Terms and Conditions
These Terms form a binding agreement for business customers. They are not legal advice to you; if you are unsure how they apply, take your own advice.
1. Agreement
1.1 These Terms and Conditions (“Terms”) govern your purchase and use of Hume services.
1.2 By completing the intake form, ticking the acceptance boxes, and/or paying for a service, you (“Client”, “you”) agree to these Terms. Our Privacy Policy explains how we handle personal data; it is an information notice provided under data protection law and does not form part of this agreement.
1.3 If you accept on behalf of an organisation, you warrant that you have authority to bind that organisation.
1.4 Business customers: These Terms are intended for business-to-business use. If you are a consumer (individual acting outside your trade, business, or profession), some provisions may not apply and your statutory rights remain unaffected.
2. Services
2.1 We provide supplier due diligence reports, under the Hume brand, based on open-source intelligence (OSINT) from public registers, publicly available legal documents, and technical checks against domains you specify.
2.2 Packs (current):
| Pack | Summary |
|---|---|
| Standard (RT1) | Automated OSINT checks on entity legitimacy and access; raw evidence and scope assumptions |
| Commercial (RT2a) · PII (RT2b) · Critical (RT3) | Progressively deeper check suites. Packs are cumulative — each runs its own checks plus every check below it |
| Hume Watch (RT4) | Ongoing monitoring subscription (separate terms may apply) |
| Bespoke (RT5) | Scope quoted per engagement (e.g. insurer, regulator, or named client framework) |
Exact check lists, pricing, and deliverables are as stated on the order page and intake form at the time of order.
2.3 What Hume is not:
- legal advice, legal opinion, or regulatory approval;
- a certification, penetration test, or audit of the supplier’s systems;
- a guarantee of supplier fitness, security, or compliance;
- a substitute for your own risk assessment, due diligence, or procurement decisions.
2.4 Methodology: Findings and evidence states are determined by coded rules applied to evidence against documented criteria — not by generative AI. No AI is used to collect evidence, process it, or determine outcomes; the assessment is entirely deterministic.
3. Client responsibilities
3.1 Accurate information: You must provide accurate supplier legal name, Companies House number (where applicable), and primary domain. Wrong identifiers produce wrong evidence.
3.2 Authority and consents: You warrant that:
- (a) you are authorised to commission due diligence on the named supplier;
- (b) you have any internal approvals required by your organisation;
- (c) where you upload a redacted executed commercial agreement (PII pack and above), you have the right and consent of your organisation (and, where required, the supplier) to share the redacted document with us for gap analysis;
- (d) sharing the document with us does not breach confidentiality, data protection law, or the agreement itself.
3.3 Redaction: For uploads, you must redact personal data and commercially sensitive material not needed for our review (see Privacy Policy). Unredacted sensitive data sent in error should be reported immediately.
3.4 No prohibited use: You must not use the Service to unlawfully surveil individuals, discriminate, or circumvent sanctions or export controls.
3.5 Cooperation: We may contact you to confirm supplier identity or clarify intake. Delays in your response extend delivery times.
4. Third-party sources and reliance
4.1 Reports depend on third-party sources we do not control, including but not limited to: Companies House, UK government registers, ICO, UKVI, sanctions lists, accreditation bodies (e.g. UKAS / IAF CertSearch), supplier websites, and DNS/public internet infrastructure.
4.2 We do not warrant the accuracy, completeness, timeliness, or availability of third-party data. Registers may be outdated, incomplete, or temporarily unavailable. Automated checks may fail due to network, DNS, or site changes.
4.3 Certification verification: Public accreditation search tools (including UKAS CertCheck) can miss valid certificates. Our workflow may flag manual verification. Absence of a certificate in a public search is not proof that a supplier lacks certification.
4.4 Your decision: You are solely responsible for procurement, onboarding, and ongoing supplier management decisions. You must not rely on Hume as the sole basis for material decisions without independent verification where appropriate.
4.5 Nature of the findings. The results of a search are drawn from open-source intelligence and public and agency registers, the reliability, accuracy and availability of which are beyond our control. Accordingly, the findings: (a) do not constitute legal advice; (b) are not an assurance of the reliability or security of any supplier evaluated; and (c) should not, in themselves, be wholly relied upon for procurement sign-off. This confirmation is presented to, and accepted by, you at intake.
4.6 Source availability. Delivery is subject to the availability of the underlying public sources. Where a source is unavailable, we will make up to three (3) attempts to retrieve the data. If the source remains unavailable after three attempts, this is beyond our control: we will note it in the report and recommend you follow up that enquiry directly with the source. No refund, whether full or partial, is made where a source is unavailable after three attempts. Any turnaround time indicated (for example on our website) is an aim only, not a contractual commitment or guarantee.
4.7 Re-runs on upgrade. Where you upgrade a supplier to a higher tier, checks shared with a lower tier are re-run against current sources and may return results that differ from your earlier report. Each report reflects public evidence as at its own run date; a difference reflects a change in the underlying public record, not a change in our methodology.
5. Deliverables and acceptance
5.1 Deliverables typically include a PDF report and/or evidence pack (screenshots, source URLs, structured JSON). Format varies by tier.
5.2 Standard pack: Delivered by email or download link; not suitable for formal procurement sign-off unless you accept the stated scope limitations.
5.3 A report reflects the methodology applied and the evidence collected as at its run date. It is not a warranty or guarantee of the supplier's behaviour, security, or compliance.
5.4 Acceptance: Unless you notify us of a material non-conformance (report not matching the ordered tier, or evidence pack missing) within 10 business days of delivery, the deliverable is deemed accepted.
5.5 We may correct clerical errors in reports without charge.
6. Confidentiality and use restrictions
6.1 Our confidentiality: We treat your contact details, intake content, uploaded documents, and non-public deliverables as confidential, subject to Section 6.3 and legal requirements.
6.2 Your restrictions — reports and evidence: The report, evidence pack, and any underlying materials we provide are licensed to you for internal business use only. You must not, without our prior written consent:
- (a) publish, post, or disclose the report or any part of it to third parties, except:
- (i) your organisation’s employees and contractors with a need to know;
- (ii) contracted external auditors, regulators, insurers, or legal advisers engaged by you, under confidentiality obligations no less strict than this clause;
- (iii) disclosure required by law or court order (you must notify us beforehand where legally permitted);
- (b) share screenshots, JSON exports, or evidence files with the supplier under review in a way that enables them to game or rebut specific checks, except where your procurement process genuinely requires it;
- (c) resell, sublicense, or white-label the report;
- (d) use the report or our branding to imply Cahoot endorses the supplier.
6.3 Exceptions: We may use anonymised, aggregated statistics about check outcomes for service improvement and marketing. We do not name your organisation or suppliers in marketing without consent.
6.4 Public OSINT: Evidence sourced from public registers and public web pages remains publicly available from those sources independently of our report.
7. Intellectual property
7.1 Cahoot owns all IP in the Service, methodology, report templates, check definitions, and branding.
7.2 You receive a non-exclusive, non-transferable licence to use deliverables for internal purposes per Section 6.2.
7.3 You retain ownership of documents you upload. You grant us a licence to process uploads solely to deliver the Service.
8. Fees and payment
8.1 Prices are as displayed at checkout (typically Stripe), exclusive or inclusive of VAT as stated.
8.2 Vouchers: We may issue a promotional code (for example a first-run voucher) that discounts an order in full or in part; we reserve the right to withdraw voucher offers at any time. The product is otherwise always a paid product.
8.3 Payment is due before we begin the ordered work unless we agree otherwise in writing.
8.4 No refund once we have commenced check execution, except: (a) we cancel the order; (b) we materially fail to deliver the ordered pack; or (c) required by law. Where an order was placed under a voucher that discounted it in full, there is no fee to refund unless a paid checkout was used in error.
8.5 Late payment interest may apply per the Late Payment of Commercial Debts Act 1998 (B2B).
8.6 Upgrades. Tiers are cumulative. If you have paid for a lower tier on a supplier, you pay only the difference to upgrade to a higher tier, and the total payable to reach any tier is that tier's list price. Where a report recommends an upgrade, a time-limited discount may apply as stated in the report. If, on re-running, the evidence would place the supplier in a tier above the one you have purchased, we deliver the tier you paid for and identify the higher tier as a recommendation only; we do not automatically charge you for it.
9. Limitation of liability
9.1 Nothing in these Terms excludes or limits liability for: death or personal injury caused by negligence; fraud or fraudulent misrepresentation; or any liability that cannot be excluded under applicable law.
9.2 Subject to 9.1, our total aggregate liability arising from or in connection with an order (whether in contract, tort, negligence, or otherwise) is limited to the greater of: (a) ten (10) times the fees paid by you for that order; or (b) £50,000 — and in any event not exceeding £1,000,000 (the limit of our professional indemnity cover).
9.3 Subject to 9.1, we are not liable for:
- (a) indirect or consequential loss, including loss of profit, revenue, contract, goodwill, or data;
- (b) decisions you or third parties make based on the report;
- (c) errors, omissions, or unavailability of third-party sources (Section 4);
- (d) supplier conduct, breach, or security incidents;
- (e) delays caused by your failure to provide accurate intake or redacted documents.
9.4 You are responsible for maintaining your own backups of deliverables after download. Expired links are not our liability.
9.5 B2B: You agree that the limitations in this Section 9 are reasonable given the nature of the Service and fees charged.
10. Indemnity
10.1 You will indemnify and hold harmless Cahoot against claims, losses, and reasonable costs arising from:
- (a) your breach of these Terms;
- (b) your upload of documents without proper authority or consent;
- (c) your unlawful use of the report or disclosure in breach of Section 6;
- (d) inaccurate or misleading information you provide.
11. Data protection
11.1 Each party complies with UK GDPR and the Data Protection Act 2018.
11.2 Our Privacy Policy describes processing of client contact data.
11.3 Our data-protection roles. We are the controller of personal data about you and your personnel (for example names, roles, and business contact details, however it reaches us). We act as your processor under UK GDPR Article 28 for personal data about supplier personnel that we process to prepare your report — whether collected from public sources (OSINT) or contained in a redacted agreement you upload; you are the controller of that data, and our DPA applies where relevant. The Privacy Policy gives the detail.
12. Term and termination
12.1 These Terms apply from acceptance until fulfilment of the order. Hume Watch subscriptions continue until cancelled per subscription terms.
12.2 We may suspend or refuse service if you breach these Terms, abuse the Service, or pose a regulatory or reputational risk.
12.3 On termination, Sections 6, 7, 9, 10, and 14 survive.
13. Force majeure
We are not liable for failure or delay caused by events beyond reasonable control, including government register outages, internet failures, cyber incidents, industrial action, or pandemic restrictions.
14. General
14.1 Governing law: England and Wales.
14.2 Jurisdiction: Courts of England and Wales (we may also bring proceedings in your place of business).
14.3 Entire agreement: These Terms and order-specific details constitute the entire agreement. The Privacy Policy is an information notice, not a contractual term, and does not form part of this agreement; we may update it without varying these Terms.
14.4 Variation: We may update these Terms for future orders by posting a new version. Orders already accepted are governed by the version you accepted.
14.5 Severability: If any provision is invalid, the remainder continues in effect.
14.6 No waiver: Failure to enforce a provision is not a waiver.
14.7 Assignment: You may not assign without our consent. We may assign to a successor in business reorganisation.
14.8 Notices: cath@cahootconsulting.com (or post to registered office).
15. Contact
Cahoot Consulting Limited<br> 54 Frensham Close, Southall, Middlesex, UB1 2YG, United Kingdom<br> Company no. 08976555 (England and Wales)<br> ICO registration ZA705720<br> VAT no. GB 183 6201 17<br> Managing Director: Catherine Furlong<br> Email: cath@cahootconsulting.com<br> Tel: 07506 144029
Last updated: 28 July 2026
Document control
| Version | Date | Author | Notes |
|---|---|---|---|
| DRAFT v1 | 22 Jun 2026 | Cahoot / AI draft | Initial draft |
| DRAFT v1.1 | 22 Jun 2026 | Cahoot | Company details added |
| DRAFT v1.2 | 22 Jun 2026 | Cahoot | ICO registration ZA705720 |
| IN REVIEW v1.3 | 26 Jul 2026 | Cahoot / AI | D-057 upgrade terms: §4.7 re-run-on-upgrade, §8.6 pay-the-difference + tier-flip; solicitor-gate note updated to D-022 |
| IN REVIEW v1.4 | 26 Jul 2026 | Cahoot / AI | Dead-claim clearance + legal-posture pass: §2.2 pack ladder replaces T0/T1/T2 naming (D-018/D-034); §2.4 methodology → deterministic/no-AI, credential claim removed (D-029/D-052); §5.3 reports reviewed not signed (D-063); §4.6 same-day-aim, no-SLA rewrite (D-053); §3.2(c)/§5.2 pack-name alignment; §8.2/§8.4 "free T0"/"no charge" → voucher wording (D-035); §12.1 "T2" → Hume Watch; §9.2 cap raised to greater of 10× fees or £50k, ceilinged at £1m (D-062); §11.3 controller/processor roles set (D-064) |
| APPROVED v1.4 | 27 Jul 2026 | Cath | Promoted to APPROVED, effective 27 Jul 2026. All blockers closed (D-062/D-063/D-064); dead-claims gate green |
| APPROVED v1.5 | 28 Jul 2026 | Cahoot / AI | Closes D-029's owed items: §1.2 no longer has the Client agree to the Privacy Policy (it is an Art. 13 information notice, linked for information only); §14.3 entire-agreement clause no longer names the Privacy Policy and states it is not a contractual term and may be updated without varying these Terms. Substance approved under D-029; no boundary variable changed |
| APPROVED v1.6 | 1 Aug 2026 | Cahoot / AI | §2.1 "Hume provides" → "We provide, under the Hume brand" — fixes an inconsistency (every other obligation in the document is "we/us"; Hume names the service, not the contracting party, per this document's own §-header definitions). Provider line (document header) now states company number 08976555 and registered office up front, alongside the existing §15 Contact statement — same facts, better placement per UK contract-drafting practice. Authorised by Cath in session; no boundary variable changed |