← CRA IncidentOps
Template document. Before publication the operator must complete the bracketed fields and obtain legal review.

Terms of Service

1. Parties and subject

[Operator name] ([Registered address], [VAT ID]) provides CRA IncidentOps to customer organisations as a cloud tool for preparing and documenting notifications under Article 14 of Regulation (EU) 2024/2847.

2. Role of the service

The service is not the ENISA portal and does not submit notifications automatically. The customer determines and confirms the legal classification of an event, the moment of awareness and the submission through the ENISA Single Reporting Platform. The field schema follows the published ENISA Glossary and must be checked against the live SRP form.

3. Subscription and payment

Plans, limits and prices are listed on the website. Payment is processed by a payment provider; VAT is charged under EU rules, and the reverse charge applies to customers with a valid VAT ID. If payment lapses, configuration changes are suspended while work on open incidents and data export remain available for 30 days; afterwards the workspace becomes read-only.

4. Customer data

The customer owns its data. An administrator can export a complete archive at any time. After a deletion request, data is erased after 30 days; backups are removed according to the retention schedule.

5. Availability and support

[Availability level, maintenance windows and support response times per plan or contract.]

6. Liability

[Limitation of liability, exclusions, force majeure.]

7. Governing law

[Governing law].