← Back to PCI-Nexus

Terms of Service

Last updated: [EFFECTIVE DATE]
Draft — pending legal review. Replace all bracketed placeholders before production.

These Terms of Service (“Terms”) govern your access to and use of the PCI-Nexus platform and related services (the “Service”) provided by [Company legal name] (“we,” “us,” or “PCI-Nexus”). By creating an account or using the Service, you agree to these Terms.

1. The Service

PCI-Nexus is a compliance management platform that helps managed service providers, consultants, and IT professionals guide their clients through the Payment Card Industry Data Security Standard (PCI DSS). The Service provides workflow tooling, document generation, and record-keeping. It does not itself perform a formal assessment or issue any certification.

2. Accounts

You are responsible for maintaining the confidentiality of your account credentials and for all activity under your account. You agree to provide accurate information and to keep it current. You must promptly notify us of any unauthorized use of your account.

3. Acceptable use

You agree not to misuse the Service, including by attempting to gain unauthorized access, interfering with its operation, or using it to violate any applicable law or the rights of others.

4. Customer data

You retain all rights to the data you and your clients submit to the Service. You grant us a limited license to process that data solely to provide and improve the Service. Our handling of data is described in our Data Handling and Privacy Policy documents.

5. No cardholder data

The Service is not designed to store, process, or transmit cardholder data or sensitive authentication data. You agree not to upload such data to the Service. See the Data Handling page for details.

6. Fees

Fees, billing frequency, and any usage-based charges are described at sign-up and in your account. [Describe billing model — e.g., per client, billed after a client is added.]

7. Disclaimers

The Service is provided “as is” without warranties of any kind. PCI-Nexus does not guarantee any particular compliance outcome, and use of the Service does not by itself establish PCI DSS compliance, which depends on your and your clients’ own controls and, where applicable, an independent assessment.

8. Limitation of liability

To the maximum extent permitted by law, PCI-Nexus will not be liable for any indirect, incidental, or consequential damages arising out of your use of the Service. [Insert liability cap language per counsel.]

9. Termination

You may stop using the Service at any time. We may suspend or terminate access for violation of these Terms or as required by law.

10. Changes

We may update these Terms from time to time. Material changes will be communicated through the Service or by email. Continued use after changes take effect constitutes acceptance.

11. Contact

Questions about these Terms may be directed to [contact email], [Company legal name], [mailing address].

Governed by the laws of [state/jurisdiction], without regard to conflict-of-law principles.