The terms that govern use of this website and the engineering, architecture and support services delivered by BFC Secure LLC. Return to the homepage
These Terms of Service form a binding agreement between BFC Secure LLC and each person or organisation that accesses this website or engages the firm to provide professional services. By browsing the website, submitting an enquiry, or accepting a proposal for work, the user agrees to be bound by these terms. A person who does not accept these terms should not use the website and should not engage the practice. Where a signed statement of work, master services agreement or similar document has been agreed between BFC Secure LLC and a client, and where that document conflicts with these terms, the signed document takes precedence for the work it covers. These terms have been written to be readable by business users while remaining precise enough to govern technical engagements.
In these terms, the practice, the firm, we and our refer to BFC Secure LLC. The terms client and you refer to the person or organisation engaging the practice or using the website. Deliverables means the documents, designs, configurations, code, reports and other materials produced by the practice during an engagement. Statement of work means a written description of a specific engagement, including its scope, schedule, fees and acceptance criteria. Personal data means information relating to an identified or identifiable natural person. Confidential information means non public information disclosed by one party to the other in connection with an engagement, whether in writing, verbally or in another form. Business day means a day other than a Saturday, Sunday or public holiday in the United States. Support services means the monitoring, maintenance and incident handling provided under an agreed service arrangement.
This website and the services of the practice are intended for business and professional users. By using the website or engaging the practice, the user confirms that they have the authority to act for the organisation on whose behalf they are dealing, or that they are acting on their own behalf as an individual client. The practice does not knowingly provide services to a person who lacks the legal capacity to enter a binding agreement. Where a minor accesses the website, the practice asks that a parent or guardian supervise that use, because the site and services are not designed for children.
The website is provided so that visitors can learn about the practice, review its services and make contact. Visitors may browse, read, print pages for internal reference, and link to the site, provided the link does not suggest a false endorsement. Copying substantial portions of the site into another publication, republishing content as if it were original, or presenting the practice work as the work of another firm is not permitted. Any automated access, such as indexing by a recognised search engine, is acceptable where it respects the technical directives published on the site, but heavy automated collection that degrades service for other visitors is not. Content on the site is provided for general information and does not constitute a technical specification or a professional opinion tailored to any particular environment.
Users must not misuse the website or the systems of the practice. The following conduct is prohibited:
The practice may take any lawful step it considers necessary to prevent or stop prohibited conduct, including blocking access, preserving evidence and reporting the matter to the competent authorities.
All content on this website, including text, layout, graphics, visual design and code, is owned by or licensed to BFC Secure LLC and is protected by applicable intellectual property law. The names, marks and branding of the practice may not be used without written permission. Intellectual property rights in deliverables produced during an engagement are set out in the applicable statement of work. Unless a statement of work states otherwise, the practice retains ownership of its pre existing tools, templates, methodologies and general knowledge, and grants the client a perpetual, non exclusive licence to use the deliverables for the internal business purposes for which they were prepared. Where the statement of work assigns ownership of custom deliverables to the client, the practice will execute the documents needed to give effect to that assignment on payment of all fees due.
Professional services are delivered under a written proposal or statement of work that describes the scope, the schedule, the responsibilities of each party, the assumptions on which the work depends, the fees and the acceptance criteria. A statement of work becomes binding when both parties accept it in writing, whether by signature or by written confirmation through email. Work that falls outside the agreed scope is treated as a change and is handled through a documented change control process. No change is binding until both parties confirm the revised scope, schedule and any fee adjustment. Where a proposal includes an estimate rather than a fixed price, the estimate is prepared in good faith from the information available, and the practice will notify the client promptly if the estimate is likely to be exceeded.
Fees for services are stated in the applicable proposal or statement of work. Unless agreed otherwise, invoices are issued on completion of a milestone or monthly for continuing services, and are payable within the period stated on the invoice. The practice may charge interest on overdue amounts where permitted by law. Amounts already invoiced for work performed are not refundable. Expenses reasonably incurred in delivering an engagement, such as travel and third party licence costs, are charged at cost where the statement of work provides for them, with supporting receipts available on request. All fees are exclusive of taxes, which are added where the law requires. Where a client disputes an invoice, the client should notify the practice within the period stated on the invoice and pay the undisputed portion while the question is resolved.
A successful engagement depends on cooperation from the client. The client agrees to provide accurate information about the environment and business requirements, to grant timely access to the systems and people needed for the work, and to nominate a person with authority to make decisions and approve deliverables. The client is responsible for maintaining its own backups unless the statement of work expressly places that duty on the practice, and for ensuring that it has the legal right to grant any access it provides. Where the client supplies data, credentials or third party materials, the client confirms that it is entitled to do so. Delays caused by the client may affect the schedule, and the practice will discuss any resulting adjustment openly.
Where an engagement requires the practice to access a client site, network or cloud tenancy, access is provided through named accounts, with least privilege applied and with logging enabled so that activity can be reviewed. The practice cooperates with the security requirements of the client, including any vetting, induction or acceptable use rules that apply on site. Credentials provided to the practice are held securely and are removed or rotated when the work is complete. Where the practice discovers a security weakness during an engagement, it reports the finding to the client promptly and treats the details as confidential until the client authorises disclosure. The client remains responsible for the security of its own environment after handover, unless a support arrangement expressly assigns that duty to the practice.
Deliverables are prepared to the standard of care expected of a competent technology engineering practice and are supplied in the formats agreed in the statement of work. The client reviews each deliverable against the acceptance criteria and notifies the practice of any material non conformance within the review period stated in the statement of work. If the client demonstrates a genuine non conformance, the practice corrects the deliverable at no additional charge. If no material non conformance is notified within the review period, the deliverable is considered accepted. Acceptance of a deliverable does not prevent the client from raising a later question about a defect that was not reasonably discoverable during review, and the practice will investigate such questions in good faith.
Engagements frequently involve products and services supplied by third parties, such as cloud platforms, hardware, software licences and connectivity. Those products and services are governed by the terms of the third party provider, and the client is responsible for complying with those terms and for paying any associated charges unless the statement of work says otherwise. The practice selects third party options with reasonable care and integrates them to the agreed design, but it does not control the provider and cannot guarantee that a provider will continue a feature, maintain a price or avoid an outage. Where a provider changes its offering in a way that affects a design, the practice informs the client and proposes options for adaptation.
Each party agrees to keep the confidential information of the other party in confidence and to use it only for the purposes of the engagement. Confidential information may be disclosed to employees, contractors or advisers who need it to perform the work, provided those people are bound by confidentiality obligations at least as protective as these terms. Confidential information does not include information that is already public, that becomes public without a breach of these terms, that was lawfully known before disclosure, or that is independently developed without reference to the disclosed material. Where the law compels disclosure, the party required to disclose gives prompt notice to the other party where that is lawful, so that protective steps can be considered. Confidentiality obligations continue after an engagement ends.
Where the practice processes personal data on behalf of a client, the practice acts as a processor and the client acts as a controller. The practice processes that data only on the documented instructions of the client, applies appropriate technical and organisational security measures, assists the client with requests from individuals and with breach notifications, and deletes or returns the data at the end of the engagement. Where the practice processes personal data for its own purposes, such as answering an enquiry, it acts as a controller and complies with the obligations described in the Privacy Policy published on this website. The privacy notice forms part of these terms by reference and should be read alongside them.
The practice warrants that services are performed with reasonable skill and care by suitably qualified personnel, and that deliverables materially conform to the agreed specification at the point of acceptance. Except for those warranties, and to the fullest extent permitted by law, the website and all services are provided without further warranty of any kind, whether express or implied, including implied warranties of merchantability, fitness for a particular purpose and non infringement. The practice does not warrant that the website will be uninterrupted, error free or free of harmful components, nor that any design will eliminate every risk. No advice given through the website creates a warranty unless it is confirmed in a signed statement of work. Some jurisdictions do not allow certain exclusions, so parts of this section may not apply to every client, in which case the remaining provisions continue in force.
To the fullest extent permitted by law, neither party is liable for indirect, incidental, special, consequential or punitive damages, or for lost profits, lost revenue, lost data or business interruption, even if the possibility of such loss was known. The total aggregate liability of the practice arising out of or relating to an engagement is limited to the total fees paid by the client to the practice for the specific engagement giving rise to the claim during the twelve months preceding the event. This limitation does not apply to liability that cannot lawfully be limited, such as liability for fraud, wilful misconduct, or death or personal injury caused by negligence where such a limitation is prohibited. The parties acknowledge that the fees reflect this allocation of risk and that the limitation is a material basis of the agreement.
The client agrees to indemnify and hold harmless the practice against claims, losses, liabilities and reasonable expenses arising from data, materials or access supplied by the client that the client was not entitled to supply, from use of a deliverable in a manner not contemplated by the statement of work, or from the client breach of these terms or of applicable law. The practice agrees to indemnify and hold harmless the client against claims that a deliverable prepared solely by the practice infringes the intellectual property rights of a third party, provided the client notifies the practice promptly, allows the practice to control the defence, and provides reasonable cooperation. Where such a claim arises, the practice may modify the deliverable, procure a licence, or refund the fees paid for the affected deliverable, at its option.
These terms apply for as long as the website is used or an engagement continues. Either party may terminate an engagement in accordance with the notice period stated in the applicable statement of work. Either party may terminate immediately if the other party commits a material breach that remains uncured after written notice, or becomes insolvent, or ceases to carry on business. The practice may suspend services where an invoice remains unpaid beyond the agreed period, or where continuing would create a security or legal risk. On termination, the client pays for work performed and expenses incurred up to the effective date, the practice returns or destroys confidential information as instructed, and each party returns or deletes the other party materials in accordance with the engagement documents. Termination does not affect provisions that by their nature should survive, including confidentiality, intellectual property, limitation of liability and governing law.
Neither party is liable for a failure or delay in performance caused by an event beyond its reasonable control, including natural disaster, severe weather, epidemic, war, civil disturbance, industrial action, failure of a public utility, failure of a major telecommunications or cloud provider, or a governmental act. The affected party notifies the other party promptly and uses reasonable efforts to mitigate the impact and resume performance. If the event continues for an extended period, either party may terminate the affected portion of the engagement by written notice, and the client pays for work performed and non cancellable commitments made before termination.
These terms and any engagement under them are governed by the laws of the State of Utah in the United States, without regard to conflict of law principles. The parties agree to attempt to resolve any dispute through good faith discussion between senior representatives before commencing formal proceedings. If a dispute is not resolved within a reasonable period, the parties agree that the courts located in Utah have jurisdiction, unless the applicable statement of work specifies a different forum or a different dispute resolution method such as mediation or arbitration. Nothing in this section prevents either party from seeking urgent interim relief from a court of competent jurisdiction to protect its confidential information or intellectual property.
These terms, together with any applicable statement of work and the Privacy Policy, constitute the entire agreement between the parties on its subject matter and supersede prior discussions on that subject. If any provision is held invalid or unenforceable, that provision is modified to the minimum extent necessary or severed, and the remaining provisions continue in full force. A failure or delay in enforcing a provision is not a waiver of that provision or of any other. Neither party may assign these terms without the written consent of the other, except to an affiliate or to a successor in a merger or sale of substantially all assets. Nothing in these terms creates a partnership, joint venture or employment relationship between the parties. The practice may use subcontractors to perform part of the work, provided the practice remains responsible for the quality of the work and for the conduct of the subcontractor.
Formal notices under these terms should be sent in writing to the addresses below. Notices to the practice may be delivered by email to security@bfcsecure.buzz and are treated as received on the next business day after transmission. Notices to a client are sent to the email address or postal address most recently provided to the practice. Either party may update its notice details by giving written notice to the other. Operational messages, such as scheduling confirmations and status updates, may be exchanged informally and do not need to follow the formal notice route.
BFC Secure LLC
134 N Welden Way, Layton - 84041-8870, United States (US)
Email: security@bfcsecure.buzz
Phone: +12705189782
The practice may update these terms from time to time to reflect changes in its services, its operating practices or the law. The current version is published on this page and takes effect when it is posted. Where a change is significant and affects an active engagement, the practice notifies the affected client and, where the change would materially increase the client obligations or reduce the client rights, seeks written acceptance before the change applies to that engagement. Continued use of the website after an update indicates acceptance of the revised terms for website use. A client who does not accept a revision to the terms governing an ongoing engagement should contact the practice to discuss the position before further work is performed.
Questions about these terms, requests for clarification, and notices of dispute are welcome and are handled directly by the practice. The dedicated email address is security@bfcsecure.buzz and the telephone number is +12705189782. Written correspondence may be sent to BFC Secure LLC, 134 N Welden Way, Layton - 84041-8870, United States (US). The practice aims to answer every question about these terms promptly, clearly and in plain language, and it keeps a record of the answers given so that its contractual commitments remain consistent over time.