
SERVERSCAN SUBSCRIBER AGREEMENT
Effective Date: August 13, 2026 | Version 2.0
IMPORTANT: PLEASE READ THESE TERMS CAREFULLY BEFORE APPLYING FOR OR USING SERVERSCAN’S PCI OR VULNERABILITY SCANNING SERVICES. BY PLACING AN ORDER FOR THE SERVICES, BY CLICKING THE BUTTON THAT COMPLETES YOUR PURCHASE, OR BY USING OR APPLYING FOR THE SERVICES, YOU ACKNOWLEDGE THAT YOU HAVE READ THIS AGREEMENT, THAT YOU UNDERSTAND IT, AND THAT YOU ACCEPT THESE TERMS. IF YOU DO NOT AGREE TO THESE TERMS, DO NOT PURCHASE OR USE THE SERVICES. THIS AGREEMENT CONTAINS A BINDING ARBITRATION CLAUSE AND A WAIVER OF CLASS AND REPRESENTATIVE ACTIONS IN SECTION 6, WHICH AFFECT HOW DISPUTES BETWEEN YOU AND SERVERSCAN ARE RESOLVED. SECTION 6.6 EXPLAINS HOW YOU MAY OPT OUT OF ARBITRATION.
This subscriber agreement is between you, as either an individual or organization, and ServerScan, LLC., the entity providing the secure scanning services. By using the services, you agree as follows:
1. Use of the Services
1.1. License. ServerScan grants you a revocable, non-exclusive, non-transferable, and limited license to use the purchased ServerScan’s vulnerability scanning services, as selected during the registration process, to identify vulnerabilities associated with a scanned device, website, or other Internet-connected system (“System”). You may only use the services on Systems under your control or where the System’s owner has provided you direct authorization to use the services. You may use the services only for lawful purposes and in accordance with any documentation provided by ServerScan. ServerScan may revoke this license only on suspension under section 3.4 or on termination of this agreement under section 3.1, and not otherwise.
1.2. Information. You shall only provide accurate and correct information in connection with the services. You must notify ServerScan promptly if any information provided is inaccurate or misleading.
1.3. Account. You shall keep the username and password protecting your account confidential. You are responsible for all activities and scanning services requested through your account. You must notify ServerScan immediately if there is any unauthorized use of your account.
1.4. Scanning. ServerScan’s services are intended to provide information about well-known vulnerabilities only. The services are not intended to detect all possible vulnerabilities or fix, prevent, or eliminate vulnerabilities associated with the scanned System. ServerScan does not guarantee the results of the scan, and you are solely responsible for securing and protecting your systems against vulnerabilities. The number and types of scans are changed regularly, and ServerScan may modify the scanning services without notice and in its sole discretion, except that ServerScan will not materially reduce the core scanning functionality you have purchased during a subscription period for which you have already paid.
1.5. Site Seal. The ServerScan site seal, the ServerScan name, and the ServerScan logo are trademarks of ServerScan. Subject to your compliance with this agreement, ServerScan grants you a revocable, non-exclusive, non-transferable, and limited license to display the site seal applicable to the provided services in connection with a System receiving a passing result from the vulnerability scanning services. The System may only display the site seal in the manner specified by ServerScan and only to indicate that the System passed the provided scanning service. You must display the site seal only by means of the seal code and seal images served by ServerScan, and you may not copy, cache, alter, resize beyond the proportions ServerScan specifies, recolor, or otherwise modify the seal, or display it in a way that suggests any certification, endorsement, or level of security that ServerScan has not provided. You may not display the site seal in a manner that misrepresents the extent of ServerScan’s services or could foreseeably result in legal action being taken against you or ServerScan. You shall cease displaying the ServerScan site seal in connection with any System that fails to achieve a passing result within two days of failing a scan. You may resume displaying the applicable site seal immediately after the System receives a new passing grade from the scanning service. The license granted in this section terminates automatically when this agreement terminates or when the services covering the relevant System lapse, and you shall remove the site seal from every System immediately on termination or lapse. ServerScan may disable, revoke, or require removal of the site seal at any time. Except as stated in this section, this agreement grants you no right to use any ServerScan trademark, and all goodwill from your use of the site seal inures to ServerScan.
1.6. Promotions. ServerScan may occasionally offer promotions with its services, such as a free trial account. ServerScan may make promotions unavailable at any time and may terminate trial accounts at any time. Promotions are limited to one per customer and may not be combined with other promotions or discounts.
1.7. Compliance. You shall comply with all laws and regulations related to use of the services, not use the services to interfere with a third party’s use of their network or Internet system, and not use the service to infringe on the intellectual property or privacy rights of a third party. You may not use the services to discover vulnerabilities that can be used to unlawfully access third party domains. You are responsible for all equipment and connectivity necessary to use the vulnerability scanning services. You must (1) comply with all regulations, policies and procedures of networks where the services are used;
(2) not use the services to infringe on the rights of any third party; and (3) not use the services in a manner that could harm ServerScan’s business or reputation.
1.8. Authorization to Scan. You represent and warrant, for every System you submit to the services and each time a scan of that System is performed, that you either own the System or have obtained express authorization to permit ServerScan to scan it from the System’s owner and from every provider that hosts, operates, or provides network connectivity to the System. You are solely responsible for obtaining and maintaining that authorization and for complying with the acceptable use policy of any hosting, cloud, or network provider. ServerScan may require written evidence of authorization before performing a scan and may refuse, suspend, or cancel any scan of any System at any time for any reason. Your indemnification obligations under section 4 apply to any claim arising from a scan of a System you were not authorized to submit, including claims under any computer fraud, unauthorized access, or wiretap statute.
1.9. Assumption of Scanning Risk. You acknowledge that vulnerability scanning is an active test of a live System and that scanning may, even when performed correctly, cause a System or the network or devices serving it to slow, become unstable, generate errors, exhaust resources, log or alert as an attack, block or throttle the scanning traffic, lock out accounts, produce unintended records or transactions in forms and applications, or become temporarily unavailable. You are solely responsible for deciding whether and when to scan, for scheduling scans at appropriate times, for maintaining current backups of the System and its data before a scan, and for notifying your hosting provider, network provider, and security vendors of scheduled scans and allowlisting ServerScan’s scanning addresses where required. You assume all risk of interruption, degradation, data loss, or damage to a System arising from a scan you requested or authorized.
1.10. PCI DSS and Compliance Scans. Where the services are offered as PCI DSS scanning, the following also applies. ServerScan is not itself an Approved Scanning Vendor. The scanning underlying the services is performed by a third-party Approved Scanning Vendor that ServerScan engages, and any ASV scan report, attestation of scan compliance, or comparable document arising from the services is issued by that vendor and not by ServerScan. You consent to ServerScan transmitting the information you submit, including the addresses, domains, and components in your scan scope and the resulting findings, to that vendor for the purpose of performing the scans and returning the results, and that vendor is a service provider for the purposes of section 2.6. You are solely responsible for identifying and submitting a complete and accurate list of every Internet-facing IP address, domain, and component that is in scope for your PCI DSS assessment, and for the accuracy of any network segmentation you rely on to exclude components from that list. ServerScan scans only what you submit and does not independently verify the completeness of your scope. You must promptly update your submitted list when addresses, domains, or components change, and a scan result covers only the addresses actually scanned on the date of that scan. A passing scan result is a statement about the specific vulnerabilities tested on the specific components scanned on the date of the scan. IT IS NOT A CERTIFICATION, ATTESTATION, OR GUARANTEE THAT YOU ARE COMPLIANT WITH THE PCI DSS OR WITH ANY OTHER STANDARD, LAW, OR CONTRACT, AND IT IS NOT A SUBSTITUTE FOR THE OTHER REQUIREMENTS OF THE PCI DSS OR FOR ANY ASSESSMENT REQUIRED BY YOUR ACQUIRER OR THE PAYMENT BRANDS. If you believe a scan result reports a vulnerability that is not present, is compensated for by controls ServerScan cannot observe, or is otherwise inaccurate, you may dispute the finding by submitting evidence to custservice@serverscan.com, and ServerScan will review the dispute and either confirm the finding or revise the result. You are responsible for remediating reported vulnerabilities and for rescanning to confirm remediation.
2. Data
2.1. Collected Information. You consent to ServerScan collecting and submitting information about your scanned Systems to ServerScan’s cloud servers, which are located in the United States. This information may contain personally identifiable information. ServerScan stores and uses this information in accordance with the privacy policy posted on its website, including improving the services, and updating the services, marketing the services. ServerScan does not license or sell collected information. ServerScan may disclose this information in connection with providing the services to you and for the reasons specified in the privacy policy. The privacy policy posted at serverscan.com/privacy-policy is incorporated into this agreement by reference.
2.2. Protection of Data. Although ServerScan has taken reasonable steps to protect data by building systems with high levels of security, there are risks of compromise beyond ServerScan’s control. ServerScan is not liable for any loss of data or information.
2.3. Emails. By subscribing to the Services, you opt into receiving further communication from ServerScan and its partners. You may opt-out of receiving additional communication (other than the communication necessary to provide ordered services, enforce this agreement, and provide notice) and any use of the information not directly related to the services by emailing a clear notice to custservice@serverscan.com.
2.4. Scan Results. ServerScan treats the detailed vulnerability findings and scan reports generated for your Systems as your confidential information. ServerScan will not disclose those findings to a third party except to its personnel and service providers who need them to deliver the services and who are bound by confidentiality obligations, to you and the users you authorize on your account, where you direct ServerScan to do so, or where disclosure is required by law or legal process. ServerScan maintains administrative, technical, and physical safeguards designed to protect scan reports against unauthorized access, and restricts access to those reports to personnel who need it. This section does not limit ServerScan’s use of aggregated or de-identified information that does not identify you or any of your Systems, and it does not restrict ServerScan’s reporting of the pass or fail status underlying a site seal you have chosen to display. This section survives termination of this agreement.
2.5. Data Protection Laws. Where ServerScan processes personal data on your behalf and that processing is subject to the EU or UK General Data Protection Regulation, the California Consumer Privacy Act, or a comparable data protection law, the parties will comply with ServerScan’s data processing addendum, which is available at serverscan.com/data-processing-addendum and which is incorporated into this agreement by reference and controls over any conflicting term of this agreement in respect of that processing. As between the parties, you are the controller and ServerScan is the processor with respect to personal data contained in the Systems you submit for scanning, and you are responsible for having a lawful basis for that processing. You acknowledge that ServerScan processes and stores this data in the United States.
2.6. Security and Breach Notification. ServerScan will maintain a written information security program with administrative, technical, and physical safeguards that are appropriate to the nature of the data it holds and that are no less protective than generally accepted industry practice for a provider of vulnerability scanning services. Those safeguards include encryption of scan reports in transit and at rest, access controls limiting access to personnel with a need to know, logging of access to scan reports, and periodic review and testing of the program. ServerScan may engage service providers to process data on its behalf, will impose obligations on them that are substantially as protective as those in this section and section 2.4, and remains responsible for their performance. If ServerScan becomes aware of a security incident that has resulted in the unauthorized acquisition of, or unauthorized access to, your scan reports or personal data held by ServerScan on your behalf, ServerScan will notify you without undue delay, and in any event within 72 hours of confirming the incident where the affected data is subject to the EU or UK General Data Protection Regulation and within 21 days of confirming the incident in every other case, will describe what is known about the nature and scope of the incident and the data involved, and will provide the information and cooperation you reasonably need to meet your own notification obligations under applicable law. Notice of an incident is not an admission of fault or liability by ServerScan.
2.7. Retention and Deletion. ServerScan retains scan reports and the data collected about your Systems for as long as your account is active and for a period after termination that is no longer than necessary for ServerScan’s legal, tax, audit, dispute resolution, and PCI DSS record-retention obligations. You may request a copy of the scan reports generated for your Systems, in the format ServerScan makes available, at any time while your account is active and for 30 days after termination. You may request deletion of your data by writing to custservice@serverscan.com, and ServerScan will delete or de-identify it within 60 days of the request except to the extent ServerScan is required to retain it by law or needs to retain it to establish, exercise, or defend a legal claim, and except for backup copies, which are deleted in the ordinary course of ServerScan’s backup cycle. Deletion may make the services unusable and may require ServerScan to close your account. This section survives termination of this agreement.
3. Termination
3.1. Term. This agreement is effective when you place an order for the services, activate your account, or use the services, whichever happens first, and lasts until terminated by either you or ServerScan. You may terminate this agreement and cancel any subscription at any time through the cancellation function in your ServerScan account, without contacting support and without giving a reason. You may also terminate by sending a clear notice of termination to custservice@serverscan.com, and termination requests sent by email are processed within two business days after receiving an email at the correct address. Cancellation stops any further renewal of the subscription and takes effect at the end of the subscription period then in progress, and you keep access to the services you have already paid for through the end of that period unless you request earlier deactivation. ServerScan will send you an email confirming the cancellation. The licenses granted herein are immediately revoked and this agreement automatically terminates if you breach this agreement. ServerScan may terminate this agreement at any time by closing your account or posting notice of the termination on its website.
3.2. Fees. You shall pay all fees related to services ordered through your ServerScan account, regardless of whether you used the services or the scanned System received a passing result from the security scanning service. Fees are owed in advance of each scan. ServerScan may provide a refund on fees paid in its sole discretion if the refund is requested within 30 days of ordering the scan. Although refunds are paid in ServerScan’s discretion, ServerScan typically only provides a refund if the System failed to pass a scan, ServerScan’s support service was promptly contacted and unable to assist you in passing the scan, and the refund is requested in writing within 30 days of ordering the services. You must raise any concerns regarding the amount owed for services with ServerScan within 30 days of when the services are purchased, as after 30 days no refunds are provided. No refunds are provided upon termination, and any outstanding balance for services remains owed post termination.
3.3. Automatic Renewal. IF THE SERVICES YOU PURCHASE ARE A SUBSCRIPTION, THAT SUBSCRIPTION RENEWS AUTOMATICALLY. At the end of each subscription period, the subscription automatically renews for a further period of the same length, and ServerScan charges the payment method on file for the then-current renewal fee, until you cancel. The length of the subscription period, the renewal fee, and the date of the next renewal are shown to you before you purchase and at all times in the billing area of your account. You authorize ServerScan to store your payment method and to charge it for each renewal. You may cancel at any time, before the next renewal date, through the cancellation function in your ServerScan account, and cancellation takes effect as described in section 3.1. ServerScan will send you an email after purchase confirming the automatic renewal terms, the amount and frequency of the charge, and how to cancel. For any subscription period of one year or longer, ServerScan will send you a reminder by email at least 15 and not more than 45 days before the renewal date, stating the renewal date, the amount to be charged, and how to cancel. ServerScan may revise its fees for future subscription periods by giving you notice by email at least 30 days before the start of the period to which the new fee applies, and the new fee applies only to periods beginning after that notice; if you do not agree to the new fee, your remedy is to cancel before that period begins.
3.4. Suspension. ServerScan may suspend your access to the services, or refuse or halt a scan, without terminating this agreement, if ServerScan reasonably believes that your use of the services violates this agreement or any law, that you lack authorization to scan a submitted System, that a scan threatens the stability or security of any network or system, or that fees owed are past due. ServerScan will give you notice of the suspension and, where the cause is one you can cure, a reasonable opportunity to cure it, except where giving notice first would create a risk of harm or is prohibited by law. Suspension does not relieve you of the obligation to pay fees for the suspended period unless ServerScan states otherwise.
3.5. Events on Termination. Upon termination, you must immediately cease using the services and remove the site seal from every System. Upon termination, all rights and obligations under this agreement cease except ServerScan’s rights under sections 2.2 and 2.3, the confidentiality obligations under section 2.4, the security and breach notification obligations under section 2.6 for so long as ServerScan holds your data, the retention and deletion obligations under section 2.7, your indemnification obligations under section 4, the limitation on damages under section 5, the arbitration requirement and class action waiver under section 6, and the miscellaneous obligations under section 7, including the intellectual property provisions of section 7.8.
4. Indemnification
4.1. Indemnification. You shall indemnify ServerScan and its affiliates, and their directors, officers, contractors, employees, and agents (each an “Indemnified Person”) against all liabilities, losses, expenses, or costs (including reasonable attorney’s fees) that are brought by a third party and that are related to, directly or indirectly, your use of the services, your infringement on the rights of a third party, your breach of the representations and warranties in section 1.8, or your breach of this agreement.
4.2. Indemnification Procedure. ServerScan will notify you promptly of any demand for indemnification. However, ServerScan’s failure to notify will not relieve you from your indemnification obligations. You may assume the defense of any action, suit, or proceeding giving rise to an indemnification obligation unless assuming the defense would result in potential conflicting interests as determined by the Indemnified Person in good faith. You may not settle any claim, action, suit or proceeding related to this agreement unless the settlement also includes an unconditional release of all Indemnified Persons from liability.
4.3. Additional Liability. Your indemnification obligations are not ServerScan’s sole remedy for a breach of this agreement and are in addition to any other remedies ServerScan may have against you. Your indemnification obligations survive the termination of this agreement.
5. Disclaimers and Limitation of Liability
5.1. Disclaimer; Assumption of Risk. THE SERVICES ARE PROVIDED “AS-IS” AND SERVERSCAN EXPRESSLY DISCLAIMS ALL IMPLIED AND EXPRESS WARRANTIES IN THE SERVICES. THIS DISCLAIMER INCLUDES ALL WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT, AND IT IS EFFECTIVE TO THE MAXIMUM EXTENT ALLOWED BY LAW. SERVERSCAN DOES NOT GUARANTEE THAT THE SERVICES WILL MEET YOUR REQUIREMENTS OR EXPECTATIONS OR THAT THE SERVICES WILL DETECT ALL KNOWN VULNERABILITIES. SERVERSCAN DOES NOT WARRANT THAT ANY RECOMMENDED REMEDIATION WILL REMEDY OR CURE A DETECTED VULNERABILITY. YOU ARE SOLELY RESPONSIBLE FOR ENSURING THE SECURITY OF YOUR SYSTEMS. If any legal right disallows or limits an exclusion of warranties, then the disclaimers herein apply to the maximum extent allowed by law.
5.2. Damage Limitation. SERVERSCAN’S MAXIMUM AGGREGATE LIABILITY FOR ALL CLAIMS RELATED TO THE SERVICES OR THIS AGREEMENT IS LIMITED TO THE GREATER OF (A) THE TOTAL AMOUNT YOU PAID SERVERSCAN FOR THE SERVICES IN THE TWELVE MONTHS IMMEDIATELY PRECEDING THE EVENT FIRST GIVING RISE TO THE CLAIM, AND (B) THE AMOUNT YOU PAID FOR THE PARTICULAR SERVICE THAT GAVE RISE TO THE CLAIM. SERVERSCAN IS NOT LIABLE FOR ANY INDIRECT, SPECIAL, INCIDENTAL, OR CONSEQUENTIAL DAMAGES, INCLUDING DAMAGES FOR LOST PROFITS, DATA, REVENUE, OR GOODWILL, EVEN IF SERVERSCAN WAS AWARE OF THE POSSIBILITY OF SUCH DAMAGES. These limitations apply to the maximum extent permitted by law regardless of 1) the reason for or nature of the liability, including tort claims, 2) the number of claims, 3) the extent or nature of the damages, or 4) whether any other provisions of this agreement have been breached or proven ineffective. Nothing in this agreement excludes or limits either party’s liability for fraud, for fraudulent misrepresentation, or for any other liability that cannot be excluded or limited under applicable law.
5.3. Limitations on Remedy. Except for actions and claims related to a party’s indemnification obligations, all actions or claims related to this agreement must be brought within one year from the date when the cause of action occurred, except where a shorter period is not permitted by the law that applies to you, in which case the shortest period that law permits applies.
6. Arbitration
6.1. Disputes. To the extent permitted by law, you will notify ServerScan of any dispute arising under this agreement before seeking dispute resolution by sending a written description of the dispute and the relief sought to custservice@serverscan.com, and ServerScan will notify you at the email address on your account. The parties will attempt in good faith to resolve the dispute informally. If the dispute is not resolved within sixty days after initial notice, then a party may proceed to resolve the dispute by arbitration conducted through the services of the American Arbitration Association (“AAA”) under its rules then in effect, including the Consumer Arbitration Rules where those rules apply. The arbitrator, and not any court, decides all issues relating to the interpretation, applicability, enforceability, and scope of this section, except that a court decides the enforceability of the class action waiver in section 6.5.
6.2. Notice and Hearing. The party initiating the arbitration must send notice to the other party. The arbitration will be conducted by a single arbitrator that is mutually agreed to by the parties. If the parties cannot agree to an arbitrator, the parties will use one selected by the AAA. The arbitration will be conducted on the documents alone, or by telephone or videoconference, unless the arbitrator determines that an in-person hearing is necessary. If an in-person hearing is held, it will be held in the county where you reside or have your principal place of business, or in Spring Hill, TN, or at another location the parties agree on. Nothing in this section requires you to travel to attend an arbitration.
6.3. Costs. Each party bears its own attorney fees, expert fees, and other costs of the arbitration, and you are responsible for all costs you incur in bringing or defending a claim. Where the AAA Consumer Arbitration Rules apply to a dispute, you pay the filing fee those rules require a consumer to pay, and ServerScan pays only those administrative fees and that portion of the arbitrator compensation that the AAA rules require ServerScan to pay in order for the AAA to administer the arbitration, and nothing beyond that minimum. In every other case, including every dispute brought by a business or other organization, you pay the AAA filing fee for any claim you initiate and the parties split the AAA administrative fees and the costs of the arbitrator equally, regardless of the final decision. The party found in default of this agreement by the arbitrator will pay all costs of the other party that are incurred in enforcing its rights under this agreement, including attorney’s fees, expert fees, and that party's share of the administrative and arbitrator costs. The arbitrator may award fees and costs where a governing statute provides for them, and may find a claim or a defense frivolous and reallocate all costs of the arbitration to the party that brought it.
6.4. Small Claims. Either party may bring an individual claim in a small claims court with jurisdiction over the parties instead of proceeding in arbitration, so long as the claim remains in that court and on an individual basis.
6.5. Class Action Waiver. THE PARTIES MAY BRING CLAIMS AGAINST EACH OTHER ONLY IN AN INDIVIDUAL CAPACITY, AND NOT AS A PLAINTIFF OR CLASS MEMBER IN ANY CLASS, COLLECTIVE, CONSOLIDATED, PRIVATE ATTORNEY GENERAL, OR OTHER REPRESENTATIVE PROCEEDING. The arbitrator may not consolidate the claims of more than one person and may not preside over any class or representative proceeding, and may award relief only in favor of the individual party seeking relief and only to the extent necessary to provide relief on that party’s individual claim. If this section 6.5 is held unenforceable as to a particular claim or a particular request for relief, then that claim or request for relief is severed from the arbitration and must be brought in the courts identified in section 7.4, and the remaining claims proceed in arbitration. If this section 6.5 is held unenforceable in its entirety, then section 6 does not apply and all disputes are resolved in the courts identified in section 7.4.
6.6. Your Right to Opt Out of Arbitration. You may opt out of sections 6.1 through 6.5 by sending written notice of your decision to opt out to custservice@serverscan.com within 30 days after you first place an order for the services. The notice must state your name, the email address on your account, and that you are opting out of arbitration. Opting out does not affect any other part of this agreement, and ServerScan will not terminate your account or change the services you receive because you opted out. If you do not opt out within 30 days, you and ServerScan are bound by sections 6.1 through 6.5.
7. General Provisions
7.1. Notices. You shall send notices to ServerScan in English writing to ServerScan. ServerScan provides notices to you by posting the notice on the ServerScan website, by sending the notice to the email address on your account, or through your Account. Notices sent by email are effective when sent. Other notices to you are effective when posted. Notices to ServerScan are effective upon receipt. You are responsible for keeping the email address on your account current.
7.2. Entire Agreement. This agreement is the entire agreement between the parties with respect to the services, superseding all other agreements that may exist with respect to the subject matter. Nothing herein modifies or affects the terms of any agreement covering ServerScan’s other products and services. ServerScan may amend this agreement in its sole discretion to the extent allowed by law. ServerScan will give you notice of any amendment by posting the modified agreement to its website with a new Effective Date, and, where the amendment materially changes your rights or obligations, by sending notice to the email address on your account at least 30 days before the amendment takes effect. A material amendment applies to you only from the date it takes effect, and if you do not agree to it your remedy is to terminate under section 3.1 before that date; continued use of the services after that date constitutes your acceptance of the change. Amendments do not apply retroactively to a dispute of which either party has already given notice under section 6.1. A party’s failure to enforce a provision of this agreement does not waive the party’s right to enforce the same provision later or right to enforce any other provision of this agreement. All waivers must be both in writing and signed by the party benefiting from the waived provision.
7.3. Force Majeure and Internet Frailties. Neither party is liable for a delay or failure to perform an obligation to the extent that the delay or failure is caused by an occurrence beyond the party's reasonable control. Each party acknowledges that the operation of the Internet is beyond the other party’s reasonable control.
7.4. Governing Law and Venue. The laws of the state of Tennessee govern the interpretation, construction, and enforcement of this agreement and all proceedings arising out of it, including tort claims, without regard to any conflicts of law principles. Where a dispute is not subject to arbitration under section 6, or where a party seeks to compel arbitration, to enforce or vacate an arbitration award, or to obtain injunctive or other equitable relief, the parties will commence all proceedings or legal action arising from this agreement in the state or federal courts of Tennessee, which courts have non-exclusive venue and jurisdiction over proceedings related to the services or this agreement. Nothing in this section overrides a mandatory provision of the law of your place of residence that you cannot waive by agreement.
7.5. Assignment. You may not assign any of your rights or obligations under this agreement, whether by merger, consolidation, operation of law, or any other manner, without the prior written consent of ServerScan. For purposes of this section only, a change in control is deemed an assignment. Any transfer without consent is void. To the extent allowed by law, ServerScan may assign its rights and obligations without your consent.
7.6. Severability. Any provision held invalid or unenforceable will be reformed to the minimum extent necessary to make the provision valid and enforceable. If reformation is not possible, the provision is deemed omitted and the balance of the agreement remains valid and enforceable.
7.7. Rights of Third Parties. There are no third party beneficiaries under the agreement.
7.8. Intellectual Property. ServerScan and its licensors own the services, the scanning platform and its software, the ServerScan website, the site seal, all ServerScan trademarks and logos, all documentation, and the format, presentation, scoring, and recommendations contained in scan reports, together with all intellectual property rights in them. This agreement grants you a license to use the services and the site seal on the terms stated in sections 1.1 and 1.5, and grants you no other right, title, or interest. You may use scan reports generated for your Systems for your own internal business purposes, including providing them to your acquirer, assessor, auditor, or customers as evidence of the scans performed. You may not resell, sublicense, or make the services available to a third party as a service, and you may not copy, modify, decompile, reverse engineer, or create derivative works of the scanning platform, or use the services or scan reports to build or improve a competing product. If you send ServerScan feedback or suggestions about the services, ServerScan may use them without restriction and without obligation to you. This section survives termination of this agreement.
7.9. Business Use. You represent that you are entering this agreement for business or commercial purposes and not primarily for personal, family, or household purposes, and that you are at least 18 years old and, if you are accepting on behalf of an organization, that you have authority to bind that organization. Where a law protecting consumers applies to you despite this representation, that law prevails over any conflicting term of this agreement to the extent it cannot be waived.
7.10. Order of Precedence. If a conflict exists between this agreement and another document, the following order controls, from highest to lowest: the data processing addendum referred to in section 2.5, in respect of the processing it governs; a written agreement signed by an authorized officer of ServerScan that expressly refers to and amends this agreement; this agreement; the order or checkout page for the services; and any other documentation ServerScan provides.
7.11. Electronic Records and Signatures. You consent to transact with ServerScan electronically, to receive this agreement, notices, disclosures, billing records, and scan reports electronically, and to the use of electronic records and electronic signatures. Your acceptance of this agreement by placing an order for the services or completing a purchase, and ServerScan’s records of that order, have the same effect as a signed writing. You may withdraw this consent, or request a paper copy of any record, by writing to custservice@serverscan.com, and ServerScan may terminate this agreement and your account if you withdraw consent, because the services are provided electronically.
ACCEPTANCE
BY PLACING AN ORDER FOR THE SERVICES AND COMPLETING YOUR PURCHASE, YOU REPRESENT THAT YOU HAVE READ AND UNDERSTAND THIS AGREEMENT, INCLUDING THE BINDING ARBITRATION CLAUSE AND CLASS ACTION WAIVER IN SECTION 6 AND THE AUTOMATIC RENEWAL TERMS IN SECTION 3.3, AND THAT YOU WILL BE BOUND BY AND COMPLY WITH ALL OF ITS TERMS. DO NOT COMPLETE YOUR PURCHASE IF YOU DO NOT ACCEPT THIS AGREEMENT.