp's intellectual property.
15. Feedback
If the Customer provides suggestions, recommendations, bug reports, or other feedback concerning SecureCMS, SecuredApp may use that feedback without restriction or compensation, provided that doing so does not disclose Customer Confidential Information or personal data except as permitted by law.
16. Confidentiality
Each party may receive non-public information from the other party that is designated as confidential or that reasonably should be understood to be confidential ("Confidential Information"). Each party will use reasonable measures to protect the other party's Confidential Information and will use it only for purposes related to the relationship.
17. Service Availability and Maintenance
SecuredApp will use commercially reasonable efforts to keep SecureCMS available in accordance with the applicable service plan or service-level agreement. The Services may occasionally be unavailable due to maintenance, upgrades, emergency security measures, infrastructure failures, or circumstances beyond SecuredApp's reasonable control.
18. Changes to the Services
SecuredApp may update, improve, modify, or discontinue features of SecureCMS from time to time. We will use reasonable efforts to avoid materially reducing core functionality during an active subscription term, except where changes are required for security, legal, regulatory, technical, or third-party dependency reasons.
19. Fees and Subscription
Where SecureCMS is provided on a paid subscription basis, fees, billing periods, usage limits, renewal terms, taxes, and payment obligations will be specified in the applicable order form, subscription agreement, or commercial proposal. Unless otherwise agreed in writing, fees are exclusive of applicable taxes and governmental charges.
20. Suspension
SecuredApp may temporarily suspend access to SecureCMS where reasonably necessary to protect the Services, other customers, or individuals; respond to a security incident; address unlawful or abusive use; comply with law or an authority's direction; or address material non-payment or breach.
21. Termination
Either party may terminate the applicable subscription or agreement in accordance with its terms. SecuredApp may terminate or suspend an account for a material breach that remains uncured after applicable notice and cure requirements.
Upon termination, access to SecureCMS may cease. Subject to the applicable agreement, the Customer may request export or return of Customer Data during a defined transition period. After the applicable retention or transition period, Customer Data may be deleted or securely disposed of.
22. Disclaimers
To the maximum extent permitted by applicable law, SecureCMS is provided on an "as available" and "as is" basis, subject to the express commitments in the applicable agreement. SecuredApp does not warrant that SecureCMS will be uninterrupted, error-free, or suitable for every particular regulatory, business, or technical requirement.
SecureCMS is a technology platform and does not provide legal, tax, compliance, cybersecurity certification, or professional advice. Use of SecureCMS does not by itself establish compliance with the DPDP Act, any regulation, contractual obligation, industry standard, or regulatory requirement.
23. Limitation of Liability
To the maximum extent permitted by applicable law and subject to any mandatory liability that cannot legally be excluded, neither party will be liable for indirect, incidental, special, consequential, exemplary, or punitive damages, or for loss of profits, revenue, business opportunities, or goodwill arising from the Services.
The aggregate liability of SecuredApp arising out of or relating to SecureCMS and these Terms will be limited to the amount paid or payable by the Customer for the Services during the applicable period specified in the governing commercial agreement.
24. Indemnification
To the extent provided in the applicable agreement and permitted by law, each party will be responsible for claims arising from its own breach of law, material contractual obligations, or misuse of the other party's intellectual property.
25. Force Majeure
Neither party will be responsible for delay or failure caused by events beyond its reasonable control, including natural disasters, war, terrorism, civil disturbance, epidemic or pandemic events, governmental actions, telecommunications failures, cloud or infrastructure outages outside reasonable control, power failures, or other comparable events.
26. Governing Law and Dispute Resolution
Unless otherwise agreed in writing, these Terms will be governed by the laws of India, without regard to conflict-of-law principles.
Any dispute-resolution procedure, jurisdiction, arbitration mechanism, venue, and seat should be specified in the applicable commercial agreement. For enterprise and regulated customers, the signed agreement will control.
27. Notices
Operational and legal notices may be provided through the SecureCMS dashboard, registered email address, contractual contact channels, or other reasonable electronic means. The Customer is responsible for maintaining current contact details.
28. Changes to These Terms
SecuredApp may update these Terms from time to time. The updated version will identify the revised effective date or version. Material changes will be communicated through reasonable means where required. Continued use of SecureCMS after the effective date of an updated version constitutes acceptance to the extent permitted by law and the applicable agreement.
29. Severability
If any provision of these Terms is found invalid or unenforceable, that provision will be modified to the minimum extent necessary to make it enforceable, and the remaining provisions will continue in effect.
30. Entire Agreement and Order of Precedence
These Terms, together with the applicable order form, subscription agreement, DPA, SLA, Documentation, and other expressly incorporated documents, constitute the agreement governing use of SecureCMS. If there is a conflict, the order of precedence specified in the applicable commercial agreement will apply.
31. Contact Information
For questions regarding these Terms, SecureCMS, or contractual matters:
32. Regulatory Reference & Document Control
These Terms are intended to support use of SecureCMS in an Indian privacy and data protection context, including the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025, as applicable. The notified Rules were published on 14 November 2025 and provide a phased commencement framework. Nothing in these Terms overrides a mandatory requirement of applicable law.
| Version | Effective Date | Owner | Status |
|---|---|---|---|
| 1.0 | 11 August 2026 | SecuredApp | Draft for legal review |
- Digital Personal Data Protection Act, 2023 — Ministry of Electronics and Information Technology (MeitY).
- Digital Personal Data Protection Rules, 2025 — Ministry of Electronics and Information Technology (MeitY), notified 14 November 2025.