Terms of Service
These Terms govern access to and use of the AfriGRC platform. They're written to be read, not just filed — the sections below cover what you can expect from us, what we expect from you, and where a specific commercial or legal detail is still being finalized.
- Last Updated
- August 5, 2026
- Effective Date
- To be confirmed upon legal review
- Version
- 0.1 (Draft)
This page is a working draft of our Terms of Service, published for transparency ahead of formal legal review. It does not constitute legal advice, and should not be treated as a final, legally approved, or binding agreement until AfriGRC confirms it has completed that review.
The plain-language version.
A brief overview — the full detail follows in each section below.
Purpose
These Terms govern access to and use of the AfriGRC platform and related Services.
Who These Terms Apply To
Any individual or organization that creates an Account or otherwise uses the Services.
Customer Responsibilities
Keeping credentials secure, using the Services lawfully, and managing your own authorized Users.
AfriGRC Responsibilities
Operating, securing, and supporting the Services in line with the commitments described below.
Key Limitations
Sections like Limitation of Liability and Disclaimers scope what AfriGRC can and can't be held responsible for.
Support Channels
How to reach our Legal, Commercial, Support, and Privacy teams — see Contact Information below.
For Enterprise Legal & Procurement Teams
Reviewing this agreement for a procurement process? These are the sections reviewed most often.
Terms used throughout this agreement.
- Account
- The registration record created to access the Services, whether by an individual User or on behalf of an Organisation.
- Organisation
- The legal entity that has entered into an agreement with AfriGRC and on whose behalf the Services are used.
- Customer
- The Organisation identified in an order form or agreement with AfriGRC, or an individual using the Services under their own Account.
- Platform
- The AfriGRC software application, including its web interface, APIs, and AI Features.
- Subscription
- The plan and term under which a Customer is licensed to access the Services.
- Services
- The Platform and any related support, onboarding, or professional services AfriGRC makes available.
- Confidential Information
- Non-public information disclosed by either party that is designated confidential or would reasonably be understood as such.
- Content
- Any data, records, documents, or other material a Customer or User submits to, or generates within, the Platform.
- User
- An individual authorized by a Customer to access the Services under that Customer's Account.
- Administrator
- A User granted elevated permissions to manage an Organisation's Account, Users, and configuration.
- API
- Any application programming interface AfriGRC makes available for programmatic access to the Services.
- AI Features
- Functionality within the Services that uses machine learning or artificial intelligence, such as the AI Copilot.
- Enterprise Services
- Additional services made available to Customers on enterprise plans, such as dedicated onboarding or premium support.
How these Terms are accepted.
By creating an Account, or by using the Services under an Organisation's Subscription, you confirm that you have the authority to accept these Terms on your own behalf or on behalf of that Organisation.
For Enterprise Customers, the specific order form or master agreement signed with AfriGRC governs where its terms differ from this page; the organisation-specific acceptance workflow (such as a click-to-accept step at signup) is still being finalized and will be described here once confirmed.
Creating and managing an Account.
Account Responsibilities
You are responsible for the accuracy of information provided when creating an Account, and for keeping it current.
Authentication
Accounts are protected by the authentication mechanisms the Platform makes available, including multi-factor authentication where enabled.
Account Security
You are responsible for maintaining the confidentiality of your credentials and for all activity under your Account.
Organisation Administration
An Organisation's Administrators are responsible for managing which Users have access, and at what permission level.
Multiple Users
An Organisation may authorize multiple Users under a single Subscription, subject to the terms of its agreement.
Enterprise Tenants
Enterprise Customers may be provisioned as a dedicated tenant, with configuration specific to that Organisation.
Commercial terms, by category.
Architecture only — specific commercial policies are set out in an order form or agreement, not invented here.
Subscription Plans
Plan tiers and included entitlements, as set out in an order form or agreement.
Set Per Agreement
Renewals
Whether and how a Subscription renews at the end of its term.
Set Per Agreement
Billing
Billing frequency and payment methods accepted.
Set Per Agreement
Invoices
How invoices are issued and delivered.
Set Per Agreement
Taxes
Responsibility for applicable taxes, levies, and duties.
Set Per Agreement
Cancellation
How a Customer may cancel a Subscription, and any required notice period.
Set Per Agreement
Refunds
Circumstances, if any, under which a refund may be issued.
Set Per Agreement
What's required, monitored, and prohibited.
- Required
Lawful Use
The Services must be used in compliance with all applicable laws and regulations.
- Required
Security
Users must not attempt to bypass, disable, or interfere with the Platform's security controls.
- Monitored
Abuse Prevention
Activity is monitored for patterns consistent with abuse of the Services or other Users.
- Prohibited
Misuse
Using the Services to store or transmit unlawful content, or to harm AfriGRC, other Customers, or third parties, is prohibited.
- Monitored
API Usage
API access is subject to rate limits and usage policies to protect Platform stability for all Customers.
- Monitored
Automated Access
Automated or scripted access outside the documented API is monitored and may be restricted.
- Required
Responsible AI Usage
AI Features must be used with appropriate human review — see AI Features below.
What we ask of you.
Maintaining Credentials
Keeping Account credentials confidential and promptly reporting any suspected unauthorized access.
Providing Accurate Information
Ensuring Account and billing information provided to AfriGRC remains accurate and current.
Compliance With Laws
Using the Services in a manner that complies with the laws applicable to your Organisation.
Managing Authorised Users
Adding, removing, and setting the permissions of Users authorized under your Account.
Data Ownership
You retain ownership of the Content you submit to the Platform — see Intellectual Property below.
What you can expect from us.
Platform Availability
We operate the Platform with the aim of consistent availability — see Availability & Maintenance and Service Levels below for how this is currently scoped.
Security
Maintaining the security measures described in our Trust Centre and referenced in our Privacy Policy.
Support
Providing support channels appropriate to your Subscription tier.
Continuous Improvement
Ongoing investment in the reliability, security, and functionality of the Platform.
Responsible Development
Building new functionality, including AI Features, to the same standard described in our Trust Centre.
Who owns what.
Software
AfriGRC and its licensors retain all rights in the Platform's underlying software.
Documentation
Product documentation and help content remain AfriGRC's intellectual property, licensed for your use of the Services.
Brand Assets
The AfriGRC name, logo, and brand assets may not be used without prior written permission.
User Content
Content you submit remains yours; you grant AfriGRC the license needed to operate the Services on your behalf.
Customer Data
Customer Data is owned by the Customer — see Data Protection below and our Privacy Policy.
Feedback
Feedback you voluntarily provide about the Services may be used by AfriGRC to improve the Platform.
Protecting what either party shares in confidence.
Each party agrees to use the other's Confidential Information only as needed to perform under these Terms, and to protect it with at least the same care it uses to protect its own confidential information of a similar kind.
These obligations do not apply to information that is independently developed, rightfully received from a third party, or required to be disclosed by law — in which case the disclosing party will, where legally permitted, give notice before disclosure.
Governed by our Privacy Policy, not restated here.
AfriGRC's collection, use, and protection of personal data is described in full in our Privacy Policy, which forms part of these Terms by reference. The security measures referenced there are described in more detail in our Security & Trust Centre.
Where a Customer's agreement requires a separate Data Processing Agreement, that document — not this page — governs the specific terms of AfriGRC's processing of Customer Data as a Processor.
Keeping the Platform running, and telling you when it won't be.
AfriGRC performs scheduled maintenance from time to time to keep the Platform secure and reliable, and will provide advance notice for maintenance expected to affect availability where practical to do so.
Unexpected outages can still occur. Except where a specific availability commitment is set out in a signed agreement — see Service Levels below — AfriGRC does not guarantee uninterrupted availability of the Services.
Enterprise SLA-ready, not yet contractually committed.
This architecture is ready to hold real commitments the moment they're agreed — none are promised here in the meantime.
Response Times
Time to first response after a support request is submitted.
Future Contractual Content
Resolution Targets
Target time to resolve an issue once acknowledged.
Future Contractual Content
Availability Commitments
A committed Platform availability percentage, where contractually agreed.
Future Contractual Content
Support Tiers
Support channels and response commitments by Subscription tier.
Future Contractual Content
AI-assisted, always reviewable.
Consistent with our Trust Centre's Responsible AI section.
Responsible AI
AI Features are built to the same evidence-cites-itself standard described in our Trust Centre's Responsible AI section.
Human Oversight
AI Features are designed to support, not replace, human judgment on decisions that matter.
AI-Assisted Functionality
Where AI Features generate a suggestion, summary, or draft, this is clearly presented as AI-assisted output.
Limitations of AI Outputs
AI Features can be incomplete or incorrect. They do not constitute legal, compliance, or professional advice.
Customer Review Responsibilities
You are responsible for reviewing AI-assisted output before relying on it for a compliance or business decision.
What we don't guarantee.
The Services are provided on an "as-is" and "as-available" basis, except as expressly stated in a signed agreement with AfriGRC.
AfriGRC disclaims all warranties not expressly stated in a signed agreement, to the extent permitted by applicable law.
Use of the Services does not guarantee any specific compliance, audit, or regulatory outcome — the Platform supports your governance program; it does not replace professional judgment.
Placeholder architecture — not yet drafted legal language.
This section will set out the limits on each party's liability to the other under these Terms — typically including exclusions for indirect or consequential loss, and a cap tied to fees paid. That specific language has not yet been drafted or reviewed by counsel, and is intentionally not fabricated here.
See Disclaimers above for the general disclaimers currently in effect.
Placeholder architecture — not yet drafted legal language.
This section will describe each party's obligation to defend and indemnify the other against specific categories of third-party claims — for example, a claim that the Platform infringes a third party's intellectual property rights. Specific indemnification language is pending legal review and is not fabricated here.
How an agreement ends.
Termination
Either party may terminate an agreement in accordance with the terms set out in that agreement.
Suspension
AfriGRC may suspend access to the Services in cases such as a security risk or a material breach of these Terms.
Account Closure
Upon termination, Account access ends in accordance with the notice terms of the applicable agreement.
Responsibilities After Termination
Obligations that by their nature survive termination — such as confidentiality and payment for Services already rendered — continue to apply.
Every revision, in one place.
- Establishes the page structure: Plain Language Summary, Definitions, and the sections that follow.
- Subscriptions & Billing, Service Levels, Limitation of Liability, and Indemnification are placeholder architecture pending legal and commercial review.
Version comparison isn't available yet
Only one version of these Terms has been published so far. This tool will let you compare revisions side by side once a second one exists.
Jurisdiction — to be confirmed.
The governing law and dispute resolution forum for these Terms have not yet been finalized. This section will name the specific jurisdiction and process once confirmed as part of formal legal review — no jurisdiction should be assumed from the absence of one stated here.
Questions about these Terms.
Questions about this agreement?
Reach our Legal team directly, talk to Sales, or explore the security architecture behind the platform.