Terms of Service

Last updated: August 2026

1. Acceptance of Terms

By creating an account, accessing the dashboard, or using GuardLMS APIs, SDKs, scanners or related services, you agree to these Terms of Service, our Privacy Policy, and our Data Processing Agreement at /dpa (which applies when we process personal data on your behalf as processor under GDPR Article 28). Accepting these Terms (including the registration checkbox that links to Terms, Privacy and DPA) constitutes acceptance of that legal package. If you do not agree, do not use the Service. You must be at least 18 and have authority to bind the organisation you represent. GuardLMS is offered for professional / business use (B2B). If you are a consumer under mandatory EU/Dutch consumer law, mandatory consumer rights remain unaffected to the extent they cannot be waived.

2. Definitions

'Agreement' means these Terms, the Privacy Policy, the DPA (where applicable), your order or plan selection, and any written addenda. 'Customer Content' means data you or your users submit to or generate through the Service about your organisation and monitored assets (including scan results and reports). 'Service' means GuardLMS as described in section 4. 'Plan' means your subscription tier and entitlements. 'Authorised Target' means a system you own or are explicitly authorised to monitor and test.

3. Service Provider

GuardLMS is operated by Ldesign Media, registered with the Dutch Chamber of Commerce (KVK) under number 86167979, address Vissershavenweg 65 - III, 2583 DL The Hague, Netherlands. These terms are governed by the laws of the Netherlands.

4. Description of Services

GuardLMS is a security monitoring and compliance-support platform for websites and learning systems. Depending on your Plan, features may include: (a) security configuration scanning (TLS/SSL, DNSSEC, IPv6, security headers, email authentication such as SPF/DKIM/DMARC and related deliverability checks); (b) uptime and availability monitoring with multi-channel alerts (email, SMS, Slack, Discord, Microsoft Teams, webhooks); (c) technology and LMS/CMS stack detection (including Moodle™, Canvas, Brightspace, WordPress and others); (d) platform-oriented vulnerability and advisory matching (plugins, themes, modules, CVEs); (e) performance signals such as Core Web Vitals where enabled; (f) optional JavaScript SDK for real-user error and performance monitoring; (g) breach-exposure signals for monitored domains; (h) visual change / journey monitoring; (i) DNS change detection; (j) authorised penetration testing (DAST) with explicit consent; (k) AI-assisted summaries, finding guides, audits, and report insights; (l) compliance evidence helpers and reporting (including NIS2-oriented materials where offered); (m) PDF/JSON reports, evidence and data exports, including white-label options where licensed; (n) multi-tenant organisation, team, API, and plugin/SDK integration capabilities; (o) agency-style portfolio monitoring where your Plan allows. Feature availability and quotas are defined by your subscription and the pricing page or order form at the time of purchase. We may improve, add or retire features with reasonable notice where material.

5. User Accounts and Security

You must keep credentials and API keys confidential and are responsible for activity under your organisation's accounts. Notify us promptly of suspected unauthorised use. Authentication may use email/password and/or Google SSO. We offer TOTP two-factor authentication with backup codes and recommend enabling it; organisation admins may require 2FA. We log logins and device signals to reduce account takeover risk. You must ensure only authorised personnel access findings that may be sensitive. You must promptly revoke access for leavers and rotate keys when compromised.

6. Acceptable Use and Authorisation

You may use GuardLMS only for lawful purposes and only against Authorised Targets. You must complete ownership or authorisation verification (for example DNS TXT, HTML meta tag, or approved plugin verification) before restricted scan types are fully enabled. You confirm that active security testing (including DAST) is permitted under applicable law (including Dutch criminal law on computer intrusion) and any third-party hosting or acceptable-use policies. You must not: (a) scan or pentest third-party systems without permission; (b) circumvent rate limits, plan quotas, or security controls; (c) resell raw scan output as a competing monitoring service without a written partner agreement; (d) attack, overload, or reverse engineer our infrastructure except as allowed by mandatory law; (e) upload unlawful, infringing or harmful content; (f) use the Service to develop a competing product by systematic extraction of non-public datasets; (g) misuse support or impersonation features. You remain responsible for how you use findings inside your organisation and toward your own customers.

7. Free Trials

If we offer a free trial, it is provided for evaluation, may be limited in features or duration, and may require a payment method only if we clearly state so. At the end of the trial, the Service may convert to a paid Plan only if you confirm purchase, or may expire and restrict access. Trial data may be deleted after a reasonable period if you do not convert. Trials are provided 'as is' without uptime commitments.

8. Beta and Preview Features

We may label features as beta, preview, early access or experimental (including certain AI capabilities). Beta features may be incomplete, change without notice, be withdrawn, or be less reliable. They are provided without warranties and may be subject to additional fair-use limits. Feedback you give on beta features may be used freely by us to improve the Service.

9. Subscriptions, Quotas and Fair Use

Plans, included features, site limits, scan limits, AI or pentest allowances, team seats and API usage are as published on our pricing page or your order form at signup. Soft or hard limits may apply when quotas are exceeded until you upgrade or usage resets. We may apply fair-use limits to prevent abuse of shared infrastructure (including excessive automated scanning, AI calls or API traffic that degrades the Service for others). We may change plan packaging with reasonable prior notice (generally 30 days for material reductions to paid entitlements during a committed term, except where required for security, legal or third-party dependency reasons).

10. Payment Terms

Paid plans are billed in advance monthly or annually via Stripe unless otherwise agreed in writing. Fees are generally non-refundable except where mandatory law requires otherwise, or where we expressly agree in writing (including clear pricing-page refund promises if any). Prices are typically shown excluding VAT; VAT is added where applicable based on your billing details. You are responsible for providing accurate VAT/tax information. Failed payments may lead to suspension after a grace period. You can manage payment methods and cancellations via account billing settings or the Stripe customer portal where enabled. Price changes take effect on the next renewal after notice, unless a fixed-term order states otherwise.

11. Agencies, Multi-Tenant Use and White-Label

If your Plan allows agency or multi-client portfolios, you may use GuardLMS to monitor Authorised Targets for your clients, provided you have their authorisation and any required data-processing arrangements with them. You remain our customer and are responsible for your clients' use and for lawful instructions to us. White-label or branded reports, where licensed, do not transfer ownership of GuardLMS software or allow you to present GuardLMS as your own platform. You must not remove notices we reasonably require. You are responsible for the accuracy of branding and client-facing statements you add to reports.

12. API, Plugins and Integrations

API keys, plugin connectors and third-party integrations (Slack, Teams, Discord, webhooks, SSO, etc.) are provided for your convenience. You must secure credentials, use HTTPS endpoints you control, and comply with third-party terms. We are not responsible for third-party services you enable. We may rate-limit or revoke keys that threaten security or stability. Deprecated API versions will be announced with a reasonable migration window where practicable.

13. Data Processing, Scanning and End Users

By adding a website you instruct and authorise us to probe it using automated techniques appropriate to the enabled features (HTTP(S) checks, TLS inspection, DNS queries, header and configuration analysis, technology fingerprinting, screenshots, and, when enabled and consented, active DAST). Optional SDK and visitor analytics collect data from your end users only if you install or enable them; you must provide required notices and consents under GDPR/AVG and ePrivacy / Telecommunicatiewet rules. Where we process personal data on your behalf as processor, the DPA at /dpa applies. You warrant that monitoring and testing the targets you configure is lawful. Explicit in-product pentest consent is required before DAST runs; consent records may be stored for audit. Customer Content remains yours; you grant us a worldwide licence to host, process, transmit and display Customer Content solely to provide and secure the Service and as otherwise permitted by the Agreement.

14. AI-Assisted Features

AI features (including but not limited to security summaries, finding guides, knowledge assistance, audits/fix plans, report insights, and pentest triage) generate suggestions from technical scan context. Outputs may be incomplete, outdated, or incorrect. They do not replace professional security, legal, or compliance advice and do not certify that a system is secure or regulatory-compliant (including under NIS2 or GDPR). You must review AI output before relying on it. Prompt and response logs may be retained for a limited time for quality and abuse prevention as described in the Privacy Policy. AI usage may be metered or plan-gated; fair-use limits may apply. We do not claim that customer prompts are used to train public foundation models under our control; third-party AI providers process data under their terms and our agreements with them.

15. Compliance and Audit Support — No Certification

Features described as GDPR evidence export, NIS2 readiness, compliance checklists, audit logs or similar are tooling to help you organise evidence and monitoring. They do not constitute a legal determination that you comply with any law or standard, and they are not a substitute for legal counsel, a formal audit, or certification by a notified body or supervisory authority. You remain solely responsible for your regulatory obligations.

16. Data Protection and Sub-processors

Our Privacy Policy describes categories of personal data. The DPA at /dpa (or a signed DPA) sets processor terms for end-user and other customer-controlled personal data. You authorise us to use sub-processors in the categories disclosed (hosting, email, SMS, payments, AI, threat-intel, CDN/security, and notification integrations you enable), with appropriate contractual safeguards. We remain responsible for sub-processor performance as required under the DPA and applicable law.

17. Confidentiality

Each party may receive non-public information from the other ('Confidential Information'). The receiving party will use it only to perform the Agreement, protect it with reasonable care, and not disclose it except to personnel and advisors under confidentiality obligations or as required by law (with notice where legally permitted). Customer Content and scan findings are your Confidential Information. GuardLMS product designs, non-public pricing, and security controls are our Confidential Information. Obligations survive for three years after disclosure, and longer for trade secrets as long as they remain secret.

18. Intellectual Property and Feedback

GuardLMS software, branding, documentation, and platform content are owned by Ldesign Media or its licensors and protected by IP laws. Your subscription grants a limited, non-exclusive, non-transferable right to use the Service for your internal business purposes (or for your clients if you are an authorised agency on an eligible Plan). You retain rights to Customer Content and reports generated for your monitored assets, subject to these terms and third-party licence constraints on underlying vulnerability databases or open-source components. If you provide feedback or suggestions, you grant us a perpetual, royalty-free licence to use them without obligation to you.

19. Third-Party and Open-Source Components

The Service may include or interoperate with third-party and open-source software. Those components are licensed under their own terms. Nothing in these Terms limits your rights under applicable open-source licences. Vulnerability intelligence and fingerprint data may be subject to third-party database licences and acceptable-use rules.

20. Customer Indemnity

You will defend and indemnify Ldesign Media and its officers, employees and agents against claims, damages, costs and reasonable legal fees arising from: (a) monitoring or testing systems you were not authorised to target; (b) Customer Content that infringes law or third-party rights; (c) your misuse of the Service or breach of these Terms; (d) claims by your clients or end users relating to your use of GuardLMS (except to the extent caused by our wilful misconduct). We will provide prompt notice and reasonable cooperation; you may not settle a claim that imposes obligations on us without our prior written consent.

21. Disclaimers of Warranty

Except as expressly stated in a signed SLA, the Service is provided 'as is' and 'as available'. We disclaim all implied warranties to the fullest extent permitted by law, including merchantability, fitness for a particular purpose, and non-infringement. We do not warrant that scans will find all vulnerabilities, that monitoring will be uninterrupted, or that results will be error-free.

22. Limitation of Liability

GuardLMS is a monitoring, detection, and reporting aid. It does not guarantee that monitored systems are free of vulnerabilities, available without interruption, or compliant with NIS2, GDPR, or any other regime. To the fullest extent permitted by Dutch law, we are not liable for indirect, incidental, special, consequential, or punitive damages (including breach of systems you monitor, lost profits, lost data, or reputational harm), whether in contract, tort or otherwise. Our aggregate liability arising from the Service is limited to the fees you paid for GuardLMS in the twelve (12) months before the claim (or EUR 100 if no fees were paid). Mandatory liability for intent (opzet) or deliberate recklessness (bewuste roekeloosheid) and other liability that cannot legally be limited remains unaffected.

23. Force Majeure

Neither party is liable for delay or failure to perform due to events beyond reasonable control, including natural disasters, war, terrorism, riots, embargoes, acts of civil or military authorities, fire, floods, accidents, network or utility failures, widespread internet failures, strikes, or shortages of transport, facilities, fuel, energy, labour or materials. The affected party will use reasonable efforts to mitigate and resume performance.

24. Export Control and Sanctions

You must not use the Service in violation of applicable export control, sanctions or trade laws of the Netherlands, the EU, the United Nations, or other applicable regimes. You represent that you are not a prohibited party under such laws and will not use GuardLMS for prohibited military or dual-use end uses where restricted.

25. Suspension and Termination

We may suspend or terminate access for material breach, abuse, non-payment, legal risk, or threat to the Service, with notice where practicable. You may cancel per the billing settings or by contacting support; access typically continues until the end of the paid period unless otherwise stated. Upon termination you should export Customer Content you need; we will delete or anonymise personal data per the Privacy Policy and DPA. Limited records may be retained for legal, tax, security or dispute purposes. Provisions that by nature should survive (including confidentiality, IP, indemnity, disclaimers, liability limits, and governing law) survive termination.

26. Data Export and Exit

During the subscription you may export certain data via product export features (for example JSON account export, reports, or evidence packs where available). On request within 30 days after termination of a paid Plan, we will reasonably assist with retrieval of remaining Customer Content still in our possession, subject to technical feasibility and security. After that period we may delete remaining Customer Content. We do not charge punitive exit fees for ordinary self-service export; extraordinary migration assistance may be quoted separately.

27. Service Availability

We aim for high availability but do not warrant uninterrupted service unless a separate written SLA applies. Maintenance will be communicated when reasonable. We are not responsible for failures of third-party networks, DNS, email providers, SMS gateways, AI providers, or force majeure. Separate SLAs may be agreed in writing for Enterprise customers.

28. Changes to These Terms

We may update these terms. Material changes will be notified by email or in-product notice with reasonable advance notice (generally at least 30 days). The effective date appears at the top of this page. Continued use after the effective date constitutes acceptance, except where mandatory law requires explicit re-consent. If you reject material changes you may cancel before they take effect.

29. Order of Precedence

If documents conflict: (1) a signed order form or enterprise agreement; (2) a signed DPA (for data-protection topics); (3) the online DPA at /dpa (for data-protection topics if no signed DPA); (4) these Terms; (5) the Privacy Policy; (6) documentation or marketing materials. Marketing pages are descriptive and not contractual warranties unless expressly incorporated.

30. General Provisions

These Terms are the entire agreement regarding the Service and supersede prior proposals on the same subject. If any provision is unenforceable, the remainder stays in effect. Failure to enforce a provision is not a waiver. You may not assign the Agreement without our prior written consent (not to be unreasonably withheld for affiliates); we may assign to an affiliate or successor in connection with a merger or sale of assets. Notices may be sent to the email on your account or to [email protected] / the postal address above. Headings are for convenience only.

31. Language Versions

These Terms may be provided in English and Dutch. For customers established in the Netherlands, the Dutch version prevails in case of conflict, unless mandatory law requires otherwise. For other customers, the English version prevails unless we agree otherwise in writing.

32. Governing Law and Disputes

These terms are governed by the laws of the Netherlands, excluding conflict-of-law rules that would refer to another jurisdiction. Courts of The Hague, the Netherlands, have exclusive jurisdiction, without prejudice to mandatory consumer protections if they apply. Parties will first attempt good-faith resolution for at least 30 days before filing suit, except for urgent injunctive relief.

33. Contact

Legal questions: [email protected]. Privacy: [email protected]. Postal: Ldesign Media, Vissershavenweg 65 - III, 2583 DL The Hague, Netherlands. Support and commercial enquiries: via the contact page or your account support channels.