CORDYN SECURITY MANAGEMENT
TERMS OF USE
Contents
Provided by Modul Development LLC
Business-to-Business SaaS Terms
These Terms of Use ("Terms") govern access to and use of Cordyn Security Management, including its websites, tenant workspaces, portals, APIs, services, documentation, integrations, and related functionality (collectively, the "Service"), provided by Modul Development LLC ("Modul," "we," "us," or "our").
By creating or activating an account, accepting an invitation, clicking to accept these Terms, or otherwise accessing or using the Service, you agree to these Terms. If you use the Service on behalf of a company, security organization, employer, government entity, or other organization (a "Customer"), you represent that you have authority to bind that Customer to these Terms.
If you do not agree to these Terms, you may not access or use the Service.
1. THE SERVICE
Cordyn Security Management is a hosted business operating platform designed for private-security and related organizations. Depending on the Customer's subscription, configuration, and features then made available by Modul, the Service may support administrative, client, site, contract, workforce, operational, reporting, compliance, storage, integration, and related workflows.
- Client, contact, and site management;
- Lead, opportunity, assessment, proposal, contract, activation, launch, renewal, and client-success workflows;
- Electronic contracting, document execution, and electronic-signature functionality, including Cordyn Sign;
- Employee, credential, training, scheduling, attendance, asset, fleet, or related workforce functions when such features are made available;
- Post orders, documents, attachments, reports, and operational records;
- Customer and client portals;
- Storage, audit logging, dashboards, notifications, APIs, and integrations;
- Identity, invitation, password-recovery, and multi-factor-authentication functionality;
- Integration with separately operated CAD, MDT, dispatch, or field systems; and
- Other functionality Modul makes available from time to time.
A reference in these Terms to a category of functionality does not represent that the functionality is currently available to every Customer or included in any particular subscription. Current features, entitlements, limits, and commercial commitments are determined by the applicable Order Form, subscription, Service description, or written agreement.
2. BUSINESS USE AND CUSTOMER RESPONSIBILITY
Cordyn is intended primarily for organizational and business use. Customers are responsible for ensuring that their use of the Service complies with laws, contracts, employment requirements, security-licensing obligations, privacy requirements, retention obligations, and industry requirements applicable to their operations.
The Service does not replace professional legal, regulatory, compliance, human-resources, law-enforcement, emergency-response, accounting, payroll, or security advice. Customer remains responsible for operational and legal decisions made using information or workflows in the Service.
3. CUSTOMER ORGANIZATIONS, TENANTS, AND WORKSPACES
Cordyn operates as a multi-tenant hosted SaaS platform. Each Customer is assigned a logically separated tenant environment and may receive a dedicated workspace address such as customername.cordynhq.com.
The Customer is responsible for activity performed by its administrators and other authorized users. Users may access only tenants, clients, sites, records, and functions for which they have authorization. Attempting to access another Customer's tenant, data, files, users, credentials, or configuration is prohibited.
4. ACCOUNT ELIGIBILITY, INVITATIONS, AND APPROVED EMAILS
Cordyn is not an open public-registration service. Access may be limited to persons specifically approved by Modul or an authorized Customer administrator.
Modul or the Customer may require a user to:
- Use the exact email address approved during onboarding or included in an invitation;
- Use an approved company email domain;
- Receive and accept a valid, unexpired, workspace-bound invitation;
- Create a personal password rather than use a password created by Modul;
- Complete required multi-factor authentication ("MFA");
- Accept applicable legal notices; and
- Satisfy additional identity or access requirements reasonably established for the account.
An approved email address or domain does not automatically entitle a person to access the Service. Authorization may be withdrawn at any time by Modul or the Customer as permitted by the applicable agreement.
5. ACCOUNT SECURITY
Users must use individual accounts and protect passwords, MFA devices, recovery codes, and other authentication credentials. Users must promptly report suspected unauthorized access or credential compromise and must not share individual accounts where individual authentication is required.
Customers are responsible for promptly suspending or disabling access for users who no longer require it, including terminated employees, former contractors, transferred personnel, and former client users. Modul may revoke sessions, require password resets, require MFA re-enrollment, or impose other reasonable protective measures if account compromise is suspected.
6. MULTI-FACTOR AUTHENTICATION AND RECOVERY
Cordyn may require MFA for some or all user roles. MFA reduces but does not eliminate account-compromise risk. Users are responsible for maintaining control of enrolled authenticators and securely storing recovery codes or other recovery material.
Account or MFA recovery may require additional verification. Modul may delay or deny a recovery request when identity or authority cannot reasonably be verified. Administrative resets and recovery actions may be logged and may revoke existing sessions or authentication factors.
7. ADMINISTRATORS, ROLES, AND PERMISSIONS
Customers may designate administrators and assign role-based permissions and organizational scope. Administrators may be able to invite or remove users, assign roles, configure sites, manage storage, review audit information, configure integrations, or perform other privileged actions.
The Customer is responsible for selecting appropriate administrators, applying least privilege, reviewing privileged access, and maintaining appropriate internal approvals. Modul is not responsible for an administrator's authorized business decisions or actions taken within permissions assigned by the Customer, except to the extent caused by Modul's breach of these Terms or applicable law.
8. MODUL PLATFORM ADMINISTRATION AND SUPPORT ACCESS
Modul operates platform-level administration for tenant provisioning, identity recovery, subscription configuration, storage allocation, infrastructure health, and security operations. Platform administration does not, by itself, grant routine access to a Customer's contracts, employee records, client reports, or other Customer business records.
If access to Customer Data is reasonably necessary to provide support, investigate a security issue, comply with law, or perform an authorized service, Modul will limit access to authorized personnel and to the scope reasonably necessary for the purpose. Where supported, such access is subject to technical access controls and audit logging. Customer-specific support-access procedures may be addressed in a separate agreement.
9. CUSTOMER DATA AND OWNERSHIP
"Customer Data" means information, records, documents, photographs, reports, attachments, personnel information, site information, client information, operational records, and other content submitted to, stored in, or generated within a Customer's Cordyn environment.
As between Modul and the Customer, Customer retains its rights in Customer Data. Customer grants Modul a limited, non-exclusive right to host, process, transmit, reproduce, back up, and otherwise handle Customer Data only as reasonably necessary to provide, secure, support, maintain, and improve the Service; perform Customer-authorized integrations; comply with law; prevent fraud or abuse; and fulfill applicable agreements.
Modul does not obtain ownership of Customer Data merely because Customer Data is processed through Cordyn.
10. CUSTOMER RESPONSIBILITY FOR DATA
Customer is responsible for determining what information is appropriate to collect, upload, retain, disclose, and process through Cordyn. Customer represents that it has the rights, notices, authorizations, consents, and other lawful bases required for Customer Data and Customer-directed processing.
Customer must not direct Modul to process information in a manner that violates applicable law or third-party rights.
11. SENSITIVE, REGULATED, AND PROHIBITED DATA
Cordyn may contain sensitive business and security information, but the Service is not automatically configured for every regulated data type. Unless Modul expressly agrees in writing that a particular feature or deployment supports the applicable requirements, Customer must not use Cordyn to store or process:
- Classified national-security information or information prohibited from commercial systems;
- Protected health information where HIPAA compliance is required and no applicable written agreement authorizes such use;
- Payment-card data requiring PCI DSS handling, other than through an approved payment provider;
- Biometric identifiers collected for biometric-recognition purposes unless an expressly supported feature and required legal terms are in place;
- Passwords, private keys, recovery secrets, or authentication credentials for unrelated external systems;
- Illegal content, malware, or malicious code; or
- Information Customer is not lawfully authorized to collect or process.
Use of Cordyn does not, by itself, make Customer compliant with any law, regulation, security framework, certification, employment requirement, or contractual standard.
12. STORAGE
Subscriptions may include a storage allocation for supported files and records. Storage limits, file-size limits, file-type restrictions, and related usage limits may vary by plan or written agreement.
If Customer reaches or exceeds its allocation, Modul may notify Customer, restrict additional uploads, offer additional storage, or apply other measures permitted by the applicable Order Form or written agreement. Modul will not intentionally expose physical server paths or another Customer's storage namespace to Customer users.
13. ACCEPTABLE USE
Users may use Cordyn only for lawful, authorized business purposes. Users may not:
- Access or attempt to access the Service without authorization;
- Access or attempt to derive another Customer's data;
- Circumvent authentication, MFA, tenant boundaries, role restrictions, or rate limits;
- Probe, scan, penetration-test, or attempt to exploit the Service without written authorization;
- Introduce malware, ransomware, malicious scripts, or harmful code;
- Disrupt the Service or conduct denial-of-service activity;
- Use unauthorized automated scraping or bulk extraction;
- Use the Service to unlawfully monitor, harass, discriminate against, intimidate, or stalk a person;
- Upload illegal, infringing, defamatory, or knowingly fabricated material;
- Misrepresent identity, authorization, or authority; or
- Use Cordyn to facilitate unlawful activity.
Modul may investigate suspected violations and may suspend access when reasonably necessary to protect the Service, Customers, users, or third parties.
14. SECURITY OPERATIONS DATA AND USER-GENERATED RECORDS
Cordyn may contain incident reports, activity records, site information, security observations, photographs, contact details, personnel records, access instructions, or other operational information. Customer is responsible for establishing who may access, create, approve, distribute, retain, export, or delete such information.
Users are responsible for the accuracy and legality of records they create. Modul does not independently verify Customer-created narratives, observations, reports, statements, or attachments, and the presence of a record in Cordyn does not mean Modul endorses or confirms its contents.
15. LOCATION INFORMATION
Where location functionality is made available and enabled, Customer is responsible for determining whether collection or use of employee, guard, vehicle, device, client, or site location information is lawful and for providing required notices or obtaining required consent. Location information may be affected by device settings, GPS accuracy, network conditions, third-party services, and other technical limitations.
16. THIRD-PARTY SERVICES AND INTEGRATIONS
Cordyn may interoperate with third-party services selected by Customer or used by Modul to operate the Service, including email, identity, mapping, messaging, payment, cloud, CAD, MDT, HR, payroll, or other systems.
Third-party services are subject to their own terms and privacy practices. Modul is not responsible for failures, changes, or acts of third parties outside Modul's reasonable control, but this provision does not limit obligations that applicable law or a signed agreement expressly places on Modul.
17. CAD, MDT, AND FIELD-SYSTEM INTEGRATIONS
Cordyn may exchange authorized data with separately operated CAD, MDT, dispatch, or field systems. Unless expressly stated in a signed agreement, Cordyn itself is not a public-safety answering point, emergency dispatch center, or law-enforcement system. Service credentials and integrations must be used only within authorized tenant scope.
18. API ACCESS
Certain subscriptions may include API access. Customer must protect API keys, service credentials, certificates, and tokens and may use APIs only in accordance with documentation, scopes, rate limits, and authorization requirements. API credentials may not be published, resold, or used to access information outside the authorized tenant or scope.
19. AUDIT LOGS
Cordyn may maintain Customer-visible and internal audit or security logs to support accountability, troubleshooting, fraud prevention, and security. No audit system captures every possible action or guarantees forensic completeness. Modul may retain system and security logs separately from Customer-visible records as reasonably necessary to operate and protect the Service.
20. ARTIFICIAL-INTELLIGENCE-ASSISTED FEATURES
If Modul makes artificial-intelligence-assisted functionality available, such functionality is intended to assist human users and may be subject to additional disclosures, configuration, or terms. Unless separately disclosed and agreed, Modul does not use Customer confidential or operational data to train publicly available or general-purpose AI models. Customer remains responsible for reviewing AI-assisted outputs before relying on them for operational, employment, disciplinary, legal, or other consequential decisions.
21. DATA EXPORT, RETENTION, AND CUSTOMER RECORDKEEPING
Where supported, Customer may export Customer Data. Customer is responsible for maintaining independent copies of information that must be preserved under Customer's own legal, contractual, insurance, evidentiary, or retention requirements.
Cordyn is not a permanent archival repository unless a written agreement expressly states otherwise. Retention periods may depend on the Customer's subscription, applicable agreement, legal obligations, security needs, and backup lifecycle. Customer should arrange export of required records before termination or expiration.
22. BACKUPS AND BUSINESS CONTINUITY
Modul may maintain backups and recovery processes as part of Service operations. Backups are intended for service recovery and are not a substitute for Customer's own records-retention obligations. No storage or backup system can guarantee against all loss, corruption, compromise, or unavailability.
Any specific recovery objective, backup frequency, geographic redundancy, or service-level commitment applies only if stated in an Order Form, Service Level Agreement, or other signed writing.
23. AVAILABILITY AND MAINTENANCE
Modul seeks to provide reliable access but does not guarantee uninterrupted or error-free availability unless a separate written Service Level Agreement states otherwise. Planned maintenance, emergency maintenance, software updates, hardware or network failures, cybersecurity events, third-party outages, Internet disruptions, Customer configuration, or force-majeure events may affect availability.
24. EMERGENCY SERVICES DISCLAIMER
CORDYN IS NOT AN EMERGENCY COMMUNICATION SERVICE OR PUBLIC SAFETY ANSWERING POINT UNLESS EXPRESSLY PROVIDED UNDER A SEPARATE WRITTEN AGREEMENT.
Users must not rely solely on Cordyn to contact police, fire, emergency medical services, or other emergency responders. If immediate emergency assistance is required, users should contact the appropriate emergency service through authorized emergency channels, including 911 where appropriate. CAD, dispatch, alerting, panic-button, notification, or integration functionality may experience delay, connectivity failure, or third-party outage. Customer remains responsible for appropriate emergency procedures.
25. SECURITY
Modul uses reasonable administrative, technical, and organizational measures designed to protect the Service and Customer Data. Measures may include TLS-protected communications, password hashing, MFA, role-based access controls, tenant separation, audit logging, backup processes, secure development practices, and administrative access controls, as applicable to the deployed Service.
No Internet-connected system is completely secure. Modul does not warrant that unauthorized access, vulnerabilities, malicious activity, account compromise, or data loss will never occur. Customer remains responsible for securing its own devices, endpoints, networks, credentials, users, and connected systems.
26. SECURITY INCIDENT COOPERATION
Customer must promptly notify Modul of suspected unauthorized Cordyn access, compromised administrator or API credentials, unauthorized disclosure, or other security events that could materially affect the Service. Modul may temporarily restrict affected accounts or integrations while investigating or containing an incident.
If Modul becomes aware of unauthorized access to Customer Data requiring notice under applicable law or an applicable written agreement, Modul will provide required notice and reasonable cooperation in accordance with those obligations.
27. INTELLECTUAL PROPERTY
Cordyn, including its software, source code, interfaces, designs, branding, workflows, documentation, and related technology, is owned by Modul or its licensors and is protected by applicable intellectual-property laws. Except for the limited right to use the Service under these Terms and applicable agreements, Customer receives no ownership interest in Cordyn.
28. TRADEMARKS
"Cordyn," "Cordyn Security Management," "Modul," "Modul Development," associated logos, and related product identifiers may constitute trademarks, service marks, or trade names of Modul. Nothing in these Terms grants a right to use Modul branding except as expressly authorized.
29. FEEDBACK
If Customer voluntarily provides ideas or feedback about Cordyn, Modul may use that feedback to improve, develop, and operate its products and services without compensation, provided that doing so does not transfer ownership of Customer Data to Modul.
30. SUBSCRIPTIONS, ORDER FORMS, AND FEES
Pricing, billing frequency, included features, user or storage limits, implementation services, and other commercial terms may be stated in an Order Form, proposal, subscription agreement, service agreement, online checkout, or other written agreement. If a signed commercial agreement conflicts with these Terms regarding commercial terms, the signed agreement controls to the extent of the conflict.
Unless otherwise stated in a signed agreement or required by law, fees are non-refundable. Customer is responsible for applicable taxes, duties, assessments, or governmental charges arising from its purchase or use of the Service, excluding taxes based on Modul's net income.
31. SUSPENSION
Modul may suspend access when reasonably necessary due to nonpayment, security threats, suspected unauthorized access, material violation of these Terms, unlawful activity, abuse, risk to another Customer or the Service, or legal requirement. Where reasonably practicable, Modul will provide notice and an opportunity to cure before suspension, except where immediate action is reasonably necessary for security, legal, or operational reasons.
Suspension ordinarily preserves Customer Data for the applicable retention period and does not, by itself, transfer ownership of Customer Data to Modul.
32. TERMINATION
Customer may terminate according to its applicable subscription or service agreement. Modul may terminate or suspend access for material breach of these Terms or an applicable agreement, subject to any cure rights in that agreement.
After termination, accounts and integrations may be disabled and Customer Data may become inaccessible and later be deleted in accordance with applicable agreements, legal obligations, security needs, and Modul's retention practices. Backup copies may remain until overwritten or expired through normal backup processes.
33. PRIVACY AND DATA PROCESSING
Use of Cordyn is subject to the Cordyn Privacy Policy. Customer is responsible for privacy notices, consents, employee-monitoring notices, location notices, and other legal requirements applicable to the information Customer directs Modul to process.
Where applicable law requires a written processor, service-provider, contractor, or data-processing agreement for Customer Data, the parties will enter into or be subject to a Data Processing Addendum ("DPA") containing the legally required terms. A signed DPA controls over these Terms with respect to Customer Data processing to the extent expressly stated in the DPA.
34. CONFIDENTIALITY
Information accessed through Cordyn may include confidential or proprietary information of Modul, Customers, users, clients, employees, or third parties. Each party must use reasonable care to protect confidential information received from the other and may use or disclose it only as authorized by the applicable agreement, as necessary to provide or use the Service, or as required by law.
35. COMPLIANCE WITH LAW
Customer and users must use Cordyn in compliance with applicable laws. Depending on Customer's operations and jurisdiction, relevant requirements may include employment, employee monitoring, security licensing, privacy, biometrics, location tracking, surveillance, background information, records retention, discrimination, accessibility, and incident-reporting laws. Modul does not provide legal advice regarding Customer's specific obligations.
36. EXPORT AND SANCTIONS COMPLIANCE
Customer and users may not access or use Cordyn in violation of applicable export-control, trade-sanctions, anti-boycott, or similar laws and regulations.
37. WARRANTIES AND DISCLAIMERS
THE SERVICE IS PROVIDED "AS IS" AND "AS AVAILABLE" EXCEPT TO THE EXTENT A SIGNED AGREEMENT EXPRESSLY PROVIDES OTHERWISE. TO THE MAXIMUM EXTENT PERMITTED BY LAW, MODUL DISCLAIMS IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, NON-INFRINGEMENT, AND WARRANTIES ARISING FROM COURSE OF DEALING OR USAGE OF TRADE.
MODUL DOES NOT WARRANT THAT THE SERVICE WILL BE ERROR-FREE, UNINTERRUPTED, COMPLETELY SECURE, OR SUITABLE FOR EVERY CUSTOMER REQUIREMENT, OR THAT CUSTOMER-CREATED DATA OR THIRD-PARTY INFORMATION WILL BE ACCURATE.
38. LIMITATION OF LIABILITY
TO THE MAXIMUM EXTENT PERMITTED BY LAW, NEITHER PARTY WILL BE LIABLE TO THE OTHER FOR INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, CONSEQUENTIAL, OR PUNITIVE DAMAGES, OR FOR LOST PROFITS, REVENUE, BUSINESS, OR GOODWILL, ARISING FROM OR RELATED TO THE SERVICE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
TO THE MAXIMUM EXTENT PERMITTED BY LAW, MODUL'S TOTAL AGGREGATE LIABILITY ARISING FROM OR RELATED TO THE SERVICE WILL NOT EXCEED THE FEES PAID OR PAYABLE BY CUSTOMER TO MODUL FOR THE SERVICE DURING THE TWELVE MONTHS IMMEDIATELY PRECEDING THE EVENT GIVING RISE TO THE CLAIM, UNLESS A SIGNED AGREEMENT EXPRESSLY PROVIDES A DIFFERENT CAP OR CARVE-OUT.
The exclusions and limitations in this section do not apply to the extent they are prohibited by applicable law. Nothing in these Terms limits liability that cannot lawfully be limited or excluded.
39. CUSTOMER INDEMNIFICATION
To the extent permitted by law, Customer will defend, indemnify, and hold harmless Modul and its officers, employees, contractors, and affiliates from third-party claims, damages, liabilities, losses, and reasonable costs arising from:
- Customer Data or Customer-directed processing that violates law or third-party rights;
- Customer's security, employment, monitoring, or other business operations;
- Reports, records, or content created by Customer personnel;
- Customer's material violation of these Terms or applicable law; or
- Unauthorized use resulting from Customer's failure to reasonably protect credentials or connected systems.
This obligation does not apply to the extent a claim is caused by Modul's breach of these Terms, gross negligence, willful misconduct, or violation of law. The indemnified party must provide reasonably prompt notice, reasonable cooperation, and control of the defense to the indemnifying party, subject to the indemnified party's right to participate with its own counsel. No settlement may impose an admission of wrongdoing, non-monetary obligation, or material restriction on the indemnified party without its consent, not to be unreasonably withheld.
40. INTELLECTUAL-PROPERTY CLAIMS
If a third party claims that the unmodified Service, as provided by Modul and used as authorized, infringes a United States patent, copyright, or trademark, Modul may, at its option, obtain the right for Customer to continue using the affected Service, modify or replace the affected functionality, or terminate the affected Service and refund prepaid fees allocable to the unused terminated period. This section does not apply to claims arising from Customer Data, Customer instructions, third-party products, unauthorized modifications, or combinations not supplied or required by Modul. Any broader intellectual-property indemnity must be stated in a signed agreement.
41. FORCE MAJEURE
Neither party will be liable for delay or failure caused by events beyond its reasonable control, including natural disasters, severe weather, fire, flood, war, terrorism, civil unrest, labor disruption, governmental action, Internet or telecommunications failures, utility failures, cyberattacks, third-party outages, or similar events. This section does not excuse payment obligations already due.
42. CHANGES TO THE SERVICE
Modul may modify the Service to add functionality, improve usability or security, address vulnerabilities, comply with law, replace technology, modify integrations, or improve performance. Modul may discontinue functionality when reasonably necessary. Material changes to paid functionality will be handled in accordance with applicable Order Forms or other written commitments.
43. CHANGES TO THESE TERMS
Modul may update these Terms from time to time. Material changes will be identified by an updated version or effective date and may be communicated through Cordyn, email, Customer administrators, or another reasonable method. Where Modul determines that affirmative re-acceptance is appropriate or required, Cordyn may require a user or authorized Customer representative to affirmatively accept the revised version before continued use.
Cordyn may record the accepted document type, version, user, tenant, and acceptance timestamp to establish which legal version was accepted.
44. ELECTRONIC COMMUNICATIONS, ELECTRONIC RECORDS, AND ELECTRONIC SIGNATURES
Cordyn may provide communications, records, contracts, agreements, notices, disclosures, approvals, acknowledgments, and other information electronically through the Service, by email, through a Customer workspace or client portal, through a secure signing link, or through another electronic method made available by Cordyn.
By using the Service, Customers and users consent to receiving Service-related communications electronically where permitted by applicable law.
Electronic communications may include, without limitation:
- Account notices;
- Security alerts;
- Multi-factor authentication communications;
- Administrative notices;
- Maintenance notices;
- Billing communications;
- Product notices;
- Legal notices;
- Proposal and contract communications;
- Electronic-signature requests;
- Signature reminders;
- Contract amendments;
- Change orders;
- Renewal notices;
- Approval requests; and
- Other transaction-related communications.
Customers and users are responsible for maintaining accurate and current contact information and for ensuring that their email systems and other communication methods can receive Cordyn communications.
Cordyn Sign
Cordyn may provide electronic-signature and electronic-contracting functionality under the name "Cordyn Sign" or another Cordyn-branded signing feature.
Cordyn Sign may allow a Customer to prepare, upload, generate, send, review, approve, acknowledge, sign, countersign, retain, download, and manage contracts and related business records electronically.
Customers may use their own contract forms, contract templates, amendments, change orders, renewals, acknowledgments, and related documents through Cordyn Sign where supported by the Service.
Modul does not become a party to a contract merely because that contract is prepared, transmitted, signed, stored, or otherwise processed through Cordyn.
Unless Modul is separately identified as a contracting party in a written agreement, contracts transmitted through Cordyn Sign are agreements between the Customer and the applicable Customer client, signer, counterparty, employee, contractor, or other identified party.
Consent to Electronic Transactions
By selecting an electronic-consent control, adopting an electronic signature, selecting an action such as "Agree and Continue," "Adopt & Sign," "Sign," "Accept," or another affirmative signing or approval action, a signer may consent to conducting the applicable transaction electronically and to using electronic records and electronic signatures for that transaction.
Cordyn may require a signer to affirmatively confirm that the signer:
- Consents to the use of electronic records and electronic signatures for the applicable transaction;
- Has had an opportunity to review the applicable document;
- Can access and retain or reproduce the electronic record;
- Intends the electronic signature or other affirmative action to constitute the signer's signature or approval; and
- Agrees to be bound by the document to the extent the signer has authority to do so.
Cordyn may record the version of the electronic-signature disclosure or consent presented to the signer and the date and time of the signer's acceptance.
Electronic Signature Intent
An electronic signature is not applied merely because a document is opened, viewed, delivered, or downloaded.
Cordyn Sign requires an affirmative action intended to evidence execution, approval, acknowledgment, or acceptance.
A signer who adopts or applies an electronic signature represents that the signer intends that action to serve as the signer's electronic signature for the document presented.
Cordyn may support typed signatures, drawn signatures, initials, confirmation controls, one-time verification codes, authenticated portal sessions, email-based access, or other signing methods made available by the Service.
The visual appearance of a signature is only one part of the electronic-signature record. Cordyn may also preserve transaction evidence associated with the signing process.
Signer Identity and Authentication
Cordyn may use one or more methods to authenticate or attribute a signing action, including:
- Access to a secure email address;
- A unique or time-limited signing link;
- A one-time verification code;
- An authenticated Cordyn or client-portal session;
- Signer-provided name, title, organization, or role;
- IP address;
- Browser or device information;
- Date and time information;
- Signing-event history; and
- Other security or authentication information reasonably related to the transaction.
The authentication method used for a particular transaction may vary.
Cordyn does not represent that email possession, an IP address, a user agent, a typed name, or any individual technical factor by itself constitutes government-issued identity verification, biometric verification, notarization, or independent proof of legal identity.
Signer Authority
A person signing on behalf of a business, organization, Customer, client, employer, or other entity represents that the person has authority to execute the applicable document on behalf of that entity.
Cordyn may require a signer to provide or confirm the signer's:
- Name;
- Title;
- Organization;
- Role; and
- Authority to sign.
Customers are responsible for selecting appropriate signers and determining whether a signer has sufficient authority to bind the applicable organization.
Modul does not independently verify corporate authority, agency authority, board authorization, procurement authority, or other legal authority unless Modul expressly agrees to do so in writing.
Customer Responsibility for Contract Content
The Customer is responsible for the substantive content, legality, accuracy, completeness, and appropriateness of contracts and other documents the Customer uploads, generates, configures, or sends through Cordyn Sign.
The Customer is responsible for determining:
- Whether the document is appropriate for electronic execution;
- Whether electronic signatures are permitted for the applicable transaction;
- Whether required notices, disclosures, clauses, licenses, approvals, or consents are included;
- Whether the selected signer is authorized;
- Whether any jurisdiction-specific requirements apply;
- Whether notarization, witnessing, physical signatures, special delivery, or another formal process is required;
- Whether the document is subject to a required retention period; and
- Whether the Customer's use of Cordyn Sign complies with applicable law.
Cordyn provides electronic-signature workflow, evidence, recordkeeping, and document-management functionality, but Cordyn does not provide legal advice and does not determine the legal sufficiency of Customer-drafted agreements.
Supported Transaction Scope
Cordyn Sign is intended primarily for ordinary business and commercial transactions, including security-services agreements and related business records.
Supported uses may include:
- Security-services agreements;
- Commercial service agreements;
- Contract amendments;
- Change orders;
- Renewals;
- Rate amendments;
- Non-disclosure agreements;
- Business acknowledgments;
- Client approvals; and
- Other ordinary business records supported by Cordyn.
Customers must not assume that Cordyn Sign is appropriate for every category of document.
Certain transactions may be subject to special requirements or may not be eligible for electronic execution under applicable law.
Unless specifically supported by Modul in writing, Cordyn Sign is not intended to serve as the electronic-signature mechanism for specialized transactions that require materially different legal formalities, including documents for which applicable law requires notarization, witnessing, a particular delivery method, or another non-electronic execution requirement that Cordyn does not expressly support.
Document Integrity and Version Control
When supported, Cordyn may use cryptographic hashing, document versioning, immutable or restricted records, timestamps, audit events, and related controls to associate an electronic signature with the specific electronic record presented for signature.
Once a document is sent for signature, Cordyn may restrict modification of the applicable document version.
If material document content must be changed after a signing request has been issued, the existing request may be cancelled, superseded, or otherwise invalidated and a new document version or signing request may be required.
Signatures must not be carried forward to materially changed contract language unless the new document is separately executed as required by the applicable workflow.
Signing Evidence
Cordyn may create and retain evidence relating to an electronic-signature transaction.
Depending on the workflow, evidence may include:
- Document identifier;
- Contract identifier;
- Document version;
- Cryptographic document hash;
- Signer name;
- Signer email;
- Signer title or organization;
- Signer role;
- Authentication method;
- Electronic-consent version;
- Consent timestamp;
- Authority attestation;
- Intent-to-sign attestation;
- Signature or initials;
- Signature timestamp;
- IP address;
- Browser or user-agent information;
- Delivery events;
- Viewing events;
- Verification events;
- Signature events;
- Decline events;
- Reminder events;
- Completion events; and
- Other transaction evidence reasonably related to the signing process.
Customers acknowledge that individual pieces of technical evidence may not independently establish identity or legal authority. Cordyn may retain multiple types of evidence as part of the overall transaction record.
Certificate of Completion
Cordyn may generate a Certificate of Completion or similar evidence record for a completed electronic-signature transaction.
The certificate may identify:
- The executed document;
- The Customer;
- The applicable counterparty;
- Required signers;
- Signing roles;
- Authentication methods;
- Relevant timestamps;
- Consent and signing events;
- Document hashes; and
- Other transaction evidence.
A Certificate of Completion is intended to document the Cordyn signing process. It is not a notarization, government certification, legal opinion, or independent determination that a signer possessed authority to execute the underlying agreement.
Executed Records
After all required signatures have been completed and the signing process has been successfully finalized, Cordyn may generate and store an executed electronic record.
The executed record may include the signed agreement, applied signatures or initials, execution information, a completion page, and an associated Certificate of Completion.
Cordyn may calculate and retain a cryptographic hash of the executed record to assist with later integrity verification.
Completed signing records may be made available for download, printing, retention, or reproduction by authorized parties.
Customers should retain copies of executed agreements in accordance with their own legal, contractual, accounting, insurance, regulatory, and records-management obligations.
Record Retention and Reproduction
Where Cordyn retains an executed electronic contract or associated signing evidence, Cordyn will use the Service's then-current storage and retention functionality to maintain the record in a form capable of being accessed or reproduced while the record remains available under the Customer's subscription, retention configuration, applicable agreement, and Modul's retention practices.
Customers remain responsible for exporting and independently retaining records that must be preserved for a specific statutory, contractual, tax, insurance, employment, litigation, or other required retention period.
Cordyn is not a permanent legal-record archive unless Modul expressly agrees otherwise in writing.
Cancellation, Expiration, and Decline
Cordyn may permit an authorized Customer user to cancel, expire, extend, remind, or replace a signer on a pending signing request where supported.
Cancellation, expiration, signer replacement, or decline does not require Cordyn to delete historical evidence that the request existed or that actions occurred before the request ended.
Cordyn may preserve such records for audit, fraud-prevention, dispute-resolution, security, contractual, or legal purposes.
Electronic Delivery
A Customer may direct Cordyn to send signing requests and related transactional communications to email addresses supplied or selected by the Customer.
The Customer is responsible for ensuring that recipient information is accurate and that the Customer has a lawful and appropriate basis to contact the recipient.
Delivery to an email server, successful transmission, or the absence of a delivery error does not guarantee that a recipient personally received, reviewed, or acted upon the communication.
Cordyn may record delivery status and related events as part of the transaction record.
Customer Branding and Sender Identification
Cordyn Sign communications may identify the Customer as the organization sending the agreement.
When Cordyn-managed email delivery is used, messages may be sent using a Modul-controlled email address while displaying the applicable Customer's name.
For example, a signing email may appear as:
Customer Name via Cordyn
<notifications@getmodul.app>
The Customer remains the contracting or sending organization unless otherwise expressly stated.
Use of a Modul-controlled technical sender address does not make Modul a party to the underlying Customer agreement.
Third-Party Email and Communications Infrastructure
Electronic-signature communications may depend on email providers, telecommunications providers, internet service providers, domain-name systems, recipient mail systems, spam filtering, and other third-party infrastructure.
Modul does not guarantee uninterrupted or instantaneous delivery through third-party systems.
Customers should maintain appropriate alternative communication processes for time-sensitive matters.
45. GOVERNING LAW AND VENUE
These Terms are governed by the laws of the State of Texas, without regard to conflict-of-law principles. Unless a signed agreement provides otherwise, any action arising from these Terms or the Service must be brought in a state or federal court located in the Texas county in which Modul maintains its principal place of business at the time the action is filed, and each party consents to personal jurisdiction and venue there.
If Customer is a governmental or public entity and applicable law prohibits or restricts a provision of these Terms, including venue, indemnification, or similar provisions, that provision applies only to the maximum extent permitted by applicable law and any signed agreement with that Customer.
46. ORDER OF PRECEDENCE AND ENTIRE AGREEMENT
These Terms, the Privacy Policy, and any applicable Order Form, service agreement, DPA, Service Level Agreement, or other signed agreement constitute the agreement governing the applicable use of Cordyn. If a signed agreement conflicts with these Terms, the signed agreement controls to the extent of the conflict. A DPA controls with respect to Customer Data processing to the extent expressly stated in the DPA.
47. SEVERABILITY
If a provision of these Terms is held invalid or unenforceable, the remaining provisions remain in effect. The invalid provision will be interpreted or modified to the minimum extent necessary to make it enforceable where permitted by law.
48. NO WAIVER
A failure to enforce a provision does not waive the right to enforce that provision or any other provision later.
49. ASSIGNMENT
Customer may not assign these Terms without Modul's prior written consent, except as expressly permitted by a signed agreement. Modul may assign these Terms in connection with a merger, acquisition, reorganization, financing, sale of assets, or transfer of the Cordyn business, subject to applicable law and contractual obligations.
50. NOTICES
Legal notices to Modul may be sent to legal@getmodul.app. Service and support inquiries may be sent to support@getmodul.app. Notices to Customer may be sent to the Customer administrator, billing contact, account email, or through the Service. A signed agreement may establish additional notice requirements.
51. CONTACT INFORMATION
Modul Development LLC
Cordyn Security Management
Legal: legal@getmodul.app
Support: support@getmodul.app
Website: https://cordynhq.com
52. ACCEPTANCE
BY CLICKING TO ACCEPT, ACTIVATING AN ACCOUNT, OR USING CORDYN SECURITY MANAGEMENT AFTER BEING PRESENTED WITH THESE TERMS, YOU ACKNOWLEDGE THAT YOU HAVE READ, UNDERSTOOD, AND AGREED TO THESE TERMS. IF YOU ACCEPT ON BEHALF OF AN ORGANIZATION, YOU REPRESENT THAT YOU HAVE AUTHORITY TO BIND THAT ORGANIZATION.