These Terms & Conditions (the Terms) govern access to and use of CertFlow's websites, browser application, mobile application, client portal, Network, Growth Tools and related services (together, the Service). They form a binding agreement between CertFlow LTD (company number 17056886), a company registered in England and Wales whose registered office is 20 Wenlock Road, London, N1 7GU (CertFlow, we, us or our) and the business or organisation identified at sign-up or in an Order (Customer, you or your).
Please read these Terms before creating an account or using the Service. By accepting an Order, creating an organisation workspace, clicking to accept these Terms or using the Service, you confirm that you have authority to bind the Customer and that the Customer agrees to these Terms.
1. About these Terms
CertFlow provides software for inspection, certification, asset management, scheduling, workforce and compliance record keeping, customer portals, business operations and professional networking. The exact modules, usage limits, support and fees included in your subscription are shown at sign-up, on the pricing page or in a written quotation, order form or statement of work (each an Order).
These Terms apply to free trials, paid subscriptions and any authorised use of the Service. They do not govern professional inspection, engineering, consultancy or subcontracting services that a Customer or Network member supplies to another person.
2. Definitions and interpretation
| Term | Meaning |
|---|---|
| Account | An individual login used by an Authorised User to access the Service. |
| Authorised User | An employee, worker, contractor, client-portal user or other individual whom the Customer permits to use the Service. |
| Customer Data | Data, files, records, images, signatures, messages and other content submitted to, generated in or made available through the Service by or for the Customer. |
| Data Protection Laws | The UK GDPR, Data Protection Act 2018, Privacy and Electronic Communications Regulations 2003, Data (Use and Access) Act 2025 and other applicable privacy or data-protection law, in each case as amended. |
| Documentation | The user guidance, help material and technical instructions that we make available for the Service. |
| Fees | The subscription, usage, implementation or other charges set out in the applicable Order, excluding VAT and similar taxes unless stated otherwise. |
| Initial Term | The first paid subscription period in the Order. |
| Order | The online checkout, quotation, order form, statement of work or other written ordering document accepted by the parties. |
| Subscription Term | The Initial Term and each renewal period until the subscription ends. |
Headings are for convenience only. Words such as “including” and “for example” do not limit the words that precede them. References to writing include email and in-product notices where appropriate.
3. Contract formation and precedence
The agreement between the parties consists of the applicable Order, these Terms, the Data Processing Agreement (DPA), and any service-specific terms or statement of work expressly incorporated into the Order (together, the Agreement). Our Privacy Policy, Cookie Policy and security information explain our practices but do not expand our contractual commitments unless the Agreement expressly says they do.
If documents conflict, the following order applies: (1) any mandatory international data-transfer terms; (2) the DPA for matters concerning processing of Customer Personal Data; (3) the Order; (4) any signed statement of work or service-specific terms; and (5) these Terms. A Customer purchase order is for administrative convenience only and its additional or inconsistent terms do not apply unless we expressly accept them in writing.
4. The Service and your right to use it
During the Subscription Term, and subject to the Agreement, we grant the Customer a limited, non-exclusive, non-transferable and non-sublicensable right for its Authorised Users to access and use the subscribed Service for the Customer's internal business operations and to provide its own services to clients. Client-portal access that the Service is designed to provide is permitted.
The Service is provided as hosted software. No ownership in the Service or its source code transfers to the Customer. Rights not expressly granted are reserved. Documentation, previews, beta functions and free tools may be changed or withdrawn and may be subject to additional notices.
We may use affiliates and subcontractors to provide the Service. We remain responsible for our obligations under the Agreement, subject to its terms, and our use of processors is governed by the DPA.
5. Eligibility, administrators and accounts
The person creating a workspace or accepting an Order must be at least 18 years old and represents that they have authority to act for the Customer. Other Authorised Users access the Service only on the Customer's authority; the Customer is responsible for ensuring that their access is lawful, appropriate and suitably supervised.
- The Customer must provide accurate sign-up, organisation and billing information and keep it current.
- The Customer controls its Authorised Users, roles, permissions, client-portal invitations and organisation settings, and is responsible for reviewing them regularly.
- Each Account is personal to one Authorised User and must not be shared. The Customer must promptly disable access when a person no longer needs it.
- The Customer and each Authorised User must protect passwords, authentication devices, recovery codes and session links and must notify us promptly at info@certflow.co.uk of suspected compromise or unauthorised use.
- Actions taken through an Account are treated as authorised by the Customer unless and until we receive notice of compromise. This does not make the Customer responsible for activity caused by our breach of the Agreement.
The Customer's workspace owner or administrators may access and control data associated with Authorised Users, including business communications and activity records. The Customer is responsible for giving its personnel and client users any notices required by law.
6. Trials, subscriptions and Fees
6.1 Free trials
If a free trial is offered, its length and included features are those displayed when the Customer signs up or stated in the Order. Unless we say otherwise, a trial is for evaluation, may be limited to one per Customer, and ends automatically on the stated date. We may end or restrict a trial if it is abused.
A trial does not automatically become paid unless the Customer selects a paid plan or the sign-up flow clearly states that it will convert. Customer Data should be exported before a trial expires if the Customer does not intend to subscribe.
6.2 Subscription Fees
Fees, billing frequency, included modules and any usage basis are set out in the Order. Unless the Order states otherwise, subscriptions are charged in advance and are based on active paid users or seats. The Customer is responsible for Fees for the seats and add-ons it authorises. Changes are charged or credited as described in the billing interface or Order.
Fees exclude VAT and other applicable taxes, which the Customer must pay where chargeable. The Customer must provide complete billing information and authorises us and our payment provider to charge the selected payment method for amounts due. We do not receive full payment-card details.
6.3 Payment and overdue amounts
Invoices and card charges are due on the date stated. If a payment fails or becomes overdue, we may retry it, ask the Customer to update its payment method, charge lawful interest and reasonable recovery costs, or suspend paid access after reasonable notice. Suspension does not remove the obligation to pay accrued Fees. Please contact us promptly if an invoice is disputed in good faith.
7. Renewal, plan changes, cancellation and refunds
Unless the Order says otherwise, a paid subscription renews for successive periods equal to its billing period until cancelled. The Customer may cancel through the billing portal or by written notice. Cancellation stops renewal and takes effect at the end of the period already paid for; access continues until then unless the Agreement is terminated earlier for cause.
Upgrades may take effect immediately and may be charged on a pro-rated basis. Downgrades, seat reductions and removal of add-ons normally take effect at the next renewal and may cause loss of access to affected functions. The billing interface or Order will control if it states a different timing.
Except where the Agreement expressly provides otherwise or law requires it, paid Fees are non-refundable and we do not provide credits for part-used periods, unused Accounts or a Customer's failure to use the Service. This does not affect a refund due because we have materially breached the Agreement and failed to remedy that breach.
We may change published Fees by giving reasonable advance notice. A change applies no earlier than the Customer's next renewal, and the Customer may cancel before it takes effect. Custom or committed pricing remains governed by the Order.
8. Customer responsibilities
The Customer is responsible for how it configures and uses the Service and for the acts and omissions of its Authorised Users. In particular, the Customer must:
- use the Service and Customer Data lawfully, fairly and in accordance with the Agreement;
- obtain all permissions, notices, lawful bases and consents needed to collect, upload, disclose, publish and instruct us to process Customer Data;
- decide appropriate access roles and limit access to people with a business need;
- verify imported data, template configuration, calculations, inspection content, certificates, dates, regulatory references and exported records before relying on or issuing them;
- maintain compatible devices, connectivity and secure operating systems, browsers and networks;
- keep its own copies of records where law, professional rules, insurance requirements or business continuity require them, and perform reasonable exports; and
- cooperate with reasonable steps needed to investigate security, abuse, data-protection or legal issues.
The Customer must not give us special-category data, criminal-offence data, children's data or payment-card data unless that use is necessary, lawful, within the intended Service and protected by appropriate settings and instructions. The Customer remains responsible for deciding whether the Service is suitable for its processing risk.
9. Acceptable use
The Customer and Authorised Users must not, and must not help anyone to:
- use the Service unlawfully, fraudulently, deceptively or in a way that infringes another person's rights;
- upload malware, malicious code or content that is unlawful, defamatory, threatening, harassing, discriminatory, exploitative or materially misleading;
- probe, scan, disable, overload, disrupt or circumvent security, authentication, rate limits, tenant isolation or access controls;
- access another customer's data or Account without authority;
- reverse engineer, decompile or attempt to derive source code except to the limited extent that law does not permit that restriction;
- scrape, harvest or use automated means to extract the Service, Network directory or other users' data except through an authorised integration;
- copy, frame, resell, lease, sublicense or provide the Service as a standalone bureau service without our written permission;
- remove proprietary notices, impersonate another person, fabricate accreditations or reviews, send spam, manipulate Network ratings or misuse messaging and job-board functions; or
- use the Service to build or benchmark a competing product for publication without our written permission.
Reasonable security testing requires our prior written authorisation. We may remove content, limit distribution or suspend access where reasonably necessary to protect users, the Service or third parties, while taking the Customer's legitimate interests into account.
10. Customer Data
As between the parties, the Customer retains its rights in Customer Data. The Customer grants us and our subprocessors a worldwide, non-exclusive licence during the Agreement to host, copy, transmit, display, format, back up and otherwise process Customer Data only as necessary to provide, secure and support the Service, comply with documented instructions and law, and exercise our rights under the Agreement. Processing of Customer Personal Data is subject to the DPA.
The Customer represents that it has the rights and authority needed for Customer Data and our instructed processing. We do not acquire ownership of Customer Data. We may create and use statistics that have been aggregated or anonymised so that they no longer identify the Customer or an individual, including to understand capacity, reliability and feature use. We will not attempt to re-identify anonymised data.
The Service may allow the Customer to publish selected organisation profiles, mini-sites, reports, reviews or other content. The Customer instructs us to make that content public and is responsible for reviewing it before publication. Removing public content may not remove copies already lawfully obtained or cached by others.
11. Intellectual property and feedback
CertFlow and its licensors own all rights in the Service, software, interface, Documentation, brand, designs, templates supplied as part of the platform, databases, improvements and usage know-how, excluding Customer Data and third-party materials.
If the Customer gives us suggestions or feedback, it grants us a perpetual, irrevocable, worldwide, royalty-free right to use that feedback without restriction or attribution. This does not give us rights in confidential Customer Data embedded in the feedback.
A bespoke template, import, configuration or deliverable may include our pre-existing tools, code, layouts and know-how. Ownership and permitted use of any genuinely customer-specific deliverable are as stated in the applicable statement of work; otherwise the Customer receives a right to use it with the Service during the Subscription Term.
12. Third-party services and integrations
The Service may interoperate with payment, mapping, email, calendar, authentication, storage, mobile synchronization or other third-party services. A third party's own terms and privacy notice govern the Customer's direct relationship with that service. We are not responsible for third-party products, content or changes outside our reasonable control.
If the Customer enables an integration or asks us to exchange data with a third party, the Customer authorises that exchange and is responsible for the third-party account and instructions. Disabling an integration may not remove data already transferred. Our processors used to deliver the Service remain subject to the DPA.
13. CertFlow Network, public profiles and member dealings
The Network helps businesses discover and communicate with each other, post opportunities, discuss topics, publish profiles and reviews, and record continuing professional development. Unless we expressly agree otherwise in writing, CertFlow acts as a platform provider and introducer only. We are not a party to, agent for, employer of or guarantor of any contract, inspection, referral, subcontract, event or payment between members.
Customers must conduct their own due diligence on competence, identity, insurance, accreditation, availability, pricing and legal compliance. A “verified” or similar platform status reflects only the checks described at the time and is not an endorsement, warranty or ongoing guarantee. Rules-based matching, rankings and suggestions are aids, not professional recommendations.
Members are responsible for their posts, messages, reviews, applications and dealings. Reviews must reflect genuine experience and must not be manipulated. We may moderate, restrict or remove content, preserve evidence and cooperate with lawful requests. We do not undertake to monitor every communication.
14. Confidentiality
Each party may receive non-public business, technical or commercial information that a reasonable person would understand to be confidential (Confidential Information). Customer Data is the Customer's Confidential Information. The Service's non-public technical information and pricing in a confidential Order are ours.
The receiving party will protect Confidential Information with at least reasonable care, use it only to perform or exercise rights under the Agreement, and disclose it only to personnel, professional advisers and subcontractors who need it and are bound by confidentiality duties. These restrictions do not apply to information that is public without breach, already lawfully known, independently developed or lawfully received without restriction.
A party may disclose information where law or a competent authority requires it, and will give advance notice where legally permitted. Confidentiality duties continue for five years after termination, and for Customer Data, trade secrets and personal data for so long as they remain confidential or protected by law.
15. Data protection
Each party will comply with Data Protection Laws applicable to its role. For Customer Personal Data that we process on the Customer's behalf, the Customer is controller (or processor acting for another controller), CertFlow is processor (or subprocessor), and the DPA is incorporated into the Agreement.
We act as an independent controller for limited business-administration processing such as managing Accounts and subscriptions, billing contacts, security, legal compliance and our direct communications, as explained in the Privacy Policy. The Customer is independently responsible for its own privacy notices, lawful bases, retention rules, rights handling and instructions.
16. Security, availability, backups and support
We maintain appropriate technical and organisational measures for the risk of processing, as described in the DPA and on our Security page. No online service is completely secure or uninterrupted, and the Customer must follow the shared-responsibility steps in section 8.
We aim to keep the Service available and may publish a non-binding availability target. Unless an Order contains a signed service-level agreement, a target is an operational objective and not a warranty or service-credit commitment. Availability calculations exclude scheduled maintenance, emergency maintenance, Customer systems, third-party services, internet failures, misuse and force-majeure events.
We may perform scheduled or emergency maintenance and will give reasonable notice of material planned interruption where practicable. Support is provided through the channels and hours stated in the Order or Documentation. Response times are targets unless expressly made contractual.
We use managed backup and recovery measures appropriate to the Service. Backups are designed for service resilience and are not an archive on demand. The Customer remains responsible for retention choices and for exporting records where independent copies are required.
17. Changes to the Service and these Terms
We may update the Service to improve security, performance, usability, legal compliance or functionality. We will not materially reduce the core functionality of a paid plan during its current paid period without reasonable notice, except where necessary to address law, security or a third-party dependency. If a change causes a material overall reduction and no reasonable alternative is provided, the Customer may terminate the affected subscription by notifying us before the change takes effect and receive a pro-rated refund for the unused affected period.
We may update these Terms. We will post the revised version and date and give reasonable advance notice of a material change, normally by email or in-product message. A change required urgently for law or security may take effect sooner. Changes do not apply retroactively. Continued use after the effective date constitutes acceptance; if the Customer does not agree to a material change, its remedy is to cancel before that date.
18. Professional, regulatory and commercial disclaimer
CertFlow is a workflow, record-keeping and business software tool. It does not itself inspect equipment, act as a competent person, certify compliance, provide legal, engineering, tax, accounting, employment or other professional advice, or replace the judgement of a suitably qualified person.
The Customer is solely responsible for deciding which law, standard, inspection interval, report wording, classification, retention period and professional sign-off applies; for verifying every report or certificate before issue; and for the acts and omissions of its inspectors and subcontractors. Templates, reminders, calculations, guidance, matching, lead scores and commercial tools are starting points and may not reflect every fact or later legal change.
Except as expressly stated in the Agreement, the Service is provided “as is” and “as available.” To the maximum extent permitted by law, we exclude implied warranties and conditions, including merchantability, fitness for a particular purpose and that the Service or Customer outputs will meet every regulatory requirement. Nothing in this section excludes the duty to provide the Service with reasonable care and skill where that duty cannot lawfully be excluded.
19. Suspension
We may suspend all or part of the Service to the extent reasonably necessary if: Fees are overdue; use creates a material security or legal risk; an Account is compromised; the Customer materially breaches the Agreement; a third-party provider or authority requires suspension; or continued provision would be unlawful.
Where practicable, we will give notice and an opportunity to remedy the issue, limit suspension to the affected Accounts or functions, and restore access promptly when the cause is resolved. We may act immediately where delay would increase risk. We are not liable for a suspension made reasonably in accordance with this section, but this does not excuse our own breach or negligence.
20. Termination and its effects
20.1 Termination for cause
Either party may terminate the Agreement by written notice if the other materially breaches it and, where the breach can be remedied, does not remedy it within 30 days after written notice. A party may terminate immediately if the other becomes insolvent, ceases business, or repeatedly breaches in a way that reasonably shows it cannot or will not comply. We may terminate immediately for serious unlawful use, deliberate security abuse or infringement that cannot reasonably be cured.
20.2 Effect of termination
When the Agreement ends, access rights end, outstanding Fees become due, and each party must stop using the other's Confidential Information except as needed for an accrued right or legal duty. Terms that by their nature should continue will survive, including confidentiality, intellectual property, payment, disclaimers, liability, data protection and general provisions.
During the Subscription Term the Customer should use available export tools. For 30 days after termination, the Customer may request a reasonable standard export of Customer Data that remains in our active systems, unless access ended for unlawful conduct or providing the export would breach law or another person's rights. Additional migration work may be chargeable if agreed in advance.
After that export period, and subject to the Customer's choice and the DPA, Customer Personal Data will be returned or scheduled for deletion. If the Customer gives no instruction, we will schedule active Customer Data for deletion within 90 days after termination. Residual protected backup copies may remain until overwritten in the ordinary backup cycle and will not be restored except for disaster recovery. Legal retention duties and data we control independently are addressed in the Privacy Policy.
21. Customer indemnity
The Customer will indemnify CertFlow against third-party claims, damages, fines, costs and reasonable legal fees to the extent arising from Customer Data or the Customer's use of the Service in breach of sections 8, 9 or 10, including an allegation that Customer Data infringes rights or was collected or disclosed unlawfully.
This indemnity does not apply to the extent a claim results from our breach, negligence, unauthorised modification or use outside the Customer's instructions. We will notify the Customer promptly, allow reasonable control of the defence and settlement, and provide reasonable cooperation at the Customer's cost. The Customer may not settle in a way that admits fault or imposes obligations on us without our written consent, not to be unreasonably withheld.
22. Liability
22.1 Liability that is not limited
Nothing in the Agreement excludes or limits liability for death or personal injury caused by negligence, fraud or fraudulent misrepresentation, breach of an obligation as to title that cannot be limited, deliberate default, or any other liability that law does not allow to be excluded or limited.
22.2 Excluded loss
Subject to section 22.1, neither party is liable for indirect or consequential loss, or for loss of profit, revenue, anticipated savings, business opportunity or goodwill, whether direct or indirect, arising from the Agreement. This exclusion does not prevent recovery of Fees properly due, reasonable data-restoration costs that are a direct result of our breach, or amounts payable under an indemnity.
22.3 Aggregate cap
Subject to sections 22.1 and 22.2, each party's total aggregate liability arising out of or in connection with the Agreement in any rolling 12-month period will not exceed 100% of the Fees paid or payable by the Customer for the Service in that period. If the event occurs during a free trial or before 12 months of paid use, the cap is the Fees that would have been payable for 12 months on the Customer's selected plan.
The cap applies collectively to claims in contract, tort (including negligence), misrepresentation, restitution, breach of statutory duty and otherwise. Nothing in the Agreement limits an individual's rights under Data Protection Laws or either party's regulatory liability to a competent authority.
23. General terms
- Force majeure. Neither party is liable for delay or failure caused by an event beyond its reasonable control, provided it takes reasonable steps to mitigate and resumes performance when possible. This does not excuse payment already due.
- Assignment. The Customer may not assign the Agreement without our written consent, not to be unreasonably withheld. We may assign it to an affiliate or in connection with a bona fide merger, reorganisation or sale of all or substantially all relevant business or assets, provided the assignee can perform it.
- Notices. Legal notices must be in writing and sent to the email/address in the Order or to info@certflow.co.uk and our registered office. Operational and service notices may be sent to Account contacts or displayed in the Service. Email is received on the next business day unless a delivery failure is received.
- No partnership or agency. The Agreement does not create a partnership, joint venture, fiduciary, employment or agency relationship.
- Third-party rights. A person who is not a party has no right under the Contracts (Rights of Third Parties) Act 1999 to enforce the Agreement.
- Entire agreement. The Agreement is the complete agreement about its subject matter and replaces prior proposals and representations. Neither party relies on a statement not set out in it, but nothing excludes fraud.
- Waiver and severability. Delay in exercising a right is not a waiver. If a provision is unlawful or unenforceable, it will be modified to the minimum extent needed or removed, and the remainder continues.
- No exclusivity. Unless an Order says otherwise, neither party is exclusive and we may provide similar services to others without using Customer Confidential Information.
24. Governing law, disputes and contact
The Agreement and any non-contractual obligations arising from it are governed by the law of England and Wales. The courts of England and Wales have exclusive jurisdiction, except that either party may seek urgent injunctive relief in any competent court to protect confidential information, personal data or intellectual-property rights.
Before starting proceedings, each party will try in good faith for at least 30 days to resolve a dispute through managers with authority to settle, unless urgent relief or a limitation deadline requires earlier action.
Questions about these Terms may be sent to info@certflow.co.uk, telephoned to 0114 392 2407, or posted to CertFlow LTD, 20 Wenlock Road, London, N1 7GU.