Legal
Terms of Service
Last updated: August 9, 2026
These Terms describe the basic rules for using Compliance Platform during public website access, account registration, workspace use, API access, and free or paid service use.
Use of the service
These Terms form a contract between the organization or person accepting them (the Customer) and Norvext SIA, a Latvian limited liability company, registration number 40203766785, registered address Irbju iela 12, Jūrmala, LV-2011, Latvia (Norvext, we or us). Compliance Platform is the service covered by these Terms (the Service). Contract notices may be sent through the Contact page or to sales@norvext.com.
Compliance Platform provides tools for TARIC/CN checks, sanctions and restricted-party screening, legal-entity screening support, reports, organization workspaces, API access, and related operational workflows.
Users must provide accurate account information, keep credentials secure, and use the service only for lawful business purposes.
Compliance information
Compliance Platform maintains its own structured working databases and search indexes derived from publicly available official sources and reference datasets, including TARIC, EUR-Lex, EU financial sanctions files, OFAC SDN/Non-SDN, UN Security Council lists, UK Sanctions List, Swiss SECO sanctions data, the U.S. Consolidated Screening List, Canada SEMA, Australia DFAT, Ukraine NSDC, Japan MOF, Latvian FID resources, and GLEIF LEI reference data.
These internal databases are used to make tariff, sanctions-list, restricted-party, legal-entity, legal-reference, and reporting workflows faster and easier to review. They do not replace the official sources.
The platform helps organize compliance research and evidence, but it does not replace legal, customs, trade, or regulatory advice, or a final decision by a competent authority.
Users remain responsible for reviewing outputs, validating business context, and ensuring critical trade and regulatory decisions are reviewed by qualified customs, legal, or trade compliance professionals and verified against official sources or competent authorities.
Compliance Platform is not affiliated with, endorsed by, or operated by the European Commission, EUR-Lex, or any EU institution.
Accounts, organizations, and API access
Organization owners and administrators are responsible for inviting the correct users, assigning appropriate roles, protecting API keys, and removing access when it is no longer needed.
API and MCP access must not be used to overload, probe, reverse engineer, bypass limits, or interfere with the platform or its providers.
The Customer retains its rights in data it submits to or generates through the Service. The Customer grants Norvext a non-exclusive, royalty-free licence for the service term to host, copy, transmit, process and display that data only as necessary to provide, secure, maintain and support the Service, follow documented instructions and comply with law. This licence does not permit Norvext to sell Customer data or use it for unrelated purposes.
Data processing
When a customer organization submits personal data for processing on its behalf, the Data Processing Terms published on the DPA page are incorporated into these Terms and apply to every plan, including Free and paid plans.
A person accepting these Terms for an organization confirms that they are authorized to bind that organization. A separately signed customer agreement or DPA may replace the standard Data Processing Terms to the extent stated in that agreement.
Commercial terms and billing
The selected plan, checkout page, Order Form or signed customer agreement states the applicable fees, billing cycle, included allowances and any committed term. Unless expressly stated otherwise, published prices exclude VAT. VAT is calculated at checkout and added where applicable. The Customer must provide accurate legal, billing and tax information; no reverse-charge treatment is promised unless the supplied tax information is validated and the law permits it.
Recurring subscriptions are billed in advance and renew for the selected billing period until cancelled. The Customer may cancel renewal before the next billing period. Unless an Order Form says otherwise, a downgrade or cancellation takes effect at the end of the paid period, and fees already paid are not refundable or creditable for a partial period except where mandatory law requires it.
Case and API top-ups are prepaid credits for the current billing period, are used after the included allowance and expire at the end of that period unless an Order Form states otherwise. Extra seats and monitoring packs are recurring subscription items. There is no automatic post-paid overage: when available credits are exhausted, the affected paid actions may be blocked until the Customer upgrades or buys an additional package.
Availability, changes, suspension and termination
We aim to keep the Service available and reliable, but access may be interrupted for maintenance, provider issues, security incidents or changes to external data sources. We may change features and limits, but will not reduce a paid Customer's material committed functionality during the then-current paid term except where reasonably necessary for security, law or a third-party dependency.
We may refuse, suspend or terminate access where reasonably necessary because of overdue payment, a material breach, abuse or a security threat, or to comply with applicable sanctions, export-control laws or a binding request of a competent authority. We will limit the action where reasonably possible, give notice where legally permitted and restore access when the reason is resolved. A possible name match alone should be reviewed before a sanctions-based decision is made.
We may update these Terms. We will give at least 30 days' notice of a material change that adversely affects a paid Customer, unless a shorter period is required for law, security or an urgent provider change. If the Customer does not accept such a change, it may terminate the affected paid Service before the change takes effect and receive a refund of prepaid fees for the unused period. We may discontinue the Service on the same notice and refund basis.
Warranties and liability
Except for express commitments in an applicable Order Form or SLA, the Service is provided “as is” and “as available” to the maximum extent permitted by applicable law. This applies to test, free and paid use.
Norvext does not warrant that outputs will be complete, error-free, current at every moment or sufficient on their own for a legal or business decision. The Customer remains responsible for validating context, reviewing matches and non-matches, and checking critical conclusions against official sources and qualified professionals.
To the maximum extent permitted by law, Norvext is not liable for indirect, incidental, special, consequential, exemplary or punitive damages, or for loss of profits, revenue, business, goodwill or anticipated savings. Norvext's total aggregate liability relating to the Service is limited to the fees paid or payable for the Service in the 12 months before the event giving rise to the claim, or EUR 100 for Free, trial or unpaid use.
Nothing in these Terms excludes or limits liability for fraud, wilful misconduct, death or personal injury caused by negligence, or any other liability that applicable law does not allow the parties to exclude or limit.
Switching, export and exit (EU Data Act)
For Customers within the scope of Articles 23–31 of the EU Data Act, a request to switch to another data-processing service, move to on-premises infrastructure or erase exportable data may be sent through the Contact page. Norvext will initiate the switching process within 30 days after a valid request. This contractual 30-day period is shorter than the statutory maximum notice period of two months. The standard transition period will not exceed 30 calendar days.
If completing the transition within 30 calendar days is technically unfeasible, Norvext will notify the Customer within 14 working days after the request, explain the technical reason and state an alternative transition period that will not exceed seven months. Direct transfer to another provider is supported only where technically feasible and securely authorized by the Customer; these Terms do not promise migration to a named provider.
Exportable data includes Customer-provided and Customer-generated cases, screening inputs and results, decisions, notes, monitoring configuration and history, uploaded files and related metadata, to the extent available to the Customer and not protected as Norvext or third-party trade secrets. Norvext provides standard exports in commonly used, machine-readable formats such as CSV or JSON, and original file formats where available, through a secure download or another documented delivery method. The Customer has at least 30 calendar days after the transition period to retrieve the data; Norvext then deletes it, subject to legal retention duties and protected backup cycles.
Standard export and switching assistance is included as described in the documentation. Custom migration, transformation, integration, data cleansing or professional services require a separate written scope and may be charged separately. Any permitted early-termination or switching charge must be stated before commitment, may not exceed Norvext's directly attributable costs and will not be charged from 12 January 2027 where the EU Data Act prohibits it.
Governing law and jurisdiction
Unless a separate written agreement says otherwise, these Terms are governed by the laws of Latvia, without regard to conflict-of-law rules.
Unless mandatory law requires another forum, disputes relating to these Terms or the service will be handled by the competent courts of Latvia.
Language of these Terms
These Terms, the Privacy Policy, the Cookie Policy and the Data Processing Terms are published in several languages so that each team can read them in its own. The Latvian version is the binding one: where a translation differs from it in meaning, the Latvian text prevails.
Contact
For questions about these Terms, privacy, access, or commercial setup, use the Contact page and include the organization name and account email where relevant.