Skip to main content

Terms of service

The agreement between Permenta and the businesses that use it. Written in plain English on purpose; the numbered sections are the contract.

Last updated .

1. Who we are and what these terms cover

These terms of service (the “Terms”) govern the use of Permenta, the product-security record and Cyber Resilience Act workspace available at permenta.com and app.permenta.com (the “Service”). The Service is operated by:

Legal name
Patchgate, LLC
Address
651 N Broad St, Suite 201Middletown, DE 19709United States

The Service is offered to businesses, public bodies and professionals acting in the course of their trade or profession. By creating an account or a workspace you confirm that you act in that capacity and that you are authorised to bind the organisation you register (the “Customer”, “you”). These Terms, the Privacy policy, the Data processing agreement and the plan you choose on the Pricing page form the whole agreement between you and us. Where they conflict, the Data processing agreement prevails for personal data and these Terms prevail otherwise.

2. What the Service is, and what it is not

Permenta provides tooling and record-keeping for manufacturers of products with digital elements: a product registry, a scope questionnaire, obligation checklists generated from a versioned catalogue of the Regulation’s text, a reporting desk for Article 14 notifications, software-bill-of-materials and vulnerability tracking, document drafting, public trust pages and an append-only evidence ledger.

Permenta does not assess, certify or guarantee that any product, process or organisation complies with Regulation (EU) 2024/2847 or any other law. Scope results, obligation lists, deadlines, generated documents and guidance are informational aids and editable drafts. You remain solely responsible for your own compliance, for the content and timing of anything you submit to an authority, and for every decision you take on the basis of the Service. Nothing in the Service or on this site is legal advice.

We may add, change or retire features. Where a change removes material functionality from a paid plan, we give at least 30 days’ notice by email to workspace owners. Features marked as preview or beta may change or disappear without notice.

3. Accounts, workspaces and members

  • Registration details must be accurate and kept up to date; we may require email verification before an account can be used.
  • You are responsible for keeping credentials confidential. Passkeys and one-time codes are available to every account and we recommend them for owners and admins.
  • A workspace owner decides who joins the workspace and with which role (owner, admin, member or viewer). You are responsible for everything done in your workspace by the people you admit, including through API keys they create.
  • If you suspect that an account, an API key or a share link has been compromised, tell us at security@permenta.com without delay and revoke what you can.

4. Acceptable use

You agree not to, and not to allow others to:

  • use the Service in breach of applicable law or of the rights of others;
  • probe, scan or test the Service for vulnerabilities except under our coordinated vulnerability disclosure policy, or interfere with its operation or with other customers’ workspaces;
  • upload content you have no right to process, or malicious code, except vulnerability and component data that the Service exists to record;
  • circumvent plan limits, rate limits or access controls, or resell or sublicense the Service, except that the agency workspaces of the Scale plan may be used for your own clients;
  • represent a trust page, an export or any other output of the Service as a certification, approval or endorsement by Permenta.

We may suspend access to a workspace that breaches this section. Where practicable we give notice first and restore access once the breach is remedied.

5. Plans, fees and payment

  • The Free plan is free of charge for as long as we offer it. Paid plans, their limits and their prices are described on the Pricing page at the time you subscribe; the limits are also enforced by the Service itself.
  • Prices exclude VAT and any other tax. Tax is calculated at checkout from the billing address and VAT identification number you provide, and you are responsible for their accuracy. Reverse charge is applied where the law provides for it.
  • Payment is collected by our payment processor, Stripe, by card or another method it offers. Paid plans begin with a 14-day trial once per workspace; a valid payment method is required to start it and the first charge is made when the trial ends unless you cancel before.
  • Subscriptions renew automatically for successive monthly or annual periods until cancelled. Invoices are issued electronically and are available in the workspace.
  • If a payment fails, your plan continues for 14 days while payment is retried; after that the workspace is limited to the Free plan until payment succeeds or the subscription ends. Existing records are never deleted for non-payment.
  • We may change prices with at least 30 days’ notice by email. A change applies from the next renewal after the notice period; if you do not accept it you may cancel before the renewal.
  • Fees paid for a billing period are not refunded for unused time, except where the law requires a refund.

6. Cancellation, downgrade and termination

  • You may cancel a paid plan at any time from Billing settings. The cancellation takes effect at the end of the billing period already paid for; the workspace then continues on the Free plan.
  • A downgrade never deletes data. Plan limits only gate the creation of new products, members and uploads; what is already recorded stays readable and exportable.
  • Either party may terminate the agreement for a material breach that is not remedied within 14 days of written notice, and we may terminate immediately in the case of serious abuse, unlawful content or a threat to the security of the Service or of other customers.
  • A workspace owner may delete the workspace at any time; deletion is explicit and is confirmed in the Service.
  • After the agreement ends or a workspace is deleted, its records remain exportable for 30 days. We then delete them from the live systems; copies in backups expire within a further 35 days. We keep invoices and other records that the law requires us to retain, and the Privacy policy describes the periods that apply to personal data.

7. Your content and your data

Everything you put into the Service, including product data, software bills of materials, vulnerability information, reports, documents and the statements on your trust pages (“Customer Content”), remains yours. You grant us the non-exclusive right to host, process, back up, transmit and display Customer Content to the extent needed to provide the Service to you and to the people you share it with, and for no other purpose.

We treat Customer Content as confidential. We do not sell it, use it for advertising, or use it to train machine-learning models. Personal data within Customer Content is processed on your behalf under the Data processing agreement; personal data about your users and billing is described in the Privacy policy.

You confirm that you have the rights needed to submit Customer Content, that it does not infringe the rights of others and that any personal data in it is processed lawfully.

8. Public trust pages and share links

A trust page is public only once you publish it, and you can unpublish it at any time. A share link opens part of your record to whoever holds the link until it expires or you revoke it. What these pages show are your statements about your products; they are neither reviewed nor endorsed by Permenta, and the pages say so.

You are responsible for the accuracy of what you publish, for keeping it current, and for any commitment you make in it, such as a support period or a security contact.

9. Intellectual property

The Service, its software, design, documentation and the paraphrases and guidance in our regulatory catalogues are protected by intellectual property rights and remain ours or our licensors’. The legal texts the catalogues quote are public documents of the European Union. Open-source components in the Service are licensed under their own terms. Exports you make of your own Customer Content are yours to keep and use.

If you send us suggestions or feedback, we may use them without obligation to you. These Terms do not transfer any rights other than those stated in them.

10. Confidentiality

Each party will keep confidential the information the other party marks as confidential or that a reasonable person would understand to be confidential, use it only to perform this agreement, and protect it with at least the care it applies to its own confidential information. This obligation does not apply to information that is or becomes public without breach, that the receiving party already knew, or that must be disclosed by law or by order of a court or authority, in which case the receiving party will, where lawful, inform the other party first.

11. Warranties and disclaimers

We provide the Service with reasonable skill and care and work to keep it available and secure, as described on our Security page. Unless we have agreed a service level in writing, the Service is provided as it is and as it is available.

To the extent the law allows, we make no other warranty. In particular we do not warrant that the Service is free from error, that vulnerability feeds, catalogue texts and other third-party sources are complete or current, that a deadline computed by the Service matches an authority’s view, or that using the Service will make any product or organisation compliant with any law. Statutory rights that cannot be excluded are not affected.

12. Liability

Our total liability for all claims arising out of or in connection with this agreement in any twelve-month period is limited to the fees you paid us for the Service in the twelve months before the event giving rise to the claim. We are not liable for loss of profit, loss of business, loss of data that you could reasonably have backed up through the export functions, or indirect or consequential loss.

These limits do not apply to liability for intent or gross negligence, for death or personal injury, for breach of an essential contractual obligation to the extent of the damage that was foreseeable when the agreement was made, under product liability law, or where the law does not allow liability to be limited.

You will indemnify us against third-party claims and reasonable costs arising from Customer Content or from your use of the Service in breach of these Terms, provided we inform you of the claim promptly and let you control its defence.

13. Changes to these Terms

We may change these Terms. We announce material changes at least 30 days before they take effect by email to workspace owners and by a notice in the Service. If you do not agree to a change you may terminate the agreement before it takes effect; continuing to use the Service afterwards means you accept it. Changes required by law or that only add functionality may take effect immediately.

14. Governing law, jurisdiction and general provisions

Governing law and place of jurisdiction
the laws of the State of Delaware, United States; the state and federal courts located in Delaware

This agreement is written in English. If a provision is invalid, the rest remains in force and the invalid provision is replaced by a valid one that comes closest to its purpose. Neither party may assign the agreement without the other’s consent, except to a successor of its business who assumes it in full. Notices to us go to the addresses in section 1; notices to you go to the email address of the workspace owners.

15. Contact

Questions about these Terms: hello@permenta.com. Security reports: security@permenta.com. Privacy: privacy@permenta.com.

Operated by Patchgate, LLC. See the Imprint for the full company details.