Please read these Terms carefully. They explain the rules for using our website and portals, your responsibilities and ours, and how electronic acceptances and records work.
1About these terms and who we are
These Terms and Conditions (the “Terms”) govern your access to and use of the website at ciso.com.sa and every portal reached through it — the client portal, the partner portal, the expert portal and the candidate portal — together with any related service, page, file or communication we make available (together, the “Site”).
The Site is operated by CISO Consulting Company for Cybersecurity, a limited liability company registered in the Kingdom of Saudi Arabia under Commercial Registration No. 7053022526, with its head office in Riyadh, trading as “CISO Consulting” (“CISO Consulting”, “we”, “us”, “our”).
By opening an account, signing in, submitting a form, uploading a file or otherwise using the Site, you confirm that you have read, understood and accepted these Terms. If you do not accept them, you must not use the Site.
2Definitions
In these Terms:
- “Account” means the access issued to an organization or person to use a portal, including every user created under it.
- “Client” means an organization that has accepted our services agreement, a proposal or an order; “Client User” means a person the Client authorizes to use the client portal on its behalf.
- “Partner” means an organization admitted to our partner program; “Expert” means an individual or firm engaged to deliver services with or for us; “Candidate” means a person who applies for a role or is put forward for one.
- “Content” means any information, document, file, message, evidence, data or material uploaded to, submitted through or generated on the Site.
- “Services” means the consulting, advisory, assessment, managed, staffing and other services we provide under a Services Agreement.
- “Services Agreement” means the master services agreement, data processing annex, statement of work, proposal, order, work order or other signed or electronically accepted contract governing particular Services.
3Other agreements and order of precedence
Services are provided only under a Services Agreement. These Terms govern use of the Site; they do not by themselves create an obligation on us to provide any Service.
If these Terms conflict with a Services Agreement, the Services Agreement prevails for the Services it covers. Within a Services Agreement, the order of precedence stated in it applies. A non-disclosure agreement between you and us prevails over these Terms on confidentiality.
4Eligibility and authority
You must be at least eighteen years old and legally able to enter into binding obligations to use the Site. If you use the Site on behalf of an organization, you confirm that you are authorized to bind it, and that organization is responsible for your use of the Site.
Certain actions — accepting a proposal, signing an agreement, approving minutes or deliverables, requesting the termination of Services or managing users — require authority. The portal records who acted and in what capacity; you must not take an action you are not authorized to take.
5Accounts, access and security
Accounts are personal to the user they are issued to. You must keep your credentials and one-time codes confidential, use multi-factor authentication where we require or offer it, and sign out on shared devices. You must not share an account or let anyone else use your session.
Tell us immediately at info@ciso.com.sa, or through the portal, if you suspect unauthorized access to your account or any Content. We may require identity verification (including through Nafath), new credentials, or temporarily restrict access to protect you, other users or the Site.
Client account owners are responsible for adding and removing their users, assigning permissions that fit each user’s role, and removing access promptly when a person leaves or changes role. Access is reviewed periodically and inactive or expired access may be suspended.
6Roles in the portals
- Clients and Client Users see only their own organization’s engagements, projects, documents, invoices and records, according to the permissions their account owner assigns.
- Partners see only the opportunities, work orders, workstreams and statements that concern them. Partners must not contact our clients about our engagements except as their work order allows.
- Experts see only the projects and tasks they are assigned to, for the period of the assignment. Client information made available to an Expert may be used only to perform that assignment.
- Candidates see only their own applications, offers, onboarding steps and documents. A client receives a candidate’s details only as described in our Privacy Policy and with the candidate’s consent where required.
Access in every role ends when the relationship, assignment or account ends, and may be limited earlier where these Terms or a Services Agreement allow.
7Acceptable use
You must not, and must not allow anyone to:
- access or attempt to access any account, record or system you are not authorized to use, or test, scan or probe the Site’s security without our written permission;
- upload malicious code, or Content that is unlawful, infringing, defamatory, misleading or that you have no right to share;
- interfere with the Site’s operation, overload it, scrape or harvest data from it, or circumvent any limit, control or security measure;
- use the Site to send unsolicited communications, impersonate any person, or misrepresent your affiliation or authority;
- copy, resell or make the Site or its non-public content available to any third party, or use it to build a competing product;
- use the Site in breach of any law of the Kingdom of Saudi Arabia, including the Anti-Cyber Crime Law and the Personal Data Protection Law.
Security researchers who find a vulnerability should report it to info@ciso.com.sa and give us reasonable time to fix it before any disclosure.
8Your content and uploads
You keep ownership of the Content you upload. You grant us a non-exclusive licence to host, store, copy, process and display it only as needed to operate the Site, provide the Services, comply with law and keep the records described in our Privacy Policy.
You confirm that you have the right to upload each item of Content and that doing so does not breach any law, contract or third-party right. Files are scanned and may be rejected, quarantined or removed if they appear unsafe or in breach of these Terms.
Keep your own copies of anything you need. Content is retained and deleted according to the applicable Services Agreement, our retention schedule and the law; deleting an item in the portal may not remove copies we are legally required to keep.
9Confidentiality
Information marked confidential, or that a reasonable person would understand to be confidential — including information about a client’s systems, controls, findings, risks, personnel and commercial terms — must be kept confidential, used only for the purpose for which it was shared and protected with at least reasonable care.
Where a non-disclosure agreement or Services Agreement applies, its confidentiality terms govern. Obligations of confidentiality survive the end of your use of the Site.
10Personal data
We process personal data in accordance with the Personal Data Protection Law and its Implementing Regulations, as described in our Privacy Policy at ciso.com.sa/privacy-policy. Where we process personal data on a client’s behalf in delivering Services, the data processing annex to the Services Agreement applies.
If you upload personal data about other people, you confirm that you are entitled to do so and that they have been informed as the law requires.
11Electronic transactions, signatures and records
Under the Electronic Transactions Law, you agree that agreements, acceptances, approvals, notices and other communications may be made electronically through the Site and have the same effect as if made in writing and signed.
When you accept a proposal or agreement, approve minutes or deliverables, sign a document or submit a request in the portal, we record your name, title, the time, your network address, the method of verification used (such as a one-time code or Nafath) and a fingerprint of the exact version you acted on. These records are evidence of the action and of its content.
12Proposals, orders and acceptance
A proposal is an offer open for acceptance until its stated validity date. It is accepted only when an authorized person of the client accepts it through the portal or in writing, choosing an option where options are offered. A proposal that changes after it was sent cannot be accepted until a new version is issued.
Accepting a proposal forms a contract on the terms of the proposal, the Services Agreement and the documents it incorporates. Work starts in accordance with those terms, which may require a purchase order or an advance payment first.
13Fees, invoices and taxes
Fees are those stated in the accepted proposal or Services Agreement. Unless stated otherwise, amounts are in Saudi Riyals and exclude Value Added Tax, which is charged at the applicable rate.
We issue tax invoices electronically in accordance with the requirements of the Zakat, Tax and Customs Authority (ZATCA). Invoices are payable within the period stated in the Services Agreement. If an invoice is disputed in good faith, raise the dispute through the portal before its due date and pay any undisputed part on time.
Late payment, suspension for non-payment and any other financial consequences are governed by the Services Agreement.
14Intellectual property
The Site, its software, design, text, graphics, logos, templates, methodologies and the CISO Consulting name and marks belong to us or our licensors and are protected by law. You receive only a limited, revocable, non-transferable right to use the Site for its intended purpose under these Terms.
Ownership and licensing of deliverables produced in delivering Services are governed by the Services Agreement. Nothing on the Site transfers any of our intellectual property to you.
15Public information is not professional advice
Articles, guides, framework summaries, tools and other public material on the Site are general information about cybersecurity, data protection and regulation. They are not legal, regulatory or professional advice for your circumstances, may not reflect the latest regulatory changes, and must not be relied on in place of advice under a Services Agreement. Regulators’ own publications prevail.
16Third-party services and links
The Site uses third-party services such as identity verification, payment processing, electronic invoicing, messaging and hosting, and may link to other websites. Their use is subject to their own terms. We are not responsible for websites we do not control, and a link is not an endorsement.
17Availability, maintenance and changes to the Site
We aim to keep the Site available and secure, but it is provided on an “as available” basis. It may be interrupted for maintenance, security measures or events outside our control. Service levels, where agreed, are set in the Services Agreement.
We may change, add or withdraw features of the Site. Where a change materially reduces a function a Client relies on under a Services Agreement, we will give reasonable notice.
18Suspension and termination of access
We may suspend or end access to the Site, in whole or in part, if you breach these Terms, if required by law or by a competent authority, to protect the security of the Site or of any person, or when the relationship under which access was given ends.
Termination of Services is governed by the Services Agreement. A Client may request termination through the client portal; such a request must be made by an authorized person and is handled according to the Services Agreement, including notice periods, work completed, handover and settlement. Ending access to the Site does not end obligations that by their nature survive, including confidentiality, payment and records.
19Disclaimer
To the extent permitted by law, the Site and public material are provided without warranties of any kind, express or implied, including fitness for a particular purpose, accuracy or uninterrupted availability. Warranties for Services are only those stated in the Services Agreement.
20Limitation of liability
To the extent permitted by law, we are not liable for any indirect or consequential loss, loss of profit, revenue, data or goodwill arising from use of the Site. Our total liability arising from use of the Site, other than under a Services Agreement, is limited to one thousand Saudi Riyals. Liability in connection with Services is governed exclusively by the Services Agreement.
Nothing in these Terms limits liability that cannot be limited under the laws of the Kingdom of Saudi Arabia, including liability for fraud or wilful misconduct.
21Indemnity
You will compensate us for loss, damage and reasonable costs arising from your breach of these Terms, your unlawful use of the Site, or Content you upload in breach of these Terms, to the extent caused by you.
22Integrity, anti-bribery and independence
We do not offer, give, request or accept bribes or improper advantages, and we expect the same of everyone using the Site. We act independently: we do not sell security products and do not accept payments from vendors for recommending them. Report any concern about integrity to info@ciso.com.sa; reports are handled confidentially and without retaliation.
23Complaints
If you are dissatisfied with the Site or our Services, raise a complaint through the client portal (Complaints) or write to info@ciso.com.sa. We acknowledge complaints, investigate them fairly, and give a reasoned decision within the timeframes shown in the portal. You may appeal a decision once. This does not affect any right you have under the law.
24Force majeure
Neither party is responsible for failure or delay caused by events beyond its reasonable control, including natural disasters, epidemics, acts of government, war, civil unrest, widespread outages of power or communications, or cyber-attacks that could not reasonably have been prevented, provided it takes reasonable steps to limit the effect.
25Changes to these Terms
We may update these Terms. The current version and its effective date are always shown on this page. Material changes are announced on the Site or in the portals before they take effect. Continued use after the effective date means you accept the updated Terms; changes do not apply retroactively to actions already taken.
26Governing law and disputes
These Terms are governed by the laws of the Kingdom of Saudi Arabia. The parties will first try to settle any dispute amicably within thirty days of written notice. Failing that, the competent courts of Riyadh have jurisdiction, unless a Services Agreement provides otherwise.
27Language
These Terms are published in Arabic and English. If there is any inconsistency between them, the Arabic version prevails.
28General
If any provision of these Terms is held invalid, the remainder continues in effect. A failure or delay in enforcing a right is not a waiver of it. You may not transfer your rights under these Terms without our consent. Notices to us must be sent to info@ciso.com.sa; notices to you may be given through the portal or to the e-mail address on your account.
29Contact
CISO Consulting Company for Cybersecurity · Commercial Registration No. 7053022526 · Riyadh, Kingdom of Saudi Arabia
E-mail: info@ciso.com.sa · Telephone: +966 55 093 9344 · Website: www.ciso.com.sa