GovScape

Terms of Service

The terms on which GovScape (operating entity to be confirmed) provides GovScape. Commercial terms — fees, users, and the length of your subscription — are in your order form, which takes precedence over anything here that conflicts with it.

Last reviewed 9 September 2026

Draft — not yet published

This document is complete except for the facts below, which cannot be determined from the application and must be supplied before it is relied on:

  • Registered company name of the operating entity
  • Companies House company number
  • Registered office address
  • ICO registration reference (data protection fee)
  • A monitored inbox for privacy and data subject requests
  • Supabase project region — where the database, logins and uploaded files actually live
  • Sentry data residency — currently the US, with AUD-44 open to move it to the EU
  • Confirmation that a UK IDTA or SCC addendum is signed with every processor outside the UK

Filling in lib/legal/entity.ts removes this notice from every legal page.

1Who these terms are between

These terms are an agreement between GovScape (operating entity to be confirmed) (“we”) and the organisation subscribing to GovScape (“you”). If you are accepting them on behalf of an organisation, you confirm you have authority to bind it.

GovScape is a business product. It is not offered to consumers, and the statutory rights of a consumer do not apply.

2What we provide

A hosted service for recording and assessing an organisation’s AI and data governance position: an inventory of AI systems, processes and data assets; a control framework mapped to recognised standards; policy and evidence storage; risk and exception management; cost and exposure estimates; and AI-assisted extraction and drafting.

We may change how features work, and we may add or withdraw them. Where a change materially reduces the functionality you are paying for, we will tell you in advance.

3Your account

  • Keep credentials confidential, and tell us promptly if you believe an account has been compromised.
  • You are responsible for what your users do in the product. Every change is attributed and logged.
  • Named user accounts are personal. Sharing one defeats the audit trail that makes the record worth keeping.
  • You are responsible for removing access for people who leave your organisation.

4Your data, and what you must have the right to upload

You own everything you put into the product. We claim no rights over it beyond those needed to provide the service, and we do not use your content to train AI models.

You must have the right to upload what you upload. That includes personal data in policy documents and evidence files, and any content read from a system you connect. Where we process personal data on your behalf, our data processing agreement applies and forms part of these terms.

You must not upload anything unlawful, anything infringing someone else’s rights, or malicious code.

5AI output is not advice, and the accountability stays with you

This clause matters more than its length suggests, so it is stated plainly.

  • GovScape uses AI models to read documents and draft content. Model output can be wrong, incomplete, or confidently mistaken. Everything it produces is a draft for a person to review, and is recorded in the audit trail as machine-authored precisely so that review is possible.
  • Nothing in the product is legal, regulatory, financial or professional advice. Cost estimates, exposure figures, risk scores and readiness percentages are modelled estimates built on assumptions and on the data you have entered. They are a prioritisation aid. They are not a prediction of any fine, loss or regulatory outcome, and no one should represent them as one.
  • You remain accountable for your own regulatory compliance. Using this product does not transfer that accountability to us, and does not by itself make you compliant with any law, standard or framework.
  • Where you record a meeting or upload material containing other people’s personal data, obtaining any consent or notice required is your responsibility.

6Acceptable use

You must not:

  • Attempt to gain access to another customer’s data, or to any part of the system you have not been granted.
  • Probe, scan or load-test the service without our written permission. Legitimate security testing is welcome — ask first.
  • Circumvent rate limits, usage limits or metering, or resell access.
  • Use the product to build a competing service, or to extract its underlying frameworks or content wholesale.
  • Submit content you know to be false in order to influence an assessment result that will be shown to a third party.

We may suspend access immediately where use threatens the security or availability of the service for others. We will tell you why, and restore access once it is resolved.

7Fees

Fees, billing frequency and subscription length are set out in your order form. Unless it says otherwise, fees are exclusive of VAT, invoices are payable within 30 days, and fees paid are non-refundable on early termination for reasons other than our breach.

If an invoice is significantly overdue we may suspend access after giving you written notice and a reasonable opportunity to pay.

8Availability and support

We aim for the service to be available at all times, but it is provided without an uptime guarantee unless your order form includes a service level agreement. We carry out maintenance, and will give notice of planned work that will take the service offline.

The service depends on third parties named on our sub-processor list, including AI providers. An outage or a change at one of those providers can affect features that depend on it.

9Warranties and liability

We warrant that we will provide the service with reasonable skill and care. Beyond that, and to the extent the law allows, the service is provided as-is: we do not warrant that it will be uninterrupted or error-free, or that any estimate, score or assessment it produces is accurate or fit for a particular purpose.

Neither party excludes liability for:

  • death or personal injury caused by negligence;
  • fraud or fraudulent misrepresentation;
  • anything else that cannot lawfully be excluded.

Subject to that, neither party is liable for loss of profit, revenue, business, goodwill or anticipated savings, or for indirect or consequential loss. Each party’s total liability arising out of this agreement in any twelve-month period is limited to the fees paid or payable by you in that period.

For the avoidance of doubt, that limit applies to any claim founded on a cost estimate, risk score, exposure figure or readiness assessment produced by the product, and to any regulatory penalty, enforcement action or third-party claim brought against you. Clause 5 explains why: those outputs are modelled estimates for prioritisation, and the compliance decision is always yours.

10Confidentiality

Each party will keep the other’s confidential information confidential, use it only to perform this agreement, and protect it with at least reasonable care. This does not apply to information that is public through no fault of the receiving party, was already known to it, or must be disclosed by law.

11Intellectual property

We own the product, its control frameworks, its scoring and cost models, and everything in it other than your content. You get a non-exclusive, non-transferable right to use it for your own internal business purposes for the length of your subscription.

If you send us feedback or a feature request, we may act on it without obligation or payment. It does not affect your ownership of your own content.

12Term, termination, and getting your data out

The agreement runs for the term in your order form and renews as it provides. Either party may terminate for material breach that is not remedied within 30 days of written notice, or immediately if the other becomes insolvent.

On termination your access ends. For 30 days afterwards you may ask us to export your data, and we will provide it in a machine-readable format. After that we delete or return it in line with the data processing agreement, except for records we are required to keep — audit logs among them, as the privacy policy explains.

13General

  • Changes. We may update these terms. Material changes are notified to account holders by email at least 30 days before they take effect, and you may terminate before then if you do not accept them.
  • Assignment. Neither party may assign without the other’s consent, except to a successor of substantially the whole business.
  • Third parties. No one other than the parties has any right to enforce these terms.
  • Entire agreement. Your order form, these terms and the data processing agreement are the whole agreement between us. Where they conflict, the order form wins, then the data processing agreement on matters of personal data, then these terms.
  • Governing law. English law, and the courts of England and Wales have exclusive jurisdiction.

14Contact

Questions about these terms: sales@govscape.app. Data protection questions: sales@govscape.app.