ECUREM CLM · LEGAL FRAMEWORK

Policies & privacy

Terms of Use, data processing rules and Legal Notices for Ecurem CLM, presented in a structured format for easy reading, reference and audit.

Terms of Use

These Terms of Use govern access to and use of Ecurem CLM, a SaaS service for digital certificate lifecycle management, monitoring, discovery, renewal, notifications, compliance and related certificate operations.

By creating an account, accessing the platform, using a trial period, subscribing to a plan, or using any Ecurem CLM module, agent, API, interface or feature, you agree to these Terms.

1. Definitions

“Ecurem” refers to the brand and activities under which Ecurem CLM is offered. As of the date of these Terms, commercial, contractual and operational activities are carried out by Concept GRC Inc., a corporation registered in Quebec. Ecurem Inc. is being incorporated. Until Ecurem Inc. becomes legally operational and any applicable contractual transition is formally completed, Concept GRC Inc. remains the contracting entity.

“Ecurem CLM” means the Certificate Lifecycle Management platform offered by Ecurem. It may be delivered as SaaS, a dedicated hosted instance or a deployment within the Customer’s environment, and may include certificate management, discovery, renewal, compliance, notifications, dashboards, APIs, agents and integrations.

“Customer” means the organization, business or person that creates an account, subscribes to a plan or uses Ecurem CLM. “User” means any individual authorized to access Ecurem CLM on behalf of a Customer.

“Customer Data” means data, configurations, technical information, metadata, certificates, domains, settings, logs, reports and content supplied, generated or processed through use of the service. “Certificates” means public or private digital certificates, TLS/SSL certificates, internal and test certificates, certificate chains, metadata, expiration dates, fingerprints, certificate authorities and related information.

2. Purpose of the service

Ecurem CLM helps organizations inventory, monitor, manage, renew and document digital certificates. Depending on the selected offering and agreement, it may be provided as SaaS, a dedicated hosted instance or a deployment in the Customer’s environment. The agreed plan or scope may include dashboards, expiration alerts, certificate discovery, renewal workflows, provider and certificate-authority integrations, compliance reports, notifications and APIs.

Ecurem CLM does not provide legal, tax or regulatory advice or certified audits. Platform information is operational assistance, not a guarantee of absolute compliance.

3. Service access and account creation

Access requires an account and accurate, complete and current information, including the user’s name, email address and identifier, the organization name, and information needed for billing or service configuration.

The Customer is responsible for its Users, access rights, credential confidentiality, activation of available safeguards—including multifactor authentication where offered—and all activity performed through its accounts. Ecurem may suspend or restrict an account because of a security risk, misuse, non-payment, a breach of these Terms, suspected compromise or an applicable legal request.

4. Plans and subscriptions

All available subscription plans are displayed at https://clm.ecurem.cloud. Plans may include Basic (free), paid Starter and Premium plans, and an Ultimate/Enterprise plan priced on request according to needs, volumes, integrations, security requirements, support and specific agreements.

Prices are in Canadian dollars unless stated otherwise. Applicable taxes and banking, currency-conversion or processing fees may apply. At the end of any trial period, the Customer must select a paid plan to continue using services that require one. Ecurem may limit, suspend or remove access when a trial expires without an active subscription.

Ecurem may change prices, plans or features and will provide reasonable notice for active subscriptions, except in a security emergency, because of a legal requirement or where a third-party provider imposes a change. Other Ecurem CLM-related products and modules may be sold separately at different prices.

5. Payments, renewal and cancellation

Subscriptions are payable on the schedule shown at checkout and may renew automatically until cancelled by the Customer or Ecurem under these Terms. The Customer must maintain a valid payment method. Following a failed payment, Ecurem may notify the Customer, retry the charge, temporarily suspend service or terminate the subscription after a reasonable period.

Unless required by law or stated in a specific commercial commitment, payments are not prorated or refunded when the Customer cancels during a billing period. Ecurem may apply a more favourable case-by-case policy without creating an ongoing obligation.

6. Customer obligations

The Customer must use Ecurem CLM only for legitimate professional purposes and in compliance with applicable law. The Customer must provide accurate information; obtain authorization to monitor, discover, analyze or renew certificates, domains, services, systems and infrastructure; avoid unauthorized scanning or access; protect private keys, secrets, tokens, credentials, API keys, DNS settings, CA access and integration information; apply least privilege; monitor platform alerts and reports; and comply with the terms of connected certificate authorities, DNS providers, hosts, cloud services and other third parties.

7. Prohibited use

Ecurem CLM must not be used to compromise, bypass or disrupt third-party security; perform unauthorized scans, attacks or intrusive tests; collect data without a legal right or required consent; access another Customer’s accounts, organizations or data; decompile, copy, resell, rent, sublicense or reproduce the platform without authorization; bypass technical, commercial or security limits; or conduct illegal, fraudulent, abusive or rights-infringing activities.

8. Certificate data and operational responsibilities

Ecurem CLM may process public or private certificate data, including domain and organization names, issuance and expiration dates, certificate authorities, fingerprints, algorithms, chains, renewal status, discovery settings and technical logs.

The Customer remains responsible for the validity, accuracy, legitimacy and use of its certificates. Ecurem does not guarantee that a certificate will be issued, renewed, installed or accepted where failure depends on a certificate authority, DNS or cloud provider, Customer configuration, external outage, network problem, validation restriction or required Customer action. The Customer must maintain continuity, backup, rotation, revocation, monitoring and emergency procedures for critical certificates.

9. Platform security

Ecurem implements reasonable administrative, technical and organizational safeguards appropriate to the service, which may include logical organization segmentation, access control, authentication, logging, backups, monitoring, encryption in transit, access restrictions and protection against unauthorized access. No computer system can guarantee absolute security, and the Customer acknowledges the inherent risks of connecting SaaS to systems, domains, certificates, APIs and third-party providers.

10. Multi-tenancy and organization separation

Ecurem CLM is designed to logically separate Customer organizations. Each Customer may access only data associated with its organization or organizations for which it has explicit authorization. Suspected access anomalies, data exposure, permission inconsistencies or tenant-separation failures must be reported immediately to info@ecurem.ca.

11. Agents, APIs and integrations

Ecurem CLM may provide agents, connectors, APIs, webhooks and third-party integrations. The Customer is responsible for installing, configuring, updating, authorizing, monitoring and removing them. Customer-supplied API keys, tokens, secrets, DNS-provider credentials, CA keys, cloud access and other secrets must be protected, withheld from unauthorized persons and revoked when compromise is suspected.

12. Availability, maintenance and evolution

Ecurem seeks to maintain reasonable service availability. Interruptions may occur for maintenance, updates, incidents, security fixes, migrations, backups, third-party failures or force majeure. Ecurem may add, modify, replace or remove features to improve security, performance, compliance, user experience or commercial viability.

13. Support

Support is provided according to the subscribed plan. Unless a contract states otherwise, support is available by email at info@ecurem.ca, and response times may vary with the plan, priority, severity and team availability.

14. Intellectual property

Ecurem, Ecurem CLM, their interfaces, code, text, logos, trademarks, architectures, workflows, knowledge bases, reports, models, scripts, documentation and visual elements belong to Ecurem or its licensors unless stated otherwise. The Customer retains rights in Customer Data and receives only a limited, non-exclusive, non-transferable and revocable right to use Ecurem CLM during the subscription term under these Terms.

15. Data, export and deletion

The Customer may request export or deletion of certain Customer Data, subject to available features and applicable legal, tax, accounting, security and evidentiary obligations. After termination or expiration, Ecurem may retain certain data for a reasonable period to allow recovery, meet legal obligations, prevent fraud, resolve disputes, maintain security or ensure operational continuity.

16. Confidentiality

Each party will protect the other party’s confidential information with reasonable care. Confidential information may include technical, commercial and financial information, security settings, secrets, configurations, reports, incidents, access data, roadmaps and other non-public information. Information that is already public, lawfully known before disclosure, lawfully obtained from a third party or independently developed without use of confidential information is not confidential.

17. Personal information

Processing of personal information is described in the Privacy Policy on this page. The Customer must inform its Users and obtain required consents for use of Ecurem CLM.

18. Third-party services

Ecurem CLM may interact with certificate authorities, DNS and cloud providers, email services, payment gateways, observability tools, hosts, security providers and software libraries. Their own terms, prices, policies and limitations may apply. Ecurem is not responsible for third-party acts, omissions, outages, changes, restrictions, fees or incidents except where required by law.

19. Limitation of liability

To the extent permitted by applicable law, Ecurem is not liable for indirect, special, incidental, punitive or consequential loss, including loss of revenue, profit, operations, business, data, customers or reputation; business interruption; certificate expiration; renewal failure; configuration errors; or website unavailability.

Ecurem’s total liability for any service-related claim is limited to the amount paid by the Customer to Ecurem for the affected service during the three months preceding the event giving rise to the claim, except for gross or intentional fault or where the law imposes a different limit.

20. Indemnification

The Customer agrees to indemnify Ecurem against claims, loss, liability, costs or expenses arising from unauthorized or unlawful use of the service, Customer Data, systems, certificates, secrets, integrations or Users, or from a breach of these Terms.

21. Suspension and termination

The Customer may terminate its subscription through available account controls or by contacting Ecurem. Ecurem may suspend or terminate access because of non-payment, a breach of these Terms, security risk, misuse, legal request, conduct harmful to the service or potential harm to Ecurem, a Customer or a third party.

22. Changes to these Terms

Ecurem may update these Terms to reflect legal, operational, technical, commercial or security changes. The update date will appear at the top of the document, and Ecurem will make reasonable efforts to notify Customers of material changes.

23. Governing law and jurisdiction

These Terms are governed by the laws applicable in Quebec and the applicable federal laws of Canada. Subject to mandatory consumer-protection or jurisdiction rules, disputes will be submitted to the competent courts of the applicable judicial district in Quebec.

24. Contact

Questions about these Terms may be sent to info@ecurem.ca.

Privacy Policy

Ecurem places a high priority on protecting personal information. This Policy explains what information Ecurem CLM collects, why it is collected, how it is used, protected, disclosed and retained, and how individuals may exercise their rights.

It applies to website visitors, prospects, Customers, authorized Users, organization administrators, people communicating with Ecurem and users of Ecurem CLM.

1. Person responsible for processing

The Privacy Officer is Ecurem Management. Requests concerning privacy, access, correction, deletion, portability or complaints may be sent to info@ecurem.ca. During launch, Ecurem is operated by Concept GRC Inc., a corporation registered in Quebec, and may subsequently be operated by Ecurem Inc. once its incorporation and the applicable contractual transition are complete. Identification details will be updated when that transition is completed.

2. Information collected

Ecurem CLM may collect or process:

  • Identity information: first and last name, user identifier, role, organization and professional title when supplied.
  • Contact details: business email address and contact information supplied through forms or communications.
  • Account data: organization name, account settings, plan, trial status, preferences, roles, permissions and administrative history.
  • Connection and security data: IP address, timestamps, browser, device, authentication events, session logs, failed logins, MFA activation and administrative logs.
  • Certificate data: domain names, organization names in public certificates, certificate authorities, issuance and expiration dates, fingerprints, algorithms, certificate chains, renewal status and discovery results.
  • Technical data: discovery configurations, agent settings, execution logs, reports, alerts, integrations, APIs and system events.
  • Payment and billing data: subscribed plan, payment status, invoices and commercial-management information. Full payment-card data is normally processed by a payment provider and not stored directly by Ecurem.
  • Communications: emails, support requests, messages, comments, incident responses and commercial correspondence.

3. Sources of information

Information may be supplied directly by a Customer or User; generated during platform use; obtained from public certificates or Customer-configured services; transmitted by Customer-authorized Ecurem agents; or received from providers needed to operate the service.

4. Purposes of collection and use

Ecurem uses personal and technical information to create, administer and secure accounts; provide Ecurem CLM features; manage organizations, roles, permissions and subscriptions; inventory, monitor, discover and renew certificates as configured by the Customer; send alerts, notifications, reports and service communications; protect the service, prevent fraud, detect unauthorized access and investigate incidents; provide support; improve performance, reliability and quality; meet legal, tax, accounting, contractual and regulatory obligations; and enforce Ecurem’s rights or respond to valid legal requests.

5. Consent and applicable grounds

Where consent is required, Customers and Users consent to collection, use and disclosure in accordance with this Policy by using Ecurem CLM. In a B2B context, certain processing is also necessary to perform the contract, secure the service, meet legal obligations or pursue the legitimate interests of Ecurem and the Customer. The Customer must inform its Users and obtain required authorizations when personal information is supplied, configured or processed in its Ecurem CLM environment.

6. Public certificate data and business data

Public certificates may contain publicly accessible business information or metadata. When associated with an account, organization, User or activity logs, such data may become operationally sensitive and is protected accordingly.

7. Disclosure to third parties

Ecurem does not sell personal information. Information may be disclosed only to providers needed for hosting, security, email, backups, observability, billing, payment or support; to certificate authorities, DNS providers, cloud services or integrations configured by the Customer; to professional advisers, auditors or providers bound by confidentiality; where required by law or competent authority or to protect rights, security and integrity; or in a reorganization, merger, financing, asset sale or business transfer subject to appropriate protections.

8. Hosting and transfers outside Quebec or Canada

Ecurem primarily serves Quebec and Canada. Depending on providers, infrastructure, and support, payment or security tools, information may be hosted, backed up, processed or accessed from other Canadian provinces or countries. Information processed outside Quebec or Canada may be subject to local law. Ecurem seeks providers with reasonable contractual, technical and organizational protections.

9. Retention

Ecurem retains information as long as needed to provide the service, meet legal, tax, accounting, contractual and security obligations, resolve disputes, prevent fraud, document incidents and maintain operational integrity. Account information may be retained during the relationship and for a reasonable period after closure; security logs for a period appropriate to detection, investigation and evidence; and invoices and accounting records for applicable statutory periods.

10. Information security

Ecurem applies reasonable safeguards appropriate to the information, which may include access controls, authentication, MFA where available, logging, logical organization segmentation, encryption in transit, backups, monitoring, configuration hardening and restricted administrative access. Customers must also protect their accounts, passwords, secrets, API keys, tokens, DNS access, private keys, CA settings and connected systems.

11. Privacy incidents

Following a privacy incident involving personal information, Ecurem will take reasonable steps to limit consequences, investigate and document the incident and, where required by law, notify affected individuals and authorities. Customers must promptly report suspected unauthorized access, account compromise, data exposure or security incidents to info@ecurem.ca.

12. Individual rights

Subject to legal exceptions, individuals may request access to personal information; correction of inaccurate or incomplete information; withdrawal of consent where processing relies on consent; deletion where possible and lawful; portability of certain computerized information where applicable; information about use, disclosure and retention; and the filing of a complaint with Ecurem or a competent authority. Requests must be sent to info@ecurem.ca, and identity verification may be required.

13. Cookies and similar technologies

Ecurem CLM may use cookies necessary to operate the service, maintain sessions, secure authentication, remember preferences and prevent abuse. If analytics, advertising or other non-essential cookies are later used, additional notice or consent controls may be introduced as required.

14. Service and commercial communications

Ecurem may send service communications about accounts, security, alerts, incidents, invoices, renewals, policy changes or essential features. Commercial or promotional communications may be limited or withdrawn through available controls or by contacting Ecurem.

15. Minors

Ecurem CLM is intended for organizations and professionals, not children or minors. Ecurem does not knowingly seek personal information from minors.

16. Automated decisions

Ecurem CLM may automatically generate certificate-related alerts, scores, reports, statuses or operational recommendations. These functions assist technical management but do not replace the Customer’s human analysis for critical decisions.

17. Changes to this Policy

Ecurem may update this Policy to reflect legal, technical, commercial, organizational or security changes. The latest update date will appear at the top.

18. Privacy contact

Questions or requests about personal information may be sent to info@ecurem.ca.