Contract documents and data processing
These terms include the Data Processing Terms in Appendix A. Section 1 explains how Orders, individually negotiated agreements and the related notices apply.
1. Agreement, eligibility and documents
Sytance Technologies Limited (序衡科技有限公司) provides Sytance. These Terms of Service, including Appendix A where applicable, govern the Service between that company (“Sytance”, “we” or “us”) and the Customer. A person accepting in an individual capacity is the Customer; a person accepting with authority for an organisation binds that organisation as the Customer.
The Service is available to eligible individuals and organisations worldwide, subject to applicable law and service availability. Every registrant and Authorised User must be at least 18 years old and have reached the legal age of majority where they live. Minors must not register. Account registration or completion of an invitation requires an affirmative adult declaration and acceptance of these terms. Marketing consent is separate and optional.
“Service” means the online hosted Sytance platform, its included features and documentation. It does not include self-hosting, private deployment or professional consulting engagements unless separately agreed. “Authorised User” means a person the Customer permits to use the Service. “Order” means a mutually accepted order form, confirmed online checkout or other written purchase agreement identifying the purchased plan.
An individually negotiated agreement prevails over these terms to the extent of an express conflict. An Order determines the purchased plan, price, billing period and quantities; it does not silently waive data-protection obligations. Appendix A governs processing on the Customer’s behalf and prevails over inconsistent general terms on that subject, subject to mandatory law and any applicable mandatory transfer clauses. The AI and Customer Data notice’s no-training commitments form part of these terms. The Privacy and Cookie Notices explain data practices and do not substitute for a processing agreement or grant additional content-use rights.
2. Use of the service
Sytance is a product cybersecurity and compliance software service. Subject to these terms and the applicable plan or Order, the Customer may allow its Authorised Users to access and use the Service for the Customer’s own lawful purposes during the service term.
The Customer must use the Service and documentation in accordance with applicable law, these terms, and any user, workspace, storage, usage, or feature limits stated in the Service, plan, or Order.
Rights granted under these terms are limited, non-exclusive, non-transferable, and non-sublicensable except as expressly permitted in an Order. No ownership interest in the Service is transferred to the Customer.
3. Availability, support, and changes
We may maintain, update, secure, or change the Service to improve functionality, address risk, comply with law, or reflect changes in technology and providers. A change will not materially reduce the core paid functionality during a current service term unless reasonably necessary for security, legal compliance, third-party dependency, or service integrity.
Planned maintenance, emergency maintenance, internet conditions, third-party dependencies, and events outside reasonable control may affect availability. Any binding support response time, uptime commitment, service credit, or business-continuity requirement applies only if stated in an Order or other written agreement.
Features identified as beta, preview, evaluation, or experimental may be incomplete, changed, suspended, or withdrawn and should not be used as the sole basis for a production, regulatory, or safety-critical decision.
4. Accounts and access
- Account information must be accurate and kept current.
- Each user must use an individual account and protect their credentials.
- The Customer is responsible for approving, reviewing, and removing user access and for activity conducted through its accounts, except to the extent caused by our breach of these terms.
- Suspected unauthorised access must be reported promptly to support@sytance.com.
5. Customer Content
“Customer Content” means data, files, records, instructions, and other material submitted to the service by or for the Customer, together with material generated for the Customer from those inputs. As between the parties, the Customer retains its rights in Customer Content.
The Customer authorises Sytance Technologies Limited and its service providers to host, copy, transmit, process, display, protect, support, return, and delete Customer Content only as reasonably needed to provide and secure the Service, follow the Customer's instructions, enforce the agreement, and comply with law.
The Customer is responsible for the accuracy and lawfulness of Customer Content and for obtaining all rights, notices, and permissions required for its use in the service.
The Customer should maintain appropriate source records and backups for information that it cannot reasonably recreate. The Service is not a substitute for the Customer's required records-management, disaster-recovery, or regulated archival controls unless an Order expressly says otherwise.
The Customer must designate persons authorised to administer its workspace and purchasing arrangements and keep their contact details current. Invitations do not transfer ownership of an organisation’s workspace to the invitee. Users must respect access restrictions after a change of role, departure or removal by an administrator.
If account authority or ownership is disputed, we may seek proportionate evidence and restrict the disputed access while reviewing it. We do not resolve employment or corporate ownership disputes, and we do not transfer content solely on an unsupported request.
No permission is granted to use Customer Content for advertising, public case studies, model training or fine-tuning. We will not publish the Customer’s name, logo or identifiable workspace material as an endorsement without separate authorisation. Operational access remains limited to the purposes authorised by these terms and, for personal data, Appendix A.
Rights in generated material are allocated to the Customer as between the parties to the extent those rights exist and may lawfully be transferred. This does not guarantee that an AI output is unique, copyrightable or free from third-party rights. Pre-existing Sytance software and templates, and third-party standards or other materials, remain subject to their respective rights. The Customer may use embedded Sytance template elements as part of its generated deliverables for its legitimate business or personal purposes, but may not distribute our template library as a competing standalone product.
6. AI-assisted features
AI-assisted features produce analysis and draft material from instructions and context supplied through the service. Output may be incomplete, inaccurate, or unsuitable for a particular purpose.
The Customer must review and validate output before relying on it, implementing it, placing it in controlled documentation, or submitting it to a customer, assessor, certification body, or authority.
Sytance supports professional work but does not replace engineering, security, quality, regulatory, legal, or management judgement. Use of the service does not by itself establish compliance, certification, or regulatory approval.
7. Acceptable use
The Customer and its authorised users must not:
- Use the service for unlawful, fraudulent, deceptive, or abusive activity.
- Submit malware, harmful code, unlawfully obtained credentials, or material that infringes another person's rights.
- Circumvent access controls, tenant boundaries, rate limits, billing controls, or security safeguards.
- Interfere with the service or conduct denial-of-service, destructive, or unauthorised security testing.
- Attempt to access another customer's account, data, or systems without permission.
- Copy, resell, sublicense, or reverse engineer the service except where expressly permitted by law or written agreement.
8. Plans, trials, billing and cancellation
The price, currency, billing period, quantities, taxes and included features are shown in the Order or checkout before the Customer confirms purchase. The Customer must provide accurate billing information and authority to use the chosen payment method. Stripe processes payment and subscription transactions; Sytance remains the service provider responsible for delivery and support. Any bank or currency-conversion charge is governed by the Customer’s arrangement with its payment institution.
Subscriptions renew automatically at the interval disclosed at checkout until renewal is cancelled. The Customer authorises the disclosed recurring charges. Renewal can be cancelled through the account’s billing-management link; if that link is inaccessible, contact support@sytance.com. Cancellation must be completed before the next renewal charge to prevent that renewal. Cancelling renewal preserves access for the current paid period and does not itself close the account or delete data.
We do not offer voluntary refunds. Except where applicable law requires otherwise, payments are non-refundable for unused or partly used periods, early cancellation or a change of mind. This rule does not exclude mandatory withdrawal, refund, repair, price-reduction or other consumer remedies. Contact support@sytance.com about duplicate, unauthorised or incorrectly calculated charges so they can be investigated; the rule does not authorise us to retain a charge that was not properly due.
If payment fails, we may notify the Customer and use the retry process available through the payment service. A failed payment does not create an indefinite extension of paid access. Once paid entitlement expires, existing workspace content remains viewable, but editing, generation, document download and other commercial exports are unavailable. A valid paid plan restores the corresponding permissions. Security restrictions and suspended or deleted accounts remain governed by section 12.
A free trial creates no payment obligation unless the Customer separately confirms a paid subscription. Trial duration and limitations are those disclosed when it is activated. Paid-plan expiry rights do not automatically extend a trial or grant paid functionality to a free account.
Any change of price or renewal conditions is communicated before the affected renewal, with sufficient information and time to cancel as required by applicable law. A plan change takes effect on the date and on the charging or credit basis disclosed before confirmation. We do not infer consent to an undisclosed additional charge merely from continued access to stored content.
Where a consumer has a statutory withdrawal or cancellation right, the request may be made by an unequivocal statement to support@sytance.com identifying the account and purchase; no explanation is required where the law does not require one. Cancelling auto-renewal and exercising a statutory withdrawal right are separate actions. Beginning to use a SaaS service does not, by itself, waive such a right. Any required request for early performance, acknowledgement, additional trader information or statutory withdrawal facility must be provided through the applicable purchasing process; these general terms do not replace it. Any legally required repayment is handled within the applicable statutory period.
For an eligible consumer distance-service contract subject to EU/EEA or UK cancellation rules, the initial withdrawal period is generally 14 days after the contract is concluded, without giving a reason. Sending the withdrawal statement before the applicable deadline is sufficient. Any longer period or additional renewal right required by applicable law remains available, including an extension caused by failure to provide required information. Buying in an individual’s name does not alone establish consumer status; the purpose of the purchase and applicable law determine it.
If the consumer expressly requests performance during that period and the law permits it, a proportionate amount for the Service actually supplied before withdrawal may be payable. We do not infer that request or the loss of a cancellation right merely from registration, login or general acceptance of these terms. Any exception based on full performance requires the prior request and informed acknowledgement required by law; an ongoing subscription is not treated as fully performed merely because access has been activated.
Where those rules require reimbursement following a valid withdrawal, we repay the amount legally due without undue delay and within 14 days after notice of withdrawal, using the original payment method unless another method is expressly agreed, without a repayment fee. These are statutory remedies, not a voluntary refund offer. For a service defect or other complaint, identify the affected purchase and problem through support@sytance.com; we investigate, explain the outcome and provide any remedy required by applicable law.
9. Sytance intellectual property
Sytance Technologies Limited and its licensors retain all rights in the service, software, technology, documentation, templates, trademarks, and related intellectual property, excluding Customer Content.
Sytance Technologies Limited may use feedback to develop and improve the service, provided that the use does not identify the Customer or disclose Customer Content.
10. Third-party services and dependencies
The Service may interoperate with or link to a third-party service that the Customer independently selects or enables. The third party's terms and privacy practices govern the Customer's direct use of that service, and the Customer authorises the exchange of information needed for the integration.
Providers selected by Sytance Technologies Limited to host, secure, support, or deliver the Service operate under our arrangements rather than a separate customer instruction. Our responsibility for those providers is governed by the applicable customer agreement and law.
We do not control a third-party service that the Customer independently accesses. A change, outage, or restriction introduced by a third party may affect an integration or dependent feature.
11. Confidentiality and data protection
“Confidential Information” includes non-public Customer Content, security information, business and technical information, and information identified as confidential or reasonably understood to be confidential from its nature and disclosure circumstances. Each party must use at least reasonable care to protect the other’s Confidential Information, use it only for the service relationship and disclose it only to persons who need it and are bound by appropriate confidentiality duties.
Information is excluded only to the extent the receiving party can establish that it was already lawfully known without restriction, became public without a breach, was lawfully received from another source without a confidentiality duty, or was independently developed without using the disclosed information. Compelled disclosure is limited to what the law requires; where permitted, the receiving party gives advance notice and reasonable cooperation to seek protection.
The Privacy Notice explains processing for our own purposes. Appendix A applies automatically, without a separate signature, to personal data we process for the Customer under this agreement. Additional signed data terms may supplement it. Neither a confidentiality exception nor a general content licence permits model training or overrides a personal-data protection requirement.
12. Suspension, termination, and data return
We may impose necessary and proportionate access restrictions for security risks, unlawful or prohibited conduct, material breach, harm to others or legal requirements. Where practicable, we will explain the reason and provide a reasonable opportunity to remedy it. Ordinary paid-plan expiry follows the viewing-access rule and is separate from account suspension for security or legal reasons.
The Customer may stop using the Service and cancel renewal through billing management. A remediable material breach must be remedied within the reasonable period specified in written notice or, if none is specified, within 30 days. Either party may terminate the affected agreement if the breach remains unremedied at that point.
Cancellation of renewal or paid-plan expiry does not automatically delete Customer Content. Workspace content is retained until the Customer deletes it or makes a valid deletion request, subject to the Privacy Notice’s deletion, backup and legal-retention provisions. Customers needing commercial exports should complete them during paid access. Statutory personal-data rights requests do not require a paid plan.
Provisions that by their nature should survive remain effective after termination, including accrued payment obligations, intellectual property, confidentiality, liability limitations and dispute resolution.
A restriction should be limited to the affected users, data or functions where reasonably practicable. We may act immediately if delay would create material security risk or breach a legal requirement. Where permitted, we explain the reason, available remedial steps and how to request review through support@sytance.com. Access is restored when the relevant grounds are resolved and the applicable account and entitlement conditions are met.
If we discontinue the Service as a whole, we will give reasonable advance notice where practicable and provide a reasonable opportunity to retrieve retained Customer Content or instruct deletion. Where normal paid export is unavailable, contact support@sytance.com to arrange that retrieval. Data return required by Appendix A or mandatory law is not conditional on buying a new subscription. Ordinary plan expiry otherwise remains subject to the browsing and export rules in section 8.
13. Warranties and disclaimers
We will provide the service with reasonable care and skill. Except as expressly stated in a written agreement and to the maximum extent permitted by law, the service and its output are otherwise provided on an “as is” and “as available” basis.
We do not warrant uninterrupted or error-free operation, identification of every vulnerability or defect, or that output will satisfy a particular law, standard, certification, or customer requirement.
Nothing in these terms excludes a right or remedy that cannot lawfully be excluded.
14. Liability
To the maximum extent permitted by law, neither party is liable for indirect, incidental, special, punitive, or consequential loss, or for loss of profit, revenue, business opportunity, goodwill, or anticipated savings.
Unless a written agreement states otherwise, the total liability of Sytance Technologies Limited arising from the service will not exceed the fees paid or payable by the Customer for the service during the twelve months before the event giving rise to the claim.
Nothing in these terms excludes or limits liability for fraud or fraudulent misrepresentation, death or personal injury caused by negligence, or any other liability that cannot lawfully be excluded or limited. Each limitation applies only to the extent permitted by applicable law.
15. General
These terms, the applicable order, and any documents expressly incorporated into them form the agreement concerning the service. If a provision is unenforceable, it will be limited to the minimum extent necessary; the remaining provisions will continue in effect.
Neither party is responsible for delay or failure caused by an event beyond its reasonable control, except that this does not excuse payment already due. A failure to enforce a provision is not a waiver. The Customer may not assign the agreement without our consent, which will not be unreasonably withheld in connection with a genuine corporate reorganisation or sale of substantially all relevant business assets.
We may update these terms for future use of the Service. We will give reasonable notice of a material change where required by law or agreement. A material change will not retroactively reduce rights already accrued.
These terms are governed by Hong Kong law. For non-consumer Customers, Hong Kong courts have exclusive jurisdiction, except that either party may seek urgent protective relief in a competent court. Consumers retain non-excludable protections under the applicable law of their habitual residence and statutory rights to bring proceedings in a competent court.
Send legal notices to legal@sytance.com unless an applicable agreement specifies another procedure.
Legal notices to Sytance should be sent to legal@sytance.com and identify the account, subject and requested action. We send contractual notices to the Customer’s current account or designated contractual email, or through a channel agreed in writing. A notice takes effect on receipt as determined by applicable law; displaying revised text alone does not replace a legally required individual notice or consent.
Chinese and English versions are intended to express the same agreement. If there is a substantive discrepancy, the language expressly agreed in an individually negotiated contract prevails; otherwise, the version in which the Customer accepted these terms governs that discrepancy, subject to mandatory consumer protections. Language selection does not change the scope of statutory rights.
If a dispute arises, either party may describe it to the other in writing and seek a good-faith resolution. That process does not prevent urgent relief, regulatory complaints, mandatory consumer remedies or timely court proceedings, and it does not automatically suspend a legal limitation period.
Appendix A. Data Processing Terms — scope
This Appendix is a binding part of the agreement wherever Sytance processes personal data contained in Customer Content on the Customer’s behalf (“Customer Personal Data”). It applies for as long as we or our subprocessors hold that data for the Customer, including retained browsing access and authorised deletion or return activities. It does not govern a separate controller’s processing for its own purposes, such as legally required payment-provider records.
The Customer is the controller or a processor authorised by its controller; Sytance is its processor or subprocessor, as applicable. Each party complies with the data-protection law applicable to its role. “Personal data breach” means a security breach resulting in accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer Personal Data.
A.1. Processing particulars
The processing concerns providing the hosted product cybersecurity and compliance workspace and the functions requested by the Customer. The Order, workspace configuration and authorised requests identify the relevant services and instructions. The Customer determines which records it submits and remains responsible for data minimisation.
Data subjects may include the Customer’s personnel, contractors, suppliers, business contacts and individuals described in product or security records. Personal data may include names, work roles, contact details, account or record identifiers, correspondence and incidental personal information in uploaded files, evidence, instructions and generated material. Product architecture and technical data fall within this Appendix to the extent they identify an individual.
Operations include receiving, recording, organising, hosting, retrieving, consulting, transmitting for requested processing, generating associated drafts, maintaining access and audit records, and returning or deleting data. Processing continues during the service relationship, retained workspace access and the completion of return, deletion or legally required restricted retention.
The Service does not require sensitive personal data, identity documents, payment-card credentials, passwords or secrets in workspace content. The Customer must not submit such data without a lawful need and safeguards appropriate to the actual processing. This Appendix does not represent that the Service is suitable for every special-category or regulated-data use case.
A.2. Instructions and permitted purposes
Sytance processes Customer Personal Data only on documented Customer instructions, including this agreement, the selected Service, authorised in-product actions and written support instructions, unless applicable law requires otherwise. Instructions include authorised transfers needed for the requested Service, subject to A.5. We inform the Customer of a legal processing requirement before acting unless the law prohibits that notice.
We do not sell Customer Personal Data, use it for independent marketing, or use it to train or fine-tune models. The prohibition applies to Sytance and external AI providers and includes inputs, prompts, files, context and outputs. We do not combine customer datasets for unrelated purposes. Processing necessary to deliver an inference or protect the requested Service does not grant rights for other use.
If we consider an instruction contrary to applicable data-protection law, we promptly inform the Customer and may suspend the affected processing while seeking a lawful instruction. We do not silently substitute a broader purpose. The Customer must have authority for its instructions and provide required notices and permissions to affected individuals.
A.3. Confidentiality and security measures
Personnel authorised to process Customer Personal Data must be subject to contractual or statutory confidentiality obligations. Access is limited to the work they are authorised to perform. We maintain technical and organisational measures appropriate to processing risks, taking account of the nature and sensitivity of the data, available safeguards and the potential impact on individuals.
Measures include authenticated access and role-based permissions; tenant and workspace access boundaries; protected transmission for service communications; controlled operational access; security-relevant logging and incident handling; vulnerability and change management; and procedures to restrict, return or delete data. Recovery and backup handling must protect confidentiality and prevent deleted data from being reintroduced into normal use.
We review and adapt safeguards as the Service and risks change and will not materially reduce the overall protection of Customer Personal Data during the processing relationship. We provide relevant security information on request under confidentiality protections. This Appendix does not claim a particular certification, universal encryption of every storage medium, a fixed recovery time or uninterrupted availability.
A.4. Subprocessors
The Customer gives general written authorisation for Sytance to use subprocessors necessary to provide hosting, infrastructure, communications, security, support and requested AI processing. Before entrusting Customer Personal Data to a subprocessor, we must impose written obligations that provide substantially equivalent protection for the relevant processing. We remain responsible to the Customer for the subprocessor’s performance of those obligations.
We make available to the Customer the relevant subprocessors’ legal identities, service roles and processing countries through privacy@sytance.com, including before processing where required. Naming provider categories publicly does not replace information that must be supplied to a Customer or individual by law. A confidentiality arrangement may protect commercial information but must not prevent legally required disclosure.
We inform affected Customers in advance of an intended addition or replacement, using their account or designated privacy contact, and allow a reasonable opportunity to object on substantiated data-protection grounds before the new processing starts. We discuss reasonable alternatives or safeguards. If an objection cannot be resolved, the affected processing must not proceed for that Customer without a lawful basis and authorisation; the parties may terminate the affected service and arrange return or deletion. Emergency changes do not waive required prior authorisation or statutory notice duties.
A.5. Processing locations and international transfers
Current application servers are in Hong Kong; supporting services may process data elsewhere. Sytance does not promise that all content, logs or backups remain in one country or offer self-hosting or private deployment. We provide the relevant recipient, location and safeguard information on request and whenever required by law.
Where data-protection law requires an adequacy basis, standard contractual clauses, a UK transfer instrument, an assessment, filing, authorisation or another safeguard, the parties must establish the applicable mechanism before the restricted transfer. This Appendix is not itself a completed transfer instrument. Sytance must cooperate with the Customer on the necessary information and safeguards and must not rely solely on general service acceptance to bypass those requirements.
A.6. Personal data incidents
Sytance notifies the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. We do not wait for a complete investigation before providing an initial notice. The notice is sent to the Customer’s designated security or privacy contact, or its account contact if none is designated.
As information becomes available, we describe the nature of the incident, affected data and individuals including approximate numbers where known, likely consequences, containment and corrective action, and a contact for follow-up. We provide updates when facts are incomplete, preserve relevant evidence and cooperate reasonably with the Customer’s response.
The Customer determines notifications to individuals and authorities for processing it controls, with our assistance; we make any notification independently required of us by law. Incident assistance and notice are not an admission of fault, and commercial liability provisions do not excuse statutory notification duties.
A.7. Rights requests and compliance assistance
Taking account of the processing and information available to us, Sytance provides reasonable technical and organisational assistance for the Customer to respond to individual rights requests, secure processing, assess data-protection impacts and consult a supervisory authority where required. We promptly pass on requests concerning Customer-controlled data and do not decide them independently unless authorised or legally required.
The Customer supplies enough information to identify the relevant records and confirm its instructions. Routine legally required assistance is not conditional on purchase of a new plan. If the Customer requests additional work beyond our statutory and agreed obligations, its scope and any reasonable charge must be agreed before that work starts; such arrangements must not obstruct legal rights or deadlines.
A.8. Return, deletion and continuing retention
Cancelling renewal or reaching paid expiry does not end the retained browsing service and is not an instruction to delete all Customer Personal Data. When the Customer ends that processing service or gives a valid deletion instruction, Sytance must, at the Customer’s choice, return or delete the relevant Customer Personal Data and delete remaining copies, except to the extent applicable law requires retention.
Where the Customer chooses return, we agree a secure, reasonably usable format and arrange return before deletion. This applies to Customer Personal Data governed by this Appendix and does not create unlimited access to paid generation or export features. A statutory or contractual return under this Appendix is not conditional on renewing a paid subscription.
Deletion is performed as soon as practicable after verifying the instruction, including instructions to relevant subprocessors. Recovery copies remain protected and unavailable for ordinary processing until overwritten or expired under the necessary backup rotation. We explain remaining categories, reasons and applicable completion criteria on request and confirm completion of the agreed deletion scope. Any data retained by legal requirement is isolated from other uses and deleted when that requirement ends.
A.9. Accountability and audits
Sytance makes available information reasonably necessary to demonstrate compliance with this Appendix and permits and contributes to audits required by applicable data-protection law, including inspections by the Customer or an independent auditor it appoints. The parties first use relevant documentation, written answers and available independent reports where these provide adequate evidence.
Where further audit is reasonably necessary, the parties coordinate scope, timing, confidentiality and secure access to protect other customers and service continuity. An auditor must be independent, suitably qualified and bound by confidentiality. Ordinary advance notice and proportionate limits may apply, but must not prevent a regulator’s powers or urgent investigation of a breach or credible non-compliance. We address established deficiencies and provide appropriate follow-up evidence.
Requests concerning this Appendix should be sent to privacy@sytance.com. Its confidentiality, security, assistance and deletion duties continue for as long as the relevant Customer Personal Data is retained.