Terms of Use
Last updated: 23 June 2026
1. Agreement
These Terms of Use govern your access to and use of the RiskSense website at risksense.cloud, the application at app.risksense.cloud, and our related products and services (together, the Service).
The Service is provided by Bridge Point Limited, NZBN 9429030686984, trading as RiskSense (RiskSense, we, us, or our).
By accessing the Service, signing up for an account, connecting a tenant, accepting an order form, or using any part of the Service, you agree to these terms. If you act for a company, managed service provider, customer, or other organisation, you confirm you have authority to bind that organisation.
If you do not agree to these terms, or you do not have that authority, you must not use the Service.
2. The Service
RiskSense provides security awareness training, simulated phishing, post-click coaching, reporting, and related tools for businesses, organisations, and managed service providers (MSPs).
- Website and free tools: public pages, resources, contact forms, demos, and training-only experiences.
- Trials: time-limited or pilot access to selected product features, subject to any limits we set.
- Paid Service: tenant-connected training, simulated phishing, coaching, reporting, integrations, and admin tools provided under an order form, master services agreement, partner agreement, or other written commercial agreement.
We may improve, add, remove, suspend, or discontinue features from time to time. If a change materially reduces paid functionality you have contracted for, we will give reasonable notice where practical.
3. Business use and authority
The Service is designed for business use. You must be at least 16 years old and must use the Service only for a business, organisation, or other non-consumer purpose.
If you connect a Microsoft 365, Google Workspace, email, identity, or other tenant to RiskSense, you confirm that you have authority from the relevant organisation to do so and to allow RiskSense to process the data needed to provide the Service.
If you are an MSP or reseller, you are responsible for ensuring you have authority from each customer tenant you onboard, administer, or access through RiskSense.
4. Accounts and security
To use most of the Service you need an account.
- The information you provide must be accurate, complete, and kept up to date.
- You are responsible for keeping credentials, invitations, magic links, API keys, and administrator access secure.
- You are responsible for all activity under your account and for the actions of users you invite or administer.
- You must tell us promptly at [email protected] if you suspect unauthorised access or compromise.
We may suspend or restrict access where we reasonably believe there is a security risk, breach of these terms, misuse, non-payment, or legal requirement to do so.
5. Paid Service and Eligible Users
Paid subscriptions, prices, payment terms, tax treatment, contract term, renewals, partner margins, and any service levels are set out in the applicable order form, master services agreement, partner agreement, or other written agreement. If there is a conflict, that written agreement applies ahead of these terms for the conflicting point.
Unless your written agreement says otherwise, paid Service charges are based on the number of Eligible Users in each connected customer tenant.
An Eligible User is an active, deliverable standard user account in a tenant that can receive or participate in the Service. Eligible Users do not include inactive or disabled accounts, accounts without a licence or mailbox, accounts manually excluded from delivery and licensing, or non-user mailbox/resource accounts such as shared mailboxes, room mailboxes, equipment mailboxes, service accounts, or other non-standard mailboxes.
Eligible User counts may be refreshed as tenant directory, licensing, mailbox, and exclusion information changes. You must keep tenant data accurate and must not manipulate directory or exclusion settings to avoid fees while still using the Service for those users.
Late payment, failed payment, or material breach of a commercial agreement may result in suspension or termination of paid access.
6. Free tools and trials
- Free tools and trials are provided as-is, with no service level commitment, and may be changed, limited, or discontinued at any time.
- Training-only tools do not necessarily include simulated phishing, tenant-wide delivery, advanced reporting, or paid integrations.
- We may apply fair-use limits, rate limits, user limits, or feature limits to free tools and trials.
- We may delete dormant free accounts after notice where practical.
7. Acceptable use
You must not:
- Use the Service to send training, simulations, or other content to people outside an organisation you are authorised to manage.
- Use the Service unlawfully, deceptively, harmfully, or in a way that infringes anyone's rights.
- Upload, transmit, or store malicious, unlawful, infringing, defamatory, or harmful material.
- Reverse-engineer, decompile, copy, scrape, or extract the Service, its source code, models, prompts, training content, or outputs except to the extent permitted by law.
- Use the Service, content, outputs, data, or access to build, benchmark, or train a competing product or model.
- Interfere with security controls, rate limits, access controls, billing controls, tenant isolation, or service integrity.
- Probe, scan, or test the vulnerability of the Service without our prior written permission, except under section 14.
8. Customer data and privacy
You retain ownership of data, content, directory information, training records, simulation records, and other material that you or your users provide to or generate through the Service (Customer Data).
You grant RiskSense a worldwide, non-exclusive licence to host, use, copy, process, transmit, display, and create operational outputs from Customer Data only as needed to provide, secure, support, maintain, and improve the Service, comply with law, and enforce our agreements.
You are responsible for having a lawful basis, notice, authority, and any required consents for Customer Data you provide to the Service, including personal information about staff, contractors, customers, or other individuals.
Our Privacy Policy explains how we collect, use, share, store, and protect personal information.
9. Intellectual property
RiskSense and our licensors own the Service, including software, workflows, designs, documentation, training content, templates, models, prompts, analytics, reports, trademarks, and Glitch the AI training companion. These terms do not transfer those rights to you.
You may use RiskSense only as permitted by these terms and your written agreement. You may use our names, logos, and brand assets only with our written permission or as expressly allowed by a partner agreement.
Feedback, ideas, and suggestions you provide may be used by us without restriction or obligation, provided we do not disclose your confidential information.
10. Third-party services
The Service may connect with third-party services such as Microsoft 365, Google Workspace, email providers, identity providers, payment providers, analytics services, and cloud infrastructure. Those services are governed by their own terms and privacy notices.
We are not responsible for third-party services, their availability, or their handling of data except to the extent they act as our contracted service providers.
11. Disclaimers
To the maximum extent permitted by law, the Service is provided as is and as available. We disclaim all warranties, representations, and conditions not expressly stated in these terms or a written agreement, including warranties of accuracy, merchantability, fitness for a particular purpose, non-infringement, uninterrupted operation, and error-free operation.
Security awareness training, simulated phishing, reporting, and coaching can reduce risk, but they cannot eliminate cyber security incidents. RiskSense does not guarantee that any attack, breach, loss, incident, or regulatory issue will be prevented, detected, or successfully responded to.
You remain responsible for your own security programme, technical controls, staff management, compliance obligations, incident response, and decisions made using Service outputs.
12. Liability
Nothing in these terms excludes or limits liability that cannot be excluded or limited by law, including liability for fraud, fraudulent misrepresentation, or any non-excludable statutory rights.
Subject to the paragraph above, RiskSense is not liable for indirect, consequential, special, exemplary, or punitive loss, loss of profits, loss of revenue, loss of business, loss of goodwill, loss of data, loss of opportunity, business interruption, or third-party claims, however arising.
Subject to the first paragraph of this section, RiskSense's total aggregate liability for all claims arising out of or in connection with the Service or these terms is limited to:
- for paid Service claims, the fees paid or payable to RiskSense for the affected Service in the 12 months before the event giving rise to the claim; and
- for free tools, trials, website use, or any other claim not linked to paid fees, NZD $100.
13. B2B statutory position
The Service is supplied to businesses for business purposes. To the maximum extent permitted by law, you confirm you acquire the Service in trade and not as a consumer.
For New Zealand business customers, the parties agree it is fair and reasonable that the New Zealand Consumer Guarantees Act 1993 does not apply, and you contract out of that Act to the maximum extent permitted by section 43. Sections 9, 12A, 13, and 14(1) of the New Zealand Fair Trading Act 1986 are also contracted out of to the maximum extent permitted by section 5D.
For Australian and United Kingdom customers, nothing in these terms excludes, restricts, or modifies any guarantee, right, remedy, or liability that cannot lawfully be excluded, restricted, or modified.
14. Responsible disclosure
If you think you have found a security issue with the Service, report it to [email protected] in good faith. Give us a reasonable opportunity to investigate and fix the issue before public disclosure.
We will not take legal action against researchers acting in good faith under standard responsible disclosure principles, provided they do not access, alter, destroy, retain, or disclose customer or personal data, interrupt the Service, or use social engineering, phishing, malware, or physical attacks.
15. Suspension and termination
You may stop using the Service at any time. Free account deletion can be requested by emailing [email protected].
Paid Service suspension, expiry, renewal, and termination are governed by the relevant written agreement, unless these terms expressly allow earlier suspension or termination.
We may suspend or terminate access immediately for material breach, suspected abuse, security risk, unlawful use, non-payment, or where required by law.
Sections that by their nature should survive termination will survive, including intellectual property, Customer Data rights, confidentiality, liability, governing law, payment obligations, and definitions.
16. Changes
We may update these terms from time to time. When we make material changes, we will update the Last updated date and notify you where appropriate. Continued use of the Service after an update means you accept the revised terms.
We will not use changes to these terms to override a signed order form, MSA, or partner agreement during its current term unless that agreement allows it.
17. Governing law and disputes
These terms are governed by the laws of New Zealand. The New Zealand courts have exclusive jurisdiction to settle any dispute or claim arising out of or in connection with these terms or the Service, except that we may seek urgent injunctive or equitable relief in any jurisdiction.
Please contact us first if you have a complaint so we can try to resolve it.
18. Contact
General questions: risksense.cloud/contact
Legal notices: [email protected]
Bridge Point Limited trading as RiskSense is based in Hamilton, New Zealand.