Terms of Service
These Terms of Service are made as of 29 September 2026 and apply to every subscription to Readymark concluded on or after that date.
1. Parties and scope
1.1. Readymark is provided by SIA "DDA Projects", registration no. 40203546787, legal address Elizabetes iela 19-7, Rīga, LV-1010, Latvia (the “Provider”), to the business that subscribes through the checkout or signs an order form (the “Customer”; together, the “Parties”).
1.2. The Readymark workspace, vulnerability scans, document templates and, on the Desk plan, the reporting desk (together, the “Service”) are offered to businesses only. By subscribing, the Customer confirms that it acts in the course of its trade or profession and that the person accepting these Terms may bind the Customer.
2. The Service and plans
2.1. The Service helps the Customer prepare documentation and processes required by Regulation (EU) 2024/2847 (Cyber Resilience Act) for products with digital elements. The plans are:
- Starter: €79 per product per month. Scope check, component list and SBOM export, technical documentation, EU declaration of conformity, user security information, disclosure policy, and vulnerability scans.
- Desk: €199 per product per month. Starter, plus review of the Customer's technical documentation by the Provider, alerts on components listed in the CISA Known Exploited Vulnerabilities catalogue, and drafts of Article 14 reports prepared by the Provider.
- Partner: €490 per month, including 10 client products, and €39 per month for each further product.
2.2. A one-off setup fee of €490 applies to each new subscription, except under the founding offer in clause 5.
2.3. On the Desk plan, the Provider aims to deliver a draft of each Article 14 report stage within 4 hours after the Customer notifies the Provider of an event or after an alert for the Customer's components. This is a target, not a guaranteed service level.
3. No legal advice; the Customer's responsibility
3.1. The Service provides tools, templates and drafts. It is not legal advice, and the Provider does not act as the Customer's lawyer, notified body, authorised representative or manufacturer.
3.2. The Customer remains responsible for the compliance of its products with Regulation (EU) 2024/2847 and other law, for the accuracy of the information it enters, for signing the EU declaration of conformity, and for submitting notifications through the single reporting platform within the legal deadlines.
3.3. Scan results come from public databases (OSV.dev and the CISA Known Exploited Vulnerabilities catalogue). They may be incomplete, may list vulnerabilities that do not affect the Customer's build, and may miss vulnerabilities in components that the databases do not cover. The Customer assesses each finding for its product.
4. Fees, invoices and VAT
4.1. Fees are charged monthly in advance through Stripe, based on the number of products in the subscription. The Customer changes that number or its payment method on the billing page. Stripe adjusts the fees pro rata for changes during a period.
4.2. Prices exclude VAT. VAT is added where the law requires it. For supplies to VAT-registered businesses in other EU Member States, the reverse-charge mechanism applies where its conditions are met, and the Customer provides a valid VAT number at checkout.
4.3. If a payment fails and remains unpaid 14 days after the Provider's reminder, the Provider may suspend the paid features until payment is received.
5. Founding offer
5.1. For the first 20 subscriptions, the setup fee is waived and the monthly fees for the first three billing periods are reduced by 50%. Stripe shows the number of places left and applies the discount automatically at checkout.
6. Term and cancellation
6.1. Each subscription runs month to month. The Customer may cancel at any time on the billing page. Cancellation takes effect at the end of the current billing period, and fees already paid are not refunded, except under clause 7.
6.2. The Provider may end a subscription with 30 days' notice by email, or at once if the Customer materially breaches these Terms or uses the Service unlawfully.
7. Documentation guarantee
7.1. If a market surveillance authority or a notified body rejects technical documentation prepared with the Service because of a gap that the Service's requirement checklist covers, the Provider corrects the documentation free of charge and refunds the fees paid for that product for the last three months. This applies only if the Customer completed the relevant workspace steps and gave accurate information. The Customer claims the guarantee in writing within 30 days after the rejection, with a copy of it.
8. Data
8.1. The workspace stores the Customer's product data in the Customer's browser. The Provider receives component names and versions when the Customer runs a scan, and the contact and billing data described in the privacy policy.
8.2. On the Desk plan, the Customer shares with the Provider the information needed for review and report drafts. The Provider keeps that information confidential and uses it only to provide the Service.
8.3. The privacy policy describes how the Provider processes personal data.
9. Intellectual property
9.1. The Provider owns the Service, its software and its templates. During the subscription, the Customer has a non-exclusive, non-transferable right to use the Service for its own products or, on the Partner plan, for its clients' products.
9.2. Documents that the Customer generates with the Service belong to the Customer, and the Customer may keep and use them after the subscription ends.
10. Availability
10.1. The Provider makes reasonable efforts to keep the Service available and may interrupt it for maintenance. The Service depends on third-party services, including Stripe, Netlify, OSV.dev and CISA, which the Provider does not control.
11. Liability
11.1. The total liability of the Provider under or in connection with these Terms is limited to the fees the Customer paid in the 12 months before the event giving rise to the claim.
11.2. The Provider is not liable for indirect or consequential loss, lost profit, lost revenue, or fines and penalties imposed on the Customer by public authorities.
11.3. These limits do not apply to damage caused intentionally or by gross negligence, or where the law does not allow liability to be limited.
12. Changes to these Terms
12.1. The Provider may change these Terms with 30 days' notice by email. If the Customer does not agree, it may cancel before the change takes effect.
13. Governing law and disputes
13.1. These Terms are governed by the law of the Republic of Latvia. The courts of the Republic of Latvia have jurisdiction over any dispute arising from them.
14. Contact
SIA "DDA Projects", Elizabetes iela 19-7, Rīga, LV-1010, Latvia. Email: hello@getreadymark.app.