Terms of service
Last updated
Acceptance
By using Get Frank you accept these terms on behalf of the organisation you represent. If you do not have authority to do so, do not use the service.
What the service is
Get Frank is an assurance posture system — a system of record for time-bounded confidence claims. It is not a certifying body. It does not issue certificates. It does not guarantee compliance with any framework or regulation. The service surfaces what is true and what is assumed; the responsibility for acting on that truth remains yours.
What the service is not
The service is not legal advice, audit advice, or a substitute for qualified professional review. Outputs are designed to be defensible — that is, traceable to evidence, scope, and known limitations — but defensibility is not the same as a regulatory pass.
Acceptable use
You will not use the service to mislead a board, regulator, customer, or auditor. We reserve the right to terminate any account used to manufacture appearances of compliance that are not supported by evidence.
You also will not misuse the service — including attempting to gain unauthorised access to it or to another customer’s data, interfering with its security or availability, probing or scanning it without our written consent, or using it for any unlawful purpose. We may investigate suspected abuse and suspend or terminate access to protect the service and its users.
Fees
Fees are charged for active scopes under assurance and additive projections beyond the baseline, in line with our published pricing. Paid plans may be subject to a separate signed agreement that overrides this section. We do not charge per user. We do not meter activity. Honest self-reporting does not increase fees.
Your data
Your data stays yours. You keep every right you hold in the files, records, and content your organisation puts into the service. You grant us only the licence we need to host, process, and display that content in order to deliver the service to you, keep it secure, and meet our legal obligations.
What you upload can carry personal information about people who are not our users — a supplier’s contact, the owner of a risk, the person an incident concerns. That information is yours to account for. You confirm that you are entitled to supply it to us, and that those people have been given whatever notice the law requires them to have; our privacy notice sets out what they can expect of us and directs them back to you. Where one of them asks us for access or correction, we will tell them you hold the record and let you know they asked.
Do not upload sensitive information as the Privacy Act 1988 (Cth) defines it. The service is not built to hold it. Where it reaches us regardless, tell us and we will remove it from working data.
We do not sell your data. We do not use it to train machine-learning models, and we do not use one customer’s content to build or improve anything for another. Where we measure how the service is used — which features get used, where things fail, how long work takes — those measurements come from application events rather than from the content you upload, and we use them to improve the service for everyone who uses it. They are aggregated, and they identify neither you nor your organisation.
Our intellectual property
The service — the software, the assurance model it implements, the interface, the design system, and the documentation — remains ours or our licensors’. These terms give you the right to use the service, not any ownership of it. You will not copy it, reverse-engineer it, or build derivative works from it, except where the law gives you that right despite this clause.
What the service produces from your data — your posture records, decisions, claims, and exports — is yours to use as you see fit, including with your auditors, customers, and regulators. Where an output carries material that is ours or a third party’s, such as framework text or the structure of the assurance model itself, you get the right to use that material as part of the output. Ownership of it does not pass to you, and it stays subject to the section above.
If you send us feedback or suggestions, you give us a perpetual, worldwide, royalty-free licence to use them to improve the service, with no obligation or payment to you. That covers the idea, not your data: where feedback carries your files or records, those remain governed by Your data above.
Retention, backups, and your own records
Frank references your systems of record; it does not become one. The contents of a file you upload are a transit artefact: we hold them so ingestion can be replayed without asking you to resubmit everything. Once your configured retention window passes — 30 days by default, 365 at the most — they become eligible for removal and are erased by a cleanup that runs daily. The record of the upload, including its name, size, content hash, and column mapping, is part of your assurance history and is kept. Keep your own copy of every source file; the service is not a store for it.
Erasure removes data from the service’s active storage. Copies in database backups persist until the backup expires, on the terms set out in our privacy notice. We give no warranty that data can be recovered from a backup: restoration is a recovery measure for us, not an export route for you.
Termination
Either party may terminate for material breach with reasonable notice. On termination, you may export your assurance records for 30 days from the date termination takes effect. We delete or de-identify what we hold within 30 days of that window closing, subject to backup expiry and to anything we are required by law to keep.
Liability
To the extent permitted by law, our aggregate liability is limited to the fees paid in the 12 months preceding the claim, or AUD 1 if no fees have been paid. Nothing in these terms excludes liability that cannot lawfully be excluded.
Governing law
These terms are governed by the laws of Queensland, Australia. Disputes are subject to the exclusive jurisdiction of the courts of Queensland, Australia.
— Get Frank