These Terms of Service (“Terms“) state the terms and conditions governing your use of and access to the Inheriti® website and Services and constitute a legally binding contract between you and SafeTech BV, registered at Witte Patersstraat 4, 1040 Etterbeek, Belgium, VAT/company number BE 0704.931.167, and its affiliate companies (“SafeTech“, “Safe Haven Tech PTE.LTD.”, ”we“, “us“)
If you are an individual, you represent and warrant that you have reached the age of majority in the jurisdiction in which you reside, and are at least 18 years old.
If you are an individual accessing or using the Services on behalf of an organisation (an “Organisation”), you represent and warrant that you have the legal authority to bind that Organisation to these Terms. References to “you” and “your” refer to both the individual and any such Organisation.
If you do not accept these Terms, you must not access or use the Services.
SafeTech may modify these Terms at any time; the “Last updated” date at the top of this page will reflect the most recent revision. Continued use of the Services after a change constitutes acceptance of the revised Terms.
You must be at least 18 years old and have the legal capacity to enter into a binding contract in your jurisdiction to use the Services. We rely on your self-declaration and do not independently verify age.
Access to the Services begins with the creation of a SafeID account (“SafeID Account”). A SafeID Account is the common user account used to authenticate to SafeTech Services. Creating a SafeID Account does not by itself provide access to every Service, product, organisation, subscription, or program. The Services and features available to you may depend on the product you access, the organisation with which your SafeID Account is associated, any applicable subscription or entitlement, your approval for a particular program, and other applicable eligibility requirements.
A SafeID Account may be associated with an organisation where you create an organisation or accept an invitation to join one. A SafeID Account may also be granted access to Inheriti® Partners if you are approved to participate in the Inheriti® Reseller Program, or may be used to access the applicable consumer product. Creating or activating an Organisation Account also requires the separate confirmation described in Section 2.1, including acceptance of the Inheriti® Business Terms and the Organisation Data Processing Addendum.
Your account type remains a SafeID Account regardless of which Service or product you use. However, your permissions, available features, and access to product-specific information may change when you access a different Service, join or leave an organisation, obtain or lose a subscription or entitlement, or are approved for or removed from a program.
The Services and the materials available through the Inheriti® website are provided for informational and operational purposes and shall not be construed as a commercial offer, a license, or an advisory, fiduciary, or professional relationship between you and SafeTech, except as expressly set out in a Subscription Record or written agreement.
You agree not to: use the Services for any unlawful purpose; attempt to gain unauthorised access to the Services or other users’ data; reverse-engineer, decompile, or interfere with the Services’ security mechanisms; use the Services to store or transmit unlawful, infringing, or harmful content; or frame the Website or any similar process.
Links to third-party websites are provided for convenience only and do not imply approval or endorsement by SafeTech; SafeTech is not responsible for the content of any linked website.
The information provided through the Services may relate to products or features that are not available in your country and/or at all times. SafeTech will use reasonable efforts to keep the Services available but does not guarantee uninterrupted or error-free operation.
The Website and Services are protected by intellectual property rights and are the exclusive property of SafeTech. Any material they contain — including text, data, graphics, pictures, sounds, videos, logos, icons, or code — is protected under intellectual property law and remains the property of SafeTech or the relevant third party.
You may copy, download, and print materials from the Website for personal and non-commercial purposes only, without modification. Any other use without SafeTech’s prior written authorisation is prohibited. Inheriti® is a registered trademark of SafeTech. All other trademarks appearing on the Website are the property of their respective owners.
SafeTech grants you a limited, non-exclusive, non-transferable licence to use the Services in accordance with these Terms.
You warrant that any information, documents, or other material (“Material”), other than personal data, that you transmit to SafeTech through the Website (for example, via a contact form) does not infringe any intellectual property or other applicable law, and does not contain viruses or other harmful code. Such Material will be treated as non-confidential and non-proprietary, and by submitting it you grant SafeTech an unlimited, irrevocable licence to use, copy, and display it.
You retain ownership of the content you upload to a Protection Plan or otherwise store within the Services. Handling of personal data is governed by our Privacy Policy, not by this section.
SafeTech applies technical and organisational security measures appropriate to the sensitivity of the data processed by the Services. You are responsible for maintaining the security of the devices, accounts, credentials, recovery codes, hardware keys, and other physical or digital items that you or your Organisation control and that are used to access, authenticate, administer, or recover a Protection Plan.
You must take reasonable steps to prevent unauthorised access to those items and must promptly notify SafeTech of any actual or suspected loss, theft, compromise, or unauthorised use affecting your account or the Services.
Loss, destruction, compromise, or unavailability of a device, credential, recovery code, secret share, hardware key, or other recovery item under your or your Organisation’s control may prevent access to a Protection Plan and may result in the permanent and irrecoverable loss of access to protected content. SafeTech is not responsible for items, accounts, devices, infrastructure, or services that it does not control, except to the extent that liability cannot lawfully be excluded or limited.
The Services integrate with third-party providers (for example, for payments, identity, communications, and blockchain connectivity). Your use of these integrations may also be subject to that third party’s own terms. SafeTech is not responsible for the acts or omissions of independent third-party providers.
We may suspend or terminate your access to the Services, with or without notice, if we reasonably believe you have breached these Terms, engaged in fraudulent or unlawful activity, or where required by law. You may terminate your account at any time in accordance with the cancellation terms applicable to your product and plan.
The Services and all materials made available through them are provided “as is” and without warranty of any kind to the extent allowed by applicable law. SafeTech does not warrant that the Services are free of inaccuracies, errors, or omissions, or that their content is appropriate for your particular use or up to date, and reserves the right to change information at any time without notice. Use of the Services is at your own risk, and you must comply with all applicable laws, rules, and regulations.
This section applies only to the extent that you access or use a Service feature involving digital assets, crypto-assets, blockchain networks, smart contracts, digital wallets, tokenised items, or distributed validation infrastructure.
You acknowledge that:
You are responsible for confirming the destination, amount, network, wallet address, permissions, and other transaction details before approving or initiating a blockchain-related operation. You are also responsible for complying with applicable laws and for maintaining the security of your wallets, credentials, recovery codes, devices, and other items under your control.
The risks in this section apply only where relevant to the feature or Service you use and do not mean that every Inheriti® product involves crypto-assets, wallet custody, or blockchain transactions.
To the maximum extent permitted by applicable law, SafeTech will not be liable for damages of any kind, including indirect, consequential, or incidental damages, lost profits or revenues, business interruption, loss of goodwill, security breaches, or loss of data, arising out of or in connection with the use of, inability to use, or reliance on the Services, even if advised of the possibility of such losses.
Subject to the above, and to the maximum extent permitted by applicable law, SafeTech’s total liability arising out of or related to these Terms or the Services shall not exceed the amount you paid to SafeTech for the applicable Service in the twelve (12) months preceding the event giving rise to the claim.
Where appropriate to the relevant product and customer type, you agree to indemnify and hold harmless SafeTech, its officers, employees, and agents from any claims, damages, liabilities, and expenses (including reasonable legal fees) arising from your breach of these Terms, your misuse of the Services, or your violation of any law or third-party right.
SafeTech may modify, add, remove, or discontinue features of the Services, and may update these Terms, at its discretion. Material changes will be notified as described in the applicable product section (see, for example, the Business Subscription Terms’ “Notice of Changes”). Continued use of the Services after a change takes effect constitutes acceptance of that change.
Any controversy or claim arising out of or related to these Terms shall be governed by the laws of Belgium, without regard to conflict-of-law principles. Subject to any mandatory consumer-protection rules of your country of residence that may entitle you to bring proceedings in your local courts, the courts of Brussels, Belgium shall have exclusive jurisdiction.
If any provision of these Terms is held invalid, illegal, or unenforceable, that shall not affect the validity of the remaining provisions.
SafeTech’s failure to exercise, or delay in exercising, a right or remedy under these Terms shall not constitute a waiver of that right. A waiver of one breach shall not operate as a waiver of a subsequent breach.
You may not assign or transfer your rights or obligations under these Terms without SafeTech’s prior written consent. SafeTech may assign these Terms in connection with a merger, acquisition, or sale of assets.
These Terms — including the Inheriti® Business Terms and, where applicable, the Organisation Data Processing Addendum in Section 2.7 — together with any order form, Subscription Record, or enterprise agreement, and our Privacy Policy, constitute the entire agreement between you and SafeTech regarding the Services and supersede any prior agreements on the same subject.
The following terms apply specifically to Inheriti® Business, in addition to the General Terms above.
These Business Terms, and the Organisation Data Processing Addendum in Section 2.7, become applicable when you create an Organisation or otherwise activate Inheriti® Business under your SafeID Account.
When you create an Organisation or activate Inheriti® Business, you must separately confirm the following, in addition to your acceptance of the General Terms under Section 1.1: “I confirm that I am authorised to act on behalf of the Organisation and agree to the Inheriti® Terms of Service, including the Inheriti® Business Terms and the Organisation Data Processing Addendum.”
This confirmation is required only from the individual who creates the Organisation or activates Inheriti® Business on the Organisation’s behalf. An individual who merely joins an existing Organisation as an Organisation Member is not required to separately accept these Business Terms or the Organisation Data Processing Addendum; the Organisation’s own acceptance, given at the time the Organisation was created or Inheriti® Business was activated, governs the processing of that Member’s Personal Data under Section 2.7.
SafeTech records the Organisation’s acceptance under this Section 2.1, including the Organisation name, the accepting individual, the date and time of acceptance, the version of these Terms accepted, and the confirmation of authority described above.
Inheriti® Business operates within an Organisation Account and is built around encrypted Protection Plans. A Protection Plan allows authorised Organisation Members to protect data, documents, and other information by encrypting the data and distributing the materials required for later access across multiple protected storage locations.
There are two types of Protection Plans:
An Organisation Member may create a Protection Plan for a Team of which that Member is a member. Organisation Owners and Organisation Managers may create plans for any Team in the Organisation. A Member may also create a Private Plan within the Organisation. A Private Plan is controlled by its creator for plan content, completion, and access requests. Organisation Owners and Organisation Managers may still see Private Plans and carry out permitted administrative actions, such as deleting a draft or destroying a completed plan, but they cannot edit the plan’s contents or start an access request for it.
A Protection Plan that is not designated as a Private Plan is a “Shared Plan” and is subject to the role-based access permissions of Organisation Administrators, Team Admins, and Plan Moderators described in Section 2.3 and Section 2.7.5.
A plan’s access may be governed by authentication, moderation, or both, according to the plan’s settings:
Only an Active Organisation Member with the required plan or Team permissions may request access, and any required authentication, moderation, or continuity conditions must be satisfied. A Plan Moderator may approve an access request only to the extent permitted by the applicable plan settings and the Moderator’s role. A Plan Moderator does not receive general access to the Organisation, other Teams, or other Protection Plans solely by holding that designation.
During plan creation, the data supplied through the plan-creation process is encrypted using the SSDP+ protocol and a unique symmetric SSDP+ key. The encrypted data is divided into data shares, and the SSDP+ key is divided into key shares using Shamir’s Secret Sharing. A unique symmetric Plan Key is automatically created for the Protection Plan. The resulting shares are encrypted with the Plan Key.
The Plan Key is wrapped using the Organisation Key and sealed using the Organisation HSM Key. The sealed Plan Key is stored in the Inheriti® database. Encrypted data shares are stored in Inheriti® Vault and may also be copied to Organisation-authorised backup Storage Layers, such as supported external cloud-storage services. Encrypted validator key shares are processed through the applicable InheritiChain smart-contract component.
Each Protection Plan also includes a Custodian Share Pair consisting of one data share and one key share. The data share remains in the custodian depot. The corresponding key share is claimed by an authorised member at the time of access and stored using the member’s SafeKey Mobile or SafeKey Pro device, as applicable.
To access the protected data, the applicable access authorisation must be active, the Organisation Key must be manually released from SafeKey Mobile, and all required authentication, moderation, or Business Continuity conditions must be satisfied. The system then collects the encrypted shares from the applicable storage locations and obtains the required custodian key share from the authorised device.
The sealed Plan Key is unsealed within the managed Hardware Security Module using the Organisation HSM Key. The private key used for that operation does not leave the HSM. Once the Plan Key is available, it is used to decrypt the encrypted data shares, key shares, and Custodian Share Pair. The required shares are then recombined using Shamir’s Secret Sharing and processed through the SSDP+ protocol layer to reconstruct the protected data in its original form.
Inheriti® Business is provided through an Organisation Account established for an organisation that subscribes to the Service.
An individual becomes an “Organisation Member” when the individual is invited to join the Organisation. An Organisation Member’s access to the Service may require the individual to accept the invitation, create or authenticate an account, and complete any other required registration or security steps.
The principal Organisation-level roles are:
Organisation Owners and Organisation Managers are collectively referred to as “Organisation Administrators” where the relevant provision applies to both roles. A provision that refers specifically to an Organisation Owner or Organisation Manager applies only to that role.
An Organisation Member may be added to one or more Teams. While assigned to a particular Team, the Organisation Member is a “Team Member” of that Team. Team membership is separate from Organisation membership and does not, by itself, give a Team Member access to every Protection Plan associated with the Organisation.
An Organisation Member may be designated as a “Team Admin” for a particular Team. A Team Admin may manage that Team and its Team Members only to the extent permitted by the applicable permissions and Organisation settings. A Team Admin does not automatically have authority over other Teams, the Organisation Account, or Protection Plans outside that Team.
An Organisation Member may be designated as a “Plan Moderator” for a particular Protection Plan. A Plan Moderator must also be an Organisation Member and, where required by the applicable Plan settings, a Team Member of the relevant Team. A Plan Moderator may perform the moderation or management functions assigned to that role for that Protection Plan. A Plan Moderator does not, solely by virtue of that designation, become an Organisation Owner, Organisation Manager, Team Admin, or administrator of any other Protection Plan.
Organisation Owners and Organisation Managers may invite and remove Organisation Members and may manage Organisation-level access and permissions according to their respective roles. Organisation Administrators may also assign Members to Teams and grant or revoke Team Admin and Plan Moderator designations where permitted by the Organisation’s settings.
A Member’s access to the Organisation, a Team, or a Protection Plan may therefore depend on several separate permissions, including:
The removal of an individual from the Organisation, a Team, or a Protection Plan may affect the individual’s access to the Service or to particular Protection Plans.
An Organisation may activate and authorise an external connection to a supported cloud-storage service as an additional storage layer for Plan share data (a “Storage Layer”). The Organisation is responsible for selecting and authorising the external cloud-storage service and for maintaining any account, permissions, credentials, and settings required to use that Storage Layer.
When a Storage Layer is activated, Inheriti® Business may connect to the relevant cloud-storage service through an application programming interface or other authorised connection to store, retrieve, synchronise, and monitor encrypted Plan share data and associated metadata as necessary to provide the Service.
Plan share data stored through a Storage Layer is handled by SafeTech as encrypted, opaque data. SafeTech does not possess the decryption capability or information necessary to decrypt the share data and cannot access the underlying plaintext share. SafeTech may, however, process metadata required to identify, locate, authenticate, retrieve, return, synchronise, monitor, and manage an encrypted share through the Storage Layer.
This metadata may include identifiers, object locations, Plan or Organisation associations, timestamps, status information, access records, and technical connection information. SafeTech may transmit, retrieve, and return encrypted share data through the Storage Layer, but does not access or use the underlying plaintext share or its contents for its own purposes.
The Organisation authorises SafeTech to access the Storage Layer and to process encrypted Plan share data and associated metadata through the applicable integration as necessary to provide the Service.
In relation to Plan share data and associated metadata stored in or accessed through an Organisation-authorised Storage Layer, the Organisation determines the purposes for which the Storage Layer is used and is responsible for establishing the lawful basis and instructions for that processing. To the extent SafeTech processes that data solely to provide the Storage Layer and related Inheriti® Business functionality on the Organisation’s instructions, SafeTech acts as a processor on behalf of the Organisation.
SafeTech is responsible for the Inheriti® Business integration with the Storage Layer, but does not control or operate the external cloud-storage service or determine the purposes for which the Organisation uses that service.
The external cloud-storage provider is selected and authorised by the Organisation. The provider’s role, and its responsibility for its own infrastructure, processing activities, and subprocessors, are governed by the provider’s applicable terms and data-processing documentation. SafeTech does not select or appoint that provider on the Organisation’s behalf and is not responsible for the provider’s independent processing activities, infrastructure, security practices, retention practices, or subprocessors.
Depending on the provider’s services and applicable terms, the external cloud-storage provider may act as a processor for the Organisation in relation to Plan share data and/or as an independent controller for other processing, such as account administration, security, billing, legal compliance, or service analytics. The provider remains responsible for its own processing activities and subprocessors in accordance with its applicable terms and data-processing documentation.
The Organisation remains responsible for assessing, authorising, and using the external cloud-storage service, including reviewing the provider’s applicable terms, privacy documentation, data-processing terms, security controls, retention settings, and subprocessors. The Organisation is also responsible for ensuring that its use of the Storage Layer complies with applicable law and with its obligations to Organisation Members, Planners, and Beneficiaries.
The availability and operation of a Storage Layer may be affected by the external cloud-storage service’s systems, policies, account status, service availability, and technical requirements. SafeTech may monitor the health and availability of the connection and may notify the Organisation of connection or service issues.
Business Continuity Plans may use an inactivity-based dead-man’s-switch mechanism. You are responsible for configuring the applicable trigger, maintaining accurate settings, monitoring required activity, and cancelling or responding to a trigger within the applicable period.
An unintended trigger—for example, one caused by prolonged inactivity, incorrect configuration, loss of access to an authorised account, or failure to respond within the applicable period—may cause an access or reveal process to begin earlier than intended. If the applicable cancellation period expires, the resulting access or release process may not be reversible.
InheritiChain is a permissioned distributed-ledger component used in connection with certain Protection Plan operations. Its availability and operation may depend on configured network participants, identity and access controls, validation processes, supporting infrastructure, and services outside SafeTech’s direct control.
Events affecting InheritiChain or its supporting infrastructure—including service interruption, configuration failure, authentication or authorisation failure, validation failure, network-participant unavailability, maintenance, security incident, or changes to the supporting infrastructure—may delay, prevent, or affect the validation, storage, retrieval, or release of Plan-related information or shares.
SafeTech does not guarantee that InheritiChain or its supporting infrastructure will remain continuously available, error-free, unchanged, or compatible with the Service.
The General Terms provisions concerning third-party services, service availability, security responsibilities, and protection-plan recovery also apply to the Organisation’s use of InheritiChain.
These Business Subscription Terms apply to all business subscription plans, including Starter, Growth, Enterprise, and any successor or additional plans we may make available. They govern subscription pricing, billing, renewal, plan entitlements, seats, data and usage limits, price changes, account-specific pricing, cancellation, and related matters.
The General Subscription Terms apply to all business subscription plans. The Starter, Growth, and Enterprise Subscription Terms contain plan-specific details and apply only to the applicable plan. These Business Subscription Terms supplement the General Terms and any applicable order form, subscription record, or written agreement.
For purposes of these General Subscription Terms:
“Billing Period” means the monthly, annual, or other period for which a subscription fee is charged.
“Renewal Date” means the date on which a subscription automatically renews for another Billing Period.
“Plan” means the applicable business subscription plan selected by the customer.
“Plan Entitlements” means the seats, data, storage, features, integrations, usage limits, support, and other benefits included with a Plan.
“Subscription Record” means the applicable order form, checkout confirmation, invoice, customer account record, pricing schedule, enterprise agreement, or other written record identifying the customer’s subscription.
“Account-Specific Price” means a promotional, negotiated, introductory, legacy, grandfathered, or other price assigned to a particular customer, account, Plan, seat allocation, usage level, or subscription term.
These General Subscription Terms apply to all paid business subscription plans, including Starter, Growth, Enterprise, and any successor or additional business plans that Inheriti® may make available. These General Subscription Terms apply to all business subscription customers unless different terms are stated in an applicable order form, enterprise agreement, or other written agreement.
Inheriti® may offer different business subscription Plans with different prices, billing intervals, seat limits, data allowances, features, integrations, support levels, usage limits, and other Plan Entitlements. The Plan applicable to a customer will be identified in the customer’s Subscription Record. Inheriti® may introduce new Plans, modify existing Plans, replace Plans, or discontinue Plans in accordance with these Terms, the applicable customer agreement, and applicable law.
Each Plan includes only the seats, data, storage, features, integrations, usage allowances, support services, and other benefits identified for that Plan. Plan Entitlements may be described in the applicable plan page, order form, customer account, checkout confirmation, invoice, pricing schedule, enterprise agreement, or other written Subscription Record. The applicable Subscription Record will control which Plan Entitlements apply to the customer. Unless otherwise stated, unused seats, data, storage, or usage allowances do not carry forward to a later Billing Period. Changes to Plan Entitlements for an existing subscription are governed by the “Changes to Plan Entitlements” section below.
A customer may use the number of seats and the amount of data, storage, or other usage included in the applicable Plan. Additional seats, storage, data, usage, or add-ons may be purchased where made available. Additional charges will be based on the rates displayed at the time the additional seats, storage, data, usage, or add-ons are ordered or stated in the applicable order form.
Unless otherwise stated in the applicable Subscription Record, recurring add-ons purchased during an active monthly Billing Period will be billed on a prorated basis from the date and time of purchase through the end of the current Billing Period. Beginning with the next monthly Billing Period, the recurring add-on will be billed at its full applicable price and will appear on the same invoice as the customer’s next subscription billing charge.
Inheriti® will not charge additional recurring amounts unless the customer has authorized the applicable purchase or the charge is otherwise permitted under the customer’s Subscription Record or applicable customer agreement. Inheriti® may impose reasonable technical, security, or usage limits to protect the service, prevent abuse, comply with legal or regulatory requirements, or maintain service availability.
The customer agrees to pay the subscription fees shown at the time of purchase or stated in the applicable Subscription Record. Subscription fees may be charged monthly, annually, or according to another billing schedule stated in the customer’s Subscription Record. Unless otherwise stated:
a. monthly subscriptions are billed at the beginning of each monthly Billing Period;
b. annual subscriptions are billed at the beginning of each annual Billing Period;
c. subscription fees do not include applicable taxes;
d. subscription fees are not refundable after the applicable Billing Period begins, except where required by law or expressly agreed in writing; and
e. subscription fees are charged in the currency shown at checkout or in the applicable Subscription Record.
Unless canceled before the applicable Renewal Date, subscriptions automatically renew for successive Billing Periods equal to the initial subscription period. A monthly subscription renews monthly. An annual subscription renews annually on its applicable Renewal Date. The customer authorizes Inheriti®, or its payment processor, to charge the payment method associated with the account for renewal fees, applicable taxes, additional usage, and other authorized charges. The customer is responsible for maintaining a valid payment method and accurate billing information.
If a payment is declined, reversed, disputed, or otherwise not received when due, Inheriti® may notify the customer and request an updated payment method or payment of the outstanding amount. Subject to applicable law and the applicable customer agreement, Inheriti® may suspend or restrict access to the subscription if the outstanding amount is not paid within the period stated in the notice. Suspension for non-payment does not cancel amounts already owed. Inheriti® may charge reasonable fees or interest on overdue amounts where permitted by applicable law and the applicable customer agreement. Access may be restored after the outstanding amount and any applicable charges have been paid, subject to the availability of the subscription and any other rights available to Inheriti® under these Terms.
Subscription fees do not include VAT, sales tax, GST, digital services taxes, withholding taxes, or similar government charges unless expressly stated otherwise. The customer is responsible for applicable taxes imposed on its purchase, except for taxes based on Inheriti®’s net income. If the customer provides valid tax-exemption or tax-registration information, the tax treatment will be determined in accordance with applicable law.
Inheriti® may change the standard price of any business subscription Plan, including the price for: monthly subscriptions; annual subscriptions; additional seats; storage; plans or data; usage; add-ons; integrations; or other subscription components. A change to the standard price will apply to new customers beginning on the effective date stated by Inheriti®. For existing customers, a changed standard price will apply only to a future Billing Period and only after providing any notice or obtaining any consent required by applicable law or contract. Inheriti® will not retroactively change the price of a completed Billing Period. For monthly subscriptions, a price change will generally apply no earlier than the next monthly renewal after the applicable notice period. For annual subscriptions, a price change will generally apply no earlier than the next annual Renewal Date after the applicable notice period. The effective date of a price change may be postponed if necessary to satisfy an applicable notice period, contractual requirement, or customer cancellation right. A change to the standard price of a Plan does not, by itself, change an Account-Specific Price.
Inheriti® may provide a customer with a promotional, negotiated, introductory, legacy, grandfathered, or other Account-Specific Price. An Account-Specific Price applies only to the customer, account, Plan, seats, usage, and subscription term identified in the applicable Subscription Record or written agreement. Unless expressly stated otherwise in a written agreement, Account-Specific Pricing: is not transferable; does not apply automatically to new seats or add-ons; may end if the customer changes Plans; may end if the customer cancels and later resubscribes; does not establish a general price for other customers; does not apply to other accounts owned or controlled by the customer; and may be modified or discontinued for a future Billing Period in accordance with these Terms, the applicable customer agreement, and applicable law. Unless expressly stated otherwise in a written agreement, an Account-Specific Price is not guaranteed to remain unchanged indefinitely.
Inheriti® may manually adjust an Account-Specific Price. Any adjustment will apply only to a future Billing Period and will not change an invoice already issued or a Billing Period that has already begun. Inheriti® will provide any notice, obtain any consent, or provide any cancellation or termination right required by applicable law or the applicable customer agreement.
Unless otherwise agreed in writing or required by law, Inheriti® will not change the recurring price of an existing subscription, Plan, seat, or add-on during a Billing Period. Changes to recurring prices will take effect at the beginning of a future Billing Period: the next monthly Billing Period for monthly subscriptions, or the next annual renewal period for annual subscriptions.
This provision does not prevent Inheriti® from charging for newly purchased seats, add-ons, usage, taxes, or other charges incurred separately during the current Billing Period. Recurring add-ons purchased during an active monthly Billing Period may be billed on a prorated basis from the date and time of purchase through the end of that Billing Period. Beginning with the following monthly Billing Period, the recurring add-on will be billed at its full applicable price and included with the customer’s next subscription billing invoice, as described in the “Seats, Data, and Usage” section.
Inheriti® may modify, add, remove, replace, or reorganize features, integrations, support levels, storage, data allowances, usage limits, and other Plan Entitlements. If a change materially reduces the core functionality of an existing paid subscription, Inheriti® will provide any notice, credit, cancellation right, refund, or other remedy required by the applicable agreement or law. Changes made for security, legal, regulatory, technical, or operational reasons may take effect sooner where reasonably necessary, subject to applicable law. If a Plan is replaced or discontinued, Inheriti® may offer the customer a successor Plan or another reasonable alternative.
Where notice is required by applicable law or contract, Inheriti® may provide notice by email, account notification, invoice, written notice, or another legally permitted method. A notice may identify the affected subscription or Plan; the current and new price; the affected features, seats, data, or usage limits; the effective date; the customer’s cancellation or termination rights; and any action the customer must take. Inheriti® will provide at least the minimum notice required by applicable law.
A customer may cancel automatic renewal using the cancellation method made available through the account or identified in the applicable subscription documentation. Unless otherwise stated or required by law, cancellation takes effect at the end of the current Billing Period. The customer may continue using the subscription until the end of the current Billing Period, but will not receive a refund for unused time, seats, data, or usage unless required by law or expressly agreed in writing.
Except where required by law or expressly agreed in writing, subscription fees are non-refundable after the applicable Billing Period begins. Inheriti® may, at its discretion, issue credits, refunds, extensions, or other accommodations. Unless otherwise stated, credits may be applied only to future charges for the applicable account and may not be transferred, exchanged for cash, or applied to another account.
If there is a conflict between documents governing a customer’s subscription, the following order of precedence applies:
a. an executed enterprise agreement or other negotiated written agreement;
b. the applicable order form;
c. the applicable Subscription Record;
d. the applicable Plan Terms;
e. these General Subscription Terms; and
f. the General Terms.
The Starter Plan is intended for customers requiring the essential features, seats, and usage limits described in the applicable Starter Plan materials.
The Starter Plan includes the following:
The Starter Plan is subject to the General Subscription Terms.
The current Starter Plan pricing is:
The applicable price for a customer will be identified in the customer’s Subscription Record and remains subject to the General Subscription Terms.
The Growth Plan is intended for customers requiring expanded features, higher seat limits, and advanced usage capabilities described in the applicable Growth Plan materials.
The Growth Plan includes the following:
The Growth Plan is subject to the General Subscription Terms.
The current Growth Plan pricing is:
The applicable price for a customer will be identified in the customer’s Subscription Record and remains subject to the General Subscription Terms.
The Enterprise Plan is designed for organizations requiring customized scale, advanced security controls, and guaranteed performance levels.
Because Enterprise requirements vary by organization, entitlements—including seat allocations, data limits, feature access, teams, protection plans, storage, and connections—are defined in the applicable order form or enterprise agreement. The plan-selection materials indicate that Enterprise customers may receive unlimited seats, teams, protection plans, and categories, as well as 5 TB of media storage. Service quality, availability, and support response times for Enterprise customers are governed by a separate Service Level Agreement (SLA).
Enterprise pricing is provided on an “on demand” or customized basis. The specific fees and payment terms will be stated in the applicable order form, enterprise agreement, or other written Subscription Record.
Enterprise subscriptions remain subject to the General Subscription Terms; however, in the event of a conflict, the terms of the executed SLA and the enterprise agreement shall control. Because Enterprise customers may use different or additional Storage Layers and may be located outside the European Economic Area, SafeTech will offer Enterprise Organisation customers a standalone, separately executed Organisation Data Processing Addendum (extracted from Section 2.7 and Annexes A–C) in place of, or alongside, the embedded Section 2.7, as agreed in the applicable enterprise agreement.
This Section 2.7 (the “Organisation Data Processing Addendum” or “DPA”) applies where an Organisation is the controller of Personal Data and SafeTech processes that Personal Data on the Organisation’s behalf as processor in connection with Inheriti® Business. It is incorporated into, and forms part of, these Terms and the binding contractual relationship between SafeTech and the Organisation described in Section 2.1. This DPA is drafted primarily for compliance with Regulation (EU) 2016/679 (the “EU GDPR”), including Article 28, and with the Belgian Act of 30 July 2018 on the protection of natural persons with regard to the processing of personal data.
For Enterprise Organisation customers, SafeTech offers a standalone, separately executed Organisation Data Processing Addendum in place of, or alongside, this Section 2.7, as described in Section 2.6.4.3.
This DPA applies to SafeTech’s processing of Personal Data on behalf of the Organisation in connection with Inheriti® Business.
The Organisation is the controller of the Personal Data described in Annex A, and SafeTech is the processor, except where SafeTech processes Personal Data for its own independent purposes as described in Section 2.7.10.
If the Organisation acts on behalf of another controller, the Organisation warrants that it is authorised to appoint SafeTech as a processor and to provide the instructions set out in this DPA.
If there is a conflict between this DPA and the remainder of these Terms concerning the processing of Personal Data for which the Organisation is controller, this DPA prevails to the extent of that conflict, subject to Section 2.7.20 (Order of Precedence).
This DPA does not apply to processing for which SafeTech acts as an independent controller, including the processing described in Section 2.7.10 and in the Privacy Policy.
For this DPA, and unless the context requires otherwise, capitalised terms not defined in this Section 2.7.2 have the meaning given to them elsewhere in these Terms (including “Organisation”, “Organisation Member”, “SafeID Account”, “Protection Plan”, “Private Plan”, “Shared Plan”, and “Storage Layer” as defined in Sections 1.3, 2.2, 2.3, and 2.4):
SafeTech shall process Personal Data only: to provide, secure, maintain, and support the Services; in accordance with the Organisation’s documented instructions; as necessary to comply with these Terms; or as required by Applicable Data Protection Law.
The Organisation’s documented instructions consist of: these Terms; this DPA; the Organisation’s configuration and use of the Services; written instructions issued by the Organisation from time to time; and the processing details in Annex A.
SafeTech shall promptly inform the Organisation if, in its opinion, an instruction infringes Applicable Data Protection Law. SafeTech may suspend the relevant processing until the Organisation confirms or changes the instruction, unless Applicable Data Protection Law requires SafeTech to continue processing.
SafeTech shall not: sell Personal Data; use Personal Data for targeted advertising; use Personal Data to create independent commercial profiles of Data Subjects; or use Personal Data for any purpose unrelated to providing or securing the Services, unless expressly authorised by the Organisation or required by Applicable Data Protection Law.
SafeTech shall operate the Services in accordance with the role-based permissions and Protection Plan privacy settings described in Sections 2.2 and 2.3. In particular:
The access limitations above describe access through the Services. They do not prevent SafeTech from processing encrypted data, Plan Metadata, technical records, or other information within its control as necessary to provide, secure, maintain, support, recover, or administer the Services in accordance with this DPA.
The Organisation is responsible for: determining the purposes and lawful basis for processing Personal Data; providing any required privacy notices to Data Subjects; ensuring that its instructions to SafeTech comply with Applicable Data Protection Law; determining which Personal Data is uploaded to the Services; configuring Members, permissions, retention settings, recovery settings, and access controls; informing its Organisation Members and other authorised users about the role-based access permissions and Protection Plan privacy settings applicable to the Services; responding to Data Subjects where the Organisation is the relevant controller; and assessing and authorising any external Storage Layer that it connects to the Services under Section 2.4.
The Organisation shall not instruct SafeTech to process Personal Data in a manner that would violate Applicable Data Protection Law.
The Organisation shall ensure that its Organisation Members and other authorised users use the Services in accordance with these Terms and applicable policies.
The Organisation is responsible for determining whether a Protection Plan should be configured as a Shared Plan or a Private Plan and for ensuring that the selected privacy setting is appropriate for the Personal Data and Protected Plan Content uploaded to or configured within the plan.
SafeTech shall ensure that persons authorised to process Personal Data are bound by confidentiality obligations or are subject to an appropriate statutory duty of confidentiality.
SafeTech shall restrict access to Personal Data to personnel who require access to perform their assigned duties, and shall ensure that personnel with access to Personal Data receive appropriate training regarding confidentiality, security, and data protection.
SafeTech shall implement and maintain appropriate technical and organisational measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or unauthorised access, as further described in Annex B.
SafeTech shall not be required to decrypt encrypted Protection Plan Content merely to perform its obligations under this DPA. Where SafeTech processes encrypted or otherwise opaque data, its security obligations apply to the data and systems within its control, including the associated Plan Metadata and technical processing environment.
SafeTech shall maintain technical controls designed to prevent Organisation Administrators from accessing the Protected Plan Content of Private Plans through the Services, while permitting the Plan Metadata and administrative functions described in Section 2.7.3.
The Organisation authorises SafeTech to use the Subprocessors listed in Annex C.
SafeTech shall: enter into a written agreement with each Subprocessor requiring data-protection obligations no less protective than those in this DPA; remain responsible for the acts and omissions of its Subprocessors to the extent required by Applicable Data Protection Law; and provide the Organisation with information about proposed new Subprocessors upon request or through an online notice mechanism.
SafeTech shall give the Organisation reasonable advance notice of any intended addition or replacement of a Subprocessor that will process the Organisation’s Personal Data. The Organisation may object to a new Subprocessor on reasonable data-protection grounds; the Parties shall work in good faith to resolve the objection, and if no reasonable solution is available, the Organisation may terminate the affected Services on written notice.
An external Storage Layer provider selected and authorised directly by the Organisation under Section 2.4 is not a Subprocessor appointed by SafeTech where SafeTech does not select, appoint, or determine the provider’s independent processing purposes. The provider’s role and responsibilities are governed by the Organisation’s arrangement with that provider, Applicable Data Protection Law, and Section 2.7.16.
SafeTech’s affiliate Safe Haven Tech PTE. LTD., named as a SafeTech contracting party in Section 1 of the General Terms, does not process Organisation Personal Data as a Subprocessor and is not otherwise involved in the processing of Personal Data in connection with Inheriti® Business. It is accordingly not listed in Annex C.
Taking into account the nature of the processing, SafeTech shall provide reasonable assistance to the Organisation in responding to requests from Data Subjects to exercise their rights under Applicable Data Protection Law, including, where technically feasible and legally permitted, by providing access to relevant Personal Data, correcting or deleting Personal Data at the Organisation’s instruction, restricting processing, supporting data export or portability, assisting with objections to processing, and providing information reasonably necessary to respond to a Data Subject request.
If a Data Subject contacts SafeTech directly regarding processing for which the Organisation is controller, SafeTech shall, unless legally prohibited, refer the request to the Organisation and shall not respond substantively without the Organisation’s instructions.
Where a request concerns Protected Plan Content in a Private Plan, SafeTech shall provide assistance through the Organisation or the authorised user who has access to that content, as applicable. SafeTech shall not provide the Protected Plan Content to an Organisation Administrator who is not authorised to access it through the Services.
SafeTech shall notify the Organisation without undue delay after becoming aware of a Personal Data Breach affecting Personal Data processed under this DPA. The notification shall include, to the extent known: the nature of the breach; the categories and approximate number of affected Data Subjects and records; the likely consequences; the measures taken or proposed; and a contact point for further information.
SafeTech shall investigate the breach, take reasonable steps to contain and remediate it, preserve relevant evidence, provide reasonable updates, and cooperate with the Organisation’s legal and regulatory obligations.
SafeTech shall not notify a supervisory authority, Data Subject, or other third party about a breach affecting the Organisation’s Personal Data without the Organisation’s prior written approval, unless required by Applicable Data Protection Law.
SafeTech may process certain information as an independent controller where SafeTech determines the purpose and means of that processing independently of the Organisation, including SafeTech’s own: SafeID Account administration; authentication and access management; security; support; fraud prevention; legal and regulatory compliance; billing and payment administration; service management; product improvement; and other purposes described in the Privacy Policy for which SafeTech determines its own purposes and means of processing.
SafeTech shall not rely on this Section 2.7.10 to classify Protection Plan Content or Organisation-controlled Personal Data as independent-controller processing merely because the data is stored on SafeTech infrastructure, processed through SafeTech technology, or made available through the Services.
SafeTech shall remain responsible for complying with Applicable Data Protection Law in relation to its independent-controller processing and shall provide appropriate information to Data Subjects where required, including through the Privacy Policy.
SafeTech’s independent-controller processing shall not authorise SafeTech to disclose Protected Plan Content from a Private Plan to an Organisation Administrator or other person who is not authorised to access that content under the Services.
If SafeTech receives a legally binding request from a public authority for access to the Organisation’s Personal Data, SafeTech shall, unless legally prohibited: notify the Organisation before disclosing the data; refer the authority to the Organisation where appropriate; limit the disclosure to the minimum legally required; and provide reasonable information about the request. SafeTech shall assess the legality of the request and may challenge it where there are reasonable grounds to do so.
Where a request concerns a Private Plan, SafeTech shall, to the extent legally permitted, apply the same access controls and confidentiality protections to the Protected Plan Content that apply under the Services.
SafeTech shall not transfer Personal Data outside the European Economic Area unless an appropriate transfer mechanism recognised under the EU GDPR is in place, such as an adequacy decision, the European Commission’s Standard Contractual Clauses, binding corporate rules, or another legally recognised transfer mechanism. The Parties shall cooperate in completing any transfer documentation reasonably required for the Services.
Taking into account the nature of the processing and the information available to SafeTech, SafeTech shall provide reasonable assistance with data protection impact assessments, consultations with supervisory authorities, records of processing activities, security assessments, and responses to reasonable data-protection enquiries. SafeTech may charge reasonable additional costs for assistance that is unusually extensive or outside the ordinary scope of the Services, provided that SafeTech notifies the Organisation in advance.
SafeTech shall make available information reasonably necessary to demonstrate compliance with this DPA, which may include relevant security certifications, audit reports, penetration-test summaries, independent assessment reports, compliance documentation, and written responses to reasonable questionnaires.
Where the information provided is insufficient to demonstrate compliance, the Organisation may conduct, or appoint an independent auditor to conduct, an audit of SafeTech’s relevant processing activities. Audits shall occur no more than once annually unless a Personal Data Breach or material compliance concern justifies an additional audit; be conducted on reasonable written notice during normal business hours; avoid unreasonable disruption to SafeTech’s operations; protect the confidentiality of SafeTech’s information; and be performed at the Organisation’s expense. The Organisation shall not have access to another customer’s data or to SafeTech information unrelated to the Services.
Cancellation of a subscription will stop renewal of the applicable Services but will not immediately terminate access or delete the Organisation or its Organisation Data. The Organisation will continue to have access to the Services until the end of its then-current paid subscription term.
While the subscription remains active, users may access Protected Plan Content through the ordinary functionality of the Services and may manually copy or otherwise retain that content. Protected Plan Content is not included in any automated export functionality.
The day after the applicable paid subscription term ends, the Organisation will enter an “Export-Only Period” lasting 14 days. During the Export-Only Period:
The Organisation is responsible for manually accessing and copying any Protected Plan Content it wishes to retain before the paid subscription term ends. Inheriti has no obligation to provide an automated export of Protected Plan Content.
An authorised Organisation Administrator may request deletion of the Organisation before the end of the paid subscription term. Unless the Organisation requests immediate deletion, or immediate deletion is required for security, legal, or other legitimate operational reasons, the Organisation will remain accessible until the end of the paid subscription term and will then enter the 14-day Export-Only Period described above.
At the end of the 14-day Export-Only Period, Inheriti will permanently delete the Organisation and its Organisation Data, including Personal Data, Protected Plan Content, Plan Metadata, logs, account information, and related technical records. Following permanent deletion, the Organisation Data cannot be accessed, exported, recovered, or restored.
An authorised Organisation Administrator may cancel a pending deletion at any time before permanent deletion occurs. Cancelling a pending deletion does not reverse or invalidate a prior subscription cancellation and does not extend the Organisation’s paid subscription term.
If the Organisation wishes to regain access to the Services or Protected Plan Content, it must reactivate or resubscribe to the applicable Services. Any reactivation or resubscription will be subject to Inheriti’s then-current subscription rates, Plans, fees, terms, and eligibility requirements. The Organisation may forfeit any promotional, introductory, negotiated, legacy, grandfathered, or other Account-Specific Price that applied before the deletion request.
Unless Inheriti expressly agrees otherwise in writing, the Organisation will not be entitled to resume its former pricing, Plan, discounts, billing terms, seats, storage allocation, usage allowances, or other subscription benefits. Reactivation or resubscription following cancellation of a pending deletion is subject to the pricing and Account-Specific Pricing provisions in Sections 2.6.1.10 through 2.6.1.13.
If the Organisation cancels a pending deletion during the Export-Only Period, the Organisation Data will remain scheduled for permanent deletion until Inheriti confirms that the applicable Services have been successfully reactivated or resubscribed to. Protected Plan Content will not become accessible merely because the deletion request has been cancelled.
Inheriti may retain limited information where retention is required by Applicable Data Protection Law, court order, regulatory requirement, or other legally binding obligation. Any retained information will be limited to what is required, retained only for the legally required period, protected against unauthorised access, and processed only for the purpose requiring its retention.
Organisation Data held in routine backup systems will be deleted or rendered inaccessible in accordance with Inheriti’s backup-deletion procedures and will not be restored except where necessary for disaster recovery, legal compliance, or security purposes. Once restored, any Organisation Data that is no longer required will be deleted in accordance with this Section.
This DPA incorporates by reference Section 2.4 (Custom Storage Layers), including Section 2.4.1 (Data-Protection Roles). In addition: SafeTech shall process the encrypted share data and associated Plan Metadata necessary to identify, locate, authenticate, retrieve, return, synchronise, and monitor the relevant encrypted share through a Storage Layer only on the Organisation’s instructions and to the extent SafeTech provides the Storage Layer integration and related Inheriti® Business functionality. The Storage Layer provider shall not receive Protected Plan Content in decrypted form solely because the Organisation has authorised the Storage Layer integration, unless these Terms or the Organisation’s configuration expressly provide otherwise.
This DPA begins when the Organisation creates an Organisation Account or activates Inheriti® Business under Section 2.1, and continues for as long as SafeTech processes Personal Data on behalf of the Organisation. It terminates automatically when the Organisation’s use of Inheriti® Business terminates, except for provisions that must continue by their nature, including confidentiality, security, deletion, audit, liability, and dispute-resolution provisions. Termination of this DPA does not affect the validity of processing carried out before termination.
Each Party shall comply with its obligations under this DPA and Applicable Data Protection Law. Liability under this DPA is subject to Section 1.13 (Liability Limitations), except to the extent Applicable Data Protection Law prohibits or restricts that limitation. Nothing in this DPA excludes or limits liability that cannot lawfully be excluded or limited.
Any amendment to this DPA must be in writing, except that SafeTech may update Annex C in accordance with Section 2.7.7. If any provision of this DPA is invalid or unenforceable, the remaining provisions remain effective. This DPA is governed by the governing-law and jurisdiction provisions of Section 1.16. SafeTech and the Organisation may execute this DPA electronically, including through the acceptance mechanism described in Section 2.1.
For any conflict concerning the processing of Personal Data for which the Organisation is controller and SafeTech is processor, the following order of precedence applies: (a) an executed enterprise agreement or other negotiated written agreement expressly addressing data processing; (b) this DPA (Section 2.7 and Annexes A–C); (c) the remainder of the Inheriti® Business Terms (Sections 2.1–2.6); and (d) the Inheriti® General Terms (Section 1). This DPA does not govern, and is not superseded by, SafeTech’s independent-controller processing described in Section 2.7.10, which is instead governed by the Privacy Policy.
These terms apply specifically to users who access Inheriti® Partners through a SafeID Account and are approved to participate in the Inheriti® Reseller Program. Inheriti® Partners is a SafeTech Service that provides approved Partners with access to the Partners Platform and related tools for managing their participation in the Reseller Program. They supplement the General Terms above.
For purposes of these Inheriti® Partners Terms:
“Inheriti® Partners” means the SafeTech product and associated Partners Platform through which approved Partners may manage their participation in the Inheriti® Reseller Program.
“Partner” means a person or legal entity approved to participate in the Inheriti® Reseller Program.
“Partners Platform” means the account interface and related tools made available through Inheriti® Partners, including tools for registration, program applications, client invitations, subscription tracking, commission tracking, and payout management.
“Reseller Program” means the Inheriti® program through which approved Partners may refer or sell Inheriti® products and receive commissions in accordance with these Terms and any applicable Partner agreement or rate card.
To participate as a Partner, you must apply through the Partners Platform and provide accurate and complete information, including, where applicable, your legal name, legal-entity identity, registered address, registered country, and contact details. SafeTech may request supporting documentation to verify this information.
Your participation in the Reseller Program is subject to SafeTech’s approval. Creating a SafeID Account or submitting an application does not guarantee acceptance into the Reseller Program or access to all Partners Platform features.
You are responsible for maintaining accurate and current information associated with your Partner application and, if approved, your Partner profile. Changes to material profile details, including your legal-entity identity, registered address, registered country, or payout information, must be submitted through the Partners Platform or otherwise requested by SafeTech. Changes may be subject to SafeTech’s review and approval before taking effect.
SafeTech may reject an application, reject a proposed change, or restrict access to relevant features where information cannot be verified or where the application, change, or proposed activity would create legal, regulatory, security, or payment-related concerns.
You must keep your SafeID Account credentials secure and must not allow unauthorised persons to access or use your SafeID Account or Partner access.
The Partners Platform may allow you to:
The availability of particular features may depend on your application or approval status, product eligibility, location, verification status, or other applicable requirements.
SafeTech may modify, restrict, suspend, or discontinue any Partners Platform feature. Information displayed in the Partners Platform may be subject to reconciliation, correction, refunds, chargebacks, fraud reviews, or other adjustments before it becomes final.
A “Partner Client” is an end customer you refer to or sell Inheriti® products under the Reseller Program.
Each Partner Client may be associated with a specific product, subscription, entitlement, or invitation. A client invitation does not by itself create a completed sale, activate a product, or entitle you to a commission. The applicable product or subscription must be successfully activated, and any other applicable conditions must be satisfied, before commissions accrue.
You are responsible for the accuracy of the information you submit about a Partner Client and for complying with all applicable requirements when inviting or referring that client. You must not submit information without the necessary authorisation or use the Partners Platform to send unsolicited, misleading, or unlawful communications.
Each Partner Client remains subject to the applicable end-customer terms for the Inheriti® product or service they use.
This Commissions section governs partner commission rates, levels, eligibility, qualifying client payments, commission calculations, VAT treatment, level progression, adjustments, and the circumstances in which commission rates may be earned or agreed under a Partner’s contract.
A Partner’s commission is determined by the commission rate and revenue model applicable under the Partner’s agreement with SafeTech. Unless the applicable agreement states otherwise, the starting commission rate is 10%.
Commission is calculated on the total amount paid by the Partner’s clients for eligible subscriptions, seats, storage, storage layers, and other paid add-ons purchased through or attributable to the Partner. Commission is calculated on amounts net of VAT and any other applicable sales, use, or similar taxes.
For example, if a client pays €480 for a subscription, including 20% VAT, the commissionable amount is €400. At a 10% commission rate, the commission payable is €$40.
Unless a different rate or qualification requirement is specified in the Partner’s agreement, the standard commission levels are based on eligible client payments during the preceding 12-month period, as shown below:
| Partner level | Eligible client payments* | Commission rate |
|---|---|---|
| Bronze | Up to €7,999 | 10% |
| Silver | €8,000–€19,999 | 12% |
| Gold | €20,000–€49,999 | 15% |
| Platinum | €50,000 or more | 20% |
*Eligible client payments during the preceding 12-month period means the total amount paid by the Partner’s clients for eligible subscriptions, seats, storage, storage layers, and other paid add-ons, calculated net of VAT and other applicable taxes. Refunds, cancellations, chargebacks, fraudulent or duplicated transactions, unpaid amounts, and other excluded amounts do not count towards the total.
The levels, payment thresholds, commission rates, eligible products, and other programme details may be published and updated by SafeTech from time to time. Any different level or rate agreed in the Partner’s agreement will apply in accordance with that agreement.
For the purposes of determining a Partner’s level, eligible client payments include amounts paid for subscriptions, seats, storage, storage layers, and other paid add-ons, unless excluded by the applicable Partner agreement, rate card, or commission rules.
Eligible payments are calculated net of VAT and other applicable taxes. Amounts that are refunded, cancelled, reversed, charged back, unpaid, fraudulent, duplicated, or otherwise excluded under the applicable commission rules do not count towards a Partner’s qualifying payment total. If such an amount has already been included in the Partner’s qualifying total or commission calculation, SafeTech may deduct or reverse the corresponding amount.
A Partner may qualify for a higher commission level by reaching the applicable eligible client payment threshold during the relevant assessment period. This is referred to as earning a level.
A level earned through eligible client payments takes effect from the next applicable commission or payout period after SafeTech confirms that the relevant threshold has been reached, unless the applicable Partner agreement provides otherwise.
A Partner may also qualify for a commission level by agreeing to that level with SafeTech as part of the Partner’s contract or a written amendment to the Partner’s contract. This is referred to as agreeing a level.
An agreed commission level, threshold, qualification requirement, or other contractual commission term applies in accordance with the applicable Partner agreement, regardless of whether the Partner has reached the corresponding standard payment threshold.
If the Partner agreement differs from the standard levels or other information published by SafeTech, the Partner agreement prevails for that Partner.
The commission level and rate applicable to a Partner are determined by the Partner’s agreement with SafeTech. A Partner may qualify for a level either by earning it through eligible client payments or by agreeing to it contractually with SafeTech.
Where the Partner’s agreement provides for a specific level or rate, that contractual term applies. A Partner will receive the higher level or rate where required by the agreement, but a published standard level does not override or amend the Partner’s agreement.
If the total eligible client payments during the applicable assessment period fall below the threshold for the Partner’s current level, the Partner will move down to the level corresponding to the Partner’s actual eligible client payments.
The reduced level and rate take effect from the next applicable commission or payout period after the shortfall is determined, unless the Partner’s agreement provides otherwise. A Partner’s level may therefore increase or decrease over time based on the Partner’s eligible client payment total.
Commissions are calculated according to the applicable level, rate, and revenue model in effect for the relevant commission period. The revenue model may provide for one-time commissions, recurring commissions, or commissions tied to the applicable subscription lifecycle.
Recorded sales, subscriptions, eligible client payments, or commission amounts may be adjusted, delayed, withheld, or excluded before a commission is finalised, including in cases involving refunds, cancellations, chargebacks, fraud, duplicate transactions, non-payment, taxes, currency conversion, or other applicable exceptions.
The applicable commission period, payment schedule, minimum payout threshold, eligible products, exclusions, and other payment conditions are those stated in the Partner’s agreement, displayed in the Partners Platform, included in the applicable rate card, or otherwise communicated by SafeTech.
This Payout Accounts section governs the payout methods and providers available to Partners, payout timing and minimum thresholds, recurring commission payments, verification requirements, payout processing, and circumstances in which payouts may be delayed, adjusted, suspended, or changed.
To receive commission payouts, you must connect an eligible payout method through SafeTech’s designated payout provider. The payout provider may require identity, tax, business, or other verification information before payouts can be enabled. SafeTech’s designated payout provider for this purpose is Stripe Connect. Stripe may act as SafeTech’s processor for payout-related processing carried out on SafeTech’s instructions, and as an independent controller for processing for which Stripe determines its own purposes and means (such as financial compliance, fraud prevention, and administration of Stripe accounts); see the Privacy Policy for further detail. SafeTech’s own use of Stripe and Stripe Connect as service providers is governed by a separate agreement between SafeTech and Stripe, which is not part of these Terms and is not a substitute for the disclosures in the Privacy Policy.
Payouts are available only in the countries and currencies supported by the applicable payout provider.
Approved commissions are calculated and paid monthly. Recurring commission is payable for each month that an eligible client remains subscribed, subject to the applicable commission rate, revenue model, and any exclusions or adjustments under these terms or the applicable Partner agreement.
An approved commission balance of €25.00 or more is automatically transferred to the Partner’s registered payout account on the first day of the applicable month. If the approved commission balance is less than €25.00, the balance rolls over to the following month until the minimum payout threshold is reached.
SafeTech may pause, delay, reject, or suspend a payout where required by the payout provider, for compliance or security reasons, or where the Partner’s account does not satisfy ongoing verification requirements.
Payouts may also be delayed or adjusted where the underlying commission remains subject to review, reversal, refund, chargeback, cancellation, non-payment, fraud investigation, or another applicable adjustment.
You may request closure of your payout account or replacement of your payout destination, subject to any applicable verification requirements and the settlement of pending, disputed, reserved, or otherwise unpaid amounts.
The applicable payout currency, processing requirements, verification requirements, and other payout conditions are those displayed in the Partners Platform, stated in the applicable Partner agreement or payout terms, or required by the designated payout provider.
You must represent Inheriti® products accurately and must not make claims about them beyond what SafeTech’s current materials and instructions support.
You must not:
SafeTech may reject an application, restrict or suspend access to the Partners Platform, suspend or terminate your participation in the Reseller Program, or withhold or adjust unpaid commissions associated with fraudulent, invalid, disputed, or non-compliant activity.
These actions are in addition to any rights SafeTech has under the Suspension and Termination section of the General Terms.
These Inheriti® Consumer Terms apply specifically to your use of Inheriti® Consumer, including Data Backup Plans and Digital Inheritance Plans. They supplement the Inheriti® General Terms. If there is a conflict between these Inheriti® Consumer Terms and the General Terms, these Consumer Terms apply only to the extent of the conflict concerning the relevant Inheriti® Consumer feature.
Inheriti® Consumer allows individuals to create protection plans for sensitive data, documents, credentials, digital assets, and other information.
A protection plan uses encryption and secret-sharing technology to divide protected data into separate shares. The shares are distributed according to the configuration selected by the Plan Owner. The required shares must be brought together through the applicable recovery or merge process before the protected data can be accessed.
Inheriti® Consumer is a technology service for protecting and providing controlled access to data. It is not a will, trust, power of attorney, estate plan, legal service, financial service, or substitute for professional advice concerning the ownership, transfer, or administration of any asset.
You may create the following types of protection plan:
The person who creates and controls a protection plan is the Plan Owner.
A person designated to receive or hold a plan share is a Beneficiary. Depending on the plan type and configuration:
The Plan Owner is responsible for selecting the appropriate Shareholders, Heirs, and Merge Authority, and for providing accurate and current information about them.
A Data Backup Plan is intended for the secure backup and controlled recovery of the Plan Owner’s data.
The Plan Owner may designate one or more Shareholders and, where supported by the selected configuration, may also be a Shareholder or Merge Authority. Access to the protected data requires the relevant shares to be brought together through the applicable merge process and the configured Plan Trigger to be completed.
A Data Backup Plan generally requires an affirmative action to authorise access. Depending on the selected configuration, a Plan Trigger may require a login, email link, or another method made available through Inheriti® Consumer.
A Digital Inheritance Plan is intended for the controlled transfer of protected data to designated Heirs when the Plan Owner is no longer actively managing the plan.
A Digital Inheritance Plan uses a Dead Man Switch. Unlike a Data Backup Plan, which generally requires an affirmative action to approve access, a Dead Man Switch is designed to activate when the required action is not completed within the configured period.
A Dead Man Switch does not independently determine whether the Plan Owner has died, become incapacitated, or lost legal capacity. It operates according to the conditions, time periods, and verification methods configured by the Plan Owner.
The Plan Owner is responsible for configuring the Dead Man Switch appropriately and for keeping the plan updated if their circumstances, intentions, Heirs, or contact details change.
Plan Triggers control when the required plan shares may be released or merged. The applicable trigger method, response requirements, and countdown period depend on the plan configuration.
Where a Merge Authority initiates the applicable merge process, the relevant activation countdown may begin. The required activation steps must be completed within the configured period before the Merge Authority can proceed with opening the plan.
The applicable process may be aborted or cancelled while the activation process remains open, where that functionality is provided for the relevant plan configuration.
SafeTech does not control whether a Plan Owner, Beneficiary, Shareholder, Heir, or Merge Authority completes the actions required by a plan. Failure to respond to a verification request, maintain access to a required device, or keep contact information current may prevent a plan from being opened or may cause a plan to operate according to its configured conditions.
Protected data is encrypted and divided into separate plan shares. A single share is not intended to reveal or reconstruct the protected data by itself. The required shares must be combined through the applicable recovery or merge process before the protected data can be accessed.
Depending on the selected plan configuration, shares may be stored using supported devices, mobile storage, cloud storage, blockchain storage, or other storage layers made available by SafeTech.
A plan may include different types of shares, including:
The availability and operation of particular storage layers, devices, networks, recovery options, and share types may depend on the plan selected and may change over time.
A supported SafeKey device, mobile device, or other supported hardware may be used to store a plan share or participate in the protection plan.
You are responsible for maintaining control and access to any device, hardware key, credential, recovery code, or other item required to operate or recover your plan. The security responsibilities in section 1.8 of the General Terms apply to those items.
The loss, theft, destruction, factory reset, compromise, malfunction, or unauthorised use of a device may result in the loss or unavailability of a plan share. Where required shares or recovery items are permanently lost or unavailable, access to the protected data may be permanently and irreversibly lost.
The Plan Owner is responsible for configuring and maintaining each protection plan, including:
SafeTech does not determine whether a person selected by the Plan Owner is trustworthy, legally entitled to receive the protected data, or acting in accordance with the Plan Owner’s intentions.
Certain Plan Trigger or verification checks may require Trigger Credits. Trigger Credits may be included with a plan or made available for separate purchase, as indicated in the product or applicable pricing information.
If the required Trigger Credits are exhausted, the relevant trigger or verification process may be limited, delayed, or paused until additional credits are available. The Plan Owner is responsible for maintaining sufficient Trigger Credits for the applicable plan to operate according to its configuration.
Trigger Credits do not guarantee that a plan will be activated, merged, or successfully recovered.
Certain Inheriti® Consumer features may allow you to connect to or interact with a third-party digital wallet, blockchain network, smart contract, token, crypto-asset, digital asset, or tokenised item.
Section 1.12 of the General Terms applies to these features. You are responsible for confirming the intended wallet, network, address, asset, transaction, permissions, and other details before approving or initiating an operation.
Blockchain transactions and smart-contract operations may be irreversible. SafeTech cannot guarantee the availability, value, transferability, functionality, redemption, or continued support of any digital asset, token, wallet, blockchain network, smart contract, or tokenised item.
Where made available, certain Inheriti® Consumer plans or configurations may be purchased using a crypto coupon, prepaid crypto-denominated credit, or discount code.
Each coupon or discount code is subject to the validity period, redemption conditions, usage limits, exclusions, and other terms displayed at the time of issue or redemption.
Unless required by law, coupons and discount codes are non-transferable and are not exchangeable for cash or refundable after redemption.
SafeTech does not guarantee that a protection plan will be activated, merged, reconstructed, or recovered in every circumstance.
Recovery may be prevented or delayed by, among other things:
The service availability, suspension, termination, warranty, liability, and third-party risk provisions in the General Terms apply to Inheriti® Consumer and are not replaced by this section.
This Annex A forms part of the Organisation Data Processing Addendum (Section 2.7).
Processing of Personal Data in connection with Inheriti® Business, including Organisation Account administration, encrypted Protection Plans, Data Backup Plans, Business Continuity Plans, Member access, moderation, verification, recovery, support, security, and related service management.
The processing includes both Plan Metadata, which may be available to Organisation Administrators and other authorised users according to their roles, and Protected Plan Content, access to which is controlled by the applicable Protection Plan privacy setting (Shared Plan or Private Plan) and role-based permissions. Organisation Administrators may access Plan Metadata for Private Plans but may not access the Protected Plan Content of Private Plans through the Services.
For the term of these Terms (in respect of Inheriti® Business) and any additional period required to complete deletion, return, recovery, backup-cycle expiry, or legally required retention.
Processing may include: collection and account setup; authentication and authorisation; role and permission management; encryption and cryptographic key management; creation and management of Protection Plans; distribution and recovery of shares; Dead Man Switch and continuity-event processing; storage and retrieval of encrypted data; moderation and verification; device and SafeKey management; customer support; security monitoring and fraud prevention; service maintenance; backup and disaster recovery; and compliance with legal obligations.
For clarity, Plan Metadata may be accessible to Organisation Administrators for Private Plans, while Protected Plan Content of Private Plans is not accessible to Organisation Administrators through the Services.
The Organisation shall not intentionally upload special-category data, financial information, credentials, or other sensitive information unless the Organisation has determined that the processing is lawful and appropriate and has configured the Services accordingly. Where such information is uploaded, it shall be treated as Personal Data under this DPA.
This Annex B forms part of the Organisation Data Processing Addendum (Section 2.7). SafeTech shall maintain measures appropriate to the risks presented by the processing, including: