SYSTEM SUPPORT CANADA INC.
Dark Web Exposure Search
Terms and Conditions
Version 1.0 · Effective 10 September 2026 · Ontario, Canada
Important — read before submitting your request. These Terms and Conditions (the “Terms”) form a binding agreement between System Support Canada Inc. (“Provider,” “we,” “us” or “our”) and the organization requesting a Dark Web Exposure Search (“Requester,” “you” or “your”). By submitting the Dark Web Exposure Search request form, you accept these Terms, you confirm that you are authorized to accept them on behalf of the Requester, and you give Provider the authorization described in Section 5. If you do not agree to these Terms, do not submit the request form. |
1. ACCEPTANCE OF THESE TERMS
1.1Provider offers a complimentary, point-in-time Dark Web Exposure Search (the “Search”) to organizations considering Provider’s managed information technology and cybersecurity services.
1.2Acceptance by submission. Your submission of the request form described in Schedule A (the “Request Form”) constitutes your acceptance of these Terms and creates a binding agreement between you and Provider. No signature is required, although Provider may in its discretion also accept these Terms by countersignature using the block at the end of this document.
1.3Provider will not commence any Search until it has recorded your acceptance of these Terms and received a completed Request Form. Provider is entitled to rely on the Request Form and on the authorization in Section 5 without further inquiry.
1.4 Authority to accept. The individual submitting the Request Form represents and warrants that he or she is at least eighteen (18) years of age, is an officer, director, employee or duly authorized agent of the Requester, and has full authority to bind the Requester to these Terms.
1.5Business use only. The Search is offered solely to organizations for business purposes. It is not offered to individuals acting for personal, family or household purposes, and these Terms are not a consumer agreement. Provider will decline any request that appears to be made by or on behalf of a consumer.
1.6 Consideration. The parties acknowledge that the mutual promises in these Terms, the authorization you grant under Section 5, and Provider’s agreement to perform the Search at no charge together constitute good and valuable consideration, the sufficiency of which each party accepts.
1.7Version. The version of these Terms displayed at the time you submit the Request Form governs your request. Provider maintains a dated archive of all versions and will provide a copy of the applicable version on request.
2. DEFINITIONS
2.1 In these Terms:
(a) “Domain Name Asset” means an internet domain name owned or controlled by the Requester and listed on the Request Form.
(b) “Email Asset” means an email address owned or controlled by the Requester and listed on the Request Form.
(c) “Exception Data” means Exposure Data that consists of, or directly reveals, a password, passphrase, security question answer, payment card number, bank account number, government identification number or other credential or identifier capable of being used to obtain access to an account or to impersonate an individual.
(d) “Exposure Data” means information relating to a Monitored Asset that a Third-Party Data Source reports as having appeared in a data breach, credential dump, paste site, criminal marketplace, forum or other source described by that Third-Party Data Source as a dark web or deep web source.
(e)“Monitored Asset” means a Domain Name Asset or an Email Asset submitted by the Requester on the Request Form.
(f)“Search Report” means the written summary of Exposure Data that Provider prepares and delivers to the Requester following the Search, together with any Provider commentary, scoring, risk narrative or recommendations contained in it.
(g)“Third-Party Data Source” means any third-party product, platform, dataset or service that Provider licenses or subscribes to in order to perform the Search, including without limitation the Dark Web ID product made available by Kaseya US LLC and its affiliates.
(h) “Applicable Privacy Law” means the Personal Information Protection and Electronic Documents Act (Canada), the Personal Information Protection Act (Alberta), the Personal Information Protection Act (British Columbia), the Act respecting the protection of personal information in the private sector (Quebec), and any other data protection or privacy legislation applicable to the Requester or to Provider in connection with the Search.
3. WHAT THE SEARCH IS
3.1The Search is a passive, point-in-time query. Provider submits each Monitored Asset to one or more Third-Party Data Sources and reports back what those sources return.
3.2The Search is performed entirely against data already held by Third-Party Data Sources. Provider does not connect to, access, scan, probe, authenticate to, or otherwise interact with any network, system, device, application or account belonging to or operated by the Requester.
3.3The Search reflects only what the applicable Third-Party Data Sources held at the moment the query was run. It is a snapshot, not a monitoring service.
3.4Provider will deliver the Search Report by a means Provider reasonably considers secure. Provider may withhold, redact or mask Exception Data in accordance with Section 8.
4. WHAT THE SEARCH IS NOT
4.1 You acknowledge and agree that the Search does not include, and Provider will not perform, any of the following:
(a)any penetration test, vulnerability assessment, port scan, network scan, configuration review, or any other activity that involves accessing, testing or interacting with the Requester’s networks, systems, devices, applications or accounts;
(b)any attempt to use, enter, test, verify or validate any credential appearing in the Exposure Data against any system, service or account, whether operated by the Requester or by any other person;
(c)any purchase, sale, exchange, ransom payment, bid, download or other acquisition of stolen data, and any negotiation, communication or other dealing with any person believed to be a threat actor, data broker or criminal actor;
(d)any attempt to remove, suppress, take down, recall or otherwise cause the deletion of data from any dark web source, criminal marketplace, forum or other location;
(e) any phishing simulation, social engineering exercise, pretexting, or other testing directed at the Requester’s personnel;
(f)any investigation of, surveillance of, or reporting on any individual, whether or not employed by the Requester, beyond reporting Exposure Data associated with a Monitored Asset;
(g)any ongoing, continuous or recurring monitoring, alerting or re-checking of any Monitored Asset;
(h) any audit, certification, attestation, opinion or assurance engagement, and any assessment of the Requester’s compliance with any law, regulation, framework, standard or contractual requirement; and
(i)any legal, regulatory, insurance, accounting or forensic service.
4.2 If the Requester wishes Provider to perform any of the activities listed in Section 4.1, a separate written agreement and, where applicable, a separate written authorization to test must be executed before that activity begins. Nothing in these Terms authorizes any such activity.
5. YOUR AUTHORIZATION AND WARRANTIES
5.1Authorization. You authorize and instruct Provider, and Provider’s Third-Party Data Sources, to use each Monitored Asset you submit and to obtain, review, compile and provide to Provider and to you the Exposure Data associated with that Monitored Asset. You acknowledge that this authorization is the prior written permission that Provider is required by its Third-Party Data Sources to obtain before performing the Search, and that Provider is entitled to rely on it and to evidence it to those Third-Party Data Sources.
5.2You represent and warrant to Provider that, as at the date you submit the Request Form and throughout the performance of the Search:
(a)you own or control every Domain Name Asset and every Email Asset you have submitted, and you have the right to submit each of them for the purposes described in these Terms;
(b)every Email Asset you have submitted is an address issued by or on behalf of the Requester to a director, officer, employee, contractor or agent of the Requester for use in the Requester’s business;
(c) you have the authority under Applicable Privacy Law, and under your own policies, contracts and any applicable collective agreement, to authorize the Search and to receive the Exposure Data, and you have given every notice and obtained every consent that Applicable Privacy Law requires you to give or obtain from the individuals associated with the Monitored Assets;
(d) you are not requesting the Search for any purpose of investigating, monitoring, disciplining or taking adverse action against any individual, and not for the purpose of litigation, competitive intelligence, due diligence on a third party, or any other purpose adverse to any person;
(e)you will not use the Search, the Search Report or any Exposure Data to harm any person or entity, or in any manner contrary to law; and
(f)your submission of the Request Form and your receipt and use of the Search Report will not breach any contract, policy, court order or law binding on you.
5.3 You will promptly notify Provider in writing if any representation in Section 5.2 becomes inaccurate before the Search Report is delivered, and Provider may then suspend or abandon the Search without liability.
5.4These warranties are fundamental. You acknowledge that Provider would not perform the Search but for the authorization and warranties in this Section 5, and that Provider has no practical means of independently verifying your ownership of, or authority over, the Monitored Assets you submit.
6. ASSETS YOU MUST NOT SUBMIT
6.1You must not submit, and Provider will not knowingly search, any of the following:
(a) any domain name or email address that the Requester does not own or control;
(b) any consumer or public webmail domain, including without limitation gmail.com, outlook.com, hotmail.com, yahoo.com, icloud.com and any comparable domain;
(c)any personal email address of any individual, including a personal address of a director, officer, employee or contractor of the Requester;
(d) any domain name or email address belonging to a competitor, customer, supplier, prospective acquisition target, former employee, family member, or any other third party;
(e)any domain name or email address of a government body, law enforcement agency or regulator; and
(f) any asset in respect of which the Requester is subject to a court order, undertaking or contractual restriction limiting its ability to authorize the Search.
6.2Provider may in its sole discretion remove any submitted asset from the scope of the Search, decline any request in whole or in part, or terminate a Search in progress, in each case without notice, reason or liability.
7. PERSONAL INFORMATION AND PRIVACY
7.1Roles. The Requester is the organization having control of the personal information associated with the Monitored Assets. Provider performs the Search as a service provider acting on the Requester’s instructions and on the Requester’s behalf. Provider does not determine the purposes of the collection.
7.2Identified purposes. Provider will collect, use and disclose personal information obtained through the Search only to perform the Search, prepare and deliver the Search Report, discuss the Search Report with the Requester, and respond to the Requester’s questions about it. Provider will not use that personal information for any other purpose, and will not sell it or make it available to any person other than the Requester and Provider’s Third-Party Data Sources as necessary to perform the Search.
7.3Limiting collection. Provider will submit only the Monitored Assets listed on the Request Form and will not seek Exposure Data in respect of any other asset.
7.4Safeguards. Provider will protect personal information obtained through the Search using safeguards appropriate to its sensitivity, including access restricted to those Provider personnel who require it, encryption in transit and at rest, and secure disposal.
7.5Retention and deletion. Provider will delete or securely destroy all raw Exposure Data, including all Exception Data, within thirty (30) days after delivery of the Search Report. Provider may retain the Search Report and the Request Form for twelve (12) months for the purpose of evidencing your authorization and Provider’s compliance with these Terms and with its obligations to its Third-Party Data Sources, after which they will be deleted or securely destroyed. Provider will delete the Search Report earlier on your written request, subject to Provider’s right to retain the Request Form and the record of your acceptance of these Terms.
7.6Processing outside Canada. You acknowledge that the Search is performed using Third-Party Data Sources that store and process data outside Canada, principally in the United States, and that Provider may transfer the Monitored Assets outside Canada for that purpose. While outside Canada, that information may be subject to lawful access by foreign courts, law enforcement and government authorities. You are responsible for making any disclosure of this transfer, and for completing any privacy impact assessment, that Applicable Privacy Law requires of you.
7.7 Access and correction requests. If Provider receives a request from an individual for access to, or correction of, personal information obtained through the Search, Provider will refer the individual to the Requester and notify the Requester without undue delay. Responding to that request is the Requester’s responsibility.
7.8Provider’s privacy practices. Provider’s handling of the contact information you supply on the Request Form is governed by Provider’s privacy policy. Provider’s Privacy Officer may be contacted using the details in Section 23.
8. EXPOSED CREDENTIALS — HANDLING AND YOUR OBLIGATIONS
8.1Sensitivity. You acknowledge that Exposure Data can be highly sensitive and can be used to compromise the rights of individuals and organizations. You will treat all Exposure Data accordingly.
8.2Masking. Provider will mask, partially redact or omit Exception Data in the Search Report wherever Provider considers it reasonable to do so. Provider is not obliged to disclose any Exception Data in full, and Provider’s decision to mask does not reduce the significance of a reported exposure.
8.3The Search Report is not, and must not be treated as, authorization to access any account. You will not, and will not permit any person to:
(a)use, enter, test or attempt to verify any credential appearing in the Search Report against any system, service or account;
(b)attempt to access any account belonging to any individual using information in the Search Report; or
(c)disclose Exception Data to any person other than as permitted by Section 12.
8.4Your remediation. You are solely responsible for deciding what to do about any exposure reported to you and for doing it, including resetting or invalidating affected credentials, enforcing multi-factor authentication, notifying affected individuals, and reviewing systems for unauthorized access. Provider has no obligation to remediate any exposure under these Terms.
9. NO WARRANTY; ACCURACY AND COMPLETENESS
9.1 THE SEARCH AND THE SEARCH REPORT ARE PROVIDED “AS IS” AND “AS AVAILABLE,” WITH ALL FAULTS AND WITHOUT WARRANTY OR CONDITION OF ANY KIND, WHETHER EXPRESS, IMPLIED, STATUTORY OR OTHERWISE. TO THE FULLEST EXTENT PERMITTED BY LAW, PROVIDER DISCLAIMS ALL WARRANTIES AND CONDITIONS OF MERCHANTABILITY, MERCHANTABLE QUALITY, FITNESS FOR A PARTICULAR PURPOSE, DURABILITY, ACCURACY, COMPLETENESS, DATA ACCURACY, DATA SECURITY AND NON-INFRINGEMENT.
9.2 Without limiting Section 9.1, you specifically acknowledge and agree that:
(a)Exposure Data originates with unknown third parties, including criminal actors, and is inherently fragmentary, unverified, unverifiable, and frequently stale, duplicated, mislabelled or simply wrong;
(b)Third-Party Data Sources index only a portion of the sources on which stolen data appears, and no product or service can search all of them;
(c) an exposure may exist without appearing in the Search Report, and information appearing in the Search Report may be inaccurate, outdated, or associated with a person or organization other than the Requester;
(d)a Search Report containing no findings, or few findings, is not evidence that the Requester has not suffered a data exposure, that the Requester’s credentials are secure, or that the Requester’s security posture is adequate. It means only that the Third-Party Data Sources returned no matching records at the moment the query ran;
(e)a Search Report containing findings is not evidence that the Requester, or any system of the Requester, has been breached, compromised or accessed without authorization. Credentials are commonly exposed through breaches of unrelated third-party services; and
(f)the Search is not a substitute for a security assessment, for appropriate technical and organizational safeguards, or for cyber liability, privacy liability or professional liability insurance.
9.3Provider gives no warranty that the Search will be performed uninterrupted or error-free, that any particular Monitored Asset will be searchable, or that any Third-Party Data Source will remain available.
9.4 Provider makes no representation or warranty in respect of any Third-Party Data Source. Provider is not responsible or liable for the acts, omissions, availability, accuracy or data practices of any Third-Party Data Source, and your rights in respect of any Third-Party Data Source are governed by that provider’s own terms and policies.
10. NO LEGAL, REGULATORY OR INSURANCE ADVICE
10.1Provider is not a law firm and does not provide legal advice. The Search Report, and any commentary, recommendation or discussion Provider provides in connection with it, is technical and informational in nature only.
10.2Exposure Data reported to you may be relevant to obligations that Applicable Privacy Law, your regulators, your insurers or your contracts impose on you, including obligations to assess whether an incident creates a real risk of significant harm or a risk of serious injury to an individual, to report or notify, and to keep records. Determining whether any such obligation applies, and discharging it, is solely your responsibility.
10.3 You will obtain your own legal, regulatory, insurance and accounting advice in relation to the Search Report. You will not rely on Provider for any such advice, and Provider owes you no duty in respect of any such matter.
10.4 Nothing in these Terms creates a fiduciary relationship, a relationship of trust or confidence beyond Section 12, or any duty of care beyond the express obligations set out in these Terms.
11. FEES; PROVIDER’S DISCRETION
11.1 The Search is provided at no charge unless Provider and the Requester have agreed otherwise in writing.
11.2 Provider may decline any request, limit the number of Monitored Assets, limit the number of Searches performed for any Requester or group of related Requesters, discontinue the Search offering, or terminate any Search in progress, in each case in its sole discretion, without notice, reason or liability.
11.3 Provider has no obligation to perform any further Search, to repeat a Search, or to update a Search Report.
12. CONFIDENTIALITY
12.1 Provider will treat the Monitored Assets, the Exposure Data and the Search Report as confidential information of the Requester and will not disclose them to any person other than Provider’s personnel and Third-Party Data Sources who require access to perform the Search, except as required by law or as permitted by these Terms.
12.2You will treat the Search Report, Provider’s methodology, templates, scoring approach, pricing and any non-public information about Provider’s tooling as confidential information of Provider and of Provider’s Third-Party Data Sources. You will protect that information with at least the care you apply to your own confidential information of like importance.
12.3You may disclose the Search Report and the Exposure Data only to:
(a)your directors, officers, employees, contractors and professional advisers who have a need to know for the purpose of acting on it, and who are bound by confidentiality obligations no less protective than those in this Section 12;
(b) your insurers, in connection with a claim or an application for coverage; and
(c) law enforcement authorities or a regulator, where required by law or where reasonably necessary for the Requester’s benefit.
12.4You will not publish, post, distribute, or make the Search Report available to the public or to any competitor of Provider, and will not use it in any advertisement, tender, litigation or proceeding without Provider’s prior written consent.
12.5This Section 12 does not apply to information that is or becomes publicly available without fault of the receiving party, was already lawfully in the receiving party’s possession, is received from a third party entitled to disclose it, or is required to be disclosed by law or court order.
13. INTELLECTUAL PROPERTY; USE OF THE SEARCH REPORT
13.1Provider retains all right, title and interest in and to the Search Report as a compilation and work of authorship, and in and to Provider’s methodology, templates, formats, scoring, narrative, recommendations and all software, tools and know-how used to perform the Search. Nothing in these Terms transfers any of it to you.
13.2Provider grants you a non-exclusive, non-transferable, revocable, royalty-free licence to use the Search Report for your own internal business purposes only, subject to Sections 8, 12 and 13.3.
13.3You will not remove or obscure any proprietary notice, attribution or disclaimer from the Search Report, and will not reproduce any part of it in a manner that omits the disclaimers in Sections 9 and 10.
13.4As between you and Provider, the Monitored Assets and the underlying personal information remain yours or that of the relevant individual. Provider claims no ownership of them.
14. THIRD-PARTY SERVICES
14.1 The Search is performed using Third-Party Data Sources. Your use of the Search and the Search Report is subject to the terms and policies of those providers, which may change without notice to you or to Provider.
14.2 UNDER NO CIRCUMSTANCES WILL PROVIDER BE RESPONSIBLE OR LIABLE FOR ANY CLAIM CAUSED BY ANY THIRD-PARTY DATA SOURCE. IF HARM ARISES TO YOU AS A RESULT OF A THIRD-PARTY DATA SOURCE, YOU AGREE THAT YOU WILL SEEK REMEDIES ONLY FROM THAT THIRD-PARTY PROVIDER.
14.3Provider maintains a Schedule of Third-Party Services identifying the third-party providers Provider uses and linking to their terms and policies. That schedule may be updated by Provider at any time and is incorporated into these Terms by reference. Provider will provide a copy of the version in effect on request.
15. COMMUNICATIONS AND CONSENT
15.1 Service messages. You consent to Provider sending you electronic messages relating to your request and the Search, including acknowledgement of your request, delivery of the Search Report, and follow-up necessary to complete or explain it. These messages are sent to give effect to your request.
15.2Discussion of results. You consent to Provider contacting you by email or telephone to discuss the Search Report and the services Provider offers in relation to the matters it identifies.
15.3Marketing messages. Provider will send you newsletters, service announcements, invitations and other commercial electronic messages only where you have separately consented on the Request Form. Provider will identify itself in each such message and include a functioning unsubscribe mechanism. You may withdraw that consent at any time without affecting Provider’s delivery of the messages described in Sections 15.1 and 15.2.
16. AGGREGATED AND DE-IDENTIFIED INFORMATION
16.1Provider may compile and use aggregated, de-identified statistics derived from Searches performed for all Requesters — for example, the proportion of organizations in a sector with at least one exposed credential — for the purpose of research, benchmarking, service improvement and marketing.
16.2Provider will not identify you, your Monitored Assets, or any individual in any such use, and will not publish any statistic derived from a set of Searches small enough that you could reasonably be identified from it. Provider will not name you as a Requester, or refer to your Search Report, without your prior written consent.
17. LIMITATION OF LIABILITY
17.1 TO THE FULLEST EXTENT PERMITTED BY LAW, PROVIDER WILL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY OR PUNITIVE DAMAGES, OR FOR ANY LOSS OF PROFIT, REVENUE, GOODWILL, BUSINESS OPPORTUNITY, ANTICIPATED SAVINGS, DATA, OR BUSINESS INTERRUPTION, ARISING OUT OF OR IN CONNECTION WITH THE SEARCH, THE SEARCH REPORT, THESE TERMS OR ANY EXPOSURE DATA, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES AND REGARDLESS OF WHETHER THE CLAIM IS FRAMED IN CONTRACT, TORT, NEGLIGENCE, STATUTE OR OTHERWISE.
17.2 TO THE FULLEST EXTENT PERMITTED BY LAW, PROVIDER’S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR IN CONNECTION WITH THE SEARCH, THE SEARCH REPORT AND THESE TERMS, FOR ALL CLAIMS COMBINED, WILL NOT EXCEED THE GREATER OF (A) THE AMOUNT, IF ANY, ACTUALLY PAID BY YOU TO PROVIDER FOR THE SEARCH, AND (B) ONE THOUSAND CANADIAN DOLLARS (CAD $1,000).
17.3 Without limiting Sections 17.1 and 17.2, Provider will have no liability whatsoever for:
(a) the accuracy, completeness, currency or provenance of any Exposure Data, or the absence of any Exposure Data from the Search Report;
(b)any decision you take, or fail to take, on the basis of the Search Report;
(c)any data breach, unauthorized access, credential compromise, ransomware event or other security incident affecting you, whether or not it relates to an exposure reported or not reported in the Search Report;
(d)any failure by you to comply with any obligation under Applicable Privacy Law, including any obligation to assess, record, report or notify; or
(e)the acts, omissions or unavailability of any Third-Party Data Source.
17.4No claim may be brought against Provider more than six (6) months after the date on which the facts giving rise to the claim first became known or ought reasonably to have become known to you. A claim not brought within that period is forever barred. The parties agree that this Section constitutes an agreement to vary the applicable limitation period in a business agreement.
17.5You waive, and will require your insurers to waive, any right of subrogation or recovery they may have against Provider and its directors, officers, employees, contractors and agents in connection with the Search.
17.6You acknowledge that the Search is provided at no charge, that the allocation of risk in these Terms reflects that fact, and that Provider would not offer the Search on any other basis. You agree that the limitations in this Section 17 are fair and reasonable in the circumstances.
17.7 Nothing in these Terms limits or excludes liability to the extent that liability cannot be limited or excluded at law.
18. INDEMNIFICATION BY THE REQUESTER
18.1 You will defend, indemnify and hold harmless Provider and its directors, officers, employees, contractors and agents from and against all claims, demands, actions, proceedings, losses, liabilities, damages, fines, penalties, costs and expenses, including reasonable legal fees on a full indemnity basis, arising out of or in connection with:
(a)any breach or inaccuracy of any representation, warranty or authorization you give under Section 5;
(b) your submission of any asset that you did not own or control, or that Section 6 prohibits;
(c) any failure by you to give a notice or obtain a consent that Applicable Privacy Law required you to give or obtain before authorizing the Search;
(d)any claim by an individual whose personal information appears in the Exposure Data, or by any third party whose domain name or email address you submitted;
(e) your use, disclosure, publication or retention of the Search Report or any Exposure Data in breach of these Terms; and
(f) any claim brought against Provider by a Third-Party Data Source arising from your acts or omissions in connection with the Search.
18.2You will pay any judgment, award or settlement in respect of a claim described in Section 18.1. Provider may participate in the defence of any such claim with counsel of its own choosing at its own expense, and you will not settle any such claim in a manner that imposes any obligation or admission on Provider without Provider’s prior written consent.
18.3 The indemnity in this Section 18 is not subject to the limitations in Section 17.
19. TERM; NO ONGOING MONITORING
19.1These Terms take effect when you submit the Request Form and, except for the provisions identified in Section 19.4, end on delivery of the Search Report or on Provider’s notice that it will not perform the Search.
19.2 THE SEARCH IS A ONE-TIME, POINT-IN-TIME QUERY. PROVIDER HAS NO OBLIGATION TO MONITOR ANY MONITORED ASSET, TO RE-RUN ANY SEARCH, TO ALERT YOU TO ANY FUTURE EXPOSURE, OR TO UPDATE THE SEARCH REPORT, AND WILL NOT DO SO.
19.3 If you wish Provider to provide ongoing dark web monitoring or any other managed service, you must enter into a separate written order with Provider under Provider’s Master Services Agreement and applicable Service Attachment, which will then govern that service.
19.4 Sections 5, 6, 7, 8, 9, 10, 12, 13, 14, 16, 17, 18, 21 and 22 survive the end of these Terms.
20. AMENDMENT
20.1Provider may amend these Terms at any time by publishing an amended version. An amendment does not apply retroactively to a Search already requested; the version in effect when you submitted the Request Form governs that Search.
20.2 No amendment, waiver or variation of these Terms proposed by you is effective unless agreed in writing and signed by an authorized representative of Provider.
21. GOVERNING LAW AND FORUM
21.1These Terms are governed by and are to be construed in accordance with the laws of the Province of Ontario and the federal laws of Canada applicable in Ontario, without regard to conflict-of-laws principles.
21.2The parties attorn to the exclusive jurisdiction of the courts of the Province of Ontario, and the Ontario Superior Court of Justice sitting in Toronto is the forum for any dispute arising out of or in connection with these Terms. Nothing in this Section prevents Provider from applying to any court of competent jurisdiction for injunctive or other equitable relief.
21.3 The United Nations Convention on Contracts for the International Sale of Goods does not apply to these Terms.
22. GENERAL
22.1Entire agreement. These Terms, together with the Request Form and the Schedule of Third-Party Services referred to in Section 14.3, constitute the entire agreement between the parties in respect of the Search and supersede all prior discussions, proposals and representations. Where the Requester and Provider have entered into a Master Services Agreement, that agreement governs all other services and these Terms govern the Search only; in the event of a conflict in respect of the Search, these Terms prevail.
22.2No partnership. Provider performs the Search as an independent contractor. Nothing in these Terms creates a partnership, joint venture, agency or employment relationship.
22.3Assignment. You may not assign these Terms or any right under them. Provider may assign these Terms to an affiliate or in connection with a reorganization or a sale of all or substantially all of its assets.
22.4Severability. If any provision of these Terms is held invalid or unenforceable, that provision is to be severed or read down to the minimum extent necessary and the remaining provisions continue in full force.
22.5No waiver. No delay in exercising, no course of dealing in respect of, and no partial exercise of any right or remedy constitutes a waiver of that or any other right or remedy.
22.6 Force majeure. Provider is not liable for any delay or failure to perform the Search caused by any event beyond its reasonable control, including the unavailability of any Third-Party Data Source.
22.7 No third-party beneficiaries. These Terms are for the benefit of the parties only, except that Provider’s Third-Party Data Sources may enforce Sections 5.1, 8, 12.2 and 14 as third-party beneficiaries.
22.8Notices. Notices to Provider must be sent to the address in Section 23 by email, courier or registered mail. Notices to you may be sent to the email address you provide on the Request Form and are deemed received on the day sent.
22.9Electronic records. The parties consent to the formation of this agreement by electronic means and agree that Provider’s records of your acceptance, including date, time and the version of these Terms displayed, are admissible and constitute prima facie evidence of your acceptance.
22.10Language. The parties have requested that these Terms and all related documents be drawn up in English. Les parties ont demandé que la présente entente et tous les documents qui s’y rattachent soient rédigés en anglais. Where a Requester is situated in Quebec, Provider will make a French-language version available on request and before acceptance.
23. CONTACT
System Support Canada Inc.
[Street address, City, Ontario, Postal Code]
Attention: Privacy Officer
Email: [[email protected]] Telephone: [ ]
SCHEDULE A — DARK WEB EXPOSURE SEARCH REQUEST FORM
The following fields must be captured before a Search is performed. Fields marked required are conditions of Provider’s performance.
FIELD | REQUIREMENT |
Legal name of organization | Full legal name of the Requester, including corporate suffix. Required. |
Business address | Street, city, province or state, postal code, country. Required. |
Name of person submitting | First and last name. Required. |
Title / position | Required. Used to evidence authority to bind the Requester. |
Business email address | Must be at a domain owned by the Requester. Required. Free webmail addresses are not accepted. |
Business telephone | Required. |
Approximate number of employees | Optional. |
Industry / sector | Optional. Used only for aggregated statistics under Section 16. |
Domain Name Assets | One or more internet domain names owned or controlled by the Requester. At least one required. Provider recommends a limit of three per request. |
Email Assets | Optional. Business email addresses issued by the Requester. Personal and webmail addresses are not accepted. |
Authority confirmation | Required unticked checkbox: “I confirm I am authorized to bind the organization named above and that it owns or controls every domain and email address I have listed.” |
Privacy authority confirmation | Required unticked checkbox: “I confirm the organization has the authority under applicable privacy law, and has given any required notice to the individuals concerned, to authorize this search and receive the results.” |
Terms acceptance | Required unticked checkbox: “I have read and agree to the Dark Web Exposure Search Terms and Conditions,” with “Terms and Conditions” hyperlinked to the current version. |
Marketing consent | Separate optional unticked checkbox: “I would also like to receive news, security updates and offers from System Support Canada Inc. I understand I can unsubscribe at any time.” |
Do not pre-tick any checkbox, and do not combine the terms acceptance with the marketing consent. Acceptance and consent must each be a separate, deliberate act by the person submitting the form. |
SCHEDULE B — ACCEPTANCE AND RECORD-KEEPING REQUIREMENTS
Because acceptance occurs on submission rather than by signature, Provider’s ability to rely on these Terms depends on the quality of its acceptance record. The following are internal requirements for Provider, not obligations of the Requester.
B.1Notice before acceptance. The full text of these Terms must be available to the Requester from the request form itself, by a clearly labelled hyperlink adjacent to the acceptance checkbox, and must open without requiring the Requester to leave the form or lose entered data.
B.2Unambiguous act of acceptance. Submission must require the Requester to tick an unticked checkbox confirming acceptance. The form must not permit submission if the checkbox is unticked.
B.3Record to capture. For every submission, Provider must record: the full submitted form contents; the date and time of submission with time zone; the originating IP address; the version number and effective date of the Terms displayed; a hash or archived copy of the exact text displayed; and the state of each checkbox.
B.4 Confirmation. Provider must send an automated confirmation email to the submitted business email address that restates the Monitored Assets submitted, attaches or links the accepted version of these Terms, and invites the Requester to notify Provider immediately if the request was not authorized.
B.5Version archive. Provider must retain a dated, immutable archive of every published version of these Terms and be able to produce the version applicable to any past Search.
B.6Pre-Search review. Before running a Search, Provider must confirm that each submitted domain resolves to the Requester and is not on the prohibited list in Section 6, and that the submitting email address is at a submitted domain. Any mismatch must be resolved with the Requester in writing before the Search proceeds.
B.7Kaseya condition precedent. Provider’s agreement with Kaseya requires prior written permission from the Client before Dark Web ID may be used on that Client’s monitoring assets, and expressly contemplates a prospective Client. The acceptance record created under this Schedule is Provider’s evidence of that permission and must be retrievable on request by Kaseya.
B.8Retention. Raw Exposure Data, including any Exception Data, must be deleted or securely destroyed within thirty (30) days of delivery of the Search Report. The Search Report and Request Form must be deleted or securely destroyed after twelve (12) months, except that the acceptance record may be retained for the period required to evidence authorization.
B.9Delivery of the Search Report. The Search Report must be delivered by a method that does not leave Exception Data in an unencrypted mailbox — for example a link to a secure portal with expiry, or an encrypted attachment with the key sent by a separate channel.
B.10Refusals. Provider must record the reason for any request it declines and retain that record, so that a pattern of refusals can be evidenced if Provider’s selection practices are ever questioned.
OPTIONAL ACCEPTANCE BY SIGNATURE
Acceptance of these Terms normally occurs on submission of the Request Form under Section 1.2. This block is provided for Requesters who prefer to execute a signed copy. Where signed, this block supplements and does not replace the Request Form.
THE REQUESTER Legal name of organization Signature of authorized representative Name (print) Title Date | SYSTEM SUPPORT CANADA INC. Signature of authorized representative Name (print) Title Date |
Not legal advice. This document was prepared as a drafting aid. It has not been reviewed by a lawyer licensed in Ontario. Statutory references — including the Personal Information Protection and Electronic Documents Act, the Limitations Act, 2002 (Ontario), Quebec’s Act respecting the protection of personal information in the private sector and Charter of the French Language, Canada’s anti-spam legislation, and the Criminal Code provisions relating to unauthorized use of a computer and identity information — should be confirmed with Ontario counsel before this document is published or relied on. |