Legal

Terms of Service

Last updated: 15 August 2026

Welcome to SecureAZ. Please read these Terms of Service ("Terms") carefully before using any SecureAZ customer platform or service operated by SecureAZ Limited ("SecureAZ", "we", "us", or "our"), including the customer application platforms at app.secureaz.com and app.secureaz.co.nz (collectively, the "Platforms"). These Terms govern your access to and use of the Platforms and SecureAZ Services. By accessing or using the Platforms or any SecureAZ Service, you agree to be legally bound by these Terms in their entirety. If you do not agree, you must immediately cease use of the Platforms and all SecureAZ Services.

These Terms apply to both direct customers and authorised Managed Service Provider and Reseller partners, with the specific rights and obligations of authorised MSPs and Resellers set out in clause 13.

1. Definitions

In these Terms:

"Agreement" means these Terms together with the documents listed in clause 3.

"App" means the SecureAZ customer application platform accessed at app.secureaz.com and app.secureaz.co.nz.

"Client Organisation" means an organisation whose users are provisioned on the Platforms by an authorised MSP or Reseller under that partner's account.

"Confidential Information" has the meaning given in clause 15.

"MSP" or "Managed Service Provider" means a customer granted written authorisation under clause 13 to provision, manage, resell, or administer the Services on behalf of Client Organisations.

"Order Form" means any proposal, quote, order form, subscription page, or written statement of work under which you purchase the Services.

"Personal Information" has the meaning given in the New Zealand Privacy Act 2020 and, where applicable, "personal information" under the Australian Privacy Act 1988.

"Reseller" means a customer granted written authorisation under clause 13 to resell or otherwise provide access to the Services to Client Organisations.

"Services" means the services described in clause 4 and any related services SecureAZ provides to you.

"Uploaded Content" has the meaning given in clause 16.

"User", "you", or "your" means the person or entity accepting these Terms and, where accepted on behalf of an entity, that entity.

2. Acceptance of Terms

By accessing or using the Platforms or any SecureAZ Service, you agree to be legally bound by these Terms in their entirety. If you do not agree, you must immediately cease use of the Platforms and all SecureAZ Services.

These Terms govern all Services provided by SecureAZ, including but not limited to cyber awareness training, phishing simulation campaigns, cyber health check tools, and any related services. Penetration testing or other professional services are only included where expressly agreed in an Order Form or separate written agreement.

Where you are accepting these Terms on behalf of a company or other legal entity, you represent and warrant that you have the authority to bind that entity and its affiliates to these Terms.

3. Structure of the Agreement & Order of Precedence

The Agreement between you and SecureAZ is made up of the following documents, incorporated by reference:

  • these Terms;
  • any applicable Order Form;
  • the Privacy Policy at secureaz.com/privacy;
  • any applicable Data Processing terms referred to in clause 14; and
  • any service-specific terms SecureAZ makes available, such as an SLA or acceptable use policy.

If there is any conflict or inconsistency between these documents, they take precedence in the following order, unless a document expressly states otherwise:

  1. any signed Order Form or written agreement between the parties;
  2. applicable Data Processing terms;
  3. these Terms;
  4. the Privacy Policy and other service-specific terms.

This Agreement constitutes the entire agreement between you and SecureAZ and supersedes all prior discussions, representations, or agreements, whether written or oral, relating to its subject matter, including any earlier Customer Agreement or Terms of Service.

4. Description of Services

SecureAZ provides cyber security awareness and training services to businesses. The specific Services available to you depend on your subscription plan or agreed scope of work, and may include:

  • Cyber security awareness training modules delivered via the App;
  • Phishing simulation campaigns targeting your employees or designated users;
  • Penetration testing services, where separately agreed in writing;
  • Cyber health check tools and assessments; and
  • Management reporting and compliance documentation.

SecureAZ may modify, suspend, or discontinue any part of the Services with reasonable notice to you. Where a change materially and adversely affects a paid Service you are actively using, we will use reasonable efforts to give you advance notice.

5. Licence and Restrictions

Subject to your compliance with the Agreement, SecureAZ grants you a limited, non-exclusive, non-transferable, revocable licence to access and use the Platforms solely for your internal business purposes.

This clause is subject to clause 13, which grants additional resale and sub-licensing rights to authorised MSPs and Resellers.

You must not:

  • Copy, modify, distribute, sell, or lease any part of the Platforms or Services, except as expressly permitted under clause 13;
  • Reverse engineer, decompile, or attempt to extract source code from the Platforms;
  • Use the Platforms to store or transmit infringing, libellous, obscene, or otherwise unlawful material;
  • Use the Platforms to store or transmit malicious code;
  • Interfere with or disrupt the integrity or performance of the Platforms;
  • Mine data from the Platforms using automated means without express written consent;
  • Resell, sublicense, or otherwise commercialise access to the App except as expressly permitted under clause 13 or by separate written agreement;
  • Use credentials belonging to another user to access the App;
  • Share login credentials with unauthorised parties; or
  • Impersonate SecureAZ, its employees, or any other person or entity.

SecureAZ may revoke this licence and suspend or terminate access in accordance with clauses 20 and 24.

6. User Accounts

6.1 Registration

Access to the App requires a registered user account. You agree to provide accurate, current, and complete information and to keep it updated.

You are responsible for maintaining the confidentiality of your login credentials and must notify SecureAZ promptly of any unauthorised access to your account.

6.2 Account responsibility

You are responsible for all activities that occur under your account. SecureAZ is not liable for any loss or damage arising from your failure to maintain account security.

6.3 Administrator accounts

Where you are given administrator access, you are responsible for managing user permissions and access within your organisation's account and for ensuring only authorised individuals are granted access.

7. Trials and Free Tiers

7.1

SecureAZ may offer free trials or free tiers of the Services. Trial and free-tier access is provided "as is" and "as available", may be modified or withdrawn at any time, and carries no service level, support, or availability commitment.

7.2

Unless you enter a paid subscription, SecureAZ is under no obligation to convert, retain, or continue providing trial or free-tier access, and may delete trial or free-tier data after the trial ends.

7.3

Trial organisations created by an MSP or Reseller under clause 13 do not consume pool seats and are not charged.

8. Awareness Training

If you deploy training on behalf of your organisation or a Client Organisation, you warrant that:

  • You have obtained all necessary consents, authorisations, and approvals required under applicable employment agreements, privacy laws, and workplace policies before deploying training to employees or third parties;
  • You have notified employees or participants of any monitoring or tracking associated with training completion to the extent required by law;
  • You will not use training results or completion data to unlawfully disadvantage, discipline, or dismiss employees without proper process; and
  • SecureAZ bears no responsibility for any employment, legal, or regulatory consequences arising from your use of training data or results.

9. Phishing Simulations

9.1 Nature of the service

SecureAZ sends simulated, non-malicious phishing emails and other social-engineering communications to individuals designated by you, to test and improve awareness of phishing threats.

9.2 Your authorisation and responsibility

By engaging phishing simulation Services, you represent and warrant that:

  • You are authorised to deploy simulations targeting the individuals and systems you designate;
  • You have obtained all necessary consents and authorisations required by law, including under employment agreements and privacy legislation; and
  • You will indemnify and hold harmless SecureAZ from any claims arising from simulations conducted under your authorisation, in accordance with clause 23.

9.3 Employee complaints and distress

You acknowledge that phishing simulations can cause stress, embarrassment, or distress to recipients. You agree that:

  • SecureAZ bears no liability for any psychological distress, emotional harm, or adverse consequence experienced by any recipient arising from a simulation, to the extent permitted by law;
  • Any employee complaints, grievances, or legal claims arising from simulations are your responsibility; and
  • SecureAZ recommends, but does not require, that you inform employees in general terms that security testing may occur, without disclosing specific timing or methods.

9.4 Simulation templates and third-party brands

Phishing simulation templates may imitate the look and feel of well-known brands or communications solely for training purposes. You acknowledge that you select and authorise the templates used in your simulations, and you are responsible for ensuring your use is lawful in your jurisdiction. SecureAZ makes no warranty that any template is free from third-party trademark or other rights, and clause 23 applies to your use of templates.

9.5 Anti-spam compliance

You are responsible for ensuring that simulations you authorise comply with applicable electronic-messaging laws, including the New Zealand Unsolicited Electronic Messages Act 2007 and the Australian Spam Act 2003, in relation to the recipients you designate. Simulated messages are sent to your own personnel or designated users at your instruction and for your internal purposes.

9.6 Deliverability

You are responsible for your own systems, email configuration, and access arrangements, including whitelisting SecureAZ's sending domains and IP addresses and ensuring your firewall, email gateway, and spam-filter settings do not block delivery. SecureAZ is not responsible for issues arising from your internal systems, email configurations, or user-access limitations, including simulations or communications that fail to deliver as a result.

10. Beta and Preview Features

SecureAZ may make features identified as "beta", "preview", "early access", or similar available to you. Such features are provided "as is", may be changed or withdrawn at any time, are excluded from any service-level or support commitment, and are used at your own risk.

11. Fees and Payment

11.1 Fees

Fees are as set out in the applicable Order Form. Unless otherwise agreed in writing, all fees are stated in New Zealand Dollars (NZD) and are exclusive of GST, which is added where applicable.

11.2 Invoicing and payment terms

Unless otherwise agreed in writing, invoices are due within fourteen (14) days of the invoice date. SecureAZ may charge interest on overdue amounts at 1.5% per month or the maximum rate permitted by law, whichever is lower.

11.3 Suspension for non-payment

SecureAZ may suspend access to the Platforms and Services, without liability, if payment is not received by the due date after providing 7 days' written notice of the overdue amount.

11.4 Disputed invoices

If you dispute an invoice in good faith, you must notify SecureAZ in writing within 7 days of receipt. Undisputed amounts remain due and payable by the original due date.

11.5 Taxes

You are responsible for all taxes, duties, and levies imposed on the Services other than taxes on SecureAZ's income.

12. Subscriptions and Renewal

Where Services are provided on a subscription basis and you are not an authorised MSP or Reseller:

  • Subscriptions automatically renew at the end of each billing period unless cancelled by you in writing at least 30 days before the renewal date;
  • SecureAZ will provide reasonable notice of any change to subscription fees before renewal;
  • Cancellation after renewal takes effect at the end of the then-current billing period, and no refunds are provided for partial periods; and
  • You may upgrade or downgrade your plan, with changes taking effect at the start of the next billing period unless otherwise agreed.

MSP and Reseller pooled billing and subscription arrangements are governed by clause 13 and, where inconsistent, clause 13 prevails.

13. Managed Service Provider and Reseller Programme

13.1 Authorisation

SecureAZ may, at its discretion, grant a customer written authorisation to act as an MSP or Reseller and to provision, manage, or resell the Services to Client Organisations. This clause applies only where that authorisation has been granted. An authorised MSP or Reseller is referred to in this clause as a "Partner". This clause supersedes the resale and sub-licensing restrictions in clause 5 for that Partner.

13.2 Resale and sub-licensing

Subject to this clause, an authorised Partner is granted a limited, non-exclusive, non-transferable right to market, resell, administer, and sub-license access to the Services to its own Client Organisations. The Partner sets its own resale pricing to Client Organisations. SecureAZ is not a party to the commercial arrangement between the Partner and its Client Organisations. The Partner does not acquire ownership of the Platforms, Services, training content, software, or other SecureAZ intellectual property.

13.3 Partner as contracting party

The Partner is the contracting party with SecureAZ. SecureAZ has no contract or billing relationship with Client Organisations unless SecureAZ separately agrees to contract directly with a Client Organisation. The Partner is responsible for its relationship with each Client Organisation, including:

  • payment;
  • administration;
  • obtaining necessary authorisations;
  • ensuring appropriate contractual terms are in place;
  • compliance with applicable laws; and
  • acts and omissions of its administrators and Client Organisations to the extent required under these Terms.

13.4 Client Organisation requirements

The Partner must ensure that each Client Organisation is contractually bound to the Partner by terms that impose obligations consistent with the applicable requirements of these Terms before the Client Organisation accesses the Services. The Partner warrants that:

  • It has authority to provide the Services to each Client Organisation;
  • It has a legitimate business relationship with each Client Organisation;
  • It has obtained all necessary consents and authorisations to provision the Services;
  • It will provide Client Organisations with appropriate information about the Services and any monitoring or testing involved; and
  • It will ensure that its Client Organisations and their users comply with the applicable use and security requirements of these Terms.

13.5 Pooled billing — monthly in arrears

Unless otherwise agreed in an Order Form, Partner seat pools are billed monthly in arrears. On the first day of each month, SecureAZ takes a snapshot of the Partner's pool size for the month just ended. The invoice is calculated by multiplying the applicable pool size by the applicable per-seat rate.

Where tiered pricing applies, the entire pool is charged at the per-seat rate applicable to the pool's final size for that billing period, rather than applying different rates to different portions of the pool.

All amounts are exclusive of GST. Payment terms are as set out in clause 11.2. Only activated, paying Client Organisations consume pool seats. Trial organisations do not consume pool seats.

13.6 Pricing models

The Partner's per-seat rate is set out in its Order Form or applicable pricing schedule and may be:

  • Manual — a fixed negotiated per-seat rate, with pool changes requested in writing; or
  • Tiered — a per-seat rate that decreases as the pool grows, in accordance with the volume bands in the applicable pricing schedule.

Where tiered pricing applies, the Partner may resize its own pool through the App and the applicable per-seat rate may change as the pool size moves between pricing bands. SecureAZ may change future Partner pricing or pricing schedules by providing reasonable written notice.

13.7 Self-service pool changes

Where the Partner may change its pool through the App:

  • Increases take effect immediately for seat availability. The corresponding billing change takes effect from the next billing period, and seats added during a month are not charged for that month;
  • Decreases take effect from the next billing period and a pool may not be reduced below the number of seats already allocated to Client Organisations;
  • A scheduled change may be replaced or cancelled before its effective date; and
  • Any authorised Partner portal administrator may make these changes. SecureAZ does not approve them in advance.

13.8 Over-allocation

The Partner must not allocate more seats than are available in its pool. If the number of seats allocated exceeds the pool size, SecureAZ may increase the pool to the required level and apply the applicable rate from the next billing period. SecureAZ may also require the Partner to reduce allocations where the over-allocation results from misuse or an error.

13.9 No pro-rating or refunds

No pro-rating or refunds are provided for partial months, unused seats, or changes to a pool during a billing period.

13.10 Delegated access

Partner administrators may have delegated administrative access into their Client Organisations' portals. The Partner is responsible for controlling and supervising that access and ensuring administrators are properly authorised.

13.11 Branding and representation

The Partner may market and promote the SecureAZ Services as part of its managed services or reseller offering. The Partner must not:

  • represent itself as SecureAZ;
  • claim ownership of SecureAZ intellectual property;
  • make statements that create an unauthorised agency relationship with SecureAZ; or
  • use SecureAZ trademarks or branding except as authorised.

White-labelling or co-branding is permitted only where separately agreed in writing and only to the extent of that written permission.

13.12 Suspension and termination of Partner account

If a Partner's account is suspended, SecureAZ may suspend access for Client Organisations under that account to the extent reasonably necessary. If the Partner's account is terminated, access for Client Organisations under that account may cease following a reasonable transition period determined by SecureAZ, subject to any applicable Order Form or written agreement.

SecureAZ accepts no liability to Client Organisations for loss or disruption arising from suspension or termination of the Partner's account, except to the extent liability cannot lawfully be excluded. Following termination, SecureAZ and the Partner will cooperate in good faith to enable an orderly transition. Where agreed by the affected Client Organisation, SecureAZ may enter into a direct agreement with that Client Organisation or facilitate a transition to another authorised Partner.

13.13 Partner indemnity

The Partner indemnifies SecureAZ against claims, losses, liabilities, damages, penalties, costs, and expenses arising from:

  • the Partner's breach of this Agreement;
  • the Partner's failure to obtain required consents or authorisations;
  • the Partner's unlawful or unauthorised use of the Services;
  • the Partner's acts or omissions in administering the Services for Client Organisations;
  • disputes between the Partner and a Client Organisation; or
  • claims arising from the Partner's deployment of phishing simulations or training where the Partner was responsible for obtaining the relevant authority or consent.

Clause 23.2 applies to this indemnity.

14. Data Protection and Privacy

14.1 Compliance

Each party will comply with the New Zealand Privacy Act 2020 and, where applicable, the Australian Privacy Act 1988, in connection with the Services.

14.2 Roles

Where you, or in the Partner model the Partner, provide SecureAZ with Personal Information about employees, users, or other individuals, the parties will comply with their respective obligations under applicable privacy law. The parties acknowledge that the legal roles and responsibilities of SecureAZ, the Partner, and Client Organisations may depend on the nature and purpose of the relevant processing. SecureAZ will process Personal Information for the purposes of providing the Services, in accordance with the Agreement, the Privacy Policy, and applicable law.

14.3 Your warranties

You warrant that you have all necessary rights, consents, authorisations, and lawful basis to provide Personal Information to SecureAZ and to authorise its processing under the Agreement. In the Partner model, the Partner gives this warranty in respect of Personal Information relating to its Client Organisations and users.

14.4 SecureAZ's obligations

SecureAZ will:

  • Process Personal Information only to provide the Services and as otherwise permitted by the Agreement or required by law;
  • Apply reasonable technical and organisational security measures appropriate to the nature of the Personal Information;
  • Ensure personnel with access to Personal Information are bound by confidentiality obligations;
  • Not sell Personal Information; and
  • Provide reasonable assistance to help you respond to individuals exercising their access and correction rights.

14.5 Sub-processors

You authorise SecureAZ to engage sub-processors, including hosting, email-delivery, and analytics providers, to help deliver the Services. SecureAZ remains responsible for its sub-processors' compliance with the relevant obligations applicable to SecureAZ under this clause and will make available, on request, a current list of material sub-processors.

14.6 Location and cross-border transfer

Personal Information may be stored and processed in New Zealand, Australia, or other locations used by SecureAZ's sub-processors. Where Personal Information is transferred outside New Zealand, SecureAZ will take reasonable steps consistent with Information Privacy Principle 12 to ensure comparable protections apply.

14.7 Breach notification

SecureAZ will notify you without undue delay after becoming aware of a notifiable privacy breach, as defined by applicable law, affecting Personal Information it processes in connection with the Services. SecureAZ will provide reasonable information to help you meet your notification obligations. Nothing in this clause allocates to SecureAZ a notification obligation that the law places on you as the agency responsible for the affected individuals.

14.8 Retention and deletion

On termination, clause 24 applies to data export. Following the applicable export period, SecureAZ will delete or de-identify Personal Information it holds in connection with providing the Services within a reasonable period, except where retention is required by law or reasonably required for the establishment or defence of legal claims.

14.9 Standalone data terms

For customers or Partners requiring a separate data processing agreement, SecureAZ's applicable data processing terms will apply and, to the extent of any inconsistency, prevail over this clause in accordance with clause 3.

15. Confidentiality

Each party will keep confidential all non-public information received from the other party in connection with the Services ("Confidential Information") and use it only for the purposes of the Agreement.

Confidential Information does not include information that:

  1. is or becomes public through no fault of the receiving party;
  2. was already known to the receiving party;
  3. is independently developed without reference to the Confidential Information; or
  4. is required to be disclosed by law or court order.

This clause survives termination.

16. Uploaded Content

You are solely responsible for all content, data, and materials you upload to the Platforms ("Uploaded Content"). You warrant that Uploaded Content does not infringe any third-party rights and does not contain unlawful, obscene, or otherwise objectionable material.

You grant SecureAZ a non-exclusive, royalty-free licence to use Uploaded Content solely to provide the Services to you.

SecureAZ may remove or disable access to any Uploaded Content it reasonably considers unlawful, infringing, or inappropriate, without prior notice.

17. Intellectual Property

All content on the Platforms, including text, graphics, logos, icons, training content, simulation templates, software, and data, is the property of SecureAZ Limited or its licensors and is protected by applicable intellectual property laws.

Nothing in the Agreement transfers any intellectual property rights to you, except for the limited licences expressly granted. Authorised MSPs and Resellers receive only the limited resale and sub-licensing rights expressly granted under clause 13.

You may not use SecureAZ's name, logo, or branding without prior written consent, except as permitted under clause 13.11.

18. Marketing and Communications

By submitting your contact details, you consent to receiving marketing communications from SecureAZ to the extent permitted by applicable law.

You may opt out at any time via the unsubscribe link in any marketing email or by emailing hello@secureaz.co.nz.

Opting out of marketing does not affect transactional or service-related communications.

19. Service Availability and Support

19.1

SecureAZ will use commercially reasonable efforts to keep the Platforms available but does not guarantee uninterrupted or error-free access.

19.2

Planned maintenance will, where practicable, be scheduled outside New Zealand business hours, and SecureAZ will aim to give reasonable notice of maintenance likely to cause material disruption.

19.3

Support is provided during SecureAZ's published support hours. Any specific service-level commitments apply only where set out in an Order Form or a separate SLA.

20. Suspension

In addition to clause 11.3, SecureAZ may suspend your access to the Platforms, in whole or in part, where it reasonably considers that:

  1. your use poses a security, legal, or integrity risk to the Platforms, SecureAZ, or other users;
  2. your use breaches the Agreement or applicable law; or
  3. suspension is required to comply with law or a regulator's direction.

SecureAZ will, where practicable, give notice and limit the scope and duration of any suspension to what is reasonably necessary, and will restore access once the cause is resolved.

21. Disclaimers

The Platforms and Services are provided on an "as is" and "as available" basis without warranties of any kind, express or implied, including implied warranties of merchantability, fitness for a particular purpose, and non-infringement, except to the extent such warranties cannot be excluded by law.

SecureAZ does not warrant that:

  • The Platforms will be uninterrupted, error-free, or free from viruses or other harmful components;
  • Results obtained from the Services will be accurate, complete, or reliable; or
  • The Services will meet any specific compliance, insurance, or regulatory requirement.

You are responsible for verifying with your insurer, regulator, or compliance team whether the Services meet your specific requirements.

22. Limitation of Liability

22.1 Cap

To the fullest extent permitted by law, SecureAZ's total aggregate liability to you for all claims arising under or in connection with the Agreement or the Services, whether in contract, tort, including negligence, equity, under statute, or on any other basis, will not exceed the total fees paid by you to SecureAZ in the twelve (12) months immediately preceding the event giving rise to the claim.

22.2 Excluded loss

SecureAZ will not be liable for any loss of profits, revenue, data, goodwill, or anticipated savings; any indirect, consequential, special, or punitive damages; business-interruption losses; or third-party claims, in each case even if advised of the possibility of such loss.

22.3 Your systems

SecureAZ is not liable for any loss or damage arising from your internal systems, email or network configuration, whitelisting or deliverability failures, or user-access limitations.

22.4 Time bar

Any claim must be brought within twelve (12) months after the date on which the event giving rise to the claim occurred, failing which the claim is waived to the extent permitted by law.

22.5 Matters not limited

Nothing in the Agreement excludes or limits liability that cannot be excluded or limited by law, including liability for fraud or fraudulent misrepresentation, for death or personal injury caused by negligence, or under the non-excludable consumer guarantees referred to in clause 25.

23. Indemnification

23.1 Your indemnity

You indemnify and hold harmless SecureAZ Limited and its directors, officers, employees, agents, contractors, and licensors from any claims, liabilities, damages, losses, penalties, fines, costs, and expenses, including reasonable legal fees, arising from or related to:

  • Your use of or inability to use the Platforms or Services;
  • Your breach of the Agreement;
  • Your violation of any applicable law, including privacy, employment, and electronic-communications laws;
  • Any claim by an employee, contractor, or third party arising from a phishing simulation or training programme conducted under your authorisation;
  • Your failure to obtain necessary consents and authorisations before deploying the Services;
  • Your violation of any third-party rights; or
  • Any content or information you submit to SecureAZ.

23.2 Procedure

The indemnified party will:

  1. give the indemnifying party prompt written notice of the claim;
  2. allow the indemnifying party to control the defence and settlement, provided no settlement imposes a non-indemnified obligation on the indemnified party without consent;
  3. provide reasonable cooperation at the indemnifying party's expense; and
  4. take reasonable steps to mitigate its loss.

23.3 SecureAZ IP indemnity

If expressly included in an applicable Order Form, SecureAZ will defend you against any third-party claim that your permitted use of the Platforms infringes that third party's New Zealand or Australian intellectual property rights, and will indemnify you for damages finally awarded, subject to clause 23.2 and the cap in clause 22.1. This indemnity does not apply to Uploaded Content, your configurations, phishing templates you select, or use outside the Agreement. This is SecureAZ's sole liability for intellectual-property infringement.

23.4 Survival

Clauses 22 and 23 survive termination.

24. Term and Termination

The Agreement commences when you first access the Platforms or agree to these Terms and continues until terminated. Either party may terminate on 30 days' written notice. SecureAZ may terminate immediately for material breach, insolvency, or non-payment where permitted by law.

On termination:

  • your access to the Platforms will cease, subject to any applicable transition period;
  • you must pay all outstanding fees;
  • each party's confidentiality obligations continue;
  • SecureAZ will provide a reasonable opportunity to export your data on request within 30 days of termination; and
  • following the export period, clause 14.8 applies.

For MSPs and Resellers, clause 13 also applies. Where an MSP or Reseller relationship is terminated, SecureAZ may allow affected Client Organisations a reasonable transition period to enter into a direct agreement with SecureAZ or another authorised Partner. Any such transition is subject to SecureAZ's approval and the applicable commercial terms.

25. Consumer Law (New Zealand and Australia)

25.1 New Zealand — business use

Where you acquire the Services for the purposes of a business, you and SecureAZ agree that the Consumer Guarantees Act 1993 and sections 9, 12A, and 13 of the Fair Trading Act 1986 do not apply, and that it is fair and reasonable for them to be excluded, to the extent permitted by sections 5C and 5D of the Fair Trading Act 1986 and the Consumer Guarantees Act 1993.

25.2 New Zealand — consumers

Where you acquire the Services as a consumer and the above exclusion does not apply, nothing in the Agreement limits or excludes rights you have under the Consumer Guarantees Act 1993 that cannot be excluded.

25.3 Australia

Nothing in the Agreement excludes, restricts, or modifies any guarantee, right, or remedy under the Australian Consumer Law that cannot lawfully be excluded. Where SecureAZ is entitled to limit its liability for breach of a non-excludable guarantee, its liability is limited, at its option, to re-supplying the Services or paying the cost of having them re-supplied.

26. Force Majeure

Neither party is liable for any failure or delay in performing its obligations, other than payment obligations, caused by events beyond its reasonable control, including natural disasters, epidemics, war, civil unrest, industrial action, failures of telecommunications or third-party infrastructure, or government action. The affected party will use reasonable efforts to mitigate the effect. If a force majeure event continues for more than 60 days, either party may terminate the affected Services on written notice.

27. General

27.1 Assignment and novation

You may not assign or novate the Agreement without SecureAZ's prior written consent. SecureAZ may assign or novate the Agreement to an affiliate or in connection with a merger, acquisition, or sale of all or substantially all of its assets, on notice to you.

27.2 Severability

If any provision of the Agreement is held invalid or unenforceable, it will be modified to the minimum extent necessary or, if it cannot be, severed, and the remaining provisions continue in full force.

27.3 Waiver

A failure or delay in exercising any right is not a waiver of that right, and no waiver is effective unless in writing.

27.4 Notices

Notices to SecureAZ must be sent to hello@secureaz.co.nz. Notices to you may be sent to the email address associated with your account or posted as a prominent notice on the Platforms. Notice is deemed given when sent, unless the sender receives a delivery-failure notification.

27.5 Dispute resolution

Before commencing proceedings, other than for urgent interlocutory relief, the parties will first attempt in good faith to resolve any dispute through senior-representative discussions and, failing resolution within 20 working days, through mediation in New Zealand.

27.6 Publicity

SecureAZ may identify you as a customer, using your name and logo, in its customer lists and marketing materials, unless you notify SecureAZ in writing that you do not consent.

27.7 Survival

Any provision that by its nature should survive termination does so, including clauses 11, 13, 14, 15, 17, 22, 23, 25, 26, 27.5, and 28.

27.8 Relationship

The parties are independent contractors. Nothing in the Agreement creates a partnership, agency, employment, fiduciary, or joint-venture relationship. The limited resale and sub-licensing rights granted to authorised MSPs and Resellers under clause 13 do not create an agency relationship between SecureAZ and the Partner.

28. Governing Law

The Agreement is governed by the laws of New Zealand, and the parties submit to the non-exclusive jurisdiction of the New Zealand courts. Where you are located in Australia, nothing in the Agreement limits your rights under the Australian Consumer Law.

29. Changes to These Terms

SecureAZ may update these Terms from time to time. We will give at least 14 days' notice of material changes by email or a prominent notice on the Platforms. Your continued use after the effective date constitutes acceptance. If you do not agree, you must stop using the Platforms and notify SecureAZ in writing.

Changes to commercial pricing are governed by the applicable provisions of clauses 11, 12 and 13 and do not require amendment of these Terms.

30. Cybersecurity Disclaimer

You acknowledge that:

  • No cybersecurity product, training programme, or phishing simulation can guarantee complete protection against all threats;
  • The cybersecurity landscape changes rapidly and the Services may not address all current or emerging threats;
  • The training content is designed for general awareness and may not be tailored to your specific industry, regulatory environment, or risk profile; and
  • Completion of SecureAZ training does not guarantee that your employees will not fall victim to a cyber attack.

SecureAZ provides the Services as an educational tool to improve awareness and makes no guarantee of specific security outcomes.

31. Contact

Company: SecureAZ Limited
Location: New Zealand