diff --git a/SECURITY.md b/SECURITY.md index 98c98b7..b137607 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -5,3 +5,33 @@ If you discover a security vulnerability, please report it to **security@privkey.io**. Do not open a public issue. + +## Scope + +This policy authorizes research against: + +- **privkey.io** and its subdomains that we operate +- Our public repositories under [github.com/privkeyio](https://github.com/privkeyio) + +Out of scope, and not authorized by this policy: + +- Third-party services the Site uses (form processing, scheduling, CDN, font, and feed providers, and our hosting provider's shared infrastructure). Report issues in those to their own security programs. +- Systems belonging to our clients, whatever the connection to us +- Denial of service, resource exhaustion, and volumetric testing of any target +- Social engineering, phishing, and physical intrusion + +Anything intrusive beyond passive analysis and proof-of-concept verification against the in-scope assets requires prior written authorization and, for engagement-style testing, a signed Rules of Engagement document. + +## Coordinated Disclosure + +We ask that you give us a reasonable opportunity to fix an issue before disclosing it publicly, and that your testing stays proportionate: no denial of service, no degradation of the service for others, no social engineering of our staff or customers, and no access to, modification of, or exfiltration of data that is not yours. + +If you find data belonging to someone else, stop, and tell us what you found rather than how much of it you could reach. + +## Safe Harbor + +Research conducted in good faith, within the scope above, and in accordance with this policy is authorized. We will not pursue legal action over it, and we will not treat it as a breach of our Terms of Service. The acceptable-use section of the Terms is expressly subject to this policy. + +If a third party brings a claim against you for research that followed this policy, we will make it known that your activity was authorized. + +Testing outside this policy requires our prior written authorization. diff --git a/legal/PUBLICATION-CHECKLIST.md b/legal/PUBLICATION-CHECKLIST.md new file mode 100644 index 0000000..aa7dc48 --- /dev/null +++ b/legal/PUBLICATION-CHECKLIST.md @@ -0,0 +1,90 @@ +# Legal Documents: Publication Checklist + +**Internal working document. Do not publish this file or its contents to privkey.io.** + +Tracks what must be resolved before `privacy-policy.md` and `terms-of-service.md` can be published as public pages. + +Nothing here is legal advice. Items marked **counsel** need attorney sign-off; **ops** are ours to resolve and do not need a lawyer; **decision** needs a business owner to pick an option. + +## Resolved on 2026-07-30 + +Applied to the drafts. Attorney still confirms these in the final Group C pass, but no bracket remains. + +### First pass — facts, retention, commercial terms + +- **Company facts:** street address 8710 N Renfrew Pl, Tampa, FL 33604 (both contact blocks + ToS 19.7); ToS 1 set to "a Florida limited liability company"; PP 5.1 hosting row = GitHub Pages (GitHub, Inc.), with PP 3.2 noting GitHub holds request logs and does not expose them to us; PP 5.1 accounting row = Xero. +- **Retention (PP 8):** durations set — 24mo inquiries, term + 7yr engagement records, 12mo reports, **credentials/key material split out** to 5 business days, 30 days raw technical data, 7yr financial, 5yr sanctions-screening records (reserved), 12mo marketing, 12mo logs, 12mo applicants. Training-account retention row later removed (see service-list strike). PP 9 destruction reworded to 30 days + 5-business-day credential rotation + backup carve-out. +- **Aliases:** decision made to use `privacy@` and `legal@`; resolved throughout both docs. *(Creating + monitoring them is still an ops task below.)* +- **Commercial terms (ToS, all Group B numbers set):** net 30; interest at lower of 1.5%/mo or legal max, no compounding/stacking, suspend at 15 days; digital-asset refunds in USD at fiat value received; 5-year confidentiality survival; 30-day warranty notice; 12-month / USD $100 liability cap; 30-day termination-for-convenience; **split cure period 30 days / 10 days for payment breach**; 30-day informal resolution; one arbitrator; 12-month non-solicitation; 30-day change notice (ToS 19.11 + PP 16). +- **ToS §12.5 (time limit): DELETED.** A contractual limitations period under one year is void under Fla. Stat. §95.03; the agreement is Florida-governed and Florida-seated, so the clause was dead weight. Florida's 5-year written-contract SOL now governs by default. +- **Confirmed earlier (2026-07-27):** digital-asset payments are accepted, so ToS 8.6 and the PP blockchain-payment sections stay. + +### Second pass — vendors, controls, AI, custody, service list + +- **PP 5.1 business-operations vendors:** email/productivity = **Proton (Proton for Business)**; CRM = **no dedicated CRM; records kept in email and accounting systems**; payment = purpose changed to "Bank transfer and digital asset payments," provider **"No third-party card processor; we do not accept card payments"**; video conferencing = **Proton (Proton Meet)**; secure file transfer = **Proton (Proton Mail / Proton Drive)**; **sanctions-screening row struck** — we do not screen today. ToS 14's "may conduct" reservation left intact, so the strike is consistent. +- **PP 9 encrypted delivery channel:** resolved to **Proton Mail or Proton Drive, or PGP-encrypted files**. +- **PP 2 AI commitment:** softened to "we do not knowingly input client confidential information into any third-party AI tool that trains on that input," and now discloses AI-assisted tooling use. **Confirmed:** the AI assistant in use is **Claude (Anthropic) paid/API**, which contractually does not train on inputs, so the claim holds; verify-bracket removed. Proton for Business tier confirmed for the email row. +- **PP 12 security controls — attested per control.** Kept: TLS 1.2+ / at-rest encryption, MFA on all internal systems, least-privilege RBAC, **hardware security keys (YubiKeys)**, file-level encryption of stored client data (Cryptomator), segregated client environments, vendor security review. **Struck:** centralized monitored logging, background checks, annual awareness training. **Reworded for accuracy:** endpoint-protection/FDE → "file-level encryption of stored client data" (Cryptomator is file-level, no disk-level FDE claimed); "documented incident response with defined roles" → "incident response procedures" (not documented yet). Internal publication-gate note removed. +- **PP Privacy Lead:** **William K. Santiago**, privacy@privkey.io. +- **Custody redraft (ToS 3 multisig, MPC bullet, §3 closing, §4.1):** rewritten to match actual practice — **PrivKey never holds production keys and never takes custody of any key that controls client assets; in the multisig architectures we advise on, signing keys are held only by the client and client-approved third parties, never PrivKey; any key material we handle is confined to testing/PoC and never controls production assets.** MPC bullet → "controlling share"; §3 closing gate → "asset-moving authority." Supersedes the prior absolute "hold nothing, in any combination" language, which overstated it in the opposite direction. **Still counsel — MTL ratification (item below).** +- **Sunbiz confirmation (2026-07-30, from the filed 2026 Annual Report):** PRIVKEY LLC, document L18000284183, FEI 83-2811040, **Florida LLC** formed 12/11/2018. **2026 Florida LLC Annual Report filed 01/11/2026** (William K. Santiago, CEO) — current, no dissolution risk. Officers: William K. Santiago (CEO) and Kyle W. Santiago (CTO), both at 8710 N Renfrew Pl, Tampa FL 33604. Clears the ToS 1 "Florida limited liability company" confirmation. **BUT the report lists the principal place of business, mailing address, and registered agent as 7901 4th St N Ste 300, St. Petersburg, FL 33702 (Registered Agents Inc) — NOT the Tampa address the drafts use. See open item on the PPB conflict.** +- **PPB confirmed Tampa + Sunbiz pointer added (2026-07-30):** owner confirms 8710 N Renfrew Pl, Tampa is the true operating address, so all doc addresses and Hillsborough County arbitration stand. Added a Sunbiz-pointer sentence (ToS 1) and a "Florida Division of Corporations: sunbiz.org (Document No. L18000284183)" line to both contact blocks, so registration status and registered-agent details stay verifiable from the public record without yearly doc edits. Physical Tampa contact/notice address retained in both docs (required by GDPR Art. 13 and for notices). Only real-move relocations require future address edits. +- **Service list (ToS 3):** **struck #9** (compliance & AML/KYC advisory) and **#10** (training programs & educational resources); **narrowed #1** CCSS to advisory/guidance only (no auditing, no certification — points at §4.3); kept multisig/MPC advisory, self-custody, pen testing, smart contracts, Bitcoin/Lightning, AI tooling. **PP reconciled:** removed training-account data row (3.1), training retention row (8), "and training" (4 legal basis), "training programs" (1 overview). **ToS reconciled:** "educational and training materials" → "educational materials" (1), training→educational (4.2, 9.1, 9.6). **§3 publication-gate note removed.** + +--- + +## Still open + +### Deferred by decision + +| Type | Item | +|---|---| +| decision | **PP 8 assessment-report retention: 12 months conflicts with the liability window.** The same pass that cut reports from 3 years to 12 months also deleted ToS 12.5, which restores Florida's 5-year written-contract SOL. Exposure got longer while the evidence retention got shorter, and PP 9 "Findings retention" still says we keep the report "to defend against claims." At 12 months the report is destroyed with roughly 4 years of claim window left. There is also a row overlap: a delivered report is arguably "engagement records and correspondence" at term + 7 years, so two rows cover the same PDF with a 6-year gap. Pick one: (a) raise report retention to match the SOL, 5 years or term + 7 to align with engagement records; (b) keep 12 months, delete the defend-against-claims rationale from PP 9, and accept destroying our own evidence; (c) split explicitly, short retention for raw findings data and long retention for the delivered report. | +| decision → counsel + insurer | **ToS §12.3 confidentiality cap.** Deferred until counsel and insurer review. Left as drafted — option (a), uncapped confidentiality exposure — with the (a)-vs-(b) 3× super-cap decision box intact. The question for the insurer is whether the E&O/cyber policy responds to the uncapped exceptions at all, not whether its limit matches the 12.2 cap. Pick (a) or (b) after that review. | + +### Blockers for both documents + +| # | Type | Item | +|---|---|---| +| 1 | counsel | Full attorney review of both documents, with every remaining `[bracketed]` item resolved or struck | +| 2 | ops | Set the effective and last-updated dates on publication, and remove the DRAFT banner only at that point | +| 3 | done | 2026 annual report confirmed filed 01/11/2026 — see Resolved log. (Address conflict tracked in item 6.) | +| 4 | ops | Actually create and monitor `privacy@privkey.io` and `legal@privkey.io`. A rights request landing in an unmonitored alias silently burns the statutory response clock (45 days U.S. state / one month GDPR; PP 11.3 table) | +| 5 | ops | Convert both to HTML pages at `/privacy/` and `/terms/`, footer-link them, add both URLs to `sitemap.xml`. Markdown under `legal/` does not render as a page on a static host | +| 6 | ops | **PPB confirmed Tampa (2026-07-30).** Owner confirms 8710 N Renfrew Pl, Tampa FL 33604 is the true operating address, so both docs, `index.html` JSON-LD, and Hillsborough County arbitration stay unchanged. Remaining cleanup: correct the principal-place-of-business/mailing address on the **next Florida annual report** (currently shows the registered agent's St. Petersburg suite), so the public record matches. | + +### Privacy Policy + +| # | Type | Item | +|---|---|---| +| 7 | counsel/ops | Confirm the Section 8 retention schedule matches real practice — deletion ownership, legal-hold exceptions, backup handling. A published schedule you do not follow is worse than none | +| 8 | ops | Confirm the 30-day / 5-business-day destruction windows in Section 9 are operationally achievable, and build the certificate-of-destruction template | +| 9 | ops | Publish and maintain `privkey.io/subprocessors` before the Section 5.1 reference goes live, or remove the reference | +| 10 | ops | Re-verify Section 7 against the deployed Site on every publication — it asserts privkey.io sets no cookies and runs no analytics, true as built and false the moment a tag is added | +| 10a | ops | **`_headers` is inert on GitHub Pages.** Confirming hosting surfaced this: `_headers` is a Netlify/Cloudflare Pages convention, and GitHub Pages ignores it. `curl -I https://privkey.io` returns `server: GitHub.com` and no HSTS, X-Frame-Options, X-Content-Type-Options, COOP, COEP, or Permissions-Policy. The CSP is a `` tag, and per spec `frame-ancestors` is ignored in meta CSP, so both clickjacking defenses are absent. Not a legal-doc item; tracked separately | +| 11 | ops | Consider self-hosting the web font. Serving Google Fonts discloses every visitor's IP to Google — the pattern EU regulators have penalized; self-hosting removes the disclosure and the Section 5.1 row | +| 12 | ops | Build the rights-request intake workflow before publishing the address: named owner, logging, identity verification, Section 11.3 deadlines, Section 11.5 appeal path | +| 13 | ops | Add a notice-at-collection link beside the contact form in `index.html`. A footer link alone does not satisfy CCPA or GDPR Art. 13 | +| 14 | counsel | Determine whether EU/UK Article 27 representatives are required (PP 11.6, 17), and appoint if so | +| 15 | counsel | Prepare the standing DPA and SCC package referenced in Sections 6 and 9, and decide whether to publish a PGP key for `security@privkey.io` | +| 16 | counsel | Confirm the Section 5.4 commitment to challenge overbroad legal process is one we are prepared to fund | + +### Terms of Service + +| # | Type | Item | +|---|---|---| +| 17 | decision/counsel | **Section 18.7 consumer opt-out.** Training is struck, so the main consumer trigger is gone — but "self-custody consulting for individuals" remains, and an individual can be a consumer. Decide whether to include the 30-day arbitration opt-out and confirm the class waiver holds against consumer clients | +| 18 | counsel | **Money-transmitter ratification.** The custody redraft (ToS 3 / 4.1) now says PrivKey never holds production or controlling keys and only handles key material in testing/PoC. Confirm this matches every engagement and that holding no asset-moving key keeps us outside MSB/money-transmitter status | +| 19 | counsel | Confirm E&O and cyber liability coverage against the Section 12.2 cap and Section 12.3 exceptions (ties to the §12.3 deferral above) | +| 20 | counsel | Confirm the set cure periods, notice periods, payment terms, and interest rate are enforceable and market-standard, and that the caps, disclaimers, and indemnities hold under Florida law | +| 21 | ops | Build the security-testing Rules of Engagement template that Section 6 says we will not start work without | +| 22 | ops | Add click-to-accept or scroll-to-accept on the Site. Browsewrap acceptance by mere access is weakly enforceable, and Section 1 relies on it | +| 23 | ops | Confirm the MIT carve-out in Section 9.1.1 reflects the intent. Inventory which repo contents are actually PrivKey's (MIT does not cover third-party theme assets, fonts, images, or trademarks). If the intent is to reserve rights in the code, the license changes rather than the Terms | + +### Cross-document consistency + +| # | Type | Item | +|---|---|---| +| 24 | ops | `SECURITY.md` is the single source for the coordinated-disclosure safe harbor. PP 13.4 and ToS 15 both point at it; keep all three aligned if the process changes | +| 25 | ops | Key-material handling is stated across PP Section 2, ToS 5.1, and now the ToS 3 / 4.1 custody language: delete promptly, tell the client to rotate, never hold controlling keys, accept no responsibility for loss. Change them together | +| 26 | counsel | Final pass on everything, including whether the answers applied above create exposure we did not see | diff --git a/legal/privacy-policy.md b/legal/privacy-policy.md new file mode 100644 index 0000000..c6ae4d8 --- /dev/null +++ b/legal/privacy-policy.md @@ -0,0 +1,262 @@ +# PrivKey LLC — Privacy Policy + +**DRAFT FOR ATTORNEY REVIEW — NOT LEGAL ADVICE** +*Prepared for PrivKey LLC (privkey.io). Bracketed items require confirmation before publication.* + +**Effective Date:** [DATE] +**Last Updated:** [DATE] +**Version:** 1.0 + +--- + +## 1. Overview + +PrivKey LLC ("PrivKey," "we," "us") provides cybersecurity, blockchain, and digital asset security services from Tampa, Florida. Privacy and operational security are the substance of our work, and we hold ourselves to the practices we recommend to clients. + +This Policy explains what personal information we collect, why, who we share it with, how long we keep it, and the rights you have. It covers privkey.io (the "Site"), our services, and our sales, marketing, and recruiting activities. + +**Scope note.** When we perform services under contract for a business client, we typically act as a **processor** (or "service provider") for personal data in that client's systems. Our client's own privacy notice governs that data, and this Policy governs our direct relationship with you. Section 9 addresses what we do with data encountered during an engagement. + +## 2. Our Privacy Commitments + +We commit to the following, and these are enforceable statements, not aspirations: + +- **We never ask for and never want your private keys, seed phrases, key shares, wallet passphrases, or recovery material.** We do not collect them. If you send them to us, we will delete them and tell you to rotate. The single exception is non-production test key material that a Statement of Work expressly provides for, which never controls production assets and is destroyed or rotated on the schedule in Section 8. +- **We do not sell personal information**, and we do not share it for cross-context behavioral advertising, as those terms are defined under U.S. state privacy laws. +- **We do not use client engagement data to train third-party AI models.** We use AI-assisted tooling in delivering our services, and we do not knowingly input client confidential information into any third-party AI tool that trains on that input. +- We collect the minimum necessary and delete on the schedule in Section 8. + +## 3. Information We Collect + +### 3.1 Information you provide + +| Category | Examples | Why | +|---|---|---| +| **Contact and professional** | Name, email, phone, company, job title, country | Respond to inquiries, deliver services, manage the relationship | +| **Engagement** | Scope discussions, technical requirements, architecture details, correspondence, meeting notes | Scope, perform, and document the engagement | +| **Onboarding / KYC** *(reserved, not current practice)* | Identity documents, entity formation records, beneficial ownership, sanctions screening results. **We do not perform KYC or sanctions screening today.** This category applies only if an engagement or applicable law requires it, as reserved in Section 14 of our Terms of Service | Legal compliance, sanctions screening, fraud prevention | +| **Billing** | Billing contact, address, tax ID, bank details, invoice history, blockchain payment addresses | Invoicing, payment, accounting, tax | +| **Recruiting** | CV, work history, references, portfolio | Evaluate candidates | +| **Communications** | Emails, support tickets, chat, call and meeting recordings *where you are notified and, where required, have consented* | Support, quality, record-keeping | + +### 3.2 Information collected automatically + +**The Site does not use cookies, analytics, or any behavioral tracking.** We do not measure pages viewed, time on page, scroll depth, or interaction events, and we do not build visitor profiles. + +What is still collected as a technical consequence of serving the Site: + +- **Server access logs** kept by our hosting provider: IP address, timestamp, requested URL, referring URL, and user agent string. The provider holds and uses these for security, abuse detection, and delivery of the Site, and retains them under its own schedule. +- **Third-party requests your browser makes to load the Site.** Certain assets are served by third parties, and your browser discloses your IP address and user agent to them when it fetches those assets. These providers are listed in Section 5.1. We do not control their logging. + +Hosting is GitHub Pages (GitHub, Inc.). GitHub holds server-side request logs under its own privacy statement and does not expose them to us, so we keep no separate copy. Update this list if any third-party asset is added or removed. + +### 3.3 Information from third parties + +Business contact data from professional networks and vetted B2B sources; referral information; payment confirmations; and public blockchain data where relevant to an engagement. Sanctions and adverse-media screening results only if we conduct screening, which we do not do today (Section 3.1). + +### 3.4 What we do not collect + +We do not intentionally collect special category data (health, biometrics, race, religion, political opinions, sexual orientation, union membership) or government identifiers, except where identity documents are required for KYC under Section 3.1. Do not include such information in unsolicited communications. + +## 4. How We Use Information and Our Legal Bases + +| Purpose | Legal basis (GDPR/UK GDPR) | +|---|---| +| Respond to inquiries and provide proposals | Pre-contractual steps at your request; legitimate interests | +| Deliver contracted services | Performance of a contract | +| Invoicing, payment collection, accounting | Contract; legal obligation | +| KYC, sanctions screening, AML compliance, if and when we conduct it (Section 3.1) | Legal obligation; legitimate interests in preventing financial crime | +| Site security, fraud prevention, abuse detection, logging | Legitimate interests in securing our systems | +| Improve the Site and our services | Legitimate interests (the Site uses no analytics; see Section 7) | +| Marketing emails and newsletters | Consent, or legitimate interests for existing B2B clients on comparable services, always with opt-out | +| Establish, exercise, or defend legal claims | Legitimate interests; legal obligation | +| Recruiting | Pre-contractual steps; legitimate interests | + +We do not use personal information for automated decision-making producing legal or similarly significant effects. + +## 5. How We Share Information + +We disclose personal information only as follows: + +**5.1 Service providers (processors).** Bound by written contracts limiting use to our instructions, requiring confidentiality and appropriate security. Current categories: + +The following providers receive data through the Site itself: + +| Category | Purpose | Data involved | Provider | +|---|---|---|---| +| Contact form processing | Deliver messages sent through the form on privkey.io | Name, email, referral source, message text | Formspree | +| Appointment scheduling | Booking consultations | Name, email, meeting details you enter | Setmore | +| Content delivery network | Serving front-end libraries | IP address and user agent, disclosed by your browser | jsDelivr | +| Web fonts | Typeface delivery | IP address and user agent, disclosed by your browser | Google Fonts | +| Feed retrieval | Rendering our newsletter feed on the Site | IP address and user agent, disclosed by your browser | rss2json | +| Site hosting | Serving privkey.io, access logs | IP address, request metadata | GitHub Pages (GitHub, Inc.) | + +The following support our business operations rather than the Site: + +| Category | Purpose | Provider | +|---|---|---| +| Email and productivity | Business communications | Proton (Proton for Business) | +| CRM | Sales pipeline and client records | No dedicated CRM; records kept in our email and accounting systems | +| Accounting and invoicing | Billing, bookkeeping | Xero | +| Payment processing | Bank transfer and digital asset payments | No third-party card processor; we do not accept card payments | +| Video conferencing | Client meetings | Proton (Proton Meet) | +| Secure file transfer | Encrypted deliverable exchange | Proton (Proton Mail / Proton Drive) | + +**We use no web analytics provider.** + +*[Publish a maintained subprocessor list at privkey.io/subprocessors before referencing it here.] We will notify contracted clients of material changes.* + +**5.2 Subcontractors.** Where an engagement requires specialist personnel, under equivalent confidentiality and data protection obligations. + +**5.3 Professional advisors.** Counsel, auditors, insurers, and accountants under duties of confidentiality. + +**5.4 Legal and safety.** Where required by law, subpoena, court order, or regulatory demand; to enforce our agreements; or to protect the rights, property, or safety of PrivKey, our clients, or the public. **Where legally permitted, we will notify the affected individual or client before disclosing, and we will challenge requests we believe to be overbroad or unlawful.** + +**5.5 Business transfer.** In connection with a merger, acquisition, financing, or sale of assets, subject to this Policy continuing to apply to the transferred information. + +**5.6 With your direction.** Where you ask us to share, such as sending an assessment report to your auditor or insurer. + +**We do not sell personal information and have not done so in the preceding twelve months.** + +## 6. International Transfers + +We are based in the United States and process information there. If you are in the European Economic Area, United Kingdom, or Switzerland, your information will be transferred to and processed in the U.S. and potentially other countries. + +For such transfers we rely on the European Commission's **Standard Contractual Clauses** (and the UK International Data Transfer Addendum where applicable), supplemented by technical and organizational measures including encryption in transit and at rest, access controls, and data minimization. A copy of the relevant transfer mechanism is available on request at privacy@privkey.io. + +## 7. Cookies and Tracking + +**7.1 The Site sets no cookies.** privkey.io is a static site. It does not set cookies of any kind, does not use browser local or session storage, and carries no analytics, advertising, retargeting, or conversion tags. There is nothing to consent to and nothing to opt out of, so we do not present a cookie banner. + +Your browser still discloses your IP address and user agent to the third parties that serve fonts, front-end libraries, and our newsletter feed, as described in Sections 3.2 and 5.1. That is a property of loading those assets, not a tracking technology we deploy. + +**7.2 If this changes.** We will not deploy analytics or any non-essential cookie without first implementing a consent mechanism that meets the requirements of the laws applicable to the visitor, and updating this Section before the technology goes live. + +**7.3 Global Privacy Control.** We do not sell or share personal information, so there is no sale or sharing to opt out of. Should that ever change, we will honor the Global Privacy Control (GPC) signal as a valid opt-out request where applicable law requires. + +**7.4 Do Not Track.** Browser DNT signals lack a common standard. Because we perform no tracking, there is no tracking for a DNT signal to disable. + +[Re-verify this section against the deployed Site on every publication of this Policy. It is written to match privkey.io as currently built, and it becomes false the moment a tag is added.] + +## 8. Data Retention + +We retain personal information only as long as necessary, then delete or irreversibly anonymize it. + +| Data | Retention | +|---|---| +| Inquiries that do not become engagements | 24 months from last contact | +| Client engagement records and correspondence | Term of engagement + 7 years (professional liability and limitations periods) | +| Assessment reports and security findings | 12 months post-delivery, then deleted unless the client requests earlier deletion or longer retention | +| Client access credentials, and non-production test key material issued to us under a SOW | Destroyed or rotated within 5 business days of engagement completion — see Section 9 | +| Client raw technical data, scan output, artifacts | 30 days after final deliverable acceptance, then securely destroyed — see Section 9 | +| Financial and tax records | 7 years (legal obligation) | +| Sanctions-screening records, if any are ever created | 5 years after relationship ends (or as law requires) | +| Marketing contacts | Until unsubscribe + 12 months suppression-list retention | +| Site and security logs | 12 months, or the hosting provider's retention period where the host holds the logs | +| Unsuccessful applicant records | 12 months, or longer with consent | + +Retention may be extended where required by legal hold, ongoing dispute, or regulation. + +## 9. Security Engagement Data — Special Handling + +Security assessments generate unusually sensitive material: credentials, network topology, key management architecture, unremediated vulnerabilities, and exploitation evidence. We treat it accordingly. + +- **Isolation.** Client engagement data is segregated per client on encrypted storage with role-based access limited to assigned engagement personnel. +- **Credentials.** Test credentials issued to us are used only within the agreed scope and testing window. We ask that you **rotate or revoke all credentials issued to us immediately upon engagement completion.** +- **Encryption.** Data encrypted at rest and in transit. Reports and findings are delivered through encrypted channels — Proton Mail or Proton Drive, or PGP-encrypted files — never as unencrypted email attachments. +- **Sanitization.** Where the assessment objective permits, we sample and redact rather than exfiltrate. We do not retain full copies of client production databases. +- **Destruction.** Raw artifacts, tooling output, and captured data are securely destroyed within **30 days** of deliverable acceptance, and any access credentials, together with any non-production test key material issued to us under a SOW, are destroyed or rotated within **5 business days** of engagement completion. Backups containing this data are purged on their normal rotation cycle and remain isolated and encrypted until then. Certificates of destruction are available on request. +- **Findings retention.** We retain the final report and remediation record for the period in Section 8 to support your remediation and re-testing, and to defend against claims. You may request earlier deletion, subject to legal hold. +- **Incidental personal data.** Testing may surface personal data belonging to your employees or customers. We do not use it for any purpose beyond documenting the finding, minimize what appears in reports, and destroy it on the schedule above. +- **Data processing terms.** For engagements involving personal data, we execute a Data Processing Agreement incorporating GDPR Article 28 terms. Request one at privacy@privkey.io. + +## 10. Blockchain Data — Important Limitation + +Public blockchains are immutable, permanent, and publicly readable by design. **If you send a payment in Bitcoin or another digital asset, that transaction — including the sending address, receiving address, amount, and timestamp — is recorded permanently on a public ledger that no party, including PrivKey, can alter, delete, or make private.** + +This is a property of the technology, not a choice we make. **Rights of erasure and rectification cannot be exercised against on-chain data.** Those rights apply only to information held in our own systems, such as the association between a wallet address and your identity in our records, which we can and will delete on request subject to legal retention requirements. + +Consider this before choosing on-chain payment. We are happy to invoice conventionally. + +## 11. Your Privacy Rights + +**11.1 Rights available.** Depending on where you live, you may have the right to: + +- **Access** — obtain a copy of the personal information we hold about you +- **Correct** — have inaccurate information rectified +- **Delete** — request erasure, subject to legal retention obligations +- **Portability** — receive your information in a structured, machine-readable format +- **Object** — object to processing based on legitimate interests, including direct marketing +- **Restrict** — limit processing in certain circumstances +- **Withdraw consent** — at any time, without affecting prior lawful processing +- **Opt out of sale or targeted advertising** — though we do neither +- **Non-discrimination** — we will not deny services, charge different prices, or provide different quality because you exercised a privacy right + +**11.2 How to exercise.** Email **privacy@privkey.io** with your request and enough information to locate your records. We will verify your identity proportionately to the sensitivity of the request; we may ask you to confirm from the email address on file or provide additional verification for sensitive data. We do not require you to create an account to make a request. + +**11.3 Timing.** Deadlines differ by jurisdiction, and we apply whichever governs your request: + +| Jurisdiction | Our deadline | Extension | +|---|---|---| +| California (CCPA/CPRA) | Confirm receipt within 10 business days; substantive response within 45 calendar days of receipt | Once, by a further 45 days, with notice and an explanation given inside the first 45 days | +| Other U.S. state privacy laws | 45 calendar days of receipt | Once, by a further 45 days, with notice inside the first 45 days | +| EEA / UK / Switzerland (GDPR, UK GDPR) | Without undue delay, and at the latest one month from receipt | Up to two further months where the request is complex or numerous, with notice and reasons given inside the first month | + +Requests are free unless manifestly unfounded or excessive. + +**11.4 Authorized agents.** You may use an authorized agent where state law permits; we will require proof of authorization and may require you to verify your identity directly. + +**11.5 Appeals and complaints.** Several U.S. state privacy laws, including Florida's, give you a right to appeal a denial. Whether or not your state requires it, we offer the same route to everyone: if we deny your request, reply to our decision with "Privacy Appeal" in the subject line, and we will respond in writing with our reasoning within **45 days**, which is the deadline those statutes set. + +If the appeal is denied you may also complain to a regulator: your **EU/EEA Data Protection Authority**, the **UK Information Commissioner's Office** (ico.org.uk), or your **state Attorney General**. For Florida residents that is the Florida Attorney General, whose contact details we will include in any denial notice. + +**11.6 Region-specific.** +- **California (CCPA/CPRA):** You have the rights above regarding the categories in Section 3, collected for the purposes in Section 4 and disclosed to the recipients in Section 5. We do not sell or share personal information for cross-context behavioral advertising. The CCPA sets 16 as the age below which selling or sharing requires opt-in consent; since we do neither at any age, that provision does not apply to us. Our own minimum age is 18, as stated in Section 14. +- **Florida (FDBR):** Florida residents may have rights under the Florida Digital Bill of Rights; we honor the rights in Section 11.1 for Florida residents regardless of whether we meet the statutory applicability threshold. +- **EEA/UK/Switzerland:** Rights under GDPR/UK GDPR as described, including the right to lodge a complaint with a supervisory authority. [Appoint an Article 27 representative if you offer services to EU individuals without an EU establishment.] + +## 12. Security Measures + +We apply controls proportionate to the sensitivity of what we hold, including: encryption in transit (TLS 1.2+) and at rest; multi-factor authentication on all internal systems; least-privilege and role-based access control; hardware security keys for privileged accounts; file-level encryption of stored client data; segregated client data environments; confidentiality agreements binding all personnel and subcontractors; incident response procedures; and vendor security review before onboarding. + +**No system is perfectly secure.** We do not guarantee absolute security, and you transmit information to us at your own risk. Use the encrypted channels we provide for sensitive material. + +## 13. Breach Notification + +Our obligations depend on which role we hold over the affected data, and the two are different. + +**13.1 Data we control.** For personal information we hold in our own right, such as inquiries, billing records, recruiting, and Site logs, we notify affected individuals and the applicable regulators ourselves, without undue delay and within the timeframes the law sets. Where GDPR or UK GDPR applies and the breach is likely to result in a risk to individuals, that means **notification to the supervisory authority within 72 hours** of becoming aware. + +**13.2 Data we process for a client.** For personal data we handle on a client's instructions during an engagement, the client is the controller and we are the processor. Our obligation runs to the client, not to the regulator or the individual: we notify the client **without undue delay** after becoming aware, and support their own assessment and notification. We do not notify regulators or individuals directly on a controller's behalf unless the client instructs us to. Notification terms in your MSA or DPA govern and may be shorter than anything stated here. + +**13.3 Contents.** Notifications will describe what happened, the information involved, steps taken, and recommended actions. + +**13.4 Reporting to us.** To report a vulnerability or suspected incident involving PrivKey, contact **security@privkey.io**. Our coordinated disclosure process, including the safe harbor for good-faith research, is published in `SECURITY.md` in our public website repository, and the Terms of Service acceptable-use section is subject to it. We will not pursue legal action against researchers who follow that process. + +## 14. Children's Privacy + +The Site and Services are intended for business users and adults. We do not knowingly collect personal information from anyone under 18. If we learn we have, we will delete it promptly. Contact privacy@privkey.io if you believe a minor has provided information. + +## 15. Third-Party Sites + +The Site may link to third-party websites, tools, and resources. This Policy does not apply to them. Review their privacy notices before providing information. + +## 16. Changes to This Policy + +We may update this Policy. Material changes will be posted here with a revised "Last Updated" date, and, where we hold your contact details, communicated by email at least 30 days before taking effect. Where a change requires consent under applicable law, we will obtain it. Prior versions are available on request. + +## 17. Contact + +**PrivKey LLC** +8710 N Renfrew Pl +Tampa, Florida 33604, United States +Florida Division of Corporations: sunbiz.org (Document No. L18000284183) + +Privacy inquiries and rights requests: **privacy@privkey.io** +Security reports: **security@privkey.io** +General: information@privkey.io +Web: https://privkey.io + +Privacy Lead: William K. Santiago, privacy@privkey.io +[EU Representative (GDPR Art. 27): [NAME AND ADDRESS]] +[UK Representative (UK GDPR Art. 27): [NAME AND ADDRESS]] diff --git a/legal/terms-of-service.md b/legal/terms-of-service.md new file mode 100644 index 0000000..c697a3e --- /dev/null +++ b/legal/terms-of-service.md @@ -0,0 +1,268 @@ +# PrivKey LLC — Terms of Service + +**DRAFT FOR ATTORNEY REVIEW — NOT LEGAL ADVICE** +*Prepared for PrivKey LLC (privkey.io). Bracketed items require confirmation before publication.* + +**Effective Date:** [DATE] +**Last Updated:** [DATE] +**Version:** 1.0 + +--- + +## 1. Agreement to Terms + +These Terms of Service ("Terms") are a binding agreement between you ("Client," "you") and PrivKey LLC, a Florida limited liability company with its principal place of business in Tampa, Florida ("PrivKey," "we," "us"). PrivKey LLC is registered with the Florida Department of State, Division of Corporations (Document No. L18000284183); current registration status and registered-agent information are available at sunbiz.org. + +These Terms govern your access to and use of the website located at privkey.io (the "Site"), our educational materials, and any consulting, security, development, or advisory services we provide (collectively, the "Services"). + +By accessing the Site, requesting a proposal, or engaging us for Services, you accept these Terms. If you do not agree, do not use the Site or the Services. + +**If you are entering into these Terms on behalf of a company or other legal entity**, you represent that you have authority to bind that entity, and "you" refers to that entity. + +## 2. Order of Precedence + +Many of our Services are delivered under a separate written agreement — a Master Services Agreement ("MSA"), Statement of Work ("SOW"), engagement letter, or Rules of Engagement document. Where a conflict exists, the following order controls: + +1. A signed MSA or engagement letter +2. A signed SOW or Rules of Engagement for the specific engagement +3. These Terms + +These Terms govern all matters not addressed in a signed agreement, and govern Site use in all cases. + +## 3. Description of Services + +PrivKey provides professional cybersecurity, blockchain, and digital asset security services, which may include: + +- **Cryptocurrency Security Standard (CCSS) advisory** — guidance on the CCSS process and readiness; we recommend controls and help you prepare, but do not perform formal audits or issue certification (see Section 4.3) +- **Multisig Concierge Services** — advisory and configuration assistance for multi-signature wallet architectures, key generation ceremonies, key splitting and distribution, cold storage design, and recovery planning. **We never hold your production keys or key shares and never take custody of any key material that controls your assets. In the multi-signature architectures we advise on, signing keys are held only by you and any third parties you approve — never by PrivKey. Any key material we handle is confined to testing or proof-of-concept environments and never controls your production assets. You generate, hold, split, and distribute your own key material.** Where we assist at a key generation ceremony, we advise on procedure while you perform every operation that touches key material. +- **Private key management advisory**, including MPC-based architectures and geographically decentralized key management design. **Design and advisory only: we do not operate, host, or hold a controlling share in any MPC deployment for you.** +- **Self-custody consulting** for individuals and institutions +- **Penetration testing, threat intelligence, and incident response** +- **Smart contract development and auditing** across EVM and non-EVM chains +- **Bitcoin and Lightning Network infrastructure design and integration** +- **AI-assisted security tooling development and systems integration** + +Nothing in this Section is an offer to perform any service in a manner inconsistent with Section 4.1. Where a client requirement would place asset-moving authority — the ability, alone or in any combination within our control, to move your assets — in our hands, we decline the requirement or refer it to a licensed custodian. + +The specific scope, deliverables, milestones, assumptions, and exclusions of any engagement are defined solely in the applicable SOW. **Any task not expressly described in a SOW is out of scope.** + +## 4. What PrivKey Is Not + +This section is material to the bargain between us. Read it carefully. + +**4.1 We are not a custodian.** PrivKey does not take custody or control of your digital assets. We never hold your production keys and never take custody of any key that controls your assets, and we never hold key material sufficient to move your assets, alone or in any combination within our control. We do not hold assets on your behalf, do not have unilateral or discretionary authority to move your assets, and are not a money transmitter, money services business, exchange, broker, or trust company. You retain sole control of your assets at all times. + +**4.2 We do not provide investment, financial, tax, accounting, or legal advice.** Nothing on the Site, in our educational materials, or in our deliverables constitutes a recommendation to buy, sell, or hold any digital asset, security, or financial instrument, nor an opinion on the legal or tax treatment of any transaction. Educational content is general in nature. Engage qualified counsel and licensed advisors for those matters. + +**4.3 We are not a certification body.** CCSS-related work is advisory. Where a formal certification or attestation is required, it must be issued by an accredited auditor or licensed CPA firm, and we will say so in the SOW. + +**4.4 Security assessments are point-in-time.** An audit, penetration test, or code review reflects the systems, code, configurations, and threat landscape existing during the assessment window and within the agreed scope. It is not a guarantee that your systems are secure, free of vulnerabilities, or immune to compromise, and it does not extend to changes made after delivery. + +**4.5 Smart contract audits do not guarantee correctness.** A smart contract audit is a best-effort review. It does not guarantee the absence of bugs, economic exploits, oracle manipulation, governance attacks, or vulnerabilities arising from composability with third-party protocols. We make no representation regarding the value, viability, or regulatory status of any token or protocol we review. + +## 5. Client Responsibilities + +You agree to: + +- Provide accurate, complete, and timely information, access, credentials, documentation, and personnel necessary for us to perform +- Designate a primary point of contact with authority to make scope and approval decisions +- Maintain your own independent backups of all data, keys, and recovery material +- Independently verify and test all deliverables in a non-production environment before production deployment +- Retain sole responsibility for the security of your operating environment, personnel, and physical facilities +- Comply with all laws applicable to your business, including AML/KYC, sanctions, securities, and data protection laws + +**5.1 Key material.** You are solely responsible for generating, recording, backing up, and safeguarding your own seed phrases, private keys, key shares, passphrases, and recovery material. **PrivKey cannot recover lost keys or seed phrases. Loss of key material generally results in permanent, irreversible loss of assets.** Do not transmit private keys, seed phrases, key shares, wallet passphrases, or recovery material to us by any means. The single exception is non-production test key material that a SOW expressly provides for, which never controls production assets. Consistent with Section 2 of our Privacy Policy, if you do so we will delete the material promptly and tell you to rotate or regenerate the affected keys. We do not retain it, we do not use it, and we are not responsible for any loss arising from your having transmitted it. + +**5.2 Delays.** Timelines assume your timely cooperation. Delays attributable to you may result in schedule extensions and additional fees at our then-current rates. + +## 6. Authorization for Security Testing + +This section applies to penetration testing, red teaming, vulnerability assessment, and any other offensive or intrusive security work. + +You represent and warrant that, for every asset, system, network, domain, wallet, contract address, or account within scope, you either **own it** or hold **express written authorization from the owner** to permit testing by PrivKey. + +Before testing begins, the parties will execute a written Rules of Engagement document specifying: in-scope targets and explicit exclusions, testing windows, permitted techniques and prohibited techniques, escalation and emergency contacts, data-handling requirements, and third-party notifications (e.g., cloud or hosting providers whose terms require pre-authorization). + +We will not commence testing without a signed Rules of Engagement. We may suspend or terminate testing immediately if we believe authorization is absent, inaccurate, or has been withdrawn. + +**You will indemnify PrivKey in full against any claim arising from your failure to hold valid authorization for any in-scope target.** This obligation survives termination and is not subject to the liability cap in Section 12. + +## 7. Vulnerability Disclosure and Findings + +Findings are delivered confidentially to you. We will not publicly disclose vulnerabilities specific to your systems without your written consent, except where disclosure is legally compelled. + +We retain the right to disclose vulnerabilities discovered in **third-party or open-source software** to the responsible maintainer under coordinated disclosure practice, provided the disclosure does not identify you or include your confidential information. Where practical, we will notify you first. + +We may publish anonymized, aggregated statistics and generalized threat research derived from our work, provided no client is identifiable. + +## 8. Fees, Invoicing, and Payment + +**8.1 Fees.** Fees, rates, and payment schedules are set out in the applicable SOW or proposal. Estimates are not fixed-price quotes unless expressly labeled as such. + +**8.2 Payment terms.** Unless the SOW states otherwise, invoices are due **net 30 days** from the invoice date. We may require a deposit or retainer before commencing work. + +**8.3 Late payment.** Overdue amounts accrue interest at the lower of 1.5% per month or the maximum rate permitted by law, without compounding or stacking. We may suspend Services and withhold deliverables on accounts more than 15 days past due, on written notice. + +**8.4 Expenses.** Pre-approved travel and out-of-pocket expenses, including third-party hardware purchased at your direction, are billed at cost. + +**8.5 Taxes.** Fees are exclusive of all sales, use, VAT, and similar taxes, which are your responsibility, excluding taxes on our net income. + +**8.6 Payment in digital assets.** Where we agree in writing to accept payment in Bitcoin or another digital asset, the invoice will specify the asset, network, the fiat-denominated amount owed, the reference exchange rate and source, and a settlement window. **You bear all network fees and price volatility risk within the settlement window.** Payment to an incorrect address, on the wrong network, or below the invoiced amount is your responsibility and generally cannot be reversed or recovered. Digital asset payments are non-refundable except as required by law; approved refunds will be issued in USD at the fiat value we received, not in digital assets. + +**8.7 Verify payment instructions.** Invoice and wire fraud is common in this industry. **Always verify payment addresses and banking details by voice with a known PrivKey contact using a number you already have. We will never send changed payment instructions by email alone.** We are not liable for funds sent to addresses or accounts you did not verify through this channel. + +## 9. Intellectual Property + +**9.1 PrivKey background IP.** We retain all right, title, and interest in our pre-existing and independently developed materials — methodologies, frameworks, templates, checklists, tooling, scripts, know-how, educational materials, and the Site and its content. Nothing transfers ownership of these to you. + +**9.1.1 Open-source carve-out.** This Section does not revoke, narrow, or condition any license we have already granted publicly. The source code of privkey.io is published under the MIT license in our public website repository, and everything that license permits remains permitted, including copying, modification, redistribution, and commercial use, to the extent of our rights in the licensed material. The MIT license covers what we own in that repository; it does not extend to third-party components included in it (which carry their own licenses), to our trademarks, name, or logo (which no open-source license conveys), or to materials we publish outside the repository. Section 9.1 reserves our rights in everything the license does not reach. + +**9.2 Deliverables.** Upon full payment, we grant you a perpetual, worldwide, non-exclusive, non-transferable license to use the deliverables for your internal business purposes. Where a SOW expressly assigns ownership of custom-developed work product to you, that assignment takes effect upon full payment and is subject to our retained rights in background IP embedded in it. + +**9.3 Residual knowledge.** We may use the general skills, knowledge, and experience retained in the unaided memory of our personnel, provided this does not involve use or disclosure of your Confidential Information. + +**9.4 Open source.** Deliverables may incorporate open-source components, which are licensed to you under their respective licenses. We will identify material components on request. + +**9.5 Client materials.** You retain ownership of all data, code, and materials you provide, and grant us a limited license to use them solely to perform the Services. + +**9.6 Restrictions.** You may not resell, sublicense, publish, or distribute our reports, educational materials, or methodologies to third parties without our written consent, except that you may share assessment reports with your auditors, regulators, insurers, and counsel under a duty of confidentiality. + +## 10. Confidentiality + +Each party may receive non-public information of the other ("Confidential Information"). Assessment reports, findings, architecture details, key management designs, proposals, and pricing are Confidential Information. + +Each party will: use the other's Confidential Information solely to perform or receive the Services; protect it with at least reasonable care; and limit disclosure to personnel and subcontractors with a need to know who are bound by comparable obligations. + +Exclusions: information that is or becomes public without breach, was rightfully known without duty of confidence, is independently developed without use of the disclosing party's information, or is rightfully received from a third party. + +Compelled disclosure is permitted where legally required, with prompt notice to the other party where lawful. + +These obligations survive for five (5) years after termination, and indefinitely for trade secrets and for your key management architecture, security findings, and unremediated vulnerabilities. + +## 11. Warranties and Disclaimers + +**11.1 Limited warranty.** We warrant that Services will be performed in a professional and workmanlike manner consistent with generally accepted industry standards by personnel with appropriate skill. Your exclusive remedy for breach of this warranty is re-performance of the deficient Services, provided you notify us in writing within 30 days of delivery. + +**11.2 Disclaimer.** EXCEPT AS EXPRESSLY STATED IN SECTION 11.1, THE SITE, SERVICES, AND ALL DELIVERABLES ARE PROVIDED "AS IS" AND "AS AVAILABLE." TO THE MAXIMUM EXTENT PERMITTED BY LAW, PRIVKEY DISCLAIMS ALL OTHER WARRANTIES, EXPRESS, IMPLIED, OR STATUTORY, INCLUDING IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, ACCURACY, AND NON-INFRINGEMENT. + +**11.3 No guarantee of security or compliance.** WE DO NOT WARRANT THAT YOUR SYSTEMS, WALLETS, SMART CONTRACTS, OR NETWORKS ARE OR WILL REMAIN SECURE, THAT ALL VULNERABILITIES WILL BE IDENTIFIED, THAT ASSETS WILL NOT BE LOST OR STOLEN, OR THAT YOU WILL PASS ANY AUDIT, CERTIFICATION, OR REGULATORY EXAMINATION. + +**11.4 Third-party products and networks.** We do not warrant third-party hardware wallets, HSMs, MPC platforms, custody providers, exchanges, cloud services, blockchain networks, or protocols. Their failure, compromise, discontinuation, supply-chain tampering, or change in terms is outside our control. Blockchain transactions are generally irreversible and network behavior — including congestion, forks, reorganizations, and consensus changes — is outside our control. + +## 12. Limitation of Liability + +**12.1 Excluded damages.** TO THE MAXIMUM EXTENT PERMITTED BY LAW, NEITHER PARTY IS LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, OR FOR LOST PROFITS, LOST REVENUE, LOST BUSINESS, LOST DATA, LOSS OF GOODWILL, OR **LOSS OR DIMINUTION IN VALUE OF DIGITAL ASSETS**, REGARDLESS OF THE THEORY OF LIABILITY AND EVEN IF ADVISED OF THE POSSIBILITY. + +**12.2 Liability cap.** PRIVKEY'S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATING TO THESE TERMS, THE SITE, OR THE SERVICES WILL NOT EXCEED THE TOTAL FEES PAID BY YOU TO PRIVKEY UNDER THE APPLICABLE SOW IN THE **TWELVE (12) MONTHS** PRECEDING THE EVENT GIVING RISE TO THE CLAIM. FOR FREE SITE USE OR FREE RESOURCES, OUR TOTAL LIABILITY WILL NOT EXCEED **USD $100**. + +**12.3 Exceptions.** The cap does not apply to: your payment obligations; your indemnification obligations under Sections 6 and 13; either party's breach of confidentiality; or liability that cannot be limited by law, including fraud, willful misconduct, and gross negligence. + +> **[Decision required before publication. As drafted, "either party's breach of confidentiality" leaves PrivKey's own exposure uncapped, and the gross negligence carve-out does the same for a client asset-loss claim pleaded that way. A confidentiality breach is the most likely and most expensive claim brought against a firm holding client key management architecture, unremediated vulnerabilities, and exploitation evidence, so this exception governs the risk that actually materializes. Pick one of the two:** +> +> **(a) Keep as drafted. Unlimited exposure on the confidentiality path, deliberately accepted.** +> +> **(b) Substitute a super-cap: "The cap does not apply to: your payment obligations; your indemnification obligations under Sections 6 and 13; or liability that cannot be limited by law, including fraud and willful misconduct. For either party's breach of Section 10 (Confidentiality), the cap in Section 12.2 is replaced by a cap of [three (3)] times the total fees paid under the applicable SOW."** +> +> **Take this to the insurer, not only to counsel: the coverage question is not whether the policy limit matches the 12.2 cap, it is whether the policy responds at all to the uncapped exceptions.]** + +**12.4 Allocation of risk.** You acknowledge that these limitations are a material and bargained-for basis of our pricing, and that fees would be substantially higher absent them. + +## 13. Indemnification + +**13.1 By Client.** You will defend, indemnify, and hold harmless PrivKey and its members, officers, employees, and contractors from any third-party claim, loss, liability, damage, fine, penalty, or expense (including reasonable attorneys' fees) arising from: (a) your breach of these Terms or of any representation regarding testing authorization under Section 6; (b) your use of deliverables in a manner not contemplated by the SOW; (c) your violation of law, including AML/KYC, sanctions, securities, or data protection law; (d) your data or materials infringing third-party rights; or (e) loss, theft, or diminution of your digital assets, except to the extent caused by our gross negligence or willful misconduct. + +**13.2 By PrivKey.** We will defend and indemnify you against third-party claims that our deliverables, as delivered and used as permitted, infringe a U.S. copyright, patent, or trade secret, subject to the cap in Section 12.2. This does not apply to claims arising from your materials, third-party or open-source components, modifications made by anyone other than us, or use in combination with other products. + +**13.3 Procedure.** The indemnified party must promptly notify the indemnifying party, allow it sole control of the defense, and cooperate at the indemnifying party's expense. No settlement imposing liability on the indemnified party may be made without its consent. + +## 14. Compliance, Sanctions, and Export Control + +You represent and warrant that you are not, and are not owned or controlled by, a person or entity that is: (a) listed on any U.S. sanctions list, including OFAC's SDN List; (b) located in or organized under the laws of a comprehensively sanctioned jurisdiction; or (c) otherwise prohibited from receiving services under U.S. law. + +We may conduct KYC, sanctions screening, and source-of-funds checks on prospective and existing clients as a condition of engagement, and may decline or terminate any engagement at our discretion. + +You will not use the Services or deliverables in violation of U.S. export control laws, or to facilitate money laundering, terrorist financing, sanctions evasion, fraud, unauthorized access to systems, or any other unlawful activity. + +**We may terminate immediately and without refund upon a reasonable belief that this Section has been breached, and may report as required by law.** + +## 15. Acceptable Use of the Site + +You may not: access the Site by automated means except as permitted by robots.txt; probe, scan, or test the Site's security except as authorized under the security research provision below; interfere with the Site's operation; misrepresent your identity or affiliation; upload malware; or use the Site to violate any law. + +**Security research.** The restriction on probing, scanning, or testing the Site's security is subject to our coordinated disclosure process in `SECURITY.md`. Research conducted in good faith and in accordance with that process is authorized, and we will not treat it as a breach of these Terms or pursue legal action over it. Testing outside that process still requires our prior written authorization. + +**Content reuse.** The Site's source code is published under the MIT license (Section 9.1.1), and reuse within that license, including commercial reuse, is permitted. This Section does not restrict it. The license does not cover third-party components, our trademarks, or materials published outside the repository, and what remains prohibited is use of our name, logo, or trademarks to imply endorsement or affiliation, and any reuse that misrepresents the source of the content. + +We may investigate suspected violations and suspend or block access at our discretion. + +## 16. Third-Party Links and Services + +The Site may link to third-party sites, tools, and resources. We do not control and are not responsible for their content, security, availability, or practices. Your dealings with them are solely between you and them. + +## 17. Term, Suspension, and Termination + +These Terms apply while you use the Site and for the duration of any engagement. + +**17.1 Termination for convenience.** Either party may terminate an engagement on 30 days' written notice. You remain responsible for all fees for work performed and non-cancellable commitments incurred through the effective date of termination. + +**17.2 Termination for cause.** Either party may terminate immediately upon the other's material breach uncured after 30 days' written notice, or 10 days' written notice for a payment breach, or upon insolvency or bankruptcy. + +**17.3 Immediate termination by PrivKey.** We may terminate immediately, without refund, upon breach of Section 6 (testing authorization) or Section 14 (compliance and sanctions), or where continued performance would in our reasonable judgment violate law or professional ethics, or place us or a third party at risk. + +**17.4 Effect.** On termination, we will deliver work product completed through the termination date for which payment has been received, and each party will return or destroy the other's Confidential Information on written request, subject to legal retention requirements and routine backup archival. + +**17.5 Survival.** Sections 4, 5.1, the indemnification obligation in Section 6, and Sections 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17.4, 17.5, 18, and 19 survive termination. Section 15 survives because it governs anyone who continues to use the Site after an engagement ends. + +## 18. Governing Law and Dispute Resolution + +**18.1 Governing law.** These Terms are governed by the laws of the **State of Florida**, without regard to conflict-of-laws principles. The U.N. Convention on Contracts for the International Sale of Goods does not apply. + +**18.2 Informal resolution.** Before initiating formal proceedings, the parties will attempt in good faith to resolve the dispute through senior-level discussion for at least 30 days after written notice describing the dispute. + +**18.3 Binding arbitration.** Any dispute not resolved informally will be resolved by final and binding arbitration administered by the American Arbitration Association under its Commercial Arbitration Rules, before one (1) arbitrator, seated in **Hillsborough County, Florida**, conducted in English. Judgment on the award may be entered in any court of competent jurisdiction. The arbitration and award are confidential. + +**18.4 Exceptions.** Either party may seek injunctive or other equitable relief in a court of competent jurisdiction to protect its intellectual property or Confidential Information, and either party may bring a claim in small claims court. + +**18.5 Class action waiver.** **DISPUTES WILL BE ARBITRATED ONLY ON AN INDIVIDUAL BASIS. NEITHER PARTY MAY BRING OR PARTICIPATE IN A CLASS, COLLECTIVE, CONSOLIDATED, OR REPRESENTATIVE ACTION.** If this waiver is held unenforceable, Section 18.3 is void in its entirety as to the affected claims. + +**18.6 Jury trial waiver.** TO THE EXTENT ARBITRATION DOES NOT APPLY, EACH PARTY WAIVES ANY RIGHT TO A TRIAL BY JURY. + +**18.7 [Consumer opt-out.]** [If offering consumer-facing training/education, include a 30-day arbitration opt-out mechanism — confirm with counsel.] + +## 19. General + +**19.1 Independent contractor.** We are an independent contractor. Nothing creates a partnership, joint venture, agency, employment, or fiduciary relationship. + +**19.2 Subcontractors.** We may engage qualified subcontractors, and remain responsible for their performance and for binding them to equivalent confidentiality obligations. + +**19.3 Non-solicitation.** During an engagement and for twelve (12) months after, neither party will knowingly solicit for employment any personnel of the other who were directly involved in the engagement. General advertising not targeted at such personnel is permitted. + +**19.4 Publicity.** Neither party will use the other's name, logo, or marks in marketing without prior written consent, except that we may list your name and logo as a client where you have separately consented in writing. + +**19.5 Force majeure.** Neither party is liable for delay or failure caused by events beyond its reasonable control, including natural disaster, war, terrorism, labor dispute, government action, internet or utility failure, or widespread network, protocol, or infrastructure failure. Payment obligations are not excused. + +**19.6 Assignment.** You may not assign these Terms without our written consent. We may assign to an affiliate or in connection with a merger, reorganization, or sale of substantially all assets. + +**19.7 Notices.** Notices to PrivKey: legal@privkey.io and PrivKey LLC, 8710 N Renfrew Pl, Tampa, Florida 33604. Notices to you: the contact details in the SOW or your account record. + +**19.8 Severability.** If a provision is held unenforceable, it will be modified to the minimum extent necessary or severed, and the remainder stays in effect. + +**19.9 No waiver.** Failure to enforce a provision is not a waiver. + +**19.10 Entire agreement.** These Terms, together with any MSA, SOW, and the Privacy Policy, are the entire agreement and supersede all prior understandings on the subject matter. + +**19.11 Changes.** We may update these Terms. Material changes will be posted with an updated "Last Updated" date and, where we hold your contact details, communicated by email at least 30 days before taking effect. Continued use after the effective date constitutes acceptance. Changes do not retroactively alter a signed SOW. + +**19.12 Language.** These Terms are drafted in English, which controls in the event of translation conflict. + +## 20. Contact + +**PrivKey LLC** +8710 N Renfrew Pl +Tampa, Florida 33604, United States +Florida Division of Corporations: sunbiz.org (Document No. L18000284183) + +General: information@privkey.io +Legal: legal@privkey.io +Security: security@privkey.io +Web: https://privkey.io