Terms and Conditions
Effective date: August 10, 2026 · Version 1.0
These Terms and Conditions (the "Terms") govern access to and use of the Bekap platform. Please read them carefully. By accepting an invitation to the Service, creating an account, or using the Service, you agree to be bound by these Terms on behalf of the organization you represent.
1. Definitions
In these Terms, the following expressions have the following meanings:
"Provider", "we", "us" or "our" means OhMyLabs LLC, a limited liability company organized under the laws of the State of Wyoming, United States, with its registered address at 75 E 3rd St, Sheridan, WY 82801, EIN 32-0850248.
"Bekap" or the "Service" means the hosted email backup and recovery software-as-a-service platform operated by the Provider, together with any related applications, application programming interfaces, documentation and support services made available to the Customer.
"Customer", "you" or "your" means the business entity that has been invited to and has registered for the Service, and on whose behalf an Authorized User accepts these Terms.
"Organization" means a tenant workspace created within the Service and associated with the Customer.
"Authorized User" means an individual whom the Customer permits to access the Service under the Customer's Organization, including the Customer's own personnel and, where applicable, personnel of an MSP.
"MSP" means a managed service provider holding an account type that permits it to create, own and administer Organizations on behalf of its own customers, as further described in section 20.
"Workspace Connection" means the authorization granted by the Customer through Google OAuth and domain-wide delegation that enables the Service to access mailboxes within the Customer's Google Workspace domain.
"Customer Storage" means the third-party object storage bucket that the Customer designates and for which the Customer supplies credentials, in which backed-up email content is written, as described in section 6.
"Customer Data" means all data submitted to, generated within, or processed by the Service for the Customer, including Mailbox Content, Backup Metadata, account records and configuration.
"Mailbox Content" means the bodies, headers and attachments of email messages copied from the Customer's Google Workspace mailboxes.
"Backup Metadata" means the index the Service maintains describing backed-up messages, including message and thread identifiers, subject lines, sender and recipient addresses, timestamps, size, labels, attachment indicators and storage keys.
"Order" means the ordering document, invitation, quotation or online plan selection by which the Customer subscribes to the Service, including the plan tier and seat or mailbox entitlement.
"Subscription Term" means the period for which the Customer has subscribed to the Service, as set out in the Order and as renewed in accordance with section 15.
"Data Protection Laws" means all laws relating to the processing of personal data applicable to a party in the performance of these Terms, including the EU General Data Protection Regulation (Regulation (EU) 2016/679) and the California Consumer Privacy Act as amended by the California Privacy Rights Act.
"DPA" means the Data Processing Agreement entered into between the parties, which forms part of these Terms.
2. Scope, business use only and order of precedence
2.1 The Service is offered to businesses and other organizations for use in the course of their trade, business, craft or profession. It is not offered to consumers, and the Customer represents that it is not entering into these Terms as a consumer. Nothing in these Terms is intended to exclude or limit any right that cannot lawfully be excluded or limited.
2.2 These Terms, together with the Order, the DPA, the Privacy Policy, the Cookie Policy, the Refund and Cancellation Policy and, where applicable, the MSP Reseller and White-Label Agreement, constitute the entire agreement between the parties in relation to the Service (the "Agreement").
2.3 If there is a conflict between documents, the following order of precedence applies: (a) the DPA, in respect of the processing of personal data; (b) any signed written agreement executed by both parties that expressly amends these Terms; (c) the Order; (d) these Terms; and (e) all other policies.
2.4 Any terms proposed by the Customer in a purchase order, vendor portal or similar document are expressly rejected and have no effect, notwithstanding any acknowledgement or acceptance of that document by the Provider.
3. Access by invitation; no trial; account registration
3.1 Access to the Service is by invitation only. There is no open self-service registration. An account may be created only through a valid invitation token issued by the Provider or by an MSP or Organization owner authorized to issue invitations.
3.2 The Service does not currently include a free tier or a Provider-operated trial period. Where the Service or an invoice displays a billing status such as "trialing", that status reflects the state reported by our payment processor and does not itself create any entitlement to free or trial access.
3.3 Registration requires the Customer to provide accurate account information and to accept these Terms. Acceptance is recorded against the registering user's account. The Customer must keep its account and billing information current.
3.4 Invitation, verification, activation and password-reset links expire. The Customer is responsible for using them within the periods notified in the relevant message.
4. Authorized Users, roles and account security
4.1 The Service supports differentiated roles within an Organization, which currently include Owner, Admin, Billing, Technical and Read-only. The Customer is responsible for assigning roles appropriately and for reviewing them regularly. The Provider is entitled to treat any action taken through the Customer's Organization by a user holding sufficient permissions as authorized by the Customer.
4.2 The Customer is responsible for all activity occurring under its Organization and for the acts and omissions of its Authorized Users as if they were its own.
4.3 The Service makes available optional multi-factor authentication using time-based one-time passwords, together with backup codes, and enforces account lockout after repeated failed authentication attempts. Multi-factor authentication is not enabled by default. The Customer is responsible for deciding whether to require it and for enabling it for its Authorized Users.
4.4 Session lifetime within the Service is configurable per Organization within the range made available in the Service. Authorized Users may view and revoke their own active sessions. The Customer is responsible for choosing a session timeout appropriate to its risk profile.
4.5 The Customer must notify the Provider without undue delay on becoming aware of any unauthorized access to or use of its Organization or credentials.
5. The Google Workspace connection and the scope of access it grants
5.1 The Customer's attention is specifically drawn to this section. In order to perform backups and restores, the Service requires the Customer to connect its Google Workspace domain. That connection is authorized by a single Google Workspace administrator of the Customer and is established using OAuth together with domain-wide delegation.
5.2 The authorization granted is not limited to the mailbox of the administrator who grants it. It permits the Service to read and, for the purpose of restores, write to every mailbox in the connected Google Workspace domain, and to read the Workspace directory, using the scopes requested at the time of authorization. Mailboxes are then backed up individually according to the Customer's configuration.
5.3 The Customer represents and warrants that: (a) the individual who authorizes the Workspace Connection has authority to bind the Customer and to grant that access; (b) the Customer has a lawful basis for the backup of its personnel's mailboxes; and (c) the Customer has given, or will give, any notice to, and obtained any consent or authorization from, its own personnel, works councils, employee representatives or other stakeholders that applicable law requires in connection with that backup.
5.4 The Customer may disconnect the Workspace Connection at any time from within the Service, or by revoking the delegation in its own Google Workspace administrative console. Doing so will cause backups to fail and may prevent restores.
5.5 The Service depends on Google APIs. The Provider is not responsible for changes to, deprecation of, quota limits imposed on, or interruption of those APIs by Google, or for the Customer's own Google Workspace configuration. However the Provider will make best efforts to mitigate the effects of quotas and limits.
6. Bring Your Own Storage
6.1 The Service operates on a bring-your-own-storage basis only. Mailbox Content backed up through the Service is written to Customer Storage: an S3 or S3-compatible bucket that the Customer selects, owns or contracts for, and for which the Customer supplies credentials to the Service. The Provider does not currently offer, operate or host a storage tier of its own for Mailbox Content.
6.2 Accordingly, the Customer alone determines the geographic region, durability class, versioning, lifecycle rules, redundancy, encryption-at-rest configuration and access policy of the location in which its Mailbox Content is stored, and contracts directly with its storage provider for those services. Any commitment as to residency, availability or durability of that stored content is a matter between the Customer and its storage provider, and no such commitment is given by the Provider.
6.3 The Provider accesses Customer Storage only to write backups and to read data for restores, using the credentials the Customer has supplied. Those credentials are encrypted by the Service before storage.
6.4 The Customer is responsible for maintaining valid storage credentials and sufficient capacity and permissions. The Provider is not liable for failed or incomplete backups or restores caused by revoked, expired or insufficiently privileged credentials, by bucket policy or lifecycle rules configured by the Customer, or by the unavailability, deletion or corruption of Customer Storage.
7. Encryption of backups and key responsibility
7.1 Encryption of backup content is an optional feature configured per backup connection. It is not enabled by default. Where the Customer does not enable it, Mailbox Content is written to Customer Storage without application-layer encryption by the Service, subject to whatever encryption the Customer has configured on its own storage.
7.2 The Service supports two encryption schemes, and the scheme that applies depends on when the relevant backup connection was created:
- Customer-held key (connections created on or after July 12, 2026). An asymmetric keypair is generated in the Customer's browser. Only the public key is transmitted to and stored by the Service, and it is used to encrypt scheduled backups. The private key is never transmitted to or stored by the Provider, except transiently in memory where the Customer supplies it in order to authorize a specific restore.
- Provider-held key (connections created before July 12, 2026). A passphrase-derived key is retained server-side, encrypted under a platform master key. For these connections the Provider retains technical means to decrypt the relevant backups. These connections are not migrated automatically to the customer-held scheme.
7.3 Where the customer-held scheme applies, loss of the private key is unrecoverable. The Provider cannot decrypt, reconstruct, reset or recover encrypted backups without it, and the corresponding Mailbox Content will be permanently inaccessible. The Customer is solely responsible for the secure generation, custody, escrow and backup of its private key, and the Provider excludes all liability for loss of access to data resulting from the loss, corruption or disclosure of that key to the maximum extent permitted by law.
7.4 The Customer may verify which scheme applies to a given connection within the Service and may create a new connection under the customer-held scheme where it wishes to move away from the provider-held scheme.
8. Scope of the Service
8.1 Subject to the Agreement and payment of the fees, the Provider grants the Customer a non-exclusive, non-transferable, non-sublicensable right, during the Subscription Term, to access and use the Service for its internal business purposes, and in the case of an MSP for the purposes permitted by section 20.
8.2 The Service provides scheduled and on-demand backup queueing of mailboxes within a connected Workspace domain, maintenance of Backup Metadata, and restore of backed-up messages to the Customer's Google Workspace on the Customer's authenticated request.
8.3 The Service is a backup and recovery tool. It is not an archiving, legal hold, e-discovery, journaling, records-management or regulatory-compliance product, and it is not represented as satisfying any statutory or regulatory retention obligation applicable to the Customer. The Customer remains responsible for determining whether its own retention and preservation obligations are met and for maintaining any independent copy it requires.
8.4 The Provider may improve, modify or discontinue features of the Service. Where a change would materially degrade a core function of the Service, the Provider will give reasonable prior notice by email or in-product notification.
9. Availability, maintenance and support
9.1 The Provider will use commercially reasonable efforts to make the Service available, but does not commit to any specific uptime percentage or service level unless a separate written service level agreement has been executed by both parties. No service credits are offered under these Terms.
9.2 The Service may be unavailable during planned maintenance, and during emergency maintenance required to preserve security or integrity. The Provider will endeavor to give advance notice of planned maintenance where practicable.
9.3 Support is provided by electronic means to the contact addresses associated with the Customer's Organization during the Provider's normal business hours. Response times are targets, not commitments.
9.4 Backup jobs may fail or be retried for reasons including Google API rate limiting, network conditions, storage errors and credential expiry. The Service records job status and errors, and the Customer is responsible for monitoring backup outcomes reported in the Service and for acting on failures.
10. Customer obligations and acceptable use
10.1 The Customer must not, and must not permit any Authorized User or third party to:
- use the Service other than in accordance with the Agreement or applicable law;
- connect a Google Workspace domain that the Customer is not authorized to administer, or back up mailboxes without the authority to do so;
- use the Service to intercept, monitor or surveil individuals in a manner that is unlawful in the jurisdiction in which those individuals are located;
- copy, modify, translate, reverse engineer, decompile or disassemble the Service or any part of it, or attempt to derive its source code, except to the extent that this restriction is prohibited by applicable law;
- circumvent or attempt to circumvent any authentication, rate limiting, tenancy isolation or other technical control in the Service, or probe or test the Service's vulnerability without the Provider's prior written consent;
- resell, sublicense, rent, lease or otherwise make the Service available to any third party, except where the Customer is an MSP acting within section 20 and any applicable reseller agreement;
- use the Service to store or transmit material that is unlawful, or that infringes the intellectual property or privacy rights of any person; or
- use the Service to build a competing product or to benchmark it for publication without the Provider's prior written consent.
10.2 The Customer is responsible for the lawfulness of the Customer Data and for its own configuration choices within the Service, including the selection of mailboxes to back up, retention periods, encryption settings and storage location.
11. Ownership of Customer Data and licence to operate
11.1 As between the parties, the Customer owns all right, title and interest in and to the Customer Data. Nothing in the Agreement transfers ownership of Customer Data to the Provider.
11.2 The Customer grants the Provider a non-exclusive, worldwide, royalty-free licence to host, copy, transmit, index, display and otherwise process Customer Data solely to the extent necessary to provide, secure, support and maintain the Service and to comply with law. The Provider does not use Customer Data to train machine-learning models and does not sell Customer Data.
11.3 The Provider may generate and use aggregated, de-identified statistical information about use of the Service, provided that such information does not identify the Customer, any Authorized User or any individual and cannot reasonably be used to do so.
12. Retention and deletion of backed-up content
12.1 The Customer may configure a retention period for each backup connection. Where a retention period is configured, backed-up messages older than that period are deleted in accordance with the configuration. The Customer is responsible for selecting a retention period consistent with its own legal, regulatory and internal requirements, and for verifying, before relying on the Service, that the configuration produces the outcome it expects.
12.2 Because backed-up Mailbox Content resides in Customer Storage, the Customer may also delete that content directly in its own storage account at any time. Doing so may leave Backup Metadata in the Service referring to content that no longer exists and may cause restores to fail.
12.3 Retention periods for account, audit and billing records are described in the Privacy Policy.
13. Provider access to Customer accounts
13.1 The Provider maintains internal administrative interfaces that allow authorized Provider personnel to perform account administration, provisioning and support. Through those interfaces, Provider personnel can view account and organization records such as user names and email addresses, account and organization status, plan tier and seat limits, membership, connected Workspace domain and administrator address, and counts of mailboxes and connections, and can take administrative actions such as locking, unlocking, activating or deactivating an account, changing plan tier or seat limit, provisioning an Organization, and correcting billing linkage records.
13.2 Those interfaces do not display Mailbox Content, and the Service provides no facility for Provider personnel to log in as, or impersonate, an Authorized User. Mailbox Content is not held in the Provider's databases at all, and where a customer-held encryption key applies it cannot be decrypted by the Provider.
13.3 The Provider operates the underlying infrastructure on which the Service runs. Provider personnel with a legitimate operational need therefore have technical access to the systems on which account data, Backup Metadata and encrypted credentials reside. Such access is limited to personnel who require it to operate, secure and support the Service, and is subject to the confidentiality obligations in section 18 and to the DPA.
13.4 The Provider will not access the Customer's Organization other than as necessary to provide, secure, support or maintain the Service, to give effect to an instruction from the Customer, or to comply with law.
14. Fees, invoicing and payment
14.1 Fees are set out in the Order and are calculated on a per-mailbox or other metered basis for each Organization. Usage is measured periodically and reported to the Provider's payment processor for billing.
14.2 Billing is by invoice. Invoices are issued through the Provider's payment processor and are payable within thirty (30) days of the invoice date unless the Order states otherwise. The Service does not automatically charge a payment card, and the Customer is responsible for ensuring that invoices are paid when due.
14.3 All fees are exclusive of value added tax, sales tax, use tax, withholding tax and other similar taxes and duties, which the Customer is responsible for paying in addition, save for taxes on the Provider's income.
14.4 If an invoice is not paid when due, the Provider may charge interest on the overdue amount at the lesser of 1.5% per month and the maximum rate permitted by law, accruing daily from the due date until payment, and may recover reasonable costs of collection.
14.5 The Customer must notify the Provider of any good-faith dispute in respect of an invoice within fifteen (15) days of the invoice date, giving reasons. Undisputed amounts remain payable.
14.6 The Provider may change its fees with at least thirty (30) days' prior written notice, with effect from the start of the next Subscription Term.
15. Term, renewal and cancellation
15.1 The Agreement begins when the Customer first accepts these Terms or first uses the Service, whichever is earlier, and continues for the Subscription Term set out in the Order.
15.2 Unless the Order states otherwise, the Subscription Term renews automatically for successive periods of the same length.
15.3 To avoid being charged for the next billing period, the Customer must give notice of cancellation at least thirty (30) days before the start of that period. Cancellation is not currently self-service within the Service; notice must be given to the Provider in writing to the support address notified to the Customer, and the Provider will action the cancellation. A cancellation request received less than thirty (30) days before the start of the next billing period takes effect at the end of that next period.
15.4 Cancellation stops future renewals. It does not entitle the Customer to a refund of amounts already charged or invoiced. Refunds and cancellation are dealt with in full in the Refund and Cancellation Policy.
15.5 Either party may terminate the Agreement immediately by written notice if the other party commits a material breach that is not remediable, or that is remediable and is not remedied within thirty (30) days of written notice requiring it to be remedied, or if the other party becomes insolvent, enters administration, liquidation or an equivalent process, or ceases to carry on business.
16. Suspension
16.1 The Provider may suspend the Customer's access to the Service, in whole or in part, where: (a) an invoice remains unpaid more than fifteen (15) days after written notice of non-payment; (b) the Provider reasonably believes that continued access presents a security risk to the Service, to the Provider or to other customers; (c) the Customer is in material breach of section 10; or (d) suspension is required by law or by a third-party provider on which the Service depends.
16.2 The Provider will give notice of suspension where it is lawful and practicable to do so, and will restore access promptly once the cause has been resolved. Suspension does not relieve the Customer of the obligation to pay fees accruing during the suspension.
16.3 Suspension of access to the Service does not delete Mailbox Content held in Customer Storage, to which the Customer retains direct access through its own storage provider.
17. Effect of termination
17.1 On expiry or termination of the Agreement, the Customer's right to access the Service ends and the Provider may deactivate the Customer's Organization.
17.2 Mailbox Content remains in Customer Storage, under the Customer's own control, and is not deleted by the Provider on termination. The Customer is responsible for retrieving, retaining or deleting it in its own storage account. Where an encryption key held only by the Customer applies, the Customer must retain that key in order to decrypt that content after termination.
17.3 Deletion of account records, Backup Metadata and audit records following termination is dealt with in the Privacy Policy and the DPA. The Provider may retain records to the extent required by law or necessary to establish, exercise or defend legal claims.
17.4 The Customer may request a copy of, or the deletion of, its account data and Backup Metadata by contacting the Provider. These requests are currently handled manually rather than through a self-service function in the Service, and the Provider will action them within the periods described in the Privacy Policy and the DPA.
17.5 Sections that by their nature should survive termination do so, including sections 1, 11, 14, 17, 18, 19, 22, 23, 24, 27 and 28.
18. Confidentiality
18.1 Each party may receive information of the other that is marked confidential or that a reasonable person would understand to be confidential ("Confidential Information"). Customer Data is the Customer's Confidential Information. The Service's non-public features, architecture, security documentation and pricing are the Provider's Confidential Information.
18.2 Each party will use the other's Confidential Information only to perform the Agreement, will protect it with at least reasonable care, and will disclose it only to its personnel and professional advisers who need it and who are bound by equivalent obligations.
18.3 These obligations do not apply to information that is or becomes public without breach, was lawfully known without obligation of confidence before disclosure, or is independently developed. A party may disclose Confidential Information where required by law or a competent authority, giving the other party such notice as is lawful and practicable.
19. Intellectual property
19.1 The Service, the Bekap and OhMyLabs names and logos, and all software, documentation, designs and other materials comprised in or supplied with the Service, and all intellectual property rights in them, are and remain the property of the Provider or its licensors. No rights are granted other than the limited right to use the Service expressly set out in section 8.1.
19.2 Where the Customer provides feedback, suggestions or feature requests, the Provider may use them without restriction or obligation.
19.3 The Copyright and Intellectual Property Notice published with the Service forms part of these Terms.
20. MSP accounts and white-labelling
20.1 An account designated as an MSP account may create and administer multiple Organizations on behalf of the MSP's own customers, and may apply its own branding, including logo, colors and custom domain, to the interface presented to those customers.
20.2 White-labelling grants no right, title or interest in the Service. All intellectual property in the Service remains with the Provider notwithstanding the removal or substitution of Provider branding, and the MSP acquires no right to represent that it developed, owns or operates the underlying platform.
20.3 An MSP is responsible, as between it and the Provider, for its own customer relationships, for its own branding and marketing claims, and for putting in place with each of its customers terms that are no less protective of the Provider than these Terms, including the disclosure required by section 5.2 as to the scope of Workspace access, the bring-your-own-storage model in section 6, the encryption and key-loss position in section 7, and the disclaimers and limitations in sections 22 and 24.
20.4 In respect of personal data, the MSP acts as processor for its customer and the Provider acts as sub-processor. The MSP must ensure that its own customer contracts permit that chain and that the Provider is identified as the operator of the underlying platform in the MSP's own terms or data processing agreement.
20.5 Where the parties have executed an MSP Reseller and White-Label Agreement, that agreement prevails over this section 20 to the extent of any conflict.
21. Third-party services
21.1 The Service depends on third-party services, including Google for mailbox access, a payment processor for billing and invoicing, a transactional email provider for system messages, a bot-mitigation provider on certain public pages, and the Customer's own storage provider. Those services are provided by the relevant third party on its own terms.
21.2 The current list of sub-processors is set out in the DPA and in the Privacy Policy. The Provider is not liable for the acts, omissions, availability, pricing or terms of any third party, other than as expressly provided in the DPA in respect of sub-processors engaged by the Provider.
22. Warranties and disclaimers
22.1 Each party warrants that it has the authority to enter into the Agreement and that its performance will comply with applicable law.
22.2 The Provider warrants that it will provide the Service with reasonable skill and care and in accordance with the Agreement.
22.3 Except as expressly stated in the Agreement, and to the maximum extent permitted by applicable law, the Service is provided "as is" and "as available" and the Provider disclaims all other warranties, conditions, representations and terms, whether express, implied or statutory, including any implied warranty of merchantability, satisfactory quality, fitness for a particular purpose, accuracy, or non-infringement.
22.4 In particular, and without limiting section 22.3, the Provider does not warrant that: (a) the Service will be uninterrupted or error-free; (b) every message in every mailbox will be captured in every backup cycle, or that any particular restore will succeed in whole or in part; (c) backups or restores will complete within any particular time; (d) the Service will meet any archiving, legal hold, evidentiary or regulatory requirement applicable to the Customer; or (e) data stored in Customer Storage will remain available, since that storage is operated by a third party under contract with the Customer.
22.5 A backup product cannot eliminate the risk of data loss. The Customer acknowledges that it is responsible for verifying the integrity of its backups, for periodically testing restores, and for maintaining such independent copies of critical data as its own risk assessment requires.
23. Indemnities
23.1 The Customer will indemnify and hold harmless the Provider and its officers, employees and agents against all losses, liabilities, damages, costs and expenses (including reasonable legal fees) arising out of or in connection with: (a) any claim that the Customer's connection of a Google Workspace domain, or the backup or restore of any mailbox, was unauthorized or unlawful, including any claim brought by an employee or other individual whose mailbox was backed up; (b) the Customer's breach of section 10; (c) any claim by the Customer's storage provider arising from the Customer's configuration or use of Customer Storage; and (d) where the Customer is an MSP, any claim by the MSP's own customer or that customer's personnel arising from the MSP's branding, representations or contractual arrangements.
23.2 The Provider will indemnify the Customer against third-party claims that the Service, as provided by the Provider and used in accordance with the Agreement, infringes that third party's intellectual property rights, provided that the Customer notifies the Provider promptly, gives the Provider sole control of the defense and settlement, and provides reasonable assistance. This indemnity does not apply to claims arising from Customer Data, from the Customer's branding, from combination of the Service with anything not supplied by the Provider, or from use of the Service in breach of the Agreement.
23.3 The indemnity in section 23.2 is subject to the limitations in section 24.
24. Limitation of liability
24.1 Nothing in the Agreement limits or excludes either party's liability for fraud or fraudulent misrepresentation, or for any other liability that cannot lawfully be limited or excluded.
24.2 Neither party is liable to the other, whether in contract, tort (including negligence), breach of statutory duty or otherwise, for any loss of profit, loss of revenue, loss of anticipated savings, loss of business or business opportunity, loss of goodwill, or for any indirect, special, incidental, punitive or consequential loss, even if that party was advised of the possibility of such loss.
24.3 Subject to sections 24.1 and 24.4, each party's total aggregate liability arising out of or in connection with the Agreement in any period of twelve (12) consecutive months is limited to the total fees paid or payable by the Customer for the Service in the twelve (12) months immediately preceding the first event giving rise to the liability.
24.4 The cap in section 24.3 does not apply to the Customer's obligation to pay fees, to the Customer's indemnity in section 23.1, or to either party's breach of section 18.
24.5 To the maximum extent permitted by law, the Provider has no liability for: (a) loss of or inability to access data resulting from the loss, corruption or disclosure of an encryption key held only by the Customer; (b) the loss, deletion, corruption or unavailability of data in Customer Storage; (c) acts, omissions or changes of Google or any other third-party provider; or (d) the Customer's own configuration of retention periods, mailbox selection, roles or encryption settings.
24.6 The parties acknowledge that the fees have been set in reliance on the allocation of risk in sections 22 to 24, and that the exclusions and limitations are reasonable in the context of a business-to-business supply.
25. Data protection
25.1 Each party will comply with the Data Protection Laws applicable to it. In respect of personal data contained in Customer Data, the Customer acts as controller (or as processor on behalf of its own customer, where the Customer is an MSP) and the Provider acts as processor (or sub-processor).
25.2 The DPA governs the Provider's processing of that personal data and is incorporated into the Agreement. Where the Agreement conflicts with the DPA in respect of the processing of personal data, the DPA prevails.
25.3 The Provider has not, as at the effective date of these Terms, appointed a representative in the European Union under Article 27 of the GDPR. The Provider will notify affected Customers once an appointment is made. Nothing in this section is a representation that such an appointment currently exists.
25.4 The Provider's handling of personal data relating to Authorized Users and account contacts in its own right is described in the Privacy Policy.
26. Changes to these Terms
26.1 The Provider may amend these Terms from time to time. Where an amendment is material, the Provider will give at least thirty (30) days' prior notice by email to the Organization's registered contact or by in-product notification, and the amendment takes effect at the end of that period.
26.2 If the Customer objects to a material amendment, it may terminate the Agreement with effect from the date the amendment would take effect, by written notice given before that date. Continued use of the Service after that date constitutes acceptance.
26.3 Non-material amendments, including corrections and clarifications, take effect on publication.
27. Governing law and disputes
27.1 The Agreement, and any dispute or claim arising out of or in connection with it or its subject matter or formation (including non-contractual disputes or claims), are governed by the laws of the State of Wyoming, United States, without regard to its conflict of laws rules. The United Nations Convention on Contracts for the International Sale of Goods does not apply.
27.2 The state and federal courts located in Sheridan County, Wyoming have exclusive jurisdiction, and each party submits to that jurisdiction and waives any objection based on forum non conveniens.
27.3 Section 27.1 does not affect any right of a data subject under the GDPR, or the mandatory rights and remedies of a data subject or supervisory authority, which are not waivable by contract. The governing law of the DPA is as stated in the DPA.
27.4 Before commencing proceedings, each party will use reasonable efforts to resolve the dispute by escalation to a senior representative of each party for a period of thirty (30) days. This does not prevent either party from seeking urgent injunctive relief.
27.5 Each party waives any right to a trial by jury and to participate in any class or representative proceeding, to the maximum extent permitted by law.
28. General
Assignment. The Customer may not assign or transfer the Agreement without the Provider's prior written consent, not to be unreasonably withheld. The Provider may assign the Agreement to an affiliate or in connection with a merger, reorganization or sale of all or substantially all of its assets.
Subcontracting. The Provider may subcontract performance, but remains responsible for the acts and omissions of its subcontractors. Sub-processing of personal data is governed by the DPA.
Notices. Notices to the Provider must be sent in writing to OhMyLabs LLC, 75 E 3rd St, Sheridan, WY 82801, United States, and by email to the address published for legal notices. Notices to the Customer may be given to the email address registered for the Organization and are deemed received on the next business day.
Force majeure. Neither party is liable for failure or delay caused by an event beyond its reasonable control, provided it notifies the other and uses reasonable efforts to mitigate. This does not excuse an obligation to pay.
No waiver. A failure or delay in exercising a right is not a waiver of it, and a single or partial exercise does not prevent further exercise.
Severance. If a provision is held invalid or unenforceable, it is modified to the minimum extent necessary to make it enforceable, or if it cannot be, severed, and the remainder continues in force.
No partnership. Nothing in the Agreement creates a partnership, joint venture, agency or employment relationship.
Third parties. No person who is not a party has any right to enforce the Agreement.
Publicity. Neither party may use the other's name or marks publicly without prior written consent, except that the Provider may identify the Customer as a customer in a customer list with the Customer's prior written consent.
Export and sanctions. Each party will comply with applicable export control and economic sanctions laws, and the Customer represents that it is not located in, or ordinarily resident in, a jurisdiction subject to comprehensive sanctions, and is not a person with whom dealings are prohibited under those laws.
Counterparts and electronic acceptance. The Agreement may be accepted electronically, and such acceptance has the same effect as a signature.
29. Contact
Questions about these Terms should be addressed to:
OhMyLabs LLC
75 E 3rd St, Sheridan, WY 82801, United States
EIN: 32-0850248
Email: legal@bekap.io