Terms of Service & Refund Policy
- Who you are contracting with
- What CRA Shield is — and is not
- Accounts and eligibility
- Plans, limits and pricing
- Payment, VAT and invoicing
- Licence and acceptable use
- Your data and uploads
- Availability and support
- Intellectual property
- Disclaimer — not legal advice
- Limitation of liability
- Term, suspension and termination
- Changes to these terms
- Governing law and disputes
- Refund Policy
- Contact
These Terms of Service (“Terms”) govern your access to and use of the CRA Shield website at cra-shield.com and the CRA Shield application at app.cra-shield.com (together, the “Service”). By creating an account or purchasing a plan, you agree to these Terms. If you do not agree, do not use the Service.
The Refund Policy in section 15 forms part of these Terms. Please read it before you buy — it explains that CRA Shield is sold on a no-refund basis, and what your mandatory rights under EU law are regardless.
1. Who you are contracting with
“CRA Shield” is a trading name of the operator of the Service. In these Terms, “we”, “us” and “our” refer to that operator, who provides the Service to you and is responsible for it under these Terms. Our full legal entity name, registered address and VAT identification are available on request at [email protected].
We are the seller of record for your purchase and the party that invoices you. Card payments are processed on our behalf by Stripe, which acts as our payment processor only — see section 5.
“You” means the natural or legal person entering into this contract. Where these Terms distinguish between a consumer (a natural person acting outside their trade, business, craft or profession) and a business customer (everyone else, including sole traders acting for business purposes), the distinction matters most in the Refund Policy.
2. What CRA Shield is — and is not
CRA Shield is a self-service compliance toolkit that helps software developers prepare for the EU Cyber Resilience Act (Regulation (EU) 2024/2847). It provides:
- a classification wizard that indicates a likely product class based on answers you provide;
- a self-assessment checklist against the essential requirements of Annex I;
- SBOM generation from dependency files you upload, with vulnerability lookup via the public OSV.dev database;
- generation of draft compliance documents from templates;
- optionally, scheduled vulnerability monitoring and pre-filled incident report forms (paid add-on).
CRA Shield is a documentation and workflow tool. It does not certify, audit, approve or file anything on your behalf, it is not a notified body or conformity assessment body, and it does not submit anything to ENISA, any market surveillance authority or any other regulator. Achieving and demonstrating compliance remains entirely your responsibility. See section 10.
3. Accounts and eligibility
- You must be at least 16 years old and able to enter into a binding contract.
- Authentication is via Google OAuth, GitHub OAuth, or an email magic link. We do not store passwords.
- You are responsible for everything that happens under your account and for keeping access to your email and OAuth accounts secure.
- You must provide accurate information and keep it current. One account per person or legal entity.
- Tell us promptly at [email protected] if you suspect unauthorised access.
4. Plans, limits and pricing
| Plan | Price | Billing | Included |
|---|---|---|---|
| Free | €0 | — | 1 app. Classification wizard only — assessment, SBOM and document generation require a paid plan. |
| Developer | €149 | One-time | Up to 2 apps. Classification, assessment, SBOM, document generation. |
| Professional | €249 | One-time | Up to 10 apps. Same features as Developer. |
| Vulnerability Monitoring add-on | €7 / month | Recurring subscription | Scheduled vulnerability scanning, email alerts, incident reporter forms. |
The one-time plans grant access to the Service as it exists from time to time, for as long as we operate it (see section 8 — a one-time payment is not a perpetual guarantee of availability). App limits are enforced by the Service; exceeding them requires an upgrade. The Monitoring add-on is a subscription that renews monthly until cancelled.
5. Payment, VAT and invoicing
- Payments are processed by Stripe, acting as our payment processor. We are the seller of record and issue your invoice. We never receive or store your card details.
- Prices are stated in euro (EUR). Any applicable VAT is calculated and shown at checkout before you confirm payment.
- Business customers can enter a valid VAT ID at checkout where reverse-charge treatment applies.
- The Monitoring add-on renews automatically each month at the then-current price until you cancel. We will give at least 30 days’ notice by email before any price change affecting your subscription.
- If a payment fails or is reversed, we may suspend access until it is resolved.
6. Licence and acceptable use
Subject to these Terms and, for the paid plans, payment of the applicable fee, we grant you a limited, non-exclusive, non-transferable, non-sublicensable right to use the Service for your own compliance purposes (including on behalf of your employer or clients, where you are acting for them).
You must not:
- resell, rent, sublicense or provide the Service as a service bureau to third parties;
- copy, reverse engineer, decompile or attempt to derive the source code of the Service, except to the extent this restriction is prohibited by applicable law;
- circumvent app limits, authentication, rate limits or any other technical restriction;
- scrape or access the Service by automated means other than functionality we expressly provide;
- upload malware, unlawful content, or files you do not have the right to upload;
- use the Service to build or train a competing product, or to benchmark it for publication without our written consent;
- use the Service in a way that damages, disables or overburdens it, or interferes with other users.
7. Your data and uploads
You retain all rights in the data and files you upload (“Your Content”), including dependency manifests, app details, assessment notes and generated documents. You grant us only the licence needed to host, process and display Your Content in order to operate the Service for you.
You warrant that you have the right to upload Your Content and that doing so does not infringe anyone else’s rights. Do not upload secrets, credentials, API keys or personal data of others — dependency manifests should not contain them.
Personal data is handled as described in our Privacy Policy, which forms part of these Terms. You can export Your Content and delete your account at any time.
8. Availability and support
The Service is provided on an “as available” basis. We do not offer a service level agreement or an uptime guarantee, and we may modify, suspend for maintenance, or discontinue features. If we permanently discontinue the Service altogether, we will give you at least 30 days’ notice by email and a reasonable opportunity to export Your Content.
Support is by email at [email protected]. We aim to respond within two business days. This is a target, not a contractual commitment.
9. Intellectual property
The Service, including its software, design, text, templates and the CRA Shield name and logo, is owned by us or our licensors and is protected by intellectual property law. Nothing in these Terms transfers ownership to you.
Documents you generate using the Service are yours to use, adapt and publish for your own compliance purposes, without attribution.
10. Disclaimer — not legal advice
You are solely responsible for determining whether your products fall within the scope of the Cyber Resilience Act, for the accuracy of the information you enter, for reviewing and adapting every generated document before relying on it or submitting it, and for your own regulatory compliance. Vulnerability data is sourced from third-party public databases (OSV.dev) and may be incomplete, delayed or inaccurate; a clean scan is not a guarantee that your software is free of vulnerabilities.
To the fullest extent permitted by law, and without limiting the mandatory rights described in section 15.4, the Service is provided without warranties of any kind, whether express or implied, including any implied warranty of merchantability, fitness for a particular purpose, accuracy or non-infringement.
11. Limitation of liability
Nothing in these Terms excludes or limits our liability for death or personal injury caused by our negligence, for fraud or fraudulent misrepresentation, for intent or gross negligence, under applicable product liability law, or for anything else that cannot lawfully be excluded — including a consumer’s mandatory statutory rights.
Subject to that paragraph:
- we are not liable for indirect, incidental, special, consequential or punitive damages, or for loss of profits, revenue, goodwill, data, or anticipated savings;
- we are not liable for regulatory fines, penalties, enforcement action, product recalls or third-party claims arising from your compliance decisions or from your use of documents generated by the Service;
- our total aggregate liability arising out of or in connection with these Terms is limited to the total amount you actually paid us in the 12 months preceding the event giving rise to the claim.
Where you are a consumer, these limitations apply only to the extent permitted by the law of your country of habitual residence.
12. Term, suspension and termination
- These Terms apply from the moment you create an account until your account is deleted.
- You may stop using the Service and delete your account at any time. Deleting your account does not entitle you to a refund — see section 15.
- You may cancel the Monitoring add-on at any time; it remains active until the end of the paid period and then stops renewing.
- We may suspend or terminate your access if you materially breach these Terms (in particular section 6), if required by law, or if your payment is reversed. Where the breach is capable of remedy, we will give you notice and a reasonable chance to fix it first.
- On termination, sections 7, 9, 10, 11, 14 and 15 survive.
13. Changes to these terms
We may update these Terms to reflect changes to the Service, the law, or our business. We will post the revised version here with a new “Last updated” date. If a change is material and disadvantageous to you, we will notify you by email at least 30 days in advance; for subscribers, continued use after the notice period constitutes acceptance, and you may cancel before it takes effect. Changes never apply retroactively to a purchase already made.
14. Governing law and disputes
These Terms are governed by the law of the country in which the operator of CRA Shield is established, excluding its conflict-of-law rules and the UN Convention on Contracts for the International Sale of Goods. The courts of that country have jurisdiction.
If you are a consumer, this choice of law does not deprive you of the protection of the mandatory provisions of the law of your country of habitual residence, and you may bring proceedings in the courts of that country. Consumers in the EU can also seek help from their national European Consumer Centre (ECC-Net). We are not obliged to, and do not, participate in dispute resolution proceedings before a consumer arbitration board.
Please contact us first at [email protected] — most issues are resolved quickly.
15. Refund Policy
15.1 Why there are no refunds
CRA Shield is an information product: the entire value — classification logic, checklists, SBOM output, vulnerability data and generated documents — is delivered digitally and in full the moment your payment succeeds. It cannot be returned, and once accessed it cannot be un-received. Pricing reflects this. All sales are therefore final.
Nothing prevents you from evaluating the product first: the plans, feature list and limits are described on our pricing page and in section 4 above, and we answer pre-sales questions at [email protected].
15.2 Business customers
If you are purchasing in the course of a trade, business, craft or profession, you have no right of withdrawal under EU consumer law, and no refunds are given for any reason other than our own material breach of these Terms. This includes, without limitation: change of mind, duplicate or accidental purchase, purchasing the wrong plan, lack of use, dissatisfaction with the classification result, or your project being cancelled.
15.3 Consumers: the 14-day withdrawal right and its waiver
If you are a consumer in the EU, you would normally have 14 days to withdraw from a distance contract without giving a reason (Articles 9–16 of Directive 2011/83/EU on consumer rights).
Because CRA Shield is digital content supplied immediately and not on a tangible medium, that right ends as soon as performance begins with your agreement. Accordingly, at checkout you are asked to confirm both of the following before payment completes, in line with Article 16(m) of that Directive:
- that you expressly request immediate access to the software; and
- that you acknowledge you thereby lose your right of withdrawal once access begins.
We record that confirmation and send you an order confirmation by email on a durable medium. Once you have given it and access has been provided, the withdrawal right no longer applies and no refund is due. If you are not willing to give that confirmation, do not complete the purchase — simply cancel the checkout; you will not be charged.
If, exceptionally, you were charged without having given that confirmation, the 14-day withdrawal right still applies and we will refund you in full. Write to [email protected] stating your order reference; we will refund within 14 days using the original payment method, at no cost to you.
15.4 What we always honour: your statutory rights if something is wrong
The no-refund rule above concerns voluntary refunds and withdrawal. It does not affect the mandatory rights consumers have when digital content or a digital service is faulty. Under Directive (EU) 2019/770, we must supply software that matches its description and works as it should. If it does not, you are entitled to have it brought into conformity and, where that is impossible, disproportionate or we fail to do it within a reasonable time, to a proportionate price reduction or termination of the contract with a refund. Those rights cannot be excluded by contract, and any term purporting to do so is not binding on you.
In practice, this means we will fix a genuine defect — and if we cannot, you get your money back for the part affected. It does not mean a refund because the Service did not produce the compliance outcome you hoped for, because you disagree with a classification result that correctly reflects your answers, or because a third-party vulnerability database returned data you did not expect.
To make a claim, email [email protected] with your order reference and a description of the problem, including steps to reproduce it. We will respond within 5 business days.
15.5 Monitoring add-on (subscription)
The €7/month Vulnerability Monitoring add-on can be cancelled at any time by emailing [email protected]. Cancellation stops future renewals; the add-on stays active until the end of the period you have already paid for. We do not refund or pro-rate the current billing period, and we do not refund past periods for non-use. Section 15.4 applies here too if the service is defective.
15.6 Duplicate charges and payment errors
Genuine billing errors are not refunds and are always corrected: if you are charged twice for the same plan, charged after cancelling the add-on, or charged an incorrect amount, email [email protected] and we will return the difference in full.
15.7 Chargebacks
Please contact us before initiating a chargeback — if there is a billing error or a defect, we will resolve it directly and faster. We may suspend an account with an unresolved chargeback until the matter is settled. This does not limit your rights under sections 15.3, 15.4 and 15.6.
16. Contact
General and billing support: [email protected]
Privacy and data requests: [email protected]
Security issues: [email protected]
CRA Shield is a compliance toolkit, not legal advice. These Terms govern your use of the Service; they are not a substitute for professional advice on your own CRA, GDPR or consumer-law obligations as a software vendor.