Terms of Service

Please read these terms carefully before using our website or services.

Terms of Service

Last updated: 7 September 2026

These Terms of Service govern access to and use of the DataFort Solutions Ltd. website and any GDPR compliance, privacy, legal coordination, cybersecurity, and advisory services supplied by DataFort Solutions Ltd. or described on this website. They are intended to give clients a clear understanding of how our services operate, what we need from clients, and the limits that apply to website information and professional engagements.

These Terms are a general framework. A signed proposal, statement of work, engagement letter, data processing agreement, security rules of engagement, or other written order agreed with a client may contain additional terms. If there is a conflict, the signed engagement document will apply to the specific professional service to the extent of that conflict.

1. Who We Are

DataFort Solutions Ltd. provides practical GDPR compliance and cybersecurity advisory services for businesses that need to understand their obligations, reduce technology risk, and protect personal and business information. The website may refer to legal, privacy, technical, or advisory specialists working with or through DataFort Solutions Ltd. Where a matter requires local legal advice, DataFort Solutions Ltd. may coordinate introductions or workstreams with independent legal partners in European countries and European Union jurisdictions.

Unless a written engagement states otherwise, DataFort Solutions Ltd. is the service coordinator and advisory provider. An independent law firm, penetration-testing specialist, cloud provider, hosting company, or other external specialist remains responsible for its own professional work and contractual relationship where it contracts directly with a client.

2. Definitions

In these Terms, the following words have the meanings below:

  • “Client” means the person or organisation accessing the website or purchasing services.
  • “Content” means text, graphics, images, templates, guidance, reports, software, links, and other materials made available through the website or a service.
  • “Deliverables” means a report, register, policy, assessment, roadmap, presentation, training material, or other output expressly identified in a written scope.
  • “Personal Data” has the meaning given to it by applicable data-protection law.
  • “Professional Services” means the GDPR, privacy, legal coordination, cybersecurity, risk, testing, incident-response, training, and related services described on the website or in a written engagement.
  • “Website” means the DataFort Solutions Ltd. website, its pages, forms, resources, and related online functionality.

3. Acceptance and Eligibility

By using the Website, submitting an enquiry, subscribing to a newsletter, requesting a proposal, or purchasing Professional Services, you confirm that you have read and accepted these Terms. If you act for an organisation, you confirm that you have authority to bind that organisation.

You must be legally able to enter into a contract in your jurisdiction. You must not use the Website or Professional Services if doing so would breach a law, regulation, court order, contractual restriction, or professional obligation that applies to you.

4. Website Information and Advisory Scope

The Website is intended to provide general information about privacy, GDPR compliance, cyber risk, security testing, incident response, and related services. It is not a substitute for a fact-specific legal opinion, regulatory decision, insurance advice, financial advice, or emergency response service.

Information on the Website may not reflect the law, regulatory guidance, technology, or threat environment applicable to your specific organisation. You should not rely on website Content as the sole basis for a legal, security, operational, procurement, or investment decision. A professional conclusion is provided only within the scope and limitations of an agreed engagement.

5. Our Professional Services

Subject to an agreed scope, DataFort Solutions Ltd. may provide one or more of the following services:

  • GDPR audits, readiness reviews, compliance gap assessments, and remediation programmes;
  • records of processing, data-flow reviews, retention reviews, policy development, and accountability support;
  • Data Protection Impact Assessments and support for privacy-by-design decisions;
  • cybersecurity risk assessments, control reviews, threat modelling, and security roadmaps;
  • penetration testing and vulnerability assessments under an agreed rules-of-engagement document;
  • incident response planning, breach-management support, containment coordination, and lessons-learned reviews;
  • staff training, awareness programmes, tabletop exercises, and executive briefings;
  • coordination with independent legal partners for country-specific European or EU privacy and regulatory matters; and
  • ongoing advisory or premium support services where expressly included in a written engagement.

Not every service is available in every country or for every client. The applicable proposal or statement of work will define the services, assumptions, timetable, personnel, dependencies, Deliverables, fees, and acceptance criteria.

6. GDPR Audits and Compliance Programmes

A GDPR audit is a review performed against the agreed scope, evidence, systems, processes, and legal or regulatory criteria identified for the engagement. The audit does not automatically constitute certification, approval by a supervisory authority, a guarantee of compliance, or a finding that every risk has been identified.

Clients must provide accurate and complete information about their processing activities, systems, vendors, locations, data subjects, retention practices, security controls, and previous incidents. If information is missing, inaccurate, or withheld, the resulting assessment may be incomplete. Recommendations are prioritised according to the information available at the time and should be reviewed as the organisation changes.

7. Cybersecurity Risk Assessments

Cybersecurity assessments identify and prioritise selected risks based on the agreed methodology. They may include interviews, document review, configuration review, sampling, technical testing, or analysis of third-party information. An assessment is not a promise that an organisation is secure or that every vulnerability, threat, misconfiguration, or future attack will be detected.

Risk ratings are professional judgements made using the evidence and assumptions available during the assessment. Clients remain responsible for deciding which recommendations to implement, the order of implementation, and the level of risk they are prepared to accept.

8. Penetration Testing and Technical Testing

Penetration testing may be performed only after the client has provided written authority and an agreed rules-of-engagement document. That document should identify authorised targets, excluded systems, test windows, permitted techniques, emergency contacts, rate limits, data-handling requirements, and stop conditions.

The client warrants that it owns or is authorised to test every target and that it has obtained all necessary permissions from hosting providers, cloud providers, telecommunications providers, customers, and other third parties. DataFort Solutions Ltd. will not knowingly test an unauthorised target. The client must not ask DataFort Solutions Ltd. to exploit a third-party system or to conceal testing activity from a system owner.

Testing can cause service disruption, alerts, data changes, account lockouts, performance degradation, or other unintended effects even where reasonable precautions are taken. Clients must maintain appropriate backups, monitoring, recovery capability, and internal approvals before testing begins. Testing does not guarantee the discovery of all vulnerabilities and does not guarantee that a system will withstand a real attack.

9. Incident Response and Breach Support

Incident-response support is advisory and coordination support unless a written engagement expressly provides for an operational response role. Clients remain responsible for activating their internal incident plan, preserving evidence, making business decisions, notifying insurers, engaging law enforcement, and meeting statutory or contractual notification duties.

DataFort Solutions Ltd. does not guarantee that an incident can be contained within a particular period or that loss, disclosure, disruption, or further compromise can be prevented. Clients must provide timely access to relevant personnel, logs, systems, vendors, legal counsel, and decision-makers. Delays in providing information or authority may limit the response available.

10. Legal Partner and European Network Coordination

DataFort Solutions Ltd. may use its professional network to help a client identify or coordinate with independent legal partners in European countries and EU jurisdictions. A referral or introduction does not mean that DataFort Solutions Ltd. guarantees the partner’s availability, advice, outcome, fees, insurance, or professional performance.

Legal advice is provided by the relevant independent law firm where an engagement is formed with that firm. Clients should review that firm’s engagement terms, conflict checks, confidentiality arrangements, fee structure, and applicable professional rules. DataFort Solutions Ltd. may coordinate project information where authorised, but the client remains responsible for confirming the legal advice it receives and the instructions it gives.

11. Deliverables and Use of Reports

Deliverables are prepared for the Client and for the purpose stated in the applicable scope. Unless agreed otherwise, a Deliverable may not be supplied to a third party, published, quoted publicly, or relied upon by another person without written permission. This restriction does not prevent disclosure to the Client’s professional advisers, auditors, insurers, regulators, or group companies where they need the information and are bound by appropriate confidentiality obligations.

Deliverables reflect conditions and evidence at the time of preparation. They may become outdated because of changes in law, guidance, technology, personnel, suppliers, threats, business activity, or processing operations. A report is not a continuing warranty and should not be treated as a substitute for ongoing governance or monitoring.

12. Client Responsibilities

The Client must provide accurate, timely, and complete information; appoint appropriate contacts; make relevant personnel available; obtain permissions; maintain backups; respond to requests; review Deliverables; and make decisions within the agreed timetable. The Client must promptly tell DataFort Solutions Ltd. about changes that may affect the scope, including new systems, acquisitions, processing activities, suppliers, incidents, jurisdictions, or regulatory requirements.

The Client is responsible for its systems, networks, devices, accounts, credentials, backups, configurations, data quality, policies, staff conduct, vendor relationships, and legal obligations. DataFort Solutions Ltd. may rely on information supplied by the Client without independently verifying every statement.

13. Scope Changes and Dependencies

Any work outside the agreed scope requires written approval. Scope changes may affect fees, timetable, personnel, Deliverables, testing windows, and dependencies. DataFort Solutions Ltd. may pause work where the Client does not provide access, decisions, information, payment, or approvals needed to continue.

Dates and estimates are good-faith estimates unless expressly identified as fixed deadlines. DataFort Solutions Ltd. is not responsible for delay caused by the Client, a third party, unavailable systems, inaccurate information, late approvals, regulatory events, or circumstances outside reasonable control.

14. Fees, Invoicing, and Payment

Fees, expenses, taxes, payment dates, currencies, deposits, and billing milestones will be set out in the applicable proposal or engagement. Unless that document states otherwise, invoices are due within 14 days. The Client must raise a genuine invoice dispute promptly and provide reasonable detail; undisputed amounts remain payable on time.

Late payment may result in interest or recovery costs to the extent permitted by applicable law. DataFort Solutions Ltd. may suspend work or access to non-critical services after giving reasonable notice where an overdue amount remains unpaid. The Client is responsible for taxes, duties, bank charges, and expenses properly identified in the engagement.

15. Confidentiality

Each party must protect confidential information received from the other party and use it only for the agreed purpose. Confidential information includes business plans, security information, personal data, credentials, reports, pricing, technical details, legal advice, incident information, and non-public methods or materials.

Confidentiality does not apply to information that is public without breach, already lawfully known, independently developed, lawfully received from another source, or required to be disclosed by law or a competent authority. Where legally permitted, the receiving party will give advance notice of compelled disclosure and disclose only what is required.

16. Data Protection

Each party will comply with applicable data-protection law. The parties will determine their roles for each engagement. Where DataFort Solutions Ltd. processes Personal Data on the Client’s behalf, the parties will enter into a data processing agreement or include appropriate processor terms in the engagement.

The Client must ensure that it has a lawful basis and all required notices, permissions, instructions, and authorisations for Personal Data supplied to DataFort Solutions Ltd. The Client must not send unnecessary sensitive data, passwords, secret keys, or live production data where a redacted, masked, synthetic, or test dataset would be sufficient.

Further information about website data practices may be provided in a privacy notice. Website forms and newsletter subscriptions should be used only for the stated purpose. The Client remains responsible for ensuring that its own use of any Deliverable, recommendation, or technical output complies with applicable data-protection requirements.

17. Information Security and Access

Clients must protect accounts, invitations, access links, credentials, devices, and systems used in connection with the Services. Access must be limited to authorised personnel and must not be shared. Clients must notify DataFort Solutions Ltd. promptly if access is lost, misused, exposed, or suspected to be compromised.

DataFort Solutions Ltd. may apply reasonable access controls, logging, authentication, storage, retention, and transfer measures appropriate to the engagement. No online service can guarantee absolute security. The Client acknowledges that email, internet services, cloud services, and third-party platforms may carry residual risks outside DataFort Solutions Ltd.’s control.

18. Premium Support

Premium support is available only where expressly included in a written engagement or service plan. It may provide priority access to a dedicated support team, extended availability, response coordination, scheduled advisory sessions, or other benefits stated in the applicable plan.

Premium support is not a guarantee of a particular resolution time, business outcome, regulatory decision, incident result, or uninterrupted availability. It does not replace emergency services, law enforcement, a supervisory authority, a managed security operations centre, or the Client’s own incident-response responsibilities.

19. Contact Forms and Communications

Information submitted through the contact form must be accurate and must not contain malicious code, unlawful material, unnecessary Personal Data, credentials, or confidential information that the Client is not authorised to share. A contact form submission is an enquiry, not an acceptance of an engagement and does not create a solicitor-client, controller-processor, or other professional relationship by itself.

We may use submitted contact details to respond to an enquiry, prepare a proposal, administer a relationship, or provide service information where permitted by law. Newsletter subscriptions may be withdrawn using the available unsubscribe method. DataFort Solutions Ltd. may retain business communications where reasonably necessary for administration, security, legal compliance, dispute resolution, or recordkeeping.

20. Intellectual Property

DataFort Solutions Ltd. and its licensors retain all rights in the Website, templates, methodologies, tools, software, branding, processes, pre-existing materials, and general know-how. Subject to payment of applicable fees, the Client receives a non-exclusive, non-transferable licence to use the Deliverables internally for the purpose stated in the engagement.

The Client retains ownership of its data and materials. The Client grants DataFort Solutions Ltd. permission to use those materials only as needed to provide the Services, comply with law, protect systems, resolve disputes, and exercise rights under the engagement. The Client must not remove proprietary notices, reverse engineer protected tools, resell Deliverables, or present DataFort Solutions Ltd. materials as its own methodology.

21. Website Acceptable Use

You may use the Website for lawful business and informational purposes only. You must not interfere with the Website, probe or scan it without permission, bypass security controls, introduce malware, scrape content at scale, impersonate another person, infringe rights, harvest contact details, submit deceptive information, or use the Website to facilitate an attack.

DataFort Solutions Ltd. may limit, suspend, or block access where it reasonably believes that use threatens the Website, its users, its providers, or the integrity of an investigation or service. Nothing in these Terms grants permission to test the Website or any DataFort Solutions Ltd. system unless written authorisation expressly says so.

22. Third-Party Services and Links

The Website or Services may reference third-party software, cloud platforms, hosting providers, law firms, consultants, training providers, payment services, analytics providers, or external websites. Third-party terms and privacy notices may apply. DataFort Solutions Ltd. does not control and is not responsible for the availability, security, accuracy, legality, or performance of third-party services.

A referral, integration, recommendation, or link is not an endorsement or guarantee. The Client must perform its own due diligence and is responsible for selecting, instructing, paying, and managing third-party providers unless the written engagement expressly states otherwise.

23. No Certification or Guaranteed Outcome

Unless expressly stated in writing, DataFort Solutions Ltd. does not issue a legal certification, regulatory approval, security certification, insurance warranty, compliance guarantee, or promise that a Client will avoid enforcement, litigation, breach, downtime, loss, or attack.

Recommendations are designed to support informed decision-making. The Client remains responsible for implementation, governance, risk acceptance, legal compliance, security operations, and the accuracy of statements made to customers, regulators, insurers, auditors, or other third parties.

24. Disclaimers

To the maximum extent permitted by law, the Website and its general Content are provided on an “as available” basis. DataFort Solutions Ltd. does not warrant that the Website will always be available, uninterrupted, current, complete, error-free, or free from harmful components. We do not warrant that a service or recommendation will achieve a particular commercial, legal, security, or operational result.

Nothing in these Terms excludes a liability or legal right that cannot lawfully be excluded. Any professional standard expressly agreed in writing applies only within the relevant scope and does not convert an advisory service into a guarantee of outcome.

25. Limitation of Liability

To the maximum extent permitted by law, DataFort Solutions Ltd. will not be liable for indirect, incidental, special, exemplary, punitive, or consequential loss, or for loss of profit, revenue, business opportunity, anticipated savings, goodwill, reputation, contracts, data, or use, whether arising in contract, tort, negligence, breach of statutory duty, or otherwise.

Subject to mandatory law and the specific engagement, DataFort Solutions Ltd.’s total aggregate liability arising from an engagement will not exceed the fees paid or payable for the affected Services during the 12 months before the event giving rise to the claim. Different limits may apply where expressly agreed in a signed engagement.

These limits do not apply to liability that cannot lawfully be limited, fraud, fraudulent misrepresentation, or deliberate wrongdoing. The Client must take reasonable steps to mitigate loss and must notify DataFort Solutions Ltd. of a claim promptly with enough information to investigate it.

26. Client Indemnity

To the extent permitted by law, the Client will indemnify DataFort Solutions Ltd. against third-party claims, losses, costs, and reasonable expenses arising from the Client’s unlawful instructions, unauthorised testing, breach of these Terms, infringement of third-party rights, violation of data-protection obligations, or failure to obtain permission to provide data or systems for the Services.

27. Suspension and Termination

DataFort Solutions Ltd. may suspend access or Services where necessary to protect systems, personnel, confidential information, third parties, or the Client; where payment is overdue; where the Client gives an unsafe or unlawful instruction; where required by law; or where continuing would create an unacceptable security, legal, or professional risk.

Either party may terminate a Professional Services engagement in accordance with its written terms. If no termination provision is stated, either party may terminate on 30 days’ written notice, subject to payment for work completed and committed costs. Termination does not affect accrued rights, confidentiality, payment, intellectual property, data protection, liability, dispute resolution, or any provision intended to survive.

28. Force Majeure

Neither party is responsible for failure or delay caused by circumstances reasonably outside its control, including natural events, war, terrorism, civil unrest, labour disruption, government action, regulatory change, epidemic, internet or power failure, cloud or telecommunications outage, widespread cyber incident, supply-chain failure, or unavailability of a critical third party.

29. Changes to These Terms

DataFort Solutions Ltd. may update these Terms to reflect changes in services, law, technology, security practice, or business operations. The updated version will be posted on this page with a revised date. Continued use of the Website after an update means that the updated Terms apply to future website use. Changes to an existing Professional Services engagement require the process stated in that engagement or a written agreement between the parties.

30. Governing Law and Disputes

These Terms are governed by the laws of Ireland, without regard to conflict-of-law rules. The parties will first try in good faith to resolve a dispute through senior representatives. If a dispute cannot be resolved, the courts of Ireland will have exclusive jurisdiction, unless a signed engagement provides a different lawful dispute process.

31. General Provisions

  • If any provision is invalid or unenforceable, it will be modified to the minimum extent necessary and the remaining provisions will continue.
  • A failure or delay to exercise a right is not a waiver of that right.
  • The Client may not assign these Terms or an engagement without written consent, except as part of a permitted corporate reorganisation. DataFort Solutions Ltd. may assign or transfer its rights and obligations to an affiliate or successor that can perform them.
  • These Terms and the applicable written engagement form the agreement between the parties for the relevant subject matter and replace earlier discussions about that subject matter.
  • No person other than the parties has a right to enforce these Terms unless applicable law provides otherwise.
  • Headings are for convenience and do not affect interpretation.

32. Contact

Questions about these Terms, a proposal, an engagement, or the Website may be sent through the contact details and contact form provided on the DataFort Solutions Ltd. website. Please do not include passwords, private keys, payment-card details, or unnecessary sensitive Personal Data in an initial enquiry.

By using the Website or requesting Professional Services, you confirm that you have read, understood, and agreed to these Terms of Service.