Terms of Service

Last updated: 15 March 2026

These Terms of Service (“Terms”) govern your access to and use of the DPOKit website (dpokit.com), the DPOKit WordPress plugin (“Plugin”), and the DPOKit licence and update API (“API”) (collectively, the “Services”). By accessing or using any Service, you agree to be bound by these Terms. If you do not agree, do not use the Services.

The Services are provided by DPOKit Ltd (“DPOKit”, “we”, “our”, or “us”). References to “you” mean the individual or entity accepting these Terms.

1. Licence grant

Subject to your compliance with these Terms and payment of applicable fees, DPOKit grants you a limited, non-exclusive, non-transferable, revocable licence to:

  • Install and use the Plugin on the number of WordPress installations permitted by your licence tier (Free: 1 site; Pro: 1 site; Agency: unlimited sites).
  • Access the API solely to validate and activate your licence key and to receive Plugin updates.
  • Access the customer dashboard to manage your licences and billing details.

This licence does not include the right to sublicence, resell, redistribute, or white-label the Plugin or API without a separate written agreement.

2. Acceptable use

You agree not to:

  • Reverse-engineer, decompile, or disassemble the Plugin beyond what is expressly permitted by applicable law.
  • Circumvent licence enforcement mechanisms, including modifying or removing licence key validation code.
  • Share your licence key with parties outside your organisation or use it on more sites than your tier permits.
  • Use the Services to process data in violation of applicable law or in a manner that infringes the rights of others.
  • Probe, scan, or test the vulnerability of the API or attempt to gain unauthorised access to any system or network.
  • Use automated means to access the API at a rate that degrades the service for other users.

3. Subscription, fees, and payment

3.1 Pricing and billing

Paid licence tiers are billed on a monthly or annual basis as selected at checkout. All prices are displayed exclusive of applicable taxes. Tax (including VAT where applicable) will be calculated and added at checkout.

3.2 Payment processor

Payments are processed by Stripe. By completing a purchase you also agree to Stripe’s terms. DPOKit does not store your full card number or CVV.

3.3 Renewals

Subscriptions renew automatically at the end of each billing period. You will receive a renewal reminder email at least 7 days before the renewal date. You may cancel at any time from the customer dashboard; cancellation takes effect at the end of the current billing period and no partial refunds are issued.

3.4 Failed payments

If a payment fails, Stripe will retry according to its standard retry schedule. We will notify you by email. If payment is not recovered within 7 days, your licence will be downgraded to the Free tier and access to paid features will be suspended until payment is resolved.

3.5 Refund policy

We offer a 14-day money-back guarantee for new paid subscriptions. To request a refund within this period, email billing@dpokit.com with your order reference. After 14 days, no refunds are available except where required by applicable consumer law.

4. Free tier

The Free tier is provided at no charge and includes the consent banner and basic third-party script scanning features. Free-tier users are subject to these Terms. We reserve the right to modify or discontinue the Free tier with 30 days’ notice.

5. API terms

5.1 API access

Access to the licence API is authenticated via your licence key. You are responsible for keeping your licence key confidential. Suspected key compromise should be reported to support@dpokit.com immediately.

5.2 Rate limits

API endpoints are rate-limited to 60 requests per minute per IP address. Exceeding this limit will result in a temporary block. The Plugin caches validation responses for 12 hours to minimise API calls.

5.3 API availability

We target 99.5% monthly uptime for the API. Planned maintenance windows will be announced at least 24 hours in advance. The Plugin includes a 7-day grace period using the last cached valid response if the API is unreachable, so short outages do not affect your site.

5.4 API changes

We will provide at least 90 days’ notice before making breaking changes to any API endpoint. Non-breaking additions (new fields, new endpoints) may be made at any time without notice.

6. Plugin updates

Paid licence holders receive automatic Plugin updates via the API for the duration of their subscription. We recommend keeping the Plugin updated to receive security patches and new features. We are not liable for issues arising from running outdated versions.

7. Data processing

When you use the Plugin on your WordPress site, you act as the data controller for personal data processed by the Plugin (such as DSAR submissions and consent records on your site). DPOKit acts as a data processor for any personal data transmitted to our API (licence activation data, site URL). See our Data Processing Agreement for the full processor terms.

8. Intellectual property

The Plugin, API, documentation, and all related materials are the intellectual property of DPOKit Ltd and are protected by copyright and other applicable laws. These Terms do not grant you any ownership rights. All feedback you provide about the Services may be used by DPOKit without restriction or compensation.

9. Disclaimer of warranties

THE SERVICES ARE PROVIDED “AS IS” WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED. TO THE FULLEST EXTENT PERMITTED BY LAW, PRIVACYVAULT DISCLAIMS ALL WARRANTIES INCLUDING IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT.

The Plugin is a tool to assist with privacy compliance; it does not guarantee legal compliance and does not constitute legal advice. Generated legal text (privacy notices, ROPA) is provided as a draft and must be reviewed by a qualified lawyer before use.

10. Limitation of liability

TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, PRIVACYVAULT’S TOTAL LIABILITY FOR ANY CLAIM ARISING OUT OF OR RELATED TO THE SERVICES SHALL NOT EXCEED THE AMOUNTS PAID BY YOU IN THE 12 MONTHS PRECEDING THE CLAIM. IN NO EVENT SHALL PRIVACYVAULT BE LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.

11. Indemnification

You agree to indemnify and hold harmless DPOKit Ltd and its officers, directors, employees, and agents from any claims, losses, or damages (including reasonable legal fees) arising out of your use of the Services, your violation of these Terms, or your violation of any third-party rights.

12. Termination

Either party may terminate these Terms at any time. DPOKit may suspend or terminate your access immediately if you breach these Terms. Upon termination, your licence key will be deactivated and you must cease all use of the Plugin’s paid features. Sections 8–11 and 13–14 survive termination.

13. Governing law and disputes

These Terms are governed by the laws of England and Wales. Any dispute shall first be attempted to be resolved by good-faith negotiation. If unresolved within 30 days, disputes shall be subject to the exclusive jurisdiction of the courts of England and Wales.

14. Changes to these Terms

We may update these Terms from time to time. Material changes will be communicated by email to the address associated with your account at least 14 days before the change takes effect. Continued use of the Services after the effective date constitutes acceptance of the revised Terms.

15. Contact

For questions about these Terms, contact us at legal@dpokit.com.