Terms governing business access to and use of the Tesarus website, platform, APIs and related non-custodial treasury and stablecoin payment services.
Tesarus is the brand used for tesarus.com and the Tesarus business software. For the website, "Tesarus", "we", "us" and "our" mean its operator. We will make that operator's legal name, geographic business address and contact email readily accessible on the website. For a Customer agreement, these words mean the existing contracting supplier identified before acceptance under section 2.
Our "contact email" means the general contact address provided for the website operator or, for a Customer agreement, the supplier contact provided in registration or the accepted Company Service Terms. Use it for support, billing, contractual notices, complaints, export or switching requests and security reports, identifying the subject and company account without sending signing keys or recovery secrets. The supplier's identity and contact details form part of the Customer agreement.
Privacy requests and complaints can be sent to privacy-requests@tesarus.com. Our Privacy Policy explains the relevant rights and processing. We will keep these details current and identify any different supplier or controller before the relevant contract or processing begins, with any notice required by law. Updating contact details does not itself amend an agreed contract or provide consent to new processing.
These Terms govern the website at tesarus.com and the Tesarus business software, applications, interfaces, APIs and documentation that we make available under these Terms (together, the "Services"). The features available to a particular customer depend on its subscription, accepted Company Service Terms described in section 2 and the features enabled for that customer.
The Services are for business use. They are not offered for personal, family or household purposes. A "Customer" is the company or other legally recognised business entity that enters into a service agreement with Tesarus under section 2. An "Authorised User" is an individual the Customer authorises to use the Services for its business. A "Visitor" is a person accessing the public website without acting under a Customer agreement. A Customer can have authorised free access before accepting a paid plan. "You" means the Customer, Authorised User or Visitor, as the context requires.
Our Privacy Policy explains how we process personal data. It is a transparency notice, not consent to every type of processing and not a waiver of privacy rights.
A Customer agreement is with the existing person or organisation identified as the supplier before acceptance. That supplier undertakes Tesarus's contractual obligations. The Customer is the business identified in registration or the accepted agreement. Its representative confirms that they are legally capable of contracting and authorised to bind it. A representative or Authorised User gives no personal guarantee merely by registering, instructing payment, signing for the Customer or using the Services within their authority. Liability independently imposed by law for fraud, unlawful conduct or unauthorised representation remains.
Section 3 explains Tesarus's software role. The provisions about website use, content, intellectual property, third-party links and liability apply to Visitors to the extent effective as legal notices or terms of a validly formed agreement. A website visit alone does not create a Customer agreement or establish acceptance of every contractual provision. Where a Visitor is asked to accept website-use terms, the action signifying acceptance will be clearly identified with access to those terms beforehand. Intellectual-property rights and duties imposed independently by law remain applicable without a Customer agreement.
The Customer accepts these Terms when its authorised representative selects "Create company account and accept Terms", or an equivalent clearly labelled acceptance control, after identifying the business and being shown the contractual notice and links. The base Customer agreement takes effect when that registration button execute by the customer. The same acceptance incorporates the linked Data Processing Addendum for processing on the Customer's behalf, including during free access. No separate handwritten signature is required.
Creating the company account does not itself buy a paid plan or guarantee approval of a feature. Available free access is governed by these Terms; paid scope and activation follow section 2.3 or a Custom Agreement. Authorised Users must be at least 18 and comply with relevant access, security and acceptable-use requirements. The Customer supplies those requirements to its users and manages their authority. Joining an existing workspace does not create a new Customer agreement or make the individual personally liable for the Customer's fees or indemnities.
Company Service Terms means the company-specific Terms of Service, service agreement or order issued by Tesarus stating the supplier, Customer, service scope, price or agreed pricing method, currency, service period, start conditions and other commercial particulars. References to an accepted order include these Company Service Terms.
Tesarus may send Company Service Terms with an invoice as an offer expressly identified for acceptance by payment. Before payment, the Customer receives the complete offer, the applicable versions of these Terms and the DPA where relevant, and a clear notice that payment accepts them, drawing prominent attention to the provisions identified at the start of this section.
The Customer accepts that offer when Tesarus receives cleared payment of the amount specified for acceptance, within the offer's validity period, made or instructed by a person authorised to accept for the identified Customer. An expressly specified deposit or first instalment may be that amount; otherwise the full invoice amount is required. A withholding required by law and supported by the evidence under section 10 counts towards that amount. The agreed service period begins on the date stated in the offer or, if none is stated, on acceptance. No countersignature is required for an offer using this route. If there was no earlier Customer agreement, this acceptance also forms it on the supplied Terms.
Payment accepts only the offer identified with that invoice. Paying an existing debt, an automatic renewal debit, an unsolicited or mistaken transfer, or payment by an unauthorised person does not by itself accept new terms. A third-party payer does not become the Customer merely by paying. Late or insufficient payment is not acceptance unless Tesarus expressly confirms acceptance in writing. Amounts received for an unaccepted offer will be returned, subject to applicable law. Agreed activation and refund rights remain effective; account-registration discretion does not permit retention of payment for an unsupplied service contrary to the agreement.
Ordinary agreements under sections 2.2 and 2.3 use the stated acceptance actions and do not require wet signatures. Before online acceptance, the representative can review the documents and correct the submitted company or order particulars. Tesarus will send an electronic confirmation without undue delay, retain the accepted versions and make a reproducible copy available to the Customer. Records of notices, acceptance and payment may provide evidence; they are not conclusive proof of authority or agreement. The Privacy Policy governs related personal information.
The parties may instead or additionally enter into a separately negotiated Custom Agreement, signed by authorised representatives of the identified supplier and Customer, including through an electronic-signature service. It takes effect as it provides and overrides these Terms only to the extent it expressly says so. "Written" includes a retainable electronic record, and "signed" includes a legally valid electronic signature. Any formality required by law or an expressly agreed execution condition still applies. A change of contracting supplier requires an express agreement or a permitted transfer under section 21; neither payment nor a new brand description alone substitutes a party.
A Custom Agreement expressly varying these Terms takes priority, followed by the accepted Company Service Terms for their specific commercial particulars, then these Terms. An invoice or commercial order does not by itself change liability limits, dispute terms or other legal provisions; such a change requires an express Custom Agreement or valid amendment under section 19. A Customer purchase order, payment reference or supplier-portal condition does not amend the agreement unless expressly accepted by Tesarus in writing. Privacy notices and other website policies do not become contractual obligations merely by appearing on the website.
Tesarus provides business software for Customer-directed use of supported accounts and business records, including preparation and submission of transaction data authorised by the Customer. The Customer makes its own commercial decisions, selects recipients and instructions, and supplies the authorisations required by its account configuration. Only the features enabled under the accepted agreement are included.
Customer-controlled and owned blockchain accounts are accessed through the software; they are not deposit accounts with Tesarus. Tesarus does not hold Customer assets, possess usable Customer private keys, or possess the decryption keys needed to use Customer-encrypted signing material. Storage of encrypted material without the means to decrypt it does not give Tesarus the means to sign for the Customer.
Tesarus does not provide banking, custody, exchange execution or arranging, or discretionary management of Customer assets under this software agreement. Separately selected provider services are governed by section 8. Tesarus does not insure assets, guarantee transactions or asset values, or undertake to fund accounts, supply liquidity or replace lost assets. Any agreed fee sponsorship is limited to its expressly stated terms.
Access, recovery, discontinuation and liability are governed by sections 5 and 13–17; no service description adds an unagreed feature, service level or guarantee.
The Customer must be validly established, provide accurate registration information, identify its authorised representatives and beneficial owners when reasonably required, and maintain the permissions needed for its own business and use of the Services.
Access may depend on the Customer's place of incorporation, operations, ownership, personnel, counterparties and the requested feature. A country appearing on our Coverage page does not establish that every business, token, network or connected service is eligible there. Third-party providers make their own eligibility decisions.
Our geographic eligibility policy excludes Russian Federation and countries covered by an active country-specific sanctions programme maintained by the United Nations, United States, United Kingdom or European Union.
You must not use false information, a nominee, an undisclosed intermediary or location-masking tools to circumvent eligibility or sanctions restrictions. Legitimate security tools are not prohibited merely because they protect a connection.
Use by a business in a licensed or otherwise restricted sector, including gambling, financial services or digital-asset services, requires all legally required permissions applicable to that business and any separate written acceptance required by Tesarus. Access to Tesarus is not evidence that the Customer's business, counterparties or transactions are lawful.
Technical support for a token does not establish that it may lawfully be offered, promoted, exchanged or accepted for a particular purchase. The Customer must observe restrictions applicable to the asset, the use, the payer and recipient, and their locations. We may limit a feature, asset or use in a territory where required by law or our eligibility policy. Selecting a country, declaring professional status or accepting these Terms does not create a regulatory exemption, establish reverse solicitation, or replace a required authorisation for either party.
Technical compatibility with a token representing a security, derivative or other regulated financial product does not include permission to use the Services for that regulated activity. Such use requires a separate written agreement and all permissions applicable to the activities actually performed. An asset's exclusion from one cryptoasset regime does not establish its exclusion from other financial-services laws.
The Customer is responsible for selecting its administrators and signers, configuring approval rules and transaction limits, reviewing their actual operation, and keeping its permissions current. It must promptly remove departing or compromised users and check whether a change also requires an on-chain update. Changing an application role does not necessarily revoke an existing on-chain authority, token approval, session credential or external credential.
You must protect devices, email accounts, passkeys, PINs, recovery material, signing keys, API credentials and integrations; use supported security features; and keep appropriate independent backups. Do not send private keys, seed phrases, authentication codes or recovery secrets to Tesarus support. Customer systems and integrations must be tested before use with material assets.
Before using the Services with assets, and throughout its use, the Customer must create, securely retain and keep current the independent backups, signing and recovery material and configuration information needed to access its accounts without Tesarus. It must verify that its selected independent recovery method works for the actual account configuration and repeat that check after material changes. A copy held only in a Tesarus profile or dependent on continued platform access is not an independent backup. The Customer must not wait for a closure notice to make these arrangements. Recovery may require multiple people, third-party tools, network fees or technical assistance. The availability of an export feature does not guarantee recovery from every loss of credentials, configuration error or account-contract failure.
Before clearing browser storage, replacing a device, changing an authenticator or removing a signer, the Customer must check whether that action removes signing or recovery material needed for its accounts. Exporting statements or downloading a personal-data copy is not a backup of signing keys. Tesarus's inability to decrypt Customer-encrypted signing material also limits the assistance it can provide after that material or its independent recovery credentials are lost.
The Customer must maintain authority arrangements that address personnel changes, incapacity, internal disputes and loss of a required signer. A disputed instruction from an owner, employee or beneficial owner does not appoint Tesarus to decide ownership of assets or resolve the Customer's corporate dispute. We may seek reasonable evidence of authority and temporarily restrict affected software access where proportionate under section 14, or comply with a binding legal requirement. An interface restriction may not stop a person who retains on-chain authority from transacting independently.
Tesarus cannot promise to recover a lost key, bypass a signature threshold, restore access after every device or credential loss, reverse a blockchain transaction or replace missing assets. The Customer must use its own backups and a compatible independent solution if Tesarus access ends. Tesarus has no contractual duty to supply a replacement interface, recreate missing secrets or operate an account for the Customer. Any separately agreed recovery assistance is limited to the work expressly agreed and is not a guarantee of success. These account-recovery provisions do not reduce mandatory data-return, switching or security duties.
The Customer must notify us promptly at our contact email, marked "Security", if it suspects compromised access, unauthorised activity or a vulnerability. It should also take protective steps within its own control. Tesarus will never require a transfer of assets to a support representative's account to prove ownership or unlock access.
The Customer is responsible for the commercial decision to make a transaction and for checking the intended recipient, address, network, token contract, amount, decimals, fees, invoice details, transaction contents and approvals before authorisation. Addresses and asset names can be deceptive, and a successful signature does not prove that the intended recipient is trustworthy.
Subject to our security obligations, we may receive and handle electronic instructions for the software functions described in section 3, including submitting transaction data after the Customer has provided the authorisations required by its configured methods, unless we have received and can reasonably act on notice that the authority is compromised. Authentication records may be evidence of an instruction; they are not conclusive proof that the Customer authorised fraud or an error caused by Tesarus.
The Customer is responsible for instructions issued by its authorised personnel within the authority it granted and for its own failure to safeguard access. Responsibility for Customer instructions does not establish that the Customer caused a software defect. The contractual remedies, exclusions and limits for any alleged defect, breach or other loss are governed by sections 16 and 17, including their mandatory-law protections.
Transactions submitted to a blockchain may be irreversible, reordered, delayed, rejected or reorganised. A displayed status, estimate, webhook, invoice marker or transaction hash is not a guarantee of finality, receipt of cleared value or legal discharge of a debt. Confirmations and finality differ between networks. The Customer must reconcile records against the relevant authoritative sources and its own commercial arrangements.
An invoice, payment request or refund tool does not make Tesarus a party to the underlying sale or contract. The Customer handles its own invoices, taxes, deliveries, customer complaints, refunds and counterparty disputes. A refund is a separate transaction and may incur further fees. Tesarus has no general power or obligation to cancel or charge back an on-chain payment.
The Customer must specify acceptable assets, networks, amounts and payment conditions to its counterparties. It must decide how its underlying contract treats partial, excess, late, misdirected or unsupported payments and independently verify any refund destination. Expiry, cancellation or deletion of an invoice record does not disable a public receiving address, erase an on-chain transfer or guarantee that further payments cannot arrive. A reference-currency display is a valuation aid; it does not convert the asset, fix an exchange rate or create a debt payable by Tesarus in that currency.
Account creation, contract deployment, fee sponsorship and transaction submission may involve independent network or infrastructure providers. A fee estimate can change, and a failed transaction may still incur network charges. A transfer to an independent provider is not by itself authorisation for that provider to carry out an exchange. Any exchange requires the separate instructions and acceptance specified in that provider's contract.
Where a fee can be quoted or paid in a stablecoin, this does not mean the network requires no native transaction fee. Before the Customer accepts that feature, Tesarus will identify the relevant fee service, any separately supplied conversion, and the applicable limits and charges. Unless expressly agreed, Tesarus has no obligation to buy fee tokens, advance network charges or continue a promotional subsidy. A failure or withdrawal of a fee service can prevent submission through that route even while assets remain recorded at the Customer's address.
Reports, exchange-rate displays, alerts, classifications and screening results are operational tools. They may contain delays, incomplete coverage or errors. They are not audited financial statements, tax determinations, legal conclusions or assurances that a counterparty or asset is safe. The Customer remains responsible for its accounting and required records.
If you identify a suspected transaction or reporting error, notify support promptly with the relevant transaction identifiers and preserve the available records. Check the actual status before resubmitting an instruction, as resubmission can create a duplicate. We may assist within the agreed support scope and applicable data-access rules; assistance does not guarantee reversal or recovery. A delay in reporting does not by itself forfeit a valid claim or shorten a statutory limitation period, although the parties' duties to mitigate loss still apply.
Digital assets can lose all value. The Customer must assess whether the assets, transactions and account arrangements it chooses are suitable for its business. The following risks can occur together and amplify one another; they do not describe every possible loss or imply that every mentioned feature is available through Tesarus.
Software and access. Tesarus software, account contracts, calculations, updates and integrations can contain defects or vulnerabilities. An error can prepare or submit incorrect transaction data, duplicate an instruction, corrupt records or cause irreversible loss even when the Customer follows the expected steps. A contract can behave as programmed but produce an unintended result. A review of a component does not establish that the entire implementation has been reviewed or is safe. Malicious dependencies, unsafe integrations and compromised administration functions can defeat controls. The Customer must review instructions, retain independent records and limit exposure to a level its controls can support. Under section 5, permissive signing or recovery rules can enable theft, while restrictive rules, lost devices or unavailable co-signers can prevent legitimate access. A compatible independent recovery tool may be unavailable. Platform closure and the Customer's recovery responsibilities are governed by sections 5 and 14.
Fraud and transaction mistakes. Phishing, fake support, altered invoices, malicious QR codes, address substitution, insider misconduct and impersonation, including synthetic audio or video, can induce a harmful instruction. A valid signature is not evidence that a transaction is safe. The Customer must independently check recipients, permissions and instructions as required by section 6. Moving assets from an invoice address to a company account is a further Customer-authorised blockchain operation and can fail or incur fees. A fraudulent refund request can cause a second loss. Counterparties may default or dispute the underlying transaction; a blockchain record does not establish delivery of goods or lawful asset history.
Infrastructure and networks. Devices, communications, hosting, authentication, network-data providers and transaction-submission or fee services can fail, provide incomplete information or withdraw service. Attacks, malicious updates, congestion, forks and reorganisations can interrupt or alter transactions. Validators, sequencers, issuers, administrators or governance participants may be able to censor, freeze or change assets or transactions; some systems depend on very few operators. A supported network or asset does not guarantee security or continued support. Unsupported forks, airdrops and migrations may be inaccessible, and attempts to claim them can expose credentials. A familiar address on another network does not establish that its account contract or recovery method works there.
Asset value and redemption. Stablecoins can lose their reference value, become illiquid or cease to be redeemable. Their issuers, reserves, banking partners, collateral or technical mechanisms can fail. Redemption may require eligibility, minimum amounts, fees or a direct issuer relationship. Freezing powers can apply despite Customer control of signing keys, and insolvency can leave uncertain recovery rights. Bridged, wrapped and synthetic assets add bridge, reserve, oracle, custodian and redemption risks; similarly named tokens or networks can confer different rights. Displayed prices may be delayed or indicative. Spreads, slippage, inflation, interest rates and currency movements affect value, and no buyer may be available at the required time or price.
Other providers and information. Independent providers have the roles and risks described in section 8. Safeguarding is not necessarily deposit insurance, and registration in one country does not establish permission for every market or feature. A decentralised protocol may offer no identifiable contracting party, complaint process or practical recovery route. Screening can miss risks or produce false matches; reports and classifications may be incomplete or unsuitable for a particular filing. Neither a favourable result nor a supported asset or integration is a recommendation or legal clearance. Public blockchain entries and shared invoice or receipt links can disclose information beyond the intended recipients; the Privacy Policy explains those risks and the respective data-processing roles.
Law and external events. Regulatory changes, sanctions, taxes, capital controls, war, civil disruption, disasters, epidemics, banking failures and wider economic events can restrict access, value or transferability. Restrictions may concern a payment's purpose as well as its asset. Providers may withdraw service in anticipation of a change. Technical availability does not establish that an activity is lawful in every territory. The Customer remains responsible for its own business permissions, counterparties and tax treatment under sections 4, 6 and 9.
Tesarus does not provide deposit insurance, investor compensation, guaranteed liquidity, asset replacement or guaranteed redemption. Any independent provider protection depends on its actual terms and applicable law. Sections 16 and 17 govern responsibility and remedies; these risk disclosures do not waive rights or duties that cannot lawfully be excluded.
Some features may allow the Customer to connect to independent providers of fiat accounts, payment services, exchange, verification, screening, blockchain infrastructure or other services. Availability in the interface does not mean that Tesarus provides the underlying service or that all providers have the same permissions or protections.
Before the Customer activates a connected financial service, Tesarus will identify its independent provider and make the applicable service terms available. That provider determines its own acceptance, due diligence, prices, execution, custody arrangements, settlement, complaints and regulatory responsibilities under its contract and applicable law. The Customer must review the provider's terms and privacy information.
Assets the Customer sends to a third party may leave the customer-controlled account model described in section 3. Any third-party custody, safeguarding, account structure, redemption right, deposit protection or insolvency treatment depends on that provider's arrangements. Tesarus does not guarantee the provider's solvency, performance or authorisation in the Customer's country.
Third-party quotes and balances displayed by Tesarus are supplied or derived from external information. Estimates are not binding offers. A quote becomes binding only under the relevant provider's acceptance process. A submitted instruction does not itself guarantee provider acceptance or settlement. Any commission or referral charge affecting the Customer's decision or price will be disclosed where required before the relevant service is accepted. Disclosure does not permit a fee, commission or benefit prohibited by applicable law.
A third party's name or logo may identify its product, network or service. Its display alone does not establish endorsement, regulatory approval or a relationship beyond the one expressly and accurately described.
Tesarus may restrict or discontinue an integration. It is not responsible for an independent provider's acts or omissions merely because it supplies a link or connection. Tesarus's responsibility for its own performance and for suppliers whose conduct is legally attributable to it remains subject to sections 16 and 17, including their protection of duties and liabilities that cannot lawfully be excluded.
Roadmap statements about fiat accounts, exchange, credit, cards, yield or other future services do not make those services available or create a commitment to supply them. Access to a separately provided service depends on the provider's acceptance, eligibility rules and applicable terms.
You must comply with laws applicable to you and your use, including applicable financial-services, sanctions, export-control, anti-money-laundering, counter-terrorist-financing, anti-bribery, fraud, tax and data-protection requirements. The Customer must establish any source-of-funds, counterparty, reporting and recordkeeping controls legally required for its own activities.
You must not use the Services to:
A person subject to an applicable asset freeze or prohibition must not use the Services. Restrictions may also apply because of ownership, control or acting on behalf of a restricted person, even when that person or entity is not individually named on a list. You must provide accurate information reasonably needed to assess these restrictions and notify us of a material eligibility change.
We may conduct proportionate verification, investigate suspected misuse, request supporting information, restrict software access, preserve relevant evidence, and make disclosures or reports where required or lawfully permitted. We may be unable to explain a restriction where doing so is unlawful or would compromise an investigation or security. These rights do not create a promise to detect every unlawful transaction or a guarantee of the Customer's compliance.
The Customer is responsible for its unlawful conduct and the underlying activities of its business. Tesarus does not approve that conduct merely by providing software. These Terms do not displace Tesarus's own legal obligations, prevent regulators or law enforcement from acting, or transfer to the Customer a liability the law does not allow us to transfer.
Customer checks or screening information do not make Tesarus the Customer's outsourced compliance officer or promise to satisfy the Customer's customer-due-diligence, transaction-monitoring, travel-rule, reporting or recordkeeping obligations. Where those obligations apply to the Customer, it must meet them for its own activity. The Customer must not describe Tesarus to its own users as holding their funds, underwriting transactions, guaranteeing legality or providing a licence that covers the Customer's business. The Customer's own notices must accurately identify its role and any separately engaged financial provider.
Pricing is set separately for each Customer in its Company Service Terms. The price or agreed calculation method, billing currency, subscription period, included usage, payment schedule, renewal terms and any additional charges will be supplied with the relevant invoice before acceptance under section 2.3, or agreed in a Custom Agreement. Tesarus may charge only fees disclosed and accepted for the relevant Services. Blockchain charges and independent-provider charges are separate unless the accepted price expressly includes them.
Automatic renewal applies only for the period and on the cancellation terms disclosed and accepted before purchase. Unless the accepted order states otherwise, cancellation before the next renewal date stops the next renewal and access continues until the end of the paid period, subject to earlier suspension or termination under section 14. You may cancel through the billing controls provided or by emailing our contact email, marked "Cancellation". We will not create an automatic renewal that was not disclosed and accepted.
An invoice offering a new order under section 2.3 does not create a debt merely by being issued. Once the relevant order or agreement has been accepted, invoices are payable by its agreed due dates; an invoice cannot impose an unagreed payment term. The Customer must raise a billing dispute promptly and pay undisputed amounts when due. Raising a dispute does not waive rights merely because a period specified for administrative review has expired. No penalty, late charge or collection fee arises under these Terms unless separately and expressly agreed and legally permitted.
Prices exclude taxes that the law requires us to charge, unless stated otherwise. Each party is responsible for taxes legally imposed on it. The Customer may make a withholding required by law and must provide the relevant evidence; no tax gross-up is implied.
We will give at least 30 days' notice of a subscription price increase. It takes effect no earlier than the next renewal after that notice period, and the Customer may cancel before it takes effect. A change to a variable network or independent-provider fee follows the terms disclosed for that fee and does not give Tesarus an unrestricted right to increase an agreed fixed price.
Fees for Services already supplied are not refundable merely because the Customer did not use them. Refunds and fee waivers required by law, an accepted order or sections 14 and 16 remain available. Tesarus has no contractual lien over customer-controlled digital assets and no authority under these Terms to debit them to recover a debt. Any mandate for payment of Tesarus software fees must be separately granted and limited to the specified fee-payment purpose; it does not give Tesarus discretion over other Customer transactions.
During the authorised free-access or agreed subscription period, subject to compliance with these Terms and payment of fees where applicable, Tesarus grants the Customer a non-exclusive, non-transferable right for its Authorised Users to access the enabled Services for the Customer's internal business operations and expressly permitted integrations. An accepted API or embedded-service order may permit additional use within its stated scope. No other resale, sublicensing or managed-service right is implied.
Tesarus and its licensors retain rights in the proprietary Services, documentation and branding. You must not copy, sell, misappropriate, reverse engineer or circumvent protections of proprietary software except to the extent expressly permitted by us, an applicable open-source licence or a right that cannot lawfully be restricted. You may make the copies of documentation reasonably needed for authorised use.
Open-source components remain subject to their applicable licences. These Terms do not restrict rights granted by those licences, remove attribution requirements, or replace any required source-code offer. An open-source licence does not grant rights to Tesarus trademarks, proprietary interfaces or hosted services beyond its scope.
The Customer must secure its APIs and webhooks, validate incoming messages, observe documented limits and avoid duplicate or unintended instructions. Unless an accepted order expressly states otherwise, a sandbox uses test data and test assets, is not a production service and must not receive real assets or live personal data. Beta features may be changed or withdrawn and carry no availability or release-date commitment.
An API credential, webhook or software integration is not a discretionary financial mandate to Tesarus. The Customer must define and test its own automation rules, including authentication, permissions, duplicate prevention, reconciliation and failure handling. Events can be omitted or arrive late, more than once or out of order; the Customer must not treat a notification alone as final settlement. Any claim arising from Tesarus's own defect or breach is governed by sections 16 and 17.
As between the parties, the Customer retains the rights it holds in data and content it supplies. This does not transfer another person's rights or restrict applicable data-protection rights. It grants Tesarus only the rights reasonably necessary to host, transmit, process and display that content to provide and secure the Services, comply with applicable law and perform the agreement. This is not an unrestricted right to sell Customer data or use confidential information to train general-purpose AI models.
The Customer may voluntarily provide feedback. Tesarus may use non-confidential suggestions to improve the Services without a royalty obligation; this does not transfer ownership of Customer data or authorise disclosure of its confidential information. Neither party may use the other's name or logo as an endorsement or customer testimonial without prior written permission.
Each party must protect non-public business, technical and security information disclosed by the other in connection with the Services, use it only for the agreement or another lawful agreed purpose, and limit disclosure to people who need it and are subject to suitable confidentiality duties. This does not cover information independently developed, lawfully obtained without restriction, already lawfully known or made public without a breach.
Disclosure to professional advisers, auditors, insurers and prospective business acquirers is permitted on a necessary and confidential basis. A party may make a disclosure required by law or a competent authority and, where lawful, give the other party reasonable notice. Nothing restricts protected disclosures or communications with regulators or law enforcement. Ordinary confidentiality obligations continue for three years after termination; trade secrets remain protected while they qualify as such, and personal data remains subject to applicable law.
Each party must comply with the data-protection obligations applicable to its role. The Data Processing Addendum incorporated under section 2 governs processing on the Customer's behalf, unless a separately agreed DPA replaces it. Tesarus will not begin that processing, including during free use, before the applicable DPA and required processing particulars and safeguards are in place. The Customer must have a lawful basis for the data and instructions it provides, supply required notices, and avoid sending unnecessary sensitive information. These Customer duties do not remove Tesarus's independent duties.
Tesarus will maintain the technical and organisational security measures required by applicable law and any agreed data processing addendum. No security measure makes a system immune to compromise. Security incident notices and assistance are governed by applicable law and the agreed addendum; nothing in these Terms waives a person's statutory privacy rights or allows a required notice to be withheld.
Tesarus supplies access to the enabled software under the accepted agreement, subject to these Terms. Unless that agreement expressly provides a service level, there is no commitment to a particular uptime, uninterrupted availability, transaction speed, support response time or compatibility with every system. Support is limited to the channels and scope included in the accepted plan. Additional implementation, migration, account recovery or consultancy work requires a separate agreement. Any standard of care or duty that cannot lawfully be excluded remains applicable, subject to lawful limitations in sections 16 and 17.
Tesarus may update, replace, restrict or discontinue the Services or supported features, integrations, networks or assets, including immediately under section 14. No subscription creates a right to indefinite access or continued support of a particular version. An express service commitment in accepted Company Service Terms or a Custom Agreement, and any mandatory notice, continuity, switching or refund requirement, take priority.
If Tesarus materially removes paid functionality before the end of the paid period without providing a substantially equivalent alternative, the Customer may terminate the affected service and receive a proportionate refund of unused prepaid fees. This does not create compensation for consequential business or asset losses; section 17 governs those claims.
Support for an asset does not commit Tesarus to support a fork, airdrop, replacement token, migration, new contract version or alternative network. The Customer must independently assess and arrange access to any associated rights. Marketing, roadmap statements and assistance outside the agreed scope do not create an ongoing service, support or recovery obligation. Sections 16 and 17 govern warranties and liability.
Tesarus may stop providing any or all Services, suspend or terminate a Customer's access, and require closure of its Tesarus profile or company workspace at any time, in its discretion, for any reason or without stating a reason, to the fullest extent permitted by applicable law and the accepted agreement. Notice may take effect immediately on receipt or on a later date stated in it. No separate warning, breach or opportunity to cure is required unless applicable law or an express provision of the accepted agreement requires one.
A closure notice identifies the affected access and the deadline for stopping use and closing the Tesarus profile or workspace. If the Customer does not complete closure by that deadline, Tesarus may disable its logins, sessions, API credentials, integrations and other platform access without further notice. Tesarus may also block access earlier where permitted by the first paragraph, including to address a security threat, unlawful use or a legal requirement. It will give written notice as soon as lawful and practicable where an immediate block must precede notice. Reasons need not be disclosed except where law or the accepted agreement requires them.
This discretion is subject to any mandatory minimum or reasonable notice period, good-faith or fairness requirement, required explanation, data-return right or continuity obligation. No termination or restriction may amount to discrimination or retaliation prohibited by applicable law. Where such a requirement prevents immediate closure, the notice and restriction take effect only as permitted by that requirement. Tesarus will not use suspension, discontinuation or termination to evade an applicable switching obligation. Section 14.1 and the Data Processing Addendum prevail for their mandatory subject matter.
The Customer must stop using the affected Services by the stated deadline, arrange independent access using the backups and recovery material required by section 5, preserve required business records, and revoke or change permissions and integrations where appropriate. It bears the costs of its chosen independent tools, network use and account-recovery arrangements, subject to rights that cannot lawfully be excluded. Tesarus is not required to restore platform access merely because the Customer failed to keep a backup or complete closure.
Closing a Tesarus profile or workspace ends software access. It does not close or erase a Customer-controlled blockchain account, transfer its assets to Tesarus, require surrender of signing secrets, cancel pending blockchain activity or end a separate provider contract. After access is blocked, the Customer must use its own retained signing and recovery material through a compatible independent solution to seek access to its blockchain accounts. Availability, compatibility and successful recovery are not guaranteed. Missing or unusable recovery material may cause permanent loss of access; Tesarus does not undertake to recreate it, bypass account permissions or replace assets. Mandatory data-handling and switching assistance remain distinct from this account-recovery responsibility.
The Customer may end a subscription under section 10 or the accepted order. It may terminate for Tesarus's material breach that remains unremedied 30 days after written notice identifying it, or earlier where law requires or the breach cannot be remedied. Where Tesarus ends or permanently discontinues a paid service before the end of the prepaid period, or the Customer validly terminates for Tesarus's uncured material breach, unused prepaid fees for the affected period are refunded proportionately. Accrued undisputed fees remain due, subject to any fee remedy under section 16; no new early-termination penalty arises. Express refunds are not reduced by the damages cap in section 17 and do not waive mandatory remedies.
Ordinary termination does not promise continued login or API access. The Customer may request an export of its available business records through our contact email within 30 days after termination. Tesarus will verify authority and provide the export securely, without undue delay and within any applicable deadline, in a usable, commonly used electronic format; structured data will be machine-readable where required by law. Request-specific delivery arrangements are confirmed when the request is made, without reducing required pre-contract information or delaying a mandatory duty. A separate secure channel may be used where it lawfully fulfils the obligation. Standard exports carry no additional charge. No custom migration, destination compatibility or recovery of unavailable signing secrets is promised; mandatory interoperability and assistance duties remain effective. An export is not an asset transfer or a guarantee of account recovery. This request period does not shorten an applicable return, retention, retrieval, privacy or switching right. Data return, deletion, backups and lawful retention follow the DPA, Privacy Policy and section 14.1; access closure alone does not authorise premature erasure. Work beyond contractual or statutory duties requires a separate agreement.
Accrued payment rights, intellectual property, confidentiality, necessary data handling, limitations, indemnities, disputes and other provisions that need to continue survive only for that purpose.
A switching request does not authorise Tesarus to take custody of or transfer the Customer's stablecoins or other blockchain assets; those remain subject to the Customer's own account controls.
The Customer may give notice to our contact email, marked "Data export or switching", that it wishes to switch to another provider, move to its own on-premises infrastructure, or erase its covered data and digital assets on termination. For a provider switch, the notice must identify the destination provider. The notice period is 30 calendar days unless an earlier date is agreed.
After that notice period, Tesarus will enable switching without undue delay within a transition of no more than 30 calendar days. If that period is technically infeasible, Tesarus will give a substantiated explanation within 14 working days after the request and specify an alternative transition not exceeding seven months. The Customer may extend the transition once for a period it considers more appropriate. During transition the affected contract continues: Tesarus will provide reasonable assistance to the Customer and its authorised third parties, support its exit strategy, exercise due care to maintain business continuity and contracted functions, explain known continuity risks, and maintain the security required by applicable law throughout transfer and retrieval. The parties will cooperate in good faith.
The export covers Customer company, user, account and counterparty records; invoice, receipt, transaction and attachment records; reports and activity history; settings, Customer-provided integration configuration and other Customer input, output and metadata; and Customer-generated or directly related digital assets that the Regulation requires us to export. No legally exportable category is excluded as internal-function data. Tesarus's proprietary code, algorithms, internal credentials and other protected material outside the legally exportable scope, and unrelated records of other customers, are excluded without restricting independent statutory or open-source rights.
Required exports will use a structured, commonly used, machine-readable format, with the information needed to interpret them. Before contracting, Tesarus will provide the applicable switching procedures and known restrictions and a reference to its current hosted online export register describing available structures, formats, standards and interoperability specifications. It will keep that information current. Request-specific delivery arrangements may be confirmed when requested, consistently with those disclosures and applicable deadlines. Legally required open interfaces and interoperability assistance remain available without additional charge; no obligation to create new technology, transfer protected proprietary material or compromise security is assumed beyond applicable law.
For covered Services, Tesarus will publish the infrastructure jurisdictions on this Terms page before contracting and keep them current. To address international governmental requests concerning non-personal data, Tesarus will assess the legal basis and scope, restrict access, limit disclosure to what is lawful, seek clarification or challenge where appropriate, and notify the Customer where lawful and required. It will apply the measures required against international governmental access. These measures do not guarantee prevention of every lawful governmental disclosure. The Privacy Policy and DPA govern personal-data transfers.
Tesarus will notify the Customer when the affected contract terminates on successful switching, or when the notice period ends if erasure was chosen instead. After switching, retrieval will remain available for at least 30 calendar days following the end of transition. Following successful switching, Tesarus will erase the Customer's exportable data and customer-generated or directly related digital assets after that retrieval period or a later agreed date, subject only to legally required retention. This does not represent that Tesarus can erase independent public blockchain records. Personal-data rights and legally required deletion remain protected.
Tesarus does not charge separately for the standard export or switching required by this subsection. Otherwise payable standard service fees and refunds remain governed by the agreement and applicable law. Bespoke work beyond our contractual and statutory duties requires a separate agreement and must not obstruct or impose a charge on a mandatory switching right. This subsection imposes no new early-termination penalty and does not restrict mandatory switching, data-access or remedy rights.
Neither party is liable for delay or failure to perform to the extent caused by events beyond its reasonable control, including natural disaster, war, civil disorder, widespread telecommunications or energy failure, government action, or external network or infrastructure failure that reasonable precautions could not prevent. Lack of funds, ordinary market losses or a failure caused by the affected party's own breach is not excused merely by describing it as force majeure.
The affected party must take reasonable steps to limit the impact and resume performance, and give notice where practicable. This clause does not excuse amounts properly due for Services already supplied, breach of a mandatory security duty, or liability that cannot be excluded. If a material interruption continues for more than 30 days, either party may terminate the affected service; the Customer receives a proportionate refund of prepaid fees for the unused period following termination.
The Services and website information are provided "as is" and "as available", subject to the express commitments in the accepted agreement and rights that cannot lawfully be excluded. To the fullest extent permitted by law, Tesarus disclaims implied warranties and conditions, including merchantability, satisfactory quality, fitness for a particular purpose and non-infringement.
Tesarus does not warrant that software, account contracts, updates, integrations, calculations, records or security controls will be free of errors or vulnerabilities; that errors will be found or corrected; that access will continue; or that a transaction, export, migration or account-recovery attempt will succeed. There is no guarantee against loss of assets, data, access or business opportunity. Express data-return and security duties remain subject to their terms and applicable law.
For a material software defect that prevents an agreed paid function from operating substantially as agreed, the Customer must report the defect with reasonable supporting information. To the extent permitted by law, its exclusive contractual service remedy is for Tesarus, at its option and within a reasonable time, to correct or reperform the affected function, provide a practical workaround, or terminate the affected service and apply the fee remedy below. If correction or a practical workaround is not provided within a reasonable time, the Customer may terminate the affected service and obtain that fee remedy. If the affected service has already ended and correction would provide no practical remedy, the fee remedy applies instead.
The fee remedy is a proportionate refund of fees paid, and waiver of unpaid fees, attributable to the affected function for the period the defect materially prevented that function from operating as agreed, together with any unused prepaid fees after termination, without double counting. It cannot exceed the fees charged for the affected Service and periods. It does not compensate for asset losses or other business losses. A valid express service-level remedy applies where agreed. Mandatory rights preserved by section 17.1 remain unaffected. Any damages claim that remains available is governed by section 17; duplicate recovery is not permitted.
Website information and support are general information. They do not constitute personalised investment, legal, tax or accounting advice or a commitment to make the Customer's decisions. Each party relies on the express agreement and its own assessment. To the extent lawful and reasonable, no contractual remedy arises for a representation outside that agreement. Fraud, mandatory remedies and express contractual commitments are unaffected.
The business exclusions and caps below govern Customer claims and business use; they do not restrict a person's mandatory consumer rights.
Nothing in these Terms excludes or limits liability for fraud or fraudulent misrepresentation; death or personal injury caused by negligence; wilful misconduct or gross negligence to the extent the applicable law prohibits its exclusion or limitation; or any other liability that cannot lawfully be excluded or limited. Nothing limits a data subject's non-waivable rights, a regulator's powers, or a mandatory statutory remedy.
Where mandatory rules governing data access, use or related services apply, these Terms do not exclude prohibited categories of fault, remove protected remedies or impose an unfair limitation. Mandatory duties to protect, return or provide access to data and any required switching continuity remain effective. Each exclusion and cap applies only to the extent it satisfies applicable reasonableness, fairness and public-policy requirements.
Subject to section 17.1 and the express service remedies and refunds in these Terms, Tesarus and the Protected Persons exclude liability, to the fullest extent permitted by law, for business loss, damage, cost or expense arising from the use of, inability to use, or reliance on the Services, including a defect, bug, vulnerability, misconfiguration, failed update, inaccurate output, incorrect preparation or submission of data, duplicated or failed instruction, interruption, loss of access or failed recovery. The exclusion expressly extends to claims based on Tesarus's or a Protected Person's breach of contract or ordinary negligence where that liability may lawfully and reasonably be excluded.
This exclusion includes direct or indirect loss of digital assets, loss or corruption of records, loss of use and costs of account recovery, replacement services or business interruption arising from those events, but does not remove a data-related remedy or other liability protected by section 17.1. The Customer must maintain independent checks, backups and continuity arrangements appropriate to the value at risk. Those requirements do not deem the Customer to have caused Tesarus's fault or waive mandatory rights.
Tesarus is also not liable to the extent a loss is caused by the Customer's breach, incorrect instructions, inadequately protected credentials, unauthorised conduct for which the Customer is responsible, or independent market, issuer, counterparty, network or other external events outside Tesarus's responsibility. Where any exclusion in this section cannot lawfully apply, remaining liability is considered under sections 17.3 and 17.4 to the extent each is independently enforceable.
Separately from section 17.2, and subject to section 17.1, Tesarus excludes liability for indirect or consequential loss. To the extent lawful and reasonable, it also excludes loss of profit, revenue, anticipated savings, business opportunity, goodwill or reputation; loss arising from market movements or failure to achieve an expected exchange rate or return; and special, exemplary or punitive damages, whether characterised as direct or indirect and whether foreseeable or advised of in advance.
A direct asset loss or data-restoration cost is not reclassified as a market or indirect loss solely to avoid a mandatory remedy. If the relevant exclusions are unavailable, a remaining recoverable loss is subject to section 17.4 only where that cap is independently lawful and enforceable.
The exclusions in sections 17.2 and 17.3 and the caps in this section govern Customer claims and business use. Where liability remains after applying the lawful exclusions, the following caps are separate fallback protections, subject to section 17.1 and their own enforceability requirements. They do not limit a Visitor's mandatory consumer rights or impose the Customer's indemnity on a Visitor or individual Authorised User.
Subject to section 17.1, the total aggregate liability of Tesarus and the Protected Persons together for events first occurring in each Contract Year will not exceed the fees paid or payable to Tesarus for the affected Services during the three months immediately before the first event giving rise to liability in that Contract Year. A Contract Year is each 12-month period beginning on the base Customer agreement's effective date under section 2 or its anniversary. A later invoice, paid plan or additional order does not restart that period unless a Custom Agreement expressly provides otherwise. If the affected paid Services have been supplied for less than three months at that event, the cap is the fees paid or payable for their first three months under the accepted order, including the unexpired part of that period. For an agreed paid term shorter than three months, it is the total fees for that term. For a prepaid subscription, fees are allocated proportionately to the relevant service period. Amounts paid solely to an independent provider, network fees, taxes and the value of customer assets are not Tesarus service fees for this calculation.
Where no fee is payable for the affected business website access, trial or other free service, the aggregate cap is USD/GBP/EUR 100 or its equivalent in the agreement's billing currency. For free access outside a Customer agreement, the cap applies to events first occurring in each 12-month period starting on acceptance of the relevant agreement. Related events are attributed to the period in which the first related event occurred. Presenting a claim under multiple legal theories or against multiple Protected Persons does not multiply the cap. Any expressly agreed liability cap in a Custom Agreement or valid amendment under section 19 that overrides this section applies instead.
The cap applies to contract, tort including negligence, misrepresentation other than fraudulent misrepresentation, breach of statutory duty and other legal grounds to the extent permitted by law. It does not reduce a specific fee refund or waiver expressly due under these Terms. Each exclusion, category limitation and cap operates separately only to the extent legally permitted. If an exclusion is unenforceable, a cap applies only if it independently satisfies applicable reasonableness, fairness and other mandatory requirements; no substitute cap applies where prohibited by law.
"Protected Persons" means Tesarus's directors, officers, employees, founders, shareholders, contractors and agents acting in connection with the Services. Only the identified contracting supplier undertakes Tesarus's contractual duties under the Customer agreement. No Protected Person gives a personal guarantee or assumes those duties solely because of their position or participation in providing the Services.
To the extent permitted by law, the Customer will bring claims for Tesarus's contractual performance against the identified contracting supplier, and the exclusions and limits in this section also protect Protected Persons. These protections do not release an individual who is themselves the identified contracting supplier from that supplier's duties, or any person from liability for their own fraud or other independently actionable conduct that cannot lawfully be excluded.
The pricing and scope of the software service reflect this allocation of risk, subject to section 17.1. Tesarus is not an insurer of the Customer's assets or business. The Customer must decide what independent controls, contingency arrangements and insurance are appropriate for its exposure.
To the extent permitted by law, the Customer will indemnify Tesarus and the Protected Persons against damages, settlements approved under this section and reasonable external legal costs arising from a third-party claim to the extent caused by: the Customer's unlawful use of the Services; the Customer's fraud or deliberate misuse; its material breach of section 9; or an allegation that content or instructions supplied by the Customer infringe another person's intellectual property, privacy or other rights.
The indemnity does not apply to the extent a claim results from Tesarus's or a Protected Person's breach, negligence, fraud, wilful misconduct or other unlawful conduct. It does not cover a regulatory fine, criminal penalty or sanction that cannot lawfully be indemnified. It does not make the Customer responsible for a regulatory duty imposed on Tesarus merely because the claim concerns the Services.
Tesarus must give prompt notice of a claim, with delay reducing the obligation only to the extent it materially prejudices the defence, and take reasonable steps to mitigate loss. The Customer may control the defence with competent counsel reasonably acceptable to Tesarus. Tesarus may participate at its own expense, except that reasonable separate external counsel costs are recoverable where an actual conflict of interest makes a joint defence inappropriate. Regulatory proceedings remain under the control of the person legally required to respond.
No settlement may admit fault by, impose a non-monetary obligation on, or fail to fully release an indemnified party without that party's written consent, not to be unreasonably withheld. Tesarus may not agree a settlement at the Customer's expense without the Customer's written consent, not to be unreasonably withheld. There may be no double recovery. The liability cap in section 17 limits Tesarus's liability and does not cap this Customer indemnity.
We may propose updated Terms or an incorporated schedule by giving the Customer at least 30 days' notice of a material change and making the new version available to retain. Material changes to liability, dispute resolution, data-use permissions or other substantial rights require affirmative acceptance before they apply to an existing Customer, unless applicable law permits a different process and the Customer has expressly agreed to it in a signed agreement. The Data Processing Addendum's own amendment requirements continue to govern it. An identified amendment may be accepted through a clearly labelled online acceptance action or electronic signature. Paying an ordinary or renewal invoice, using an existing account or receiving a link to the latest website version does not by itself accept a material amendment.
We may make a change sooner to address a legal requirement or urgent security issue, but only to the extent necessary and with notice as soon as reasonably practicable. Changes do not retrospectively alter accrued rights, pending disputes or earlier transactions. If the Customer does not accept a material change, it may stop the affected service; where Tesarus cannot continue the previous terms, termination and the unused prepaid-fee refund provisions in section 14 apply.
An update to the Privacy Policy does not by itself obtain consent for processing that requires consent. Changes to a third-party provider's terms follow that provider's separate contract.
Please send a complaint or contractual dispute notice to our contact email, marked "Complaint" or "Legal notice", identifying the Customer and relevant events without including private keys or recovery secrets. Each party will use reasonable efforts for 30 days after receipt to resolve a dispute through an authorised business representative. This process does not prevent urgent protective proceedings, a privacy or regulatory complaint, or a claim needed to preserve a limitation period.
These Terms and contractual and non-contractual disputes arising from them are governed by the law of England and Wales. The courts of England and Wales have exclusive jurisdiction, except where mandatory law requires otherwise. Either party may seek interim protection in another competent court where needed to protect its rights without changing the forum for the underlying dispute.
This choice does not remove mandatory protections applicable to a person or activity, prevent a competent regulator from exercising its powers, or restrict data-protection rights to complain to an authority or bring proceedings in a forum provided by applicable law. No mandatory arbitration, class-action waiver or shortened statutory limitation period is imposed by these Terms.
Each party bears its own legal costs of the initial business-resolution process. Costs of formal proceedings remain subject to mandatory law and the competent court's powers.
The agreement does not create a partnership, employment relationship, joint venture, general agency or fiduciary relationship. Neither party may bind the other except under an express written authority.
The Customer may not assign the agreement without our written consent, not to be unreasonably withheld or delayed. Tesarus may assign the agreement to an affiliate or successor in a genuine reorganisation or transfer of the relevant business if the successor assumes its obligations, the transfer does not materially reduce the Customer's contractual protections, and we give notice. A transfer of personal data remains subject to applicable law. Other assignments require consent.
Tesarus may use suppliers to perform its obligations, subject to applicable law and the data processing addendum. This does not itself release Tesarus from those obligations. A failure to enforce a provision immediately is not a waiver. If a provision is unenforceable, it is severed or limited only as the competent court and applicable law permit; the remaining provisions continue so far as they can operate lawfully.
The agreement is the entire agreement for its subject matter, subject to the protections in sections 16 and 17. Protected Persons may enforce the protections. No other third party receives contractual enforcement rights, without affecting statutory rights. The contracting parties may vary or end the agreement without a Protected Person's consent.
Contractual notices must be sent to the Customer's designated contact in its registration or accepted agreement or, for Tesarus, the contact email or business address made available under section 1, or the supplier address expressly stated in the accepted agreement. We may send Customer notices to its registered administrative email. Each party must keep its contact details current. Email notice takes effect when delivered to the recipient's server without a failure notification, subject to evidence of non-delivery; an in-app notice alone does not replace an expressly required written notice. Service of court proceedings follows the applicable procedural rules.
The English version governs the agreement unless mandatory law or a signed agreement requires another version. These Terms do not override mandatory local-language or disclosure requirements.
Last updated: 1 October 2026
This Data Processing Addendum (DPA) sets the terms for processing personal data on a business customer's behalf when incorporated into a service agreement (Agreement). The parties are the existing person or organisation expressly identified before acceptance as the contracting supplier in the Agreement (Tesarus), and the business identified in the accepted company account, order or Agreement (Customer). Supplier identification and acceptance follow section 2 of the Terms and Conditions. The version of this DPA supplied before acceptance is incorporated through the same company-registration or identified payment-acceptance process, or through a Custom Agreement expressly incorporating it. No separate signature or checkbox is required for that incorporation, subject to mandatory law and any expressly agreed execution condition under Terms section 2.4. It applies before Customer Personal Data processing begins, including during free use. The initial Subprocessor disclosure must be supplied before authorisation under section 4 and Annex 3. Incorporation does not replace any transfer instrument or further particulars required by section 8.
Applicable Data Protection Law means privacy and data-protection laws applicable to the processing under this DPA, including, where applicable, the EU General Data Protection Regulation (EU GDPR), the UK GDPR and Data Protection Act 2018 as amended, and applicable US state privacy laws including the California Consumer Privacy Act as amended (CCPA). Terms such as controller, processor, personal data, processing, personal data breach, business, service provider and contractor have the meaning given by the applicable law. Customer Personal Data means personal data Tesarus processes on the Customer's behalf under this DPA. Subprocessor means a further processor engaged by Tesarus to process that data.
The Customer is the controller and Tesarus its processor for the processing described in Annex 1. If the Customer is itself a processor, Tesarus acts as its subprocessor, and the Customer confirms it has the controller's authority to appoint Tesarus and provide the instructions in this DPA. The Customer remains the contact for those instructions and assistance unless mandatory law or a separate written agreement requires otherwise.
Processing, controller, processor, service provider and contractor describe data-protection activities and roles, not custody of assets or discretion over financial decisions. The Terms and Conditions govern the business software and allocation of transaction responsibilities. This DPA covers its associated personal-data processing, including preparation and submission of Customer-authorised transaction data where enabled; it grants no authority to manage funds or approve a transaction's commercial merits or legality.
This DPA does not govern processing for which Tesarus independently determines its own purposes, as described in the Privacy Policy, or a separate provider's independent processing. Labelling a party does not override its actual role. A new independent purpose for Customer Personal Data requires a lawful basis and any notice or agreement required by law; it is not authorised merely by the preceding sentence.
This DPA prevails over inconsistent terms of the Agreement for its subject matter. Mandatory transfer instruments prevail as their terms require. The Agreement otherwise remains in effect. A representative gives no personal guarantee merely by accepting for a disclosed legal entity; obligations imposed on a person by law remain unaffected.
The Customer instructs Tesarus to process Customer Personal Data only to provide the Services described in Annex 1, operate the configurations and integrations it lawfully selects, follow its documented service instructions, and comply with this DPA. The Agreement, this DPA, accepted orders and actions by authorised administrators within the Services constitute documented instructions to the extent consistent with Applicable Data Protection Law. Instructions for international transfers of personal data remain subject to section 8.
Tesarus must not use Customer Personal Data for its own advertising, sell or share it for cross-context behavioural advertising, or use its contents to train a general-purpose AI model. It will not authorise a Subprocessor's own advertising, unrelated profiling or AI training outside the Customer's documented instructions and this DPA. Neither use of a feature nor a supplier's standard terms authorises an undisclosed secondary use. Any agreed AI processing will be described in the processing details and Subprocessor disclosure before it begins.
The Customer determines its purposes, information submitted, authorised users, retention instructions and lawful use of the Services. It is responsible for the legal basis, notices and, where required, consents for the processing it instructs. It must limit submitted information to what is appropriate for the agreed functions, keep information accurate as required, and use access and security settings suitable for its operations. These responsibilities do not release Tesarus from obligations imposed on it by law or this DPA.
Tesarus will process Customer Personal Data only on documented instructions, including for international transfers, unless a legal requirement recognised by Applicable Data Protection Law requires otherwise. For EU GDPR processing, this exception is limited to Union or Member State law to which Tesarus is subject; for UK GDPR processing, it is limited to UK domestic law. Tesarus will inform the Customer of the requirement before processing unless that law prohibits notification on important grounds of public interest. Foreign demands remain subject to section 8 and applicable transfer restrictions.
Tesarus will immediately inform the Customer if, in its opinion, an instruction infringes Applicable Data Protection Law. It may suspend only the affected processing while the parties address the instruction. Tesarus will explain the issue, allow the Customer to revise its instruction lawfully and avoid unnecessary disruption. No party is required to perform unlawful processing.
Instructions to publish, share or export records, invite users or connect providers must come from an authorised person. Tesarus may verify authority and restrict the affected action where there are reasonable grounds for doubt. A successful sign-in or instruction log does not conclusively establish lawful authority or excuse Tesarus's security obligations. Unauthorised disclosure remains subject to section 6 where it constitutes a personal data breach.
The Customer determines the audience and records for public or shareable links and must account for access without sign-in, forwarding and external copies where enabled. Tesarus applies the agreed access controls; a sharing instruction does not authorise disclosure of other records. Removing a user's access does not itself instruct deletion of retained records; sections 5 and 9 govern deletion and individual rights.
A material change to the agreed processing scope or a new sensitive-data category requires a documented amendment to Annex 1 and the safeguards needed for that change. Tesarus is not required to design a new service merely because it receives an instruction outside the Agreement. Necessary statutory assistance remains governed by this DPA.
Under this DPA, Tesarus will ensure that persons it authorises to process Customer Personal Data are bound by confidentiality commitments or an appropriate statutory duty of confidentiality. Tesarus will limit their access to what they need for their authorised work.
Tesarus will maintain technical and organisational measures appropriate to the risk throughout its processing of Customer Personal Data, taking account of the state of the art, implementation costs, nature, scope, context and purposes of processing, and risks to individuals. Its measures will address, as appropriate, confidentiality, integrity, availability and resilience; protection such as encryption or pseudonymisation; timely restoration after an incident; and regular assessment of effectiveness. Annex 2 sets out Tesarus's contractual security commitments.
Tesarus may update a measure to address changes in threats, technology or operations, provided that the update does not materially reduce the overall level of protection required by this DPA. Material changes remain subject to any required agreement or risk assessment. This clause does not authorise replacement of an expressly agreed safeguard with a materially weaker one.
The Customer safeguards its own devices, credentials, recovery material, authorised-user permissions and systems. Customer control of encryption or signing keys limits what Tesarus can inspect or recover; it does not excuse Tesarus from protecting the data and metadata it processes.
The Customer gives general written authorisation for the Subprocessors identified in Annex 3, subject to this section. Independent providers engaged directly by the Customer are not Tesarus Subprocessors merely because the Services connect to them; their actual role and contracting arrangement determine the position.
Tesarus gives the Customer notice of a proposed addition or replacement at least 30 days before the new Subprocessor begins processing Customer Personal Data. The notice identifies the provider, service, location and relevant processing and gives the Customer an opportunity to object on reasonable grounds related to data protection. Notice is delivered to the Customer's designated contact; updating the disclosure without the agreed notification is insufficient.
If the Customer objects within that period, the parties seek a practical resolution, such as a different configuration or provider. Tesarus must not use the proposed Subprocessor for the objecting Customer's data while the objection remains unresolved. If no workable resolution is available, either party may terminate the affected part of the Services on written notice before that processing begins. The Customer owes fees for service supplied; unused prepaid fees for the terminated period of the affected service are returned. No early-termination penalty applies to that termination.
If an urgent replacement is necessary to protect data or preserve essential service, Tesarus promptly explains the circumstances and obtains the Customer's specific written authorisation for any shortened notice period before that provider processes Customer Personal Data.
Before giving a Subprocessor access, Tesarus will enter into a binding written agreement imposing the same data-protection obligations as this DPA for the entrusted processing, with equivalent protection and sufficient guarantees of appropriate technical and organisational measures, as required by Applicable Data Protection Law. These include confidentiality, security, assistance, deletion and transfer obligations. Tesarus remains responsible to the Customer for the Subprocessor's performance to the extent required by law and keeps the Annex 3 disclosure current.
Taking account of the nature of the processing, Tesarus assists the Customer by appropriate technical and organisational measures, insofar as possible, to respond to requests to exercise rights under Applicable Data Protection Law. It notifies the Customer without undue delay of a request relating to Customer Personal Data received directly, unless prohibited by law, and does not decide the request on the Customer's behalf without instructions or an independent legal duty.
Taking account of the processing and information available to it, Tesarus assists the Customer with applicable security obligations, personal data breach notifications, data-protection impact assessments and prior consultations with a supervisory authority. Assistance is limited to the Services, processing and information reasonably within Tesarus's control, without restricting assistance required by law.
Ordinary assistance through existing service functions and compliance information is included in the agreed service. If an additional bespoke request requires substantial work beyond that scope, the parties may agree the work and reasonable charges in writing before it starts. Tesarus does not condition urgent or mandatory assistance on resolving a fee dispute, or charge the Customer to remedy a breach of this DPA attributable to Tesarus.
The Customer remains responsible for its controller decisions and communications unless the law assigns an obligation directly to Tesarus. Tesarus does not provide a general compliance guarantee for the Customer's business.
Tesarus notifies the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. It does not wait for a complete investigation before giving an initial notice.
To the extent available, the notice describes the nature of the breach, affected categories and approximate numbers of people and records, likely consequences, measures taken or proposed to address it and mitigate harm, and a contact for further information. Where details are unavailable, Tesarus provides them in phases without undue further delay.
Tesarus takes appropriate steps to contain, investigate and remedy the breach in relation to its processing, preserves relevant evidence and provides the assistance required by section 5. It keeps the Customer reasonably informed of material developments relevant to the Customer's duties.
Notification is sent to the Customer's incident contact in Annex 1. The Customer keeps that contact current. Tesarus may use another verified contact if the designated route fails. Neither a notification nor assistance is, by itself, an admission of legal liability.
The Customer determines notifications to individuals or authorities for processing for which it is controller. This does not prevent Tesarus from making a notification the law independently requires it to make. Where lawful and practicable, Tesarus coordinates such a notification with the Customer.
Tesarus makes available information necessary to demonstrate compliance with this DPA and applicable processor obligations, and allows and contributes to audits, including inspections, by the Customer or an auditor it mandates.
The parties first use relevant existing documentation and available independent assurance reports where these adequately answer the concern, without replacing an audit or inspection needed to verify compliance.
Routine reviews are scheduled during normal business hours on reasonable notice, with scope proportionate to the relevant processing and measures to protect other customers' information, security and confidentiality. Auditors must be suitably qualified and bound by confidentiality. These arrangements must not prevent an effective audit, regulatory inspection, urgent investigation of a credible breach, or any exercise of mandatory rights.
Each party bears its ordinary internal compliance costs. The Customer bears the cost of its own chosen auditor, except to the extent the Agreement, applicable law or a separately agreed remediation arrangement provides otherwise. No unspecified audit fee is payable to Tesarus without prior written agreement. A fee dispute does not block legally required access or information.
Tesarus informs the Customer if it becomes unable to meet this DPA or relevant processor requirements. The parties take the steps required by law to stop and remedy unauthorised processing, including proportionate suspension or termination where necessary. Tesarus cooperates with a competent supervisory authority as required by law.
Processing countries, remote-access locations and transfers are identified in Annexes 1 and 3. Tesarus must not make a restricted international transfer of Customer Personal Data unless the Customer's documented instructions cover it and a valid mechanism under Applicable Data Protection Law is in place.
Before a restricted transfer begins, the parties will enter into any required transfer instrument with the particulars applicable to that transfer. This may include the relevant European Commission Standard Contractual Clauses and the UK Addendum or International Data Transfer Agreement, with the applicable parties, modules, selections and annexes. Each party will carry out the transfer assessments and supplementary measures required of it by Applicable Data Protection Law.
Any reliance on an adequacy decision or certified-recipient framework must be valid for the particular recipient, information and transfer. If a mechanism ceases to provide a lawful basis, the parties implement a valid alternative or suspend the affected transfer. No clause in this DPA reduces protections or third-party rights in a binding transfer instrument.
Tesarus assesses legal demands for Customer Personal Data and, where legally permitted, informs the Customer, seeks appropriate clarification or challenges a demand where there are reasonable grounds, and limits disclosure to what the law requires. It does not volunteer unrestricted access because the Customer has accepted the Agreement. Duties under a binding transfer instrument also apply.
At the end of the relevant processing, Tesarus, at the Customer's choice, returns or deletes Customer Personal Data and deletes existing copies. Retention is permitted only where required by law recognised for that purpose under Applicable Data Protection Law, meaning Union or Member State law for EU GDPR processing and UK domestic law for UK GDPR processing. The Customer can communicate its choice through the contact in Terms section 1 or the agreed service process. Annex 1 governs return and deletion arrangements.
The closure date under section 14 of the Terms ends ordinary platform access. Where lawful, Tesarus may block the platform and provide required data return through a separate secure channel instead. Closure does not end mandatory return, deletion, privacy or switching rights, or required continuity during a statutory switching period. If the Customer gives no direction, deletion is the default after a reasonable opportunity to choose return and the end of any applicable retrieval period, subject to required retention. An immediate closure does not authorise deletion before that opportunity or a mandatory retrieval period ends.
Where a legal requirement prevents deletion, Tesarus identifies the applicable requirement and retained categories to the Customer unless prohibited, limits processing to that legal purpose, and deletes the data when the requirement ends. Personal data held for Tesarus's separate controller purposes must have an independent lawful basis and be identified as such; a generic legal-claims assertion does not reclassify all Customer Personal Data.
Backups awaiting deletion remain protected, are put beyond ordinary use and expire within the period in Annex 1. If restored for disaster recovery, relevant deletion instructions are reapplied before the data returns to ordinary use. On request, Tesarus confirms completion of return/deletion, identifies remaining lawful retention and explains the applicable final deletion date or criteria.
Tesarus cannot delete records maintained by independent public blockchain participants and will explain this limitation before the relevant use. The Customer must not instruct unnecessary publication of personal information. This limitation does not remove Tesarus's own data-protection duties or prevent deletion of off-chain records it controls.
To the extent the CCPA applies, the Customer discloses Customer Personal Data to Tesarus only for the limited and specified business purposes in Annex 1. Tesarus acts as a service provider or contractor, as applicable, complies with the CCPA and its regulations, and provides the same level of privacy protection required of a business for that information.
Tesarus must not sell or share Customer Personal Data; retain, use or disclose it outside the specified business purposes or direct business relationship; or combine it with personal information from another person or from Tesarus's own interaction with an individual, except as expressly permitted for a service provider or contractor by the CCPA and consistent with this DPA. The statutory ability to perform a permitted security or quality function does not authorise advertising profiles, cross-customer marketing or another incompatible commercial purpose.
Tesarus certifies that it understands these restrictions and will comply with them. It notifies the Customer if it determines it can no longer meet its applicable obligations. The Customer may take reasonable and appropriate steps to ensure use is consistent with its CCPA duties, and, on notice, stop and remedy unauthorised use. The information, assessment and audit process in section 7 supports those rights and does not restrict a legally required form of oversight.
Tesarus assists the Customer with applicable requests, including deletion or correction instructions and communication to relevant Subprocessors. Within the scope of section 5, it provides assistance required for the Customer's applicable cybersecurity audits, risk assessments and automated-decisionmaking obligations. The Customer supplies the instructions and information needed to address a request. Tesarus imposes equivalent applicable restrictions on persons it engages for the processing under section 4.
For other applicable US state laws, Tesarus adheres to the Customer's instructions and assists with rights requests, security, breach notifications and assessments as required, considering the nature of processing and information available. Each person processing data is subject to confidentiality; subprocessors are subject to the required written flow-down terms and objection process. Tesarus makes necessary compliance information available and permits the assessments required by the relevant law. Sections 3–9 apply to these activities.
As between the Customer and Tesarus, the Agreement's exclusions and limitations of liability, including Terms sections 16 and 17 where incorporated, apply to this DPA to the fullest extent permitted by law. DPA claims share the applicable aggregate cap with other Agreement claims; presenting the same loss under both does not create a separate cap or permit double recovery. These limits do not restrict non-excludable compensation or recourse rights, a regulator's powers, liability that cannot be limited, or obligations and third-party rights under a mandatory transfer instrument. They do not excuse performance of this DPA's duties.
This DPA continues while Tesarus processes Customer Personal Data, including any permitted retention after service termination. Confidentiality, security, permitted use, assistance, transfer, audit and deletion provisions continue for that data for as long as required to give them effect.
Material amendments require the parties' documented agreement, except for permitted Subprocessor changes and security updates under sections 3 and 4. A change required by mandatory law must preserve the required protections; the parties document the necessary amendment or stop affected processing that cannot lawfully continue. Website changes, routine invoice payments and renewal debits do not amend the accepted DPA or authorise a new purpose or material reduction of safeguards.
Parties and contacts. The parties and their contractual contact details are identified in the Agreement. Terms section 1 provides the current contact route unless the accepted Agreement specifies another supplier contact. Customer notices, including privacy, incident and Subprocessor notices, go to the relevant contact designated through its company account or Agreement, or otherwise to its primary account administrator. Each party keeps its contact details current. If the Customer acts as a processor, it must document its authority from the controller and provide the information needed to give effect to that controller's rights.
Subject matter. Processing of personal data contained in the Customer's business records and users' activity through the software features it uses under the Agreement.
Nature and purposes. Collection, recording, organisation, storage, retrieval, display, access management, transmission, reporting, export, correction and deletion of the data below to maintain the Customer's business records, apply its access settings, operate its selected connections and provide related support. This includes preparing and submitting Customer-authorised transaction data and displaying related status information. The Customer selects transactions and recipients; its authorised users make approval decisions. Tesarus records those decisions and applies the configured rules.
Processing outside this scope requires the agreement described in section 2. Transmission grants no discretion over Customer assets. A provider's independent processing is outside this annex.
Sharing instructions. The Customer's enabled sharing settings and documented instructions determine the records, recipients and integrations to which access is given. Before the Customer enables a public or shareable link, Tesarus will explain any access without sign-in and will apply the selected access restrictions. These instructions do not authorise disclosure of unrelated records.
Categories of people. The Customer's authorised users, personnel and business representatives; counterparties and their contact persons; and invoice contacts, payers and recipients whose data the Customer lawfully submits.
Types of data. Names, business contact details and company roles associated with Customer records; user identifiers and records of instructions and approval or rejection decisions made by the Customer's users; labels for Customer-controlled accounts, public blockchain addresses and transaction identifiers where linkable to a person; invoice, counterparty, payment-reference and transaction details; and documents and communications the Customer lawfully submits within this scope.
Sensitive data. No special-category, criminal-offence, identifying biometric or government-identifier data is authorised by default. Processing such data requires a separate express written agreement specifying the categories, purpose, legal authority and additional safeguards. Credentials and financial information within the ordinary agreed software functions remain subject to the protections required by the laws applicable to those categories.
The Customer must consider sensitive information revealed by descriptions, attachments and transaction inferences, not only fields labelled as sensitive. An accidental submission does not expand the agreed scope: the parties restrict the affected processing and agree lawful correction, removal or documented handling, while preserving any required incident response or legal retention.
Frequency and duration. Continuous or recurring processing while the Customer uses the relevant function and for the documented return/deletion period. Any exceptional retention follows section 9.
Locations. The disclosure provided to the Customer under Annex 3 identifies the authorised hosting, backup and remote-access countries and applicable transfer safeguards. Sections 4 and 8 govern changes and restricted transfers. Required public infrastructure-jurisdiction information for a covered hosted Service is addressed in Terms section 14.1.
Return and deletion. Tesarus will return Customer Personal Data securely in a usable form, using structured, commonly used and machine-readable formats where applicable. It will verify the requester's authority, confirm the format and delivery arrangements for the request, and provide the return without undue delay and within applicable deadlines. Request-specific arrangements do not replace information that must be provided before contracting or postpone a mandatory deadline. Terms section 14.1 governs applicable switching rights. A secure return route may remain available after ordinary platform access ends without reinstating that access. Standard exports and statutory switching carry no additional charge; section 5 governs separately agreed bespoke assistance.
Tesarus deletes active copies without undue delay, normally within 30 days after a verified deletion instruction or the end of the applicable return or retrieval period. Protected backups are put beyond ordinary use and expire no later than 90 days after active deletion, only where applicable law permits that delay. Any mandatory earlier deadline, including EU Data Act erasure at the end of a statutory retrieval period, overrides both periods. Only information subject to a specific legal retention requirement may be held longer under section 9. That section also addresses independently maintained public blockchain records. A personal-data export is not an asset transfer or a guarantee of account recovery.
Customer rights and obligations. Sections 2 and 4–9 govern Customer instructions, authorised users, return/deletion choices, assistance, information and oversight rights, subject to its controller or upstream-processor duties.
Under this DPA, Tesarus will apply the following measures from the start of processing Customer Personal Data and throughout its retention, in accordance with section 3:
Tesarus may provide confidential security evidence through a controlled channel, subject to the Customer's information and audit rights in section 7.
Tesarus will provide the Customer with a dated Subprocessor disclosure before the Customer authorises the relevant processing. That disclosure forms part of this annex for providers authorised under section 4. It will identify the legal name, address and contact details of each Subprocessor in the processing chain, its service and tasks, relevant data categories, processing and remote-access countries, and applicable transfer safeguard. It will also identify Tesarus's own relevant processing locations.
Tesarus will supply the disclosure directly through the separate Terms and Conditions document related to the Subprocessor services, containing the particulars above, by secure delivery or through a restricted customer resource. This disclosure does not itself create a contract between the Customer and a Subprocessor or alter Tesarus's obligations under section 4. Tesarus will provide updates proactively, keep the information readily available to the Customer and retain the associated notice and authorisation records. Changes remain subject to section 4. Public descriptions of provider categories do not replace this Customer disclosure or constitute authorisation of an unidentified Subprocessor.
Reasonable confidentiality arrangements may protect the disclosure, but must not prevent required access by the Customer, an upstream controller, their authorised advisers or auditors, competent authorities, or an individual entitled to recipient information under applicable law. This clause does not require publication of a complete supplier list or permit withholding information required by law.
Tesarus will identify a provider's independent-controller activities separately from its Subprocessor activities; connecting its service does not by itself make it a Subprocessor.
Section 8 governs restricted transfers and any required contractual safeguards. Tesarus will provide the relevant completed documents through the contact in Terms section 1, subject to lawful protection of confidential information. Where no restricted transfer occurs or a valid adequacy basis applies, Tesarus will record that basis. The Subprocessor disclosure does not itself create a transfer instrument or replace the safeguards in section 8.