GuardVett Terms of Service
Website preview. The wording has been approved for implementation. Factual publication checks remain in progress; this preview does not change existing agreements.
On this page
- 1 The parties and the agreement
- 2 The service and its limits
- 3 Accounts and authorised users
- 4 Screening information and lawful instructions
- 5 AI and document recognition
- 6 Communications and integrations
- 7 Trials and pilot arrangements
- 8 Charges and billing
- 9 Cancellation and refunds
- 10 Acceptable use
- 11 Availability and support
- 12 Ownership and confidentiality
- 13 Suspension
- 14 Ending the agreement
- 15 Data return and deletion
- 16 Responsibility and liability
- 17 Events beyond reasonable control
- 18 Changes and notices
- 19 General provisions
1 The parties and the agreement
GuardVett is supplied by ISO Consultants U.K. Limited, registered in England and Wales under company number 10766230, whose registered office is Lewis Building, 35 Bull Street, Birmingham, England, B4 6AF (“ICUK”, “we” or “us”). Contact us at sales@guardvett.com.
The “Customer” or “you” is the organisation, partnership or sole trader subscribing for business purposes. The person accepting confirms that they have authority to bind the Customer. Candidates and referees do not become paying Customers merely by using a portal or replying to a request.
The agreement consists of the order or checkout details expressly accepted by the Customer, these Terms and the applicable GuardVett Data Processing Agreement (“DPA”). It takes effect when we accept your order or make the ordered service available following your express acceptance. Merely reading a website does not create a subscription. We will make the applicable terms and order details available to you.
The DPA prevails for personal-data processing. A signed order may vary these Terms where it expressly identifies the variation. Otherwise these Terms prevail over conflicting general order wording. The Privacy Notice explains processing; it does not authorise wider processing than the DPA. Existing customers are not retrospectively bound by a new version they have not validly accepted.
2 The service and its limits
GuardVett helps you maintain screening records, manage evidence and references, track tasks and dates, record human decisions and produce exports or audit material. Features and usage allowances depend on your selected plan and any written order.
The service supports your screening and compliance processes. It does not itself conduct every underlying identity, right-to-work, DBS, SIA, financial or employment check, and it is not a certification, legal opinion or guarantee of conformity with BS 7858 or any other requirement. You remain responsible for completing the necessary checks, obtaining current authoritative results, interpreting applicable obligations and making employment and deployment decisions.
An AI finding, completed workflow or generated report does not establish that a person is suitable or that your organisation complies with every requirement. We will provide the service with reasonable care and skill. Nothing in this section excuses a failure to meet our express contractual obligations.
3 Accounts and authorised users
You must provide accurate organisational and billing details, appoint suitable administrators, grant only necessary access, and promptly remove access when it is no longer authorised. Each person must use their own account and keep credentials and recovery methods secure. You must use the authentication controls required by the service and notify us promptly of suspected compromise.
You are responsible for your authorised users’ use of the service and instructions, subject to our own responsibility for service security and performance. You must not share accounts to avoid user limits, misrepresent authority, access another customer’s information or bypass access controls.
4 Screening information and lawful instructions
You retain control of your screening information and are responsible for its lawful collection, accuracy, relevance, notices and disclosure. You must identify a lawful basis and any additional condition needed for special category or criminal offence data, and maintain any required policy document. Do not upload excessive information simply because a document is available.
You must comply with applicable employment, equality, screening, confidentiality and data-protection requirements. Use sensitive features, including health questionnaires and criminal-record evidence, only where appropriate and lawful. Configure retention for the particular records and purpose, rather than assuming a default is a legal requirement.
You authorise us to process Customer information only as necessary to deliver the agreed service, meet the DPA and follow lawful documented instructions. If an instruction appears unlawful, we will inform you and may pause the affected processing while it is resolved. The DPA governs confidentiality, security, assistance, audits, subprocessors, transfers and personal-data breaches.
5 AI and document recognition
Document recognition and AI features may extract text, suggest structured information, detect possible inconsistencies and assist review. They can make mistakes, omit content or misunderstand context. Your authorised reviewers must verify outputs against reliable evidence before relying on them, and personally make any required attestation or decision.
The service must not be used to delegate an employment or other significant decision solely to AI without the legal basis and safeguards required by law. Our agreed service is designed to support human review, not replace it. The Subprocessor Register explains the providers and relevant data routes. The DPA does not authorise training general-purpose models on Customer screening information.
6 Communications and integrations
You are responsible for the authority, content and recipients of screening requests sent in your name, including delegated email-domain configuration. Do not use reference or candidate messaging for unsolicited marketing. Delivery depends on recipient systems and third-party providers; a scheduled request is not proof of delivery or a completed reference.
Third-party services may have separate terms and availability limits. We remain responsible for our suppliers to the extent required by this agreement and the DPA. You are responsible for integrations you independently choose and for safely handling any information exported to them.
7 Trials and pilot arrangements
Trial duration, limits and any subsequent charge must be clearly stated in the order or checkout. A trial does not authorise an undisclosed payment. A trial converts to a paid subscription only on the billing terms you expressly accept.
A pilot or design-partner arrangement applies only as agreed in writing. We will not retrospectively charge for an agreed free pilot. Any transition to paid service requires notice of the price, date and applicable terms and the Customer’s agreement.
8 Charges and billing
Charges, currency, billing frequency and included allowances are those shown in the accepted order or checkout. VAT and other applicable taxes will be identified as required. Recurring subscriptions renew for the stated billing period unless cancelled under clause 9. You authorise the selected payment method for the agreed recurring charges.
Unless the order states otherwise, invoice payments are due within 14 days of issue. Tell us promptly about a disputed charge, explaining the reason; pay any undisputed amount when due. We will investigate in good faith. We may restrict new work for overdue undisputed charges after giving notice and a reasonable opportunity to remedy the failure. We will not treat non-payment alone as an instruction to erase your screening records.
Plan changes and extra usage charges require disclosure of the resulting charges before commitment. A price increase takes effect at a renewal, after at least 30 days’ notice, and you may cancel before that renewal. We do not apply price increases retrospectively.
9 Cancellation and refunds
You may cancel renewal through the billing controls where available, or by emailing sales@guardvett.com from an authorised account. Cancellation takes effect at the end of the current paid period unless we agree otherwise. We will confirm receipt and the effective date. Cancel before the renewal is processed to avoid the next period’s charge.
Unless the order provides otherwise, fees for an already-started subscription period are not refundable solely because you stop using the service. This does not affect a refund expressly provided by these Terms, correction of a billing error, or any right that cannot lawfully be excluded. Clause 15 governs data return and deletion after termination.
10 Acceptable use
You must not use GuardVett unlawfully, upload malicious content, impersonate another person, disclose information without authority, harass recipients, interfere with other customers or attempt to circumvent security or usage limits. Do not resell the service or use it to build a competing service by copying protected material, except with our written agreement or where a restriction is prohibited by law.
Responsible reporting of a suspected vulnerability is welcome at sales@guardvett.com. Testing must not involve accessing another customer’s data, disrupting service or exceeding agreed authority.
11 Availability and support
We will use reasonable efforts to keep the service available, maintain it and resolve reported faults. Planned maintenance, urgent security work and third-party outages can interrupt access. We will give reasonable notice of planned material interruption where practicable.
Support requests can be sent to sales@guardvett.com. A guaranteed response time, uptime commitment or service-credit scheme applies only if set out in your order. Do not rely on the service as your sole emergency alert channel or as a replacement for required organisational supervision.
We may improve or change the service. We will give reasonable notice of a material reduction in core paid functionality. If such a reduction materially prevents your agreed use and we cannot reasonably resolve it, you may terminate the affected service and receive a proportionate refund of prepaid charges for its unused period.
12 Ownership and confidentiality
You retain your rights in Customer information and documents. You grant us the limited rights needed to host, process, transmit and return them in providing the service under this agreement. We retain our rights in GuardVett software, documentation and underlying technology. During the subscription we permit your authorised users to use the service for your internal business purposes within the agreed plan.
Each party must protect the other’s confidential information using reasonable care and disclose it only to people who need it for the agreement and are subject to suitable duties. This does not cover information lawfully public, independently developed or lawfully received without restriction. Legally required disclosure is permitted, with prior notice where lawful. Confidentiality duties continue after termination for as long as the information remains confidential; the DPA separately governs personal data.
13 Suspension
We may suspend affected access or processing where reasonably necessary to address a material security risk, unlawful instruction, serious misuse, material breach or overdue undisputed payment. We will make the suspension proportionate, explain it and give an opportunity to remedy where practicable. Urgent action may be necessary before notice.
Where lawful and technically safe, we will preserve access to existing records or provide an alternative means of obtaining an export. We will restore service when the reason is resolved. Suspension is not itself deletion or termination, and does not remove our obligations to protect and return information.
14 Ending the agreement
Either party may terminate for a material breach that remains unremedied 14 days after written notice identifying the breach and required remedy, or immediately if the breach cannot reasonably be remedied. Either may terminate where continued performance is unlawful. Insolvency-related termination is subject to applicable restrictions.
We may end a recurring service without cause at the end of a paid period on at least 30 days’ notice and will refund prepaid charges relating to any period we do not supply. If you terminate for our unremedied material breach, we will refund prepaid charges for the unused affected period. Accrued payment rights remain, subject to applicable rights and remedies.
15 Data return and deletion
You may export available Customer information during the subscription. On termination, we will give you a 30-day opportunity to request return or deletion, unless you instruct earlier deletion or the law requires a different approach. We will provide the standard available export without an additional exit fee and agree any separately requested bespoke work in advance.
Your choice under the DPA governs return or deletion of screening information. If you give no instruction during that opportunity, we will contact your nominated administrator and agree the next step; silence does not permit indefinite retention. We will document and communicate the applicable deletion schedule, including backup expiry and any lawful retention exception. Information retained solely for a legal requirement will be restricted to that purpose and deleted when the requirement ends.
We will not withhold a return required by the DPA solely because a fee is disputed. You are responsible for downloading and protecting exports and arranging any onward migration.
16 Responsibility and liability
Nothing in this agreement excludes or limits liability for death or personal injury caused by negligence, fraud or fraudulent misrepresentation, or any liability which cannot lawfully be excluded or limited. Nothing limits an individual’s statutory data-protection rights or a regulator’s powers.
Subject to the preceding paragraph, each party’s total liability arising from this agreement in any 12-month period is limited to the greater of £1,000 and the charges paid or payable for the service in that period. For breach of confidentiality or data-protection obligations, a higher aggregate limit applies instead: the greater of £10,000 and twice those charges. A loss falls under one applicable limit, not both; connected claims are treated consistently in the period of the first event giving rise to them. These limits apply across contract, tort including negligence, and other legal grounds.
Subject to the first paragraph, neither party is liable for indirect or consequential loss. Reasonable direct costs of investigating a breach, restoring data or obtaining a required replacement service are not excluded merely by calling them consequential. You remain responsible for agreed subscription charges. Each party must take reasonable steps to reduce loss.
17 Events beyond reasonable control
A party is not responsible for delay caused by an event beyond its reasonable control, to the extent it could not reasonably prevent or mitigate the event. It must notify the other party and take reasonable steps to restore performance. This does not excuse payment already due, confidentiality, data protection or failure to take reasonable resilience measures. If material interruption continues for more than 30 days, either party may end the affected service, with a refund for prepaid service not supplied.
18 Changes and notices
We will give at least 30 days’ notice of a material change to these Terms and explain its effect and proposed start date. Urgent changes necessary for law or security may take effect sooner, with notice as soon as practicable. A change cannot retrospectively remove accrued rights. Where a material adverse change is not legally required, you may end the affected subscription before it takes effect and receive a proportionate refund for the unused prepaid period.
Changes to data-processing instructions, subprocessors and the DPA follow its separate notice and acceptance provisions. Contractual notices must be sent to the nominated account contact or to sales@guardvett.com. Keep that contact current. An undeliverable email is not reliable evidence that notice was received.
19 General provisions
The agreement is governed by the law of England and Wales and the courts of England and Wales have exclusive jurisdiction, subject to any mandatory law. A person who is not a party has no contractual enforcement right under the Contracts (Rights of Third Parties) Act 1999; this does not affect statutory personal-data rights.
Neither party may transfer the agreement without the other’s consent, not to be unreasonably withheld, except as part of a genuine business reorganisation or sale where obligations and protections are preserved and notice is given. No transfer authorises otherwise unlawful processing. Neither party is the other’s agent or partner. If a provision is unenforceable, the remainder continues. A failure to enforce a right immediately is not a waiver. This agreement records the agreed service terms without excluding liability for fraud or any mandatory right.