1. Provider and contact details
Kelpie is supplied by YUMA IT PTY LTD (ABN 62 684 389 839, ACN 684 389 839), trading as Yuma IT. Our registered address is 49 Phillip Ave, Watson ACT 2602, Australia. Contact us at hello@yumait.com.au or through our contact page.
These terms should be read with the applicable quote, order form, statement of work, marketplace offer, or other ordering document (an Order), our Privacy Policy, and our Refund Policy. Together they form the contract.
2. Acceptance and authority
You accept the contract by signing or accepting an Order, creating or using a Kelpie account, downloading or deploying Kelpie, or otherwise indicating acceptance. If you act for an organisation, you confirm that you have authority to bind it.
You must be at least 18 years old and legally capable of entering the contract. If you do not accept the contract, do not access, deploy, or use Kelpie.
3. Orders and contract priority
An Order describes the subscription or licence term, deployment model, authorised users, fees, support, professional services, and any special terms. An Order is binding when both parties accept it or when we make Kelpie available in response to it.
If documents conflict, the following order applies: the Order, any signed statement of work, these terms, then referenced policies. A marketplace term applies only to marketplace billing or fulfilment unless it expressly changes another part of the contract.
4. Licence and permitted use
During the term and subject to payment, we grant you a limited, non-exclusive, non-transferable licence to deploy and use Kelpie for your internal incident response, security operations, investigation, evidence, reporting, and related business purposes.
Use is limited to the organisations, environments, users, capacity, and deployment model in the Order. Contractors may use Kelpie for you if they follow the contract and you remain responsible for them. No ownership transfers to you.
5. Acceptable use
You must use Kelpie lawfully and only within authority granted by the owners of affected systems and data. You must not:
- use Kelpie to access, monitor, disrupt, contain, or change systems without permission;
- circumvent licence, identity, approval, tenant, audit, or security controls;
- introduce malware, exploit the service, or interfere with other users or infrastructure;
- reverse engineer, decompile, copy, resell, sublicense, or create a competing product from Kelpie except where law expressly permits it;
- remove ownership notices or misrepresent Kelpie, its outputs, or your authority; or
- use automated or AI-assisted actions without appropriate human review, permissions, and safeguards for the intended environment.
6. Your responsibilities
You are responsible for your deployment, configuration, backups, identity provider, users, credentials, integrations, networks, endpoints, cloud accounts, approval design, retention settings, and recovery procedures unless an Order expressly assigns a task to us.
You decide which alerts, evidence, personal information, secrets, and other content enter Kelpie. You must have all notices, permissions, lawful bases, licences, and authorisations needed for that content and for actions requested through connected providers.
Kelpie supports operational decisions; it does not replace professional judgement. You must verify targets and scope before approving containment or other high-impact actions.
7. Customer data and privacy
You retain ownership of data, evidence, configurations, and content you or your users submit to Kelpie (Customer Data). You grant us only the rights reasonably needed to supply support or services requested under an Order.
Kelpie is designed for customer-controlled deployment. We do not receive Customer Data merely because you run Kelpie in your environment. If we handle Customer Data for support, managed hosting, or professional services, we will handle it under the contract, documented instructions, and applicable privacy law.
Our own handling of personal information is described in the Privacy Policy. If a separate data processing agreement is required, the parties may enter one as part of the Order.
8. Integrations and third-party services
Kelpie can connect to identity, security, intelligence, storage, email, cloud, API, and marketplace services. Those services are provided under their own terms. You are responsible for obtaining accounts, credentials, permissions, and licences for them.
We are not responsible for a third-party service, its availability, data, security, pricing, or changes. We may change or stop an integration when its provider changes access, when continued support creates material security or legal risk, or when the Order does not include it.
9. Security, updates, and support
We use reasonable care and skill to develop and support Kelpie. No security product, software, integration, or response process can detect or prevent every incident or operate without interruption.
You must apply supported updates within a reasonable time, protect credentials, review audit and integration health, and notify us promptly of suspected vulnerabilities affecting Kelpie. Support levels, maintenance, response targets, and any service levels are those stated in the Order.
10. Fees, taxes, and renewal
Fees, currency, invoicing, payment dates, usage limits, and taxes are set out in the Order. Unless stated otherwise, fees exclude GST and are payable without set-off. Undisputed overdue amounts may accrue reasonable recovery costs and interest permitted by law.
A subscription renews only if the Order says it automatically renews. We will give any renewal notice required by the Order or applicable law. You may stop renewal using the notice method and deadline in the Order.
11. Intellectual property
We and our licensors retain all intellectual property rights in Kelpie, its documentation, updates, branding, and materials we create independently of Customer Data. Open-source components remain governed by their licences.
If you give feedback, you grant us a perpetual, worldwide, royalty-free right to use it without identifying you or disclosing your confidential information. Deliverables created specifically for you are governed by the applicable statement of work.
12. Confidentiality
Each party must protect the other party’s non-public business, technical, security, and commercial information using reasonable care and may use it only for the contract. Disclosure is allowed to personnel and advisers who need it and are bound to protect it.
Confidential information does not include information lawfully known without restriction, independently developed, publicly available without breach, or lawfully received from another source. A legally compelled disclosure is allowed after notice where lawful and reasonable cooperation.
13. Consumer guarantees and warranties
Nothing in the contract excludes, restricts, or modifies a right, guarantee, warranty, or remedy that cannot lawfully be excluded, including under the Australian Consumer Law (ACL).
Where the ACL applies, services come with non-excludable guarantees, including that they are supplied with due care and skill and are fit for a disclosed purpose where the law requires. Remedies may include correction, resupply, cancellation, refund of an unused portion, or compensation, depending on the failure and applicable law.
Except for non-excludable rights and any express warranty in an Order, Kelpie is supplied as available. We do not promise that it will be error-free, uninterrupted, compatible with every third-party service, or sufficient by itself to meet a legal, regulatory, certification, or security outcome.
14. Liability
Neither party excludes liability that cannot lawfully be excluded. Subject to that, neither party is liable for indirect or consequential loss, loss of profit, revenue, opportunity, goodwill, or anticipated savings, or loss caused by the other party’s systems, instructions, unauthorised use, or third-party services.
To the extent permitted by law, each party’s total aggregate liability arising from an Order is limited to fees paid or payable under that Order in the 12 months before the event giving rise to the claim. This cap does not apply to fraud, wilful misconduct, breach of confidentiality, infringement of the other party’s intellectual property, unpaid fees, or liability that law does not permit us to limit.
Where the law permits a remedy to be limited, our liability is limited, at our option, to resupplying the affected services, paying the cost of resupply, repairing or replacing affected goods, or paying the cost of repair or replacement.
15. Indemnity
You indemnify us against third-party claims and direct losses to the extent caused by your unlawful or unauthorised use of Kelpie, Customer Data that infringes another person’s rights, or an action you request against a system without authority. This does not apply to the extent we caused the loss.
We will defend a third-party claim that your authorised use of unmodified Kelpie infringes Australian intellectual property rights and pay finally awarded damages or an approved settlement. We may modify or replace Kelpie, obtain continued rights, or end the affected Order and refund prepaid fees for the unused portion. This is subject to prompt notice, control of the defence, and reasonable cooperation.
16. Suspension
We may suspend access we control where reasonably necessary to contain a security threat, prevent unlawful or materially harmful use, comply with law, or address undisputed overdue fees after notice. We will limit suspension where practical and restore access when the reason is resolved.
17. Termination and data return
Either party may terminate an Order for material breach if the breach is not remedied within 20 business days after written notice, or immediately if the other party becomes insolvent. Convenience termination applies only where the Order permits it.
When an Order ends, licence rights end and amounts accrued remain payable. For customer-controlled deployments, you remain responsible for export and deletion from your systems. If we host Customer Data, the Order will state the export window and deletion process.
Terms that by nature should continue survive, including confidentiality, privacy, intellectual property, payment, liability, indemnities, refunds, disputes, and governing law.
18. Changes to these terms
We may update these terms for future Orders. For an existing term, we will give at least 30 days’ notice of a materially adverse change. If you reject that change before it takes effect, you may terminate the affected Order and receive a pro-rata refund of prepaid fees for the unused period.
19. Notices, disputes, and governing law
Contract notices must be in writing to the address or email in the Order. Notices to us may be sent to hello@yumait.com.au or 49 Phillip Ave, Watson ACT 2602, Australia.
Before starting court proceedings, each party must describe the dispute in writing and try in good faith to resolve it for 20 business days. Either party may seek urgent relief, and this process does not restrict a consumer from using a regulator or non-excludable legal right.
The contract is governed by the laws of the Australian Capital Territory, Australia. The parties submit to the non-exclusive jurisdiction of its courts. Mandatory laws in another place continue to apply where they cannot be excluded.
20. General
- The contract is the entire agreement about its subject and does not exclude liability for misleading or deceptive conduct.
- If a term is unenforceable, it is read down or severed and the remaining terms continue.
- A waiver must be in writing. Delay in enforcing a right is not a waiver.
- Neither party may assign an Order without consent, except to an affiliate or successor that assumes the contract.
- The parties are independent contractors. No partnership, agency, employment, or joint venture is created.
- Neither party is liable for delay caused by events beyond reasonable control, provided it takes reasonable steps to mitigate them. This does not excuse fees already due.
- Electronic acceptance, signatures, and notices may be used where permitted by law.
