Plain-language summary, not legal advice. This document is a template you can use to evaluate Univaultport. Enterprise customers should rely on their negotiated Master Services Agreement (MSA) and Data Processing Addendum (DPA) for contractual terms.
01 Acceptance & eligibility
By accessing or using the Univaultport platform (the “Service”) you, on behalf of yourself or the legal entity you represent (“Customer”), agree to these Terms of Service (“Terms”). If you do not agree, do not use the Service.
You represent that you are at least 18 years old, have the authority to bind your organization, and are not barred from receiving the Service under applicable export controls or sanctions laws (including, without limitation, the U.S. Department of Commerce's Denied Persons List and the U.S. Treasury OFAC-administered lists).
Enterprise customers. Where Customer and Univaultport have executed a Master Services Agreement (MSA) and Order Form, those documents control over these Terms. The Data Processing Addendum (DPA) executed in connection with the MSA governs the processing of personal data.
02 The service
Univaultport is a hosted platform for migrating digital assets — files, metadata, folder hierarchies — between cloud storage, content management, and digital-asset-management systems via configurable source and destination connectors.
We may update the Service from time to time, including by adding, modifying, or removing features. We will not materially reduce core functionality during a paid term without notice and a reasonable transition period.
03 Accounts & workspaces
3.1 Account creation
To use the Service, Customer must create an account and at least one workspace. Customer is responsible for the accuracy of registration information and for keeping it current.
3.2 Authorized users
Customer may invite individuals (“Authorized Users”) into a workspace and assign them roles. Customer is responsible for Authorized Users' actions in the workspace and for ensuring each Authorized User has agreed to these Terms (or has been bound by Customer's internal policies that incorporate them).
3.3 Credentials & access
Customer must safeguard sign-in credentials, API tokens, and connector credentials. Customer must notify us promptly at security@univaultport.com on learning of any unauthorized access. Customer is responsible for activity occurring under its accounts until notice is received.
04 Acceptable use
Customer and Authorized Users will not, and will not permit others to:
- Use the Service in violation of applicable law, third-party rights, or any industry-specific regulation (including HIPAA, FERPA, GLBA, or PCI-DSS where such data is involved) without separate written agreement.
- Upload, transmit, or process content that infringes intellectual-property rights, contains malware, or violates a third party's privacy.
- Attempt to reverse-engineer, decompile, scrape, or copy the Service except as permitted by applicable law that cannot be lawfully waived.
- Probe, scan, or test the vulnerability of the Service except through a coordinated disclosure process at security@univaultport.com.
- Use the Service to bulk-transfer assets the Customer is not authorized to access, or to migrate data that would violate the source platform's terms of service.
- Resell, sublicense, or make the Service available to any third party except Authorized Users acting on Customer's behalf.
We may suspend access (with or without notice, depending on severity) to address an active threat to the Service, our other customers, or third parties. We will restore access as soon as practicable after the issue is resolved.
05 Customer data & ownership
Customer retains all rights, title, and interest in Customer Data — including the assets and metadata you migrate through the Service. Customer grants Univaultport a non-exclusive, worldwide license to host, transmit, and process Customer Data solely to provide and improve the Service for that Customer and to comply with law.
We do not use Customer Data to train models, build commercial datasets, sell to third parties, or share across customers. See the Privacy Policy for processor obligations and the DPA for contractual terms.
5.1 Data portability & deletion
On request during the term, Customer may export Customer Data in machine-readable formats supported by the Service. Within 30 days of termination, we delete production Customer Data and connector credentials; encrypted backups age out within 35 days thereafter.
06 Third-party connectors
The Service connects to third-party platforms (e.g. AWS S3, Google Drive, Cloudinary, WordPress, Contentful, SFTP servers) at Customer's direction. Use of those platforms is governed by their own terms; Univaultport is not responsible for their availability, behavior, or compliance with Customer's agreements with them.
Customer is solely responsible for ensuring the credentials supplied to a connector grant only the permissions necessary for the migration in question and comply with the third party's acceptable-use policies.
07 Fees & taxes
Fees, if any, are as set forth on the applicable Order Form, pricing page, or Stripe checkout. Unless otherwise specified, fees are quoted in US dollars and exclusive of taxes. Customer is responsible for all applicable taxes other than taxes on Univaultport's net income.
Annual and multi-year subscriptions are non-cancellable and non-refundable except as expressly provided in an Order Form. Past-due amounts may incur late charges at the lesser of 1.5% per month or the maximum rate permitted by law, plus collection costs.
08 Service availability
We target high availability for the Service and continuously monitor production systems. A formal Service Level Agreement (SLA) with uptime credits is available to enterprise customers under an executed Order Form.
Free, trial, and beta usage are provided “as available” without uptime commitments. Scheduled maintenance is announced in advance where possible; emergency maintenance may occur with limited notice.
09 Security & privacy
We implement administrative, technical, and physical safeguards designed to protect Customer Data, including encryption in transit and at rest, role-based access control, audit logging, and a documented incident-response process. See the Privacy Policy for details. For contractual commitments, see the DPA executed with your MSA.
Customer agrees to use the Service's security features (MFA when available, least-privilege role assignments, prompt removal of departing Authorized Users) consistent with industry norms. Customer is responsible for the security of its own systems and credentials outside of the Service.
10 Confidentiality
Each party may receive confidential information of the other in connection with the Service (“Confidential Information”). The receiving party will (a) use the Confidential Information only as necessary to exercise rights or perform obligations under these Terms, (b) protect it with no less than reasonable care, and (c) not disclose it to third parties except to its affiliates, employees, and contractors bound by equivalent confidentiality obligations and with a need to know.
These obligations do not apply to information that is or becomes publicly available without breach, was rightfully known prior to disclosure, is independently developed, or is required to be disclosed by law (with prompt notice where legally permitted).
11 Intellectual property
Univaultport and our licensors retain all rights, title, and interest in the Service, including all software, documentation, designs, trademarks, and improvements. No rights are granted to Customer except as expressly stated in these Terms.
Feedback, suggestions, or ideas Customer provides about the Service may be used by us without obligation or attribution. Customer represents that it has the right to provide such feedback without restriction.
12 Warranty disclaimer
THE SERVICE IS PROVIDED “AS IS” AND “AS AVAILABLE” WITHOUT WARRANTIES OF ANY KIND, whether express, implied, statutory, or otherwise, including any implied warranties of merchantability, fitness for a particular purpose, title, or non-infringement. We do not warrant that the Service will be uninterrupted, error-free, or secure, that defects will be corrected, or that any data migration will be complete or accurate in all cases. Customer is responsible for verifying migration outcomes against authoritative records of the source and destination platforms.
13 Limitation of liability
To the maximum extent permitted by law, neither party will be liable for any indirect, incidental, special, consequential, exemplary, or punitive damages,including lost profits, lost revenue, business interruption, or loss of data, even if advised of the possibility of such damages.
Each party's aggregate liability for all claims arising out of or relating to these Terms or the Service is limited to the greater of (a) the fees paid or payable by Customer to Univaultport for the Service in the twelve (12) months preceding the event giving rise to the claim, or (b) USD $100. These limitations apply in the aggregate and not per incident.
Nothing in these Terms limits either party's liability for: (i) breach of confidentiality, (ii) infringement of the other party's intellectual property, (iii) indemnification obligations, (iv) Customer's payment obligations, or (v) liability that cannot be limited under applicable law (including, in some jurisdictions, gross negligence, willful misconduct, fraud, or death/personal injury).
14 Indemnification
By Customer. Customer will defend, indemnify, and hold Asset Migrator harmless from third-party claims arising from (a) Customer Data, including infringement, defamation, or privacy violations resulting from the content or use of the data; (b) Customer's breach of these Terms or applicable law; or (c) misuse of the Service by Authorized Users.
By Univaultport. We will defend, indemnify, and hold Customer harmless from third-party claims alleging that the Service, as provided by us and used in accordance with these Terms, infringes a U.S. patent, copyright, or trademark of the claimant. Our obligation does not extend to claims arising from (i) Customer Data or third-party content, (ii) combinations with non-Asset Migrator products, or (iii) modifications not made by us.
Indemnification is conditioned on the indemnified party (a) promptly notifying the indemnifying party in writing, (b) giving control of the defense and settlement (provided no admission of liability is required without consent), and (c) providing reasonable cooperation at the indemnifying party's expense.
15 Term & termination
These Terms apply for as long as Customer uses the Service. Paid subscriptions run for the term stated on the applicable Order Form.
15.1 Termination for convenience
Customer may close its account at any time through the workspace settings or by contacting support@univaultport.com. Free-tier termination is effective immediately; paid plans run through the current billing cycle unless the applicable Order Form provides otherwise.
15.2 Termination for cause
Either party may terminate immediately on written notice if the other party (a) materially breaches these Terms and fails to cure within 30 days of notice, or (b) becomes insolvent or subject to bankruptcy proceedings.
15.3 Effect of termination
On termination, Customer's right to access the Service ends. Customer is responsible for exporting Customer Data prior to termination; we will retain a read-only window of up to 30 days at our discretion. After that window we delete Customer Data per the retention schedule in the Privacy Policy.
Sections that by their nature should survive termination — including 5 (ownership), 7 (fees accrued), 10 (confidentiality), 11 (IP), 12–14 (warranties, liability, indemnity), 17 (governing law), and 18 (general) — will survive.
16 Modifications
We may update these Terms from time to time. We will provide at least 30 days' notice for material changes via in-app notification and email to workspace owners. Continued use after the effective date constitutes acceptance. If you do not agree to a material change, your remedy is to terminate the Service before the change takes effect.
17 Governing law & disputes
These Terms are governed by the laws of the State of California, USA, excluding its conflict-of-laws principles and the UN Convention on Contracts for the International Sale of Goods. The parties consent to the exclusive jurisdiction of the state and federal courts located in San Francisco County, California for any dispute that is not subject to arbitration.
17.1 Informal resolution
Before initiating formal proceedings, the parties will attempt in good faith to resolve any dispute through written notice describing the claim and a 30-day negotiation period.
17.2 Arbitration (US customers)
Any unresolved dispute under USD $250,000 will be resolved by binding arbitration administered by JAMS under its Streamlined Arbitration Rules in San Francisco, California, with one arbitrator. Either party may seek injunctive relief in court for misappropriation of confidential information or intellectual-property infringement.
Class action waiver. The parties may bring claims only in their individual capacity, not as a plaintiff or class member in any purported class or representative proceeding.
18 General provisions
- Entire agreement. These Terms, together with any executed MSA, Order Form, DPA, and the Privacy Policy, constitute the entire agreement between the parties and supersede prior agreements on the subject.
- Assignment. Neither party may assign these Terms without the other's consent, except in connection with a merger, acquisition, or sale of substantially all assets. Any assignment in violation of this section is void.
- Independent contractors. The parties are independent contractors; nothing creates a partnership, joint venture, or employment relationship.
- No third-party beneficiaries. Except as expressly provided, these Terms do not create rights in third parties.
- Force majeure. Neither party is liable for delays caused by events outside its reasonable control (natural disasters, war, terrorism, internet outages, denial-of-service attacks, government action) so long as the affected party takes reasonable steps to mitigate.
- Notices. Notices to Univaultport should be sent to legal@univaultport.com; notices to Customer are sent to the email address on the workspace owner's account.
- Severability. If a provision is held unenforceable, the remainder of these Terms remains in effect and the provision is modified to the minimum extent necessary.
- Waiver. A failure to enforce a provision is not a waiver of future enforcement.
- Government users. The Service is “commercial computer software” under 48 C.F.R. §12.212 and 48 C.F.R. §227.7202. Government customers acquire only those rights set forth in these Terms.
- Export controls. Customer will comply with all applicable export and re-export laws and will not export the Service to embargoed countries or restricted parties.
19 Document change log
- v1.0 — 2026-05-26
- Initial Terms of Service.
Get in touch
We route legal and privacy mail to dedicated mailboxes so they reach the right team quickly. Enterprise customers should reach out to their assigned account contact.
privacy@univaultport.com
Data requests, GDPR/CCPA inquiries
security@univaultport.com
Vulnerability reports, incident notices
legal@univaultport.com
Contracts, DPA, subpoenas
support@univaultport.com
Product questions