Terms of Service
1. Who we are and what these terms cover
Associate Works ("the platform", "we", "us") is a provider-operated client collaboration platform. It is operated by a single independent consultant (the "provider") who uses it to work with the client organisations they serve. Each client organisation receives its own private, isolated workspace on the platform (a "workspace" or "tenant").
These Terms of Service ("terms") are a binding agreement between you and the provider. They govern your access to and use of the websites associate.works and admin.associate.works, the application programming interface (API), the notification channels (email and WhatsApp) and every related service (together, the "service").
Where a separate written agreement between the provider and your organisation (for example an engagement letter, statement of work or master services agreement) addresses the same subject, that agreement prevails over these terms to the extent of the conflict. These terms fill every gap it leaves.
2. Acceptance
You accept these terms by creating an account, accepting an invitation, signing in, or otherwise using the service. If you use the service on behalf of an organisation, you confirm that you are authorised to bind that organisation and "you" includes it.
You must be at least 18 years old and legally able to enter into contracts. The service is a business tool and is not directed at children.
If you do not agree to these terms, do not use the service.
3. The service
The service lets the provider and each client organisation work together inside that client's workspace. Depending on your role, a workspace may include projects and hierarchical tasks, an information library with file attachments, a secrets vault, resource links, comments and mentions, notifications, an activity feed and a trash with restore.
The provider is the sole operator of the platform. The provider creates workspaces, invites people into them, and manages platform-wide settings such as email and WhatsApp templates, API keys and storage. Client organisations use their workspace and never see, share with or contact any other client organisation through the platform.
The service is offered as it exists from time to time. Features may be added, changed or removed. Section 11 explains how we handle material changes.
4. Accounts, invitations and roles
Invitation only. Accounts are created through invitations issued by the provider or by an administrator of your workspace. An invitation is personal to the address it was sent to and expires at the time shown in it.
Roles. Each account in a workspace holds one of two roles. A Workspace Admin may manage the workspace's members, profile and security policy and has full access to the workspace's collaborative content. A Member sees and works on the items they created or were assigned to. The provider holds a separate platform role and can see every workspace in order to operate the service.
Accurate information. You must keep your name, email address and any phone number you provide accurate and current. Notifications and security notices are sent to those addresses.
One person per account. Accounts are for one named person and must not be shared. You are responsible for everything done through your account until you tell us it has been compromised.
API keys. The provider may issue API keys bound to a workspace. An API key acts with the access of that workspace, must be stored securely, and must be revoked through the provider when it is no longer needed or may have been exposed.
5. Your security responsibilities
- Choose a strong, unique password and change it if you suspect it is known to anyone else.
- Where your workspace requires it, or wherever you can, enable two-factor authentication (an authenticator app or a passkey) and keep your second factor safe.
- Sign out on shared devices. Do not disable or work around any security control of the service.
- Tell us without delay through the contact page if you believe an account, API key or secret has been compromised.
Secrets stored in the vault are encrypted at rest and shown only after a fresh second-factor check. You remain responsible for what you choose to store and for who you assign it to.
6. Acceptable use
You agree not to, and not to allow anyone using your account to:
- access or attempt to access any workspace, account, data or system you are not authorised to use, including by probing, scanning or testing the vulnerability of the service without our written permission;
- upload or transmit malware, or content that is unlawful, infringing, defamatory, harassing or otherwise harmful;
- use the service to send unsolicited messages, or to contact the provider's other clients;
- interfere with the operation of the service, impose an unreasonable load on it, or bypass rate limits, the contact-form protections or other technical restrictions;
- reverse engineer, copy, resell, sublicense or provide the service to third parties, except as expressly permitted in writing;
- remove or alter proprietary notices, or misrepresent your relationship with the provider or the platform;
- use the service in breach of any applicable law, including export control, sanctions and data-protection laws.
We may investigate suspected breaches and take any action we consider appropriate, including removing content, suspending accounts and reporting to authorities.
7. Client content and ownership
Your content stays yours. Everything you or your organisation put into a workspace (projects, tasks, notes, files, secrets, comments, links, profile information) is "client content". You or your organisation own it. Nothing in these terms transfers ownership of client content to us.
Licence to operate the service. You grant the provider a non-exclusive, worldwide, royalty-free licence to host, store, copy, transmit, display and process client content solely to provide, secure, back up and support the service and to fulfil the engagement between the provider and your organisation.
Your responsibility. You are responsible for client content, for having the rights needed to put it on the platform, and for making sure it does not break the law or these terms. We do not review client content in advance.
Collaborative items. Within a workspace, Workspace Admins may create, edit, assign, archive, restore and delete collaborative items. Members may create items and edit, assign or delete the items they created or were assigned to, within the limits shown in the application. Deleted items go to the workspace trash and may be restored or permanently purged by an authorised person.
8. Confidentiality and isolation between clients
Every workspace is isolated. Client content is bound to its workspace in the database and in file storage, and requests without a valid workspace context are refused. No client organisation can discover, view, share with or message another client organisation through the service.
The provider treats client content as confidential and uses it only to deliver the engagement and operate the service. The provider may see content across workspaces because they operate the platform, and is bound by the confidentiality terms of the engagement with each client.
You agree to treat non-public information about other people in your workspace, and about the platform's security, as confidential.
9. Privacy
Our Privacy Policy explains what personal data we collect, why, how long we keep it, who we share it with, and the rights you have. It forms part of these terms.
10. Third-party services
The service relies on third-party infrastructure and messaging providers, currently cloud hosting, object storage for files and backups, a transactional email provider, and the WhatsApp Business Platform for optional WhatsApp notifications. Their availability and terms are outside our control. Where you interact with them directly (for example by receiving a WhatsApp message), their own terms and privacy policies also apply to that interaction.
Links to third-party websites are provided for convenience. We are not responsible for their content or practices.
11. Availability, maintenance and changes
We aim to keep the service available at all times but do not guarantee uninterrupted or error-free operation. Planned maintenance is carried out, where practical, outside Indian business hours. Emergency maintenance may happen without notice.
We may change or discontinue features. Where a change materially reduces what your organisation relies on, we will give reasonable notice through the application, by email or through your engagement with the provider.
Backups of the platform database are taken daily and kept for a limited period. They exist to recover the platform from failure and are not a substitute for your own copies of important content. Section 14 explains how to export your data.
12. Fees
Access to the service is provided as part of the professional engagement between the provider and your organisation. Any fees, payment terms and taxes are set out in that engagement, not in these terms. Where no fee is agreed, access is granted free of charge and may be withdrawn as described in section 13.
13. Suspension and termination
By you. A Workspace Admin may remove members at any time. Your organisation may end its use of the service by asking the provider to archive the workspace.
By us. We may suspend or terminate an account or a workspace, with or without notice, if we reasonably believe that these terms have been breached, that the account is compromised, that continued access creates a legal or security risk, or when the engagement between the provider and your organisation ends. Where practical we give notice and an opportunity to export data first.
Effect. On termination your right to use the service ends. Sections that by their nature should survive (including 7, 8, 14 to 19 and 21) continue to apply.
14. Data export and deletion
On request, the provider can export a workspace's content as a machine-readable file that includes every record in the workspace and a manifest of its files. Vault secrets are exported in their masked form only. Ask through the provider or the contact page.
After a workspace is archived and the engagement has ended, the provider deletes or anonymises its content within a reasonable period, subject to legal retention duties and to the rolling deletion of backups described in the Privacy Policy.
15. Intellectual property
The service, including its software, design, text, logos and documentation, is owned by the provider or its licensors and protected by intellectual-property laws. These terms give you a limited, revocable, non-transferable right to use the service for your organisation's internal purposes. No other rights are granted.
If you send us suggestions or feedback about the service, you allow us to use them without any obligation to you.
16. Disclaimer of warranties
The service is provided "as is" and "as available". To the fullest extent permitted by law we disclaim all warranties, express or implied, including warranties of merchantability, fitness for a particular purpose, title and non-infringement, and any warranty that the service will be secure, uninterrupted, timely or error-free, or that content will not be lost. You use the service at your own risk and are responsible for keeping copies of content that matters to you.
17. Limitation of liability
To the fullest extent permitted by law, the provider will not be liable for any indirect, incidental, special, consequential or punitive damages, or for loss of profits, revenue, business, goodwill or data, arising out of or connected with the service or these terms, however caused and under any theory of liability, even if advised of the possibility of such damages.
To the fullest extent permitted by law, the provider's total aggregate liability arising out of or connected with the service or these terms will not exceed the fees paid by your organisation for the service in the twelve months before the event giving rise to the claim, or ten thousand Indian rupees (INR 10,000) if no fees were paid.
Nothing in these terms limits liability that cannot be limited by law, including liability for fraud or for death or personal injury caused by negligence.
18. Indemnity
You will defend, indemnify and hold harmless the provider from and against claims, damages, losses and expenses (including reasonable legal fees) arising out of client content you provide, your breach of these terms, or your unlawful use of the service.
19. Governing law and disputes
These terms are governed by the laws of India. Before starting formal proceedings, the parties will try in good faith to resolve any dispute by discussion for at least thirty days after one party notifies the other of it in writing.
Subject to that, the courts having jurisdiction at the provider's principal place of business in India have exclusive jurisdiction over any dispute arising out of or connected with these terms or the service, and each party submits to that jurisdiction.
20. Changes to these terms
We may update these terms from time to time. The current version is always published at associate.works/terms with its effective date. For material changes we give at least fourteen days' notice through the application or by email. Continued use of the service after the effective date of a change means you accept the updated terms.
21. General
- Entire agreement. These terms, the Privacy Policy and any written engagement between the provider and your organisation are the entire agreement about the service and replace earlier understandings on the same subject.
- Severability. If any provision is found unenforceable, the rest remains in force and the provision is applied to the maximum extent permitted.
- No waiver. A failure to enforce a provision is not a waiver of it.
- Assignment. You may not assign these terms without our written consent. We may assign them to a successor of the provider's business on notice to you.
- Force majeure. Neither party is liable for delay or failure caused by events beyond its reasonable control.
- Notices. We give notices through the application, to the email address on your account, or by public posting at associate.works. You give notices through the contact page below.
22. Contact
Questions about these terms, notices, security reports and requests about your data all reach the provider through the contact page.