PRIVACY POLICY
Hazmat Software LLC / Hazmat Toolbox Platform
Effective Date: June 16, 2026
1) INTRODUCTION
- This Privacy Policy explains how Hazmat Software LLC, a New York limited liability company (“Company,” “we,” “us,” or “our”), collects, uses, stores, discloses, protects, and otherwise processes information in connection with the Hazmat Toolbox platform, including our websites, mobile applications, web applications, software tools, subscription services, training resources, support services, communications, and related products or services (collectively, the “Platform”).
- This Privacy Policy applies to individuals and organizations that access or use the Platform, including individual users, emergency responders, instructors, students, agency users, administrators, departments, organizations, enterprise customers, contractors, and any other person or entity using the Platform (“User,” “you,” or “your”).
- If you use the Platform on behalf of an agency, department, employer, company, school, training organization, government entity, or other organization, this Privacy Policy applies to information processed through that organizational account. Your organization may also have access to and control over certain information associated with your use of the Platform.
- This Privacy Policy is incorporated into the Company’s Terms of Service. By accessing or using the Platform, you acknowledge this Privacy Policy and agree that your use of the Platform is subject to the Terms of Service and any applicable subscription terms, agency agreement, enterprise agreement, data processing addendum, or other written agreement.
- If you do not agree with this Privacy Policy, do not access or use the Platform.
2) INFORMATION WE COLLECT
- We may collect information that you provide directly to us, information generated through your use of the Platform, information provided by your organization, and information received from third-party services or integrations.
- Account information may include name, email address, phone number, username, password or authentication credentials, organization name, agency affiliation, role, title, permissions, account type, subscription status, and related account details.
- Organizational information may include agency name, department name, company name, address, billing contacts, administrator contacts, user rosters, assigned roles, training groups, reporting structures, subscription details, license counts, and other information associated with an organizational account.
- Billing and transaction information may include subscription plan, payment status, invoices, purchase orders, billing address, tax information, transaction history, payment method details, and related payment records. Payment card information may be processed by third-party payment processors and may not be stored directly by the Company.
- Training information may include course enrollments, assigned training, attendance, quiz results, assessment results, completion records, certificates, transcripts, continuing education records, instructor activity, student activity, and related training documentation.
- User Content may include information uploaded, submitted, entered, stored, imported, generated, or transmitted through the Platform, including incident notes, reports, photos, videos, maps, equipment inventories, response plans, pre-plans, scenarios, forms, documents, agency policies, checklists, training records, chemical information, facility information, and other materials submitted by you or your organization.
- Incident-related information may include incident notes, location information, hazard information, chemical information, container information, weather-related information, mapping data, operational notes, equipment use, response actions, responder assignments, photographs, videos, reports, and after-action materials.
- Device and technical information may include IP address, device type, operating system, browser type, app version, device identifiers, mobile carrier, crash logs, diagnostic data, log files, session information, authentication activity, and security-related information.
- Usage information may include pages viewed, features used, tools accessed, searches performed, reports generated, files uploaded, exports downloaded, training completed, timestamps, click activity, administrative actions, user settings, and interaction history.
- Location information may be collected if you enable location-based features, GPS functions, mapping tools, mobile app permissions, or other Platform functions that require location access.
- Communications information may include support requests, emails, chat messages, feedback, survey responses, bug reports, security reports, billing communications, sales communications, and other communications with the Company.
- AI and automation information may include prompts, submitted content, generated outputs, summaries, classifications, recommendations, reports, usage logs, and related information processed through AI-enabled or automated features.
- Third-party integration information may include information received from or transmitted to connected systems, such as payment processors, authentication providers, mapping services, learning systems, agency systems, cloud services, analytics tools, AI providers, or other integrations enabled by you or your organization.
3) HOW WE USE INFORMATION
- We may use information to provide, operate, maintain, secure, support, and improve the Platform.
- We may use information to create and manage accounts, authenticate users, assign roles, manage permissions, provide subscriptions, process payments, generate invoices, and administer organizational accounts.
- We may use information to deliver training content, track course progress, generate certificates, maintain training records, support instructors, provide reports, and manage training administration.
- We may use information to provide Platform tools, including reference tools, documentation tools, scenario tools, incident-support tools, mapping tools, equipment tools, reporting tools, AI-enabled tools, and other software features.
- We may use information to process User Content, generate reports, display records, organize data, support exports, maintain backups, troubleshoot errors, and respond to user or administrator requests.
- We may use information to provide customer support, respond to questions, investigate issues, resolve disputes, communicate with users, provide service notices, and send administrative messages.
- We may use information to analyze Platform usage, monitor performance, improve functionality, develop new features, test beta features, debug errors, conduct analytics, and improve user experience.
- We may use information to protect the Platform, detect misuse, prevent unauthorized access, investigate prohibited activity, enforce the Terms of Service, maintain audit logs, and support security operations.
- We may use information to comply with legal obligations, respond to lawful requests, preserve records, enforce agreements, protect rights, prevent harm, and support business operations.
- We may use aggregated, anonymized, or de-identified information for analytics, research, benchmarking, product development, performance monitoring, business planning, and service improvement, provided such information does not reasonably identify you or your organization.
4) ORGANIZATIONAL ACCOUNTS
- If you access the Platform through an agency, department, employer, school, enterprise customer, or other organization, your organization may control certain information associated with your account.
- Authorized administrators may be able to view, access, manage, export, modify, assign, or delete certain information associated with the organizational account, including user activity, training records, completion records, reports, uploaded content, account status, role assignments, and administrative settings.
- We may rely on instructions from authorized administrators regarding user access, permissions, account management, data access, exports, deletion requests, subscription changes, and related account actions.
- We are not responsible for disputes between you and your organization regarding account access, training records, employment status, role assignments, administrator actions, internal policies, or control of organizational data.
5) USER CONTENT AND INCIDENT DATA
- As between you and the Company, you retain whatever ownership rights you have in User Content, subject to the rights granted to the Company under the Terms of Service, this Privacy Policy, and any applicable written agreement.
- We process User Content to provide the Platform, operate enabled features, generate reports, maintain records, support organizational administration, provide customer support, secure the Platform, troubleshoot issues, comply with law, and enforce our agreements.
- You and your organization are responsible for determining whether any User Content, incident data, agency data, responder data, student data, facility data, chemical data, photograph, video, document, or report is lawful and appropriate to upload to the Platform.
- You should apply OPSEC review, data minimization, redaction, and authorization before uploading sensitive operational information to the Platform.
- Do not upload classified information, restricted information, protected health information, law enforcement sensitive information, export-controlled information, personally identifiable information, confidential incident information, or other regulated information unless you and your organization have confirmed that the upload is lawful, authorized, appropriate, and permitted under your applicable subscription or written agreement.
6) AI-ENABLED FEATURES
- The Platform may include artificial intelligence, automation, machine learning, natural language processing, summarization, classification, recommendation, drafting, translation, or other generated-output features.
- Information submitted to AI-enabled features may be processed by Company systems, third-party providers, cloud infrastructure, APIs, hosted models, or other external services, depending on the feature and configuration.
- You are responsible for determining whether information is appropriate to submit to AI-enabled features, especially if the information is sensitive, confidential, regulated, personal, incident-related, or OPSEC-relevant.
- Unless otherwise stated in a separate written agreement, you should not submit sensitive operational information, protected information, classified information, law enforcement sensitive information, medical information, or high-risk personal information into AI-enabled features.
- AI-generated outputs may be inaccurate, incomplete, outdated, or unsuitable for a particular use. You must independently review and verify generated outputs before relying on them.
- We may use AI-related usage data, prompts, outputs, error data, and performance information to provide, secure, troubleshoot, evaluate, and improve AI-enabled features, subject to this Privacy Policy and any applicable written agreement.
7) HOW WE DISCLOSE INFORMATION
- We may disclose information to service providers, vendors, contractors, hosting providers, payment processors, analytics providers, communication providers, AI providers, mapping providers, security providers, support providers, and other third parties that help us provide, operate, secure, and improve the Platform.
- We may disclose information to authorized administrators or representatives of your organization when the information is associated with that organization’s account, subscription, users, training records, reports, billing, administrative activity, or organizational data.
- We may disclose information when necessary to process payments, manage subscriptions, issue invoices, resolve billing issues, prevent fraud, or respond to chargebacks.
- We may disclose information to comply with law, regulation, subpoena, court order, public-records request, government request, legal process, or other legal obligation.
- We may disclose information when we believe disclosure is necessary to protect the Company, the Platform, users, organizations, responders, the public, or third parties; investigate misuse; prevent harm; protect rights or property; enforce agreements; or respond to security incidents.
- We may disclose information in connection with a merger, acquisition, financing, restructuring, sale of equity, sale of assets, bankruptcy, transfer of business operations, or similar transaction.
- We may disclose aggregated, anonymized, or de-identified information that does not reasonably identify you or your organization.
- We do not sell User Content as a standalone product to unaffiliated third parties.
8) THIRD-PARTY SERVICES
- The Platform may connect to or rely on third-party services, including cloud hosting, payment processing, mapping, geolocation, weather, chemical databases, AI services, analytics, communications, authentication, app stores, and other external systems.
- Third-party services may collect, process, store, or transmit information according to their own terms and privacy policies.
- We are not responsible for the privacy practices, security practices, data accuracy, availability, or content of third-party services that we do not control.
- If you or your organization connects the Platform to a third-party system, you represent that you have the authority to authorize that connection and the related data processing.
9) COOKIES AND SIMILAR TECHNOLOGIES
- We may use cookies, pixels, local storage, device identifiers, log files, analytics tools, and similar technologies to support authentication, security, preferences, account management, analytics, performance, troubleshooting, and Platform improvement.
- You may be able to adjust browser or device settings to limit certain technologies, but doing so may affect Platform functionality.
- We may use analytics tools to understand Platform usage, diagnose issues, improve performance, and develop features.
10) MOBILE APP INFORMATION
- If you use a mobile application, we may collect information related to your device, app version, operating system, crash logs, diagnostic data, mobile permissions, notification settings, and location information if enabled.
- Certain mobile app features may require device permissions, including camera, microphone, photos, files, notifications, Bluetooth, location, or storage.
- You may disable certain permissions through device settings, but doing so may limit or prevent use of certain features.
- If your device is lost, stolen, compromised, transferred, or no longer controlled by you or your organization, you or your administrator should promptly revoke access, change credentials, or notify the Company.
11) DATA SECURITY
- We use reasonable administrative, technical, and organizational safeguards designed to protect information against unauthorized access, disclosure, alteration, loss, misuse, or destruction.
- Security safeguards may include access controls, authentication controls, encryption where appropriate, monitoring, logging, vendor controls, backups, administrative procedures, and other measures appropriate to the nature of the information and Platform.
- No internet-based, mobile, or cloud-based system can be guaranteed to be completely secure. We do not guarantee that unauthorized access, disclosure, alteration, loss, misuse, or destruction will never occur.
- The FTC recommends that businesses understand what personal information they have, how it moves through the business, and who has or could have access to it when assessing data security practices.
- You are responsible for maintaining secure credentials, securing your devices, using appropriate administrator controls, limiting access to authorized users, and promptly reporting suspected unauthorized access or security incidents.
12) DATA RETENTION
- We may retain information for as long as reasonably necessary to provide the Platform, maintain accounts, comply with legal obligations, resolve disputes, enforce agreements, support security, process billing, provide customer support, maintain records, and conduct legitimate business operations.
- Retention periods may vary based on the type of information, account type, organizational instructions, subscription status, legal obligations, backup systems, audit requirements, dispute needs, and written agreements.
- Deletion from active Platform views may not immediately remove all copies from backups, logs, archives, disaster recovery systems, legal holds, billing records, or records retained for compliance, security, dispute resolution, or legitimate business purposes.
- If you access the Platform through an organizational account, your organization may control retention, export, deletion, and access to certain organizational data.
13) DATA EXPORT, ACCESS, CORRECTION, AND DELETION
- Depending on your account type, applicable law, organizational relationship, and the nature of the information, you may request access to, correction of, deletion of, or export of certain personal information.
- Requests may require verification of identity, account ownership, administrator status, organizational authority, or legal authorization.
- If information is controlled by your organization, we may direct you to contact that organization or require authorization from the organization before acting on the request.
- We may deny or limit requests where permitted by law, including where information must be retained for legal compliance, security, dispute resolution, billing, records retention, contractual obligations, or legitimate business purposes.
14) STATE PRIVACY RIGHTS
- Certain users may have privacy rights under applicable state privacy laws, depending on residence, the type of information involved, and whether the law applies to the Company.
- These rights may include the right to know what personal information is collected, used, or shared; the right to request deletion; the right to correct inaccurate information; the right to access or obtain a copy of information; the right to opt out of certain uses; and the right not to be discriminated against for exercising privacy rights.
- California’s Attorney General describes CCPA rights as including the right to know, the right to delete, the right to opt out of sale or sharing, and the right to non-discrimination for exercising CCPA rights.
- If you believe you have rights under a state privacy law, contact us using the privacy contact information listed below.
- We will respond to privacy requests as required by applicable law.
15) CHILDREN’S PRIVACY
- The Platform is not intended for children under thirteen (13) years of age.
- We do not knowingly collect personal information from children under thirteen (13) without appropriate authorization.
- If we become aware that we have collected personal information from a child under thirteen (13) without required authorization, we may delete or restrict the information.
- If the Platform is used by schools, training programs, cadet programs, explorer programs, youth programs, or similar organizations involving minors, the organization is responsible for obtaining all required parental, guardian, school, or legal consents and ensuring compliance with applicable laws.
16) PUBLIC RECORDS, LEGAL PROCESS, AND GOVERNMENT USERS
- If you are a government entity, public agency, municipality, public school, or similar organization, information submitted to the Platform may be subject to public-records laws, records-retention obligations, subpoenas, discovery, audits, investigations, or other legal requirements.
- You and your organization are responsible for determining whether information submitted to the Platform is appropriate for upload and whether any public-records, retention, disclosure, or confidentiality obligations apply.
- We may preserve, disclose, restrict, or produce information when required by law or legal process.
17) INTERNATIONAL USERS
- The Platform is operated from the United States.
- If you access the Platform from outside the United States, you understand that information may be processed in the United States or other locations where the Company or its service providers operate.
- You are responsible for ensuring that your use of the Platform complies with laws applicable to your location and organization.
18) SECURITY INCIDENTS
- If we become aware of a security incident involving personal information, we may investigate and provide notices as required by applicable law or written agreement.
- The New York Attorney General’s SHIELD Act guidance describes covered breaches as including unauthorized acquisition and, under the SHIELD Act expansion, unauthorized access to computerized private data that compromises confidentiality, security, or integrity.
- You must promptly notify us if you become aware of unauthorized access, account compromise, improper disclosure, suspected misuse, or a security incident involving the Platform.
19) CHANGES TO THIS PRIVACY POLICY
- We may update this Privacy Policy from time to time.
- Updates may be posted on the Platform, sent by email, displayed in-app, provided through account notices, or otherwise made available.
- Unless otherwise stated, updated versions become effective when posted or made available.
- Continued use of the Platform after an updated Privacy Policy becomes effective constitutes acknowledgment of the updated Privacy Policy.
20) CONTACT INFORMATION
- Privacy questions, requests, or concerns should be directed to:
Hazmat Software LLC
Email: support@hazmathaven.com
Mailing Address: 446 East Meadow Avenue #139, East Meadow, NY 11554
Website: www.hazmathaven.com
- Security concerns, suspected unauthorized access, or data incidents should be reported to:
Security Contact: John Holtan
Email: john.holtan@hazmathaven.com
- We may require verification of identity, account ownership, administrator status, organizational authority, or legal authority before responding to privacy, security, access, deletion, correction, or export requests.
DATA PROCESSING AGREEMENT
Hazmat Software LLC / Hazmat Toolbox Platform
Effective Date: June 16, 2026
1) INTRODUCTION
- This Data Processing Addendum (“DPA”) governs the processing, handling, protection, retention, access, disclosure, and return or deletion of Customer Data submitted to or processed through the Hazmat Toolbox platform, including related websites, mobile applications, web applications, software tools, subscription services, training resources, data services, artificial intelligence features, support services, and related products or services made available by Hazmat Software LLC (“Company,” “we,” “us,” or “our”).
- This DPA applies when an agency, department, enterprise customer, government entity, municipality, school, training organization, company, contractor, or other organizational customer (“Customer”) uses the Platform and submits, uploads, stores, transmits, processes, or otherwise makes Customer Data available to the Company.
- This DPA supplements the Company’s Terms of Service, Privacy Policy, Acceptable Use Policy, Subscription and Payment Terms, Agency Account Addendum, Training Disclaimer / Certification Policy, AI Use Disclaimer, Refund and Cancellation Policy, Mobile App End User License Addendum, and any applicable order form, purchase agreement, enterprise agreement, agency agreement, or other written agreement between Customer and the Company.
- If this DPA conflicts with the Terms of Service or Agency Account Addendum regarding the processing of Customer Data, this DPA shall control only to the extent of that conflict.
- If a separate written agreement signed by the Company contains different data-processing, privacy, security, retention, deletion, breach-notification, or confidentiality terms, the separate written agreement shall control only to the extent of the conflict.
2) DEFINITIONS
- “Customer Data” means any data, records, documents, images, files, reports, training records, incident records, agency information, user information, equipment information, facility information, maps, scenarios, forms, communications, User Content, or other information submitted to, uploaded to, generated in, stored in, transmitted through, or processed by the Platform on behalf of Customer or Customer’s authorized users.
- “Personal Information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked to an individual, as defined under applicable privacy or data-protection laws.
- “Sensitive Information” means information that may create elevated legal, privacy, security, operational, or safety risk if accessed, disclosed, altered, lost, or misused, including protected health information, medical information, personally identifiable information, law enforcement sensitive information, confidential incident information, controlled unclassified information, export-controlled information, critical infrastructure information, security-sensitive information, operationally sensitive information, or other regulated or protected information.
- “Processing” means any operation performed on Customer Data, including collection, access, use, storage, transmission, hosting, organization, analysis, display, retrieval, disclosure, deletion, modification, export, backup, security monitoring, support access, or other handling.
- “Subprocessor” means a third-party service provider, vendor, contractor, hosting provider, AI provider, payment processor, analytics provider, security provider, support provider, communication provider, or other third party engaged by the Company to process Customer Data in connection with the Platform.
- “Security Incident” means unauthorized access to, acquisition of, disclosure of, alteration of, loss of, or destruction of Customer Data that compromises the confidentiality, integrity, or availability of such data. Security Incident does not include unsuccessful access attempts, scans, pings, firewall events, denial-of-service attempts, or similar events that do not result in unauthorized access to Customer Data.
- “Authorized Users” means Customer’s employees, responders, members, volunteers, contractors, instructors, students, administrators, representatives, or other individuals authorized by Customer to access the Platform under Customer’s account.
3) ROLES AND RESPONSIBILITIES
- Customer determines what Customer Data is submitted to the Platform, who may access it, how it is configured, what users are authorized, and how the Platform is used by Customer and Authorized Users.
- The Company processes Customer Data to provide the Platform and related services to Customer.
- Customer is responsible for determining whether use of the Platform is appropriate for Customer’s legal, regulatory, operational, procurement, cybersecurity, training, privacy, records-retention, OPSEC, and data-handling requirements.
- Customer is responsible for ensuring that Customer has all rights, permissions, authority, consents, approvals, legal bases, and authorizations necessary to submit Customer Data to the Platform and permit the Company to process Customer Data under this DPA.
- Customer is responsible for all instructions given to the Company by Customer, Customer’s administrators, and Authorized Users.
- The Company may rely on instructions from Customer’s authorized administrators, account owners, billing contacts, security contacts, legal contacts, or other representatives reasonably appearing to act on behalf of Customer.
4) SCOPE OF PROCESSING
- The Company shall process Customer Data only as reasonably necessary to provide, maintain, secure, support, troubleshoot, improve, administer, and operate the Platform and related services.
- The Company may process Customer Data to create accounts, authenticate users, assign roles, manage permissions, provide subscriptions, process records, generate reports, deliver training content, maintain training records, provide customer support, manage organizational accounts, maintain backups, monitor performance, secure the Platform, investigate misuse, comply with law, enforce agreements, and perform other Platform-related functions.
- The Company may process Customer Data according to Customer’s account settings, administrator instructions, enabled features, subscription plan, support requests, written agreements, and use of the Platform by Customer and Authorized Users.
- The Company shall not sell Customer Data as a standalone product to unaffiliated third parties.
- The Company may use aggregated, anonymized, or de-identified data derived from Platform usage, Customer Data, account activity, training activity, technical activity, or operational metadata for analytics, product improvement, security, performance monitoring, research, benchmarking, reporting, development, and business purposes, provided such data does not reasonably identify Customer or any individual.
5) CUSTOMER INSTRUCTIONS
- Customer instructs the Company to process Customer Data as necessary to provide the Platform and related services under the applicable agreements.
- Customer may provide additional lawful written instructions regarding Customer Data, subject to Platform functionality, subscription limits, legal requirements, technical feasibility, security requirements, and any applicable fees.
- The Company is not required to follow instructions that the Company reasonably believes are unlawful, technically infeasible, inconsistent with the Platform, inconsistent with Company security practices, inconsistent with third-party obligations, or likely to create legal, security, operational, privacy, or safety risk.
- If the Company determines that an instruction may violate applicable law or create material risk, the Company may suspend performance of the instruction and notify Customer where legally permitted.
6) CUSTOMER RESPONSIBILITY FOR DATA SUBMITTED
- Customer is solely responsible for the accuracy, legality, quality, completeness, appropriateness, authorization, and reliability of Customer Data submitted to or processed through the Platform.
- Customer shall not submit Customer Data unless Customer has determined that such submission is lawful, authorized, appropriate, operationally justified, and consistent with Customer’s policies, legal obligations, confidentiality obligations, OPSEC requirements, and data-handling rules.
- Customer shall not submit classified information, restricted information, controlled unclassified information, protected health information, medical records, criminal justice information, law enforcement sensitive information, export-controlled information, confidential incident information, personally identifiable information, security-sensitive information, or other regulated information unless Customer has confirmed that such use is lawful, authorized, appropriate, and permitted under the applicable subscription plan and written agreement.
- Customer is responsible for applying OPSEC review, data minimization, redaction, anonymization, de-identification, and access limitation before submitting Customer Data to the Platform.
- Customer is responsible for obtaining any required consent, authorization, approval, clearance, release, or legal basis before submitting information relating to individuals, patients, victims, witnesses, responders, students, employees, contractors, agencies, facilities, customers, or third parties.
7) SECURITY SAFEGUARDS
- The Company shall maintain reasonable administrative, technical, and organizational safeguards designed to protect Customer Data against unauthorized access, disclosure, alteration, loss, misuse, or destruction.
- Such safeguards may include access controls, authentication controls, least-privilege access, encryption where appropriate, logging, monitoring, backups, vendor review, incident-response procedures, internal policies, security reviews, administrative procedures, and other measures appropriate to the nature of the Platform and Customer Data.
- The Company’s security safeguards shall be commercially reasonable and proportionate to the nature of the services, the type of Customer Data processed, the risks presented by processing, and the Company’s size, resources, and operations.
- The FTC recommends that businesses protect personal information by understanding what they have, limiting unnecessary collection, protecting stored information, securely disposing of unneeded data, and preparing for security incidents.
- Because the Company is a New York business and may maintain private information, Customer acknowledges that New York’s SHIELD Act requires reasonable administrative, technical, and physical safeguards for private information.
- Customer acknowledges that no internet-based, mobile, cloud-based, or software-based system can be guaranteed to be completely secure.
- Customer remains responsible for securing its own systems, devices, accounts, credentials, email accounts, administrator access, single sign-on systems, identity providers, API keys, networks, exports, and local copies of Customer Data.
8) ACCESS CONTROLS
- The Company shall limit employee, contractor, vendor, and Subprocessor access to Customer Data to personnel or systems with a legitimate need to access such data for Platform operation, support, security, troubleshooting, compliance, or other authorized business purposes.
- Customer is responsible for managing Authorized User access, administrator permissions, role assignments, account removals, identity provider settings, and organizational access controls.
- Customer shall promptly remove or restrict access for any Authorized User who is no longer employed by, affiliated with, assigned to, contracted by, authorized by, or otherwise permitted to use the Platform on behalf of Customer.
- Customer shall promptly notify the Company of suspected unauthorized access, account compromise, improper disclosure, lost devices, credential misuse, or any other event that may affect Platform security or Customer Data.
9) CONFIDENTIALITY
- The Company shall treat Customer Data as confidential information and shall not disclose Customer Data except as permitted by this DPA, the Terms of Service, the Privacy Policy, a separate written agreement, Customer’s instructions, or applicable law.
- The Company shall require personnel with access to Customer Data to be subject to confidentiality obligations or professional obligations that protect Customer Data from unauthorized use or disclosure.
- Customer shall treat non-public Company information, Platform functionality, software design, security practices, documentation, training materials, AI configurations, prompts, workflows, and technical information as Company confidential information.
10) SUBPROCESSORS
- Customer authorizes the Company to use Subprocessors to provide, host, secure, support, improve, and operate the Platform.
- Subprocessors may include cloud hosting providers, database providers, payment processors, email providers, SMS providers, analytics providers, AI providers, mapping providers, security providers, customer support systems, monitoring tools, app store providers, and other service providers.
- The Company shall use commercially reasonable efforts to require Subprocessors that process Customer Data to protect such data through contractual, technical, or organizational safeguards appropriate to the services provided.
- The Company remains responsible for Subprocessor processing of Customer Data to the extent required by applicable law and the applicable agreement with Customer.
- The Company may add, replace, or remove Subprocessors from time to time.
- Customer may request a current list of material Subprocessors, if available. The Company may provide such list through the Platform, support channel, website, security documentation, or other reasonable method.
- If Customer objects to a new material Subprocessor on reasonable security or legal grounds, Customer shall notify the Company in writing. The Company may use commercially reasonable efforts to address the objection, provide an alternative where feasible, or allow Customer to terminate the affected service according to the applicable agreement.
11) AI PROCESSING
- Customer acknowledges that some Platform features may use artificial intelligence, automation, machine learning, natural language processing, hosted models, third-party APIs, or other automated tools.
- Customer is responsible for deciding whether to enable or use AI-enabled features and whether Customer Data is appropriate for submission to such features.
- Customer shall not submit sensitive, restricted, classified, protected, law enforcement sensitive, medical, personally identifiable, OPSEC-relevant, or high-risk information into AI-enabled features unless Customer has determined that such submission is lawful, authorized, appropriate, and permitted under Customer’s policies and the applicable agreement.
- AI-enabled features may process information through Company systems, third-party providers, cloud infrastructure, APIs, hosted models, or other external services, depending on the feature and configuration.
- AI-generated outputs may be inaccurate, incomplete, outdated, or unsuitable for a particular use. Customer is responsible for ensuring that Authorized Users independently review and verify AI-generated outputs before reliance.
- Unless otherwise stated in a separate written agreement, the Company may use AI-related usage data, prompts, outputs, error data, and performance information to provide, secure, troubleshoot, evaluate, and improve AI-enabled features, subject to the Privacy Policy and this DPA.
12) SECURITY INCIDENTS
- The Company shall notify Customer without unreasonable delay after the Company confirms a Security Incident involving Customer Data.
- Notification may be provided to Customer’s administrator, security contact, legal contact, account owner, or other contact designated by Customer.
- The Company’s notification may include, to the extent reasonably available and legally permitted, a description of the Security Incident, categories of Customer Data involved, approximate timing, known or suspected cause, steps taken by the Company, and recommended steps for Customer.
- The Company may provide information in phases as the investigation develops.
- The Company’s notification of a Security Incident is not an admission of fault, liability, violation of law, or breach of contract.
- Customer is responsible for determining whether Customer must notify affected individuals, agencies, regulators, authorities, employees, responders, students, customers, or other third parties unless a separate written agreement states otherwise.
- The Company shall reasonably cooperate with Customer’s investigation and legally required notices, subject to applicable law, security requirements, confidentiality obligations, and reasonable cost reimbursement where appropriate.
- Customer shall promptly notify the Company if Customer becomes aware of a Security Incident, unauthorized access, improper disclosure, or misuse involving the Platform or Customer Data.
13) LEGAL PROCESS AND REQUIRED DISCLOSURE
- The Company may disclose Customer Data if required by law, subpoena, court order, warrant, public-records request, government request, regulatory request, or other legal process.
- Where legally permitted, the Company may provide Customer with notice of a legal request seeking Customer Data.
- The Company may object to or limit legal requests where appropriate but is not required to do so unless required by a separate written agreement.
- Customer is responsible for public-records obligations, records-retention obligations, discovery obligations, litigation holds, subpoenas, audits, investigations, regulatory obligations, and other legal obligations applicable to Customer Data.
- If Customer is a government entity, Customer acknowledges that Customer Data may be subject to public-records, freedom-of-information, retention, disclosure, and similar laws.
14) DATA RETENTION
- The Company may retain Customer Data for as long as reasonably necessary to provide the Platform, maintain accounts, support Customer, comply with legal obligations, resolve disputes, enforce agreements, process billing, maintain security, operate backups, preserve audit logs, and conduct legitimate business operations.
- Retention periods may vary based on account type, subscription status, Customer instructions, legal obligations, backup systems, security logs, audit needs, dispute needs, and written agreements.
- Customer is responsible for configuring available retention settings, exporting required records, and maintaining any required official records outside the Platform unless a separate written agreement states otherwise.
- Deletion from active Platform views may not immediately remove all copies from backups, archives, logs, disaster recovery systems, legal holds, billing records, support records, or records retained for compliance, security, dispute resolution, or legitimate business purposes.
15) RETURN, EXPORT, AND DELETION
- During the active subscription term, Customer may export certain Customer Data using available Platform functionality, subject to subscription limits, technical feasibility, security requirements, and applicable fees.
- Upon cancellation, expiration, suspension, or termination of Customer’s subscription, Customer’s access to Customer Data may be limited, suspended, or terminated.
- Customer is responsible for exporting required Customer Data before cancellation, expiration, downgrade, suspension, or termination where Platform functionality permits.
- The Company may provide a limited post-termination export period if commercially reasonable or required by a separate written agreement.
- After termination, the Company may retain, delete, restrict, preserve, or make available Customer Data according to the Terms of Service, Privacy Policy, this DPA, applicable law, records-retention needs, security requirements, billing requirements, dispute-resolution needs, and any separate written agreement.
- The Company is not required to return or delete Customer Data in a manner that would violate law, compromise security, disrupt backups, interfere with legal holds, impair dispute resolution, violate third-party obligations, or require disproportionate technical effort.
16) DATA LOCATION
- The Platform is operated primarily from the United States.
- Customer Data may be processed in the United States and in other locations where the Company or its Subprocessors operate.
- Customer is responsible for determining whether use of the Platform and the processing locations are acceptable under Customer’s applicable laws, policies, procurement rules, and contractual requirements.
- If Customer requires specific data residency, geographic processing, or hosting requirements, such requirements must be agreed to in a separate written agreement signed by the Company.
17) AUDITS AND SECURITY INFORMATION
- Upon reasonable written request, the Company may provide Customer with available security information, policies, summaries, questionnaires, attestations, or documentation reasonably necessary for Customer to assess the Company’s data-processing practices.
- Any security information provided by the Company is Company confidential information and may not be disclosed except as permitted by the Company in writing.
- Customer may not perform penetration testing, vulnerability scanning, security testing, load testing, scraping, probing, or technical assessment of the Platform without the Company’s prior written authorization.
- If Customer requires a formal audit, certification, security review, or third-party assessment beyond standard documentation, such review must be agreed to in writing and may be subject to additional fees, scope limits, confidentiality terms, security controls, and scheduling restrictions.
18) CUSTOMER SECURITY REVIEWS AND PROCUREMENT TERMS
- Customer may request completion of security questionnaires, vendor forms, procurement forms, insurance forms, privacy questionnaires, or similar documentation.
- The Company may complete such materials in its discretion and may charge fees for extensive or custom review requests.
- Customer procurement forms, vendor terms, security forms, purchase order terms, or similar documents do not amend this DPA unless expressly accepted in writing by an authorized representative of the Company.
19) DE-IDENTIFIED AND AGGREGATED DATA
- The Company may create and use aggregated, anonymized, or de-identified data derived from Customer Data, Platform usage, account activity, training activity, technical activity, or operational metadata.
- The Company may use such data for analytics, product improvement, research, benchmarking, reporting, security, performance monitoring, feature development, business planning, and service improvement.
- The Company shall not use aggregated, anonymized, or de-identified data in a manner that reasonably identifies Customer, Authorized Users, or individuals.
20) CUSTOMER USE OF EXPORTS AND DOWNLOADED DATA
- Customer is responsible for all Customer Data exported, downloaded, printed, shared, transferred, stored locally, or otherwise removed from the Platform by Customer or Authorized Users.
- The Company is not responsible for Customer Data after it is exported, downloaded, printed, transmitted, or otherwise controlled outside the Platform by Customer or Authorized Users.
- Customer is responsible for securing exports, reports, certificates, training records, incident data, downloaded files, local copies, screenshots, and other materials removed from the Platform.
21) LIMITATION OF PLATFORM AS RECORDKEEPING SYSTEM
- The Platform may support documentation, reporting, training records, and operational recordkeeping, but it is not intended to serve as Customer’s sole official recordkeeping system unless expressly stated in a separate written agreement.
- Customer is responsible for maintaining official records, backups, retention schedules, legal holds, public-records processes, compliance documentation, training documentation, incident documentation, and other required records.
- Customer is responsible for verifying that any Platform-generated record, export, certificate, report, or transcript satisfies Customer’s legal, regulatory, operational, training, or administrative requirements.
22) COMPLIANCE WITH LAWS
- Each party shall comply with laws applicable to its own performance under this DPA.
- Customer is responsible for laws and requirements applicable to Customer’s use of the Platform, Customer Data, Authorized Users, agency records, public records, training records, incident records, privacy obligations, OPSEC obligations, cybersecurity requirements, procurement rules, and regulatory compliance.
- The Company is responsible for laws applicable to the Company as a provider of the Platform and processor of Customer Data.
- Nothing in this DPA constitutes legal, regulatory, cybersecurity, procurement, records-retention, privacy, tax, safety, training, or compliance advice.
23) INDEMNIFICATION
- Customer agrees to defend, indemnify, and hold harmless the Company, its owners, members, managers, officers, directors, employees, contractors, agents, affiliates, licensors, vendors, service providers, successors, and assigns from and against any claims, demands, actions, losses, liabilities, damages, judgments, settlements, penalties, fines, costs, and expenses, including reasonable attorneys’ fees, arising out of or related to Customer Data, Customer’s instructions, Customer’s use of the Platform, Authorized User activity, unauthorized submissions, improper disclosure, violation of law, violation of privacy rights, violation of OPSEC obligations, public-records obligations, records-retention obligations, or Customer’s breach of this DPA.
- The Company’s indemnification obligations, if any, shall be only as expressly stated in a separate written agreement signed by the Company.
24) LIMITATION OF LIABILITY
- The Company’s liability under this DPA shall be subject to all limitations, exclusions, disclaimers, and liability caps in the Terms of Service and any applicable written agreement.
- In no event shall the Company be liable for indirect, incidental, consequential, special, exemplary, punitive, or enhanced damages, including lost profits, lost data, business interruption, operational disruption, training disruption, incident outcomes, regulatory penalties, reputational harm, or loss of goodwill, except to the extent such limitation is prohibited by law.
25) TERM AND TERMINATION
- This DPA remains in effect while the Company processes Customer Data on behalf of Customer.
- Termination or expiration of Customer’s subscription, order form, agency agreement, enterprise agreement, or access to the Platform shall not immediately terminate provisions of this DPA that by their nature should survive.
- Provisions regarding confidentiality, security, legal process, retention, deletion, aggregated data, exported data, indemnification, limitation of liability, and survival shall survive termination as necessary.
26) CHANGES TO THIS DPA
- The Company may update this DPA from time to time.
- Updated versions may be posted on the Platform, provided by email, displayed in-app, provided through account notices, sent to administrators, or otherwise made available.
- Unless otherwise stated, updated versions become effective when posted or made available.
- Continued use of the Platform after an updated DPA becomes effective constitutes acceptance of the updated DPA unless a separate written agreement provides otherwise.
27) CONTACT INFORMATION
Data processing, security, privacy, legal, or agency-data questions should be directed to:
Hazmat Software LLC
Data Processing Contact: support@hazmathaven.com
Privacy Contact: support@hazmathaven.com
REFUND AND CANCELLATION POLICY
Hazmat Software LLC / Hazmat Toolbox Platform
Effective Date: June 16, 1016
1) INTRODUCTION
- This Refund and Cancellation Policy (“Policy”) governs cancellations, refunds, credits, renewals, subscription changes, trial conversions, account termination, and related billing matters for the Hazmat Toolbox platform, including related websites, mobile applications, web applications, software tools, subscription services, training resources, data services, support services, and related products or services made available by Hazmat Software LLC (“Company,” “we,” “us,” or “our”).
- This Policy applies to individual users, agencies, departments, organizations, enterprise customers, administrators, purchasers, billing contacts, and any other person or entity purchasing, subscribing to, paying for, or using paid access to the Platform (“User,” “you,” or “your”).
- This Policy is incorporated into the Company’s Terms of Service and Subscription and Payment Terms. By purchasing, subscribing to, renewing, accessing, or using a paid Platform plan, User agrees to this Policy.
- If User purchases or manages a subscription on behalf of an agency, department, employer, company, school, government entity, enterprise customer, or other organization, User represents that User is authorized to bind that organization to this Policy.
- If this Policy conflicts with a separate written agreement signed by the Company, the separate written agreement shall control only to the extent of that conflict.
2) GENERAL REFUND RULE
- Unless otherwise required by law or expressly stated in a separate written agreement signed by the Company, all fees are non-refundable once paid.
- Non-refundable fees may include subscription fees, renewal fees, user-license fees, agency fees, enterprise fees, implementation fees, onboarding fees, training fees, support fees, data migration fees, integration fees, storage fees, add-on fees, usage-based fees, custom development fees, administrative fees, and other paid services.
- Failure to use the Platform, lack of usage, user error, failure to cancel before renewal, staffing changes, agency budget changes, internal procurement issues, feature dissatisfaction, or failure to complete assigned training does not entitle User or User’s organization to a refund.
- The Company may, in its discretion, issue refunds, credits, account extensions, service adjustments, or other accommodations on a case-by-case basis.
- Issuing a refund, credit, extension, or accommodation in one instance does not require the Company to do so in any other instance.
3) CANCELLATION OF SUBSCRIPTIONS
- User may cancel a subscription according to the cancellation procedures made available by the Company or stated in the applicable order form, purchase agreement, agency agreement, enterprise agreement, app store terms, or subscription plan.
- Cancellation must be completed before the applicable renewal date to avoid future renewal charges.
- Cancellation stops future renewal charges but does not automatically entitle User or User’s organization to a refund of fees already paid.
- The Company may require cancellation requests to be submitted through the Platform, account dashboard, administrator portal, billing email, written notice, app store subscription settings, or other designated cancellation method.
- Informal communications, support conversations, verbal statements, social media messages, sales communications, lack of usage, failure to log in, failure to assign users, failure to complete onboarding, or failure to use the Platform do not constitute cancellation unless accepted by the Company through the designated cancellation process.
- If User accesses the Platform through an organization, only an authorized administrator, billing contact, procurement contact, account owner, or other approved representative may cancel the organizational subscription unless otherwise permitted by the Company.
4) EFFECTIVE DATE OF CANCELLATION
- Unless otherwise stated in a separate written agreement, cancellation becomes effective at the end of the then-current billing period or subscription term.
- User may continue to have access to paid features through the end of the paid subscription period, unless access is suspended or terminated earlier under the Terms of Service, Acceptable Use Policy, or other applicable terms.
- The Company may terminate access immediately if the account is canceled for violation of Company terms, security risk, misuse, nonpayment, fraud, prohibited activity, or legal risk.
- Cancellation does not relieve User or User’s organization of payment obligations incurred before cancellation.
5) AUTO-RENEWALS
- Unless otherwise stated in a separate written agreement, subscriptions may automatically renew at the end of each billing period or subscription term.
- User is responsible for reviewing renewal dates, billing cycles, renewal notices, payment obligations, cancellation deadlines, and account settings.
- To avoid renewal charges, User must cancel before the renewal date according to the Company’s cancellation procedures.
- Failure to cancel before the renewal date may result in a renewal charge that is non-refundable unless otherwise required by law or expressly approved by the Company.
- Failure to receive, read, notice, or act upon a renewal reminder does not excuse payment if the subscription terms disclose automatic renewal.
6) FREE TRIALS, PILOTS, AND PROMOTIONAL ACCESS
- The Company may offer free trials, pilot access, beta access, promotional pricing, discounted subscriptions, demonstration accounts, or complimentary access.
- Free trials, pilots, promotional access, discounted access, or complimentary access may be modified, restricted, converted, suspended, or discontinued at any time unless otherwise stated in writing.
- If a free trial automatically converts to a paid subscription, the conversion terms will be disclosed at signup, checkout, in the applicable subscription terms, or in a written agreement.
- User is responsible for canceling before the end of the trial period if User does not want the trial to convert to a paid subscription.
- Fees charged after a disclosed trial conversion are non-refundable unless required by law or expressly approved by the Company.
- Trial, pilot, beta, promotional, discounted, or complimentary access may have limited features, reduced support, limited data retention, limited exports, or other restrictions.
7) MONTHLY SUBSCRIPTIONS
- Monthly subscriptions are billed according to the billing cycle selected or assigned at purchase.
- Unless otherwise stated in a separate written agreement, monthly subscription fees are non-refundable once billed.
- Cancellation of a monthly subscription stops future renewal charges but does not provide a refund or prorated credit for the current billing period.
- If User cancels during a monthly billing period, access may continue through the end of that paid billing period unless otherwise terminated under the Terms of Service.
8) ANNUAL OR MULTI-YEAR SUBSCRIPTIONS
- Annual and multi-year subscriptions are purchased for the full stated term.
- Unless otherwise stated in a separate written agreement, annual and multi-year subscription fees are non-refundable once paid.
- Cancellation of an annual or multi-year subscription stops future renewal charges but does not provide a refund or prorated credit for the unused portion of the current subscription term.
- If User cancels during an annual or multi-year term, access may continue through the end of the paid term unless otherwise terminated under the Terms of Service.
- Agency, enterprise, government, municipal, or organizational subscriptions may be subject to separate contract terms, order forms, purchase orders, procurement terms, or budget-cycle requirements, but such documents do not modify this Policy unless accepted in writing by the Company.
9) AGENCY, DEPARTMENT, AND ENTERPRISE ACCOUNTS
- Agency, department, government, municipal, school, enterprise, or organizational accounts may have subscription terms, cancellation requirements, renewal dates, notice periods, payment terms, and refund rules stated in a separate written agreement, order form, purchase agreement, agency agreement, enterprise agreement, or invoice.
- If an organizational account is canceled, individual users under that account may lose access to paid features, organizational data, training records, reports, documents, certificates, administrative tools, and other account materials.
- The organization is responsible for exporting or preserving required records before cancellation, expiration, suspension, downgrade, or termination where Platform functionality permits.
- The Company is not required to provide refunds, prorated refunds, credits, or extensions due to internal agency delays, procurement delays, staffing changes, leadership changes, budget changes, failure to assign users, failure to onboard users, failure to complete training, or lack of usage.
10) UPGRADES, DOWNGRADES, AND PLAN CHANGES
- User may be permitted to upgrade, downgrade, add users, remove users, purchase add-ons, increase storage, add features, or otherwise change subscription plans, subject to Platform functionality and Company approval.
- Upgrades may take effect immediately, and additional fees may be charged immediately or prorated as determined by the Company.
- Downgrades may take effect at the end of the then-current billing cycle or subscription term unless otherwise approved by the Company.
- Downgrading may result in loss of access to features, storage, reports, integrations, administrative tools, training content, data exports, or other Platform functionality.
- The Company is not responsible for loss of functionality, workflow changes, data-access limits, or feature limitations resulting from a downgrade selected by User or User’s organization.
- Fees for add-ons, upgrades, or additional users are non-refundable unless otherwise stated in a separate written agreement.
11) CUSTOM SERVICES AND PROFESSIONAL SERVICES
- Fees for custom development, implementation support, onboarding, consulting, training services, data migration, integrations, reporting customization, enterprise configuration, or other professional services are non-refundable unless expressly stated in a separate written agreement.
- Custom services may require deposits, milestone payments, hourly fees, fixed fees, retainers, or other payment structures.
- Delays caused by User, User’s organization, third-party vendors, missing information, procurement delays, data issues, failure to provide required access, or failure to provide timely feedback do not entitle User to a refund.
- If a custom service project is canceled after work begins, User or User’s organization remains responsible for all fees incurred, work performed, non-cancelable commitments, and expenses through the cancellation date.
12) TRAINING PURCHASES
- Training purchases, course enrollments, training modules, continuing education materials, certificates, instructor resources, student access, and related training products may be subject to separate refund, transfer, or cancellation rules stated at purchase or in a separate written agreement.
- Unless otherwise stated in writing, training fees are non-refundable once access is granted, the course begins, the user enrolls, the user accesses course content, or training materials are made available.
- Failure to complete a course, failure to pass a quiz or assessment, failure to attend, failure to participate, failure to obtain agency credit, or failure to have the course accepted by an employer or authority having jurisdiction does not entitle User to a refund.
- The Company may allow course transfers, substitutions, credits, or extensions in its discretion.
13) APP STORE PURCHASES
- If User purchases a subscription, app, add-on, or other service through the Apple App Store, Google Play Store, or another app marketplace, billing, cancellations, renewals, and refunds may be handled by the applicable app store provider.
- App store terms, payment rules, cancellation procedures, renewal rules, refund rules, and device-account rules may apply.
- The Company may not be able to cancel, refund, modify, or manage subscriptions purchased through an app store unless the app store provider permits such action.
- User is responsible for managing app store subscriptions through the applicable app store account settings where required.
- Requests for refunds for app store purchases may need to be submitted directly to the applicable app store provider.
14) NONPAYMENT AND SUSPENSION
- Failure to pay amounts when due may result in suspension, restriction, downgrade, or termination of access to the Platform.
- The Company may suspend access to paid features, agency tools, administrative functions, training records, reports, exports, support services, integrations, and related services until payment is resolved.
- Suspension for nonpayment does not cancel the subscription unless the Company confirms cancellation or termination in writing.
- Suspension or termination for nonpayment does not relieve User or User’s organization of payment obligations incurred before suspension or termination.
- Overdue amounts may be subject to late fees, interest, collection costs, chargeback fees, reinstatement fees, attorney’s fees, or other costs to the maximum extent permitted by law and any applicable written agreement.
15) CHARGEBACKS AND PAYMENT DISPUTES
- User shall contact the Company promptly regarding suspected billing errors, duplicate charges, unauthorized charges, invoice questions, or payment disputes.
- If User initiates a chargeback, payment reversal, payment dispute, stop payment, or similar action without first attempting to resolve the matter with the Company, the Company may suspend or terminate access to the Platform.
- User remains responsible for all valid amounts owed, including chargeback fees, reversal fees, collection costs, reinstatement fees, and related expenses.
- The Company may correct billing errors and issue credits or refunds where appropriate.
16) REFUND REQUEST PROCESS
- Refund requests must be submitted through the Company’s designated billing contact method.
- User may be required to provide account information, invoice number, transaction date, payment method information, reason for request, administrator authorization, and other information reasonably required to evaluate the request.
- The Company may require verification of identity, account ownership, administrator authority, billing contact status, organizational authorization, or legal authority before reviewing or acting on a refund request.
- Submitting a refund request does not guarantee approval.
- Approved refunds may be issued to the original payment method, applied as account credit, credited to a future invoice, or handled through another method approved by the Company.
- Refund processing times may vary based on payment method, payment processor, bank, app store provider, or administrative requirements.
17) CREDITS AND ACCOUNT ADJUSTMENTS
- The Company may issue account credits, service extensions, partial credits, billing adjustments, or other accommodations in its discretion.
- Credits are not cash refunds unless expressly stated by the Company.
- Credits may expire, may be limited to specific services, and may not be transferable.
- Credits may not be redeemed for cash unless required by law.
- Issuing a credit or adjustment in one instance does not obligate the Company to issue a credit or adjustment in any other instance.
18) DATA ACCESS AFTER CANCELLATION
- Upon cancellation, expiration, suspension, downgrade, or termination, User’s access to Platform features and data may be limited, suspended, or terminated.
- The Company is not required to provide access to User Content, training records, reports, exports, certificates, account history, or other materials after cancellation, expiration, suspension, downgrade, or termination unless required by law or expressly stated in a separate written agreement.
- User or User’s organization is responsible for exporting or preserving required records before cancellation, expiration, suspension, downgrade, or termination where Platform functionality permits.
- The Company may retain, delete, restrict, preserve, or make available data after cancellation or termination according to the Terms of Service, Privacy Policy, Data Processing Addendum, applicable law, records-retention needs, security requirements, billing requirements, dispute-resolution needs, and any separate written agreement.
19) TERMINATION BY THE COMPANY
- The Company may suspend, restrict, disable, downgrade, or terminate access to the Platform as provided in the Terms of Service, Acceptable Use Policy, Subscription and Payment Terms, Agency Account Addendum, or other applicable written agreement.
- If the Company terminates access due to User’s breach, misuse, nonpayment, fraud, prohibited activity, security risk, OPSEC violation, intellectual property violation, or other violation of Company terms, User shall not be entitled to a refund unless required by law or expressly approved by the Company.
- Termination by the Company does not limit the Company’s right to collect amounts owed or pursue available remedies.
20) NO REFUND FOR CERTAIN EVENTS
- Unless otherwise required by law or expressly stated in a separate written agreement, refunds shall not be provided for:
- failure to use the Platform;
- failure to cancel before renewal;
iii. lack of satisfaction with a feature that was available for review before purchase;
- change in agency leadership, staffing, budget, procurement status, or internal priorities;
- inability to use the Platform due to User’s device, browser, network, firewall, app store, operating system, or local technical issue;
- failure to complete onboarding, training, implementation, or account setup;
vii. failure to assign users, invite users, or use purchased licenses;
viii. downtime, maintenance, degraded service, or discontinued features, except where a separate written service-level agreement provides otherwise;
- user error, administrator error, inaccurate account setup, incorrect billing information, or failure to maintain current contact information;
- suspension or termination for breach of Company terms;
- removal, modification, or discontinuation of beta, trial, promotional, or experimental features;
xii. app store purchase restrictions or app store refund decisions; or
xiii. third-party service outages, restrictions, or failures.
21) LEGAL RIGHTS
- Nothing in this Policy limits any refund, cancellation, or consumer protection right that cannot be waived under applicable law.
- If applicable law requires a refund, cancellation period, notice, or other right, the Company will comply to the extent required by law.
- If User is a government entity or public-sector customer with legally required cancellation or appropriation terms, those terms must be stated in a separate written agreement signed by the Company to modify this Policy.
22) RELATIONSHIP TO OTHER TERMS
- This Policy supplements the Company’s Terms of Service, Privacy Policy, Acceptable Use Policy, Subscription and Payment Terms, Agency Account Addendum, Data Processing Addendum, Training Disclaimer and Certification Policy, AI Use Disclaimer, Mobile App End User License Addendum, and any other applicable written agreement.
- If this Policy conflicts with the Subscription and Payment Terms, this Policy shall control only with respect to refund and cancellation procedures.
- If a separate written agreement signed by the Company conflicts with this Policy, the separate written agreement shall control only to the extent of the conflict.
23) CHANGES TO THIS POLICY
- The Company may update this Policy from time to time.
- Updated versions may be posted on the Platform, provided by email, displayed in-app, provided through account notices, or otherwise made available.
- Unless otherwise stated, updated versions become effective when posted or made available.
- Continued purchase, renewal, access, or use of paid Platform services after an updated Policy becomes effective constitutes acceptance of the updated Policy.
24) CONTACT INFORMATION
Refund, cancellation, billing, invoice, or subscription questions should be directed to:
Hazmat Software LLC
Billing / Refund Contact: support@hazmathaven.com
Website: www.hazmathaven.com