Terms of Service
These terms govern engaging CipherCru for professional services. Using this website alone is governed separately, by the Website Terms of Use.
Last updated 1 September 2026
These Terms of Service are Version 1.0.
Part I: Introduction
1. Introduction
These Terms of Service (these “Terms”) govern your access to and use of the website, platforms, portals, and professional services provided by CipherCru Innovations Private Limited, a company incorporated under the Companies Act, 2013 with its registered office at 602, The Elysian, A-31, Swej Farm Circle, Swej Farm, New Sanganer Road, Sodala, Jaipur, Rajasthan 302019, India (referred to in these Terms as “CipherCru”, “we”, “us”, or “our”).
1.1 Purpose. These Terms constitute a legally binding agreement between CipherCru and the individual or legal entity accessing our Website or engaging us for Services (referred to as “Client”, “you”, or “your”). These Terms define the rights, obligations, limitations, and remedies of each party in connection with all services, deliverables, and digital interactions with CipherCru.
1.2 Scope. These Terms apply to all visitors to and users of the CipherCru website located at https://www.ciphercru.com and any subdomains thereof (the “Website”); all individuals, companies, and entities that engage CipherCru for any professional services, including but not limited to software development, consulting, managed services, SaaS products, AI solutions, DevOps, cloud engineering, staff augmentation, and all other service offerings described in Section 10 (collectively, the “Services”); and all interactions arising from proposal requests, quotations, project engagements, support relationships, and ongoing commercial relationships with CipherCru.
1.3 Supplementary Documents. These Terms should be read together with the following documents, which are incorporated by reference and form part of the overall legal framework governing your relationship with CipherCru:
- Master Services Agreement (MSA): governs the overarching commercial relationship for ongoing or multi-project engagements.
- Statement of Work (SOW): governs the scope, timeline, deliverables, and pricing of individual projects.
- Privacy Policy: governs the collection, processing, and storage of personal data.
- Cookie Policy: governs the use of cookies and tracking technologies on the Website.
- Data Processing Agreement (DPA): governs data processing activities where CipherCru acts as a data processor.
- Support and SLA Policy: governs post-delivery support commitments and service level standards.
- Acceptable Use Policy (AUP): governs permitted and prohibited uses of CipherCru's platforms, tools, and deliverables.
- Refund and Cancellation Policy: governs refund eligibility, cancellation procedures, and related commercial arrangements.
- Mutual Non-Disclosure Agreement (NDA): governs the protection of confidential information exchanged between the parties.
The MSA, SOW and NDA are executed between the parties rather than published. In the event of a conflict between these Terms and any executed MSA or SOW, the MSA or SOW shall prevail to the extent of the conflict, unless these Terms expressly state otherwise.
2. Definitions
The following terms have the specific meanings assigned below whenever they appear in these Terms, and in any document that incorporates these Terms by reference, with an initial capital letter.
- Acceptance
- The formal or deemed acknowledgment by the Client that a Deliverable, milestone, or phase of work satisfies the requirements specified in the applicable SOW, in accordance with the acceptance procedures set out in Section 12.7.
- Acceptance Period
- The period of ten (10) Business Days following CipherCru's notification to the Client that a Deliverable is ready for review, unless a different period is expressly stated in the applicable SOW.
- AI Tools
- Any artificial intelligence, machine learning, or generative AI services, platforms, APIs, or tools used by CipherCru in the performance of Services, including but not limited to OpenAI, Anthropic Claude, Google Gemini, Microsoft Copilot, GitHub Copilot, Cursor, Tabnine, and any successor or equivalent AI systems or large language model services.
- AI-Generated Content
- Any text, code, images, documentation, designs, data, outputs, or other materials generated in whole or in part using AI Tools during the performance of Services.
- Applicable Law
- The laws and regulations of the Republic of India applicable to the parties, including the Indian Contract Act 1872, the Information Technology Act 2000 and rules thereunder, the Digital Personal Data Protection Act 2023 (“DPDP Act”), the Companies Act 2013, the Arbitration and Conciliation Act 1996, and any other applicable statute, regulation, order, or guideline issued by a competent authority.
- Business Day
- Any day that is not a Saturday, Sunday, or public holiday in Rajasthan, India.
- Change Request
- A written request submitted by either party to modify the scope, timeline, budget, or specifications of any Services or Deliverables beyond what is described in the applicable SOW.
- Client
- The individual, company, organisation, or other legal entity that has accepted these Terms, signed an MSA or SOW with CipherCru, or otherwise engaged CipherCru for Services.
- Client Materials
- All content, data, documentation, code, designs, logos, trademarks, databases, media, datasets, and other materials supplied by the Client to CipherCru for use in connection with the Services.
- Confidential Information
- Has the meaning given in Section 30.1.
- Deliverable
- Any work product, software, code, design, report, documentation, API, application, system, or output produced by CipherCru specifically for the Client under an applicable SOW.
- Fees
- The charges payable by the Client to CipherCru for Services, as specified in the applicable SOW, quotation, or as otherwise agreed in writing between the parties.
- Force Majeure Event
- Has the meaning given in Section 41.1.
- Intellectual Property Rights (IP Rights)
- All intellectual property rights of any nature anywhere in the world, whether subsisting now or in the future, including patents, patent applications, copyright including moral rights, database rights, design rights, trade marks, trade names, service marks, domain names, trade secrets, know-how, rights in software, rights in inventions, and all similar or equivalent rights, whether registered or unregistered.
- Internal Frameworks
- CipherCru's proprietary and internally developed reusable assets, libraries, frameworks, templates, modules, pipelines, scripts, agents, and methodologies, including Java frameworks, Spring Boot starters, React component libraries, Next.js templates, NestJS modules, Docker images, Kubernetes manifests, Terraform modules, DevOps scripts, CI/CD pipeline configurations, SDKs, utility libraries, AI agents, workflow automations, internal architecture templates, and all similar proprietary tools and methodologies.
- MSA
- The Master Services Agreement executed or to be executed between CipherCru and the Client, which governs the overarching commercial relationship for multi-project or ongoing engagements.
- Open Source Software
- Any software licensed under an open-source licence, including licences approved by the Open Source Initiative such as Apache 2.0, MIT, BSD, GNU General Public Licence, GNU Lesser General Public Licence, and Mozilla Public Licence.
- Personal Data
- Has the meaning given under the DPDP Act or, where applicable to data subjects outside India, the meaning given under the GDPR or the CCPA, as the context requires.
- Pre-existing IP
- Any Intellectual Property Rights owned or controlled by a party prior to the commencement of any Services, or developed independently of the Services.
- Project
- A specific engagement or work stream for which the parties have agreed a SOW.
- Services
- All professional, consulting, technology, and support services provided by CipherCru to the Client, as more fully described in Section 10 and in applicable SOWs.
- SOW (Statement of Work)
- A document, agreed and signed by both parties, that specifies the scope of work, Deliverables, timeline, milestones, Fees, and other project-specific terms applicable to a specific Project.
- Third-Party Services
- Software, platforms, APIs, cloud infrastructure, tools, or services owned and operated by third parties, not CipherCru, that may be integrated into or used in connection with the Services.
- Website
- The CipherCru website located at https://www.ciphercru.com and all associated subdomains, pages, and digital properties operated by CipherCru.
3. Acceptance of terms
3.1 How Acceptance Occurs. You accept these Terms and enter into a binding agreement with CipherCru by any of the following acts:
- clicking or selecting a button, checkbox, or link indicating agreement to these Terms;
- signing or electronically executing a SOW, MSA, or other contract that incorporates these Terms by reference;
- submitting a project enquiry, request for proposal, or purchase order to CipherCru;
- making payment of any Fees to CipherCru;
- accessing or using the Website or any part of the Services after being presented with these Terms;
- exchanging email communications that expressly reference and agree to these Terms or incorporate them by reference.
3.2 Authority to Accept. If you are accepting these Terms on behalf of a company, organisation, or other legal entity, you represent and warrant that you have the legal authority and capacity to bind that entity to these Terms. If you do not have such authority, you must not accept these Terms and must not use the Services on behalf of that entity.
3.3 No Verbal Overrides. No verbal agreement, oral representation, or informal understanding shall modify, supplement, or override these Terms unless confirmed in writing and signed by an authorised representative of CipherCru.
3.4 Severability of Acceptance. Acceptance of these Terms in relation to Website use does not automatically constitute an agreement for the provision of Services. A separate SOW or MSA is required to engage CipherCru for professional services.
4. Eligibility
4.1 Minimum Age. You must be at least eighteen (18) years of age to access the Website or engage CipherCru for Services. By accepting these Terms, you represent and warrant that you meet this minimum age requirement.
4.2 Legal Capacity. You must have full legal capacity to enter into binding contracts under Applicable Law. If you are entering into these Terms on behalf of a legal entity, that entity must be validly incorporated, registered, or otherwise legally constituted.
4.3 Prohibited Persons. You must not access the Website or use the Services if you are located in, a national of, or otherwise subject to the laws of a jurisdiction that is subject to comprehensive sanctions administered by the United Nations Security Council, the Government of India, the United States Office of Foreign Assets Control, the European Union, or the United Kingdom; if you are listed on any applicable government list of prohibited, sanctioned, or restricted persons or entities; or if your use of the Services would violate any Applicable Law.
4.4 Corporate Eligibility. Where a Client is a corporate entity, it represents and warrants that the individual accepting these Terms on its behalf is duly authorised and that the corporate entity is not subject to any order, judgment, or restriction that would prevent it from entering into or performing its obligations under these Terms.
5. Changes to terms
5.1 Right to Amend. CipherCru reserves the right to modify, update, or replace these Terms at any time at its sole discretion. We will provide notice of material changes by posting a notice on the Website; by sending an email to the contact address associated with your account or engagement; and by updating the last-updated date at the top of these Terms.
5.2 Effect of Continued Use. Your continued access to the Website or continued engagement with CipherCru for Services after the effective date of any amended Terms constitutes your acceptance of the revised Terms. If you do not agree to the revised Terms, you must cease using the Website and must provide written notice to CipherCru of your intention to terminate any active engagement, subject to the termination provisions in Section 37.
5.3 Existing Projects. Changes to these Terms will not retroactively alter the terms applicable to an engagement where a SOW has already been executed and work has commenced, unless both parties agree in writing. For executed SOWs, the Terms in effect at the time of execution shall continue to govern that engagement unless modified by written agreement.
5.4 Review Responsibility. It is your responsibility to review these Terms periodically. CipherCru is not obligated to individually notify each Client of every update.
Part II: Website use
6. Website usage
6.1 Licence to Access. Subject to these Terms, CipherCru grants you a limited, non-exclusive, non-transferable, revocable licence to access and use the Website for the purpose of learning about CipherCru's Services, submitting enquiries, and accessing publicly available content.
6.2 Permitted Use. You may access and use the Website for lawful purposes only. You agree not to use the Website in any manner that violates any Applicable Law or regulation; infringes the IP Rights of CipherCru or any third party; transmits or facilitates the transmission of unsolicited commercial communications; introduces or attempts to introduce malicious code, viruses, trojans, spyware, ransomware, or other harmful software; or interferes with or disrupts the operation, security, or integrity of the Website or its underlying infrastructure.
6.3 Availability. CipherCru makes reasonable efforts to ensure the Website is available and functional but does not guarantee uninterrupted or error-free access. The Website may be temporarily unavailable for maintenance, updates, or due to factors outside CipherCru's control. CipherCru is not liable for any loss or inconvenience arising from Website unavailability.
6.4 Third-Party Links. The Website may contain hyperlinks to third-party websites. Those links are provided for convenience only. CipherCru does not endorse, control, or take responsibility for the content, privacy practices, or terms of any linked third-party website. Your use of any linked website is entirely at your own risk.
6.5 Website Content. All content on the Website, including text, graphics, logos, icons, images, audio, and software, is the property of CipherCru or its licensors and is protected by applicable copyright, trade mark, and other IP laws. You may not reproduce, distribute, publish, modify, or create derivative works from any Website content without CipherCru's prior written consent.
6.6 No Reliance. Content on the Website is provided for general informational purposes. It does not constitute professional advice, whether legal, financial, technical or otherwise, and should not be relied upon as such. CipherCru makes no representations as to the accuracy or completeness of information on the Website.
7. User accounts
7.1 Account Creation. Certain features of the Website or CipherCru platforms may require you to create an account. When creating an account, you must provide accurate, current, and complete information and must update that information promptly if it changes.
7.2 Account Credentials. You are solely responsible for maintaining the confidentiality of your account credentials, including username and password, and for all activities that occur under your account, whether or not authorised by you.
7.3 Unauthorised Access. You must notify CipherCru immediately at the contact details in Section 45 if you become aware of any unauthorised access to your account, breach of security, or loss or theft of your credentials. CipherCru shall not be liable for any loss or damage arising from your failure to protect your credentials.
7.4 Account Security Obligations. You are responsible for using strong and unique passwords for your account; enabling multi-factor authentication where available; not sharing your credentials with any other person or entity; and logging out of your account when not in use on shared or public devices. CipherCru is not responsible for any loss, damage, or unauthorised action resulting from your failure to comply with these security obligations.
7.5 Account Termination. CipherCru reserves the right to suspend or terminate your account without prior notice if you breach these Terms; if your account is involved in fraudulent, abusive, or illegal activity; or if CipherCru is required to do so by Applicable Law or court order.
8. Acceptable use
8.1 General Standards. You agree to use the Website, CipherCru's platforms, and any Deliverables provided to you in a lawful, responsible, and ethical manner, consistent with CipherCru's Acceptable Use Policy, which is incorporated by reference and published on this site.
8.2 Prohibited Content. You must not use CipherCru platforms or Deliverables to host, transmit, store, or distribute content that is unlawful, defamatory, obscene, or otherwise objectionable; content that infringes the IP Rights of any third party; content that violates applicable privacy, data protection, or anti-spam laws; malware, spyware, or any other malicious software; or content that promotes or facilitates violence, terrorism, hate speech, discrimination, or human exploitation.
8.3 Compliance with Laws. You are solely responsible for ensuring that your use of any Deliverable or platform provided by CipherCru complies with all Applicable Laws in each jurisdiction where you deploy or use that Deliverable or platform.
9. Prohibited activities
9.1 Without limiting Section 8, you must not engage in any of the following activities in connection with the Website, Services, or Deliverables:
- Reverse engineering. Decompiling, disassembling, reverse engineering, or otherwise attempting to derive the source code, architecture, or algorithms of any software or tool provided by CipherCru, except to the extent expressly permitted by Applicable Law.
- Circumvention. Circumventing, disabling, or interfering with any security feature, access control, copy-protection mechanism, or licence enforcement mechanism.
- Unauthorised scraping. Using automated bots, crawlers, scrapers, or similar tools to extract content or data from the Website or any CipherCru platform without prior written consent.
- Impersonation. Impersonating CipherCru, its employees, representatives, or any other person or entity, or misrepresenting your affiliation with CipherCru.
- Overloading infrastructure. Transmitting an unreasonably large volume of requests or otherwise placing an unreasonable or disproportionate load on CipherCru's infrastructure or third-party infrastructure used in connection with the Services.
- Competitor intelligence. Accessing the Website or Services primarily for the purpose of competitive analysis or developing a competing product or service, without CipherCru's prior written consent.
- Solicitation. Using contact information obtained from CipherCru to solicit CipherCru's employees, contractors, or other clients without CipherCru's prior written consent.
- Data harvesting. Collecting or harvesting Personal Data of other users, visitors, or individuals without appropriate legal authority.
- Fraudulent activity. Engaging in fraudulent, deceptive, or misleading conduct in connection with any engagement with CipherCru.
- Export violations. Using the Services, Deliverables, or any technology provided by CipherCru in violation of any applicable export control, sanctions, or trade restriction laws, including laws administered by the Government of India, OFAC, or the European Union.
9.2 Consequences. Violation of this Section 9 may result in immediate suspension or termination of your access to the Website and Services, and may expose you to civil or criminal liability under Applicable Law.
Part III: Services
10. Service description
10.1 Services Offered. CipherCru provides the following categories of professional services:
- Custom software development: design, development, and deployment of bespoke software applications, systems, and platforms tailored to Client specifications.
- Enterprise software development: development of large-scale enterprise-grade software solutions, including integration with existing enterprise systems.
- SaaS product development: end-to-end design, development, and launch of Software-as-a-Service products, including multi-tenant architecture, subscription management, and cloud deployment.
- AI solutions: development and integration of artificial intelligence, machine learning, and generative AI capabilities, including custom model fine-tuning, AI agent development, AI workflow automation, and AI API integration.
- AI agents: design, development, and deployment of autonomous AI agents, including multi-agent systems, AI orchestration pipelines, and AI-powered automation workflows.
- Cloud engineering: cloud infrastructure design, provisioning, migration, optimisation, and management across AWS, Google Cloud Platform, Microsoft Azure, and other cloud platforms.
- DevOps services: implementation and management of CI/CD pipelines, containerisation, orchestration, infrastructure-as-code, monitoring, and DevOps culture adoption.
- Managed services: ongoing management, monitoring, maintenance, and support of Client infrastructure, applications, and systems under defined service levels.
- Website development: design and development of corporate websites, e-commerce platforms, content management systems, and web portals.
- Mobile application development: design and development of native, hybrid, and cross-platform mobile applications for iOS and Android.
- UI/UX design: user experience research, interface design, prototyping, design systems, and usability testing.
- API development and integration: design, development, and integration of RESTful APIs, GraphQL APIs, and third-party API integrations.
- Technical consulting and architecture: technical strategy, architecture review, technology selection, code audits, and advisory services.
- Staff augmentation: supply of skilled technical professionals to supplement Client teams on a time-and-materials or fixed-term basis.
- Maintenance and support: post-delivery maintenance, bug fixing, performance optimisation, and technical support services.
- Digital transformation: advisory, planning, and execution of technology-driven business transformation programmes.
10.2 Future Services. CipherCru may introduce new service offerings at any time. Unless specifically excluded, these Terms shall apply to all future services provided by CipherCru to the Client.
10.3 Services Not Advice. Unless expressly agreed in writing in an applicable SOW, CipherCru's Services do not constitute legal, financial, regulatory, accounting, medical, or investment advice. Clients requiring such advice should engage appropriately qualified professionals.
10.4 Sub-contractors. CipherCru reserves the right to engage sub-contractors, freelancers, or third-party specialists to perform all or part of the Services. CipherCru remains responsible to the Client for the performance of sub-contracted work to the standards agreed in the applicable SOW.
11. Quotations
11.1 Nature of Quotations. Any quotation, proposal, or estimate provided by CipherCru is indicative only and is not a binding offer unless the quotation is expressly stated to be a fixed-price binding offer, or the parties execute a SOW incorporating or referencing the quotation.
11.2 Validity Period. Unless otherwise stated, all quotations are valid for thirty (30) calendar days from the date of issue. CipherCru reserves the right to withdraw or revise a quotation at any time before it has been formally accepted through an executed SOW.
11.3 Changes in Scope. Quotations are based on the scope, requirements, and assumptions communicated by the Client at the time of the quotation. If the Client's requirements change after a quotation has been issued, CipherCru reserves the right to revise the quotation accordingly.
11.4 Good Faith Estimates. Where quotations are based on time-and-materials pricing, any hours or cost estimates are good faith projections only and do not represent a guaranteed maximum unless expressly stated as a not-to-exceed figure in writing.
11.5 Currency. All quotations are in Indian Rupees unless the quotation expressly states otherwise. Where quotations are provided in a foreign currency, Fees shall be converted and invoiced in the currency stated in the applicable SOW.
12. Statements of work
12.1 Requirement for SOW. All professional Services shall be governed by a Statement of Work executed by authorised representatives of both parties. No work shall commence, and no obligation to perform Services arises, until a SOW has been executed, unless otherwise agreed in writing by CipherCru.
12.2 SOW Contents. Each SOW shall typically include a description of the Services to be performed; a list of Deliverables and associated specifications; project milestones and target timelines; the Fee structure, whether fixed price, time-and-materials, or other; a payment schedule; assumptions on which the SOW is based; Client responsibilities and dependencies; the Acceptance Period and acceptance criteria, if applicable; and any special terms applicable to that Project.
12.3 SOW Precedence. In the event of a conflict between a SOW and these Terms, the SOW shall prevail to the extent of the conflict unless the SOW expressly states otherwise.
12.4 SOW Amendments. No amendment to a SOW is valid unless it is documented in a written Change Request signed by authorised representatives of both parties, in accordance with Section 16.
12.5 Template SOW. CipherCru's standard SOW template, where used, incorporates these Terms by reference. Deviations from the standard template must be agreed in writing.
12.6 Multiple SOWs. Each SOW constitutes a separate contractual commitment. Unless otherwise stated, rights and obligations under one SOW do not affect rights and obligations under another SOW.
12.7 Acceptance Procedure. Unless the applicable SOW specifies a different procedure, the following acceptance process applies:
- Upon completion of a Deliverable or milestone, CipherCru will notify the Client that the Deliverable is ready for review.
- The Client shall review the Deliverable and either provide written Acceptance, or provide a written list of material defects specifying how the Deliverable fails to conform to the agreed specifications, within the Acceptance Period.
- If the Client fails to respond within the Acceptance Period, the Deliverable shall be deemed accepted (“Deemed Acceptance”), and CipherCru shall be entitled to invoice for the applicable milestone payment.
- Where the Client raises material defects, CipherCru shall address those defects within a reasonable period and resubmit the Deliverable for review. A fresh Acceptance Period shall apply to the resubmitted Deliverable.
- Minor defects, cosmetic issues, or feature enhancements that are beyond the agreed specifications do not constitute grounds for withholding Acceptance. The Client must not withhold Acceptance unreasonably.
- Post-acceptance defects are addressed under the applicable warranty or support arrangement as set out in Section 33 or the applicable SOW.
13. Project initiation
13.1 Kickoff. Following execution of a SOW, CipherCru will schedule a project kickoff meeting with the Client to align on objectives, communication protocols, tooling, access requirements, and the project plan.
13.2 Access and Credentials. The Client must provide CipherCru with timely access to all systems, environments, codebases, credentials, APIs, and other resources necessary for CipherCru to perform the Services. Delays in providing such access may affect project timelines in accordance with Section 15.
13.3 Project Manager. Each party shall designate a primary point of contact for day-to-day project communication. The Client shall ensure that its designated contact has appropriate authority to make decisions within the agreed scope and to provide timely approvals.
13.4 Communication Tools. Unless otherwise agreed, CipherCru will use industry-standard project management and communication tools. The Client agrees to engage through these tools and to respond to communications within a reasonable timeframe.
13.5 Environment Setup. Unless otherwise stated in the SOW, the Client is responsible for provisioning and maintaining production, staging, and testing environments. CipherCru will develop and test in environments reasonably representative of the target production environment, but is not responsible for issues caused by differences between development and production environments that are outside CipherCru's control.
14. Client responsibilities
14.1 General Obligations. The Client's co-operation is essential for CipherCru to deliver Services on time and to the agreed standard. The Client is responsible for:
- designating an accountable project contact with appropriate decision-making authority;
- providing accurate, complete, and timely information, requirements, feedback, and approvals as required by the project plan or requested by CipherCru;
- providing timely access to all systems, infrastructure, credentials, environments, and third-party accounts necessary for the performance of the Services;
- ensuring that all Client Materials supplied to CipherCru are accurate, complete, and licensed for the purpose for which they are supplied;
- conducting user acceptance testing, where applicable, within the agreed timelines;
- making payments in accordance with the payment schedule in the applicable SOW;
- escalating issues or concerns promptly, rather than allowing them to accumulate.
14.2 Client Materials. The Client represents and warrants that it owns or has all necessary rights, licences, consents, and authorisations to provide all Client Materials to CipherCru and to authorise CipherCru to use those Client Materials in the performance of the Services; and that the use of Client Materials by CipherCru in the performance of the Services will not infringe the IP Rights of any third party, violate any Applicable Law, or breach any agreement to which the Client is party.
14.3 Client Indemnity for Materials. The Client shall indemnify, defend, and hold harmless CipherCru and its officers, directors, employees, contractors, and agents from and against any claims, losses, liabilities, damages, costs, and expenses, including legal fees, arising out of or in connection with any claim that Client Materials infringe the IP Rights of a third party; any failure by the Client to obtain required licences, permissions, or consents for Client Materials; and any inaccuracy or defect in Client Materials that causes harm to CipherCru or any third party.
14.4 Responsibility for Decisions. All final decisions regarding business requirements, design, functionality, technology choices, and commercial strategy rest with the Client. CipherCru may provide recommendations and technical guidance, but the Client is solely responsible for decisions made regarding the Project and for the commercial outcomes of the final Deliverable.
15. Project delays
15.1 CipherCru's Obligations. CipherCru will use commercially reasonable efforts to complete Services within the timelines specified in the applicable SOW, and will notify the Client promptly if it becomes aware that a timeline is at risk.
15.2 Client-Caused Delays. If a project delay is caused, contributed to, or arises from the Client's failure to provide timely approvals, decisions, feedback, or sign-offs; the Client's failure to provide required access, credentials, environments, or infrastructure; the Client's failure to supply Client Materials, content, or data in a timely and complete manner; changes requested by the Client to the agreed scope, specifications, or requirements; the Client's delayed or deficient performance of any obligation under the applicable SOW or these Terms; the unavailability or underperformance of third-party systems, services, or vendors under the Client's control or responsibility; or any other act, omission, or event attributable to the Client or to circumstances within the Client's reasonable control, then the following apply:
- Timeline extension. All affected project milestones and delivery dates shall be automatically extended by a period equal to the delay caused by or attributable to the Client, plus any additional time reasonably required by CipherCru to reschedule and re-allocate resources.
- Resource re-allocation. CipherCru reserves the right to re-assign team members allocated to the delayed Project to other client engagements. Upon resumption of the Project, CipherCru will re-assign available resources but cannot guarantee that the same team members will be available.
- Additional costs. Additional costs incurred by CipherCru as a result of Client-caused delays, including re-onboarding costs, resource re-allocation fees, extended infrastructure costs, or overtime, may be charged to the Client and invoiced as an additional Fee, provided CipherCru gives reasonable notice of such costs before incurring them where practicable.
15.3 Notice of Delay. CipherCru will give the Client reasonable written notice of a Client-caused delay and the estimated impact on project timelines. The Client acknowledges that project delays have downstream cost implications and agrees to co-operate to minimise any delays.
15.4 Mutual Delay Avoidance. Both parties shall co-operate in good faith to identify and resolve potential delays as early as possible in the project lifecycle.
16. Change requests
16.1 Right to Request Changes. Either party may request a change to the scope, timeline, budget, or specifications of any Services by submitting a written Change Request.
16.2 Change Request Procedure. Upon receipt of a Change Request, CipherCru will assess the impact of the proposed change on project scope, timeline, cost, and quality, and will provide the Client with a written change impact assessment within a reasonable timeframe. The assessment will include a description of the proposed change; the estimated additional cost, if any; the estimated impact on the project timeline; any dependencies or risks created by the change; and whether the change constitutes a material scope change or a minor modification.
16.3 Approval Required. No Change Request shall be implemented until it has been agreed in writing and signed by authorised representatives of both parties. Work performed in connection with an unapproved Change Request is at CipherCru's discretion and may be invoiced at CipherCru's standard rates.
16.4 Impact on Deliverables. Approved Change Requests may affect the scope, specifications, and acceptance criteria of previously agreed Deliverables. The parties shall agree on revised specifications and Acceptance criteria as part of the Change Request approval process.
16.5 Minor Changes. Where a requested change is minor in nature, meaning it does not materially affect cost, timeline, or architecture, CipherCru may implement it without a formal Change Request. Such changes will be documented in project communications and are subject to these Terms.
16.6 Cumulative Changes. The Client acknowledges that multiple small changes can cumulatively result in a material scope change. CipherCru reserves the right to raise a formal Change Request where cumulative changes would otherwise materially affect project cost or timelines.
17. Third-party services
17.1 Use of Third-Party Services. CipherCru may recommend, integrate, or incorporate Third-Party Services into the Deliverables or in the performance of Services. Such Third-Party Services include cloud platforms, SaaS tools, payment gateways, SMS and email service providers, mapping services, analytics platforms, and AI service providers.
17.2 Third-Party Terms. The use of Third-Party Services is subject to the terms, conditions, privacy policies, and licences of the applicable third-party provider. The Client is responsible for reviewing and accepting the terms of Third-Party Services it uses or into which it is integrated; maintaining valid accounts, licences, and subscriptions with required third-party providers; and ensuring that its use of Third-Party Services complies with applicable third-party terms and Applicable Law.
17.3 No Responsibility for Third-Party Services. CipherCru is not responsible for the availability, performance, security, accuracy, or reliability of any Third-Party Service; any changes, deprecations, API modifications, or discontinuations by third-party providers that affect the Deliverables or Services; any costs arising from the Client's use of Third-Party Services, including subscription fees, usage fees, or overage charges; or any breach, data loss, or security incident caused by a third-party provider.
17.4 Changes by Third-Party Providers. Where a third-party provider modifies, deprecates, or discontinues a service or API that is integrated into a Deliverable, any remediation or re-integration work required shall be treated as a Change Request under Section 16 and may be subject to additional Fees.
17.5 AI Service Providers. CipherCru may use AI Tools provided by third-party AI service providers in the performance of Services. The Client acknowledges that AI Tools and their providers may change their terms of service, capabilities, pricing, or availability at any time without notice to CipherCru; that CipherCru is not responsible for changes to AI Tools or providers that affect Deliverables; that the terms of AI service providers apply to the use of AI-generated outputs, including any restrictions on commercial use, training data obligations, or attribution requirements; and that AI-generated outputs are not guaranteed to be error-free, unique, accurate, or free from third-party IP infringement, as further described in Section 28.
Part IV: Payments
18. Pricing
18.1 Fee Structure. The Fees payable for Services shall be specified in the applicable SOW. CipherCru offers fixed price, being a fixed total Fee for a defined scope of work; time and materials, being fees calculated on the basis of actual hours worked at agreed hourly or daily rates plus reimbursable expenses; monthly retainer, being a recurring monthly Fee for an agreed allocation of resources, where retainer hours not used within a calendar month are forfeited unless the SOW expressly permits rollover; milestone-based, being fees tied to the achievement of defined project milestones; and hybrid, being a combination of the above as agreed in the applicable SOW.
18.2 Fee Revisions. CipherCru reserves the right to revise its standard rates for new SOWs at any time by providing at least thirty (30) days' prior written notice. Fee revisions do not apply to SOWs already executed and in progress, unless the parties agree otherwise in writing.
18.3 Expenses. Unless otherwise stated in the SOW, reasonable and pre-approved out-of-pocket expenses incurred by CipherCru in the performance of the Services, such as travel, accommodation, software licences, and third-party service costs, shall be reimbursed by the Client at cost. CipherCru shall provide supporting documentation for all claimed expenses above a mutually agreed threshold.
18.4 Assumptions. All Fees are based on the assumptions set out in the applicable SOW. If those assumptions prove to be materially incorrect, CipherCru reserves the right to revise the Fees by providing the Client with written notice and a revised cost estimate, to be agreed as a Change Request under Section 16.
19. Taxes
19.1 Goods and Services Tax. All Fees quoted by CipherCru are exclusive of applicable Goods and Services Tax and any other applicable taxes or levies, unless the SOW or invoice expressly states otherwise. GST will be charged in addition to the quoted Fees at the rate applicable at the time of invoicing.
19.2 International Tax. Where Services are provided to Clients outside India, the parties shall co-operate to determine the applicable tax treatment. Any withholding taxes applicable under Indian law or an applicable double-taxation avoidance treaty shall be handled in accordance with Applicable Law. If the Client is required by law to withhold any amount from payments to CipherCru, the Client shall notify CipherCru before deducting such amounts; promptly provide CipherCru with official tax deduction at source certificates or equivalent documentation; and gross up the payment so that CipherCru receives the agreed net amount, unless otherwise agreed in writing.
19.3 Client's Tax Obligations. The Client is solely responsible for all taxes, duties, levies, and governmental charges applicable to its receipt and use of the Services in its own jurisdiction. CipherCru is not responsible for advising the Client on its tax obligations.
19.4 GST Compliance. CipherCru is a GST-registered entity and will issue valid GST invoices for all taxable supplies of Services. The Client must provide its GSTIN where applicable to enable input tax credit.
20. Payment terms
20.1 Payment Schedule. The payment schedule for each Project shall be specified in the applicable SOW. In the absence of a specific payment schedule, the following default terms apply: for fixed-price projects, fifty percent (50%) of the total Fee is payable upon execution of the SOW and the remaining fifty percent (50%) upon delivery and Acceptance of the final Deliverable; for time-and-materials and retainer engagements, Fees are invoiced monthly in arrears and are due within fifteen (15) Business Days of the invoice date; and for milestone-based projects, Fees are invoiced upon achievement of each milestone and are due within fifteen (15) Business Days of the invoice date.
20.2 Invoice Disputes. If the Client disputes any invoice, the Client must notify CipherCru in writing within five (5) Business Days of receiving the invoice, specifying the basis for the dispute. The undisputed portion of the invoice remains due and payable on the original due date. The parties shall work in good faith to resolve any disputed amounts within fifteen (15) Business Days of the dispute notice.
20.3 Payment Method. Unless otherwise agreed, all payments shall be made by bank transfer to the bank account details specified in CipherCru's invoice. CipherCru may also accept payment by other methods, which will be specified on the applicable invoice.
20.4 Advance Payments. Advance payments, retainer payments, and milestone payments made to CipherCru are applied towards the applicable Services as specified in the SOW. Advance payments are not refundable except as expressly provided in Section 23.
20.5 Work in Progress. Work commenced but not yet completed at the time of termination, for any reason, shall be invoiced on a pro-rata basis at the applicable rate, and such amount shall be immediately due and payable.
21. Late payments
21.1 Interest on Overdue Amounts. If the Client fails to pay any undisputed amount by the due date, the outstanding amount shall accrue interest at the rate of eighteen percent (18%) per annum, calculated on a daily basis from the due date until the date of full payment. This right to interest is without prejudice to any other remedies available to CipherCru under these Terms or Applicable Law.
21.2 Collection Costs. The Client shall reimburse CipherCru for all reasonable costs incurred in recovering overdue amounts, including collection agency fees, legal fees, and court costs.
21.3 Allocation of Payments. Where the Client owes multiple outstanding invoices and makes a partial payment, CipherCru reserves the right to allocate that payment against any outstanding invoices in any order CipherCru determines in its sole discretion, notwithstanding any instruction from the Client to the contrary.
21.4 Credit Limit. CipherCru reserves the right to set or revise a credit limit for the Client's account. Invoices in excess of the Client's credit limit may require advance payment before work commences.
22. Suspension
22.1 Right to Suspend. CipherCru reserves the right to suspend the performance of Services, withhold Deliverables, or restrict access to any CipherCru platform or system if any undisputed payment remains overdue for more than fifteen (15) Business Days after the due date; if the Client is in material breach of these Terms or any applicable SOW and has not remedied the breach within the cure period specified in Section 37.2; if CipherCru has reasonable grounds to believe that the Client's use of the Services violates Applicable Law; or if CipherCru is required to suspend Services by order of a court, regulator, or competent authority.
22.2 Notice Before Suspension. Before exercising its right to suspend for non-payment or unremedied breach, CipherCru will provide the Client with at least five (5) Business Days' prior written notice of its intention to suspend, specifying the reason for suspension and the action required to avoid it.
22.3 Effect of Suspension. During any period of suspension, project timelines shall be paused and extended accordingly; CipherCru's obligations under the applicable SOW are suspended; the Client remains liable for all Fees accrued up to the date of suspension and interest on overdue amounts continues to accrue; and CipherCru is not liable for any loss or damage arising from the suspension.
22.4 Resumption. Upon the Client rectifying the reason for suspension, including paying all overdue amounts and applicable interest, CipherCru will use commercially reasonable efforts to resume Services. The timeline for resumption will depend on the availability of CipherCru's resources, and the Client acknowledges that CipherCru may have assigned resources to other engagements during the suspension period.
23. Refund policy
23.1 General Policy. Subject to Sections 23.2 and 23.3, Fees paid to CipherCru for Services are generally non-refundable, given the custom nature of the work and the allocation of dedicated resources.
23.2 Refunds for Breach by CipherCru. CipherCru may, at its discretion, provide a partial or full refund where CipherCru materially fails to perform agreed Services and that failure is directly attributable to CipherCru, and not to Client-caused delays, Client Material deficiencies, or factors outside CipherCru's control; or where a court or arbitral tribunal has found CipherCru liable to refund amounts to the Client.
23.3 Advance Payments. Advance payments may be partially refundable where a project is terminated by the Client for CipherCru's material breach, subject to deduction of all Fees for Services performed up to the date of termination; all non-recoverable costs, expenses, or commitments incurred by CipherCru in connection with the Project; and any resource reservation or mobilisation costs incurred by CipherCru.
23.4 No Refund for Completed Deliverables. No refund is available for any Deliverable that has been accepted, or deemed accepted under Section 12.7, by the Client.
23.5 Subscription and SaaS Products. Where CipherCru provides access to a SaaS product developed for multiple users rather than exclusively for the Client, refunds for subscription Fees shall be governed by the applicable product-specific terms and the Refund and Cancellation Policy incorporated by reference in Section 1.3. To the extent of any conflict, the product-specific terms shall prevail.
23.6 Refund Process. All refund requests must be made in writing to CipherCru at the contact details in Section 45, setting out the grounds for the refund. CipherCru will review all refund requests and respond within twenty (20) Business Days.
Part V: Intellectual property
24. Ownership
24.1 Ownership of Deliverables. Subject to full payment of all Fees and compliance with these Terms, CipherCru assigns to the Client all IP Rights in the custom Deliverables specifically created for the Client under a SOW, to the extent that such Deliverables do not incorporate CipherCru's Pre-existing IP; Internal Frameworks; Open Source Software; third-party IP or licences; or AI-Generated Content.
24.2 Assignment Upon Payment. The assignment described in Section 24.1 is conditional on the Client having paid all Fees in full and having no outstanding overdue amounts. Until such payment is made in full, CipherCru retains all IP Rights in the Deliverables and grants the Client no licence to use them beyond what is strictly necessary for review and acceptance purposes.
24.3 CipherCru's Retained Rights. Notwithstanding Section 24.1, CipherCru retains all IP Rights in Pre-existing IP; Internal Frameworks; know-how, methodologies, processes, and techniques developed or refined in the course of providing the Services; tools, utilities, and supporting software used in the delivery of Services but not forming part of the specific Deliverables; and AI Tools, AI agents, workflow automations, and prompt libraries.
24.4 Licence for Retained Rights. To the extent that any Deliverable incorporates CipherCru's retained IP described in Section 24.3, CipherCru grants the Client a non-exclusive, non-transferable, perpetual, royalty-free licence to use that retained IP solely as embedded in and for the purpose of operating the specific Deliverable, within the field of use for which the Deliverable was created.
24.5 No Broader Licence. Nothing in these Terms grants the Client any right to extract, copy, or use CipherCru's retained IP independently of the Deliverable; to sublicence, sell, or otherwise transfer CipherCru's retained IP to any third party; or to use CipherCru's retained IP in any project or engagement other than the specific Project for which the Deliverable was created.
25. Source code
25.1 Source Code Delivery. CipherCru will deliver source code for custom Deliverables as specified in the applicable SOW. Where the SOW does not address source code delivery, CipherCru's default practice is to deliver compiled or deployable builds unless source code delivery is explicitly requested and agreed upon.
25.2 Source Code Ownership. Subject to Section 24, the Client owns the source code for custom Deliverables created specifically for the Client under a SOW, upon full payment of all Fees.
25.3 Source Code Escrow. Where the Client requires source code escrow arrangements, such arrangements must be specified in the SOW and may be subject to additional costs.
25.4 Internal Framework Code. Source code that forms part of CipherCru's Internal Frameworks is not included in any source code delivery to the Client, regardless of whether such code is embedded or referenced in the Deliverable. The Client receives a licence to use such code as embedded in the Deliverable, in accordance with Section 24.4.
25.5 Third-Party Code. Source code of Third-Party Services, Open Source Software, or any other third-party components integrated into Deliverables is governed by the applicable third-party or open-source licence and is not subject to assignment under Section 24.1.
26. Pre-existing IP
26.1 Client Pre-existing IP. The Client retains all IP Rights in its Pre-existing IP, including Client Materials. Nothing in these Terms transfers Client Pre-existing IP to CipherCru. The Client grants CipherCru a non-exclusive, royalty-free licence to use Client Pre-existing IP solely to the extent necessary to perform the Services.
26.2 CipherCru Pre-existing IP. CipherCru retains all IP Rights in its Pre-existing IP. Nothing in these Terms transfers CipherCru Pre-existing IP to the Client. Where CipherCru Pre-existing IP is incorporated into a Deliverable, the Client receives only the licence described in Section 24.4.
26.3 Internal Frameworks. CipherCru's Internal Frameworks are CipherCru's proprietary Pre-existing IP and constitute valuable trade secrets and commercially sensitive assets. Internal Frameworks are the exclusive property of CipherCru, whether created before or during any engagement; are not assigned to the Client under Section 24.1, irrespective of whether they are incorporated into a Deliverable; may not be accessed, copied, extracted, reverse-engineered or modified by the Client; may be reused by CipherCru across multiple client engagements; and their use in a Deliverable is acknowledged by the Client as a feature of CipherCru's service delivery model that enables superior quality and efficiency.
26.4 AI Agents and Prompts. Unless explicitly transferred in writing in the applicable SOW, all AI agents, multi-agent systems, and AI orchestration pipelines developed by CipherCru remain CipherCru's property; all prompts, system prompts, meta-prompts, workflow prompts, and prompt libraries developed by CipherCru in connection with the Services, including prompts used to generate code, documentation, or other outputs, remain CipherCru's property; prompt engineering methodologies and AI workflow architectures developed by CipherCru are CipherCru's proprietary know-how and are not disclosed to or assigned to the Client; and where specific AI agents or prompts are to be transferred to the Client as part of a Deliverable, this shall be expressly documented in the SOW and may be subject to additional Fees.
27. Open source software
27.1 Use of Open Source. CipherCru may use Open Source Software in the performance of Services and in Deliverables. The use of Open Source Software is subject to the terms of the applicable open-source licence.
27.2 Permissive Licences. Open Source Software licensed under permissive licences, including Apache 2.0, MIT, and BSD, may be incorporated into Deliverables without restriction, subject to compliance with the applicable licence terms including attribution requirements.
27.3 Copyleft Licences: GPL and AGPL. Open Source Software licensed under strong copyleft licences, including the GNU General Public Licence v2 or v3 and the GNU Affero General Public Licence, carries obligations that may require derivative works to be distributed under the same licence. CipherCru will disclose to the Client where GPL or AGPL-licensed software is incorporated into a Deliverable; assess and communicate to the Client the implications of such incorporation for the Client's intended use of the Deliverable; and endeavour to avoid incorporating GPL or AGPL-licensed software in ways that would impose licensing obligations on the Client's proprietary code, unless the Client has been informed and has given written consent.
27.4 LGPL and MPL. Open Source Software licensed under the GNU Lesser General Public Licence or Mozilla Public Licence may generally be used as a library alongside proprietary code without triggering copyleft obligations on the proprietary code, subject to compliance with the applicable licence terms.
27.5 Open Source Disclosure. Upon request, CipherCru will provide the Client with a list of Open Source Software incorporated into any Deliverable, along with the applicable licence for each component.
27.6 Client's Responsibility. The Client is responsible for ongoing compliance with Open Source Software licence terms applicable to any Deliverable after delivery, including maintaining required attribution notices and complying with distribution obligations where applicable. CipherCru's responsibility for open-source licence compliance is limited to the period of active development under the applicable SOW.
28. AI-generated content
28.1 Use of AI Tools. CipherCru may use AI Tools in the performance of Services. By engaging CipherCru for Services, the Client acknowledges and accepts that AI Tools may be used unless the applicable SOW expressly prohibits their use.
28.2 Nature of AI Output. The Client acknowledges and accepts that:
- Accuracy. AI-generated outputs may contain errors, hallucinations, inaccuracies, or misleading information. CipherCru applies human review to AI-generated outputs but does not guarantee that all errors will be identified or corrected.
- Uniqueness. AI-generated outputs may not be unique and may be substantially similar to content generated for other users of the same AI Tool. CipherCru makes no warranty that AI-generated content is unique or exclusive to the Client.
- IP infringement. AI-generated outputs may incorporate, resemble, or reproduce third-party intellectual property, including copyright-protected works used in training data. CipherCru is not responsible for third-party IP claims arising from AI-generated content incorporated into Deliverables, and recommends that Clients conduct independent IP clearance review where AI-generated content is commercially sensitive.
- Human verification. Human verification and professional review of AI-generated outputs is strongly recommended before reliance upon or commercial deployment of such outputs.
- Provider changes. AI Tool providers may modify, restrict, deprecate, or discontinue their services at any time. Changes to AI Tools may affect CipherCru's ability to reproduce or maintain Deliverables that rely on those tools. Such changes do not constitute a breach by CipherCru.
- Regulatory uncertainty. The legal and regulatory framework governing AI-generated content is evolving. Clients are responsible for ensuring that their use of AI-generated Deliverables complies with Applicable Law in each jurisdiction where they are deployed.
28.3 No AI Output Warranty. CipherCru makes no warranty, express or implied, that any AI-generated content is accurate, fit for purpose, legally compliant, original, or free from third-party claims.
28.4 AI Prompts and Agents as CipherCru IP. All prompts, system prompts, AI agent architectures, workflow configurations, and prompt libraries used by CipherCru in generating AI outputs are CipherCru's Intellectual Property, as set out in Section 26.4. The Client has no right to access or reproduce such prompts or agents unless explicitly transferred in the applicable SOW.
28.5 Client Use of AI. Where the Client requests that AI-generated content be embedded in a Deliverable or integrated into a Client system, the Client acknowledges the limitations set out in Section 28.2; accepts responsibility for ensuring the AI-generated content is appropriate for the Client's intended use; and indemnifies CipherCru against claims arising from the Client's deployment or use of AI-generated content, except to the extent caused by CipherCru's negligence.
29. Portfolio rights
29.1 Right to Reference. Unless prohibited by a separately executed NDA or by a specific written restriction in the applicable SOW, CipherCru reserves the right to identify the Client by name and display the Client's logo in CipherCru's marketing materials, website, pitch decks, and case studies; to describe the nature of Services provided to the Client, without disclosing Confidential Information, in promotional materials; to display screenshots, mockups, or visual representations of completed Deliverables in CipherCru's portfolio; and to reference the Client engagement in proposals submitted to prospective clients.
29.2 Accuracy and Confidentiality. CipherCru will ensure that all portfolio references are accurate and not misleading; will not disclose the Client's Confidential Information in any portfolio reference; and will not disclose commercially sensitive metrics, performance data, or financial information in portfolio references without the Client's written consent.
29.3 Client Objection. If the Client objects to a specific portfolio reference, the Client shall notify CipherCru in writing. CipherCru will, within a reasonable period, remove or modify the objectionable reference, provided that the Client's objection is based on legitimate grounds, including a reasonable concern about confidentiality or reputational harm.
29.4 NDA Override. Where the parties have executed a Mutual NDA, the NDA's provisions on confidentiality shall govern the extent to which portfolio references are permitted. CipherCru will not make any reference to an NDA-protected engagement that would breach the applicable NDA.
Part VI: Confidentiality
30. Confidential information
30.1 Definition. For the purposes of these Terms, “Confidential Information” means any information, data, know-how, or materials disclosed by one party (the “Disclosing Party”) to the other party (the “Receiving Party”) in connection with the Services, whether disclosed orally, in writing, electronically, visually, or by any other means, and which is designated as confidential or proprietary at the time of disclosure; would reasonably be understood as confidential given the nature of the information and the circumstances of disclosure; or falls within the following non-exhaustive categories, which are automatically deemed Confidential Information:
- business plans, strategies, forecasts, and financial data;
- Client or prospect lists, customer data, and marketing plans;
- source code, technical specifications, software designs, and system architectures;
- CipherCru's Internal Frameworks, methodologies, pricing models, and trade secrets;
- project requirements, SOWs, and MSAs;
- Personal Data of any natural person;
- information received from third parties that a party is obligated to treat as confidential.
30.2 Exclusions. Confidential Information does not include information that is or becomes publicly available through no fault of the Receiving Party; was already known to the Receiving Party, without restriction, at the time of disclosure, as evidenced by written records predating the disclosure; is independently developed by the Receiving Party without reference to or use of the Disclosing Party's Confidential Information; or is rightfully received by the Receiving Party from a third party who is not under any obligation of confidentiality with respect to that information.
31. Non-disclosure
31.1 Obligation of Confidentiality. The Receiving Party shall hold the Disclosing Party's Confidential Information in strict confidence; not disclose Confidential Information to any third party without the prior written consent of the Disclosing Party; use Confidential Information only for the purpose of performing or receiving the Services; and protect Confidential Information using at least the same degree of care it applies to its own confidential information of a similar nature, and in any event no less than reasonable care.
31.2 Permitted Disclosures. The Receiving Party may disclose Confidential Information to its employees, directors, officers, contractors, and professional advisors who need to know the information for the purpose of the Services, provided that such persons are bound by confidentiality obligations no less protective than those in these Terms; and to a court, tribunal, regulator, or other competent authority, to the extent required by Applicable Law, provided that the Receiving Party gives the Disclosing Party prior written notice where permitted by law, co-operates with any reasonable request by the Disclosing Party to seek a protective order, and discloses only as much information as is strictly required.
31.3 Duration. Obligations of confidentiality under this Section 31 shall survive the termination or expiry of these Terms for a period of five (5) years. Obligations with respect to trade secrets shall survive indefinitely.
31.4 Return or Destruction. Upon the request of the Disclosing Party or upon termination of the engagement, the Receiving Party shall promptly return or securely destroy all Confidential Information in its possession or control, and shall certify such destruction in writing upon request. CipherCru may retain archival copies of Confidential Information as required by Applicable Law or for legitimate backup and compliance purposes.
31.5 Injunctive Relief. The Receiving Party acknowledges that any breach of this Section 31 would cause irreparable harm to the Disclosing Party for which monetary damages would be an inadequate remedy. Accordingly, the Disclosing Party is entitled to seek injunctive or other equitable relief in addition to any other remedies available at law or in equity.
31.6 Non-Solicitation. The Client agrees that during the term of any engagement with CipherCru, and for a period of twelve (12) months following the completion or termination of any Project, the Client shall not directly or indirectly solicit, recruit, hire, or engage any employee, contractor, consultant, or freelancer of CipherCru who was involved in the performance of Services for the Client; or encourage or assist any such person to terminate their relationship with CipherCru. In the event of a breach of this provision, the Client shall pay CipherCru a sum equal to twelve (12) months of the relevant individual's annual compensation as liquidated damages, which the parties agree represents a genuine pre-estimate of CipherCru's loss. This provision is in addition to and does not limit any other remedy available to CipherCru.
32. Data protection
32.1 Compliance. Each party shall comply with all Applicable Laws relating to the processing of Personal Data, including the DPDP Act and, where applicable to the Client's data subjects, the GDPR and the CCPA.
32.2 CipherCru as Data Processor. Where CipherCru processes Personal Data on behalf of the Client in the course of providing Services, CipherCru acts as a data processor. In such cases the Client is the data principal or controller, and is responsible for ensuring it has a lawful basis for processing Personal Data and for providing appropriate notices to data subjects; the parties shall execute a Data Processing Agreement that governs the processing of Personal Data by CipherCru on the Client's behalf, incorporating the requirements of the DPDP Act and, where applicable, the GDPR; and the absence of an executed DPA does not relieve either party of its obligations under Applicable Law.
32.3 CipherCru as Data Controller. Where CipherCru processes Personal Data in its own capacity, for example personal data of the Client's employees, representatives, or contacts collected for account management, billing, or communication purposes, CipherCru acts as a data controller and processes such data in accordance with its Privacy Policy.
32.4 Data Security. CipherCru implements reasonable technical and organisational security measures to protect Personal Data processed in connection with the Services. However, no security measure is infallible. The Client is responsible for implementing adequate security measures within its own systems and environments.
32.5 Data Incidents. If CipherCru becomes aware of a personal data breach affecting Client Personal Data that CipherCru processes as a data processor, CipherCru will notify the Client without undue delay and will co-operate with the Client in investigating and remediating the breach, in accordance with the applicable DPA.
32.6 International Data Transfers. Where Personal Data is transferred across national borders, the parties shall implement appropriate safeguards as required by Applicable Law, including where applicable standard contractual clauses or other transfer mechanisms recognised under the GDPR.
Part VII: Warranties
33. Limited warranty
33.1 Warranty Period. CipherCru warrants that Deliverables will materially conform to the specifications set out in the applicable SOW for a period of thirty (30) calendar days from the date of Acceptance or Deemed Acceptance (the “Warranty Period”), unless a different Warranty Period is specified in the applicable SOW.
33.2 Warranty Remedy. During the Warranty Period, if the Client notifies CipherCru in writing of a material defect that causes a Deliverable to fail to conform to the applicable SOW specifications, CipherCru shall, at its sole discretion, repair or rectify the defect within a reasonable period at no additional charge, or re-perform the affected portion of the Services. This is CipherCru's sole liability and the Client's exclusive remedy for warranty claims.
33.3 Warranty Exclusions. The warranty in Section 33.1 does not apply to defects or failures caused by modifications or alterations to the Deliverable made by the Client or any third party without CipherCru's prior written consent; the Client's failure to comply with CipherCru's instructions, documentation, or recommended configuration; hardware failures, network issues, third-party software defects, or cloud infrastructure failures outside CipherCru's control; Client Materials that are inaccurate, defective, or incompatible; changes to Third-Party Services, APIs, or platforms that affect the Deliverable; the Client's use of the Deliverable in a manner inconsistent with its intended purpose or the applicable SOW; or force majeure events.
33.4 Post-Warranty Support. After the expiry of the Warranty Period, ongoing support and maintenance is available under CipherCru's Support and SLA Policy or a separate maintenance SOW, and may be subject to additional Fees.
34. Disclaimer
34.1 Exclusion of Implied Warranties. To the fullest extent permitted by Applicable Law, CipherCru expressly disclaims all implied warranties, representations, and conditions, including implied warranties of merchantability; of fitness for a particular purpose; of title or non-infringement; and that the Services or Deliverables will be error-free, uninterrupted, secure, or free from vulnerabilities.
34.2 Website Disclaimer. The Website and its content are provided “as is” and “as available” without warranty of any kind. CipherCru does not warrant that the Website will be available, accurate, free from errors, or free from malware or other harmful components.
34.3 AI Disclaimer. Without limiting Section 28, CipherCru expressly disclaims all warranties in respect of AI-Generated Content, including any warranty of accuracy, fitness for purpose, originality, or freedom from third-party IP claims.
34.4 Cybersecurity Disclaimer. CipherCru is not liable for any security breaches, data loss, unauthorised access, or cyberattacks arising from:
- the Client's use of weak, shared, or compromised passwords or credentials;
- vulnerabilities in third-party hosting, cloud platforms, or infrastructure;
- vulnerabilities in third-party plugins, modules, or integrations not developed by CipherCru;
- malware, ransomware, phishing, social engineering, or other attacks directed at the Client's own systems;
- outdated software, operating systems, or libraries on Client infrastructure;
- the Client's failure to apply security patches, updates, or configuration best practices;
- incidents in cloud vendor environments or other infrastructure environments outside CipherCru's direct control;
- compromised third-party services integrated into the Deliverable where the compromise originates from the third-party service itself;
- any other security incident arising from infrastructure, environments, or systems not developed, maintained, or operated by CipherCru.
CipherCru recommends that all Clients engage qualified cybersecurity professionals to conduct independent security assessments of any Deliverable prior to production deployment.
35. Limitation of liability
35.1 Aggregate Cap. To the fullest extent permitted by Applicable Law, CipherCru's total aggregate liability to the Client under or in connection with these Terms, any SOW, or any MSA, whether in contract, tort, negligence, breach of statutory duty, or otherwise, shall not exceed the total Fees actually paid by the Client to CipherCru under the specific SOW or Project to which the claim relates in the twelve (12) months immediately preceding the event giving rise to the claim.
35.2 Exclusion of Consequential Loss. To the fullest extent permitted by Applicable Law, CipherCru shall not be liable to the Client for any indirect or consequential loss or damage; loss of profits, revenue, or business; loss of anticipated savings or wasted expenditure; loss of goodwill or reputation; loss of contracts or business opportunity; loss of data or data corruption, except where directly and solely caused by CipherCru's gross negligence; punitive or exemplary damages; incidental damages; business interruption losses; or any other special or indirect damages, in each case whether or not CipherCru has been advised of the possibility of such loss or damage and regardless of the theory of liability.
35.3 Essential Basis. The Client acknowledges that the limitations of liability in this Section 35 form an essential element of the bargain between the parties and reflect a fair allocation of risk, without which CipherCru would not be in a position to provide the Services at the agreed Fees.
35.4 Exceptions. Nothing in these Terms limits or excludes CipherCru's liability for death or personal injury caused by CipherCru's negligence; fraud or fraudulent misrepresentation; or any other liability that cannot be limited or excluded under Applicable Law.
36. Indemnification
36.1 Client Indemnity. The Client shall indemnify, defend, and hold harmless CipherCru and its directors, officers, employees, contractors, affiliates, and agents (collectively, the “CipherCru Indemnitees”) from and against any and all claims, actions, proceedings, losses, liabilities, damages, costs, and expenses, including reasonable legal fees, arising out of or in connection with the Client's breach of these Terms, any SOW, or any MSA; the Client's breach of any representation or warranty given in these Terms; any claim by a third party arising from Client Materials, including any allegation of IP infringement or data protection violation; any claim arising from the Client's use or misuse of any Deliverable; the Client's violation of any Applicable Law; the Client's use of AI-generated content in its products, services, or communications, as further described in Section 28.5; and any claim arising from the Client's non-compliance with third-party licences, including Open Source Software licences, applicable to components integrated at the Client's request.
36.2 CipherCru's Indemnity. CipherCru shall indemnify, defend, and hold harmless the Client from and against any third-party claims alleging that a custom Deliverable, excluding Client Materials, AI-Generated Content, Open Source Software, Third-Party Services, and Internal Frameworks incorporated with the Client's knowledge and consent, infringes the IP Rights of a third party, provided that the Client gives CipherCru prompt written notice of the claim; the Client grants CipherCru sole control of the defence and settlement of the claim; and the Client provides CipherCru with all reasonable co-operation and assistance. This indemnity does not apply where the infringement arises from modifications made by the Client or a third party; combination of the Deliverable with software, hardware, or materials not provided by CipherCru; use of the Deliverable in a manner not contemplated by the SOW; or the Client's failure to apply updates or corrections provided by CipherCru.
36.3 Indemnity Procedure. The indemnified party shall promptly notify the indemnifying party in writing of any claim subject to indemnification; not make any admission, settlement, or compromise without the indemnifying party's prior written consent; and co-operate fully with the indemnifying party in the defence or settlement of the claim.
Part VIII: Termination
37. Termination
37.1 Termination for Convenience. Unless otherwise specified in an applicable SOW or MSA, either party may terminate an engagement, at the SOW level or, if no SOW exists, at the level of these Terms as applied to any ongoing relationship, by providing thirty (30) calendar days' prior written notice to the other party. For clarity, termination of a specific SOW does not terminate other active SOWs or these Terms as a whole.
37.2 Termination for Breach. Either party may terminate an applicable SOW or the engagement governed by these Terms immediately by written notice if the other party commits a material breach of these Terms, the applicable SOW, or any MSA, and fails to remedy the breach within fifteen (15) Business Days of receiving written notice specifying the breach and requiring its remedy; or commits a breach that is not capable of remedy.
37.3 Termination for Insolvency. Either party may terminate immediately by written notice if the other party becomes insolvent, ceases or threatens to cease to carry on business; enters into any arrangement or composition with its creditors or has a liquidator, receiver, administrator, or similar officer appointed over any of its assets; or is subject to any voluntary or compulsory insolvency proceeding under the Insolvency and Bankruptcy Code 2016 or any other applicable insolvency law.
37.4 Immediate Termination by CipherCru. CipherCru may terminate immediately by written notice if any Fees remain unpaid for more than thirty (30) calendar days after the due date and the Client fails to make payment within five (5) Business Days of a written demand; if the Client engages in conduct that CipherCru reasonably believes is fraudulent, illegal, or likely to cause harm to CipherCru or third parties; or if the Client violates Section 9.
37.5 Effect on Other SOWs. Termination of one SOW does not, unless expressly stated, affect other active SOWs or the ongoing relationship governed by these Terms.
38. Effect of termination
38.1 Fees on Termination. Upon termination of any SOW or engagement for any reason, all Fees for Services performed up to the effective date of termination are immediately due and payable, whether or not the relevant Deliverables are complete; where a fixed-price project is terminated before completion, the Client shall pay CipherCru on a pro-rata basis for all work performed up to the date of termination, calculated by reference to the agreed milestones or, where milestones have not been reached, a fair valuation of work in progress; and all non-recoverable costs and expenses committed by CipherCru in connection with the Project, including resource reservation, software licences, and third-party commitments, are immediately due and payable.
38.2 Return of Materials. Within fifteen (15) Business Days of termination, CipherCru shall return or securely destroy all Client Materials and Client Confidential Information in its possession, retaining only archival copies as required by Applicable Law or for legitimate backup purposes; and the Client shall return or destroy all CipherCru Confidential Information and any CipherCru materials provided for the Project, and shall certify such return or destruction upon request.
38.3 Deliverables at Termination. Where termination is by the Client for CipherCru's material breach, CipherCru shall deliver to the Client, upon full payment of all outstanding amounts, all Deliverables completed up to the date of termination, together with associated source code where applicable. Where termination is by CipherCru for the Client's breach or non-payment, CipherCru may withhold delivery of incomplete Deliverables and source code until all outstanding Fees, interest, and costs are paid in full. Incomplete Deliverables are delivered as-is and CipherCru makes no warranty in respect of incomplete work.
38.4 Licence Termination. Upon termination, any licence granted to the Client under Section 24.4 that relates to an incomplete Project terminates, unless and until all outstanding Fees are paid in full; and any licence granted to CipherCru to use Client Pre-existing IP in connection with the terminated Project terminates.
38.5 Survival. The following provisions survive termination or expiry of these Terms, and any applicable SOW, for any reason: Sections 2 (Definitions), 19 (Taxes), 21 (Late Payments), 24 to 29 (Intellectual Property), 30 to 31 (Confidentiality), 34 (Disclaimer), 35 (Limitation of Liability), 36 (Indemnification), 38 (Effect of Termination), 39 (Governing Law), 40 (Arbitration), 42 (Severability), and 44 (Entire Agreement).
Part IX: Legal
39. Governing law
39.1 Governing Law. These Terms, all SOWs, and all MSAs executed hereunder shall be governed by and construed in accordance with the laws of the Republic of India, including the Indian Contract Act 1872, the Information Technology Act 2000, and the Arbitration and Conciliation Act 1996, without regard to conflict of law principles.
39.2 Jurisdiction. Subject to the arbitration clause in Section 40, the courts of Jaipur, Rajasthan, India shall have exclusive jurisdiction over any matter arising out of or in connection with these Terms that is not subject to arbitration.
39.3 International Clients. Where the Client is located outside India, these Terms and any engagement entered into pursuant to these Terms shall nonetheless be governed by Indian law. International Clients agree to submit to the exclusive jurisdiction of the courts and arbitral tribunals seated in Jaipur, Rajasthan, India.
40. Arbitration
40.1 Mandatory Arbitration. Subject to Section 40.5, any dispute, controversy, or claim arising out of or in connection with these Terms, any SOW, or any MSA, including any question regarding their existence, validity, breach, or termination, shall be finally resolved by arbitration under the Arbitration and Conciliation Act 1996, as amended by the Arbitration and Conciliation (Amendment) Acts of 2015 and 2019.
40.2 Arbitral Tribunal. The arbitration shall be conducted by a sole arbitrator, agreed upon by the parties within fifteen (15) days of the arbitration notice. If the parties fail to agree on a sole arbitrator within that period, the arbitrator shall be appointed in accordance with the Arbitration and Conciliation Act 1996 upon the application of either party.
40.3 Seat and Venue. The seat of arbitration shall be Jaipur, Rajasthan, India. The arbitral proceedings shall be conducted in the English language.
40.4 Award. The arbitral award shall be final and binding on both parties, and either party may apply to a court of competent jurisdiction to enforce the award. Each party shall bear its own costs of arbitration unless the arbitral tribunal orders otherwise.
40.5 Exceptions. Notwithstanding Section 40.1, either party may seek urgent interlocutory or injunctive relief from any court of competent jurisdiction without first resorting to arbitration, where such relief is necessary to prevent irreparable harm, including for breach of confidentiality or IP obligations under these Terms.
40.6 Confidentiality of Arbitration. The existence, content, and outcome of any arbitral proceedings under these Terms are confidential. Neither party shall disclose information relating to the arbitration to any third party without the other party's consent, except to the extent required by Applicable Law or to enforce an arbitral award.
41. Force majeure
41.1 Definition. A “Force Majeure Event” means any event beyond a party's reasonable control, including acts of God; pandemic or epidemic; earthquake, flood, storm, or other natural disaster; fire or explosion; war, armed conflict, terrorism, or civil unrest; government action, legislation, or regulation; strikes, lockouts, or industrial disputes other than involving the party's own workforce; power outages; internet or telecommunications failures outside the party's control; and actions or failures of third-party service providers, including AI service providers, cloud infrastructure providers, or payment processors.
41.2 Effect. Neither party shall be liable to the other for any delay or failure to perform its obligations under these Terms or any SOW to the extent that such delay or failure is caused by a Force Majeure Event, provided that the affected party gives prompt written notice to the other party as soon as reasonably practicable after the occurrence of the Force Majeure Event, specifying the nature and expected duration of the event; and the affected party uses reasonable endeavours to mitigate the effects of the Force Majeure Event and to resume performance as soon as reasonably practicable.
41.3 Payment Obligations. A Force Majeure Event does not affect the Client's obligation to pay Fees that have already been earned and invoiced by CipherCru.
41.4 Extended Force Majeure. If a Force Majeure Event continues for more than sixty (60) calendar days, either party may terminate the affected SOW by providing fifteen (15) calendar days' written notice. In such event, CipherCru shall be entitled to payment for all Services performed up to the date of termination.
42. Severability
42.1 Severability. If any provision of these Terms is found by a court or arbitral tribunal of competent jurisdiction to be invalid, unlawful, void, or unenforceable in any jurisdiction, that provision shall be modified to the minimum extent necessary to make it valid and enforceable, or, if modification is not possible, severed from these Terms.
42.2 Remaining Provisions. The invalidity or unenforceability of any provision shall not affect the validity or enforceability of the remaining provisions of these Terms, which shall continue in full force and effect.
42.3 Liability Cap Severability. Without limiting the generality of this Section, if Section 35 is found unenforceable in any respect, that finding shall not affect the enforceability of the remainder of Section 35, and the parties shall negotiate in good faith to agree on a substitute limitation that achieves the same commercial intent to the greatest extent permissible under Applicable Law.
43. Assignment
43.1 Assignment by Client. The Client may not assign, transfer, novate, sub-licence, or otherwise deal with any of its rights or obligations under these Terms, any SOW, or any MSA without the prior written consent of CipherCru, which shall not be unreasonably withheld.
43.2 Assignment by CipherCru. CipherCru may, without the Client's consent, assign or transfer any of its rights or obligations under these Terms to any affiliate or related entity of CipherCru; or assign these Terms in connection with a sale, merger, acquisition, or reorganisation of CipherCru or a substantial part of its business, provided that the assignee assumes all obligations of CipherCru under these Terms. CipherCru shall provide the Client with written notice of any such assignment.
43.3 Binding Effect. These Terms are binding upon and inure to the benefit of the parties and their respective permitted successors and assigns.
44. Entire agreement
44.1 Entire Agreement. These Terms, together with all executed SOWs, MSAs, the Privacy Policy, the Cookie Policy, the DPA, the Support and SLA Policy, the Acceptable Use Policy, and the Refund and Cancellation Policy incorporated by reference, constitute the entire agreement between the parties with respect to the subject matter hereof and supersede all prior negotiations, representations, warranties, understandings, and agreements, whether oral or written, between the parties relating to that subject matter.
44.2 No Oral Modifications. No modification, amendment, or waiver of any provision of these Terms shall be valid or binding unless made in writing and signed by authorised representatives of both parties.
44.3 Waiver. No failure or delay by either party in exercising any right, power, or remedy under these Terms shall operate as a waiver thereof. No single or partial exercise of any right, power, or remedy shall prevent further exercise of that or any other right, power, or remedy.
44.4 Relationship of Parties. The parties are independent contractors. Nothing in these Terms creates any employment, partnership, joint venture, agency, or franchise relationship between the parties. Neither party has authority to bind the other in any manner.
44.5 Headings. Section headings in these Terms are for convenience only and do not affect the interpretation of these Terms.
44.6 Counterparts and Electronic Signatures. These Terms and any SOW or MSA may be executed in counterparts and may be signed electronically, including by way of a PDF signature or equivalent electronic signature tool, each of which shall be deemed an original and together shall constitute one and the same document. Electronic signatures are legally valid under the Information Technology Act 2000.
44.7 Export Controls. The Client represents and warrants that it will not use, export, re-export, transfer, or transmit any Deliverable, technology, software, or documentation provided by CipherCru in violation of any applicable export control laws, economic sanctions, or trade restrictions, including laws administered by the Government of India, the United States Bureau of Industry and Security, OFAC, or the European Union. The Client is solely responsible for compliance with all export regulations applicable in its jurisdiction.
44.8 Language. These Terms are drafted in the English language. If these Terms are translated into any other language, the English version shall prevail in the event of any inconsistency.
45. Contact information
45.1 CipherCru Contact Details. For all notices, enquiries, and communications under these Terms, including legal notices, dispute notices, termination notices, and refund requests, please contact CipherCru at:
- Entity
- CipherCru Innovations Private Limited
- Registered office
- 602, The Elysian, A-31, Swej Farm Circle, Swej Farm, New Sanganer Road, Sodala, Jaipur, Rajasthan 302019, India
- legal@ciphercru.com
- Website
- https://www.ciphercru.com
45.2 Legal Notices. All formal legal notices under these Terms must be provided in writing and delivered to the contact address above by hand delivery, effective upon delivery; by registered post or courier with proof of delivery, effective upon receipt; or by email to the email address above, effective upon receipt of a read or delivery receipt, or twenty-four (24) hours after sending if no receipt is received and no bounce notification is received.
45.3 Client Notices. Notices to the Client shall be sent to the email address or postal address provided by the Client during registration, onboarding, or as updated in writing. The Client is responsible for keeping its contact information current.
45.4 Grievance Officer. In accordance with the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021, complaints and grievances may be submitted to CipherCru's Grievance Officer at privacy@ciphercru.com. Complaints will be acknowledged within forty-eight (48) hours and addressed within fifteen (15) days of receipt.