This English text is provided for convenience. The authoritative version is the Romanian one and, in the event of any divergence, it prevails.
1Preamble, provider and definitions
1.1.The Provider.The 4Tify platform and services (together, “4Tify”) are supplied by TECHCORNER S.R.L., a Romanian company with its registered office at str. Slt. Radu Teoharie, bl. D3, sc. B, et. 1, ap. 21, Târgu Neamț, Neamț county, 615200, Romania, registered with the Trade Register under no. J2025025184003, VAT no. 51592659 (the “Provider”, “we”). Contact: [email protected], website: https://4tify.io.
1.2.Nature of this document.These Terms and Conditions (the “Terms”) constitute the framework agreement between the Provider and the Client for the use of the 4Tify platform and services. The Terms are supplemented by the Annexes specific to each service (Annexes A–F), by the Data Processing Agreement (Annex G), by the data protection notice (Annex H), by the accepted Offer/Order and, where applicable, by the Authorisation Letter.
1.3.Business-to-business only (B2B).The Services are intended exclusively for legal entities, authorised natural persons and other professionals within the meaning of art. 3 of the Romanian Civil Code. The Services are not offered to consumers. By accepting the Terms, the Client declares that it acts for the purposes of its professional activity.
1.4.Definitions.For the purposes of these Terms:
- Client – the entity that creates an account, places an Order or signs an Offer for Services.
- User – any natural person to whom the Client grants access to its 4Tify account.
- Platform – the 4Tify web application, the dashboard, the APIs and the reports accessible through 4tify.io.
- Services – the services described in Annexes A–F: vulnerability scanning, penetration testing, AI-assisted code analysis, Deep/Dark Web monitoring, Attack Surface Management and Bug Hunting.
- Targets (In-Scope Assets) – the domains, subdomains, IP addresses, applications, APIs, code repositories, email addresses and names declared by the Client and validated under Section 3.
- Scope – the exhaustive list of Targets and permitted activities, set out in the Order or in the Authorisation Letter.
- Authorisation Letter – the written declaration, signed by the Client's legal representative (and, where applicable, by the third parties holding the assets), expressly authorising the testing of the Targets.
- Rules of Engagement (RoE) – the technical and operational conditions of the testing: time windows, permitted and prohibited techniques, emergency contacts, stop procedures.
- Finding – a vulnerability, misconfiguration or exposure identified through the Services.
- Report – the document or the view in the Platform presenting the Findings, their severity and the remediation recommendations.
- Subscription – recurring access to the Services under a package (e.g. BASIC, BUSINESS, ENTERPRISE) with periodic payment.
- One-off Service – a single engagement, with a scope and price set in the Offer (e.g. a pentest).
- Client Data – any data supplied by the Client or obtained about the Client's Targets in the course of providing the Services.
- Personal Data – has the meaning given in Regulation (EU) 2016/679 (“GDPR”).
- Authorised Partner – a third-party entity mandated by the Provider to advise on and sell the Services, without any right to amend these Terms.
2Subject matter, acceptance and account
2.1.Subject matter.The Provider makes the Platform available to the Client and performs the Services ordered, within the limits of the authorised Scope, of the chosen package and of the Annex applicable to each Service.
2.2.Acceptance.The Terms are accepted by any of the following: (a) ticking the acceptance box when creating the account or paying online; (b) signing an Offer or Order that refers to these Terms; (c) paying an invoice issued on their basis. Electronic acceptance produces the effects of a contract concluded in written form, under Law no. 365/2002 on electronic commerce.
2.3.Unusual standard clauses.The Client declares that it has read and expressly accepts, within the meaning of art. 1203 of the Romanian Civil Code, the clauses concerning: limitation of liability (Section 12), suspension and termination (Section 13), the exoneration for the effects of authorised testing (Section 3.7), the applicable law and the jurisdiction of the courts (Section 13). At online payment, this acceptance is given through a separate tick box.
2.4.The account.The Client supplies identification data that is real, complete and up to date. The Client is responsible for all actions carried out from its account, for the confidentiality of its credentials and for enabling two-factor authentication where the Platform offers it. Any unauthorised access must be notified to the Provider within 24 hours of discovery.
2.5.Users.The Client may invite Users within the limits of its package. The Client ensures that Users comply with the Terms and is liable for their acts as for its own.
2.6.Authorised Partners.The Services may be promoted and negotiated through Authorised Partners. The contract is nevertheless concluded exclusively between the Client and the Provider. No promise made by a Partner that is not carried over into the Offer signed by the Provider binds the Provider.
2.7.Order of precedence of documents.In the event of inconsistency, the following order applies: (1) the Authorisation Letter and the RoE, for everything concerning the Scope and the permitted techniques; (2) the signed Offer/Order; (3) the Annex specific to the Service; (4) the DPA; (5) these Terms. The Client's general terms do not apply unless expressly accepted in writing by the Provider.
2.8.Amendment of the Terms.The Provider may amend the Terms with notice by email and in the Platform at least 30 days before they take effect. Amendments do not apply retroactively to One-off Services already ordered. If it does not agree, the Client may terminate the Subscription without penalty up to the effective date; continued use after that date constitutes acceptance.
3Testing authorisation and rules common to all Services
3.1.The authorisation principle.The Provider tests only Targets for which the Client has demonstrated the right to authorise testing. Any access to a computer system without right may constitute a criminal offence under art. 360–365 of the Romanian Criminal Code. This Section is therefore an essential condition of the contract, without which the Provider would not have contracted.
3.2.The Client's representations.By declaring a Target, the Client warrants that: (a) it is the owner, holder or legitimate administrator of that Target; or (b) it holds the written consent of the owner, including of the hosting, cloud, CDN or SaaS providers where their terms so require; (c) the person signing has the power to bind the Client.
3.3.Validation of Targets.Before any active testing, the Provider may request, and the Client supplies, proof of control over the Target, for example: a DNS TXT record, a verification file on the server, an email to an administrative address of the domain, or contractual documents. Unvalidated Targets are not actively tested.
3.4.The Authorisation Letter.For penetration testing, bug hunting and any active testing beyond standard scanning, signing an Authorisation Letter is mandatory. It specifies at least: the Targets, the period, the permitted and prohibited techniques, the Provider's source IP addresses, and the emergency contacts of both parties.
3.5.Third-party assets.The Client does not include in the Scope assets belonging to third parties (e.g. the shared infrastructure of a cloud provider, external SaaS services) without their consent. The Provider may exclude from the Scope any asset it has reasonable grounds to believe belongs to a third party.
3.6.Common rules of engagement.
- Testing is carried out only within the Scope and only within the agreed windows.
- The Provider does not perform denial-of-service attacks, social engineering or physical access, unless expressly provided for in the Authorisation Letter.
- The Provider does not exfiltrate, alter or delete Client data beyond the minimum necessary to demonstrate a vulnerability (proof of concept).
- On discovering an actively exploitable critical vulnerability, or signs of an existing compromise, the Provider stops work on that vector and notifies the Client's emergency contact within 24 hours.
- Either party may request the immediate cessation of testing, through the emergency contacts.
3.7.The inherent risk of testing.The Client understands that security testing, even when carried out with professional diligence, may cause slowdowns, temporary unavailability, alerts, account lockouts or the generation of test data. The Client is required to make backups and to inform its internal teams and relevant providers. The Provider is not liable for such effects where it acted within the Scope and in accordance with the RoE, save for intent or gross negligence.
3.8.False representations.If the representations under 3.2 are false or incomplete, the Client bears in full any third-party claim and any legal consequence, and indemnifies the Provider under Section 12. The Provider may immediately suspend the Services.
3.9.The Client's duty to cooperate.The Client supplies in good time the access, test accounts, documentation and contacts required; adds the Provider's IP addresses to its allow-list, where agreed; and does not modify the Targets during testing without notice. Delays caused by the Client extend the Provider's deadlines accordingly.
3.10.Limits of the Services.No Service guarantees the discovery of every vulnerability or immunity from attack. Results reflect the state of the Targets at the time of testing. Remediating Findings remains the Client's responsibility, unless separately ordered.
Annex A — Vulnerability scanning
A.1.Description.Automated, non-intrusive or low-intrusion scanning of the declared Targets (web applications, APIs, servers, exposed services) to identify known vulnerabilities (CVEs), misconfigurations and outdated software versions.
A.2.Frequency.Within Subscriptions, monitoring scans run weekly, regardless of package. Additional scans on request may be ordered separately, according to the price list in force.
A.3.Targets.The maximum number of Targets is the one provided by the package. Targets must be validated under Section 3.3 before the first scan. Replacing a Target is permitted at most 2 times per month.
A.4.What it does not include.The Service does not include exploiting vulnerabilities, manual testing, authenticated testing (unless provided by the package), denial-of-service attacks or business logic verification.
A.5.Results.Findings are displayed in the Platform, classified by severity (e.g. on the basis of CVSS), with general remediation recommendations. Automated results may contain false positives and false negatives; the Provider does not guarantee that they are exhaustive. Manual validation of a Finding may be requested for a fee.
A.6.Operational impact.The Client may set time windows for scanning. Failing that, the Provider chooses low-traffic windows. The Client must allow traffic from the scanning IP addresses if it wants complete results; blocking it does not constitute non-performance by the Provider.
A.7.Retention.Scan results are kept for the duration of the Subscription and for 12 months after termination, and are then deleted, unless the law requires otherwise.
Annex B — Penetration testing (pentest)
B.1.Description.A manual, tool-assisted assessment in which the Provider's specialists simulate the actions of an attacker in order to identify and exploit, under control, the vulnerabilities within the Scope. Possible types: web applications, APIs, mobile applications, external or internal infrastructure, cloud.
B.2.Conditions for starting.Testing begins only after: (a) signature of the Offer; (b) signature of the Authorisation Letter and of the RoE; (c) payment of the advance, if the Offer provides for one; (d) provision of the necessary access.
B.3.Approach.The testing model (black-box, grey-box or white-box), the reference methodology (e.g. OWASP WSTG, OWASP MASTG, PTES) and the duration in person-days are set in the Offer. The work is time-boxed: the Provider does not guarantee that every possible vector will be covered within the allotted time.
B.4.Controlled exploitation.Exploitation stops at the level needed to demonstrate impact. Escalation, lateral movement or access to sensitive data occur only where the RoE permits. Any account, file or artefact created during the test is documented and removed at the end, or handed over to the Client for removal.
B.5.Deliverables.Within 10 business days of the end of testing, the Provider delivers a Report comprising: an executive summary, the Scope and methodology, Findings with severity, reproduction steps, evidence and remediation recommendations.
B.6.Retest.The Offer may include a retest of the remediated Findings, within 30 days of delivery of the Report. After that period, a retest is ordered separately.
B.7.Acceptance.The Client may submit observations on the Report within 10 business days of receipt. In the absence of observations, the Report is deemed accepted. Observations concern factual errors, not the Provider's professional conclusions.
B.8.Rescheduling and cancellation.Rescheduling less than 5 business days before the start, or the impossibility of starting due to the Client's fault, may attract a fee of 25% of the value of the Offer, for the resources already allocated.
B.9.Use of the Report.The Report is intended for the Client's internal use and, where applicable, for its auditors, insurers or authorities. It does not constitute a certification, an attestation of compliance or a guarantee of security towards third parties.
Annex C — AI-assisted code and exposure analysis
C.1.Description.Analysis of the source code, dependencies and configurations supplied by the Client, using static analysis tools (SAST), software composition analysis (SCA), detection of exposed secrets (API keys, passwords, tokens) and artificial intelligence models that prioritise and explain the Findings.
C.2.Access to the code.Access is granted through an integration with the repository (e.g. GitHub, GitLab, Bitbucket), with read-only rights, or by uploading an archive. The Client may revoke access at any time. The Provider makes no changes (commit, push, merge) in the Client's repositories without an express written request.
C.3.Rights over the code.The Client warrants that it has the right to submit the code for analysis, including code developed by third parties or licensed components. The Provider acquires no intellectual property right over the code.
C.4.Use of AI.The Client is informed that part of the analysis is performed with AI models, operated by the Provider or by sub-processors declared in the DPA. The Provider undertakes that: (a) the Client's code is not used to train its own models or those of third parties; (b) the AI providers used are contracted with no-retention/no-training clauses on data; (c) transfers outside the EEA comply with Chapter V GDPR.
C.5.Limits of AI results.Findings and remediation suggestions generated with AI may be incomplete or erroneous. They are recommendations and must be reviewed by qualified Client personnel before being applied. The Provider is not liable for code modified by the Client on the basis of these suggestions without review.
C.6.Exposed secrets.If the analysis identifies live secrets (credentials, keys), the Provider notifies the Client as a priority and does not use the secrets for any purpose other than minimal confirmation of validity, where authorised. Rotating the secrets is the Client's responsibility.
C.7.Retention of the code.Working copies of the code are deleted within 30 days of the end of the analysis; only the Findings and the minimal excerpts needed to illustrate them remain in the Platform.
Annex D — Deep Web and Dark Web monitoring
D.1.Description.Searching public, semi-public, Deep Web and Dark Web sources (forums, marketplaces, messaging channels, leaked databases, credential collections) for exposures associated with the domains, email addresses and names declared by the Client.
D.2.Frequency.Automated checking runs once every 7 days across the sources available to the Provider. Alerts for new exposures are sent through the Platform and by email.
D.3.Passive in nature.The Service is purely collection and correlation (OSINT / threat intelligence). The Provider does not buy stolen data, does not interact with malicious actors on the Client's behalf, does not pay ransoms and does not attempt to have data removed from illegal sources, unless separately agreed and within the limits of the law.
D.4.Personal data monitored.The email addresses and names of natural persons are Personal Data. For these:
- The Client is the controller and the Provider is the processor, under the DPA.
- The Client declares that it has a legal basis (e.g. the legitimate interest in protecting its organisation, art. 6(1)(f) GDPR) and that it has informed the data subjects (employees, management) about the monitoring.
- Monitoring persons unconnected to the Client's organisation (e.g. private individuals, competitors) is prohibited.
- Monitoring of names is limited to persons acting in their role within the Client or who have expressly consented.
D.5.Handling of the data found.The Provider reports the existence and nature of the exposure (source, date, type of data). Passwords and other sensitive data are displayed only partially or in hashed form. The Provider does not redistribute the leaked content and does not retain it longer than is necessary for reporting.
D.6.Limits.Dark Web source coverage is by its nature incomplete and variable. The absence of an alert does not mean the absence of an exposure. Information from these sources may be false, stale or fabricated; the Provider presents it as such, with an estimated confidence level.
D.7.Obligations after an alert.The Client decides on and applies the response measures (password resets, notification of the supervisory authority or of the data subjects under art. 33–34 GDPR, where applicable). The Provider may assist for a fee.
Annex E — Attack Surface Management (ASM)
E.1.Description.Continuous discovery and inventory of the internet-exposed assets associated with the Client (subdomains, IP addresses, open ports and services, certificates, technologies, cloud assets, DNS records), plus flagging of changes and new risks.
E.2.Starting point.Discovery starts from the root domains, the organisation name and the IP ranges declared and validated by the Client.
E.3.Automatically discovered assets.Assets identified through discovery do not automatically enter the Scope of active testing. They are analysed passively (DNS, certificates, public banners, open sources) until the Client confirms, in the Platform or in writing, that they belong to it and authorises their testing. Assets that appear to belong to third parties are flagged and excluded.
E.4.Attribution.Attributing an asset to the Client is an estimate based on technical correlation. The Client verifies and confirms the inventory; the Provider is not liable for incorrect attributions resulting from erroneous public data, where the asset was not actively tested without confirmation.
E.5.Frequency and alerts.The inventory is updated at the package's frequency (at least weekly). Relevant changes (a newly exposed service, an expired certificate, a subdomain vulnerable to takeover) generate alerts.
E.6.Relationship with other Services.Confirmed assets may be included, within the limits of the package, in vulnerability scanning (Annex A) or proposed for a pentest (Annex B).
Annex F — Bug Hunting
F.1.Description.Manual searching — continuous or in campaigns — for vulnerabilities in the Client's Targets, carried out by the Provider's specialists and, where the Offer so provides, by external researchers selected and contracted by the Provider (the “Researchers”).
F.2.Programme and Policy.For each programme, a written Programme Policy is established containing: in-scope and out-of-scope Targets, accepted and excluded vulnerability types, prohibited techniques, reporting rules and, where applicable, the reward scale. The Policy forms an integral part of the Authorisation Letter.
F.3.External researchers.The Provider is liable to the Client for the Researchers it involves as for its own personnel. Each Researcher: (a) is identified and vetted by the Provider; (b) signs a confidentiality agreement and an undertaking to comply with the Policy; (c) tests only from the infrastructure or IP addresses communicated to the Client. The Client has no direct contractual relationship with the Researchers.
F.4.Validation and triage.The Provider verifies, deduplicates and classifies by severity all reports before passing them on to the Client. The Client is invoiced only for valid, unique and in-scope Findings, where the pricing model is per Finding.
F.5.Rewards.Where the programme provides for rewards, they are paid by the Client to the Provider under the scale in the Policy, and the Provider distributes them to the Researchers. The Client may not refuse payment for a Finding validated under the Policy by subsequently invoking exclusions not provided for in it.
F.6.Disclosure.No vulnerability is made public without the Client's written consent. The Client undertakes not to bring legal action against the Provider or the Researchers for activities carried out in good faith within the limits of the Policy (safe harbour clause).
F.7.Difference from a pentest.Bug hunting does not guarantee methodical coverage of the Targets and does not replace a pentest; the outcome depends on the interest and the time the specialists devote during the programme period.
Annex G — Data Processing Agreement (DPA, art. 28 GDPR)
G.1.Legal framework.This Annex constitutes the contract required by art. 28(3) of Regulation (EU) 2016/679 (“GDPR”) and is supplemented by Law no. 190/2018 on implementing measures for the GDPR. The competent supervisory authority is the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP).
G.2.Roles of the parties.
- For Personal Data processed in performing the Services (Annexes A–F), the Client is the controller and the Provider is the processor.
- For account, billing, commercial communication and Platform security data, the Provider is an independent controller, under Annex H.
- If the Client itself acts as a processor for a third party, the Provider becomes a sub-processor, and the Client warrants that its instructions are authorised by the original controller.
G.3.Subject matter, nature and purpose of the processing.The processing has the sole purpose of performing the Services ordered: identifying, analysing and reporting the vulnerabilities and exposures concerning the Client's Targets. The operations include collection, consultation, correlation, storage, structuring, pseudonymisation, transmission to the Client through Reports, and erasure.
G.4.Categories of data and data subjects, per Service.
| Service | Data subjects | Categories of data | Nature |
|---|---|---|---|
| A. Vulnerability scanning | Users and administrators of the Client's systems | IP addresses, technical identifiers, data incidentally exposed in server responses | Incidental |
| B. Pentest | Employees, customers and users of the Client | Data from the accounts and databases accessed for proof of concept, credentials, logs | Incidental, minimised |
| C. AI code analysis | Developers, persons whose data appears in the code | Names and emails from commit history, test or real data in the code, secrets | Incidental |
| D. Deep/Dark Web | Employees, management, persons declared by the Client | Names, emails, compromised passwords (hashed or partial), phone numbers, other data from leaks | Principal |
| E. Attack Surface | Technical and administrative contacts | Names and emails from WHOIS, DNS, certificates; IP addresses | Incidental |
| F. Bug Hunting | As for a pentest | As for a pentest | Incidental, minimised |
The Provider does not request and does not seek the processing of special categories of data (art. 9 GDPR), data relating to criminal convictions (art. 10 GDPR) or the personal numeric code. If such data is accessed incidentally, the Provider does not copy it, mentions it in the Report only at the level of data type, and flags it to the Client.
G.5.Duration.The processing lasts for the term of the contract and the retention periods set out in Annexes A–F, after which G.14 applies.
G.6.Documented instructions.The Terms, the Annexes, the Offer, the Authorisation Letter and the settings made by the Client in the Platform constitute the Client's documented instructions within the meaning of art. 28(3)(a) GDPR. Further instructions are given in writing. The Provider immediately informs the Client if, in its opinion, an instruction infringes the GDPR or another data protection rule, and may suspend its execution pending clarification.
G.7.The Provider's obligations.The Provider:
- processes Personal Data only on documented instructions, including as regards transfers, unless required to do so by a legal obligation; in that case it informs the Client beforehand, unless the law prohibits it;
- ensures that the persons authorised to process the data have committed themselves to confidentiality or are under a statutory obligation of confidentiality;
- applies the security measures set out in G.9 (art. 32 GDPR);
- complies with the conditions on sub-processors in G.10;
- assists the Client, through appropriate technical and organisational measures, in fulfilling its obligation to respond to data subject requests (art. 15–22 GDPR); requests received directly are forwarded to the Client within 5 business days, without responding in its own name;
- assists the Client in complying with art. 32–36 GDPR, including with data protection impact assessments (DPIA) and prior consultation of the ANSPDCP;
- maintains a record of the processing activities carried out on behalf of the Client (art. 30(2) GDPR);
- makes available to the Client the information necessary to demonstrate compliance and allows audits under G.13.
G.8.The Client's obligations as controller.The Client:
- establishes and documents the legal basis for each processing operation (art. 6 GDPR), including, where it relies on legitimate interest, the balancing test;
- informs the data subjects under art. 13–14 GDPR, in particular the employees whose emails and names are monitored under Annex D;
- complies, to the extent that the monitoring qualifies as workplace monitoring, with the conditions of art. 5 of Law no. 190/2018 (justified legitimate interest, complete prior information, consultation of employee representatives, proportionality);
- carries out a DPIA where the processing requires one under art. 35 GDPR and the ANSPDCP list;
- does not transmit to the Provider more Personal Data than is necessary for the Service (data minimisation).
G.9.Technical and organisational measures (art. 32 GDPR).Taking into account the state of the art, the costs, the nature of the processing and the risks to data subjects, the Provider applies at least:
- encryption of data in transit (TLS 1.2 or above) and at rest;
- logical separation of each Client's data and role-based access control on a need-to-know basis;
- multi-factor authentication for personnel with access to Personal Data;
- logging of access to Reports and to leaked data;
- pseudonymisation or masking of passwords and sensitive data found (Annex D.5);
- encrypted backups and tested restore procedures;
- dedicated, hardened workstations for testing activities;
- regular data protection training for personnel and Researchers;
- regular testing and reassessment of the effectiveness of these measures.
The Provider may update the measures, provided that the level of protection does not decrease.
G.10.Sub-processors.The Client grants the Provider a general authorisation to engage sub-processors (art. 28(2) GDPR), under the following conditions:
- the up-to-date list (name, registered office, service, place of processing) is published at 4tify.io/subprocesatori;
- any addition or replacement is notified at least 15 days in advance; the Client may object on reasoned grounds within that period; if the parties cannot find a solution, the Client may terminate the affected Service, with a proportionate refund of amounts paid in advance;
- the Provider imposes on each sub-processor, by contract, data protection obligations equivalent to those in this Annex (art. 28(4) GDPR);
- the Provider remains fully liable to the Client for the sub-processors' performance of their obligations.
The external Researchers under Annex F are considered sub-processors within the meaning of this clause.
G.11.Transfers outside the EEA.As a rule, Personal Data is processed within the European Economic Area. Any transfer to a third country takes place only on the basis of one of the mechanisms in Chapter V GDPR:
- an adequacy decision of the European Commission (art. 45), including, for the USA, in respect of entities certified under the EU-U.S. Data Privacy Framework;
- standard contractual clauses approved by Decision (EU) 2021/914 (art. 46), accompanied by a transfer impact assessment and supplementary measures where necessary.
On request, the Provider makes available to the Client a copy of the applicable safeguards, from which confidential commercial information may be removed.
G.12.Personal data breach (art. 33–34 GDPR).The Provider notifies the Client without undue delay, and in any event within 48 hours of becoming aware of a breach of the security of the Client's Personal Data. The notification includes, to the extent available: the nature of the breach, the categories and approximate number of data subjects and records, the likely consequences, the measures taken or proposed and a point of contact. Information not available initially is provided in phases. The Client, as controller, decides on notifying the ANSPDCP (within 72 hours) and the data subjects; the Provider does not notify the authority or the data subjects on the Client's behalf without its instruction, except where required by law.
Findings about leaks of the Client's data identified through Annex D do not constitute breaches of the security of data processed by the Provider; they are information delivered to the Client as the result of the Service.
G.13.Audit.The Client exercises its audit right, in the first instance, by requesting the relevant documentation (security policies, audit reports or certifications of the Provider or of its sub-processors, where they exist). If these are not sufficient, the Client may carry out, directly or through an independent auditor bound by confidentiality, an on-site audit: at most once a year (except in the event of a breach or a request from the authority), with 30 days' notice, during business hours, without access to other clients' data. The costs of the audit are borne by the Client.
G.14.Deletion or return of the data.On termination of the Services, at the Client's choice expressed within 30 days, the Provider returns the Personal Data (in a structured format, e.g. an export of Reports) and/or deletes it, including existing copies, unless Union or Romanian law requires storage. Backup copies are deleted at the expiry of the normal rotation cycle, of at most 90 days, during which they remain protected and are not used. On request, the Provider issues written confirmation of the deletion.
G.15.Liability.The parties' liability towards data subjects is determined under art. 82 GDPR. As between the parties, the limitations in Section 12 apply, except where the law prohibits limitation. Each party bears the administrative fines imposed on it for its own infringements.
G.16.Precedence.As regards the protection of Personal Data, this Annex prevails over any other clause of the contract.
Annex H — Notice on processing by 4Tify as controller (art. 13–14 GDPR)
H.1.The controller.TECHCORNER S.R.L., VAT no. 51592659, with its registered office at str. Slt. Radu Teoharie, bl. D3, sc. B, et. 1, ap. 21, Târgu Neamț, Neamț county, 615200, Romania. Data protection contact: [email protected].
H.2.Data subjects.The representatives, employees and Users of Clients, the contact persons of prospective clients, newsletter subscribers and visitors to the 4tify.io website.
H.3.Purposes, legal bases and storage periods.
| Purpose | Data | Legal basis (GDPR) | Storage period |
|---|---|---|---|
| Creating and administering the account | Name, email, phone, job title, company, credentials (hashed) | Art. 6(1)(b) – performance of the contract | For the life of the account + 3 years (the general limitation period) |
| Invoicing and accounting records | Identification data of the Client and of its representative, payment history | Art. 6(1)(c) – legal obligation (Law no. 82/1991, the Fiscal Code) | The periods laid down by accounting and tax legislation |
| Processing online payments | Transaction data; card details are processed exclusively by Stripe | Art. 6(1)(b) | In accordance with the processor's legal obligations |
| Technical support and operational communications | Name, email, content of requests | Art. 6(1)(b) and (f) | For the term of the contract + 2 years |
| Platform security and abuse prevention | IP addresses, access logs, device identifiers | Art. 6(1)(f) – legitimate interest | 12 months, except for incidents under investigation |
| Newsletter, newsroom alerts and commercial communications | Name, email, topic preferences | Art. 6(1)(a) – consent or, for existing clients, art. 12(2) of Law no. 506/2004 | Until unsubscribe |
| Quoting through Authorised Partners | Contact details of the person representing the prospective client | Art. 6(1)(f) – legitimate interest (developing B2B relationships) | 12 months from the last contact, if no contract is concluded |
| Establishing, exercising or defending legal claims | The data relevant to the dispute | Art. 6(1)(f) | Until final resolution and the lapse of the limitation period |
H.4.Legitimate interest.Where the legal basis is legitimate interest, the Provider has assessed that the processing is necessary, proportionate and foreseeable for the data subjects, in the context of a professional relationship. The data subject may object at any time, under art. 21 GDPR.
H.5.Recipients.The data may be transmitted, strictly to the extent necessary, to: hosting and infrastructure providers, the payment processor Stripe, email and communication providers, the accountant and legal advisers (bound by confidentiality), the Authorised Partners involved in the commercial relationship, and public authorities where the law so requires. The data is not sold.
H.6.Transfers.Transfers outside the EEA are made only with the safeguards described in G.11.
H.7.Automated decisions.The Provider does not take decisions based solely on automated processing, including profiling, that produce legal effects or similarly significant effects on data subjects (art. 22 GDPR). The AI tools used in the Services analyse systems and code; they do not evaluate people.
H.8.Nature of the provision of data.The data marked as mandatory when creating the account is necessary for concluding and performing the contract; refusing to provide it makes it impossible to supply the Services. Subscribing to commercial communications is optional.
H.9.Data subject rights.Every data subject has the right of access (art. 15), rectification (art. 16), erasure (art. 17), restriction (art. 18), portability (art. 20), objection (art. 21) and the right to withdraw consent at any time, without affecting the lawfulness of prior processing. Requests are sent to the address in H.1 and receive a response within one month, extendable by two months in the cases provided for in art. 12(3) GDPR. For data processed within the Services (Annex G), requests are addressed to the Client, as controller.
H.10.Complaint.A data subject may lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (www.dataprotection.ro) or bring the matter before the competent court.
H.11.Source of the data (art. 14 GDPR).Where the data is not collected directly from the data subject, it comes from the Client that created the account or from the Authorised Partners and, in the case of the Service in Annex D, from public sources and threat intelligence sources, acting as the Client's processor.
H.12.Cookies.The use of cookies and similar technologies on 4tify.io is described in the Cookie Policy at 4tify.io/cookies, in accordance with Law no. 506/2004.
10Prices, invoicing and payments
10.1.Prices.Subscription prices are those published on 4tify.io at the date of the order. Prices for One-off Services (pentest, bug hunting, retests) are those in the accepted Offer. Prices exclude VAT, which is added in accordance with the law.
10.2.Payment.Online payments are processed through Stripe; the card statement shows the description “4TIFY.IO”. The Provider does not store full card details. Offers may also be paid by bank transfer, against an invoice.
10.3.Subscriptions.Subscriptions are invoiced in advance, monthly or annually, and renew automatically at the end of each period until cancelled. Cancellation takes effect at the end of the paid period.
10.4.One-off Services.Unless the Offer provides otherwise: 50% in advance on signature and 50% on delivery of the Report. Invoices are payable within 15 days of issue.
10.5.Late payment.Late payment attracts penalties of 0.1% per day of delay, not exceeding the value of the debt. After 15 days of delay, the Provider may suspend the Services with 5 days' prior notice.
10.6.Refunds.Amounts paid are non-refundable, except in the case of: (a) non-performance of the Service through the Provider's exclusive fault; (b) termination by the Client under 2.8 (amendment of the Terms), in which case the unused period is refunded proportionately.
10.7.Price changes.Subscription prices may be changed with at least 30 days' notice; the new price applies from the next billing period. The Client may cancel before it takes effect.
11Confidentiality, data protection and intellectual property
11.1.Confidentiality.Each party keeps confidential the non-public information received from the other, including the Findings, the Reports, access credentials and system architecture. The obligation lasts for the whole contractual relationship and 5 years after its end; for credentials and unremediated vulnerabilities, it lasts indefinitely. Exceptions: information already public without that party's fault, lawfully obtained from third parties, or whose disclosure is required by law or by an authority, with prior notice to the other party where the law permits.
11.2.GDPR roles.For Personal Data processed within the Services, the Client is the controller and the Provider is the processor, within the meaning of art. 28 GDPR. Processing is carried out in accordance with Annex G (DPA), an integral part of the contract, which sets out: the subject matter, the duration, the categories of data and data subjects, the security measures, the sub-processors and the assistance with data subject requests. For the Client's account and billing data, the Provider is a controller, under Annex H.
11.3.Sub-processors.The list of sub-processors (e.g. hosting, payment processing, AI providers) is available at 4tify.io/subprocesatori. The Provider notifies any change at least 15 days in advance; the Client may object on reasoned grounds.
11.4.Security of Client Data.The Provider applies appropriate technical and organisational measures: encryption in transit and at rest, access control on a need-to-know basis, logging, logical separation between clients. Any security incident affecting Client Data is notified to the Client without undue delay, within 48 hours of discovery.
11.5.The Provider's property.The Platform, the software, the methodologies, the report templates, the tools, the models and the Provider's know-how remain the exclusive property of TechCorner S.R.L., protected by Law no. 8/1996. The Client may not copy, decompile, resell or use the Platform to build a competing service.
11.6.The Client's property.The Client Data, its code and the Targets remain the property of the Client. After payment in full, the Client receives a non-exclusive, perpetual and non-transferable licence to use the Reports internally.
11.7.Aggregated data.The Provider may use anonymised and aggregated technical data (e.g. statistics on vulnerability types) to improve the Services and for threat intelligence material, without identifying the Client, the Targets or any natural person.
11.8.References.The Provider may mention the Client's name and logo as a commercial reference only with the Client's written consent.
12Warranties, liability and prohibited use
12.1.The Provider's warranties.The Provider performs the Services with the diligence of a professional in the field, through qualified personnel, in accordance with the applicable Annex. The Provider's obligations are obligations of means, not of result: the Provider does not guarantee the discovery of every vulnerability, the absence of future incidents, compliance with a particular standard, or the obtaining of a certification.
12.2.Platform availability.The Provider targets Platform availability of 99% per month, excluding announced maintenance and causes outside its control. Unless the Offer provides otherwise, this level is a target, not a commitment backed by penalties.
12.3.Liability cap.To the extent permitted by law, the Provider's total liability for any claim connected with the contract is limited to the amounts actually paid by the Client for the Service in question in the 12 months preceding the triggering event.
12.4.Excluded damages.The Provider is not liable for indirect damages: lost profits, loss of customers or reputation, business interruption, loss of data that could have been prevented by backups, nor for damage caused by third-party attackers.
12.5.Exceptions to the limitation.The limitations in 12.3 and 12.4 do not apply to damage caused intentionally or by gross negligence (art. 1355 of the Romanian Civil Code), nor to damage to life, physical integrity or health.
12.6.Indemnification by the Client.The Client indemnifies the Provider against any claim, fine or expense (including reasonable legal fees) arising from: (a) false representations as to the right to authorise testing; (b) the inclusion in the Scope of third-party assets without consent; (c) the monitoring of persons without a legal basis; (d) breach of Section 12.7.
12.7.Prohibited use.The Client may not use the Platform or the Services for:
- testing, scanning or monitoring systems or persons without authorisation;
- offensive reconnaissance, preparing attacks or spying on competitors or third parties;
- tracking, harassing or profiling natural persons;
- reselling the Services or the Reports without the Provider's written consent;
- attempting to compromise the Platform, to circumvent the technical limits of the package or to access other clients' data;
- any activity contrary to the law, public order or good morals.
Breach of this clause permits immediate suspension and termination under Section 13, without refund, and notification of the competent authorities where the law so requires.
13Term, termination and final provisions
13.1.Term.The contract enters into force on acceptance of the Terms and lasts for as long as the Client has an active Subscription or an ongoing One-off Service.
13.2.Cancelling the Subscription.The Client may cancel at any time from the Platform; the effect occurs at the end of the paid period.
13.3.Suspension.The Provider may immediately suspend the Services, in whole or in part, if: (a) there are reasonable indications of prohibited use or of missing authorisation; (b) continuing the testing endangers the Client's systems or those of third parties; (c) an authority so requires; (d) payment is late under 10.5. The suspension is notified and lifted once the cause ceases.
13.4.Termination for breach.Either party may terminate the contract by written notice if the other party breaches an essential obligation and does not remedy the breach within 15 days of notice. Breach of Sections 3 (authorisation) or 12.7 (prohibited use) by the Client permits termination by operation of law, without notice of default and without court intervention (express termination clause, art. 1553 of the Romanian Civil Code).
13.5.Effects of termination.On termination: access to the Platform is closed; the Client may export the Reports within 30 days; Client Data is deleted or returned under the DPA; amounts due remain payable. The clauses on confidentiality, liability, indemnification and applicable law survive termination.
13.6.Force majeure.Neither party is liable for non-performance caused by force majeure within the meaning of art. 1351 of the Romanian Civil Code. The affected party notifies the other within 5 days. If the force majeure lasts more than 30 days, either party may terminate the contract without compensation.
13.7.Assignment and subcontracting.The Client may not assign the contract without the Provider's written consent. The Provider may subcontract parts of the Services to specialists or suppliers bound by equivalent confidentiality obligations, remaining liable to the Client.
13.8.Notices.Notices are given in writing, by email to the addresses in the account or in the Offer, or through the Platform. Notice by email is deemed received on the business day following dispatch.
13.9.Applicable law and disputes.The contract is governed by Romanian law. The parties will attempt to settle any dispute amicably within 30 days. Failing agreement, the dispute is settled by the competent courts at the Provider's registered office.
13.10.Final provisions.If a clause becomes void, the remaining clauses stay in force and the parties replace it with a valid clause of the closest possible effect. Failure to exercise a right does not amount to a waiver of it. The Terms are drawn up in Romanian; any English version is for information only and, in the event of divergence, the Romanian version prevails.
Questions about this document?
Write to us and a real person will answer — contract, data protection or scope.