1. The agreement and who it covers
1.1 PowerPlot is operated by Maison Labs Ltd, registered in England and Wales with company number 17318993, whose registered office is 168 Church Road, Hove, United Kingdom, BN3 2DL ("Maison Labs", "we", "us"). Contact: hello@powerplot.app.
1.2 These Terms govern business use of the PowerPlot software service, including enabled Scout features, invitation-only evaluations and previews of new features (the "Service"). The contracting customer ("Customer", "you") is the business identified in the accepted subscription order, invitation or account-setup confirmation (the "Order"). An Order may be recorded by email or through the account-setup process; it need not be a separately signed document. A person accepting on the Customer's behalf must have authority to bind it. The Service is intended for UK business and commercial-property activity, not consumer subscriptions.
1.3 The agreement consists of the Order, these Terms and Schedule 1 (Data Processing Schedule). The Schedule prevails on personal-data processing carried out on the Customer's behalf; an expressly agreed Order prevails on other commercial matters. An Order cannot remove mandatory data-protection obligations. Customer purchase-order terms do not apply unless we expressly agree to them in writing.
1.4 We provide links to these Terms and our Privacy Policy as part of the invitation or account-setup process. The agreement is formed when an authorised Customer representative accepts these Terms and the relevant Order, and we confirm or activate access. Acceptance may be given by email or by requesting, confirming or completing setup after these Terms have been brought to that representative's attention and it has been made clear that the action constitutes acceptance. Creating an account ourselves, sending an unsolicited invitation, or merely displaying links does not by itself establish the Customer's acceptance. We will retain the relevant acceptance and version record and make a copy available on request. Paid charges and commitments require the express agreement described in clauses 2 and 3; an invitation to an individual user does not alone create a paid subscription.
1.5 People submitting enquiries or receiving proposals are not thereby parties to this annual SaaS subscription. Installation, survey, consultancy and any finance arrangements are made separately with the relevant provider. Our Privacy Policy is a transparency notice, not a request for blanket consent or a substitute for this agreement.
2. Trials, evaluations, subscription term and renewal
2.1 Where we offer a standard subscription trial, it lasts 30 days from activation unless the Order states otherwise. The Order must identify any trial restrictions and any separately chargeable Scout activity before it is incurred. Invitation-only evaluations and new-feature previews are governed by clauses 2.7-2.10 and do not automatically become standard 30-day subscription trials.
2.2 A paid subscription following the trial requires your express acceptance of the price, 12-month commitment and renewal terms. You may accept those terms when starting the trial, in which case the paid subscription starts when the trial ends unless you notify us before the trial ends that you do not wish to continue. Without that advance acceptance or a later accepted paid Order, the trial ends without creating a paid annual commitment. Mere continued access does not replace acceptance of undisclosed charges.
2.3 The initial paid term is 12 months from the paid start date stated in the Order. A monthly billing arrangement, if agreed, is a way of paying the annual commitment; it is not a month-to-month subscription.
2.4 The subscription automatically renews for successive 12-month terms unless either party gives written notice of non-renewal at least 30 calendar days before the next renewal date. Notice must be received under clause 17. The Order or renewal communication will identify the paid start date, renewal date and applicable cancellation deadline.
2.5 Non-renewal takes effect at the end of the current term. Notice given after the deadline ordinarily takes effect at the end of the next renewal term, unless we agree otherwise. We will send a renewal reminder sufficiently before the deadline to allow you to act; this is an operational commitment and does not replace the agreed notice period.
2.6 You cannot terminate a paid term for convenience without paying the remaining committed base subscription charges. Stopping use, removing users or disabling Scout does not itself cancel the subscription. Your rights to terminate for our breach or under another express termination provision are unaffected.
2.7 Invitation-only evaluations and feature previews. We may offer evaluation access to the whole Service or to specified new or experimental features from time to time. These provisions apply to future evaluations as well as the current invitation-only programme. Evaluation access, including any Scout usage included in the invitation, is free unless charges are expressly agreed in writing before they are incurred. We will identify the scope, usage limits and any stated end date in the invitation or setup confirmation. Separate paid subscriptions and authorised usage remain subject to their agreed charges.
2.8 Evaluation access continues until any end date stated in the invitation, or until either party ends the affected evaluation on at least 14 calendar days' written notice. The earlier suspension and termination rights in clauses 12 and 13 continue to apply where justified by security, misuse, breach or law. Evaluation features may change or be withdrawn, subject to the applicable notice and data-return obligations. We do not promise that an experimental feature will become generally available or be included in a later paid subscription.
2.9 Evaluation access does not automatically become a paid subscription, and expiry of an evaluation does not create a fee or an annual commitment. A paid subscription or paid continuation requires an expressly accepted Order identifying the price, term and applicable usage arrangements. The ordinary 12-month term and automatic-renewal provisions apply to an agreed paid subscription, not to a free evaluation merely because an account remains active.
2.10 Evaluating or ending an optional feature within a paid account does not by itself cancel, renew, extend or reduce the Customer's existing paid subscription or the protections in clauses 8.3 and 13.5. A feature already included in the agreed paid service cannot be withdrawn as though it were a free preview merely by relabelling it. Confidentiality, data protection, permitted-use and applicable liability provisions continue to apply during an evaluation. Clause 14 governs return and deletion of affected data when an evaluation ends.
3. Charges and Scout usage
3.1 The Order states the base subscription charge, included features and limits, billing frequency, Scout rates and any prepaid allocation. Unless otherwise agreed, base charges are invoiced annually in advance and invoices are payable within 14 days. Charges are in pounds sterling and exclude VAT where applicable. No in-platform payment facility is required for an invoice to be payable.
3.2 Scout may be purchased using discounted prepaid credits or allocations, with separately agreed pay-as-you-go (PAYG) usage. The applicable rate card must identify chargeable events, credit deductions, treatment of unsuccessful or empty lookups, and PAYG rates before chargeable activity is authorised. We will not charge for an event that was not disclosed as chargeable.
3.3 PAYG usage or automatic credit top-ups require authority in the Order or explicit approval from an authorised Customer administrator at the disclosed rates. Accepting these Terms alone does not authorise unlimited usage or automatic top-ups. Once prepaid availability is exhausted, further chargeable activity requires an agreed PAYG arrangement or further purchase.
3.4 Unless the Order states otherwise, purchased prepaid credits expire 12 months after purchase. They are specific to your organisation, cannot be transferred or exchanged for cash, and are not refundable except as expressly provided in these Terms. Renewal does not reset a purchase's expiry date. Credits remaining when the agreement ends are forfeited unless an express refund provision applies. Promotional trial credits have the expiry stated when granted.
3.5 You are responsible for activity properly authorised by your users. We will make relevant usage records available to help resolve a genuine charge dispute. You are not responsible for charges attributable to our billing error or unauthorised activity caused by our breach of the agreement.
3.6 Base subscription prices are fixed for the current paid term. A renewal increase requires at least 60 days' written notice before renewal. An increase notified later applies only with your express agreement or at a subsequent renewal following sufficient notice.
3.7 We may change rates for future PAYG use or future credit purchases on at least 30 days' written notice. Changes do not retrospectively alter charges already incurred or reduce the purchased entitlement of existing unexpired prepaid credits. You may stop the affected optional Scout activity without cancelling the base subscription.
3.8 Raise invoice disputes promptly with enough detail to investigate and pay the undisputed amount on time. We will investigate in good faith. We may seek statutory late-payment interest and recovery costs where legally available, but will not treat a reasonable, genuinely disputed amount as undisputed debt while investigating it.
4. Access and permitted use
4.1 During the agreed term, we grant you a non-exclusive, non-transferable right to allow your authorised users to access the Service for your business, within your Order's scope. Consultants may use it to serve their own clients where permitted by the Order; this does not permit reselling platform access or redistributing a raw third-party dataset.
4.2 Keep account details accurate, restrict access to authorised people, protect credentials and promptly remove access when no longer needed. Tell us promptly about suspected compromise. Administrators are responsible for assigning appropriate roles and permissions. Additional access rights do not arise merely because a feature is technically visible.
4.3 Do not access another tenant without authority; bypass security, feature entitlements or usage restrictions; introduce malicious code; interfere with the Service; extract or resell restricted datasets; or use it for unlawful, misleading or abusive activity. Do not copy, reverse engineer or circumvent the software except to the extent permitted by law that cannot be excluded by contract.
4.4 Third-party integrations, exports and external communications remain subject to applicable law and any properly disclosed third-party conditions. An integration or export function is not a grant of rights that the relevant data owner has not provided.
5. Your data, forms and business activities
5.1 "Customer Data" means information and material supplied by you or your users, submitted through your forms, or held in your workspace on your instructions, including enquiries, contact records, consumption information and proposals. This definition does not transfer ownership of third-party data to either party.
5.2 You are responsible for the authority, accuracy and lawfulness of the Customer Data and instructions you supply; your user permissions; and the wording, configuration, pricing assumptions and claims used in your customer-facing materials. Do not collect unnecessary sensitive information through the Service.
5.3 Your forms and communications must identify the relevant organisation, provide appropriate privacy information and distinguish a requested enquiry response from optional marketing. You must establish the applicable lawful basis and obtain consent where required, rather than rely on these Terms as consent from an enquiry submitter.
5.4 We route enquiries to the relevant tenant, not to unrelated customer organisations. Any onward sharing you arrange, including a consultant passing a lead to an installer outside PowerPlot, is your responsibility and must be lawful and properly explained. We do not become the installer or a party to that arrangement.
6. Indicative estimates and third-party information
6.1 PowerPlot outputs are indicative calculated estimates based on available information, configured assumptions and customer inputs. They are not binding quotations, offers to install, technical designs, surveys, structural assessments, guarantees of savings or professional advice from Maison Labs.
6.2 Site suitability, final design and price require assessment by an appropriately qualified provider. Satellite or aerial imagery cannot reliably establish every material condition, including access, roof condition or strength, electrical infrastructure, permissions, network requirements and installation constraints. Actual generation, consumption, tariffs, costs and savings may differ from estimates.
6.3 You must review outputs before sharing or relying on them, make their indicative status clear and retain relevant disclaimers. You are responsible for the technical and commercial statements you make to your own clients. This does not remove our obligation to provide the Service with reasonable care and skill.
6.4 A survey fee, its refundability or credit against an installation price, an installation contract, a consultant's fee, or an installer-arranged power purchase agreement or finance arrangement is solely a matter between the relevant parties. PowerPlot does not offer or arrange finance, take installation deposits or conclude installation contracts on their behalf.
6.5 External address, property, EPC, business-rates, company and contact records may be incomplete, out of date or incorrectly matched. A ratepayer, registered company address or property association is not, by itself, proof of current occupation, ownership, decision-making authority, suitability or consent to contact. Verify material facts before using them.
6.6 Third-party information is subject to its source rights and licences. We will identify material usage restrictions and attribution requirements applicable to the supplied data. You must preserve required notices and must not resell, publish, bulk redistribute or use it outside the permitted scope. We do not claim exclusive ownership of public or third-party datasets.
7. Scout contacts and outreach
7.1 Scout facilitates customer-directed prospecting and access to externally supplied contact information. Availability of an email address, LinkedIn profile or a provider's consent-related label does not guarantee that every Customer may lawfully contact that person for every purpose or through every channel.
7.2 Before outreach, you must assess the recipient type, your intended purpose and channel, the applicable lawful basis, and the evidence and scope of any required consent. In particular, rules for corporate subscribers differ from those for sole traders and certain partnerships. Do not assume that a personal LinkedIn account has the same status as a corporate email address.
7.3 Comply with UK data-protection law and the Privacy and Electronic Communications Regulations where applicable. Identify the actual sender, provide a valid and effective way to object or opt out, honour objections and withdrawals, and maintain and apply appropriate suppression records. Do not conceal the sender or reimport an objecting contact to evade suppression.
7.4 Where you obtain personal information indirectly, provide the required privacy information within the applicable time: normally no later than one month, and earlier where required by first contact or disclosure. Rely on an exception only where it genuinely applies and can be justified. Keep enough provenance and compliance records to explain your use.
7.5 A requested proposal response is not permission for unrelated campaigns. You remain responsible for outreach sent through PowerPlot or exported for use elsewhere, including LinkedIn. Maison Labs retains its own applicable duties and will exercise reasonable care in selecting and administering suppliers; this clause does not transfer our legal responsibilities to you.
7.6 We may restrict or suspend offending outreach where reasonably necessary to address unlawful activity, complaints, security risks or email-delivery abuse, applying clause 12. We do not guarantee a lead volume, response rate, successful contact, conversion, or third-party data's completeness.
7.7 Suppression, correction and deletion. We will maintain and apply procedures to give effect to applicable privacy requests, objections, corrections and supplier deletion or suppression requirements affecting third-party contact information held in PowerPlot. We will check supplier request updates at the intervals required by our applicable source agreements and apply relevant requests to information we continue to hold, whether it is active, used, marked for retention or archived. These procedures may result in information being corrected, restricted, removed from use or deleted. We may retain the minimum information reasonably necessary to honour an objection, prevent inappropriate reintroduction of a record or demonstrate compliance, subject to applicable retention requirements.
7.8 Exported records and onward use. You must promptly apply any correction, suppression, deletion or use restriction we notify to you to affected copies under your control, including records exported to another system. Where required, you must communicate the restriction to authorised onward recipients. You must not reimport, reacquire or otherwise use information to circumvent an applicable restriction or objection. A source-licence deletion requirement applies to the affected source information and does not, by itself, require erasure of separately and lawfully obtained enquiry or contract records; any applicable privacy right or marketing objection must still be honoured.
7.9 Third-party contact-data rights. Access to third-party contact information does not transfer ownership or confer an unrestricted or permanent right to retain, export or redistribute it. You may use and export that information only within the scope permitted by your Order and the applicable source restrictions made available to you. We may restrict access or require deletion where necessary to comply with law or an applicable source licence, including where our right to supply the affected information ends. This does not remove your express rights under clauses 8.3 and 13.5 where a resulting change materially affects an agreed paid service. Necessary minimal suppression records may be retained only for an applicable lawful purpose and not as an alternative contact database.
7.10 PDL acceptable use. For PDL-sourced information, you and your authorised users must comply with PDL's Acceptable Data Use Policy identified in Appendix B. Use is limited to the business-contact and commercial-property purposes authorised by the Order, and must not fall within a prohibited use under that policy. Incorporation of those use restrictions does not incorporate PDL's subscription prices, liability limits, governing law or other unrelated commercial terms into this agreement. We will make the applicable restrictions available before use and notify material changes; clauses 8.3 and 16 govern their effect on the Service and this agreement.
7.11 Platform opt-outs and archiving. PowerPlot maintains a platform-wide opt-out status to restrict further prospecting use of affected contacts within the Service. Lookup contacts that have not been used or marked for ongoing use within 30 days after retrieval are archived. Archiving is not erasure and does not override a privacy request, source restriction or the obligations in clauses 7.7-7.9. Marking a contact for ongoing use does not authorise indefinite retention or override an objection.
7.12 Required outreach explanation and opt-out. Scout outreach emails sent through PowerPlot include a platform-controlled explanation of why the recipient is being contacted and where the contact information came from, together with an opt-out link. Tenant drafting controls do not allow users or administrators to remove that content. You must not hide, alter or circumvent it, including by moving a campaign outside the Service to avoid an objection. You remain responsible for the accuracy of the sender, purpose and campaign content and for providing the privacy information required for your processing. External outreach must also contain the information and opt-out arrangements required by law. This notice is not evidence of marketing consent, and its delivery does not replace either party's earlier or separate transparency obligations under clauses 7.4 and 11.3.
8. Service standard, support and changes
8.1 We will provide the Service with reasonable care and skill and materially in accordance with the agreed description. We will provide reasonable technical support by email at hello@powerplot.app, or through another support route expressly agreed in the Order. No fixed response time, uptime percentage or service-credit scheme applies unless expressly agreed in writing.
8.2 We do not promise uninterrupted or error-free operation or that every third-party service will remain available. We will use reasonable efforts to minimise disruption and give reasonable notice of planned maintenance where practicable. Trial restrictions do not exclude duties or liabilities that cannot lawfully be excluded.
8.3 We may improve or change the Service, but will not materially reduce the paid core functionality during your current term without your agreement, except where reasonably necessary for law, security or circumstances beyond our reasonable control. Where a necessary change materially and adversely affects an essential paid function and no reasonable alternative is available, you may terminate the affected service and receive the refund described in clause 13.5.
8.4 You remain responsible for your internet connection, compatible equipment, user configuration and appropriate copies of important outputs. This does not remove our security, resilience, data-return or restoration obligations under Schedule 1.
9. Intellectual property and authorised data use
9.1 Maison Labs and its licensors retain all intellectual-property rights in the Service, its software, calculation functionality, platform templates, documentation and branding. PowerPlot is the product name. No rights are transferred except the access and output-use rights expressly granted here.
9.2 As between the parties, you retain rights you hold in Customer Data and your branding. Third-party rights remain with their owners. Subject to those rights, you may use, download, retain and share proposals generated for your business, including after the subscription ends. This permission does not authorise copying the underlying software or selling a standalone PowerPlot template library.
9.3 You authorise us to host, copy, transmit, display and otherwise process Customer Data only as reasonably necessary to provide, secure, administer and support the Service, carry out your lawful instructions, and comply with applicable law. Personal-data roles are governed by clause 11, and Schedule 1 applies where Maison Labs processes personal data on the Customer's behalf. This is not a licence to sell your leads, share them across tenants or use identifiable tenant content for unrelated marketing or model training.
9.4 Authorised personnel may access relevant tenant information for necessary support, troubleshooting, administration and incident handling, on a need-to-know basis and subject to confidentiality. We may use necessary service diagnostics for reliability and security and genuinely anonymised, non-confidential aggregate usage statistics to improve the Service. Anonymisation itself must be lawful and within the applicable instructions; merely removing a name is not sufficient.
9.5 We will not identify you as a customer or use your logo in publicity without your permission.
10. Confidentiality
10.1 Each party will protect the other's non-public business, technical and commercial information with reasonable care and use it only to perform or exercise rights under the agreement. Disclosure is limited to personnel, authorised providers and professional advisers who need it and are bound by appropriate confidentiality duties.
10.2 These duties do not cover information independently developed, lawfully received without restriction, already lawfully known, or public other than through a breach. Legally compelled disclosure is permitted to the necessary extent, with advance notice where lawful and practicable.
10.3 Confidentiality duties continue while the information remains confidential. Personal-data duties apply independently and survive for as long as either party retains relevant information.
11. Data protection
11.1 Each party must comply with the data-protection law applicable to its activities. Schedule 1 applies whenever Maison Labs processes personal data on the Customer's behalf and is incorporated into this agreement.
11.2 You normally act as controller for your tenant's enquiries, leads, proposals and outreach. Where you act for another controller, you must have the authority and upstream arrangements needed to appoint us as sub-processor. Roles follow the actual processing, not a contractual label.
11.3 Independent activities and Scout contact information. Maison Labs acts as a separate controller for its necessary customer-relationship, billing, legal-compliance and service-administration activities. Maison Labs also acts as a controller for the sourcing and supply of licensed third-party contact information through Scout where it independently determines the purposes and essential means of that processing.
The Customer remains responsible for its selection and use of contacts and its prospecting and outreach activities, subject to clause 11.2. Where Maison Labs stores records, manages enquiries or proposals, or sends communications solely on the Customer's instructions, Maison Labs acts as a processor under Schedule 1.
Each party is responsible for the lawful basis, privacy information, retention and handling of individual rights applicable to its own controller activities. The parties will reasonably cooperate where a request concerns both parties' processing. This clause does not permit Maison Labs to sell Customer enquiry data, share it across tenants or use it for unrelated marketing.
12. Suspension
12.1 We may suspend the affected access where reasonably necessary to address a material security threat, unlawful or seriously abusive activity, a binding legal requirement, or a material breach of this agreement. For non-payment, we will ordinarily give at least seven days' written warning after the undisputed payment is overdue.
12.2 We will limit the scope and duration of suspension where reasonably practicable, explain the reason unless prohibited or unsafe to do so, and restore access promptly after the issue is resolved. We will provide an opportunity to remedy the issue where appropriate. Suspension is not a right to withhold a legally required data return or response.
12.3 Charges continue during a suspension caused by your breach, subject to applicable law. We will not charge you for an unjustified suspension caused by us, and will credit affected prepaid service charges proportionately.
13. Termination, outstanding charges and refunds
13.1 Either party may terminate for a material breach not remedied within 30 days after written notice identifying the breach and requiring remedy. A material breach incapable of remedy may justify immediate termination. Termination for insolvency is permitted only to the extent allowed by applicable law.
13.2 We may terminate immediately where continuing the affected service would be unlawful or where serious, deliberate abuse cannot reasonably be addressed by suspension. Where this is not caused by your breach, clause 13.5 applies. We may elect not to renew under clause 2 and may end evaluation access under clause 2.8, but have no general right to end your paid term early for convenience without the refund and release in clause 13.5.
13.3 For ordinary non-renewal, committed charges remain payable through the current term and access continues subject to this agreement. If we agree to an early convenience cancellation, the unpaid balance of that term's committed base subscription becomes payable, unless agreed otherwise. No hypothetical future PAYG activity is charged. Amounts already paid count towards, and are not added again to, the annual commitment.
13.4 Where we terminate for your material breach, unpaid committed base charges for the current term and accrued authorised usage remain payable to the extent enforceable by law. This is not a right to double recovery or to recover sums that the law requires us to reduce. Ordinary cancellation does not create an entitlement to a refund of properly charged past service or used credits.
13.5 Where you validly terminate for our unremedied material breach, or terminate under an express adverse-change or unresolved sub-processor provision, we will refund prepaid base charges for the unused affected period and the purchase value of unused affected paid Scout credits. No further base charges accrue for that affected service after termination. The same applies if we end a paid service early without your breach. Accrued lawful charges for service already supplied remain payable.
13.6 Ending optional Scout functionality alone does not terminate the base subscription unless the circumstances and the express termination right justify ending the wider service. We will not use this distinction to leave you paying for a service that no longer materially meets the agreed essential purpose.
14. Data return and deletion when service ends
14.1 Before the effective end date, arrange any needed export. During the following 30 days we will, on an authorised request, make Customer Data available for return using an available export or reasonable secure delivery method. This does not promise ongoing normal application access after termination. Data-protection return obligations are not conditional on payment of a disputed invoice.
14.2 We will delete live tenant Customer Data and stored tenant files, including brand assets and saved proposal files, no later than 30 days after the effective end date, subject to a lawful earlier instruction or a legal retention requirement. Any retained file versions must follow the same deletion requirement. Personal-data return, residual database backups and restricted legal retention are governed by Schedule 1. The 30 days run from the agreement's effective end, not the date non-renewal notice is sent.
14.3 We do not control copies lawfully retained or exported by you or other recipients. Clause 7 continues to apply to affected third-party contact information, including exported copies. Necessary Maison Labs contract, accounting, suppression and compliance records may be retained separately for an applicable lawful purpose under our Privacy Policy; this is not permission to retain your full tenant dataset.
14.4 Third-party contact information remains subject to clauses 6.6 and 7. Return of data does not grant new rights to use, retain or redistribute source-licensed information or revive a right that has ended. We will identify applicable restrictions and, where reasonably practicable, separate restricted source information from the Customer's own returnable records. This provision does not remove mandatory data-protection return obligations.
14.5 Where the entire evaluation or account ends, the ordinary return and deletion provisions apply. Where only a feature evaluation ends, those provisions apply to information processed solely for that feature and no longer needed for continuing agreed services. Ending a feature evaluation does not itself require deletion of records lawfully needed for the Customer's continuing Service, or permit us to retain information for an unrelated purpose.
15. Liability
15.1 Nothing in this agreement excludes or limits liability for death or personal injury caused by negligence, fraud or fraudulent misrepresentation, or any other liability that cannot lawfully be excluded or limited.
15.2 Subject to clause 15.1, neither party is liable for indirect or consequential loss. Neither party guarantees the other's anticipated profit, sales opportunities, energy savings or business outcomes. This does not exclude recoverable direct loss merely by describing it as a business loss, or remove an express contractual duty.
15.3 Subject to clauses 15.1, 15.4 and 15.5, each party's total aggregate liability to the other arising out of or in connection with this agreement, whether in contract, tort (including negligence), breach of statutory duty or otherwise, for events arising in a Contract Year is capped at 100% of the Charges paid or payable by that Customer for that Contract Year. This is a customer-specific cap, not a fixed sum or a separate cap for each claim. The same cap applies to confidentiality and data-protection claims between the parties; there is no additional or doubled cap.
For this clause, a "Contract Year" is each 12-month paid subscription term. Before a paid term begins, or where there is no paid annual term, it is each successive 12-month period from first activation, with any such period ending when a paid term begins. "Charges" means the committed base subscription charges for the relevant period, charges for Scout prepaid allocations purchased for that period, and authorised additional Scout usage charges actually incurred in that period, excluding VAT and hypothetical future usage. Use of prepaid credits is not counted again as an additional charge. Related events and claims are allocated to the period in which the first event giving rise to them occurred; events arising solely after service ends are allocated to the final relevant service period.
15.4 Where access is provided entirely without charge and no Charges are paid or payable for the relevant no-charge access period, including a wholly free trial or evaluation, the aggregate cap for each party for that no-charge access period is GBP 1, subject to clauses 15.1 and 15.5. No separate higher trial or evaluation cap applies. Where Charges are paid or payable, including authorised paid Scout activity during otherwise free access, clause 15.3 applies instead. A no-charge feature preview within an otherwise paid account does not reduce the charges-based cap for that account to GBP 1. These provisions do not limit an individual's statutory rights, a regulator's powers, or liability that cannot lawfully be limited.
15.5 Your obligation to pay properly due contractual Charges is not reduced by the damages caps. Each party must take reasonable steps to mitigate loss. Reasonable direct costs of restoring data or responding to a breach are not automatically excluded as consequential loss, but remain subject to the applicable cap where lawful.
15.6 The parties acknowledge the indicative nature of outputs, the subscription price and the allocation of responsibilities when assessing risk. These provisions apply only so far as permitted by applicable law and do not remove our reasonable-care-and-skill obligation.
16. Changes to the agreement
16.1 Material adverse commercial changes normally take effect at renewal, with at least 60 days' written notice so you can choose not to renew. We will not retrospectively change accepted prices, liability allocation or cancellation requirements for the current term.
16.2 A change needed to comply with law or address a material security risk may take effect earlier to the necessary extent, with as much notice as reasonably practicable. A material adverse reduction in paid functionality is dealt with under clause 8.3. Changes to sub-processors follow Schedule 1, not a general website-update permission.
16.3 The accepted version continues to govern unless amended under this clause or by written agreement. Posting revised terms alone does not create undisclosed charges or an unrelated right to reuse Customer Data.
17. Notices
17.1 Send contractual notices, including non-renewal, to hello@powerplot.app, identifying your organisation and subscription. You may also send them to our registered office, marked "PowerPlot contractual notice". We send notices to the Customer's administrator or billing contact recorded for the subscription. Keep that address current.
17.2 An email notice takes effect when delivered to the recipient's mail system, provided no delivery-failure notice is received. A postal notice takes effect when delivered. Our acknowledgement is helpful evidence but is not a condition of a valid cancellation notice. Keep evidence of sending and delivery. Dates and deadlines use UK local time.
17.3 This clause does not govern formal service of court proceedings or prevent a person from exercising privacy rights through another legally valid route.
18. General provisions and governing law
18.1 Neither party is responsible for delay caused by events beyond its reasonable control, provided it takes reasonable mitigating steps. This does not excuse payment for service already supplied or displace mandatory data-protection duties. If an event prevents an essential service for more than 30 consecutive days, either party may end the affected service and clause 13.5 applies to the unused prepaid period.
18.2 Neither party may assign the agreement without the other's consent, not unreasonably withheld or delayed. Maison Labs may transfer it with a genuine sale or reorganisation of the relevant business on prior notice if the successor assumes the obligations and there is no material reduction in your contractual or data-protection safeguards. Any consent required for a legal novation or by applicable law must still be obtained.
18.3 Neither party is the other's agent or partner. This agreement is the entire agreement about the Service, without excluding fraud or overriding an expressly agreed written warranty. If a provision is unenforceable, the remainder continues. Delay in exercising a right is not a waiver. A non-party has no contractual enforcement right under the Contracts (Rights of Third Parties) Act 1999; independent statutory rights remain unaffected.
18.4 The agreement and non-contractual disputes arising from it are governed by the law of England and Wales. The courts of England and Wales have exclusive jurisdiction, subject to any mandatory rule that cannot lawfully be excluded.
Schedule 1 - Data Processing Schedule
This Schedule forms part of the PowerPlot Terms and Conditions.
D1. Scope and roles
D1.1 "Data Protection Law" means the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003, in each case as amended, and other applicable UK data-protection law. "Controller", "processor", "personal data", "processing" and "personal data breach" have their meanings under that law. "Customer Personal Data" is personal data Maison Labs processes on the Customer's behalf under the agreement.
D1.2 The Customer is controller and Maison Labs is processor for the instructed tenant processing. Where the Customer is itself a processor, Maison Labs is its sub-processor and the Customer warrants that it has authority to appoint and instruct us. References to controller instructions then include properly relayed instructions of the ultimate controller.
D1.3 This Schedule does not relabel a supplier's or Maison Labs' genuinely independent controller activities. Those activities require their own lawful arrangements and transparency. Maison Labs will not use this distinction to repurpose Customer Personal Data outside the agreed instructions.
D1.4 Scout processing. References to Scout in the processing particulars in D2 cover activities carried out on the Customer's behalf. They do not extend the controller-to-processor provisions of this Schedule to independently controlled sourcing or supply of contact information described in clause 11.3. Those activities remain subject to Data Protection Law and the applicable controller obligations.
D2. Processing particulars
| Item | Agreed description |
|---|---|
| Subject matter | Operating the Customer's PowerPlot workspace and enabled enquiry, indicative-pricing, proposal, Scout and communication functions to the extent carried out on the Customer's behalf, subject to D1.4. |
| Purpose and nature | Receive, collect as instructed, validate, organise, match, calculate with, store, retrieve, display, transmit, support, secure, return and delete relevant information to provide the Customer-directed Service. |
| People concerned | Customer users and representatives; business enquiry submitters; prospective contacts; commercial-property owners or representatives; and other individuals identified in Customer-instructed records. |
| Personal data | Names, job titles, employer names and associations, derived seniority, available work email addresses and LinkedIn profile links; employment-start, last-verified and last-changed dates; email-availability flags and contact-disclosure status; provider person and company identifiers and employer website details; search fingerprints, processing-strategy and job references, discovery and last-seen timestamps and stale-record reasons; user-account identifiers and permissions; identifiable property or business associations; enquiries, consumption records, proposals, correspondence, proposal-access and delivery records; and necessary support or technical metadata. |
| Sensitive information | Special-category and criminal-offence data are not intended or required. The Customer must not instruct processing of them without a separate written arrangement and lawful safeguards. |
| Duration | The service term and the limited return/deletion period in D10, including any expressly disclosed residual backup period or legally required retention. |
| Customer rights and duties | Determine lawful purposes and instructions, provide transparency, maintain authority to supply data, manage access, respond to individuals and exercise the return, assistance and audit rights in this Schedule. |
D3. Instructions and confidentiality
D3.1 Maison Labs will process Customer Personal Data only on documented Customer instructions, including this agreement, authorised configuration and feature requests, and authorised support or administrative requests. These include necessary service operation, customer-directed lookups and communications, fault resolution and proportionate security and administration. They do not authorise cross-tenant disclosure or independent marketing reuse.
D3.2 If law requires other processing, we will tell the Customer of the requirement before processing unless prohibited by law. If we consider an instruction infringes Data Protection Law, we will immediately inform the Customer and may pause the affected processing while the parties resolve it.
D3.3 We will ensure that people authorised to process the data are bound by confidentiality obligations or an appropriate statutory duty, receive suitable instructions and have access limited to their responsibilities. Support access will be necessary, proportionate and subject to appropriate authorisation and records.
D4. Security
D4.1 Each party will implement the appropriate technical and organisational measures required for its role. Maison Labs will maintain measures appropriate to the risk, including the security commitments in Appendix A, taking account of the nature of the data, the state of the art, implementation costs and potential harm.
D4.2 We may update the measures without materially reducing the overall protection. We will provide reasonable information needed for the Customer to assess them. References to AWS or another provider do not assert that Maison Labs holds a certification it has not separately evidenced.
D5. Sub-processors
D5.1 The Customer gives general written authorisation for the sub-processors specifically identified as such in Appendix B and the onward sub-processors used for their described functions under the published supplier arrangements linked there, subject to this Schedule. Maison Labs will maintain relevant identity, function, location and transfer-safeguard information. A public-data source or independent controller is not automatically a sub-processor.
D5.2 Direct appointments by Maison Labs. Before a new or replacement sub-processor we appoint directly receives Customer Personal Data, we will give at least 30 days' written notice, unless the Customer expressly agrees to a shorter period. The notice will give sufficient information to assess the change and allow an objection on reasonable data-protection grounds. We will not implement the affected direct appointment while a timely, reasonable objection remains unresolved.
D5.3 Changes within an existing supplier's processing chain. Where an existing sub-processor changes its own onward sub-processors, we will notify affected Customers promptly after receiving the supplier's notice and pass on the relevant information and available advance notice. The supplier's notice period may be shorter than 30 days. We will provide a meaningful opportunity to object before the new processing starts and explain the available objection period. We will not treat a supplier's shorter notice, or an individual's silence, as permission to disregard Data Protection Law or the Customer's objection rights.
D5.4 Objections and resolution. We will discuss a reasonable alternative or resolution to a timely, reasonable objection. Where necessary to preserve the Customer's objection rights, including where insufficient advance notice is available, we will pause or avoid the affected processing while it is resolved. We remain responsible for arranging this with our suppliers. If no reasonable resolution is available, either party may terminate the affected service before the objected-to processing begins. The refund and release from future affected charges in clause 13.5 apply. A Customer need not accept materially inadequate protection to preserve an unrelated service.
D5.5 We will require the applicable data-protection obligations to be imposed throughout the delegated processing chain and will put in place the written contracts required by Data Protection Law. We remain responsible to the Customer for our sub-processors' performance of those obligations. This clause does not reduce mandatory authorisation, transparency or international-transfer requirements.
D6. International transfers
D6.1 Core tenant hosting is in the AWS London region. We will not make a restricted transfer of Customer Personal Data outside the UK except under documented Customer instructions and in compliance with Data Protection Law. Agreed supplier arrangements must identify the relevant processing and any overseas access, not rely on the storage region alone.
D6.2 Where required, we will ensure a valid adequacy arrangement or appropriate safeguards, complete the required transfer assessment, and provide reasonable information about those measures. We will not rely on blanket acceptance of this Schedule as an individual's consent to a transfer.
D7. Rights requests and regulatory assistance
D7.1 Taking account of the processing, we will provide appropriate technical and organisational assistance for the Customer to respond to individual-rights requests. If we receive a request about its data, we will notify the Customer without undue delay and not respond substantively except on instructions or where law requires.
D7.2 Taking account of the nature of processing and information available to us, we will assist with security compliance, breach notification, data-protection impact assessments and prior consultation with a supervisory authority.
D7.3 Routine assistance is included in the subscription. Material additional work may be charged only at reasonable rates agreed in advance, and not where required because of our breach. A fee dispute does not justify delaying urgent assistance required by law.
D8. Personal data breaches
D8.1 Maison Labs will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. We will not wait for a full investigation before giving the initial notice.
D8.2 As information becomes available, we will describe the nature of the breach, affected categories and approximate numbers of people and records where known, likely consequences, mitigation taken or proposed, and a contact for further information. Information may be provided in phases without undue delay.
D8.3 We will take appropriate containment and remediation steps, preserve relevant evidence and cooperate with the Customer's lawful response. The Customer remains responsible for notifications required of it as controller, with our assistance. Neither party will make a notification in the other's name without authority, unless law requires it.
D9. Evidence and audits
D9.1 We will make available the information necessary to demonstrate compliance with this Schedule and our applicable processor obligations, and allow and contribute to audits and inspections by the Customer or an independent auditor it appoints.
D9.2 The parties will normally use existing documentation first and agree reasonable notice, confidentiality and security arrangements. Routine audits will ordinarily be no more than once in a 12-month period, but that limit does not apply where an additional audit is reasonably required by a material incident, credible non-compliance concern or regulatory requirement. No arrangement may obstruct a regulator's powers or a necessary audit.
D9.3 Each party bears its ordinary compliance costs. An auditor must avoid unnecessary disruption and disclosure of other customers' information. We will promptly address identified failures for which we are responsible.
D10. Return, deletion and retention
D10.1 At the end of processing, the Customer may choose return followed by deletion or deletion without return. We will support an authorised return request during the 30-day exit period and securely delete live Customer Personal Data no later than 30 days after the agreement's effective end date, unless law requires retention. The Customer should request return early enough to avoid unnecessary delay; a request received before deletion will be handled rather than ignored.
D10.2 Standard return will use a reasonably available, commonly used electronic format for structured data and available original formats for other material, with secure delivery. One standard return is included. A custom migration may be separately agreed, without restricting the statutory right to return.
D10.3 The database is backed up daily with a rolling seven-day retention period. Residual database backups containing deleted Customer Personal Data will expire within seven days after live deletion and no later than 37 days after the agreement's effective end date. Until expiry, residual copies will be protected and unavailable for ordinary business use. If a recovery restores deleted or suppressed data, we will reapply the relevant instructions before returning it to ordinary processing. Stored tenant files, including brand assets, saved proposal files and retained object versions, must be deleted under the 30-day deadline in clause 14.2; the database-backup period does not authorise retaining those files longer. Sub-processors must follow applicable deletion instructions.
D10.4 Where law requires continued storage of particular Customer Personal Data, we will, unless prohibited, identify the requirement and expected period, restrict the data to that purpose and delete it when the requirement ends. This is not an unrestricted right to retain the tenant dataset for our own potential future use.
D10.5 We will confirm completion of the applicable deletion process on reasonable request. Necessary independent-controller accounting or contract records are treated separately and do not extend the permitted retention of Customer Personal Data.
D10.6 Clauses 7 and 14.4 address source-licensed contact information and minimal independent-controller suppression or compliance records. They do not reduce our mandatory processor return or deletion obligations for Customer Personal Data. Independently controlled Scout information is handled under clause 11.3 and the Privacy Policy, not retained as an unrestricted copy of the tenant workspace.
D11. Continuing obligations
D11.1 This Schedule continues while Maison Labs or its sub-processors hold Customer Personal Data. The agreement's liability provisions apply between the parties to the extent lawful, without limiting the rights of individuals or the powers of a supervisory authority.
Appendix A. Security commitments
Maison Labs will maintain risk-appropriate measures covering the following areas. These are contractual commitments to implement and maintain, not claims of an independently verified certification.
Access and tenant separation. Unique authorised user identities, appropriate role permissions, logical separation of tenants, controlled privileged access, prompt access removal when no longer needed, confidentiality duties and appropriate administrative access records.
Protection of information. Encryption in transit over public networks and appropriate encryption at rest for hosted data and backups; secure handling of credentials and secrets; data minimisation in diagnostics; and restrictions on copying production information into unrelated environments.
Operational security. Proportionate monitoring, vulnerability and patch management, controlled changes, incident-response procedures, supplier management, and regular assessment of the measures' effectiveness.
Resilience and deletion. Appropriate backup and recovery arrangements, periodic restoration checks, documented retention and deletion procedures, and safeguards preventing restored or residual copies from defeating deletion instructions.
People and facilities. Relevant staff guidance and training, need-to-know access, appropriate confidentiality, and reliance on assessed infrastructure-provider physical security where hosting is outsourced.
Appendix B. Supplier and source register
This register identifies providers used for the stated functions. Authorisation is limited to those functions and to processing that complies with this Schedule. Referenced supplier arrangements explain their processing chains; they do not import unrelated supplier prices, liability terms or governing law into this agreement. Changes are governed by D5.
Amazon Web Services - authorised sub-processor. Contracting entity: Amazon Web Services EMEA SARL (AWS). Functions: core hosting, storage, Amazon SES email delivery and Amazon CloudWatch monitoring. Primary service region: London, United Kingdom. Data: information required for those functions. Data protection arrangements: AWS processes personal data under its standard Data Processing Addendum, including the AWS UK GDPR Addendum and applicable international-transfer safeguards. Any processing outside the UK must comply with the international-transfer provisions in D6. AWS's Service Terms, section 1.14, incorporate those arrangements where applicable.
Postcoder - address lookup service. Provider: Allies Computing Ltd, trading as Postcoder. The PowerPlot server sends a UK postcode-based lookup query, an optional referring-page address in the Referer header, and ordinary connection and service metadata; it receives matching address information. The lookup does not require a person's name, email address, telephone number, consumption data or a copy of the tenant's enquiry record. To the extent it processes Customer Personal Data solely to perform our instructed lookup, Postcoder is an authorised sub-processor for that limited activity under D5. Its supply of reference address data remains subject to its source rights and licence.
Postcoder location and safeguards. Postcoder states that its API is hosted in the United Kingdom and Ireland. Its published sub-processor register includes Axiom Inc., United States, for API traffic analysis. Its Terms of Use, incorporated Data Processing Addendum and Privacy Policy govern the relevant supplier processing. For personal data processed in Ireland, applicable UK adequacy regulations provide the transfer basis. Any other restricted transfer must meet D6 using an applicable UK adequacy arrangement or appropriate UK safeguards and any required assessment. The supplier register does not establish that all PowerPlot query fields are sent to every listed supplier, and this entry does not represent the integration as exclusively UK-processed.
Scout contact-data API - People Data Labs, Inc. (PDL).
Purpose and information. PDL supplies names, job titles, employer details, LinkedIn profile links, available work email addresses, employment-start and job-verification/change dates, job-title levels and source identifiers for Scout's business-contact discovery. Known company information drives the search. PowerPlot derives a highest-level seniority classification, an email-availability flag and disclosure-status information, and retains the source and processing records described in D2. An actual email address is stored only where returned by PDL and the reveal setting is enabled. The selected fields and provenance are held in PowerPlot's database, not in application logs. Maison Labs holds the licence used to supply this functionality within PowerPlot. Requests are limited to the company-related criteria and identifiers reasonably required for the requested function.
Data-protection roles. PDL independently controls its own contact database. To the extent PDL processes Customer Personal Data solely to fulfil our instructed lookup requests, it is an authorised sub-processor for that activity under its Data Processing Agreement and D5. That limited authorisation does not extend to independent commercial reuse of Customer Personal Data. Maison Labs' and the Customer's activity-specific responsibilities are set out in clause 11 and D1.4.
Location and safeguards. PDL is a United States-based provider and relevant personal data may be processed in the United States. Where legally required, the applicable transfer arrangements use the EU Standard Contractual Clauses supplemented by the UK International Data Transfer Addendum, together with any additional safeguards and assessments required by Data Protection Law. This arrangement is separate from the AWS London hosting described above.
Retention, suppression and permitted use. PDL-sourced information held in PowerPlot is subject to clause 7, including restrictions on authorised exports. PDL's own source records and submitted-request processing are governed by its applicable privacy and contractual arrangements; PowerPlot's tenant-deletion period does not define PDL's independent retention. Deleting a record from PowerPlot does not by itself delete the underlying record from PDL's independently maintained database. No supplier label or available contact record establishes consent to a particular Customer's marketing.
Referenced supplier documents. PDL Privacy Policy; PDL Data Processing Agreement; PDL Services Subscription Agreement; and PDL Acceptable Data Use Policy, effective 1 April 2026, for clause 7.10. The supplier privacy and processing documents describe PDL's arrangements; only the use restrictions expressly identified in clause 7 are incorporated into the Customer's permitted use, subject to the agreement's change provisions.
Resend - support-email receipt and forwarding. Provider: Plus Five Five, Inc. (Resend). Functions: receiving and forwarding correspondence sent to hello@powerplot.app. Data: sender and recipient details, message content, attachments and related delivery information. This support route is separate from the Amazon SES application-email service described above.
Role. Resend is our processor for instructed email handling. Where correspondence contains Customer Personal Data we process on the Customer's behalf, Resend is an authorised sub-processor for that limited activity under D5. Its independent processing of account and usage information follows its Privacy Policy.
Location and safeguards. United States. Resend's standard Data Processing Addendum includes EU Standard Contractual Clauses supplemented by the UK Addendum for relevant transfers. D6 continues to apply.
Retention and deletion. The support-case retention period does not require Resend to retain operational email copies for 12 months. We will use available deletion controls or request provider assistance where needed to meet an applicable deletion obligation. Supplier defaults do not extend our obligations under D10. See Resend's retention information and sub-processor register.
Microsoft 365 - destination support mailbox. Provider: Microsoft, through Microsoft 365 / Exchange Online under the Microsoft agreement applicable to Maison Labs' tenant. Account operator: Maison Labs Ltd. Functions: receiving forwarded correspondence, storing messages and attachments, and enabling authorised support personnel to respond. Data: sender and recipient details, message contents, attachments and necessary account, security and delivery metadata. Microsoft is our processor for instructed mailbox handling and an authorised sub-processor under D5 where correspondence contains Customer Personal Data processed on the Customer's behalf.
Microsoft processing and safeguards. Regional mailbox-storage commitments depend on the tenant and applicable Microsoft Product Terms. Microsoft service operations may involve other countries, including the United States. Processing is governed by the Microsoft Products and Services Data Protection Addendum, including the transfer safeguards applicable to UK data. D6 applies to restricted transfers; this entry does not promise exclusively UK processing. We will provide relevant supplier and safeguard information on request.
Microsoft retention and access. Access to the support mailbox is restricted to authorised personnel. Routine support-case correspondence follows the 12-month closed-case period in the Privacy Policy, subject to earlier deletion of copied tenant content and applicable legal retention. Mailbox recovery and retained copies must be managed consistently with those duties; use of Microsoft 365 does not create a separate right to retain tenant data indefinitely.
Public/business-property sources. Ordnance Survey OpenData, local-authority ratepayer/business-rates records, the EPC Register and Companies House supply relevant reference information. They are not designated as sub-processors merely because their data is used. Any separate API processing of personal information must follow its applicable role, licence and transfer arrangements and this Schedule. We and the Customer must preserve source-specific attribution and permitted-use restrictions where applicable.