Terms of Use
1. Introduction
Welcome to TrustOps Portal.
TrustOps Portal is a secure assurance, continuity and compliance platform used to provide controlled access to approved records relating to backup assurance, recovery evidence, data hosting statements, audit documents, service coverage, tenant assurance, cloud continuity records and approved client requests.
TrustOps Portal is designed to support ABNO and Lolla products and to give authorized users clear evidence without exposing unsafe technical access, raw databases, cloud credentials or other clients' data. TrustOps is positioned as the assurance, continuity and compliance center across ABNO and Lolla products.
By accessing or using TrustOps Portal, you agree to these Terms of Use.
2. Definitions
In these Terms:
| Term | Meaning |
|---|---|
| TrustOps Portal / Portal | The online platform used for assurance, continuity, compliance, audit evidence and approved request management |
| Service Provider | ABNO Softwares International Ltd, Lolla Technologies Ltd, or the relevant product-owning/contracting entity |
| Client / Organization | The institution, company, enterprise or entity authorized to access TrustOps Portal |
| User / You | Any person granted access to TrustOps Portal |
| Authorized User | A user approved by the client or Service Provider to access the Portal |
| Evidence Room | Controlled area containing approved assurance and audit documents |
| Assurance Records | Backup, recovery, hosting, access control, service coverage or compliance records |
| Secure Data Copy | Approved encrypted data copy or backup export released under authorization and custody controls |
| Tenant Data Export | Approved client-specific data export from a shared SaaS platform |
| Application Support | User support, functional assistance, issue resolution and application updates |
| Cloud Continuity | Hosting, monitoring, backups, security, infrastructure management and continuity controls |
| Client Agreement | Any signed contract, SLA, AMC, subscription agreement, proposal, quotation, addendum or order form between the client and Service Provider |
3. Purpose of TrustOps Portal
TrustOps Portal is provided to help authorized users access or request approved information relating to:
- backup assurance
- recovery evidence
- data hosting location
- audit evidence
- access control statements
- tenant assurance
- service coverage
- cloud continuity
- secure data copy requests
- tenant data export requests
- recovery test requests
- incident closure records
- compliance support records.
TrustOps Portal is an assurance and governance platform. It is not a raw database access portal, cloud console, backup download portal or developer console.
4. Relationship With Client Agreements
These Terms govern access to and use of TrustOps Portal.
They do not replace the client's signed product agreement, SLA, AMC, subscription agreement, CICS addendum, cloud continuity plan, proposal, quotation or data processing agreement.
Where there is a conflict, the following order shall apply unless expressly stated otherwise in writing:
- signed master agreement or main client contract
- signed data processing agreement or privacy/data protection addendum
- signed cloud continuity, CICS, hosting or infrastructure addendum
- signed SLA, AMC or subscription terms
- signed quotation, proposal or order form
- these Terms of Use
- portal notices, help text or online guidance.
The CICS client guide separates ordinary application support from cloud infrastructure and continuity services such as hosting, monitoring, backups, security and infrastructure management. TrustOps Portal helps show this separation clearly.
5. Authorized Use Only
TrustOps Portal may only be used by authorized users.
You may access the Portal only if:
- your organization is an approved client or authorized stakeholder
- you have been granted access by the Service Provider or the client's authorized representative
- you use your own account credentials
- you access only information you are permitted to view
- your access is for legitimate business, audit, technical, compliance or governance purposes.
Personal, unauthorized, abusive, fraudulent or unlawful use is prohibited.
6. User Roles and Access Levels
TrustOps Portal access is role-based.
Typical user roles may include:
| Role | Typical Access |
|---|---|
| Client Executive | High-level assurance status, risks, approvals and evidence overview |
| Client ICT | Technical assurance records, hosting, backup and recovery evidence |
| Client Finance | Service coverage, optional services and billing-related visibility where enabled |
| Client Auditor | Read-only approved evidence documents |
| Client Approver | Approval of selected requests |
| Customer Success | Client request coordination and communication |
| CloudOps | Backup, recovery and infrastructure assurance records |
| Legal/Compliance | Custody, evidence approval and compliance records |
| Finance/Admin | Billing, optional services and continuity coverage |
| CEO/CTO/Governance | Oversight, exceptions and risk dashboards |
The Portal may restrict access based on role, organization, product, document status, request type, approval status and access duration.
7. Account Security
You are responsible for protecting your account.
You must:
- keep your login details confidential
- use your own account only
- not share passwords or MFA codes
- not allow another person to use your account
- notify the Service Provider immediately if you suspect unauthorized access
- use official work email addresses where possible
- comply with any MFA, password or identity verification requirements.
The Service Provider may suspend or revoke access where account misuse, compromise or suspicious activity is detected.
8. Prohibited Activities
You must not:
- attempt to access another client's records
- attempt to bypass role restrictions
- attempt to access raw backups, databases, credentials or cloud consoles
- upload malware or harmful files
- interfere with Portal availability or performance
- scrape, copy or extract data without authorization
- use the Portal for unlawful, fraudulent or abusive purposes
- misrepresent your identity, role or authority
- share evidence documents with unauthorized persons
- use personal email or personal drives for official evidence handling
- submit passwords, credentials or raw database files through general forms
- reverse engineer, test, scan or attack the Portal without written authorization
- alter, falsify or misuse evidence records
- use the Portal to harass, threaten or defame any person or organization.
9. Evidence Room Terms
The Evidence Room provides access to approved documents only.
Evidence documents may include:
- Backup Assurance Reports
- Recovery Test Certificates
- Data Hosting Location Statements
- Access Control Statements
- Tenant Isolation Statements
- Service Coverage Statements
- Secure Data Copy Custody Records
- Incident Closure Reports
Audit Evidence Packs.
Evidence documents may have issue dates, expiry dates, validity periods, version numbers and approval status.
Expired, revoked, draft or internal-only documents should not be relied upon as current assurance.
10. No Raw Backup or Credential Access
TrustOps Portal does not provide ordinary users with:
- raw production database backups
- direct database credentials
- cloud console access
- backup storage access
- live database replica access
- server root/admin access
- internal DevOps credentials
- other clients' data
- unrestricted download rights.
Where a client requires a backup export, secure data copy or tenant data export, the request must follow the approved authorization, encryption, secure transfer and custody process.
11. Shared SaaS Tenant Rule
For shared SaaS platforms, multiple clients may use the same platform while data is logically separated at tenant level.
For such products, the Service Provider does not release a full raw platform database backup to an individual client because it may contain data belonging to other tenants.
Where appropriate, a client may request:
- tenant-specific data export
- tenant isolation statement
- platform backup assurance
- tenant-level recovery support, where technically feasible
- approved audit evidence.
This is aligned to the TrustOps product architecture model, which distinguishes dedicated database environments from shared SaaS tenant assurance.
12. Requests Submitted Through the Portal
You may use TrustOps Portal to submit requests such as:
- Backup Assurance Report
- Recovery Test
- Data Hosting Statement
- Audit Evidence Pack
- Secure Data Copy
- Tenant Data Export
- Tenant-Level Recovery
- Extended Backup Retention
- Kenya-Resident Backup Copy
- Dedicated DR Assessment
- Auditor Support Session
Continuity Question.
Submitting a request does not mean it is automatically approved, included, free, technically feasible or legally permissible.
Requests may be subject to:
- identity verification
- authority confirmation
- deployment model review
- technical feasibility review
- legal/compliance review
- finance review
- client approval
- Service Provider approval
- quotation and payment
- secure custody controls.
13. Backup Export and Secure Data Copy
Backup export, secure data copy and tenant data export are sensitive data custody processes.
Such requests require:
- formal request
- valid purpose
- authorized requestor
- approved recipient
- clear data scope
- deployment model confirmation
- finance confirmation where billable
- legal/compliance review where sensitive
- CloudOps/Product approval
- encryption
- secure transfer
- custody acceptance
TrustOps record.
The Service Provider may reject or pause any request that creates security, legal, privacy, confidentiality, tenancy, technical or commercial risk.
14. Data Hosting Statements
TrustOps Portal may provide approved statements showing where a product or platform is hosted.
A Data Hosting Location Statement may include:
- hosting provider
- hosting region
- backup region
- platform or database model
- Kenya-resident copy status where applicable
- cross-region replication status where applicable
- verification date
- approval status.
The Service Provider does not make unverified hosting, residency, replication or disaster recovery claims.
15. Recovery Evidence
Recovery evidence may include recovery test certificates, restoration summaries or incident closure records.
A recovery certificate should only be issued after an actual recovery test or restoration activity has been performed and validated.
Backup existence does not automatically mean:
- restoration has been tested
- recovery will happen within a fixed time
- disaster recovery is included
- full platform recovery is guaranteed
- tenant-level recovery is always technically possible.
Recovery targets apply only where expressly agreed in a signed contract, continuity plan, SLA, CICS addendum or enterprise arrangement.
16. Optional and Billable Services
Some TrustOps-related services may be optional or separately chargeable.
Examples include:
- custom audit evidence packs
- additional backup assurance reports
- auditor support sessions
- secure data copy
- tenant data export
- restore testing
- emergency recovery caused by client-side action
- extended backup retention
- Kenya-resident backup copy
- cross-region backup copy
- dedicated DR environment
- DR drill
- custom compliance reports.
The internal infrastructure framework recognizes that cloud infrastructure cost is driven by factors such as users, database size, concurrent transactions, document storage, integrations and backup retention requirements.
TrustOps Portal may show whether a service is included, optional, billable, quoted, waived, pending approval, not available or not applicable.
17. Client and User Responsibilities
The client and its users are responsible for:
- ensuring only authorized persons access the Portal
- notifying the Service Provider when users leave or roles change
- protecting downloaded evidence
- ensuring auditors and consultants keep evidence confidential
- reviewing evidence validity dates
- submitting accurate requests
- avoiding excessive or unlawful data requests
- protecting any data copy released to the client
- maintaining internal data protection, audit and access controls
- using official communication channels
- promptly reporting suspected unauthorized access or data compromise.
18. Auditor Access
Auditor access may be granted only where approved by the client and/or Service Provider.
Auditor access may be:
- read-only
- document-specific
- time-bound
- limited to approved evidence
- subject to access logging
- subject to confidentiality requirements.
Auditors do not receive automatic access to raw backups, databases, cloud consoles, infrastructure secrets, internal notes or other clients' information.
19. Confidentiality
TrustOps Portal may contain confidential information, including:
- client product records
- service coverage information
- backup and recovery evidence
- hosting statements
- audit documents
- request records
- incident summaries
- access control statements
- custody records.
You must keep such information confidential and use it only for authorized business, audit, compliance, technical or governance purposes.
You must not disclose Portal information to unauthorized persons without written approval.
20. Privacy and Data Protection
TrustOps Portal may process personal data such as names, official emails, phone numbers, roles, organization details, user activity logs, approvals, requests and audit access records.
Personal data shall be handled according to the applicable Privacy and Data Protection Notice, client agreement and applicable data protection laws.
In Kenya, personal data protection is governed by the Data Protection Act, and the Office of the Data Protection Commissioner is the statutory regulator responsible for regulating personal data processing.
The Data Protection Act defines concepts such as personal data, data controller, data processor, data subject, processing and personal data breach.
21. Data Uploaded or Submitted by Users
You must not upload or submit unnecessary sensitive information through the Portal.
Do not submit through general request forms:
- passwords
- database credentials
- cloud credentials
- raw production backups
- unencrypted sensitive files
- national IDs unless specifically requested and approved
- payment card information
- unrelated personal data
- data belonging to other organizations.
Where sensitive information is required, the Service Provider will provide approved secure instructions.
22. Portal Availability
The Service Provider will use reasonable efforts to maintain TrustOps Portal availability.
However, access may be interrupted due to:
- scheduled maintenance
- emergency maintenance
- network failure
- cloud provider issues
- security incidents
- upgrades
- client connectivity issues
- force majeure events
- suspension for security, legal or commercial reasons.
TrustOps Portal availability does not replace the availability obligations, if any, contained in the applicable product agreement or continuity plan.
23. Portal Changes
The Service Provider may update, improve, restrict, suspend or modify TrustOps Portal features, workspaces, access roles, document formats, request types or security controls.
Such changes may be made to improve:
- security
- compliance
- usability
- auditability
- product coverage
- continuity management
- access control
- evidence governance.
24. Intellectual Property
TrustOps Portal, including its design, workflows, software, content structure, templates, evidence formats, terminology, branding and documentation, belongs to the Service Provider or its licensors.
You are granted a limited, revocable, non-transferable right to use the Portal for authorized purposes only.
You may not copy, reproduce, commercialize, reverse engineer, resell or create derivative works from TrustOps Portal without written permission.
25. Suspension or Termination of Access
The Service Provider may suspend, restrict or terminate access where:
- the client agreement ends
- user authorization is withdrawn
- fees or service coverage lapse where applicable
- security risk is detected
- user breaches these Terms
- client requests deactivation
- auditor access expires
- unlawful activity is suspected
- data protection or confidentiality risk exists
- continued access may expose the Service Provider, client or other users to risk.
Suspension of Portal access does not automatically terminate the underlying client agreement unless stated in the applicable contract.
26. Logs, Monitoring and Audit Trail
The Service Provider may log and monitor Portal activity for security, compliance, audit and operational purposes.
Logs may include:
- login activity
- failed login attempts
- role changes
- document views
- document downloads
- request submissions
- approvals
- rejections
- comments
- evidence uploads
- custody acceptance
- access grants and revocations.
Such logs may be used to investigate misuse, support audits, prove custody, resolve disputes and maintain system security.
27. Disclaimers
TrustOps Portal provides approved assurance records based on available system records, service coverage, deployment model and verification status.
To the maximum extent permitted by law:
- Portal records do not create guarantees beyond signed agreements
- backup assurance does not guarantee disaster recovery unless contracted
- data hosting statements reflect verified information at the time of issue
- expired evidence should not be relied upon as current
- service coverage may change based on contract, payment, subscription or plan status
- tenant-level recovery may not always be technically possible
- the Portal does not provide legal, accounting, audit or regulatory advice
- auditors and clients remain responsible for their own independent professional judgments.
28. Limitation of Liability
To the maximum extent permitted by law, the Service Provider shall not be liable for:
- unauthorized access caused by user credential sharing
- misuse of downloaded evidence by the client or auditor
- client failure to revoke user access
- client disclosure of evidence to unauthorized third parties
- inaccurate information submitted by users
- client-side internet, browser or device issues
- reliance on expired or revoked evidence
- client failure to maintain its own internal controls
- third-party cloud, network or hosting incidents beyond the Service Provider's control
- loss caused by use of Portal information outside its intended purpose.
Nothing in these Terms excludes liability that cannot be excluded under applicable law.
29. Indemnity
The client and user shall indemnify the Service Provider against losses, claims, costs or liabilities arising from:
- unauthorized use of Portal access
- breach of these Terms
- disclosure of evidence to unauthorized persons
- misuse of data exports or secure data copies after custody transfer
- inaccurate or unauthorized request submissions
- user credential compromise caused by negligence
- unlawful or excessive data requests
- breach of confidentiality obligations
- misuse of auditor access.
30. Governing Law and Dispute Resolution
Unless a signed client agreement states otherwise, these Terms shall be governed by the laws of Kenya.
The parties shall first attempt to resolve any dispute through good-faith discussions between authorized representatives.
If the dispute is not resolved, it shall be handled according to the dispute resolution clause in the applicable client agreement. If no such clause exists, the parties may submit the dispute to the competent courts of Kenya or such other forum as may be agreed in writing.
31. Changes to These Terms
The Service Provider may update these Terms from time to time.
Where changes are material, the Service Provider may notify users through:
- Portal notice
- updated terms page
- client communication
- contract addendum where required.
Continued use of TrustOps Portal after updated Terms become effective means you accept the updated Terms.
32. Contact and Support
For TrustOps Portal support, access issues or assurance requests, users should contact the official support channel provided to their organization.
General contact:
TrustOps Portal Team
Email: info@abnosoftwares.com
Phone: +254 (0)705 597336
Website: trustopsportal.com
For product-specific support, clients should use their official support channel.
