Terms
Service terms in plain language.
The short version: read-only connections, human approval on every action, your data stays yours. The binding version follows. Last updated August 8, 2026.
Service
ChurnRisk provides customer revenue-risk analysis and human-controlled workflows. Outputs support business judgment and do not replace it. Accounting connections are read-only, and ChurnRisk never writes to a connected book.
Customer responsibilities
Customers must have authority to connect data, configure users, supply lawful consent, review proposed actions, and maintain their source systems.
Acceptable use
The service cannot be used for unlawful surveillance, spam, harassment, emergency communication, consumer credit decisions, or attempts to cross tenant boundaries.
Messaging and consent
The customer is the sender of record for every message the service helps send. Messages go to the customer's own existing customers, from the customer's own mailbox or number, and only after a person on the customer's team approves the complete action. A per-channel kill switch stops sending immediately.
Under CASL, the position relied on is implied consent through an existing business relationship, which runs two years from the last transaction and is tracked per customer. A lapsed record cannot be messaged without explicit consent. Sender identification and a working unsubscribe accompany every commercial message regardless of the consent basis, opt-outs are honoured within the statutory window, and suppression, quiet hours, and frequency limits are enforced before sending. The customer is responsible for the lawfulness of the messages it approves. The privacy page states the same position from the data side.
Data, export, and termination
Customers retain rights to their data. Export and deletion follow the agreement and documented retention controls when service ends.
Cancellation does not remove export access. Export remains available for the post-cancellation window recorded in the agreement, so cancelling never locks a customer out of their own evidence. Deletion on request removes derived signals as well as raw records, and the audit record that deletion occurred does not contain the deleted content.