This End-User License and Subscription Agreement ("EULA" or "Agreement") is a legal agreement between the individual or entity accepting this Agreement ("Customer," "You," or "Your") and Secured2 Corporation, a Delaware corporation ("Secured2," "we," "us," or "our").
This Agreement governs Your access to and use of Citadel™ Storage by Secured2, including the Citadel web application, software, storage services, Vaults, related applications, APIs, security technologies, support services, Documentation, updates, and any related services ordered from Secured2 (collectively, the "Citadel Services").
BY CREATING AN ACCOUNT, PURCHASING A SUBSCRIPTION, ACCESSING CITADEL, UPLOADING OR STORING DATA, INSTALLING OR USING ANY CITADEL SOFTWARE, OR CLICKING "I ACCEPT," "AGREE," "CONTINUE," OR A SIMILAR BUTTON ASSOCIATED WITH THIS AGREEMENT, YOU ACKNOWLEDGE THAT YOU HAVE READ, UNDERSTAND, AND AGREE TO BE BOUND BY THIS AGREEMENT.
IF YOU ARE ACCEPTING THIS AGREEMENT ON BEHALF OF A COMPANY, GOVERNMENT ENTITY, OR OTHER ORGANIZATION, YOU REPRESENT AND WARRANT THAT YOU HAVE AUTHORITY TO BIND THAT ORGANIZATION TO THIS AGREEMENT.
If You do not agree to this Agreement, You may not access or use the Citadel Services.
1. DEFINITIONS
1.1 "Account"
means the Citadel account established by or for Customer through which Customer and its Authorized Users access the Citadel Services.
1.2 "Applicable Law"
means all applicable federal, state, local, international, and other laws, statutes, rules, regulations, orders, and legally binding governmental requirements applicable to a party or its performance under this Agreement.
1.3 "Authorized User"
means an individual whom Customer has authorized to access or use the Citadel Services under Customer's Account, including Customer's employees, officers, directors, contractors, or other authorized personnel.
1.4 "Citadel"
or "Citadel Services" means Secured2's Citadel secure storage platform and related software, systems, applications, APIs, Vaults, storage functionality, security functionality, support, Documentation, and associated services.
1.5 "Citadel Security Technology"
means the proprietary software, processes, algorithms, architectures, methods, systems, and technologies used by Secured2 to protect, transform, process, distribute, store, authenticate, retrieve, restore, or otherwise manage Customer Data.
Citadel Security Technology may include proprietary data transformation, fragmentation or shredding, distributed storage, authentication, access controls, secure transmission, restoration processes, and other security mechanisms.
1.6 "Customer Data"
means files, folders, documents, images, videos, databases, content, information, metadata, or other electronic data submitted, uploaded, transmitted, stored, archived, indexed, processed, or otherwise placed into Citadel by or on behalf of Customer.
1.7 "Documentation"
means Secured2's then-current user documentation, instructions, technical materials, help content, and other published documentation relating to Citadel.
1.8 "Intellectual Property Rights"
means all patent rights, copyrights, trademarks, service marks, trade names, trade secrets, know-how, database rights, moral rights, contract rights, proprietary rights, and other intellectual property rights existing anywhere in the world.
1.9 "Order"
means an online purchase, Quote, order form, purchase order accepted by Secured2, or other written agreement identifying the Citadel Services purchased by Customer.
1.10 "Plan"
means the Citadel subscription level purchased or otherwise assigned to Customer, including the features, Authorized Users, Storage Capacity, Subscription Term, and other usage rights applicable to Customer.
1.11 "Storage Capacity"
means the amount of digital storage allocated to Customer under its Plan or Order.
1.12 "Subscription Term"
means the period during which Customer is authorized to use the Citadel Services under an applicable Plan or Order.
1.13 "Third-Party Services"
means hosting, networking, cloud infrastructure, payment processing, hardware, software, or other products or services supplied by third parties that may be utilized in connection with Citadel.
1.14 "Usage Data"
means technical and operational information concerning the operation, performance, security, and use of Citadel, excluding the substantive contents of Customer Data.
1.15 "Vault"
means a logical secure storage container within Citadel that Customer may use to organize and manage folders, files, and other Customer Data.
2. LICENSE AND RIGHT TO USE CITADEL
2.1 Subscription Right
Subject to Customer's payment of applicable Fees and continued compliance with this Agreement, Secured2 grants Customer a limited, non-exclusive, non-transferable, non-sublicensable right during the Subscription Term to access and use Citadel for Customer's authorized personal or internal business purposes.
No ownership interest in Citadel or Secured2's underlying technology is transferred to Customer.
2.2 Authorized Users
Customer may permit Authorized Users to use Citadel to the extent permitted by Customer's Plan. Customer is responsible for the activities of its Authorized Users and for ensuring that Authorized Users comply with this Agreement.
2.3 Evaluation or Trial Services
If Secured2 makes Citadel available on a free, evaluation, beta, proof-of-concept, or trial basis, Customer may use the applicable services only during the period and subject to the limitations designated by Secured2. Trial or evaluation services may contain reduced features, storage limitations, different support levels, or other limitations. Unless otherwise agreed in writing, Secured2 may discontinue a trial or evaluation service at any time.
3. RESTRICTIONS
Except as expressly permitted by this Agreement or Applicable Law, Customer shall not, and shall not permit any third party to:
1. copy, modify, adapt, translate, or create derivative works from Citadel or the Citadel Security Technology; 2. reverse engineer, reverse compile, decrypt, disassemble, decompile, discover, derive, or attempt to derive the source code, algorithms, security architecture, underlying processes, or proprietary techniques of Citadel; 3. circumvent, disable, defeat, interfere with, or attempt to bypass any authentication, security, storage, access-control, usage-control, or technological protection mechanism; 4. sublicense, lease, rent, sell, resell, distribute, transfer, assign, time-share, or commercially exploit Citadel except pursuant to a separate written agreement with Secured2; 5. use Citadel to develop or assist in developing a competing product or service; 6. intentionally benchmark, probe, scan, penetration test, or security test Citadel without Secured2's written authorization, except to the extent such restriction is prohibited by Applicable Law; 7. use Citadel to interfere with or disrupt Secured2 infrastructure or the systems of another customer; 8. remove or alter Secured2 copyright, patent, trademark, confidentiality, or proprietary notices; or 9. access or use Citadel in violation of Applicable Law.
Nothing in this Section restricts rights that cannot lawfully be restricted under Applicable Law.
4. CUSTOMER ACCOUNTS AND AUTHENTICATION
4.1 Account Information
Customer agrees to provide accurate information when establishing and maintaining an Account and to promptly update materially inaccurate Account information.
4.2 Account Security
Customer is responsible for protecting its usernames, passwords, authentication credentials, recovery methods, devices, and other means used to access Citadel. Customer shall promptly notify Secured2 if Customer knows or reasonably suspects that an Account or credential has been compromised.
4.3 Multi-Factor Authentication
Secured2 may require or make available multi-factor authentication or other authentication technologies as a condition of accessing certain Citadel functionality. Customer is responsible for properly configuring and maintaining authentication methods available to it.
4.4 Account Recovery
Because Citadel may employ security technologies intentionally designed to prevent unauthorized reconstruction or access to Customer Data, Secured2 may not always be able to restore access when Customer loses required credentials, authentication methods, recovery information, or other information necessary to access its Account or Customer Data. Customer is responsible for maintaining all authentication and recovery information made available by Secured2. Secured2 will not circumvent its security architecture to provide access to Customer Data where doing so would materially compromise the security or integrity of Citadel.
5. ORDERS, SUBSCRIPTIONS, AND FEES
5.1 Plans and Orders
Customer's Plan, Storage Capacity, Subscription Term, Fees, Authorized Users, and other purchased features will be identified through the applicable checkout page, Quote, Order, or other ordering documentation.
5.2 Fees
Customer agrees to pay all fees associated with its Plan or Order ("Fees"). Except as expressly stated otherwise in an Order or required by Applicable Law, Fees are non-refundable.
5.3 Storage Upgrades
Customer may purchase additional Storage Capacity or upgrade its Plan if such options are made available by Secured2. Additional Fees may apply.
5.4 Storage Limits
Customer may not intentionally exceed its purchased Storage Capacity. If Customer exceeds an applicable limit, Secured2 may require Customer to purchase additional capacity, reduce Customer's storage utilization, restrict additional uploads, or otherwise bring the Account into compliance with the applicable Plan. Secured2 will not intentionally delete Customer Data solely because of a temporary storage overage without providing reasonable notice where commercially practicable.
5.5 Payment
If Customer purchases Citadel directly from Secured2, Customer will pay Fees in accordance with the payment terms presented at purchase or contained in the applicable Order. Secured2 may use a third-party payment processor to process payments.
5.6 Taxes
Fees do not include applicable sales, use, value-added, excise, withholding, or similar taxes unless expressly stated otherwise. Customer is responsible for taxes associated with its purchase or use of Citadel, other than taxes imposed on Secured2's net income.
5.7 Renewals
A Citadel subscription will automatically renew only if the applicable checkout process, Order, or Quote states that the subscription automatically renews. If automatic renewal applies, Customer authorizes Secured2 or its payment processor to charge applicable renewal Fees using Customer's designated payment method, subject to Applicable Law. Customer may prevent renewal by cancelling the subscription in accordance with the cancellation procedures applicable to its Plan.
5.8 Price Changes
Secured2 may change Citadel pricing from time to time. Unless otherwise agreed, a price change affecting an existing paid Subscription Term will become effective at the beginning of the next renewal term.
6. CUSTOMER DATA OWNERSHIP
6.1 Customer Ownership
AS BETWEEN CUSTOMER AND SECURED2, CUSTOMER RETAINS ALL RIGHT, TITLE, AND INTEREST IN AND TO CUSTOMER DATA. Secured2 does not acquire ownership of Customer Data merely because Customer stores, processes, protects, or manages Customer Data using Citadel.
6.2 Limited Rights Required to Operate Citadel
Customer grants Secured2 and its authorized service providers a limited right to process Customer Data solely to the extent reasonably necessary to provide, protect, maintain, secure, support, and improve the operation of the Citadel Services. Depending upon Citadel's technical architecture, such processing may include transmitting, transforming, compressing, fragmenting, shredding, distributing, storing, indexing, retrieving, reconstructing, restoring, displaying, or otherwise processing Customer Data as necessary to provide functionality requested by Customer. This limited right does not transfer ownership of Customer Data to Secured2.
6.3 Rights to Customer Data
Customer represents and warrants that Customer has all rights and permissions necessary to upload, store, transmit, process, and otherwise use Customer Data through Citadel.
6.4 No Advertising Sale of Customer Data
Secured2 will not sell Customer Data for advertising purposes.
6.5 Artificial Intelligence Training
Unless Customer expressly agrees otherwise, Secured2 will not use the substantive contents of Customer Data to train general-purpose artificial intelligence models made available to unrelated third parties. If Citadel offers optional AI, search, indexing, classification, or similar features, additional functionality or terms may apply to Customer's voluntary use of those features.
7. CITADEL SECURITY AND STORAGE ARCHITECTURE
7.1 Security
Citadel is designed to protect Customer Data using Secured2 security technologies and commercially reasonable administrative, physical, and technical safeguards. Citadel may use proprietary security technologies that differ materially from conventional storage and encryption architectures.
7.2 Proprietary Processing
Citadel may process Customer Data using proprietary technologies designed to reduce the exposure of intact Customer Data during storage or transmission. Depending upon the applicable version and configuration of Citadel, such technologies may include data transformation, fragmentation, shredding, distributed storage, authentication, access controls, secure transport, or restoration mechanisms. Nothing in this Agreement requires Secured2 to disclose confidential algorithms, source code, trade secrets, security architecture, or proprietary methods used by Citadel.
7.3 No Absolute Security Guarantee
No software, network, storage system, authentication mechanism, cloud infrastructure, or cybersecurity system can be guaranteed to prevent every possible failure, attack, misuse, or unauthorized access under every circumstance. Accordingly, unless expressly stated in a separate written warranty signed by Secured2, descriptions of Citadel's security characteristics do not constitute a guarantee that a security incident, hardware failure, software defect, human error, malicious action, or other event can never occur.
7.4 Infrastructure Providers
Secured2 may use one or more third-party infrastructure, cloud, network, data-center, hosting, or storage providers in connection with Citadel. Use of third-party infrastructure does not give such provider ownership of Customer Data.
7.5 Data Location
Customer Data or components derived from Customer Data may be stored or processed at locations used by Secured2 or its authorized infrastructure providers, subject to the applicable Order, Documentation, data-residency commitments, or Applicable Law. Where Customer requires specific data-residency commitments, those commitments must be expressly stated in the applicable Order or other written agreement with Secured2.
8. CUSTOMER RESPONSIBILITY FOR DATA
8.1 Customer Responsibility
Customer is responsible for determining what information it places into Citadel and whether its use of Citadel is appropriate for Customer's legal, regulatory, contractual, security, and business requirements.
8.2 Independent Copies
Unless Customer's applicable Order expressly states otherwise, Customer should maintain independent copies of information that Customer cannot afford to lose. Citadel is not intended to eliminate Customer's responsibility for appropriate business-continuity, records-management, or disaster-recovery practices.
8.3 Regulatory Requirements
Customer is responsible for determining whether its use of Citadel satisfies laws and regulations applicable to Customer or Customer Data. Secured2 may enter into additional agreements, security addenda, data-processing agreements, business associate agreements, government contract terms, or other compliance documentation when mutually agreed in writing. No general statement regarding Citadel's security should be interpreted as representing that Citadel automatically makes Customer compliant with a particular law, regulation, framework, or industry standard.
9. DELETION AND RESTORATION OF CUSTOMER DATA
9.1 Customer Deletion
Citadel may permit Customer to delete files, folders, Vaults, or other Customer Data. Customer acknowledges that a deletion action may be permanent.
9.2 Security-Based Irrecoverability
Because Citadel may use technologies designed to prevent reconstruction of deleted or inaccessible Customer Data, certain deletion operations may render Customer Data permanently unrecoverable. Customer is responsible for confirming that Customer wishes to permanently delete Customer Data before initiating an irreversible deletion process.
9.3 Restoration
Secured2 will use the Citadel functionality made available under Customer's Plan to permit Customer to retrieve or restore Customer Data. Secured2 does not guarantee restoration of Customer Data that has been permanently deleted, corrupted before being submitted to Citadel, rendered inaccessible by Customer action, or otherwise made unrecoverable through circumstances outside Secured2's reasonable control.
10. ACCEPTABLE USE
Customer may not use Citadel to knowingly: 1. violate Applicable Law; 2. infringe or misappropriate another person's Intellectual Property Rights; 3. store or distribute unlawful content; 4. distribute malware, ransomware, viruses, malicious code, or destructive software; 5. conduct unauthorized attacks, intrusions, scanning, exploitation, or surveillance; 6. interfere with Citadel, Secured2 infrastructure, or another customer's systems; 7. impersonate another person without authorization; 8. facilitate fraud, theft, or unlawful conduct; 9. circumvent storage, security, authentication, billing, or usage controls; or 10. use Citadel in a manner reasonably likely to materially impair the security, integrity, availability, or operation of Citadel.
Secured2 may investigate suspected violations and may cooperate with lawful governmental requests as required by Applicable Law.
11. PRIVACY AND OPERATIONAL DATA
Secured2 may collect Account information, billing information, system logs, device information, authentication information, performance information, security events, and Usage Data reasonably necessary to operate, maintain, secure, troubleshoot, bill, and improve Citadel. Secured2 may create aggregated or de-identified statistics from Usage Data provided such information does not reasonably identify Customer or disclose the substantive contents of Customer Data. Secured2's collection and use of personal information is also subject to any applicable Secured2 privacy notice.
12. MODIFICATIONS AND UPDATES
12.1 Updates
Secured2 may update, modify, patch, improve, or otherwise change Citadel from time to time. Updates may include security patches, bug fixes, performance improvements, new functionality, changes to existing functionality, and other modifications.
12.2 Automatic Updates
Certain updates may be installed or implemented automatically where reasonably necessary to maintain the security, reliability, compatibility, or operation of Citadel.
12.3 Service Changes
Secured2 may modify or discontinue particular Citadel functionality. For paid customers, Secured2 will use commercially reasonable efforts to avoid materially reducing the core functionality purchased by Customer during a then-current Subscription Term, except where a modification is reasonably necessary because of security concerns, Applicable Law, third-party dependency changes, technical necessity, or circumstances outside Secured2's reasonable control.
13. SUPPORT
Support for Citadel will be provided in accordance with the applicable Plan, Order, Documentation, or support policy. Secured2 is not responsible for technical problems caused primarily by systems, hardware, networks, applications, services, configurations, or other technology outside Secured2's reasonable control.
14. SUSPENSION
Secured2 may suspend some or all access to Citadel where reasonably necessary: 1. to respond to an actual or suspected security incident; 2. to prevent material damage to Citadel, Customer, Secured2, another customer, or a third party; 3. if Customer materially violates this Agreement; 4. if Customer fails to pay undisputed Fees when due following applicable notice; 5. if required by Applicable Law, court order, or lawful governmental directive; 6. if Customer's activity materially threatens the availability or integrity of Citadel; or 7. during emergency maintenance or circumstances beyond Secured2's reasonable control.
Where commercially practicable and legally permitted, Secured2 will provide Customer with notice of a suspension and will restore access after the condition causing suspension has been resolved.
15. INTELLECTUAL PROPERTY
15.1 Secured2 Ownership
Secured2 and its licensors retain all right, title, and interest in and to: • Citadel; • Citadel Security Technology; • Secured2 software; • Documentation; • APIs; • interfaces; • source code and object code; • algorithms; • security processes; • architecture; • designs; • trademarks; • patents; • trade secrets; • proprietary methods; and • all improvements, modifications, and derivative works thereof.
Except for the limited rights expressly granted under this Agreement, no rights are granted to Customer.
15.2 Feedback
If Customer voluntarily provides suggestions, recommendations, ideas, or other feedback concerning Citadel, Customer grants Secured2 the right to use that feedback without restriction or compensation, provided Secured2 does not publicly identify Customer as the source without permission.
16. OPEN-SOURCE AND THIRD-PARTY SOFTWARE
Citadel may contain or interact with software licensed under open-source or third-party licenses. Applicable open-source components remain subject to their respective licenses. To the extent a third-party or open-source license expressly grants Customer rights that conflict with restrictions contained in this Agreement, the applicable third-party or open-source license will govern solely with respect to that component.
17. CONFIDENTIALITY
Each party may receive confidential or proprietary information of the other party. The receiving party will: 1. use the disclosing party's confidential information only as necessary to perform or exercise its rights under this Agreement; 2. protect such information using reasonable care; and 3. not disclose such information except to personnel, contractors, professional advisors, or service providers who have a legitimate need to know and are bound by appropriate confidentiality obligations.
Confidential information does not include information that the receiving party can demonstrate: • is or becomes publicly available through no breach of this Agreement; • was lawfully known without confidentiality obligations; • is independently developed without use of the confidential information; or • is lawfully received from another source without confidentiality restrictions.
A party may disclose confidential information if required by Applicable Law, subpoena, or court order, subject to legally permitted notice to the other party. Secured2's proprietary security architecture, algorithms, methods, technical documentation, trade secrets, and non-public Citadel technology constitute Secured2 Confidential Information.
18. TERM, CANCELLATION, AND TERMINATION
18.1 Term
This Agreement begins when Customer first accepts it and continues for as long as Customer has an Account, active subscription, or other continuing obligation under this Agreement.
18.2 Customer Cancellation
Customer may cancel the renewal of its Citadel subscription in accordance with the procedures applicable to its Plan. Unless otherwise stated in the applicable Order or required by law, cancellation will become effective at the end of the then-current paid Subscription Term and will not entitle Customer to a refund of prepaid Fees.
18.3 Termination for Cause
Either party may terminate this Agreement or an applicable Order if the other party materially breaches this Agreement and fails to cure the breach within thirty (30) days after receiving written notice describing the breach. Secured2 may terminate or suspend the Agreement immediately if: • Customer intentionally compromises or attempts to compromise Citadel security; • Customer uses Citadel for unlawful purposes; • continued service would violate Applicable Law or a binding governmental order; • Customer's conduct creates an immediate material security risk; or • Customer becomes insolvent, ceases business operations, or enters bankruptcy proceedings not dismissed within sixty (60) days, subject to Applicable Law.
18.4 Non-Payment
Secured2 may suspend Citadel for undisputed amounts materially past due after providing reasonable notice and an opportunity to cure.
18.5 Effects of Termination
Upon expiration or termination: 1. Customer's right to use Citadel terminates; 2. Customer may lose access to Customer Data; 3. outstanding amounts owed to Secured2 remain payable; and 4. provisions that by their nature should survive termination will survive.
18.6 Data Retrieval Period
Unless otherwise provided in Customer's Plan or Order, Secured2 may provide a period of up to thirty (30) days following expiration or termination during which Customer may request retrieval of Customer Data. Secured2 does not guarantee continued availability of Customer Data during this period unless expressly stated in an Order or applicable service commitment. Customer is responsible for retrieving required Customer Data before the end of the applicable Subscription Term.
18.7 Deletion After Termination
Following expiration of any applicable retrieval period, Secured2 may permanently delete Customer Data associated with the terminated Account. Because of Citadel's security architecture, deletion may be irreversible. Secured2 may retain limited information to the extent reasonably required for legal, accounting, fraud-prevention, security, dispute-resolution, backup-cycle, or regulatory purposes.
19. LIMITED WARRANTIES
19.1 Citadel Services
Secured2 warrants that paid Citadel Services will perform materially in accordance with the applicable Documentation under normal authorized use. If Customer reasonably believes Secured2 has materially breached this warranty, Customer must notify Secured2 and provide sufficient information for Secured2 to reproduce or investigate the issue. Secured2's obligation will be to use commercially reasonable efforts to correct the material nonconformity.
19.2 Exclusions
The warranty does not apply to issues caused by: • unauthorized modifications; • Customer misuse; • unsupported systems or configurations; • Customer equipment; • third-party systems outside Secured2's reasonable control; • internet or telecommunications failures; • Customer Data corruption existing before submission to Citadel; • Customer's violation of Documentation; or • events outside Secured2's reasonable control.
19.3 Disclaimer
EXCEPT FOR THE EXPRESS WARRANTIES PROVIDED IN THIS AGREEMENT, AND TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, CITADEL AND ALL RELATED SERVICES ARE PROVIDED "AS IS" AND "AS AVAILABLE."
SECURED2 DISCLAIMS ALL OTHER EXPRESS, IMPLIED, STATUTORY, OR OTHER WARRANTIES, INCLUDING IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT.
SECURED2 DOES NOT WARRANT THAT CITADEL WILL BE COMPLETELY ERROR-FREE, OPERATE WITHOUT INTERRUPTION, PREVENT EVERY POSSIBLE CYBERATTACK OR SECURITY EVENT, OR MEET EVERY CUSTOMER REQUIREMENT.
NOTHING IN THIS AGREEMENT EXCLUDES A WARRANTY OR RIGHT THAT CANNOT LAWFULLY BE EXCLUDED.
20. ALLOCATION OF RISK
Customer acknowledges that the Fees charged for Citadel reflect the allocation of risk established by this Agreement, including the warranty disclaimers, Customer responsibilities, indemnification obligations, and limitations of liability. These provisions form an essential basis of the agreement between Customer and Secured2. If Applicable Law prohibits enforcement of a particular limitation, the limitation will apply to the maximum extent permitted by law.
21. LIMITATION OF LIABILITY
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, NEITHER SECURED2 NOR ITS AFFILIATES, OFFICERS, DIRECTORS, EMPLOYEES, AGENTS, LICENSORS, OR SERVICE PROVIDERS WILL BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, PUNITIVE, OR CONSEQUENTIAL DAMAGES ARISING FROM OR RELATING TO THIS AGREEMENT OR CITADEL.
THIS EXCLUSION INCLUDES, WITHOUT LIMITATION, LOST PROFITS, LOST REVENUE, LOST BUSINESS OPPORTUNITIES, LOSS OF GOODWILL, BUSINESS INTERRUPTION, OR LOSS OR CORRUPTION OF DATA, EVEN IF SECURED2 HAS BEEN ADVISED THAT SUCH DAMAGES ARE POSSIBLE.
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, SECURED2'S AGGREGATE LIABILITY ARISING OUT OF OR RELATING TO THIS AGREEMENT OR CITADEL WILL NOT EXCEED THE AMOUNT ACTUALLY PAID BY CUSTOMER TO SECURED2 FOR CITADEL DURING THE TWELVE (12) MONTHS IMMEDIATELY PRECEDING THE EVENT GIVING RISE TO THE CLAIM.
If Customer used Citadel without charge, Secured2's aggregate liability will be limited to the maximum extent permitted by Applicable Law. The foregoing limitations apply regardless of the theory of liability and even if a remedy fails of its essential purpose. Nothing in this Agreement limits liability to the extent such liability cannot lawfully be limited.
22. SECURED2 INTELLECTUAL PROPERTY INDEMNIFICATION
Subject to the limitations contained in this Agreement, Secured2 will defend Customer against a third-party claim alleging that Customer's authorized use of the unmodified Citadel software furnished by Secured2 infringes a United States patent, copyright, trademark, or trade secret. This obligation applies only if Customer: 1. promptly notifies Secured2 in writing of the claim; 2. provides reasonable cooperation; 3. allows Secured2 to control the defense and settlement; and 4. does not admit liability or settle the claim without Secured2's written consent.
If Citadel becomes or, in Secured2's reasonable judgment, is likely to become subject to such a claim, Secured2 may: 1. obtain the right for Customer to continue using Citadel; 2. modify or replace the affected functionality with substantially equivalent non-infringing functionality; or 3. terminate the affected Citadel Services and refund the unused prorated portion of prepaid Fees for the affected Subscription Term.
Secured2 will have no obligation to the extent a claim arises from Customer Data, Customer modifications, unauthorized use, combination with technology not supplied or approved by Secured2 where the combination causes the infringement, or continued use after Secured2 has provided a non-infringing replacement.
23. CUSTOMER INDEMNIFICATION
To the extent permitted by Applicable Law, Customer will defend, indemnify, and hold harmless Secured2, its affiliates, and their respective officers, directors, employees, agents, successors, and assigns from third-party claims, liabilities, damages, judgments, costs, and reasonable attorneys' fees arising from: 1. Customer Data that infringes or violates the rights of another person; 2. Customer's unlawful use of Citadel; 3. Customer's material violation of this Agreement; or 4. Customer's fraud, willful misconduct, or unlawful acts.
Secured2 will provide reasonable notice of an indemnified claim and reasonable cooperation in its defense.
24. U.S. GOVERNMENT CUSTOMERS
Citadel software and Documentation are commercial computer software and commercial computer software documentation. For United States Government customers, Citadel will be licensed consistent with applicable federal procurement law, including applicable provisions governing commercial computer software. The Government receives only those rights expressly granted under this Agreement, an applicable Order, contract, or negotiated addendum, to the extent such terms are consistent with Applicable Law. If an applicable government contract requires rights different from those contained in this Agreement, the parties may document those rights in an appropriate written addendum or contract.
25. EXPORT CONTROL AND SANCTIONS
Customer agrees to comply with United States export-control, economic-sanctions, and trade-control laws applicable to its use of Citadel. Customer may not export, re-export, transfer, provide, or use Citadel in violation of Applicable Law. Customer represents that it will not knowingly use Citadel in connection with a prohibited person, prohibited destination, prohibited transaction, or prohibited end use under applicable United States trade laws.
26. ANTICORRUPTION
Each party agrees to comply with applicable anti-bribery and anticorruption laws, including the U.S. Foreign Corrupt Practices Act to the extent applicable. Neither party will knowingly offer, promise, authorize, request, or provide an unlawful bribe, kickback, or improper payment in connection with this Agreement.
27. CUSTOMER OBLIGATIONS
Customer represents and warrants that: 1. Customer will use Citadel only for lawful purposes; 2. Customer will comply with Applicable Law; 3. Customer has appropriate rights to Customer Data; 4. Customer will maintain reasonable security practices for devices and systems used to access Citadel; 5. Customer will appropriately manage Authorized Users and authentication credentials; and 6. Customer will not knowingly use Citadel in a manner that compromises the security or operation of Citadel or another person's systems.
28. CHANGES TO THIS AGREEMENT
Secured2 may update this Agreement from time to time to address changes in Citadel, Applicable Law, security requirements, technology, or business operations. Secured2 will make the then-current Agreement available electronically. For material changes affecting an existing paid Subscription Term, Secured2 will provide reasonable notice where required by Applicable Law. Unless a change is required earlier for security, legal, regulatory, or compliance reasons, materially adverse changes to Customer's contractual rights ordinarily will become effective upon Customer's next renewal. Continued use of Citadel after an updated Agreement becomes effective constitutes acceptance of the updated Agreement to the extent permitted by Applicable Law.
29. GENERAL PROVISIONS
29.1 Governing Law
This Agreement will be governed by the laws of the State of Minnesota, without regard to its conflict-of-law principles. The United Nations Convention on Contracts for the International Sale of Goods does not apply. Subject to Applicable Law, any legal action arising from or relating to this Agreement will be brought in the appropriate state or federal court located in Minnesota, and each party consents to personal jurisdiction and venue in such courts. Government entities or other Customers legally prohibited from accepting this governing-law provision will be subject to the governing law required by Applicable Law.
29.2 Severability
If any provision of this Agreement is held invalid or unenforceable, that provision will be enforced to the maximum extent legally permitted, and the remaining provisions will remain in effect.
29.3 Waiver
Failure to enforce a provision of this Agreement does not constitute a waiver of that provision or any other provision.
29.4 Assignment
Customer may not assign this Agreement without Secured2's prior written consent, except in connection with a merger, acquisition, corporate reorganization, or sale of substantially all assets relating to the applicable business, provided the assignee agrees to be bound by this Agreement. Secured2 may assign this Agreement in connection with a merger, acquisition, corporate reorganization, financing, sale of assets, or transfer of the Citadel business.
29.5 No Partnership
This Agreement does not create a partnership, joint venture, fiduciary relationship, franchise, employment relationship, or agency relationship between Customer and Secured2.
29.6 No Third-Party Beneficiaries
Except as expressly stated otherwise, this Agreement does not create rights enforceable by any third party.
29.7 Force Majeure
Neither party will be liable for delay or failure caused by circumstances beyond its reasonable control, including natural disasters, war, terrorism, civil disturbance, labor disruption, utility or telecommunications failure, internet disruption, governmental action, widespread cyberattack, or failure of third-party infrastructure beyond the affected party's reasonable control. This Section does not excuse Customer's obligation to pay Fees properly due for services already provided.
29.8 Order of Precedence
If Customer and Secured2 execute an Order, Statement of Work, Data Processing Addendum, service-level agreement, government contract addendum, or other written agreement expressly modifying this EULA, the more specific written agreement will control solely to the extent of the conflict.
29.9 Entire Agreement
This Agreement, together with applicable Orders and other expressly incorporated written agreements, constitutes the entire agreement between Customer and Secured2 concerning Citadel and supersedes prior or contemporaneous discussions or agreements concerning the same subject matter. Terms contained in Customer purchase orders or other Customer documents will not modify this Agreement unless expressly accepted in writing by an authorized representative of Secured2.
29.10 Headings
Headings are provided for convenience only and do not affect interpretation of this Agreement.
29.11 Electronic Communications
Customer agrees that Secured2 may provide contractual notices, billing communications, security notifications, and other Citadel-related communications electronically, subject to Applicable Law.
30. ENGLISH LANGUAGE CONTROLS
This Agreement is prepared in English. Secured2 may provide translations for convenience. If a translation conflicts with the English-language version, the English-language version will control to the extent permitted by Applicable Law.
31. COMPLIANCE WITH EMPLOYMENT AND CIVIL RIGHTS LAWS
To the extent applicable to Secured2's performance under a government contract or Applicable Law, Secured2 will comply with applicable employment, equal-opportunity, veterans, disability, nondiscrimination, and civil-rights requirements. Nothing in this Agreement is intended to impose obligations under a statute, executive order, regulation, or governmental requirement that has been rescinded, repealed, superseded, or is otherwise no longer applicable.
32. CONTACT AND LEGAL NOTICES
Questions regarding this Agreement may be directed to:
Secured2 Corporation Citadel Storage Email: sales@secured2.com
Notices required under an applicable Order may also be delivered using the notice information specified in that Order.
© 2026 Secured2 Corporation. All Rights Reserved.
SECURED2®, Citadel™, and associated names, logos, technologies, product names, and service marks are trademarks or proprietary rights of Secured2 Corporation or their respective owners.
