terms of service.

Version 0.8, 26 August 2026. Questions: contact@noctovisor.com

Noctovisor is Noctovisor – Piotr Bogdanowicz, registered in Poland, ul. Hoża 5/7/61, 00-528 Warszawa. EU VAT ID PL5262736443, REGON 146596070, D-U-N-S® Number 427695885. Contact for everything in these terms: contact@noctovisor.com.

The Customer is the organisation that sends Noctovisor a list of companies to watch or subscribes to the service.

The watched companies are the companies on that list. They may be the Customer's suppliers, service providers, customers, partners or any other third party, and a company here includes a business run by an individual, such as a sole trader.

These terms are the main agreement. The data processing agreement covers personal data and is its own document; this one covers everything else: what the service does, what it costs, what each party can rely on, and what happens when it stops. Like its siblings it is deliberately short, and it states nothing that is not currently true.

1. When these terms take effect

They take effect when the Customer accepts them or, if earlier, when a list is first sent. The same is true of the data processing agreement, which is why a list is confidential from the moment it arrives rather than from the moment an invoice is issued.

Submitting the watch form on noctovisor.com is acceptance of these terms and of the privacy policy, both as published on the day it is sent. The form carries a hidden field recording the version of each, so what was accepted is on the record and not only the fact that something was. A list sent by email instead of through the form accepts the versions published on the day it arrives, and Noctovisor names them in its reply.

The comment link on an alert is not acceptance of anything. It is a page for answering one alert, it asks for no agreement, and using it or ignoring it changes nothing about this agreement either way.

The version and date at the top of this page tell you which text you are reading. Previous versions are available on request.

2. What the service is

Noctovisor reads public sources for information about the watched companies and emails the Customer what meets the criteria the Customer has stated. What arrives: a resolution of the list to legal entities, a baseline report on each company, alerts when something crosses the line the Customer set, a weekly log, a monthly report, and an export of the whole record on request.

Delivery is email. There is no portal, no login, no dashboard and no software installed anywhere on the Customer's estate. There is no Noctovisor account for anyone at the Customer to hold, which is stated in the security summary as a security property and is repeated here as a contractual one: nothing in this agreement obliges the Customer to maintain access to a system of ours, because there is none.

Each alert carries a link to a page for answering that alert, and that page is the one exception worth naming. It is not a portal: there is no account, no password, nothing to keep access to, and it shows the alert's reference and nothing else. Answering is optional, and an alert nobody answers is never recorded as unanswered anywhere the Customer can see. The link identifies the alert rather than a person, so whoever holds it can answer, which is why what it records is a note against the Customer's record and never an instruction. Instructions still arrive only by email, from an address the Customer has recorded as authorised.

Silence is the normal state. A quiet week produces a log saying what was checked and that nothing crossed the line, not an empty inbox. The Customer is buying designed silence and the dated proof underneath it, and both are part of what is delivered.

What stands behind an alert. Every name on the list is resolved to a registered legal entity before monitoring starts, and every alert names the identifier it matched and links its primary source. A second automated check reads the claim back against that source before delivery. A person reads every alert and every weekly log before it is sent. These are commitments in the security summary and the data processing agreement; section 14 does not take them back.

Instructions arrive by email. Because there is no login, Noctovisor acts only on instructions from an address the Customer has recorded as authorised, and confirms a change of delivery address to the previous recipients as well as the requester. Section 3 of the data processing agreement carries the operative terms and this agreement does not restate them.

An alert is information, not advice. It is not legal, financial or compliance advice, and it is not a verdict on a company or on anyone named in a record. Noctovisor does not decide, recommend, rank, score or rate. Every decision that follows is the Customer's: keep the relationship, escalate, file, do nothing.

3. Public sources only, and the limit that follows

Noctovisor collects information about the watched companies from publicly available sources only. It does not contact them, send them questionnaires, accept evidence from them, use credentials it is not entitled to, or ask the Customer for contracts or spend data. It will not accept an instruction to do investigative or covert work. Some public records sit behind a registration or a per-page fee, court dockets especially, and Noctovisor pays for those like anyone else.

The limitation that follows: if something is not published, Noctovisor will not see it. No alert does not mean nothing happened.

The kinds of source read are listed at noctovisor.com/sources.html, which moves as the coverage moves. What Noctovisor will read for a particular list, in a particular market, is confirmed in writing before the Customer commits to anything.

4. The free watch, and how it ends

The free watch is up to ten companies for thirty days. No card is asked for and none is held. It is a month of the real product rather than a limited version of it: the list resolved to legal entities, the baseline report, alerts as they are verified, the Monday logs including what stayed below the line, and on day 31 the whole month as one dated report.

How it ends: it ends. At the end of the thirty days the watch stops. Nothing renews, nothing converts, and no invoice appears, because there is no card to charge and no subscription running underneath. The day-31 report arrives after the window closes and is the Customer's to keep whether or not anything follows. Continuing is an act the Customer takes: a written reply putting the watch back on.

What happens to the data if nothing follows. Everything that is theirs is deleted no later than 90 days after the end of the watch, without them having to ask, and earlier on request at any time. That clock, and exactly what it covers, is in section 4 of the data processing agreement and section 9 of the privacy policy. It is a promise published before a list is sent.

One free watch per organisation, and it is not a way to run a paid list for free in ten-company pieces. Where a second free watch would plainly be that, Noctovisor says so rather than quietly starting one.

Starting date. The service is built for a small number of concurrent free watches today. If more are running than can be started at once, Noctovisor says which day yours starts rather than starting it badly.

5. Plans and fees

There are three plans: watch, compliance and athena. They are separated by how many companies are watched and by what the higher plans add. The current prices, the company cap on each plan and what each includes are published at noctovisor.com. They are not repeated here, because a price held in two places goes stale in one of them.

Billing is monthly. On the two self-serve plans a yearly option is offered at two months free, and is never required; monthly is the headline and is meant to be. athena is priced by the year and to the Customer's size, and its fee is agreed in writing before it starts.

There is no overage billing. If the Customer's list grows past the plan's company cap, Noctovisor asks the Customer to move up a plan. It does not add a line to the invoice for the extra companies and does not start watching them until the plan moves. A surprise charge is not something this service does.

Moving between plans. Up at any time, effective when the Customer asks. Down at any time, effective the following month. Neither needs a call.

Promotion codes. The checkout page has a field for one, and a code is offered from time to time. A code applies only where Noctovisor has given it to the Customer or published it, only to the plan and billing period it names, and only while it is live. There is no code sitting behind that field waiting to be guessed, and the published price is the price without one.

6. Payment, VAT and late payment

Card or bank transfer. Card payment is taken through Stripe, on a checkout page Stripe hosts rather than one Noctovisor runs, so card details never reach any system here and none are stored here. Invoice and bank transfer remain available to any Customer whose finance function needs an invoice before it can pay, and are the path for athena. Ask and an invoice is issued. Stripe is named on the sub-processor list, with the scope of what it receives and what it does not.

Prices exclude VAT, which is added where it is due: at the checkout page where the Customer pays by card, on the invoice where it pays by transfer. The rate and the treatment depend on where the Customer is established and whether it holds a valid EU VAT number, which is why the checkout asks for that number and the invoice states both. Where the reverse charge applies, the Customer accounts for the VAT itself. The Customer is responsible for the accuracy of the billing details and the VAT number it gives, and for telling Noctovisor when they change.

Invoices are payable by the date on the invoice. Late payment in a commercial transaction carries statutory interest under Polish law, and Noctovisor's practice is to email the Customer rather than charge it.

If an invoice goes unpaid, Noctovisor writes first, to the billing contact and to the person who gave the instructions, and gives a reasonable period to put it right. Only then is monitoring suspended, and the nominated recipients are told that the watch has stopped rather than left to notice the quiet. The Customer is told when monitoring stops, not only when it resumes, which is the same commitment the security summary makes about an outage and holds here for the same reason. Suspension does not delete anything: the record stands and the export in section 8 of the data processing agreement remains available.

7. Term, cancellation and what happens at the end

A monthly plan runs from month to month until it is cancelled. Change or cancel whenever you like, effective the following month. There is no minimum term, no notice period and no lock-in. That is the published position on noctovisor.com and in the continuity section of the security summary, and this is the contractual form of the same thing: the maximum exposure is one month.

A yearly plan is cancelled the same way and the same sentence applies to it. Where months have been paid for in advance and not used, what happens to them is settled in writing before the cancellation takes effect. Noctovisor does not keep money for months it did not watch. That is the point on which the yearly option and the no-lock-in promise have to agree, so it is written down: paying a year up front buys two months free and does not tie the Customer to a term.

Cancelling is an email. Write to contact@noctovisor.com from an authorised address and say so. No form, no retention call, no exit survey. Where the plan is paid by card, Noctovisor cancels the subscription at Stripe so the card stops being charged, and writes back to confirm that it has done so.

Either party may end this agreement for a material breach the other has not put right within 30 days of being told about it in writing, and Noctovisor may end it where continuing would be unlawful. If Noctovisor decides to stop providing the service generally it says so as early as it can and, where the circumstances are within its control, at least 30 days ahead, with a final export first, under section 14 of the data processing agreement, which also records the standing arrangement for the case where Noctovisor cannot act at all.

At the end, the export, deletion, return and transition commitments in sections 8 and 15 of the data processing agreement apply, and the retention clocks in section 9 of the privacy policy govern what outlives them. They are not restated here, because they are the ones that were published first and a second copy would eventually disagree with them. In outline, so the shape is visible: a full export in a non-proprietary format, deletion or return at the Customer's choice, dated written confirmation once it is done, and transition support for up to three further monthly terms at the same monthly fee if the Customer asks before the end.

Nothing to unwind. There is no software installed at the Customer, no integration and no credential to revoke. Stopping the service stops an email. Every alert and summary already delivered is in the Customer's own mailbox and stays there.

8. What the Customer is responsible for

  • The list. That the companies on it are identified well enough to be resolved, and that a correction is sent when a name, a domain or a corporate structure changes. Noctovisor returns what it cannot pin down rather than guessing at it, and a returned name is not being watched.
  • The criteria. That the confirmed criteria say what the Customer means. They are sent back in writing and dated at the start and after every change, and the Customer can ask for the current version and the full history at any time. A criterion nobody corrected is the one the service runs on.
  • The recipients. That the nominated addresses are current, that people who have left are removed, and that the Customer's own access controls protect what lands in its mailboxes. There is no user directory here to offboard anyone from.
  • Instructions. That instructions come from the addresses recorded as authorised, and that the record is kept current.
  • A lawful basis for the names it sends. The Customer is the controller for its list and warrants in section 13 of the data processing agreement that it holds its own lawful basis and authorisation for the category of data it asks to receive. That warranty lives there and is referenced rather than repeated.
  • Its own decisions. What the Customer does about an alert, including doing nothing, is the Customer's call and its record to keep.

9. What the service may not be used for

The list is short on purpose:

  • No reselling. Alerts, logs, reports and exports are for the Customer's own organisation and the uses in section 10. They may not be resold, republished, syndicated, or supplied as a monitoring service to anyone else. A group company or an adviser reading them under section 10 is not resale; charging a third party for them is.
  • No harassment. The service may not be used to pressure, intimidate or expose a person named in a public record, or to build a file on an individual. Noctovisor's unit of record is the company, and that limit is only meaningful if it survives delivery.
  • No automated adverse decisions about individuals. Output from this service may not be used as the basis of a decision about a person that is taken without a human being reading the source. Nothing here is a score, a rating or a determination, and it must not be turned into one downstream. If the Customer intends to feed alerts into an automated decision process, say so before starting, because it would change what Noctovisor is willing to report.
  • No presenting it as more than it is. The Customer may state that its third parties are monitored by Noctovisor, on the terms in section 12. It may not present an alert as a certification, a rating, an audit finding or Noctovisor's endorsement or condemnation of a company.
  • Nothing unlawful, and nothing that would put Noctovisor in breach of a source's own terms or of data protection law.

Where Noctovisor thinks a request crosses one of these lines it says so and asks, rather than quietly declining. It may pause a criterion or refuse a category of finding if reporting it would be unlawful or out of proportion to the purpose of the service, which is the same right section 13 of the data processing agreement records.

10. Who owns what

The reports are the Customer's. Alerts, weekly logs, monthly reports, baseline reports and exports are the Customer's to keep and to use without asking: inside its own organisation and its group, with its auditors, its regulators, its insurers and its professional advisers, and in the evidence pack it builds for any of them. That is what they are for, and the licence to use them that way is perpetual and survives the end of this agreement. Building the record is the point; a record the Customer could not show would be worthless.

The service is Noctovisor's. The software, the site, the pipeline, the source selection, the entity-matching work, the report designs and the Noctovisor name and marks stay ours. Nothing in these terms transfers them, and the Customer gets what it needs to use the service and no more.

The public record belongs to whoever published it. A court filing, a register entry, a sanctions listing and a news article are not ours, and Noctovisor claims nothing in them. That is why every alert links to its original rather than reproducing it whole: the Customer should be reading the source, and the source's publisher keeps its rights in it.

11. Confidentiality, both ways

The Customer's side. The list and everything derived from it are confidential from the moment they are received, whether or not the sender becomes a customer, and that does not expire. Section 4 of the data processing agreement carries it in full, including who may have access and on what terms. Which companies a Customer watches is its commercial position, and Noctovisor does not disclose it: not to the companies being watched, not to another customer, and not to an individual asking about a record, unless the Customer agrees or the law compels it.

Noctovisor's side. Some of what a Customer receives during diligence is not published: redacted sample exports, providers' processing terms sent on request, the written continuity arrangement, and written answers to security and due-diligence questionnaires. Those are Noctovisor's confidential information, to be used for evaluating and running the service and shown to the Customer's own advisers, auditors and regulators on the same footing. Not to be published, and not to be handed to a competitor of ours.

The usual exceptions, both ways. Nothing is confidential that is already public without a breach, that the receiving party already had or worked out independently, or that the law or a regulator requires to be disclosed. Where a disclosure is compelled, the party compelled tells the other first if it lawfully can, and discloses no more than it must.

These obligations survive the end of this agreement.

12. Names and logos, both ways

Noctovisor naming the Customer. A paying Customer grants Noctovisor a limited, non-exclusive, royalty-free licence to use the Customer's name and logo on Noctovisor's website and in its marketing materials, solely to identify the Customer as a client. Nothing else: not a quote the Customer did not give, not a case study it has not read, and never anything about which companies it watches, which is confidential under section 11.

The Customer may revoke this permission at any time by emailing contact@noctovisor.com. No reason needed and none asked for. The website is updated within 30 days of the request. Revocation is forward-looking: materials already printed or already in circulation are not recalled, because a promise to recall them could not be kept, and saying so is better than promising it.

The Customer naming Noctovisor. Noctovisor grants the Customer a limited, non-exclusive, royalty-free licence to state that its third parties are monitored by Noctovisor, and to show the Noctovisor name and logo, in its own audit, compliance, procurement and regulatory materials, and in its register of third parties. This is the direction that usually goes unwritten. A Customer buying the evidence needs to be able to name where the evidence came from.

Two limits on it. The logo may not be altered, and it may not be used to suggest that Noctovisor certified, audited, approved or vouched for any company. Noctovisor reports what the public record says and does not assess anybody. Noctovisor may revoke this licence by email if it is used that way, having asked first.

Neither licence survives the end of this agreement, except in materials already produced. Those stay as they are, on both sides.

13. Data protection

Personal data is handled by the data processing agreement, which takes effect when the Customer accepts it or, if earlier, when a list is first sent. It covers roles, instructions, security, sub-processors, transfers, data subject requests, breach notification, audit, deletion and exit. It is not restated here and these terms do not override it: where the two conflict about personal data, the data processing agreement prevails, and where the standard contractual clauses it refers to apply, they prevail over both.

The privacy policy covers what Noctovisor does as controller: website visitors, enquiries, billing, and its own collection of material from public sources. The sub-processor list is the current, dated list of the companies underneath the service, and the security summary is what a security reviewer reads before onboarding Noctovisor as a supplier.

One thing from that set belongs here because it is a commercial fact and not only a privacy one: there is no choice of processing region. The server that holds the list and runs the monitoring is in Canada, and the language model providers are in the United States. If the Customer's own policy requires EEA-only processing, this service does not meet it, and no paperwork changes that.

14. What is promised, and what is not

The service is provided as it is described on noctovisor.com and in the published documents this one sits beside. That description is the promise, and there is no other one hiding underneath it.

Completeness is not warranted. Noctovisor monitors public sources, and a public source can be late, wrong, offline, restructured, moved behind a paywall or simply silent about something that happened. A watch can miss an event. That is a known limit of a product built on the public record. It is stated in the same words in section 6 of the data processing agreement and on the pages a reader meets before buying, so it is not a late disclaimer undoing an early marketing claim. No alert does not mean nothing happened.

Nor is the service warranted to be uninterrupted. Everything runs on one server, so there is no failover and no second region: losing it stops monitoring until it is rebuilt. Where a provider underneath the service has an outage, Noctovisor is a customer like anyone else: the Customer is told what is affected, and not told that Noctovisor is fixing something it has no access to. No recovery time or recovery point objective is published without operating history to support one, and no alert service level is published for the same reason. When there is history, the figures achieved get published rather than the figures hoped for.

No regulatory outcome is warranted. Using Noctovisor does not by itself satisfy an obligation under DORA, NIS2, Regulation S-P, NYDFS Part 500, CMMC or any other regime, and nothing produced by the service is legal, financial or compliance advice. The data processing agreement also records that this service is not represented as suitable to support a function the Customer has classified as critical or important under DORA. A Customer considering that should get in touch before contracting.

What this section does not disclaim. The commitments made in the security summary and the data processing agreement are commitments and they stand: entity resolution before monitoring starts and the matched identifier on every alert; the source link on every alert; the second automated check that reads each claim back against its source; a person reading every alert and every weekly log before it is sent; a wrong alert corrected and the correction logged; breach notification within 24 hours of becoming aware; export, deletion and exit as written. Nothing in this section reduces them, and a disclaimer that quietly did would make the rest of the published set dishonest.

Beyond what is written here and in the documents referred to, and to the extent the law allows it, no other warranty is given, including implied ones.

15. Liability

Each party's total liability to the other for direct loss arising out of the service and these terms is limited, in aggregate, to the fees the Customer paid in the 12 months before the event giving rise to the claim, or EUR 100 where that is greater.

The floor is there for a reason worth naming. A free watch has paid nothing, so a cap expressed only as fees paid would be a cap of zero, which refuses liability outright rather than limiting it. EUR 100 is a small number, and it keeps the clause a cap.

Polish law does not allow liability for damage caused intentionally to be excluded, and this cap does not try to. Under art. 473 § 2 of the Polish Civil Code a term excluding it in advance is void, and the cap above is read subject to that.

The cap does not apply to, and nothing here limits:

  • damage caused intentionally, as above;
  • liability for death or personal injury caused by negligence, for fraud, and for anything else that cannot be limited under applicable law;
  • breach of the confidentiality obligations in section 11 and in section 4 of the data processing agreement;
  • the Customer's obligation to pay fees for the service it received;
  • either party's liability to a data subject, including under Article 82 of the GDPR, which is a statutory matter between that party and the data subject and cannot be limited by contract;
  • the liability provisions of the standard contractual clauses referred to in section 7 of the data processing agreement, where those clauses apply.

Neither party is liable to the other for indirect or consequential loss, for lost profit, revenue or anticipated savings, or for loss arising from a decision the other party took, or did not take, about a watched company. Deciding is the Customer's part of this and is described that way throughout.

Claims under the data processing agreement are capped by section 16 of that agreement rather than twice under both, and the two caps are not cumulative.

Fees are monthly, so a 12-month cap is a modest number. A Customer needing a higher cap should raise it before contracting rather than after an incident.

16. Indemnity

Two, both narrow, and neither of them the usual one-sided page.

The Customer covers Noctovisor against a third-party claim arising from the list it sent: that it had no right to send those names, or no lawful basis for the category of data it asked to receive.

Noctovisor covers the Customer against a third-party claim that the service, as delivered, infringes that third party's intellectual property rights.

In both directions: the party asking for cover tells the other promptly, lets it take part in the defence, and does not settle without its agreement. Both sit under the cap in section 15, stated here because an indemnity written to sit outside a cap makes the cap decorative.

17. Changes to these terms

The version and date at the top move whenever the text moves. Changes are notified by email to the Customer's nominated contact, and published here at the same time.

A change that materially affects the Customer takes effect 30 days after notice, and the Customer may cancel without penalty in that period, with a final export first. A smaller change takes effect when it is published: a correction, a clarification, a change that only makes a commitment stronger. The version line records it. Continuing to use the service after a change has taken effect is acceptance of it.

Changes to the data processing agreement follow that agreement's own rules, not these. Sub-processor changes follow the 30-day notice and objection process in section 7 of it and on the sub-processor list.

18. Other terms

Assignment and change of control. Noctovisor may transfer this agreement to a company it forms or to a successor that takes over the service, provided that company assumes these obligations in full and unchanged. The Customer is told at least 30 days beforehand and may terminate without penalty in that period, with a full export first. Noctovisor will not assign these terms to anyone else without the Customer's agreement, and will not sell or transfer customer data as an asset separately from the service. The Customer may transfer these terms to a successor of the business the service is bought for, on notice.

Subcontracting. Noctovisor may use the providers on the sub-processor list and remains fully responsible for their performance. Adding or replacing one follows the notice and objection process in section 7 of the data processing agreement.

The whole agreement. These terms, the data processing agreement, the plan the Customer chose as published on noctovisor.com, and the dated written confirmation of the Customer's criteria are the whole of what is agreed. Purchase-order terms, supplier portal terms and standard conditions printed on the back of something do not apply unless Noctovisor has agreed to them in writing. Neither party is relying on anything said outside these documents, which is not a formula here: if something was said in an email and it matters, ask for it to be written into the criteria confirmation, and it will be.

Severability. If a provision is unenforceable, the rest stands and the unenforceable one is read down to what the law allows.

No waiver by silence. Not enforcing something once does not give it up.

Notices. To Noctovisor: contact@noctovisor.com. To the Customer: the address it has given for notices, and for anything affecting delivery, the nominated recipients as well.

Survival. Sections 9, 10, 11, 12, 14, 15, 16, 18 and 19 survive the end of this agreement, along with the parts of section 7 that describe what happens after it.

Language. These terms are published in English and English governs. A translation is a convenience and does not change the meaning.

19. Law, forum, and business customers only

Polish law governs these terms and anything arising out of them, including non-contractual claims.

The courts with jurisdiction over Noctovisor's registered seat, in Warsaw, are the forum. This does not affect a data subject's rights under Article 79 of the GDPR, or any jurisdiction provision in the standard contractual clauses referred to in the data processing agreement, or a regulator's own jurisdiction over either party.

The service is sold to businesses. It is not offered to consumers and is not directed at them: everything in it is bought for a purpose connected with the buyer's own trade or profession. Noctovisor does not accept an order from someone buying outside a business.

Scope of this version

What these terms do not carry, for the same reason the data processing agreement names its own limits: the machinery a regulated financial entity operating at scale will want, namely a clause-by-clause mapping to Article 30 of DORA, the register-of-information field set, the sub-outsourcing assessment, pooled audits and the UK international data transfer addendum. Those sit with that agreement's scope note, and a Customer who needs them should get in touch before contracting.


Version 0.8, 26 August 2026. Questions and corrections to contact@noctovisor.com