Terms of Service
These Terms of Service ("Terms") govern your access to and use of the EHIRAR compliance posture scanning platform operated at ehirar.com (the "Service"). By creating an account or subscribing to a paid plan, you agree to be bound by these Terms. If you do not agree, do not use the Service.
In plain language: EHIRAR is a B2B subscription that scans the public-facing posture of domains you own or have permission to scan. You must not use it on domains you do not control. We bill monthly or annually through Lemon Squeezy. Cancel anytime; we will pro-rate where required by law.
1. Definitions
- "EHIRAR", "we", "us": the operators of ehirar.com, based in Türkiye.
- "Customer", "you": the legal entity entering into these Terms.
- "Service": the EHIRAR external posture assessment platform, including its web interface, API, scan engine, AI commentary, and generated reports.
- "Subscription": the paid plan (Essential, Professional, or Enterprise) to which you subscribe.
- "Authorised Domains": the internet domains the Customer is legally entitled to assess.
2. Eligibility and accounts
The Service is offered exclusively to legal entities (companies, partnerships, foundations, and equivalent). It is not intended for individual consumers. By creating an account you represent that you are at least 18 years of age and authorised to bind the legal entity on whose behalf you register. You are responsible for keeping your credentials confidential and for all activity that occurs under your account.
3. The Service we provide
EHIRAR delivers a passive external posture assessment. The Service:
- Reads only the public-facing signals an external observer can already see — DNS, SSL certificates, HTTP headers, publicly accessible files, public subdomain records, JavaScript bundle content.
- Maps findings to specific PDPL articles, NCA ECC-2:2024 controls, and UAE PDPL clauses.
- Generates AI commentary explaining each finding and a recommended remediation path.
- Provides downloadable reports in English and Arabic.
The Service is not a penetration test, vulnerability exploitation tool, intrusion attempt, or active scan. It does not require, and we do not hold, an NCA penetration testing licence, and none is needed to use the Service.
4. Authorised use — what you may scan
You may only submit for scanning domains that you legally own, lease, or have written authorisation to assess. By submitting a domain, you warrant that you hold this authorisation. You agree not to use the Service to:
- Scan domains owned by third parties without their authorisation.
- Build a competing product by scraping the Service.
- Reverse-engineer the scan logic, AI commentary system, or remediation library.
- Interfere with the Service's availability, integrity, or rate limits.
- Use the Service for any unlawful purpose under Turkish, Saudi, Emirati, or your local law.
We reserve the right to suspend or terminate any account engaging in any of the above without refund.
5. Subscription, fees, and billing
Subscriptions are billed by our Merchant of Record, Lemon Squeezy, on a recurring monthly or annual basis depending on the plan you select. Prices are displayed in Saudi Riyal (SAR) and US Dollar (USD).
- Monthly plans renew automatically every month until cancelled.
- Annual plans renew automatically every 12 months until cancelled and include two months at no additional charge versus monthly billing.
- Payment methods: Visa, Mastercard, American Express, and Apple Pay, processed by Lemon Squeezy. Mada-co-badged cards work via the Visa/Mastercard network.
- Taxes: Lemon Squeezy handles VAT, sales tax, and equivalent indirect taxes as required by the customer's jurisdiction.
- Failed payments: the Service may be suspended after three failed renewal attempts. Reactivation requires payment of the outstanding balance.
6. Cancellation and refunds
- Monthly plans: may be cancelled at any time from your account dashboard. Access continues until the end of the current billing period; no further charges are made.
- 14-day money-back guarantee: new monthly subscribers may request a full refund within 14 days of their first charge by emailing support@ehirar.com.
- Annual plans: may be cancelled and refunded within 14 days of the initial charge. After 14 days, annual plans are non-refundable but may be paused or downgraded for the remaining term.
- Refund processing: refunds are issued to the original payment method within 5–10 business days of approval.
7. Acceptable use and rate limits
Each subscription tier has a defined limit on the number of authorised domains, subdomains, and scan frequency. Exceeding these limits or attempting to circumvent them may result in throttling, account suspension, or termination. We may adjust technical rate limits to maintain Service stability; material changes will be communicated by email.
8. Intellectual property
The Service, including its source code, AI prompts, knowledge base, design, and brand, is the exclusive property of EHIRAR and its licensors. You are granted a non-exclusive, non-transferable, revocable licence to use the Service for the duration of your subscription. The reports generated for your authorised domains are yours: you may use, redistribute, and incorporate them into your internal compliance documentation without restriction.
9. Data protection
Our handling of personal data is governed by the Privacy Policy, which forms an integral part of these Terms. We process personal data in compliance with the KSA Personal Data Protection Law, the UAE Personal Data Protection Law, and the GDPR where applicable. Enterprise customers may request a data processing agreement (DPA) by writing to privacy@ehirar.com.
10. Service availability
We target 99.5% monthly uptime for the Essential and Professional tiers, and 99.9% with SLA-backed credits for the Enterprise tier. Scheduled maintenance windows will be announced at least 48 hours in advance. The Service is provided on an "as available" basis, and we do not warrant that it will be uninterrupted, error-free, or that all findings will be exhaustive.
11. Disclaimer of warranties
The Service is provided "as is" and "as available". EHIRAR makes no warranty that the Service will detect every vulnerability, every PDPL violation, or every misconfiguration. The Service is a tool to assist your compliance posture; it is not a substitute for legal counsel, qualified information security professionals, or formal certification audits. To the maximum extent permitted by applicable law, we disclaim all implied warranties of merchantability, fitness for a particular purpose, and non-infringement.
12. Limitation of liability
To the maximum extent permitted by applicable law, in no event shall EHIRAR's aggregate liability arising out of or related to these Terms exceed the total fees paid by the Customer to EHIRAR in the twelve (12) months preceding the event giving rise to the claim. EHIRAR shall not be liable for any indirect, incidental, special, consequential, or exemplary damages, including loss of profits, loss of business, loss of data, or regulatory fines, even if advised of the possibility of such damages.
13. Indemnification
You agree to indemnify and hold EHIRAR harmless from and against any third-party claim arising out of your breach of these Terms, your unauthorised scanning of domains you do not control, or your misuse of the reports generated by the Service.
14. Suspension and termination
We may suspend or terminate your account immediately if you breach these Terms, engage in fraudulent activity, or fail to pay fees due. You may terminate your account at any time as described in Section 6. Upon termination, your access ceases; scan data is retained for the period stated in the Privacy Policy and then permanently deleted.
15. Changes to the Service and to these Terms
We may evolve the Service, add features, retire features, and adjust prices. Material changes to features will be communicated by email at least 14 days in advance. Price increases for existing subscribers will take effect at the next renewal and will be communicated at least 30 days in advance. Continued use of the Service after a change takes effect constitutes acceptance of the change.
16. Governing law and jurisdiction
These Terms are governed by the laws of the Republic of Türkiye, without regard to its conflict-of-laws principles. Any dispute arising out of or in connection with these Terms shall be submitted to the exclusive jurisdiction of the courts of Istanbul (Çağlayan), Türkiye. Nothing in this clause limits the statutory rights of customers domiciled in the Kingdom of Saudi Arabia or the United Arab Emirates to bring claims in their local courts where mandatory consumer or data protection law so permits.
17. Force majeure
Neither party shall be liable for failure or delay in performance to the extent caused by events beyond its reasonable control, including acts of God, natural disasters, war, terrorism, civil unrest, internet outages, third-party cloud provider failures, government action, or epidemics.
18. Entire agreement
These Terms, together with the Privacy Policy and any order form executed between the parties, constitute the entire agreement between you and EHIRAR with respect to the Service and supersede all prior agreements, communications, and proposals.