Signet Cloud
Terms of Service
The agreement between you and us for the hosted Signet service. Written to be read, not to be survived.
1. Who you are contracting with
Signet Cloud is operated by GeldenTech Inc., a federal corporation under the Canada Business Corporations Act, with its registered office in Montreal, Quebec, Canada. In these terms, "we" and "us" mean GeldenTech Inc., and "you" means the person or organisation that opens an account.
2. What we provide
We give you access to a hosted Signet instance that we operate for you. We are not licensing you a copy of the software. Nothing in these terms lets you copy, redistribute, resell, or reverse engineer the service, except where the law says otherwise and cannot be contracted away.
3. Your data
Your users, sessions, and secrets live in a PostgreSQL database dedicated to you. Nobody else's data shares it. We acquire no right, title, or interest in what you put there, and we do not use it for anything except running the service for you.
Here is exactly what we store. We never store a password in plain text: a password reaches us once, to be set or checked, and what we keep is a salted hash that cannot be turned back into the password, not by us, not by anyone. Session tokens and second-factor secrets are stored, because the service cannot run without them, and they live in your dedicated database like everything else. Card numbers never touch us at all; Stripe handles those (section 6).
For the hosted service we operate that database on your behalf, on our infrastructure. If you run Signet on your own infrastructure instead, the database is yours entirely and we never touch it.
You can ask us for an export of your data at any time, and we will provide one within 7 days, usually much sooner. When your account ends we destroy your instance and its database within a reasonable period, and we will give you an export first if you ask for one before we do. Copies of your data in our backups age out on a fixed schedule rather than vanishing at the same moment, and where the law requires us to keep something for longer, we keep only what it requires, for only as long as it requires.
4. Security and incidents
We protect your data with reasonable technical and organisational measures. Concretely, today: every connection to the service is encrypted in transit, every customer gets a database of their own rather than a slice of a shared one, and passwords are stored only as salted hashes, never in plain text. If we confirm a security incident involving your data, we will notify you without undue delay, and tell you what happened, what it touched, and what we are doing about it.
If you are a hosted customer, the data-processing commitments you would normally have to request as a separate agreement are part of these terms: for your end-users' data we act only on your documented instructions; the suppliers in section 10 are bound to obligations equivalent to ours; and export and destruction work as section 3 says. Quebec law asks that these commitments be in writing, so they live here on this page rather than in a document you have to ask for. If you need a signed copy for your records, legal@signetauth.com will provide one.
5. Your account and acceptable use
Keep your credentials safe. You are responsible for what happens under your account. Do not use the service to break the law, to attack anyone, or to attack the service itself, and do not try to circumvent the limits of the plan you are on.
6. Fees, billing, and cancellation
Paid plans are a flat monthly price for the plan you choose. There is no usage metering and no usage charge. We take payment through Stripe, who handle your card details. We never see or store your card number.
We charge in advance for each billing period. If a free trial is offered on your plan, we say so before you pay, and your card is not charged until the trial ends.
You can cancel at any time from the billing page in your console, without contacting us. If the console is ever unavailable, an email to support@signetauth.com works too. When you cancel, your subscription stays active until the end of the period you have already paid for, and we do not charge you again. We do not refund part of a period you have already started.
If a payment fails, we will tell you and give you a chance to fix it before anything is suspended.
7. Availability
We do not offer a service level agreement on these terms today, and we would rather say so than print a number we have not engineered. We operate the service with commercially reasonable efforts, and we give notice of planned maintenance where we can. If we introduce an SLA, we will publish it here first.
8. Suspension and ending the agreement
You can close your account at any time. We may suspend or end your access if you do not pay, or if your use is an active security threat to the service or to other customers. Where it is practicable we will tell you first and give you a chance to put it right.
9. Changes to the service and to these terms
The service changes as we build it. We will not remove something you are paying for during a period you have already paid for; if we ever retire a paid feature, the change waits for the end of your current paid period, and we will tell you before it happens. We will post changes to these terms on this page, with at least 30 days notice before they take effect. If you keep using the service after a change takes effect, that is your acceptance of it.
10. Who else touches your service
We use a small number of suppliers to run Signet Cloud: Stripe for payments, and the cloud provider our servers run on. We will name our current suppliers on request, and we will give 15 days notice before we add or change one. The one exception: if security or keeping the service running requires an immediate replacement, we make the change first and tell you as soon as practicable afterwards. Our suppliers are bound to data-protection obligations equivalent to the ones we take on in section 4; if you need the data-processing commitments as a separate signed document, legal@signetauth.com will provide one.
11. Warranties and liability
We provide the service as it is. We warrant that we will provide it with reasonable skill and care, and we do not make any other promise about it. To the extent the law allows, we are not liable for indirect or consequential loss, and our total liability to you in any twelve month period is limited to the fees you paid us in that period.
Nothing here limits liability that cannot be limited by law.
12. Governing law
These terms are governed by the laws of the Province of Quebec and the federal laws of Canada that apply there. The courts of Quebec have jurisdiction, and nothing here removes any right you have to bring a claim where you live if the law gives you that right.
13. Contact
legal@signetauth.com for anything about this agreement. support@signetauth.com for the service itself.