1. Who we are and what this covers
1.1. Auditee is a web application for recurring audits and the remediation tasks that follow from them, provided in a SaaS model by Effiware Andrzej Ratajski, a sole proprietorship entered in the Central Registration and Information on Business (CEIDG), place of business ul. Wrocławska 69, 63-200 Jarocin, Poland, REGON 520168139, NIP PL6172221670, e-mail contact@auditee.com ("Effiware", "we", "us").
1.2. These Terms set out the types, scope and conditions of services supplied by electronic means within the meaning of the Polish Act of 18 July 2002 on the provision of services by electronic means, and they apply to:
- the public website at https://auditee.com;
- the registration service at https://auditee.com/register, where a new organization is created and Subscriptions are managed;
- the Auditee application at https://app.auditee.com, or on the domain set in the Order on platinum and uranium;
- support and technical communication channels.
1.3. Auditee is offered to organizations only. It is not addressed to consumers, and there is no self-service consumer sign-up: registration creates an organization account.
1.3a. Sole traders with consumer-style rights. A Customer who is a natural person conducting business and who concludes the Agreement outside their professional specialisation ("przedsiębiorca na prawach konsumenta") may withdraw from the Agreement within 14 days of the Subscription purchase under clause 3.4, without giving a reason, by an unequivocal statement sent to contact@auditee.com. Placing an Order is a request that performance begin immediately: in that case, on withdrawal Effiware retains a part of the Fee proportional to the period during which the Application was made available, and refunds the remainder within 14 days.
1.4. Silver and gold are supplied on these Terms as they stand, through self-service registration and purchase. Platinum and uranium are supplied under an individual agreement negotiated with the Customer.
1.4a. An individual agreement or Order varies these Terms; it does not replace them. Where such a document addresses a matter, it prevails in case of conflict. Where it is silent, these Terms continue to apply in full — including the provisions on intellectual property, confidentiality, acceptable use, liability, complaints and termination.
2. Definitions
| Term | Meaning |
|---|---|
| Application | The Auditee software made available over the internet in a SaaS model; a work within the meaning of the Act of 4 February 1994 on copyright and related rights. |
| Website | https://auditee.com, the public informational site. |
| Customer | The entrepreneur that enters into the Agreement and on whose behalf the Organization is created: a legal person, an organizational unit with legal capacity, or a natural person conducting business. |
| Organization | The Customer's tenant in the Application. One Organization is one tenant. |
| User | A natural person authorised by the Customer to use the Application within the Organization. |
| Roles | Org admin (full read-write across the Organization), Auditor (creates and manages audits and tasks for the teams they manage), Reviewer (approves submitted tasks and sees the audit result), Auditee (fills audits in and works on tasks). Auditor, Reviewer and Auditee are assigned per team. |
| Audit | A structured questionnaire published by the Customer, optionally recurring on a schedule. |
| Round / Assignment | One scheduled occurrence of an Audit, and one person's copy of it. |
| Task | A corrective action with an owner, a deadline, optional evidence and an approval step. |
| Poll | A one-off questionnaire opened with a one-time access Code, always anonymous at storage level. |
| Code | The one-time access credential to a Poll. 32 cryptographically random characters; only a one-way hash is stored. |
| Customer Data | All data the Customer and its Users enter into or generate in the Application: questions, answers, scores, tasks, evidence files, poll answers, history records and Organization configuration. |
| Derived Data | Data Effiware produces from Customer Data on the silver and gold plans by irreversibly removing everything that identifies the Customer, the Organization, its Users or any natural person, and by combining it with other Customers' data, so that it is no longer personal data and does not identify the Customer. Derived Data excludes free-text answers, evidence files and poll answers. |
| Plan | One of silver, gold, platinum, uranium, as described on https://auditee.com/plans and in the Order. |
| Seat unit | The unit in which capacity is sold: 25 Users plus 1 Org admin. |
| Subscription | The paid stage of the Agreement, beginning with the purchase under clause 3.4. |
| Order | The order form, quotation or subscription confirmation setting the Plan, seat count, Fees, billing period and term. |
| Fees | The amounts payable for the Plan under the Order. |
| Maintenance window | A planned, announced interruption for technical work. |
| Force majeure | An extraordinary external event outside Effiware's organization and control, whose consequences could not be prevented — including fire, flood, natural disaster, war, terrorism, acts of public authority, strikes and cyber attack. |
| Privacy Policy | The document at https://auditee.com/privacy, forming part of the Agreement. |
| DPA | The data processing agreement under Art. 28 GDPR, https://auditee.com/dpa. |
| GDPR | Regulation (EU) 2016/679. |
3. Conclusion of the Agreement
3.1. The Agreement is concluded when the Customer's Organization is created following registration, or when the Customer first uses the Application, whichever is earlier. From that moment these Terms, the Privacy Policy and the DPA apply in full, whether or not any Fee has yet been paid.
3.2. A person registering an Organization represents that they are authorised to act for the Customer. Effiware may request evidence of that authority.
3.3. The Agreement begins with a 14-day trial, during which the Application is made available in a scope Effiware determines and no Fees are due.
3.4. A trial requires no payment card and does not convert into a paid subscription automatically. To continue using the Application after the trial, the Customer purchases a subscription through the payment operator named in clause 6.2. That purchase is the Subscription; the Order and the Fees run from it, and so does the withdrawal period in clause 1.3a. Until the purchase is completed no Fees are charged and no payment instrument is held. A trial Organization that has not purchased a Subscription is deleted 30 days after the trial ends; Effiware sends a reminder by e-mail before doing so.
3.5. There is no public registration form inside the Application. Users join an existing Organization by invitation from an Org admin. New Organizations are created only by Effiware: through the registration service referred to in clause 1.2, either by self-service sign-up or on a request sent through its contact form.
4. Accounts, invitations and access
4.1. Access to the Application requires an account. Authentication uses OAuth2 / OpenID Connect against an identity provider operated by Effiware. The Application itself never receives or stores a password; the identity provider stores it only as a salted hash. On platinum and uranium the Customer may connect its own identity provider, in which case Effiware holds no credentials.
4.2. Invitations are valid for at most 72 hours and may be used more than once within that window. Admin-issued sign-in links are single-use and valid for 30 minutes.
4.3. Users in the Auditee role do not need an e-mail address. Org admins, Auditors and Reviewers do, because the Application sends them notifications and, for Org admins, the notices provided for in these Terms.
4.4. The Customer is responsible for deciding who receives access and in which role, for keeping that list current, and for ensuring Users keep their credentials confidential. The Customer must notify Effiware without undue delay of any suspected unauthorised access.
4.5. Accounts are personal and must not be shared. Accounts and the Agreement may not be transferred without Effiware's prior written consent, on pain of invalidity.
4.6. The Customer must provide true, complete and current registration and billing data and update it promptly when it changes. Effiware may verify the data provided.
5. Plans, seats and scope of the Service
5.1. All Plans run the same Application, with the same audits, rules and tasks. Plans differ in the capabilities listed on https://auditee.com/plans and in the Order, in particular:
- silver — no export or download of Organization data. Viewing in the Application is unrestricted and Users always keep their own uploads. Import is included on every Plan;
- gold — adds CSV exports, attachment download, poll results export and print/PDF;
- platinum — a dedicated instance hosted by Effiware: the Customer's own database, identity realm and domain, plus their own SSO or identity provider and self-service organization settings;
- uranium — the same separation on the Customer's own infrastructure, with no seat cap.
5.2. Capacity is sold in Seat units of 25 Users plus 1 Org admin. A pending invitation reserves a seat and a disabled member continues to consume one. Current usage is shown on the billing page.
5.3. Plan capabilities are enforced server-side. Effiware may vary the composition of Plans for future billing periods, subject to clause 17.
5.4. Uranium deployments run on the Customer's own infrastructure, in a location the Customer chooses. Effiware does not host them, does not operate them and does not process Customer Data in them, except during support access under §12 of the DPA; the Customer is the sole controller and operator. Such deployments are governed by a separate licence and deployment agreement, and these Terms apply to them only as far as the nature of an on-premise installation allows.
6. Fees, invoicing and suspension
6.1. Fees and the payment term are set in the Order. The billing period is monthly or annual, as chosen in the Order, unless a separate agreement provides otherwise. Fees are stated net of VAT unless the Order says otherwise.
6.1a. VAT. Effiware invoices from Poland. Customers established in another EU Member State who supply an EU VAT number that Effiware validates in VIES are invoiced without Polish VAT under the reverse charge mechanism. Customers established outside the EU who show that they act as a business, for example with a tax registration number, are invoiced without Polish VAT, as the supply falls outside its scope, and account for any tax due in their own country. In every other case, including Customers established in Poland and EU Customers without a validated number, Polish VAT is added at the applicable rate. The Customer is responsible for supplying valid evidence and keeping it current; where it cannot be validated, Effiware charges Polish VAT.
6.2. Payments are handled by Stripe (Stripe Payments Europe Limited, One Wilton Park, Wilton Place, Dublin 2, D02 FX04, Ireland), the payment operator. Paying for a subscription requires the Customer to accept Stripe's own terms and to enter its payment details directly with Stripe. Effiware never receives or stores payment card numbers.
6.2a. Effiware is not a party to the agreement between the Customer and Stripe, has no influence on its content or performance, and is not liable for the payment service itself. Where a payment fails or is disputed, the Customer should contact Stripe first; Effiware will help clarify the matter where it technically and organizationally can.
6.3. Invoices are issued electronically in PDF. By accepting these Terms the Customer consents to receiving invoices in electronic form within the meaning of the VAT legislation, and undertakes to store them itself.
6.4. On late payment: the Customer keeps full access for 2 days after the due date, with a visible banner in the Application. Within that period the Customer may pay or contact Effiware to agree another arrangement. After it, access may be suspended.
6.5. Suspension does not terminate the Agreement and does not delete Customer Data. Effiware deletes a suspended Organization, with all Customer Data in it, 12 months after suspension, having given the Customer at least 14 days' prior notice by e-mail and an opportunity to request an export under clause 16.4. Payment of the outstanding Fees before the date stated in that notice restores access and the Organization is not deleted.
6.6. Upgrading the Plan or adding seats takes effect immediately upon payment of the additional Fee. Downgrades and reductions take effect from the start of the next billing period.
6.7. Statutory interest for late payment in commercial transactions is due on overdue Fees. Where Fees remain unpaid for 30 days after the due date, Effiware may terminate the Agreement with immediate effect; clause 6.5 then governs deletion.
7. What the Service does, and what it does not do
7.1. The Application supports the Customer in running audits and remediation. It records what the Customer's own people report, and turns failing answers into tasks according to rules the Customer configures.
7.2. The Application does not certify compliance and is not a source of binding legal, technical or safety advice. Scores, pass/fail results, analytics and exports are a record of the Customer's own data, not an assessment by Effiware. Responsibility for the content of audits, for evaluating results and for any decision taken on their basis rests with the Customer.
7.3. Effiware is undergoing certification of its information-security practices and, until it is complete, holds no security or compliance certificate and does not present one. Effiware describes its practices at https://auditee.com/security.
7.4. Anonymity, stated precisely. The Customer acknowledges and undertakes to inform its Users that:
- Anonymous audits are anonymous at display level. The submitter's identity is still stored and is hidden on every read surface in the Application. There is no per-submission drill-in for anyone, including Org admins and Effiware. Alert e-mails, reminders, identity-carrying exports and per-person analytics are structurally unavailable on an anonymous audit. Anyone with direct database access could re-identify a submitter: on silver and gold that is Effiware's authorised personnel, on platinum and uranium also the Customer's own administrators. Polls are different: nothing identifying is stored, so no level of database access reveals a respondent. Effiware does not claim that it fails to record who answered.
- Anonymity is chosen before publication and frozen at publication. Results are withheld until the number of distinct submitters reaches the greater of 5 and 20% of the people assigned.
- Polls are anonymous at storage level. No user identifier, name, e-mail address or IP address is stored with a poll answer, and the link between a Code and the answers given with it is removed on submission or when the Poll closes. Effiware cannot recover a Code. Once a response is submitted, or the Poll closes, no one can link an answer to a person: not the Customer, not Effiware, not an authority. Until then the Code is joined to the draft so the participant can resume it, and an invitation may sit in the outbound mail queue for up to 3 days; after that window the queue can show that a Code was sent to an address, never what was answered with it.
7.5. Records are retained. Submitted answers, scores, task history and evidence captured in a history snapshot are retained so that the audit trail stays meaningful and defensible. Effiware does not promise deletion of submitted answers. Erasure requests are handled as described in §9 of the DPA: on silver and gold, identifying attributes in structured fields are removed or pseudonymised and the record itself is retained, including any free text, photographs and evidence as entered; on platinum, hard deletion is available on written request under the individual contract.
7.6. After an Audit is published, only its name, description, logo and tags can be changed. That constraint is deliberate: it is what makes the audit trail meaningful.
7.7. Features the Application does not have, and which the Customer must not assume: a mobile application, push notifications, a public API, webhooks, third-party integrations, calendar sync, a template catalogue, offline mode.
8. Customer Data
8.1. Customer Data belongs to the Customer. Effiware acquires no ownership of it.
8.2. Effiware processes Customer Data solely in order to provide, secure, support and maintain the Service, on the Customer's documented instructions, and for no other purpose. In particular Effiware does not:
- use Customer Data for its own marketing;
- sell or make Customer Data available to third parties other than the sub-processors listed in the Privacy Policy;
- use Customer Data to train artificial-intelligence models; Derived Data is governed by clause 8.6a.
8.3. Where Customer Data contains personal data, the Customer is the controller and Effiware is the processor. The parties' obligations are set out in the DPA, which forms part of the Agreement.
8.4. The Customer warrants that it is entitled to enter the Customer Data into the Application and to have it processed by Effiware, including that it has satisfied its own information obligations towards its Users and any other data subjects, and that it has a lawful basis for the processing.
8.5. The Customer is solely responsible for the content, lawfulness and accuracy of Customer Data, and for the questions it asks its people. Effiware does not review audit content.
8.6. Effiware may process aggregated, non-identifying technical and usage statistics to operate and improve the Service. Such statistics never contain Customer Data or identify the Customer.
8.6a. On the silver and gold plans the Customer authorises Effiware to produce Derived Data from Customer Data and to use it to improve and develop the Service, including to train artificial-intelligence models. Effiware does not use raw Customer Data for that purpose, does not attempt re-identification, and does not make Derived Data available to third parties other than sub-processors acting on its behalf. The Customer may object to the production of Derived Data at any time by writing to privacy@auditee.com; the objection takes effect for the future and does not cover Derived Data already produced. On the platinum and uranium plans no Derived Data is produced and Customer Data is never used to train models.
9. Availability, maintenance and support
9.1. Effiware will use reasonable efforts to keep the Application continuously available.
9.2. Silver and gold: availability target. Effiware aims for monthly availability of the Application of 99.5%, measured over a calendar month. On these plans this is a target rather than a guaranteed service level: it creates no separate claim, and no service credit or other remedy attaches to a shortfall.
9.2a. Platinum: guaranteed service level. Effiware guarantees monthly availability of 99.5%, measured over a calendar month. Where availability in a calendar month falls below that level, the Customer is entitled to a discount on the next invoice, calculated on the monthly Fee for the affected Plan:
| Availability in the month | Discount |
|---|---|
| below 99.5%, at least 99.0% | 10% |
| below 99.0%, at least 95.0% | 25% |
| below 95.0% | 50% |
9.2aa. The discount is granted on the Customer's request, submitted within 30 days of the end of the month concerned, and is applied to the next invoice issued. Discounts for a single month do not exceed 100% of that month's Fee. On annual billing the discount is calculated on one twelfth of the annual Fee. The discount is the Customer's sole and exclusive remedy for unavailability, and the Order may set different figures for an individual Customer.
9.2b. Uranium. No availability commitment is given: the installation runs on the Customer's own infrastructure under clause 5.4 and is operated by the Customer. Support response times may be agreed in the Order.
9.2c. Clauses 9.2–9.2a do not apply to: force majeure; announced Maintenance windows; disruption caused by the Customer, its Users, its subcontractors or third parties for which Effiware is not responsible; use of the Application contrary to its purpose or to the Agreement; and problems originating in the Customer's own network, devices or software.
9.3. Effiware announces planned Maintenance windows at least 24 hours in advance, together with the expected duration.
9.4. Effiware may issue updates and new versions of the Application without the Customer's consent. Changes will not reduce rights already acquired by the Customer for the paid period.
9.5. Faults may be reported to support@auditee.com or through the contact form. Support is provided by e-mail on business days in Poland. Effiware gives a first reply within 2 business days on silver and gold and within 1 business day on platinum, or within any shorter time set in the Order. A first reply is an acknowledgement with the next step, not a commitment to resolve within that time. On uranium, support is as agreed in the Order.
9.6. Minimum technical requirements: a device with internet access; a current version of Mozilla Firefox, Google Chrome, Microsoft Edge or Safari with JavaScript enabled and the ability to store cookies; an active e-mail address for Users in roles that receive notifications. The management interface is designed for desktop use. Effiware is not liable for the Application failing to work on devices or software that do not meet these requirements.
10. Customer obligations and acceptable use
10.1. The Customer and its Users must use the Application in accordance with the Agreement, the law and good practice, and must not:
- upload or generate content that is unlawful, infringes third-party rights (including copyright, trade secrets and personal data protection), or is defamatory, discriminatory, hateful or terrorist in character;
- upload personal data of third parties without a lawful basis;
- attempt to obtain information about the internal structure or operation of the Application other than from Effiware, or modify, decompile, disassemble or reverse engineer it;
- extract, separate, sub-license, rent, lend or otherwise make the Application available to third parties, or use it to provide a competing service;
- take any action that may impair the correct operation, integrity or security of the Service, including automated access that places a disproportionate load on it;
- circumvent Plan limits, seat limits or permission checks;
- use the Service for advertising or marketing towards other users.
10.2. Uploaded files are validated by inspecting the file itself rather than by trusting the browser, and SVG files are refused everywhere. Maximum file sizes and accepted types are set in the Application.
10.2a. Data the Customer must not enter. The Customer undertakes not to enter into the Application, and to instruct its Users not to enter, data that the audit does not require — and in particular:
- payment card numbers, bank credentials, passwords, API keys or other access credentials;
- government identification numbers, or scans and photographs of identity documents;
- personal data of third parties who are not participants in the audit, unless the Customer has a lawful basis for processing it;
- personal data, and in particular special categories of data within the meaning of Art. 9 GDPR, in free-text answers, photographs, signatures and uploaded evidence beyond what the audit requires.
10.2b. What the Customer must tell its people, and why it matters on silver and gold. The Customer is responsible for instructing its Users on clause 10.2a before giving them access. On the silver and gold plans, erasure reaches identifying attributes in structured fields only: free-text answers, photographs, signatures and uploaded documents are retained as entered and cannot be individually deleted on those plans. Where the Customer needs deletion to reach that content, the platinum and uranium plans provide it. This is set out in full in §9 of the DPA.
10.2c. Effiware does not monitor, review or moderate the content of audits, answers or evidence, and does not filter what is entered. Responsibility for that content rests with the Customer under clause 8.5, and the indemnity in clause 14.7 applies to it.
10.2d. Clauses 10.2a–10.2c allocate responsibility between the Customer and Effiware. They do not reduce Effiware's own obligations as a processor under the DPA and Arts. 28, 32 and 33 GDPR, and they do not affect any right a data subject has under Art. 82 GDPR.
10.3. The Customer undertakes to grant access only to appropriately authorised and informed people within its organization, to access the Service over secure channels, and to report any irregularity or security incident to Effiware without undue delay.
10.4. In the event of a material or repeated breach, Effiware may — applying proportionality and with prior warning where circumstances allow — restrict or block access to the Service, to the Organization or to particular content, and in the case of a gross breach terminate the Agreement with immediate effect.
11. Intellectual property
11.1. The Application, the Website and all materials made available by Effiware (text, graphics, trademarks, logotypes, documentation) are protected works. Effiware or its licensors hold all rights to them.
11.2. For the term of the Agreement and to the extent of the Plan purchased, Effiware grants the Customer a non-exclusive, non-transferable, non-sublicensable right to use the Application for the Customer's own internal purposes. No other rights are granted.
11.3. The Customer grants Effiware a licence to Customer Data limited to what is necessary to provide the Service under clause 8.2, lasting as long as the Service is provided. On the silver and gold plans the licence also covers producing and using Derived Data under clause 8.6a, without limit in time.
11.4. Use of Effiware's or Auditee's marks requires prior consent.
11.5. Effiware does not name the Customer, display its logo or quote it publicly as a reference without the Customer's prior, separate written consent. Such consent is given for a specific use, is not part of the Agreement, and may be withdrawn at any time by notice, after which Effiware removes the material within a reasonable period.
12. Confidentiality
12.1. Each party undertakes to keep confidential the other party's information obtained in connection with the Agreement and not publicly known, and to use it only for the purpose of the Agreement.
12.2. The obligation does not cover information that is publicly available, was lawfully known before disclosure, or must be disclosed under a legal obligation or an order of a competent authority. Derived Data is not confidential information of the Customer.
12.3. The obligation survives termination of the Agreement for:
- 1 year on the silver and gold plans;
- 3 years on the platinum and uranium plans.
12.4. Clause 12.3 does not limit the protection of trade secrets within the meaning of Art. 11(2) of the Act of 16 April 1993 on combating unfair competition. Information meeting that definition — in particular Effiware's source code, architecture and security arrangements, and the Customer's non-public commercial and operational information — remains protected for as long as it retains that character, regardless of the periods in clause 12.3.
12.5. Personal data is not governed by this section. It is governed by the Privacy Policy and the DPA, and the periods in clause 12.3 do not shorten any obligation arising under the GDPR.
13. Warranties and disclaimers
13.1. The Application is provided in the state in which it is. Adapting it to the Customer's individual needs is a separate service not covered by these Terms.
13.2. Effiware warrants that the Service will be provided with due professional care and substantially as described in the documentation and on the Website.
13.3. Beyond clause 13.2, and to the extent permitted by law, Effiware gives no other warranty, in particular no warranty that the Service will be uninterrupted, error-free, or fit for a purpose the Customer has not communicated. Statutory warranty for defects (rękojmia) is excluded to the extent permitted between businesses. This exclusion does not apply to Customers under clause 1.3a, whose rights in respect of conformity of the Service are governed by mandatory law.
14. Liability
14.1. To the fullest extent permitted by law, Effiware's liability for non-performance or improper performance of the Agreement is limited to damage caused through its fault, limited to actual loss and excluding lost profits, loss of business, loss of anticipated savings and any indirect or consequential damage. Loss of Customer Data is direct damage subject to the cap in clause 14.2.
14.2. To the fullest extent permitted by law, Effiware's total liability arising from or in connection with the Agreement, from all events in any 12-month period taken together, is limited to the total Fees paid by the Customer in the 12 months preceding the event giving rise to the claim.
14.3. The limitations in clauses 14.1–14.2 do not apply to damage caused intentionally, and do not apply where liability cannot be limited or excluded by mandatory law.
14.4. No carve-outs beyond clause 14.3 apply. Any further exception to the cap is a matter for individual negotiation and, if agreed, is recorded in the Order.
14.5. Effiware is not liable for: the consequences of the Customer disclosing credentials; the consequences of untrue data provided by the Customer; the operation of third-party telecommunications networks, operating systems or devices; content entered by the Customer or its Users; or decisions the Customer takes on the basis of audit results.
14.6. Effiware is not liable for temporary unavailability caused by an announced Maintenance window or by force majeure, and is not obliged to refund Fees or grant credits in such cases, except as provided by an SLA under clause 9.2.
14.7. The Customer indemnifies Effiware against third-party claims arising from Customer Data or from use of the Service in breach of the Agreement.
15. Complaints, notices and the contact point
15.1. Complaints. The Customer may submit a complaint about non-performance or improper performance of the Service free of charge, to support@auditee.com, and should do so within 30 days of the event. Effiware handles later complaints as far as its records still allow; this does not affect the Customer's statutory claims. The complaint should identify the Customer, describe the problem with the date and time of occurrence, and state what the Customer expects. Effiware responds within 14 days of receipt, or, in particularly complex cases, within a longer period notified by e-mail before the 14 days expire.
15.2. Illegal content (DSA). Effiware counteracts the dissemination of illegal content in accordance with Regulation (EU) 2022/2065 (Digital Services Act) and Regulation (EU) 2021/784. Reports may be sent to contact@auditee.com and should contain: a sufficiently substantiated explanation of why the content is considered illegal; a clear indication of its exact electronic location; the reporting party's details, unless the report concerns content covered by Art. 16(2) DSA; and a statement of good faith as to the accuracy and completeness of the report.
15.3. In response to a report, Effiware may decide to remove content, disable or restrict access to it, suspend or terminate the Service in whole or in part, or suspend, restrict or remove the Organization's account. Effiware informs the reporting party and the affected Customer of the decision and its reasons.
15.4. Internal complaint-handling system. For six months from notification of a decision under clause 15.3, the affected party may lodge a free electronic appeal to contact@auditee.com. A justified appeal results in the decision being reversed without undue delay. Parties also retain the right to use an out-of-court dispute settlement body certified by the Digital Services Coordinator.
15.5. Contact point. Effiware designates contact@auditee.com as its electronic contact point for Users, for authorities of EU Member States, for the European Commission and for the European Board for Digital Services.
15.6. Security reports are handled as described at https://auditee.com/.well-known/security.txt.
16. Term, termination and exit
16.1. The Agreement is concluded for the period stated in the Order and is renewed for successive billing periods unless terminated by either party at least 2 days before the end of the current billing period. This applies to monthly and annual billing alike on the silver and gold plans. On the platinum and uranium plans the notice period is the one set in the Order. Before an annual billing period renews, Effiware sends a reminder by e-mail at least 14 days in advance.
16.1a. The date on which the next payment falls due is shown in the Application at all times. Late payment is governed by clauses 6.4 to 6.7.
16.2. Either party may terminate the Agreement with immediate effect if the other party materially breaches it and fails to remedy the breach within 14 days of a written demand.
16.3. Termination does not entitle the Customer to a refund of Fees paid for the current billing period, except where termination results from Effiware's material breach.
16.4. Exit. For 30 days after the Agreement ends, Effiware will, on the Customer's written request, make the Customer's data available for export. This includes Customers on the silver plan, for whom Effiware performs a one-off export on request even though the plan itself has no export capability. After that period Effiware deletes the Organization and all Customer Data, subject to the 14-day backup window described in the DPA and to any retention required by law. Deletion does not extend to Derived Data, which identifies neither the Customer nor any person. Where the Agreement ends through non-payment, clause 6.5 applies instead and deletion takes place 12 months after suspension.
17. Changes to the Terms
17.1. Effiware informs Customers of changes to these Terms by notice in the Application and by e-mail to the address held for the Organization.
17.2. Changes take effect no earlier than 15 days after notification, unless the law provides otherwise. A shorter period, including immediate effect, applies where the change follows from a legal or regulatory obligation that cannot be met within 15 days, or is necessary to counter a threat to the security of the service, to protect against fraud, malware, spam, a data breach or another cyber-security risk.
17.3. If the Customer does not accept the change, it may terminate the Agreement before it takes effect. Continued use of the Service after the change takes effect constitutes acceptance.
17.4. The current version of these Terms is always available on the Website and can be saved or printed.
18. Final provisions
18.1. The Agreement is governed by Polish law.
18.2. Disputes are submitted to the Polish court having jurisdiction over Effiware's place of business in Jarocin. This clause does not apply to Customers under clause 1.3a; for them the competent court is determined by the general rules.
18.3. These Terms are drawn up in Polish and published together with an English translation. In case of discrepancy, the Polish version prevails. The remaining interface languages of the Website are not translations of these Terms.
18.4. If any provision is invalid, the remainder stays in force and the invalid provision is replaced by the closest lawful provision reflecting the parties' intent.
18.5. Annexes: Annex 1 — Plans and capabilities (https://auditee.com/plans); Annex 2 — Privacy Policy; Annex 3 — DPA.