Legal · draft
Terms of Service
Document id: tos
Draft version: tos.draft-0
Published version string: [COUNSEL: set on sign-off — this exact string is stored against every customer's consent record by apps/api/consent.pyand served byGET /v1/public/meta. Once a version is published it may never be reused for different wording.]
Effective from: [COUNSEL: set on sign-off]
Language: English. [COUNSEL: confirm whether a Kiswahili version must be published alongside, and which language governs if the two differ. The service delivers reports in Kiswahili on request, so a customer may reasonably expect the terms in Kiswahili too.]
1. Who you are contracting with
These Terms are an agreement between:
- {{LEGAL_ENTITY}}, a company incorporated in Kenya, of {{POSTAL_ADDRESS}}, trading as Reconesys (“Reconesys”, “we”, “us”, “our”); registered with the Office of the Data Protection Commissioner under {{ODPC_NUMBER}}; contactable at {{CONTACT_EMAIL}} and {{PHONE}}; and
- you, the business on whose behalf you request or receive our services (“you”, “your”, “Customer”).
Our website is {{SITE_ORIGIN}} (the “Site”).
[COUNSEL: confirm the correct description of the legal entity — company limited by shares, business name, or partnership — and whether the ODPC registration number may be published in the Terms before the certificate is in hand. Until the certificate is issued, no wording anywhere may state or imply that registration is complete.]
2. What these Terms cover, and when they apply
These Terms apply when you:
- submit the intake form on the Site to request a Free Exposure Snapshot;
- receive a report or any other written output from us; or
- buy any paid service from us, unless we have signed a separate written agreement with you, in which case that agreement takes precedence over these Terms to the extent of any conflict.
By submitting the intake form you confirm that you have read and accept these Terms. We record which version of these Terms was in force when you submitted, together with the exact wording of each statement you confirmed and the time you confirmed it.
3. What the service actually is
This section is the most important one in this document. Read it before anything else.
3.1 The Free Exposure Snapshot
When you submit a domain and a work email address:
- A person at Reconesys reads public records about that domain. The records are: public DNS records; the mail posture those records describe (SPF, DKIM, DMARC, MX); public certificate transparency logs, which are held by third parties and not by you; and the public domain registry entry (RDAP), which is held by the registry and not by you.
- That person writes a report in plain language, with a rating, the issues we consider most important, and suggested next steps.
- That person emails the report to you, normally within one to two business days. This is a target, not a commitment — see clause 3.5.
The Site also offers an optional password check. That check runs entirely inside your own web
browser. Neither the password nor its full fingerprint reaches us or is capable of reaching us;
there is no page on the Site that accepts a password. See data-processing-note.md and
privacy-policy.md for exactly how it works and what the third-party breach index can see.
3.2 What the service is not
The Free Exposure Snapshot is not a penetration test, a security audit, or a vulnerability scan. We read public records — DNS, mail records, certificate transparency logs and the domain registry. We never connect to your website or servers, never log in, and never test your defences. We do not probe ports.
One honest qualification, because the absolute version of that sentence would be false. Reading
DNS means asking whichever name servers are authoritative for your domain, and those may be machines
you or your provider run. We will not claim that no request of ours ever reaches anything of yours.
What we do say precisely is that the only contact is a public DNS lookup of the same kind every mail
server on the internet makes to find you, and that nothing we do opens a connection to your website,
your ports or your applications. data-processing-note.md sets out the boundary query by query.
We also do not, on the free tier, provide:
- monitoring of any kind, continuous or periodic;
- alerting, notifications of change, or breach notification;
- incident response, or any commitment to respond within a stated time;
- certification, accreditation, or a statement that you comply with any law.
We are not a law firm and nothing we provide is legal advice. We are not an insurer and nothing we provide is insurance or a warranty against loss.
3.3 What the report is, honestly
A report is one person’s professional reading of what public records showed on one day. It is evidence that you looked, and a description of what was visible from outside. It is not proof that your business is secure, and it cannot be. Records change, and our view is partial by design.
The report will state what we looked at, what we could not look at, and how confident we are. A free snapshot is never rated as high confidence, because it rests on external evidence only.
3.4 Compliance is yours, not ours
Nothing we supply makes your business compliant with the Data Protection Act 2019, the Data Protection (General) Regulations 2021, the Digital Health Act 2023, or any other law. Compliance covers how you collect personal data, what you tell people, how you store it, who you share it with, your contracts with suppliers, your staff training and much more.
What our report can give you is documented evidence relating to one technical control — that you reviewed your external exposure on a given date, and what you did about it. That is a real and useful piece of a compliance record. It is not the whole record, and we do not sell it as one.
[COUNSEL: confirm this disclaimer is drafted strongly enough to defeat a later claim that we held ourselves out as compliance advisers, and whether any Kenyan rule on holding out as a consultant or adviser applies here.]
3.5 Timing
Our target for a free snapshot is one to two business days from the point at which we begin. Because a person reviews every report, weekends, public holidays and demand can push it out. If it is going to take materially longer we will tell you.
This target is not a service level and carries no remedy. We do not offer an SLA on any service described in these Terms.
[COUNSEL: confirm that stating a delivery target in this way does not create an enforceable term under Kenyan contract or consumer law, and advise whether the Consumer Protection Act 2012 applies to any of our customers — a sole trader or a very small business may be treated as a consumer, which would restrict several exclusions in clauses 9 and 10.]
3.6 Paid services
Paid services (for example fix sprints, deeper assessments, and managed services) are agreed separately in writing, with their own scope, price and delivery terms. Prices shown on the Site are in US dollars with an indicative Kenyan shilling equivalent; you are billed in shillings, and the shilling figure moves with the exchange rate.
At launch we invoice; there is no online checkout. Payment terms, taxes and any late-payment charge are set out on the invoice or in the separate written agreement.
[COUNSEL: set payment terms, the late-payment position, and the VAT treatment of these services. Confirm whether VAT applies to the free tier (we take the view it does not, as no consideration passes) and how digital-services tax rules apply if any customer is outside Kenya.]
4. Eligibility
You may use our services only if:
- you are using them for the purposes of a business, trade, or profession, and not as a consumer;
- you are at least 18 years old; and
- you have authority to accept these Terms on behalf of that business.
Our services are directed at businesses in Kenya. [COUNSEL: confirm whether we should refuse or restrict customers outside Kenya, given that governing law, the ODPC complaint route and the Cybercrimes Act analysis in clause 5 are all Kenyan. Our current view is to accept them but say plainly that the terms and our legal analysis are Kenyan.]
5. Your authorisation warranty — the clause that makes this lawful
This clause is not a formality. It is the basis on which we are willing to look at a domain at all.
5.1 What you warrant
Each time you request an assessment of a domain, you warrant to us that:
- the domain is owned or controlled by the business you represent;
- you are authorised by that business to request an assessment of that domain and to receive the resulting report; and
- nobody has told you that such a request would breach any agreement, policy or instruction binding on you or on that business.
You confirm points 1 and 2 explicitly on the intake form. We store that confirmation with the exact wording you were shown and the time you gave it, so that both of us have the same record. If we are ever asked who authorised an assessment, that record is the whole answer.
5.2 What you must not do
You must not request an assessment of a domain you do not own or control. This includes a competitor’s domain, a supplier’s domain, a customer’s domain, a former employer’s domain, or a domain you are merely curious about.
Assessing a third party’s domain can be a legitimate business need — supplier due diligence, for example. We can help with that, but only with the third party’s written agreement, arranged in advance. Contact us at {{CONTACT_EMAIL}}.
5.3 Why we insist
Kenya’s Computer Misuse and Cybercrimes Act 2018 (as amended in 2025) treats reading published
information differently from touching somebody else’s system. Kenya has no responsible-disclosure
safe harbour, and systems that may be designated critical information infrastructure — hospitals and
payment systems among them — carry the heaviest penalties. [COUNSEL: verify the current penalty figures and section numbers; our working figures are up to KES 25,000,000 and up to 20 years for offences involving protected computer systems, and we do not want to publish a figure we cannot cite.]
We therefore design the free tier so that a false warranty by you cannot cause us to touch anybody’s systems: on an unverified domain we read public records only, and our software has no mode in which a free snapshot does anything else. Your warranty still matters, because a report about somebody’s domain in the wrong hands is a harm in itself.
5.4 If your warranty turns out to be wrong
If you request an assessment of a domain you were not authorised to request, we may stop work immediately, refuse to deliver or withdraw the report, decline future requests from you or your business, and record the domain as one we will not assess again without contacting its owner. You indemnify us as set out in clause 11.
6. Acceptable use
You must not:
- use our services other than for the lawful purposes of your own business;
- use a report, or anything we tell you, to attack, embarrass, or gain advantage over anybody, including a competitor;
- submit somebody else’s email address as the recipient of a report;
- submit deliberately false information, including a domain or business you have no connection to;
- attempt to overload, circumvent or reverse-engineer the Site or our intake system, including by automating submissions, evading rate limits, or bypassing the checks on the intake form;
- resell, sublicense or systematically redistribute our reports or other outputs, except as clause 8 allows;
- represent to anybody that a report from us is a penetration test, a security audit, a vulnerability scan, a certification, or a statement of compliance; or
- use our name, marks or reports in a way that implies we endorse, certify or have secured your business.
The free tier is limited to one snapshot per domain every 30 days, and is subject to rate limits
on submissions. [COUNSEL: confirm we may state and enforce these limits without a stated remedy, and whether any pre-notification is required before we suspend a free-tier user.]
7. Your responsibilities
- The information you give us must be accurate, particularly the domain and the email address a report will be sent to. We will send the report to the address you gave; if that address is wrong, or is a shared mailbox, or forwards elsewhere, that is outside our control.
- Acting on a report is your decision. We recommend; we do not instruct. Some fixes — changing DNS records, for example — can interrupt your email or your website if done carelessly. Make changes with someone who understands your systems, and keep a way back.
- You remain responsible for your own compliance obligations, including registration with the ODPC where it applies to you, breach notification, and your own security safeguards.
8. Intellectual property, and what you may do with a report
8.1 Ownership
We own the report and every other output we produce, including its structure, wording, rating method, templates and any software behind it. Nothing in these Terms transfers ownership of any of it to you.
You own your own data: your domain, your business information, and the underlying facts described in a report. Facts about your systems are yours; our description and assessment of them is ours.
8.2 What you may do with the report
We grant you a perpetual, worldwide, royalty-free, non-exclusive licence to use the report for your own business purposes, including to:
- read it, store it and act on it;
- share it in full with your own staff, your IT provider, your professional advisers, your insurer or broker, your auditor, and your bank;
- provide it to the Office of the Data Protection Commissioner or another regulator, or to a court, where you consider it relevant; and
- share it with a prospective customer or partner conducting due diligence on you.
Share it whole, not in extracts, and keep our name and the date on it. A finding taken out of the report loses the confidence statement and the coverage statement that qualify it, which is how an honest report becomes a misleading one.
You may not publish the report openly, sell it, or use it in your own marketing without our written agreement.
[COUNSEL: confirm this licence is wide enough for a regulated customer — a hospital may need to hand the report to the ODPC, to an accreditation body, or to a bank as a condition of financing — and that "share it whole" is enforceable rather than merely advisory.]
8.3 What we may do
We may keep a copy of every report we produce, and the evidence behind it, for the periods set out in
privacy-policy.md. We may use aggregated, anonymised patterns across many assessments to improve
our checks and to write general guidance.
We will not name you, identify you, or publish findings about you without your separate written agreement. The optional “case study” box on the intake form is a permission to ask you later; it is not permission to publish, and we will not publish anything about you without agreeing the specific words with you first.
8.4 Feedback
If you send us suggestions about our service, we may use them without obligation to you. This does not apply to anything you mark as confidential.
9. No warranty
We provide our services with reasonable care and skill, and we mean it — a person reads every report before it is sent, precisely so that what reaches you is worth reading.
Beyond that, and to the fullest extent Kenyan law permits:
- our services and reports are provided “as is”;
- we give no warranty that a report is complete, that it identifies every issue affecting you, that its conclusions are free from error, or that acting on it will prevent any incident;
- we give no warranty that public records were accurate, current or complete at the time we read them — we report what those records said, and we do not control them;
- we give no warranty that the Site will be available, uninterrupted or error-free; and
- we exclude all warranties, conditions and terms implied by statute or common law, to the extent they can lawfully be excluded.
A clean report is not a statement that you are safe. It is a statement about what was visible from outside on one day.
[COUNSEL: identify which terms cannot lawfully be excluded under the Sale of Goods Act, the Consumer Protection Act 2012, or the common law of Kenya for a business-to-business services contract, and redraft this clause so it does not over-reach. An unenforceable blanket exclusion is worse for us than a narrower one that holds.]
10. Limitation of liability
[COUNSEL: this whole clause needs your numbers and your judgement. Our commercial position is set out below so you can tell us what is defensible in Kenya. We would rather have a clause that survives a challenge than a maximal one that does not.]
10.1 What we never exclude
Nothing in these Terms limits or excludes our liability for:
- death or personal injury caused by our negligence;
- fraud or fraudulent misrepresentation;
- any liability that cannot lawfully be limited or excluded under Kenyan law, including our obligations under the Data Protection Act 2019 to the extent they cannot be contracted out of.
10.2 What we exclude
Subject to clause 10.1, we are not liable for:
- loss of profit, revenue, business, contracts, anticipated savings, goodwill or reputation;
- loss or corruption of data;
- business interruption or downtime;
- any loss arising from a security incident, breach, fraud or ransomware affecting you, whether or not the report mentioned the relevant issue;
- any loss arising from a change you or a third party made in response to a report; or
- any indirect or consequential loss of any kind,
in each case whether or not we were told such loss was possible.
10.3 The cap
Subject to clause 10.1, our total liability to you arising out of or in connection with these Terms and our services, whether in contract, tort (including negligence), breach of statutory duty or otherwise, is limited to:
[COUNSEL: set the cap.] Our proposal, for you to accept or replace:
| Service | Proposed cap | Reasoning |
|---|---|---|
| Free Exposure Snapshot | [COUNSEL: a fixed nominal sum — we suggest KES 10,000] | Nothing was paid. A cap of “the fees paid” would be zero, and a zero cap may be treated as no cap at all, or as unconscionable. A small fixed sum is more likely to hold. |
| Paid services | [COUNSEL: the greater of the fees paid in the preceding 12 months and a floor sum] | Standard, and proportionate to a business whose largest self-serve item is under KES 60,000. |
[COUNSEL: advise on (a) whether a per-claim or aggregate cap is preferable; (b) whether our professional indemnity cover, once arranged, should set the floor rather than the cap; and (c) whether a Kenyan court would enforce a cap this low against a hospital claiming a large loss. If the answer to (c) is no, we would rather know now and price insurance accordingly than discover it in a dispute.]
10.4 Time limit for claims
You must bring any claim under these Terms within [COUNSEL: set a period — we suggest 12 months]
of the date you became aware, or ought reasonably to have become aware, of the circumstances giving
rise to it. [COUNSEL: confirm whether the Limitation of Actions Act permits contracting to a shorter period than the statutory one, and if not, delete this clause rather than publish an unenforceable one.]
11. Your indemnity
You will indemnify us against any claim, loss, liability, cost or expense (including reasonable legal fees) arising from:
- a breach by you of the authorisation warranty in clause 5;
- your request for an assessment of a domain you did not own or control;
- your breach of clause 6 (acceptable use); or
- your use, republication or misrepresentation of a report in breach of clause 8.
[COUNSEL: confirm the scope, and whether it should be capped or subject to a duty to mitigate. An uncapped indemnity against a small business may be challenged; we care most about the clause 5 limb.]
12. Suspension and termination
12.1 By you
You may stop using our services at any time. For a paid subscription, tell us at {{CONTACT_EMAIL}};
cancellation takes effect at the end of the period you have paid for, and we do not pro-rate refunds
unless the separate written agreement says otherwise. [COUNSEL: confirm the refund position, and whether any cooling-off right applies.]
12.2 By us, on notice
We may stop providing free services to you, or decline a request, at any time and without giving a
reason. We may terminate a paid service on [COUNSEL: set a notice period — we suggest 30 days]
written notice, and will refund the unused portion of any prepaid fee.
12.3 By us, immediately
We may suspend or terminate your access immediately, without notice, if:
- you breach clause 5 (authorisation) or clause 6 (acceptable use);
- we reasonably believe your use is unlawful, or exposes us or a third party to legal risk;
- you fail to pay an invoice by its due date and do not put it right within
[COUNSEL: set a cure period — we suggest 14 days]of a written reminder; or - you become insolvent, or a step is taken towards your winding up or administration.
12.4 What survives
Clauses 5.4, 8, 9, 10, 11, 13, 14 and 15 survive termination, along with any clause which by its nature is intended to.
Termination does not by itself delete your data. What happens to your data, and how you ask us to
delete it, is in privacy-policy.md.
13. Confidentiality
Each of us will keep the other’s confidential information confidential, use it only for the purposes of these Terms, and protect it with at least reasonable care.
Findings about your business are your confidential information. We will not disclose them except: to our own staff and contractors who need them to do the work and who are bound by equivalent obligations; where you tell us to; or where we are required to by law or by a regulator.
One important exception, stated plainly: if we ever become aware of something with wider public consequences — a vulnerability affecting many businesses, or an active compromise with third-party impact — the route for that in Kenya is the national computer incident response team, KE-CIRT, and we may report it there. We will tell you first, and we will not name you publicly.
[COUNSEL: confirm this KE-CIRT carve-out is correctly framed, and whether any Kenyan law obliges us to report in circumstances the customer has not consented to. Also confirm whether we owe a notification duty to a customer's data subjects in any scenario, which we currently believe we do not, because we are a controller only of the lead data.]
14. Data protection
Each of us complies with the Data Protection Act 2019 and its regulations.
For the personal data you give us when you request a report — your work email address, and the other
items listed in privacy-policy.md — we are the data controller, and privacy-policy.md is our
notice to you under section 29 of that Act.
Our services do not normally involve us processing personal data on your behalf. If a paid engagement ever does, we will sign a written data processing agreement with you first, as the Act requires.
[COUNSEL: verify the section reference for the notice requirement, and confirm that a data processing agreement is genuinely not required for the free tier. Note that public records we read can contain personal data about people other than the customer — a domain registrant's contact details in the registry, for example — and advise how we should describe our basis for reading and reporting those.]
15. Governing law and disputes
15.1 Governing law
These Terms, and any dispute arising out of or in connection with them (including non-contractual disputes), are governed by the laws of Kenya.
15.2 Talk to us first
If something goes wrong, tell us at {{CONTACT_EMAIL}} and give us a fair chance to put it right. Most problems are a misunderstanding about what a report does and does not say, and those are quicker to fix in a conversation than anywhere else.
15.3 Formal dispute resolution
If we cannot resolve it between us within [COUNSEL: set a period — we suggest 30 days]:
[COUNSEL: choose the route and draft it. The options we understand to be available are (a) the courts of Kenya, with exclusive jurisdiction; (b) mediation, then the courts; or (c) arbitration by a single arbitrator under the Arbitration Act 1995, seat Nairobi, language English, appointed by the Nairobi Centre for International Arbitration failing agreement. Our preference is (b) — mediation first, then the courts of Kenya — because arbitration costs are heavy relative to our contract values and would in practice deny a small customer a remedy. Please advise whether that preference is sound and draft accordingly.]
Nothing in this clause prevents either of us from applying to a court for urgent injunctive relief.
16. Changes to these Terms
We may change these Terms. When we do:
- we publish the new version at {{SITE_ORIGIN}} with a new version identifier and the date it takes effect;
- for a change that materially affects you — a change to liability, to what the service is, to
price, or to how we handle your data — we give at least
[COUNSEL: set a notice period — we suggest 30 days]notice by email to the address we hold for you before it takes effect; - for a minor change (a correction, a clarification, a new contact detail) the change takes effect when published;
- if you do not accept a material change, you may stop using the service before it takes effect, and we will refund the unused portion of any prepaid fee.
The version in force when you submitted a request is the version that governs that request. We store the version identifier with your consent record so that both of us can look up which one it was.
[COUNSEL: confirm that the notice mechanism is adequate under Kenyan law, and whether we may treat continued use as acceptance. We would rather rely on notice plus a right to leave than on silence.]
17. General
- Whole agreement. These Terms, together with
privacy-policy.md,acceptable-use-and-authorisation.mdwhere it applies, and any separate signed agreement, are the whole agreement between us on their subject matter. Neither of us relies on any statement not written in them, except that nothing excludes liability for fraudulent misrepresentation. - No partnership. Nothing here creates a partnership, joint venture, agency or employment relationship.
- Assignment. You may not assign or transfer these Terms without our written consent. We may assign them to a successor to our business on written notice to you.
- No third-party rights.
[COUNSEL: confirm the position under Kenyan law — we intend that nobody other than you and us may enforce these Terms.] - Severability. If any provision is held unenforceable, the rest continues in force and the unenforceable provision is modified to the least extent needed to make it enforceable.
- No waiver. A delay in enforcing a right is not a waiver of it.
- Force majeure. Neither of us is liable for a failure caused by something genuinely outside our reasonable control, including a failure of a public network, a power grid, or a third-party record source we depend on.
- Notices. Notices to us go to {{CONTACT_EMAIL}}, copied to {{POSTAL_ADDRESS}}. Notices to you go to the email address you gave us.
Appendix A — The statements you confirm on the intake form
These are the exact statements the intake form asks you to confirm. Each is stored with its wording version and the time you confirmed it. If the wording on the form and the wording here ever differ, the form is what you agreed to, and this appendix is wrong and must be corrected.
| Key | Required | Statement |
|---|---|---|
service_delivery | Yes | Send me my report. I agree that Reconesys may use my email address and domain to prepare and send me this report, and to contact me about it. |
authorised_to_request | Yes | I am authorised to request an assessment of this domain on behalf of the business that owns it. |
not_a_pentest_understood | Yes | I understand this is not a penetration test. Reconesys will read only public records and will not connect to my systems unless I authorise it separately, in writing. |
marketing_contact | No | Send me occasional practical guidance on data protection and security in Kenya. No more than once a month, unsubscribe in one click. |
case_study_use | No | You may refer to our business as a case study if you ask us first and we agree in writing. |
Build note, not for publication. This table is a copy of
CONSENT_CATALOGUEinapps/api/consent.py, which is itself asserted equal to the rendered form bytests/api/test_consent_catalogue.py. If a sentence changes, its version string changes, the catalogue changes, and this table changes — all in the same commit.