Ruvalin

Engagements

Terms of service

The rules that apply to paid engagements: audit, monitoring, awareness training and, where commissioned, penetration testing. They sit behind the quote, which remains the governing document.

Last updated

01

Purpose and scope

These terms govern the services provided by Tom Gernez, trading as Ruvalin, SIRET 947 978 433 00037 (“the provider”), to its business clients (“the client”).

They apply to every order, to the exclusion of any purchasing terms of the client's unless the provider accepts them expressly in writing. Use of the site and its free tools is covered by a separate document, the terms of use

02

Contract documents

The contract consists of the signed quote and its schedules, the data processing annex where personal data is entrusted to the provider, and these terms. Where they conflict they rank in that order: the quote first, these terms last.

03

The services

  • Authentication audit and remediation: establishing the state of the SPF, DKIM and DMARC records, inventorying sending services, fixing what is missing, then moving DMARC to rejection in stages.
  • Monitoring and monthly reporting: collecting and reading the aggregate reports returned by receiving servers, and a monthly summary in plain language.
  • Phishing awareness: measured simulation campaigns, followed by a debriefing session with the teams.
  • Penetration testing, where expressly commissioned and covered by written authorisation.

The exact content, scope and timetable of each engagement are set out in the quote. Anything outside that scope is priced in an amendment before it is carried out.

04

Quote, order and performance

Quotes are valid for thirty days. The contract is formed on receipt of the signed quote, or of written acceptance by email, which counts as signature between the parties.

Stated timescales are indicative and run from the point at which the client actually provides the information and access required. Delay attributable to the client shifts the timetable accordingly.

05

Price, invoicing and payment

Prices are in euros and are not subject to VAT: article 293 B of the French tax code applies. They depend on the number of domains and sending services involved.

Unless the quote says otherwise, one-off work is invoiced on completion and recurring work monthly in advance. Payment is by bank transfer, thirty days from the invoice date.

Late payment automatically incurs, without prior notice, interest at the European Central Bank's most recent refinancing rate plus ten points, together with a fixed recovery charge of forty euros (articles L. 441-10 and D. 441-5 of the French Commercial Code). No discount is given for early payment.

Where payment is more than thirty days late and a reminder has gone unanswered, the provider may suspend monitoring and reporting until the account is settled, without that suspension amounting to a breach on its part.

06

Term, renewal and termination

Monitoring is agreed for the term stated in the quote and renews automatically for equal periods. Either party may end it at the term on thirty days' written notice.

Where either party is in serious breach, the other may terminate automatically thirty days after an unanswered formal notice. At the end of the relationship the provider hands over the configuration then in force and stops all collection, without affecting the protection already published on the client's domain.

07

The client's obligations

  • Name a single point of contact, authorised to approve DNS changes.
  • Provide accurate and complete information, in particular the list of services sending email in its name.
  • Apply the DNS values supplied, or grant limited access to the zone concerned.
  • Inform staff in advance that a phishing simulation campaign will take place, and consult employee representative bodies where the law requires it.
  • Report without delay any incident, change of tool or new sending service liable to affect the configuration.

Hardening authentication without a complete inventory of legitimate senders can stop messages sent in your name being delivered. That is why the move to rejection is staged, and it is also why the completeness of the information the client provides is decisive.

08

Nature of the undertaking

The provider is bound by an obligation of means, not of result. Information security cannot be guaranteed: the work reduces an exposure, it removes neither the risk of impersonation nor that of a compromise by a route outside the agreed scope.

In particular, no DMARC configuration prevents mail being sent from a different domain that merely looks like yours. That is a technical fact, stated before the engagement rather than after it.

09

Penetration testing

No penetration test begins without specific prior written authorisation, signed by an authorised representative of the client, setting out the technical scope, the time windows, the emergency contacts and the excluded actions. That authorisation is what makes the work lawful; it is not a formality.

Where the scope covers systems hosted by a third party, it is for the client to obtain that host's agreement. Such engagements are delivered together with senior partner engineers, under the provider's responsibility, who answers for their work as for his own.

10

Confidentiality

Each party keeps confidential the information it receives from the other and uses it only to perform the contract. The obligation survives the relationship by five years. Security findings concerning the client, and the very existence of vulnerabilities, are covered without time limit.

11

Ownership of deliverables

Reports, findings and recommendations delivered to the client belong to it once paid for in full, and it may put them to whatever internal use it wishes. The provider retains ownership of its pre-existing methods, templates, tools and know-how, which it remains free to use on other engagements.

12

Liability

The provider's liability, on any basis whatsoever, is limited to the amount excluding tax actually paid by the client for the service concerned over the twelve months preceding the triggering event.

Indirect loss, loss of revenue, loss of data and reputational harm are excluded. These limits do not apply in cases of gross negligence or wilful misconduct, to personal injury, or where the law forbids them.

13

Personal data

Where an engagement has the provider process personal data on the client's behalf — DMARC reports, the addresses of recipients in a simulation campaign — the parties are bound by the data processing annex

Processing of the client's own data for commercial administration is described in the privacy policy

14

Use as a reference

The provider will not name the client, publish its logo or refer to the engagement without prior written agreement. Discretion is part of the work, and the absence of published references on this site is not an oversight.

15

Force majeure and right of withdrawal

Neither party is liable for a failure caused by force majeure within the meaning of article 1218 of the French Civil Code. Where the impediment lasts more than sixty days, either party may terminate without compensation.

These services are addressed to professionals acting in the course of their business, so no right of withdrawal applies. By exception, a client employing five staff or fewer who commissions work unrelated to its main activity has the fourteen-day period provided by article L. 221-3 of the French Consumer Code.

16

Governing law and disputes

The contract is governed by French law. The parties will seek an amicable solution first: write to contact@ruvalin.com or call +33 6 44 64 17 13. Failing agreement within thirty days, the dispute falls to the exclusive jurisdiction of the French courts.

The French version prevails; this English translation is provided for convenience.

CallBook