# **PIIQ - Terms & Conditions**

**V 2.3 — 11-Jan 2026**

This document (Part A) governs the use of the PIIQ Software as a Service platform ("the Service") provided by Nearfield.ai Ltd ("Nearfield.ai" or "the Processor") to professionals, firms, and enterprises ("the Subscriber" or, in the context of data processing, "the Controller") utilising the Service for processing data related to Data Subject Access Requests (DSAR), Freedom of Information Act (FOIA) requests, and general PII detection.

Throughout this Agreement:
- "Subscriber" refers to the customer using the Service
- "Controller" refers to the Subscriber in their capacity as data controller under GDPR
- "Processor" refers to Nearfield.ai in its capacity as data processor
- "Source Data" refers to documents uploaded for processing

**Note:** These Terms & Conditions should be read in conjunction with our Privacy Policy.

---

## **1. Acceptance of Terms**

**1.1 Binding Agreement**
This Agreement (including the Terms & Conditions, Privacy Policy, and Data Processing Agreement) becomes legally binding upon the Subscriber when the Subscriber completes the Electronic Acceptance Process during registration.

**1.2 Acceptance Procedure Required**
By registering for the Service, the Subscriber must:
- (a) Review all three parts of this Agreement (Terms & Conditions, Privacy Policy, and Data Processing Agreement)
- (b) Provide explicit consent via the electronic acceptance checkboxes
- (c) Confirm their role as Data Controller
- (d) Acknowledge their GDPR compliance obligations

**1.3 No Passive Acceptance**
Access to the Service is not permitted without completing the Acceptance Procedure. Mere browsing of marketing materials or documentation does not constitute acceptance of these terms.

**1.4 Legal Effect**
Completion of the Acceptance Procedure creates a legally binding contract under UK law and satisfies the requirements for electronic signatures under the UK Electronic Communications Act 2000 and EU Regulation 910/2014 (eIDAS).

---

## **2. Description of Service**

The Service provides a cloud-based, AI-powered platform for the automated identification, contextual analysis, and compliant redaction of Personally Identifiable Information (PII) within unstructured data assets, specifically designed to streamline the fulfillment of DSAR and FOIA requests. Access is granted exclusively under these terms.

---

## **3. Subscriber Accounts, Registration, and Credentials**

**3.1 Registration**
Subscribers must provide accurate, current, and complete account and contact information during the registration process.

**3.1.1 GDPR Compliance Acceptance**
During registration, Subscribers must:
- Review and accept these Terms & Conditions (Part A)
- Review and accept the Privacy Policy (Part B)
- Review and accept the Data Processing Agreement (Part C)
- Confirm their role as Data Controller
- Acknowledge their GDPR compliance obligations to their clients

**3.2 Security**
The Subscriber is solely responsible for maintaining the confidentiality of their login credentials and for all activities that occur under their account. The Subscriber must notify Nearfield.ai immediately of any unauthorised use or breach of security.

**3.3 Professional Use**
Accounts are intended for use by compliance, legal, and HR professionals (the underlying Data Controllers) utilising the Service within their professional capacity to assist clients.

**3.3.1** Subscribers acting as controllers must ensure clients accept PIIQ Terms including DPA (Part C); non-compliance voids this agreement.

**3.3.2** The Processor requires partners to have back-to-back DPA terms with their clients.

**3.3.3 Subscriber Compliance Framework:**
- **Annual Compliance Certification** - Self-assessment questionnaire, DPA acceptance documentation, client complaints log
- **Audit Rights** - Random sampling of 10% partner-client relationships annually, documentation review (DPA acceptances, client communications), remediation timeline: 30 days for minor issues, immediate for critical
- **Breach Reporting** - Subscriber must notify Nearfield within 12 hours of any suspected breach, cooperative investigation requirements
- **Training Requirements** - Quarterly GDPR compliance updates for Subscriber staff, annual certification renewal

---

## **4. Subscription, Payment, and Credits**

### **4.1 Subscription Model**

Access to the Service requires a valid subscription based on the chosen plan (Essential, Advanced, Pro or Enterprise).

**4.1.1 Subscription + Credits Model**
The Service operates on a dual-pricing model:
- (a) **Subscription Fee:** Grants access to the platform, tools, and features
- (b) **Processing Credits:** Consumed when performing PII detection, redaction, and report generation

Both a valid subscription AND sufficient credits are required to perform processing operations.

### **4.2 Usage Fees (Credits)**

Core processing functions (including search, PII detection, and redaction) consume PIIQ Credits. Credits are purchased on an as needed basis, or bulk in advance.

### **4.3 Payment Terms**

**4.3.1 Advance Payment Requirement**
Subscription fees and Credit purchases must be paid in advance before services can be accessed or processing can commence.

**4.3.2 Payment Methods**
Payment may be made via:
- Credit/debit card (processed securely via our payment provider)
- Invoice and bank transfer (on request for Enterprise and Contract plans only)

**4.3.3 Automatic Renewal**
Unless cancelled in accordance with Section 10 (Termination), subscriptions will automatically renew at the end of each billing period at the then-current rates.

### **4.4 Service Suspension for Non-Payment**

**4.4.1 Grace Period**
If payment fails or subscription fees remain unpaid beyond the due date, the Subscriber will receive a 7-day grace period during which:
- Full platform access continues
- All processing functions remain available
- Email reminders will be sent on days 1, 4, and 7

**4.4.2 Suspension After Grace Period**
If payment is not received within the 7-day grace period, the Processor may:
- Suspend new processing operations (uploads, new case creation, new redaction jobs)
- Restrict account access to read-only mode
- Subscriber retains access to: Credit Estimator tool, Discovery/Search functionality, Completed outputs and reports

**4.4.3 Protection of Existing Data**
Even during service suspension or after account termination, the Processor will ensure all generated reports are stored locally and can be accessed by the customer after the contract ends.

**4.4.4 Data Retention During Suspension**
During service suspension:
- All existing data remains securely stored for 30 days
- After 30 days of continued non-payment, standard data deletion policies will apply

**4.4.5 Service Reinstatement**
To reinstate full service access:
- Pay all outstanding fees plus any applicable late payment charges
- Service access will be restored within 24 hours of payment confirmation
- All data created prior to suspension will remain accessible

### **4.5 Credit Balance and Expiration**

**4.5.1 Credit Usage**
Credits are deducted from the Subscriber's account balance as processing operations are performed. Real-time balance tracking is available in the account dashboard.

**4.5.2 Credit Expiration**
- **Monthly Plans:** Credits do not expire at the end of each monthly billing period (unused credits do roll over)
- **Annual Plans:** Credits are valid for 12 months from purchase date and do not expire, but a subscription plan is required to be able to use them

**4.5.3 Insufficient Credits**
If the Subscriber's Credit balance is insufficient to complete a processing operation:
- The system will notify the Subscriber before processing begins
- Processing will not commence until additional Credits are purchased
- Ad hoc credits can be purchased to complete processing

**4.5.4 Unused Credits on Termination**
- **Subscribers:** Non-refundable. Credits remain available for 90 days post-termination should the Subscriber wish to reinstate service
- **Voluntary Cancellation:** If Subscriber voluntarily cancels service with unused credits, no refund provided unless required by consumer protection law
- **Nearfield-Initiated Termination:** If service terminated by Nearfield.ai for breach, no refund provided. Exception: If Nearfield.ai terminates the Service for reasons other than Subscriber breach (e.g., service discontinuation, force majeure), Subscriber shall receive a pro-rata refund of unused subscription fees and credit value

### **4.6 Late Payment and Collection**

**4.6.1 Late Payment**
Service will be suspended for 7 days and reinstated when payment is received.

### **4.7 Pricing Changes**

**4.7.1 Notice of Changes**
The Processor reserves the right to modify subscription fees and Credit pricing upon 30 days' written notice to the Subscriber.

**4.7.2 Effect of Changes**
- **Current Term:** Pricing changes do not affect the current billing period
- **Renewal:** New pricing takes effect upon the next renewal date
- **Right to Cancel:** Subscriber may cancel before renewal to avoid new pricing (see Section 10)

### **4.8 Taxes and Additional Charges**

**4.8.1 Value Added Tax (VAT)**
All prices are exclusive of VAT unless otherwise stated. VAT will be added to invoices at the applicable rate for UK businesses or as required by law.

**4.8.2 Subscriber Tax Obligations**
The Subscriber is responsible for all taxes, duties, and levies (other than taxes on the Processor's income) arising from the use of the Service.

### **4.9 Billing Disputes**

**4.9.1 Dispute Notification**
If the Subscriber disputes any charge, they must notify the Processor in writing at compliance@nearfield.ai within 30 days of the invoice date, providing:
- Invoice number and date
- Specific charges disputed
- Detailed explanation of the dispute
- Supporting documentation (if applicable)

**4.9.2 Resolution Process**
The Processor will:
- Acknowledge the dispute within 2 business days
- Investigate and respond with findings within 10 business days
- Suspend collection efforts on disputed amounts during investigation
- Provide detailed explanation of charge calculation or issue credit as appropriate

### **4.10 International Transfers and Safeguards**

All data processing occurs within the UK/EEA. Any transfers to third countries will only occur with appropriate safeguards under GDPR Chapter V, including Standard Contractual Clauses or adequacy decisions. See the Data Processing Agreement (Part C) for full international transfer provisions.

---

## **5. License and Use Restrictions**

**5.1 Grant of License**
The Subscriber is granted a limited, non-exclusive, non-transferable, and revocable license to access and use the Service strictly for its internal and client-facing business purposes related to compliance and data request fulfillment.

**5.2 Prohibited Activities**
The Subscriber shall not:
- (a) reverse engineer, decompile, or disassemble the Service
- (b) use the Service to process data that violates any third-party rights or laws
- (c) attempt unauthorised access to any component of the Service or related systems
- (d) use the Service for any purpose other than the processing of PII/DSAR/FOIA data

---

## **6. Intellectual Property**

All software, visual interface, underlying AI algorithms, trademarks, and methodologies associated with the Service remain the exclusive property of Nearfield.ai. The Subscriber retains all ownership rights to the data they upload (Source Data) and the final output files generated.

---

## **7. Data Sovereignty and Security**

**7.1 UK Data Sovereignty**
All data processing, including all AI and LLM operations, takes place exclusively on servers hosted within the United Kingdom (UK Data Centres). This is maintained to support the Subscriber's need for data residency and compliance with UK GDPR regulations.

**7.2 Security Measures**
The Processor implements robust, commercially reasonable security measures, including end-to-end encryption (HTTPS) for data transmission, and physical and logical access controls within the UK data centres to protect Subscriber data against unauthorized access, alteration, or disclosure.

---

## **8. Limitation of Liability**

In no event shall the Processor be liable for any indirect, incidental, special, punitive, or consequential damages arising out of or in connection with the use or inability to use the Service, EXCEPT as provided in the following paragraph.

The total liability of the Processor for any claim shall not exceed the total fees paid by the Subscriber in the twelve (12) months preceding the claim.

Nothing in this agreement limits liability for data protection violations, fraud, or breaches of confidentiality.

The Subscriber must explicitly confirm and warrant that they have a lawful basis under applicable data protection laws, including the GDPR, for processing any special category data provided to the Processor under this Agreement.

The Processor shall implement enhanced technical and organisational security measures appropriate to the sensitivity and risk associated with processing special category data, in order to protect it against unauthorised or unlawful processing and accidental loss, destruction, or damage.

The Parties acknowledge and agree that the processing of special category data carries heightened legal obligations and risks. The Processor will not be held liable for any unauthorised processing arising from the Controller's failure to provide a lawful basis or appropriate instructions for such data.

---

## **9. Governing Law**

These Terms are governed by the laws of **England and Wales**, without regard to its conflict of law principles.

---

## **10. Termination**

The Service may be terminated by either party with notice as described in the Subscriber's specific service agreement or subscription terms. Upon termination, the Subscriber's access will cease, and data deletion policies as defined in the Data Processing Agreement (Part C) will apply.

---

## **Contact Information**

For any inquiries or concerns regarding these Terms & Conditions, please contact:

**Email:** compliance@nearfield.ai

**Nearfield.ai Ltd**
44 Queens Drive, Stockport, SK4 3JW
