Skip to the main content
SentinelSphere CRA

The small print

General terms of service

Key terms under which DASKALOS APPS provides CRA readiness services: nature of the services, exclusions, acceptance, fees, liability, governing law.

  • Version of 7 September 2026

⚖ marks a point a French lawyer still has to confirm before we use these terms with a customer.

In short

  • What we do for you, and the work we do not take on — sections 2 and 3.
  • You stay the manufacturer of your product: signing the declaration and putting on the CE mark are yours to do — section 2.
  • Who watches your product after we finish — you do, with a tool in your own account; we do not watch it and we are on call for nobody — sections 3 and 6.
  • How you accept a piece of work, and what happens if one falls short of what we owe — section 5.
  • Fees, invoices and payment — section 7.
  • What we are answerable for, and the limits on it — section 9.

This summary is here to help you find your way. It does not replace the terms below, and the agreement you sign comes before both.

Jump to a section

1. Who these terms apply to

These terms apply to professional customers who order services from DASKALOS APPS SAS (the "Provider"). They are not consumer terms. Services are ordered under a master services agreement and one or more statements of work signed by both parties. In case of conflict, the signed agreement prevails, then its annexes, then the statement of work, then this page.

2. Nature of the services

Purpose. The services are professional advisory and engineering-support services intended to help the customer prepare for and maintain its own compliance with the Cyber Resilience Act. Each engagement is a fixed-scope piece of work that ends when its last deliverable is accepted. We operate nothing, watch nothing and are on call for nothing.

Obligation of means. The Provider performs the services with reasonable skill and care, in accordance with good industry practice, using appropriately qualified personnel. The Provider does not guarantee, warrant or represent that the customer, any product, any process or any deliverable is, will be, or will be found by any authority to be, compliant with the regulation, any standard or any other law.

The customer remains the manufacturer. The customer is and remains the manufacturer (or importer or distributor) of its products and is solely responsible for the obligations attached to that role: essential requirements, conformity assessment, technical documentation, the EU declaration of conformity, CE marking, vulnerability handling, support period commitments, security updates and all notifications and reports to authorities. The Provider is not appointed and does not act as authorised representative; does not sign, issue or co-sign any declaration of conformity; does not affix CE marking; is not a conformity assessment body or notified body and issues no certificate; does not place any product on the market; does not, in any circumstances, submit any notification, report or communication to an authority on the customer's behalf, and accepts no mandate to do so — every submission is made by the customer, in its own name, from its own account, on its own assessment and within its own deadlines; and does not monitor the customer's products, systems, components or any vulnerability feed on the customer's behalf, receives no alert from any monitoring tool, and owes no response to any alert, vulnerability or incident.

Not legal advice. The services interpret technical and regulatory requirements from an engineering perspective. They are not legal advice.

Evolving framework. Implementing measures, guidance and standards change, and several standards are drafts. Deliverables reflect the Provider's professional understanding at the date of delivery. The Provider has no obligation to monitor for such changes, to notify the customer of them, or to update any deliverable after delivery. Where the customer orders a periodic review, that review is a new engagement under its own statement of work, priced and accepted in its own right; it is not an update of an earlier deliverable and it does not renew automatically.

Automated tooling and AI. The Provider uses scanning tools and AI-assisted tooling, including large language models, to produce parts of the services. Every deliverable is reviewed and released by a named professional before delivery. Such tools may fail to detect issues and may produce output requiring correction. The Provider's obligations remain an obligation of means.

3. Exclusions

Unless a statement of work expressly includes them, the services do not include, and the Provider is not responsible for: penetration testing, red-teaming, security certification or attestation of any product; modifications to the customer's source code, firmware, products, infrastructure or supply chain, or their remediation; any submission, notification or communication to any authority, or representation before one; legal advice or the determination of the customer's legal obligations; hardware testing, radio, safety or other regulatory regimes; any monitoring, watch, alerting, triage, response or availability of any kind, whether during or outside business hours — we operate no watch, hold no rota, are on call for no one, and offer no response target, service level or service credit in respect of any vulnerability, alert or incident; any guarantee that a product is free of vulnerabilities or that all vulnerabilities, exploitation or incidents will be detected; the operation, availability, accuracy, completeness, security, continuity, licensing or cost of any monitoring tool or other third-party tool we recommend, evaluate or configure under section 6, and any change its vendor makes to it after hand-over; the receipt of, or any action or response to, any alert, report or finding produced by such a tool or by the customer's own systems; the obligations of the customer's importers, distributors or downstream customers; and any work on products, versions or components not identified in the statement of work.

Four of these exclusions are absolute: no statement of work may buy back submission to an authority, monitoring or availability of any kind, responsibility for a third-party tool, or a response to an alert. A statement of work purporting to include them has no effect. ⚖

4. Customer obligations

The customer provides complete and accurate information, materials and access in good time, designates a single point of contact with authority to decide, and is solely responsible for its own decisions, including which recommendations to implement and whether, when and what to notify to any authority. The Provider may rely on the customer's materials and decisions without independent verification. The customer records its decisions on the Provider's recommendations in a decision log; a recommendation not recorded as accepted within 10 business days of delivery is deemed declined.

5. Deliverables and acceptance

Within 10 business days of delivery, the customer either accepts the deliverable in writing or notifies a material non-conformity with the statement of work, with reasonable detail. A deliverable is deemed accepted if no such notice is given in that period or if the customer uses it for its business. Where a material non-conformity is duly notified, the Provider corrects it within a reasonable time and re-delivers; the corrected deliverable has a further acceptance period of 5 business days. Correction and re-delivery are the customer's sole and exclusive remedy for non-conformity of a deliverable. Beyond that period, and for twelve months from delivery, the Provider corrects and re-delivers at no charge a deliverable that falls short of the reasonable skill and care owed, including where a customer of the customer or a distributor rejects it for a reason inside the agreed scope (Article 7.4 of the services agreement). That undertaking does not qualify Article 13.4: the Provider gives no warranty concerning the position an authority may take, and a rejection or challenge by an authority is not a trigger. ⚖ Where the deliverable is, or includes, a configuration made in an account we no longer have access to — a monitoring tool handed over under section 6 — that undertaking is discharged by giving the customer corrected written instructions it can apply itself; it does not oblige us to regain access to that account, and it does not cover anything changed there after hand-over. ⚖

6. Monitoring set-up and tool recommendations

What is ordered. Where a monitoring set-up is ordered in a statement of work, the Provider, for one technical-documentation unit and on a one-off basis: advises on the choice of a monitoring tool suited to the customer's stack, component list and budget; configures that tool in an account held by, contracted for by and paid for by the customer, against the component list identified in the statement of work; routes that tool's alerts to contacts designated by, and belonging to, the customer; delivers a written runbook telling the customer what to do when its own monitoring alerts it, and a picture of the customer's exposure at the date of the set-up; walks the customer through the configured tool; and hands over.

What is not ordered, and it is the essential point. The set-up is a one-off piece of advisory work that ends at hand-over. The Provider does not monitor the customer's products. After hand-over we hold no account, receive no alert, watch no feed on the customer's behalf, and owe the customer no response, no availability, no service level and no service credit in respect of any vulnerability, alert or incident, at any hour. We are not a security operations centre, an incident-response provider or a managed-security-service provider. The exposure picture describes the position on the day it was produced and nothing after it.

The customer monitors, decides and reports. The customer is and remains solely responsible for operating and paying for the tool and keeping its configuration, component list and contacts current; for receiving, reading and acting on its alerts; for determining whether a vulnerability is actively exploited or an incident is severe; for deciding whether, when and what to notify to an authority; and for making every submission itself, in its own name and within the statutory deadlines.

Third-party tools. The tool is supplied to the customer by its vendor, under the customer's own contract with that vendor. The Provider is not a party to that contract, is not the vendor's agent, distributor or reseller, and gives no warranty of any kind in respect of the tool. Vulnerability feeds and the tools built on them are third-party sources which may be incomplete, inaccurate or delayed, and neither party controls them.

Recommendations are advice, and any interest is disclosed. ⚖ Every recommendation of a named tool or vendor states plainly, in writing and at the time it is made, whether the Provider has any commercial relationship with that vendor — a referral fee, commission, reseller margin, partner status, or free or discounted use — and if so what it is; is a recommendation only, which the customer is free to decline or replace with a tool of its own choosing; and is recorded in the decision log with the customer's decision, so that the record shows the customer chose the tool. A recommendation is not a certification, an endorsement, a procurement decision or an assurance that the tool is fit for the customer's purpose.

Credentials. The customer gives such access to its own accounts as the set-up requires. The Provider holds that access only for as long as the set-up requires it, uses it only for the work in the statement of work, and at hand-over returns or destroys every credential it held and confirms in writing that it has done so. From that confirmation we have no access to and no visibility of the tool or its alerts.

7. Fees, invoicing and payment

Fees are stated in the statement of work, exclusive of VAT and of pre-approved expenses invoiced at cost. Unless the statement of work provides otherwise, fixed-price services are invoiced 50% on signature and 50% on delivery, save that a statement of work whose total fee is small is invoiced in full on delivery. No service is invoiced on a recurring basis: a periodic review, where ordered, is invoiced under its own statement of work in the year it is performed. Invoices are payable within 30 days of the invoice date by bank transfer, without set-off or withholding. An invoice dispute must be notified within 10 business days of receipt; the undisputed part remains due. ⚖ Late payment automatically incurs, without notice, interest at three times the French legal interest rate and a fixed recovery indemnity of €40 per invoice, as provided by French law, without prejudice to further costs on justification. If an invoice remains unpaid 15 days after a written reminder, the Provider may suspend the services and withhold deliverables until payment.

8. Intellectual property and data

The Provider's pre-existing materials (methods, control library, knowledge base, templates, prompts, software and tooling) remain its property. On full payment, the customer receives a non-exclusive, perpetual licence to use, reproduce and modify the deliverables for its internal purposes and to demonstrate the conformity of its products to authorities, customers and auditors; deliverables may not be resold or used to provide services to third parties. Customer materials remain the customer's property. The Provider does not use customer materials, including source code, to train, fine-tune or evaluate machine-learning models, and contracts with its AI model providers on terms under which customer materials are not used to train the provider's models. Where the Provider processes personal data on the customer's behalf, it does so as processor under the data processing agreement annexed to the master services agreement, with sub-processors established in the EU.

9. Warranties and liability

The Provider warrants that the services are performed with reasonable skill and care; the sole remedy for breach of this warranty is correction or re-performance under section 5. All other warranties, including as to fitness for purpose, results, compliance, absence of vulnerabilities or detection of vulnerabilities, are excluded to the extent permitted by law. The Provider gives no warranty concerning the position any authority may take on scope, classification, conformity or notification.

Cap. ⚖ The Provider's total aggregate liability arising out of or in connection with the agreement and any statement of work does not exceed the total fees paid by the customer under the statement of work giving rise to the claim during the twelve months preceding the event giving rise to the claim.

Excluded losses. The Provider is in no event liable for indirect or consequential loss; loss of profit, revenue, business, contracts, opportunity, goodwill or anticipated savings; loss, corruption or unavailability of data or software; regulatory fines, penalties or sanctions of any kind; costs of recall, withdrawal, corrective measures, market-surveillance actions or product suspension; claims by third parties, including product-liability claims; losses arising from any security incident, exploitation, vulnerability or breach affecting the customer's products or systems; costs of remediating products; or losses arising from the acts or omissions of the customer, an authority or a third-party provider of feeds, hosting or other services.

Reliance. The Provider has no liability arising from inaccurate, incomplete or late customer materials, information or decisions, or from the customer's failure to implement a recommendation.

Mandatory carve-outs. ⚖ Nothing in these terms excludes or limits liability for gross negligence (faute lourde), wilful misconduct (dol), death or personal injury caused by negligence, or any other liability that cannot be excluded or limited under applicable law.

Time bar. ⚖ Any claim against the Provider must be brought within twelve months of the event giving rise to it.

The customer retains the regulatory and product risk attaching to its role as manufacturer and maintains appropriate insurance. The Provider maintains professional civil liability insurance with [INSURER] for at least [INSURED AMOUNT] per claim and per year.

10. Term and termination

The master services agreement may be terminated by either party on three months' written notice without affecting statements of work in progress. Every statement of work ends on acceptance of its last deliverable. There are no retained, recurring, subscription or continuing services under these terms, and no service renews automatically. Where the customer orders a periodic review, each review is a separate statement of work signed for that occasion; placing one such order neither obliges nor entitles either party to a further one, and no tacit renewal arises from a review being ordered in successive years. ⚖ Either party may terminate for material breach not remedied within 30 days of written notice. On termination the customer pays for services performed and deliverables delivered up to that date. The sections on the nature of the services, exclusions, the correction undertaking, credentials, fees, intellectual property, confidentiality, data protection, warranties and liability survive termination. ⚖

11. Governing law and jurisdiction

These terms and the agreement are governed by French law. The parties attempt to resolve any dispute amicably within 30 days of written notice. ⚖ Failing that, any dispute is submitted to the exclusive jurisdiction of the Tribunal de commerce de Bourg-en-Bresse, including in case of multiple defendants, summary proceedings or third-party proceedings.

12. Contact

DASKALOS APPS SAS, [FULL ADDRESS], Péronnas, France. RCS Bourg-en-Bresse 928 998 715. [CONTACT EMAIL]. Company details are on the legal notice page.

Anything here you would like explained?

Ask us. An engineer answers, in plain words, and says so when a question is one for your own lawyer.