1. Company and Scope
These Terms apply to the websites https://www.enigmalabs.ee and https://www.enigmalabs.ee and, when incorporated into an order or engagement, to services provided by Enigma Labs OÜ ("Enigma Labs", "we", "us").
| Company information | Details |
|---|---|
| Legal name | Enigma Labs OÜ |
| Legal form | Osaühing (Estonian private limited company) |
| Registry code | 17166408 |
| VAT number | EE102825316 |
| Registered address | Harju maakond, Tallinn, Kesklinna linnaosa, Juhkentali tn 8, 10132, Estonia |
| hello@enigmalab.io |
Enigma Labs is the trading name. Enigma Labs OÜ is the contracting party for engagements agreed with this Estonian entity. These Terms do not transfer an existing agreement with another Enigma Labs company or change the terms on its websites.
Our services are offered to businesses and organisations acting in their professional capacity. A person accepting an engagement on behalf of an organisation must have authority to bind it. Website information is general information about our services. Browsing the website, requesting a quote or submitting a contact form does not purchase a service or create a paid engagement.
Our Privacy Policy describes personal-data processing. Our Cookie Policy describes browser storage. Neither document makes browsing or an enquiry consent to optional marketing or tracking.
2. Agreeing an Engagement
An engagement is formed when both parties accept a written order, statement of work or other written agreement identifying Enigma Labs OÜ and the customer. Acceptance may be recorded electronically. The engagement describes the services, scope, deliverables, fees, schedule, dependencies, contacts and any acceptance criteria.
Services may include cybersecurity audits, penetration testing, incident response, security engineering, and secure web or mobile application development. Only the services and commitments agreed for the engagement are included. Emergency availability, response times, service levels, ongoing monitoring and retainers require express agreement.
The order of precedence is: mandatory law; applicable Standard Contractual Clauses for international data transfers; the Data Processing Agreement for personal-data matters; the signed order or statement of work; and these Terms. A separately negotiated agreement may replace these Terms where it expressly says so.
Changes to scope, fees, delivery dates or responsibilities require written agreement. Each party must promptly communicate circumstances affecting delivery. Enigma Labs may use suitably qualified personnel and subcontractors, remaining responsible for its contractual obligations and subject to the DPA for any sub-processing.
3. Authorisation and Responsibilities
The customer must:
- Identify and authorise the systems, applications, accounts and locations within scope, and obtain required permissions from their owners and relevant third-party providers.
- Agree testing windows, prohibited techniques, escalation contacts, stop conditions and other rules of engagement before intrusive testing begins.
- Provide accurate information, timely access and decisions, appropriately secured credentials, and necessary backups and recovery arrangements.
- Establish the lawful basis for personal-data processing, give required notices and ensure its instructions are lawful.
- Avoid submitting malicious content outside an agreed security-testing context, infringing third-party rights, or using the services for unlawful surveillance, unauthorised access or other prohibited purposes.
We may pause work where authorisation is unclear, instructions appear unlawful, or continuing would create a material safety or security risk. We will explain the reason and cooperate on a safe resolution where lawful. Testing can affect system availability or reveal sensitive information; the parties must agree proportionate precautions for the actual engagement.
Customers remain responsible for their business decisions, risk acceptance and implementing recommendations unless implementation is expressly included. Neither party may use the services or deliverables in breach of applicable Estonian, EU or other applicable export-control and sanctions laws.
4. Fees, Payment and VAT
Fees, currency, payment milestones, expenses and invoice due dates are stated in the accepted order. Website pricing is indicative unless expressly stated to be a binding offer. No subscription or automatic renewal arises merely from visiting the site or submitting an enquiry.
Fees exclude VAT and other applicable taxes unless expressly stated otherwise. Enigma Labs OÜ's VAT number is EE102825316. VAT is charged or accounted for according to the applicable place-of-supply, customer-status and reverse-charge rules; no single VAT treatment is promised for every customer.
The customer must raise invoice disputes promptly with supporting details and pay undisputed amounts when due. Statutory late-payment interest and lawful recovery costs may apply. After written notice and a reasonable opportunity to resolve overdue undisputed payments, we may suspend affected work, subject to applicable law and safeguards for customer data.
5. Intellectual Property and Licences
Each party retains its pre-existing intellectual property. The customer retains ownership of its data and materials and grants us only the rights needed to perform the agreed services.
Unless the order states otherwise, after payment of the relevant fees the customer receives a perpetual, non-exclusive licence to use the agreed final reports and deliverables for its internal business purposes and to share them with its professional advisers, auditors, insurers and competent authorities under appropriate confidentiality obligations. Reports describe findings within the agreed scope and at the time of assessment; third parties may not rely on them as an assurance addressed to them without our written agreement.
Ownership or assignment of bespoke application source code, designs and other commissioned development work must be specified in the statement of work. Our reusable tools, methods, templates, know-how and pre-existing code remain ours; any licence needed to use them as part of a paid deliverable is included to the extent necessary for the agreed use.
Third-party software and open-source components remain subject to their own licences. We will identify applicable third-party licence requirements for deliverables where relevant. Customers must not remove required notices or use materials beyond the rights granted.
The registry code and VAT number above identify the Estonian company and its VAT registration. They are not professional certifications or regulatory service licences. Any certification, regulated activity or specific assurance required for an engagement must be expressly identified and verified in that engagement.
6. Confidentiality and GDPR
Each party must protect the other's non-public business, technical, security and personal information received in connection with an engagement, use it only for the engagement or lawful exercise of contractual rights, and disclose it only to persons who need it and are bound by appropriate confidentiality obligations.
This duty does not apply to information the recipient can show was lawfully known without restriction, independently developed, lawfully received from a third party, or made public without breach. Legally required disclosures are permitted to the extent required; the recipient must give advance notice where lawful and reasonably cooperate to protect confidentiality. Confidentiality survives termination for as long as the information remains confidential, subject to mandatory law.
Where we process personal data on the customer's behalf, the Data Processing Agreement must form part of the engagement before processing begins. It implements Article 28 GDPR and addresses instructions, security, sub-processors, transfers, breaches, assistance, audits and deletion. Enigma Labs OÜ processes business contact and administration data as controller under its Privacy Policy.
Nothing in these Terms limits individuals' GDPR rights, supervisory-authority powers, mandatory breach-notification duties or rights under applicable transfer safeguards.
7. Service Standards and Limitations
We will perform the agreed services with reasonable professional care and skill and in material accordance with the accepted scope. If a deliverable materially fails the agreed requirements, notify us with sufficient detail so we can investigate and, where appropriate, correct or reperform the affected work within a reasonable time. This does not exclude remedies available under mandatory law.
Security work reduces risk but cannot guarantee that every vulnerability will be found or that an incident will never occur. Findings depend on the information, access, environment and time available. A security report is not a guarantee of certification or legal compliance, and recommendations may need reassessment after systems or threats change.
Third-party systems and services are subject to their operators' terms and availability. We remain responsible for obligations we expressly undertake, including responsibilities for subcontractors under the engagement and GDPR.
8. Liability
Subject to the exclusions below and to mandatory law, each party's aggregate contractual liability arising from an engagement is limited to the fees paid or payable for that engagement during the twelve months immediately preceding the event giving rise to the claim. To the extent permitted by law, neither party is liable to the other for indirect or consequential losses, loss of profits or business opportunities.
These limitations do not apply to payment obligations, breaches of confidentiality, fraud, intentional misconduct, gross negligence, death or personal injury caused by negligence, or any liability that cannot lawfully be excluded or restricted. They do not limit a data subject's rights to compensation under Article 82 GDPR or rights under applicable Standard Contractual Clauses. Any negotiated allocation of data-protection liability must respect those rights and applicable law.
The limitations are subject to Estonia's Law of Obligations Act and other applicable rules on the validity and fairness of standard terms. They apply only to the extent legally effective. Each party must take reasonable steps to mitigate its losses.
9. Term, Suspension and Termination
An engagement lasts for the period or work specified in its order. Renewal, cancellation notice periods and retainer arrangements apply only where agreed in writing.
Either party may terminate for a material breach that remains unremedied thirty days after written notice identifying the breach, or sooner where the breach cannot be remedied or mandatory law permits immediate termination. Either party may exercise other termination rights provided by the accepted order or applicable law.
On termination, the customer must pay for properly performed services and agreed, unavoidable commitments up to termination. Any unused prepaid fees for services we will not deliver must be addressed under the order and applicable law; termination for our uncured material breach entitles the customer to a refund of unused prepaid fees for the affected services. We will cooperate on an orderly handover. Personal data must be returned or deleted under the DPA, regardless of any payment dispute.
Payment obligations already accrued, intellectual-property rights, confidentiality, applicable liability terms, dispute provisions and data-protection duties intended to survive remain effective.
10. Estonian Law and Disputes
These Terms and engagements incorporating them are governed by Estonian law, including applicable EU law. The UN Convention on Contracts for the International Sale of Goods does not apply.
For business-to-business disputes, the parties will first seek resolution through their nominated contacts. If unresolved, the courts of Estonia, with Harju County Court (Harju Maakohus) in Tallinn as the court of first instance where legally permitted, have jurisdiction, unless the parties expressly agree otherwise in writing. Either party may seek urgent interim relief from a competent court.
This clause does not restrict mandatory consumer protections if a person legally qualifies as a consumer, data subjects' choice of forum or remedies under the GDPR, complaints to Andmekaitse Inspektsioon or another competent supervisory authority, or the forum required by applicable Standard Contractual Clauses.
11. General Terms and Notices
Neither party is responsible for a failure caused by an event qualifying as force majeure under applicable Estonian law, to the extent that law excuses performance. The affected party must notify the other promptly and take reasonable steps to reduce the impact. This does not remove mandatory personal-data security, notification or cooperation duties.
If a provision is invalid, the remaining provisions continue to apply to the extent permitted by law. Failure to exercise a right is not a waiver. An assignment may not reduce the other party's rights or conflict with applicable law or agreed data-protection restrictions.
Updates to website Terms are identified by the effective date. They do not retrospectively amend an existing engagement; changes to an accepted engagement require the agreement or procedure specified in that engagement and applicable law. The English version is the published version for these Estonian domains.
Send notices and legal enquiries to hello@enigmalab.io, identifying Enigma Labs OÜ and the engagement, or by post to Enigma Labs OÜ, Harju maakond, Tallinn, Kesklinna linnaosa, Juhkentali tn 8, 10132, Estonia. Registry code: 17166408. VAT number: EE102825316. Formal service of court documents remains subject to procedural law.