Software Services Agreement
SKRIB, INC.
Software Services Agreement (SSA)
For Organization and Enterprise customers | Effective Date: 26 May 2026 | Last Updated: 26 May 2026
This Software Services Agreement (this “Agreement”) is entered into between Skrib, Inc. (“Skrib”) and the customer identified in the Order (“Customer”) and governs Customer’s access to and use of Skrib offerings provided under Organization and Enterprise plans. If Customer is purchasing a free or Professional plan, the Skrib Terms of Service at https://skrib.com/legal/terms apply instead of this Agreement. If Customer is purchasing through a reseller authorised by Skrib (a “Reseller”), this Agreement supplements the agreement between Customer and Reseller governing the purchase of subscriptions to the Skrib Platform.
By accepting this Agreement as part of an Order, you agree to this Agreement on behalf of the entity for which you are acting (such as an employer) (“Customer”). You represent and warrant that you have full legal authority to bind Customer to this Agreement. If you do not have authority or do not agree, you (and Customer) are not authorised to access or use the Skrib Platform.
Capitalised terms used but not defined in the body of this Agreement are defined in Exhibit A.
1. Skrib’s obligations
1.1 Access to the Skrib Platform.
Subject to this Agreement, Skrib grants Customer a limited, non-exclusive, non-transferable (subject to Section 9.6), non-sublicensable right in the Territory, during the Order Term, for Authorized Users to access and use the Skrib Platform in connection with Customer’s own business purposes.
1.2 Protection of Customer Data.
Skrib will implement and maintain the security requirements set forth in Exhibit B. The Data Processing Addendum at https://skrib.com/legal/dpa is incorporated into this Agreement by reference.
2. Service terms
2.1 Use restrictions.
Except as expressly authorised, Customer will not, and will not encourage or assist third parties to: (i) reverse engineer, decompile, disassemble, or attempt to derive source code or algorithms from the Skrib Platform (except where such restriction is impermissible under applicable law); (ii) provide, sell, resell, transfer, sublicense, lend, distribute, rent, or otherwise allow others to access or use the Skrib Platform; (iii) copy, modify, create derivative works of, or remove proprietary notices from the Skrib Platform; or (iv) use the Skrib Platform for personal or other non-commercial purposes.
2.2 Acceptable Use Policy.
Customer will comply with the Acceptable Use Policy at https://skrib.com/legal/aup, which is incorporated into this Agreement.
2.3 Account management.
Customer will appoint one or more administrative users to manage Customer’s account, add or remove Authorized Users, approve purchases, and act on behalf of Customer for purposes relating to the Skrib Platform and this Agreement. Each Authorized User account is personal; account credentials may not be shared. Customer is responsible for the confidentiality of usernames and passwords and for all activities of its Authorized Users.
2.4 Customer Content.
As between the parties, Customer retains all rights in Customer Content. Customer authorises Skrib and its service providers to use Customer Content for the sole purpose of providing the Skrib Platform and performing the activities contemplated by this Agreement (including maintaining, securing, debugging, and otherwise performing quality control).
2.5 Feedback.
If Customer provides feedback, comments, or suggestions concerning the Skrib Platform (collectively, “Feedback”), Customer grants Skrib the right to use such Feedback to maintain, improve, and enhance Skrib’s products and services.
2.6 Usage Data.
Skrib may collect and analyse data and other information relating to access, use, and performance of the Skrib Platform (“Usage Data”) and may use Usage Data in de-identified and aggregated form to maintain, improve, and enhance Skrib’s products and services. Usage Data excludes Customer Content itself.
2.7 Reservation of rights.
As between the parties, Skrib owns all right, title, and interest in the Skrib Platform. Customer owns all right, title, and interest in Customer Content. Except as expressly granted, all rights are reserved.
3. Charges and payment
This Section 3 applies when Customer purchases subscriptions to the Skrib Platform directly from Skrib (and not via a Reseller).
3.1 Fees.
Customer will pay Skrib all fees described in an Order in accordance with the terms therein. Unless otherwise specified, all fees are stated and payable in U.S. Dollars; payment obligations are non-cancellable and not subject to setoff; fees paid are non-refundable; and quantities purchased cannot be decreased during the Order Term. Skrib may change fees applicable to a renewal by providing Customer at least forty-five (45) days’ written notice before the end of the then-current Order Term.
3.2 Payment.
Unless otherwise specified, Customer will be invoiced annually in advance, with full payment due thirty (30) days from the date of the invoice. Unpaid amounts are subject to a finance charge of 1.5% per month or the maximum permitted by law, whichever is lower. If Customer fails to pay, Skrib may limit access to the Skrib Platform in addition to other remedies.
3.3 Taxes.
Fees do not include taxes. Each party is responsible for the payment of all taxes (including any interest and penalties) imposed on that party by law in connection with this Agreement.
3.4 Withholding.
Payments by Customer will exclude any deduction or withholding. If a deduction or withholding is required by law, Customer will pay such additional amounts as are necessary so that the net amount Skrib receives equals the full amount Skrib would have received without the deduction or withholding.
4. Confidentiality
4.1 Confidential Information.
Each party (the “Discloser”) may disclose Confidential Information to the other party (the “Recipient”). Skrib’s Confidential Information includes non-public information regarding the features, functionality, performance, and security of the Skrib Platform; Customer’s Confidential Information includes Customer Content. Confidential Information excludes information that (a) becomes generally available to the public without action or omission by Recipient; (b) was known to Recipient before receipt; (c) was rightfully disclosed to Recipient without restriction by a third party; or (d) was independently developed by Recipient without use of Discloser’s Confidential Information.
4.2 Obligations.
Recipient will use Discloser’s Confidential Information only to exercise its rights and fulfil its obligations under this Agreement. Recipient will use reasonable care to protect against disclosure to parties other than Recipient’s employees, contractors, affiliates, agents, or professional advisers (“Representatives”) who need to know and have legal obligations to keep it confidential. Recipient may disclose Discloser’s Confidential Information (a) if directed by Discloser, or (b) to the extent required by legal process, with prompt notice to Discloser where lawful. Confidentiality obligations under this Section survive for the duration of the Order Term and five (5) years after expiration or termination.
5. Warranties
5.1 Mutual warranties.
Each party represents and warrants that this Agreement has been duly executed, that the executing party is not subject to any other agreement or restriction that would prevent performance, and that it will perform its obligations in accordance with applicable law.
5.2 Skrib warranties.
During the Order Term, Skrib represents and warrants that (a) the Skrib Platform and any applicable support services will be provided in substantive conformity with the Documentation; and (b) Skrib will employ industry-standard measures to protect the Skrib Platform against software viruses, Trojan horses, worms, or similar malicious code.
5.3 Disclaimer.
EXCEPT FOR THE EXPRESS REPRESENTATIONS AND WARRANTIES IN THIS SECTION 5, THE PARTIES MAKE NO REPRESENTATION OR WARRANTY OF ANY KIND, AND SKRIB EXPRESSLY DISCLAIMS ALL IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, QUALITY, ACCURACY, TITLE, AND NON-INFRINGEMENT. NON-SKRIB RESOURCES ARE PROVIDED BY THIRD PARTIES AND ARE SOLELY BETWEEN CUSTOMER AND THE THIRD-PARTY PROVIDER.
6. Indemnity
6.1 Indemnification by Skrib.
Skrib will defend Customer from any third-party Claim alleging that the Skrib Platform infringes or misappropriates a third-party copyright, patent, trade secret, or trademark, and will indemnify Customer for any Losses resulting from such Claim. Skrib has no obligation to defend or indemnify to the extent the Claim is based on (i) Customer’s failure to use updates or modifications Skrib has made available; (ii) the combination, operation, or use of the Skrib Platform with third-party equipment, software, or data, including Non-Skrib Resources, where the infringement would not have occurred but for the combination; (iii) use of the Skrib Platform in violation of this Agreement; or (iv) Customer Content.
If Customer’s use of the Skrib Platform is, or in Skrib’s reasonable discretion is likely to be, subject to a Claim that may give rise to indemnity obligations, Skrib may, at no charge to Customer (in addition to indemnity obligations): (i) procure for Customer the right to continue using the Skrib Platform; (ii) replace or modify the Skrib Platform so that it is non-infringing and includes substantially similar functionality; or (iii) if (i) and (ii) are not commercially practicable, terminate Customer’s right to use the impacted portion and provide a pro-rata refund of any pre-paid fees that remain unused as of termination.
THIS SECTION 6.1 SETS FORTH SKRIB’S SOLE AND EXCLUSIVE OBLIGATIONS, AND CUSTOMER’S SOLE AND EXCLUSIVE REMEDIES, WITH RESPECT TO ANY ACTUAL OR ALLEGED INFRINGEMENT BY THE SKRIB PLATFORM.
6.2 Indemnification by Customer.
Customer will defend Skrib from any Claim based on Customer Content or Customer’s (or Customer’s Authorized Users’) use of the Skrib Platform in violation of this Agreement, and Customer will indemnify Skrib from any Losses resulting from such Claim.
6.3 Process.
If a party entitled to indemnification (the “Indemnified Party”) becomes aware of an indemnifiable Claim, it will give the other party (the “Indemnifying Party”) written notice as soon as reasonably practicable. The Indemnified Party will cooperate at the Indemnifying Party’s expense and will allow the Indemnifying Party sole control of the defence or settlement. The Indemnified Party may participate at its own expense. The Indemnified Party will use commercially reasonable efforts to mitigate Losses and will not admit liability without consent (except as required by law). Indemnity obligations are contingent on compliance with this process.
7. Limitations of liability
7.1 Indirect liability.
EXCEPT FOR EXCLUDED CLAIMS, UNDER NO CIRCUMSTANCES WILL EITHER PARTY OR ITS AFFILIATES OR PARTY REPRESENTATIVES BE LIABLE FOR ANY SPECIAL, INDIRECT, INCIDENTAL, CONSEQUENTIAL, OR EXEMPLARY DAMAGES (INCLUDING LOSS OF PROFITS, DATA, USE, OR COVER) ARISING OUT OF OR RELATING TO THIS AGREEMENT, EVEN IF SUCH PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
7.2 Aggregate liability.
EXCEPT FOR EXCLUDED CLAIMS, THE TOTAL AGGREGATE LIABILITY OF EITHER PARTY ARISING OUT OF OR RELATING TO THIS AGREEMENT WILL NOT EXCEED THE FEES PAID AND PAYABLE TO SKRIB UNDER THE APPLICABLE ORDER IN THE TWELVE-MONTH PERIOD PRIOR TO THE DATE ON WHICH THE DAMAGE OCCURRED.
7.3 Excluded Claims.
“Excluded Claims” means damages resulting from (1) either party’s wilful misconduct or gross negligence; (2) infringement by a party of the other party’s intellectual-property rights; or (3) Customer’s payment obligations.
7.4 General.
Each provision providing for a limitation of liability, disclaimer of warranties, or exclusion of damages allocates the risks of this Agreement between the parties. The limitations apply to the maximum extent not prohibited by law and notwithstanding the failure of essential purpose of any limited remedy.
8. Term and termination
8.1 Term.
This Agreement begins on the Subscription Start Date of the first Order between the parties and continues until all Orders expire or until terminated as provided here.
8.2 Termination.
Either party may terminate an Order or this Agreement on written notice if the other party materially breaches and the breach is incapable of cure or, with respect to a curable breach, is not cured within thirty (30) days of notice. Either party may terminate immediately if (a) the other party breaches terms relating to intellectual-property rights or Confidential Information, or (b) the other party becomes the subject of a petition in bankruptcy or similar proceeding.
8.3 Effect of termination.
Termination of this Agreement results in termination of all ongoing Orders; termination of a single Order does not terminate this Agreement or other Orders. If Customer terminates under Section 8.2, Skrib will provide a pro-rata refund of pre-paid unused fees for the remainder of the Order Term. If terminated for any other reason, Customer will not receive a refund and will pay all fees as if the Order had not been terminated. On termination, Skrib will make Customer Content available for export for thirty (30) days, after which Skrib may delete or retain Customer Content as directed by Customer. Sections 2, 4, 5.3, and 7–9 survive termination.
9. Miscellaneous
9.1 Affiliates.
A Customer Affiliate may enter into an Order under this Agreement; in such case, by entering into the Order, the Affiliate agrees to be bound by this Agreement with respect to the Order and is considered “Customer” with respect to that Order.
9.2 Product-Specific Terms.
Certain Skrib offerings (including AI Features and beta features) are subject to Product-Specific Terms at https://skrib.com/legal/product-specific-terms. Where Customer elects to use such offerings, the applicable Product-Specific Terms apply.
9.3 Force Majeure.
Neither party will have liability for failures or delays resulting from a Force Majeure Event. The affected party will promptly notify the other and use reasonable efforts to limit damages and resume performance. If a Force Majeure Event causes a party to fail to comply for thirty (30) or more consecutive days, either party may terminate this Agreement on written notice without liability.
9.4 Notices.
Notices must be in writing (electronic mail sufficient) and sent to the contact identified in the Order, with a copy to contact@skrib.com (for Skrib).
9.5 Severability and waiver.
If a provision is held invalid or unenforceable, the remainder of the Agreement remains in effect. No failure or delay constitutes a waiver.
9.6 Assignment.
Neither party may assign this Agreement without the other party’s prior written consent, except that either party may (without consent) assign in connection with a merger, acquisition, corporate reorganisation, or sale of all or substantially all of its assets. Any purported assignment in violation of this section is null and void.
9.7 Service providers.
Skrib may engage third-party service providers (including the sub-processors listed at https://skrib.com/legal/subprocessors) to support its performance. Skrib remains responsible for compliance with this Agreement.
9.8 No partnership.
This Agreement does not create an agency, partnership, joint venture, or employment relationship.
9.9 Governing law and dispute resolution.
The governing law and exclusive forum for disputes arising out of or relating to this Agreement are determined by Customer’s place of establishment, as set out in the table below. The United Nations Convention on Contracts for the International Sale of Goods is specifically disclaimed.
United States, Canada, or any country in the Americas — Governing law: State of Delaware, USA (without regard to conflicts of law); Exclusive forum: State and federal courts located in Wilmington, Delaware.
European Economic Area, Switzerland, or the United Kingdom — Governing law: Republic of Ireland; Exclusive forum: Courts of Dublin, Ireland.
Asia-Pacific (including Japan, Singapore, Australia, India) — Governing law: Singapore; Exclusive forum: Courts of Singapore.
Any other jurisdiction (default) — Governing law: Georgia (country); Exclusive forum: Courts of Tbilisi, Georgia.
9.10 Export control.
The Skrib Platform and Customer’s use of it are subject to U.S. Export Administration Regulations and OFAC sanctions programmes (and analogous laws). Each party represents it is not on any list of prohibited or restricted parties. Customer will not access or use the Skrib Platform or Customer Content in violation of Export Controls. Skrib may take measures (suspending access, terminating, blocking Customer Content) required to comply with Export Controls.
9.11 Anti-corruption.
Neither party has received or been offered any illegal or improper bribe, kickback, payment, gift, or thing of value from an employee or agent of the other party in connection with this Agreement.
9.12 Government use.
If Customer is a U.S. government or U.S. public-sector entity (or use is for the U.S. government), the Skrib Platform and Documentation are “commercial computer software” and “commercial computer software documentation” under 48 C.F.R. §§ 2.101, 12.212, 227.7202. Sections inconsistent with applicable law (governing law, Customer indemnification, auto-renewal) are waived to the extent necessary.
9.13 Trademark guidelines.
Use of the Skrib name and logo is governed by the Trademark Guidelines at https://skrib.com/using-the-skrib-brand.
9.14 Patent assertion entities.
If Customer is a Patent Assertion Entity (a non-practising entity that derives or seeks to derive a significant portion of its revenue from the offensive assertion of patent rights), or is acting on behalf of one, Customer will not assert against Skrib any claim that the Skrib Platform infringes any intellectual-property right (including patents).
9.15 Interpretation.
Wherever the words “including,” “include,” or “such as” are used, they will be deemed to be followed by “without limitation.”
9.16 Entire agreement.
This Agreement supersedes all other agreements between the parties relating to its subject matter. In the event of conflict among Orders, Product-Specific Terms, and this Agreement, the order of precedence is: (a) Product-Specific Terms; (b) this Agreement; and (c) the Orders (newest to oldest), unless an Order expressly overrides the foregoing. Any terms and conditions stated in a Customer purchase order or vendor management portal are void.
Exhibit A — Definitions
“Affiliate” means an entity that, directly or indirectly through one or more intermediaries, controls, is controlled by, or is under common control with such entity.
“Agreement” means this Software Services Agreement (together with its exhibits and addenda) and any Product-Specific Terms.
“Authorized User” means employees, contractors, and other persons associated with Customer or its Affiliates who access or use the Skrib Platform through Customer’s account.
“Claim” has the meaning given in Section 6.1.
“Customer Content” means materials developed by Customer or its Authorized Users on the Skrib Platform or uploaded to the Skrib Platform by Customer or its Authorized Users.
“Customer Data” means Customer Content and Customer Personal Data.
“Customer Personal Data” means Personal Data pertaining to Customer’s logged-in Authorized Users processed by Skrib on behalf of Customer under this Agreement.
“Documentation” means Skrib-provided documentation available at https://help.skrib.com or such successor link identified by Skrib.
“Excluded Claims” has the meaning given in Section 7.3.
“Force Majeure Event” means any event or circumstance (other than a party’s inability to satisfy payment obligations) outside a party’s reasonable control.
“Losses” has the meaning given in Section 6.1.
“Non-Skrib Resources” means applications and materials developed or provided by a party other than Skrib, including design files, plugins, component libraries, services, products, platforms, integrations, and code components.
“Order” means an ordering document or online order entered into between Skrib and Customer (or, where applicable, between Reseller and Skrib) that specifies the Skrib offerings purchased.
“Order Term” means the subscription term length set forth in the applicable Order or, with respect to early-access features, the evaluation period set by Skrib.
“Personal Data” has the meaning given in applicable Data Protection Laws.
“Product-Specific Terms” means the terms and conditions at https://skrib.com/legal/product-specific-terms.
“Reseller” means a third party authorised by Skrib to resell the Skrib Platform.
“Skrib” means Skrib, Inc.
“Skrib Platform” means the Skrib offerings identified in an Order, including any related mobile and desktop applications, early-access features, integrations, and Documentation. The Skrib Platform excludes Non-Skrib Resources.
“Sub-processor” means Skrib’s vendors and third-party service providers that process Customer Data.
“Systems” means the applications, databases, infrastructure, and platforms under Skrib’s control that are used to provide the Skrib Platform to Customer.
“Territory” means worldwide, with the exception of (1) jurisdictions embargoed or designated as supporting terrorist activities by the United States Government and (2) jurisdictions whose laws do not permit engaging in business with Skrib.
Exhibit B — Skrib Security Standards
Skrib implements and maintains the following technical and organisational measures (the “Security Standards”) for the security of Customer Data, as required by Article 32 of the GDPR and analogous Data Protection Laws. The Security Standards are reviewed at least annually; Skrib may make changes that maintain or improve the level of security.
Information Security Policy — Controls: Skrib maintains a written Information Security Policy reviewed at least annually and after any material change in applicable law, regulatory guidance, or Skrib’s systems..
Codes of conduct and ethics — Controls: Skrib maintains and communicates codes of conduct and policies covering anti-bribery, anti-corruption, whistle-blowing, anti-money laundering, anti-slavery, and equal opportunity. Failure to comply is addressed through documented disciplinary actions..
Information-security programme — Controls: Responsibility for information-security management is assigned to senior personnel. Skrib maintains a written security programme including policies, procedures, and technical and physical controls designed to ensure security, availability, integrity, and confidentiality of Customer Data..
Background checks and confidentiality — Controls: Skrib conducts pre-employment background screening on personnel and contractors who will access Customer Data, to the extent legally permissible. All Skrib personnel and Sub-processors execute confidentiality agreements as a condition of engagement..
Access control — Controls: Unique User IDs and authenticated access to Systems. Least-privilege defaults. Access lists maintained and reviewed; access revoked within one (1) business day of transfer or termination. Strong-password policy and multi-factor authentication for Systems access. Privileged accounts logged and reviewed..
Logging, audit, and accountability — Controls: Centralised audit logging of administrative actions, access to Customer Data, and security-relevant events. Logs retained for at least one (1) year. Anomaly detection and 24/7 alerting on security-relevant events..
System change control — Controls: Configuration baselines for Systems based on industry-standard practices. Formal change-control procedures including documentation, testing, quality control, and managed implementation. Source code controls (version control, segregated repositories, least-privilege access). Separate development, test, and production environments. Customer instances logically separated..
Secure development — Controls: Skrib follows a structured secure-development methodology, adheres to secure-coding standards, and undergoes security-assessment activities (dynamic and static scans) to identify and remediate vulnerabilities before production release..
Vulnerability management — Controls: Up-to-date anti-malware. Continuous vulnerability scanning. Subscription to vulnerability-notification services. Risk-based prioritisation and remediation timeframes. Annual penetration testing by qualified independent third parties; summary made available to Customer on request..
Capacity planning — Controls: Capacity-management programme that continuously monitors and evaluates the performance and capacity of the Systems..
Physical and environmental security — Controls: Skrib’s production environments are operated in tier-3 or higher data centres certified to ISO/IEC 27001 (or equivalent), with physical-access controls (access cards, alarms, video surveillance, exterior security)..
Security incidents — Controls: Documented incident-response plan with defined roles, severity levels, and escalation. 24/7 on-call rotation. Personal Data Breach notification to Customer without undue delay and in any event within seventy-two (72) hours of confirmation..
Sub-processors — Controls: Risk-based reviews of all Sub-processors. Written agreements with Sub-processors imposing data-protection and security obligations no less protective than this Exhibit B. Public Sub-processor List maintained at https://skrib.com/legal/subprocessors with subscription form for change notifications..
Encryption — Controls: Customer Data encrypted in transit (TLS 1.2+) and at rest (AES-256 or equivalent). Cryptographic keys protected from unauthorised use, disclosure, alteration, and destruction; backup and recovery process maintained. Compromised private keys result in revocation of associated certificates..
Data retention and deletion — Controls: On expiry or termination, Skrib deletes or returns Customer Data (excluding back-up or archival copies, which are deleted in accordance with Skrib’s backup retention schedule), except where Skrib is required to retain copies under applicable law..
Secure disposal — Controls: Skrib securely disposes of Customer Data in accordance with applicable law and industry standards (NIST SP 800-88 “Guidelines for Media Sanitization” or equivalent)..
Risk assessments — Controls: Documented risk-assessment programme with regular risk assessments and corrective-action processes. Annual risk assessments performed internally or with contracted independent resources..
Asset management — Controls: Asset-management programme that classifies and controls hardware and software assets throughout their life cycle..
Business continuity and disaster recovery — Controls: Industry-standard practices for redundancy, robustness, and scalability. Documented contingency, data-backup, and disaster-recovery plans, tested at least annually. Regular backup and recovery testing..
Security and privacy training — Controls: Mandatory annual training for personnel and relevant contractors on business ethics, privacy, and information-security awareness. Specific training on secure coding for personnel involved in development that affects Customer Data..
Security control testing — Controls: At least annually, Skrib engages a qualified independent external auditor to conduct periodic reviews of Skrib’s security practices against recognised audit standards (such as SOC 2 Type II and ISO 27001 audits, including surveillance and recertifications). Reports made available to Customer at https://compliance.skrib.com or under NDA on request..
Data protection governance — Controls: Responsibility for data protection assigned to senior personnel (including Skrib’s Data Protection Officer).