Terms of Service
Effective 2026-08-28. These terms are deliberately short and in plain language: they contain only what is true about the service today — a product that is free while in beta — and no boilerplate for things we do not do yet (no billing mechanics we have not built, no refunds, no data-processing agreement we have not written). We reserve the right to introduce paid plans, described below. They have not yet been reviewed by outside counsel; that is stated plainly rather than hidden. They are published in English only, and the English text governs.
The NOA Mandate service is operated by Tora Toraman (enkeltmandsvirksomhed — sole proprietorship), CVR 42692271, Amager Strandvej 28C, 2. th., 2300 København S, Denmark.
Enterprise console accounts are protected by role-based access control and, for sensitive actions, step-up passkey re-authentication — see /security for the full, honestly-labeled control list (including named gaps). Keep your credentials and paired devices to yourself; if you suspect a credential or device has been compromised, rotate it and tell us at security@noamandate.com so we can revoke what needs revoking.
The hosted console and the mobile app are pre-general-availability beta software, provided as is and as available, without warranties of any kind. There is no uptime commitment and no SLA; the service may change, be interrupted, or end, with notice on this page. To the maximum extent Danish law permits, our liability in connection with the service is limited — we do not invent a numeric cap here, and nothing in these terms limits liability that Danish law does not allow to be limited. What is already stated plainly elsewhere on this site is not re-promised here more strongly: this is not a certification of SOC 2, EU AI Act, or NIST AI RMF compliance (see /regulations), and the audit trail is tamper-evident, not tamper-proof (see /security).
We may suspend or terminate access that violates the acceptable-use rules above or that creates a security risk for other users. You can stop using the service at any time. What happens to data afterwards is governed by the retention terms in the privacy policy — expired sign-in artifacts and aged security-event records are removed by the retention cleanup job, while append-only audit and receipt records are not deleted by that job and are kept as the tamper-evident accountability record.
These terms are governed by the law of Denmark, and disputes belong before the courts of Denmark.
When these terms change, this page changes, with a new effective date at the top. The current version is effective 2026-08-28; it replaces the version of 2026-08-12, adding the reservation of the right to introduce paid plans with advance notice. The 2026-08-12 version replaced the first version of 2026-08-11, correcting the description of what the retention cleanup job removes.
Questions about these terms: legal@noamandate.com