IMPORTANT — PLEASE READ CAREFULLY
By accessing www.resolveandevolve.co, requesting a consultation, using our scan tools, or engaging our services in any capacity, you confirm that you have read, understood, and agree to be bound by these Terms & Conditions in their entirety. If you do not agree, you must immediately cease use of our website and services.
1. Definitions
The following terms have the meanings set out below wherever used in these Terms:
| Term | Meaning |
|---|---|
| "Company" / "We" / "Us" | Resolve & Evolve, a privacy, data protection, and cybersecurity consultancy registered in India, operating through www.resolveandevolve.co. |
| "Client" / "You" | Any individual, business, or legal entity that accesses our website, uses our tools, or engages our services. |
| "Services" | All offerings provided by the Company, including but not limited to privacy gap scans (free and paid), full compliance assessments, fractional DPO services, regulation readiness programmes, ISO/SOC gap scans, and audit readiness handholding. |
| "Report" | Any compliance gap assessment, scoring output, roadmap, or advisory document generated and delivered by the Company. |
| "Scan Tool" | The AI-assisted automated domain scanning and questionnaire system used by the Company to generate compliance assessments. |
| "Confidential Information" | Any non-public business, technical, operational, or legal information disclosed by either party in the course of an engagement. |
| "Intellectual Property" / "IP" | All methodologies, frameworks, scan logic, report templates, training data, software, branding, and written content owned or licensed by the Company. |
| "Personal Data" | Any information relating to an identified or identifiable natural person, as defined under the applicable privacy laws including the DPDP Act 2023, GDPR, and CCPA. |
| "Engagement Agreement" | A separate written agreement, proposal, or Statement of Work executed between the Company and a Client for a specific paid service. |
2. Scope of Terms & Acceptance
These Terms & Conditions govern:
- Your use of the Company's website, free tools, and publicly available resources.
- Your engagement of any paid or contracted Services.
- All communications, deliverables, and interactions between you and the Company.
These Terms are supplemented by, and should be read alongside:
- Our Global Privacy Notice (available at www.resolveandevolve.co/privacy).
- Our Cookie Policy (available at www.resolveandevolve.co/cookie).
- Any applicable Engagement Agreement or Statement of Work signed between the parties.
In the event of a conflict between these Terms and a signed Engagement Agreement, the Engagement Agreement shall prevail to the extent of the inconsistency.
3. Description of Services
The Company provides the following categories of services. Detailed scope, deliverables, and pricing for each are confirmed in the applicable Engagement Agreement or on the relevant service page of our website.
| Service | Description |
|---|---|
| Free Privacy Gap Scan | AI-assisted automated scan of a Client's domain. Outputs a compliance score and top-5 gap summary. No advisory opinion is provided. Subject to the limitations in Clause 7. |
| Full Privacy Gap Assessment | Deep domain scan combined with a structured Client questionnaire. Outputs clause-level gap mapping, penalty exposure analysis, prioritised remediation roadmap, and a readiness checklist. Reviewed and verified by an experienced privacy professional. |
| Fractional DPO Services | Ongoing privacy leadership and DPO function provided on a retainer or part-time basis. Scope defined in the Engagement Agreement. |
| Regulation Readiness Programme | End-to-end compliance build covering DPDPA 2023, GDPR, HIPAA, or other applicable frameworks; including documentation, notices, consent frameworks, DPIAs, and data maps. |
| ISO / SOC Gap Scan | AI-assisted scan mapped to ISO 27001, ISO 27701, and/or SOC 2 controls. Outputs a scored gap report with prioritised remediation actions. |
| ISO / SOC Audit Readiness | Full handholding from gap identification through to certification; including evidence library build, control framework implementation, and support through Stage 1 and Stage 2 audits. |
4. Client Engagement & Onboarding
4.1 Initiation of Services
Paid Services commence only upon: (a) execution of an Engagement Agreement or signed Statement of Work; and (b) receipt of the agreed initial payment, unless otherwise specified in writing by the Company.
4.2 Client Cooperation Obligations
The Client agrees to:
- Provide accurate, complete, and timely information and access as reasonably required by the Company to perform the Services.
- Respond to questionnaires, clarification requests, and follow-up queries within the timelines specified in the Engagement Agreement.
- Designate a point of contact with authority to provide instructions and approvals on behalf of the Client organisation.
- Notify the Company promptly of any material change to the Client's business operations, data processing activities, or regulatory status that may affect the scope of Services.
The Company's ability to deliver accurate and complete assessments is directly dependent on the quality and completeness of information provided by the Client. Delays or inaccuracies attributable to the Client shall not constitute a breach by the Company.
5. Fees, Payment & Invoicing
5.1 Fee Structure
All fees are as set out in the applicable Engagement Agreement, proposal, or published service pricing page. The Company reserves the right to revise its pricing at any time; revised pricing shall apply only to new engagements initiated after notice of the revision.
5.2 Payment Terms
- For assessment related engagements payments are to be made in advance for the commencement of services.
- For other related engagements, Invoices are due and payable within 14 (fourteen) days of the invoice date, unless otherwise specified in the Engagement Agreement.
- For project-based engagements, the Company typically requires a 50% advance payment prior to commencement, with the balance due upon delivery of the final deliverable.
- All fees are exclusive of applicable taxes (including GST), which shall be charged additionally at the prevailing rate.
5.3 Late Payment
Without prejudice to any other remedy available to the Company, overdue invoices shall attract interest at the rate of 1.5% per week (or the maximum rate permitted by applicable law, whichever is lower) from the due date until the date of actual payment. The Company reserves the right to suspend Services pending settlement of overdue amounts.
5.4 Expenses
Any pre-approved out-of-pocket expenses (including travel, third-party tool costs, or filing fees) incurred by the Company in the performance of Services shall be reimbursed by the Client at cost, with supporting documentation.
6. Intellectual Property Rights
6.1 Company IP
All Intellectual Property created, developed, or used by the Company in the provision of Services; including but not limited to scan methodologies, AI models, compliance frameworks, scoring logic, report templates, and pre-existing proprietary tools shall remain the exclusive property of the Company. Nothing in these Terms or any Engagement Agreement transfers any ownership of Company IP to the Client.
6.2 Client Deliverables
Upon full payment of all applicable fees, the Company grants the Client a non-exclusive, non-transferable, perpetual licence to use the specific deliverables (Reports, roadmaps, documentation) produced for the Client's own internal compliance and business purposes only.
6.3 Restrictions
The Client shall not:
- Reproduce, resell, sublicense, or distribute any Company deliverable or tool to any third party without prior written consent from the Company.
- Reverse-engineer, decompile, or attempt to extract the underlying methodology or logic of any Company scan tool or software.
- Represent Company-generated deliverables as the Client's own independent work in any regulatory filing, procurement process, or public representation.
6.4 Feedback & Improvements
Any feedback, suggestions, or ideas the Client provides regarding the Company's Services may be used by the Company without restriction or compensation to improve its tools and offerings.
7. Nature of Services, Limitations & No Legal Advice
This section is material. Please read it carefully.
The Company provides regulatory compliance advisory services, not legal advice. Our Services are intended to assist organisations in understanding and improving their compliance posture. They do not constitute, and should not be relied upon as, legal advice, legal opinions, or a guarantee of regulatory compliance or protection from enforcement action.
7.1 Automated Scan Limitations
The Free Privacy Gap Scan and automated components of the Full Privacy Gap Assessment operate by analysing publicly accessible information on the Client's domain. Accordingly:
- Scan results reflect the state of the domain at the time of the scan and may not capture all compliance gaps, particularly those relating to internal processes, third-party contracts, or back-end data handling.
- Automated outputs are a starting point for compliance review, not a definitive legal or regulatory determination.
- The Company does not warrant that a domain which achieves a high compliance score is fully compliant with all applicable laws.
7.2 Professional Verification
All paid Reports are reviewed and verified by an experienced privacy professional prior to delivery. Notwithstanding this, the Client is advised to seek independent legal counsel before making material compliance decisions based on any Report.
7.3 Regulatory Changes
Privacy and cybersecurity regulations evolve continuously. The Company endeavours to keep its frameworks current; however, the Company does not warrant that its deliverables will reflect regulatory amendments enacted after the date of delivery. Clients are responsible for monitoring regulatory developments applicable to their business.
8. Confidentiality
8.1 Mutual Obligation
Each party agrees to hold the other's Confidential Information in strict confidence, using at least the same degree of care it applies to protect its own confidential information (and in no event less than reasonable care). Neither party shall disclose the other's Confidential Information to any third party without prior written consent, except as expressly permitted under Clause 8.2.
8.2 Permitted Disclosures
Confidential Information may be disclosed to:
- Employees, contractors, or advisors of either party who have a need to know and are bound by equivalent confidentiality obligations.
- Regulatory or legal authorities when required by binding law, court order, or regulatory mandate — provided the disclosing party gives the other as much prior written notice as is legally permissible.
8.3 Exclusions
Confidentiality obligations do not apply to information that: (a) is or becomes publicly known through no fault of the receiving party; (b) was rightfully known to the receiving party prior to disclosure; (c) is independently developed by the receiving party without reference to the Confidential Information; or (d) is received from a third party without restriction.
8.4 Survival
Confidentiality obligations survive termination or expiry of these Terms or any Engagement Agreement for a period of 3 (three) years.
8.5 Non-Solicitation
During the term of any engagement and for 12 (twelve) months thereafter, neither party shall directly solicit for employment any key personnel of the other party who was materially involved in the engagement, without prior written consent.
9. Data Protection & Privacy
9.1 As Data Controller
In respect of personal data collected from the Client and its representatives through the website and during the course of an engagement, the Company acts as a Data Controller/Data Fiduciary and processes such data in accordance with its Global Privacy Notice, available at www.resolveandevolve.co/privacy.
9.2 As Data Processor
Where the Company processes personal data on behalf of the Client in the course of delivering Services (for example, when scanning datasets provided by the Client), the Company acts as a Data Processor. In such cases, the parties shall execute a Data Processing Agreement (DPA) governing such processing prior to commencement of the relevant Services.
9.3 Client's Responsibility
The Client warrants that it has all necessary rights, permissions, and consents to share any personal data or organisational data with the Company for the purpose of receiving the Services. The Client indemnifies the Company against any claim arising from the Client's failure to comply with this warranty.
9.4 Security Measures
The Company applies industry-standard technical and organisational measures to protect all data processed in connection with the Services, including encryption in transit and at rest, role-based access controls, and regular security assessments. Details are available in the Company's Privacy Notice.
10. Representations & Warranties
10.1 Company Warranties
The Company represents and warrants that:
- It has full authority to enter into and perform obligations under these Terms and any Engagement Agreement.
- Services will be performed with reasonable skill, care, and diligence by suitably qualified and experienced professionals.
- It maintains appropriate professional indemnity insurance.
- It will comply with all applicable laws in the performance of the Services.
10.2 Client Warranties
The Client represents and warrants that:
- It has full authority to enter into and perform obligations under these Terms and any Engagement Agreement.
- All information and materials provided to the Company are, to the best of the Client's knowledge, accurate, complete, and not misleading.
- Its use of the Services will comply with all applicable laws and will not infringe the rights of any third party.
10.3 Disclaimer of Implied Warranties
Save as expressly stated in Clause 10.1, all warranties, conditions, and representations; whether express, implied, statutory, or otherwise are excluded to the fullest extent permitted by applicable law, including any implied warranties of merchantability, fitness for a particular purpose, or non-infringement.
11. Limitation of Liability
Liability Cap: To the maximum extent permitted by applicable law, the Company's total aggregate liability to the Client; whether in contract, tort (including negligence), breach of statutory duty, or otherwise shall not exceed the total fees paid by the Client to the Company in the 3 (three) months immediately preceding the event giving rise to the claim.
11.1 Exclusion of Consequential Loss
The Company shall not be liable for any: (a) loss of profits or revenue; (b) loss of business or contracts; (c) loss of anticipated savings; (d) loss of data; (e) damage to reputation or goodwill; (f) regulatory fines, penalties, or enforcement actions; or (g) any indirect, special, or consequential loss, howsoever arising even if the Company has been advised of the possibility of such loss.
11.2 Regulatory Enforcement
The Company expressly disclaims liability for any regulatory fines, penalties, enforcement actions, or legal proceedings brought against the Client by any data protection authority, information commissioner, or other regulatory body. Compliance outcomes remain the Client's sole responsibility.
11.3 Exceptions
Nothing in these Terms limits or excludes liability for: (a) death or personal injury caused by negligence; (b) fraud or fraudulent misrepresentation; or (c) any other liability that cannot be excluded or limited under applicable law.
12. Indemnification
The Client shall indemnify, defend, and hold harmless the Company and its officers, directors, employees, advisors, and contractors from and against any claims, liabilities, damages, losses, costs, and expenses (including reasonable legal fees) arising out of or relating to:
- The Client's breach of these Terms or any Engagement Agreement.
- The Client's breach of any applicable law or regulation.
- Any inaccuracy or misrepresentation in information provided by the Client.
- The Client's use of Company deliverables in a manner not authorised under these Terms.
- Any third-party claim arising from the Client's data processing activities.
13. Term & Termination
13.1 Term
These Terms apply for the duration of any use of the Company's website or engagement of Services. Individual engagements are subject to the term specified in the applicable Engagement Agreement.
13.2 Termination for Convenience
Either party may terminate an ongoing engagement by providing 30 (thirty) days' written notice to the other party. The Client shall pay for all Services performed and expenses incurred up to the effective date of termination. The Company shall refund any pre-paid fees attributable to Services not yet performed, less a reasonable administrative fee.
13.3 Termination for Cause
Either party may terminate an engagement immediately upon written notice if the other party: (a) commits a material breach that is incapable of remedy, or fails to remedy a remediable breach within 14 days of written notice; (b) becomes insolvent or enters any form of administration, liquidation, or bankruptcy proceeding; or (c) engages in fraudulent, illegal, or grossly negligent conduct.
13.4 Effect of Termination
Upon termination: (a) all outstanding fees become immediately due and payable; (b) each party shall return or securely destroy the other's Confidential Information; (c) licences granted to the Client under Clause 6.2 survive in respect of deliverables for which full payment has been received; and (d) Clauses 6, 7, 8, 9, 11, 12, 14, 15, and 16 survive termination indefinitely.
14. Force Majeure
Neither party shall be liable for any failure or delay in performing its obligations under these Terms to the extent that such failure or delay is caused by circumstances beyond that party's reasonable control, including acts of God, war, civil unrest, terrorism, pandemic, government action, natural disaster, widespread internet or infrastructure outages, or failure of third-party systems outside the party's control. The affected party shall notify the other promptly and use reasonable endeavours to mitigate the impact. If a force majeure event continues for more than 60 days, either party may terminate the affected engagement without liability on 14 days' written notice.
15. Acceptable Use of Website & Tools
By accessing the Company's website and tools, you agree that you will not:
- Use the website or any tool for any unlawful, fraudulent, or malicious purpose.
- Attempt to gain unauthorised access to any part of the website, its underlying systems, or any connected infrastructure.
- Introduce viruses, malware, or any other harmful code or material.
- Scrape, harvest, or systematically extract data from the website without prior written consent.
- Use the Free Scan tool to generate reports for resale or distribution without the Company's prior written consent.
- Attempt to reverse-engineer or extract the underlying logic of any scan tool or AI model.
- Use the website or Services in any way that could damage the Company's reputation or cause harm to other users.
The Company reserves the right to suspend or permanently terminate access to any user or organisation found to be in breach of this clause, without notice and without liability.
16. Third-Party Links, Tools & Services
Our website may contain links to third-party websites or refer to third-party tools. These are provided for information only. The Company has no control over, and accepts no responsibility for, the content, privacy practices, or availability of any third-party website or service. A link does not constitute an endorsement by the Company.
17. Amendments to These Terms
The Company reserves the right to update or modify these Terms at any time. Material changes will be notified via a prominent notice on the website and, where practicable, by email to registered users. The updated Terms take effect from the date of publication. Your continued use of the website or Services after that date constitutes acceptance of the revised Terms.
18. General Legal Provisions
18.1 Governing Law
These Terms, and any dispute or claim arising out of or in connection with them (including non-contractual disputes), shall be governed by and construed in accordance with the laws of India. Where a Client is based in the European Economic Area or the United Kingdom, applicable consumer or business protection laws of the Client's jurisdiction shall apply to the extent required by law.
18.2 Dispute Resolution
The parties shall first attempt to resolve any dispute through good-faith negotiation. If a dispute is not resolved within 30 days of written notice, either party may refer the matter to arbitration under the Arbitration and Conciliation Act, 1996 (India), with a sole arbitrator appointed by mutual agreement. The seat and venue of arbitration shall be Bangalore, India. The language of arbitration shall be English.
18.3 Jurisdiction
Subject to the arbitration clause above, the courts of Bengaluru, Karnataka, India shall have exclusive jurisdiction over any matter arising out of or in connection with these Terms.
18.4 Entire Agreement
These Terms, together with the Global Privacy Notice, Cookie Policy, and any applicable Engagement Agreement, constitute the entire agreement between the parties with respect to the subject matter hereof and supersede all prior agreements, representations, and understandings.
18.5 Severability
If any provision of these Terms is found to be invalid, illegal, or unenforceable by a court of competent jurisdiction, the remaining provisions shall continue in full force and effect.
18.6 No Waiver
No failure or delay by either party in exercising any right or remedy under these Terms shall constitute a waiver of that right or remedy. A waiver is only effective if given in writing and signed by an authorised representative of the waiving party.
18.7 Assignment
The Client may not assign, transfer, or sub-contract any of its rights or obligations under these Terms without the prior written consent of the Company. The Company may assign its rights and obligations to any successor entity in the context of a merger, acquisition, or corporate restructuring, provided the successor assumes all obligations herein.
18.8 Notices
All formal notices under these Terms must be in writing and sent by email with read-receipt confirmation, or by registered post to the address of the receiving party. Notices to the Company shall be addressed to legal@resolveandevolve.in.
18.9 Relationship of Parties
The Company and the Client are independent contractors. Nothing in these Terms creates any partnership, joint venture, agency, franchise, or employment relationship between the parties.
19. Contact Us
For any questions, concerns, or requests relating to these Terms, please contact:
| Legal & Contractual Queries | support@resolveandevolve.co |
|---|---|
| Privacy Matters | privacy@resolveandevolve.in |
| Grievance Officer | Amrita Grover, Independent Privacy Counsel — grievance@resolveandevolve.in |
| Registered Address | Resolve & Evolve, Bangalore, Karnataka, India |
| Website | www.resolveandevolve.co |
We practise what we preach. Privacy. Security. Compliance. Built from the inside out.