Scan Terms and Conditions of Use

Version: v1.0 - 21/12/2025

Publisher: Click&Mortar, SAS with capital of 1,750 euros, RCS Paris B 810 921 619, 105-109 rue du Faubourg Saint-Honore, 75008 Paris, France, [email protected], +33 1 85 45 04 42 (hereinafter "Purple Scan")

User: any legal entity or natural person acting for professional purposes (hereinafter "the User").

1. Purpose - Mandatory Acceptance Before Scan

These terms govern access to and use of the Purple Scan service enabling the execution of technical analyses (including SEO, security, compliance, performance) of a website using automated tools (hereinafter the "Service").

Prior acceptance: before launching a scan, the User must expressly accept these Scan Terms (checkbox + timestamp + proof retention). Otherwise, no scan can be executed.

2. Definitions

3. Eligibility - Professional Use Only

The Service is intended for professionals. The User declares to be acting for purposes within the scope of their professional activity. Purple Scan may refuse access or suspend a scan in case of doubt about the User's status or authorization.

4. Audit Authorization and Mandate (Essential Condition)

4.1 Authorization Declaration

The User warrants:

4.2 Mandate

The User expressly mandates Purple Scan to access, browse and analyze the Target on their behalf, within the scope defined in section 5.

4.3 Proof of Authorization / Proof of Control

Purple Scan may at any time require proof of authorization (written mandate) and/or proof of control (DNS TXT, /.well-known/... file, meta tag, or any equivalent method). Failing provision within a reasonable time, Purple Scan may refuse, interrupt or suspend the Scan and/or the Account, without compensation.

5. Scan Scope - Technical Security Rules

5.1 Authorized Scope

Unless explicitly agreed otherwise, the Scan is limited to:

Purple Scan implements controls aimed at preventing scope deviation (e.g. DNS/IP validation, network restrictions, private IP blocking, redirect controls, etc.). The User acknowledges that these controls may result in blocks or partial results.

5.2 Credentials / Authenticated Areas

If the User provides credentials (test account) to scan an authenticated area:

5.3 Limits and Quotas

To prevent any negative impact (slowdown/unavailability), Purple Scan applies limits (e.g. rate, depth, page budget, maximum duration). These parameters may vary according to the plan and may be adjusted for security reasons.

5.4 Compliance with Exclusion Instructions

By default, Purple Scan may take into account certain conventions (e.g. robots.txt) depending on the Service configuration. The User understands that:

6. Prohibited Uses (AUP)

It is strictly prohibited to use the Service to:

In case of suspected abuse, Purple Scan may immediately interrupt the Scan, suspend the Account and retain the elements necessary for security/traceability.

7. Reports, Collected Data, Intellectual Property

7.1 Ownership / Rights

7.2 License of Use

Purple Scan grants the User a non-exclusive, non-transferable license, for the duration of the contract, to view and use the Reports for internal purposes.

7.3 Retention / Deletion

Retention periods for Collected Data and Reports are:

The User may delete certain Reports according to Service features. Purple Scan may retain minimal proof elements (timestamp, scope, technical logs) for security, compliance and billing purposes, to the extent necessary.

8. Data Protection (GDPR) - Role Distribution

8.1 "Account" Data

For data relating to the Account (account creation, billing, support), Purple Scan acts as data controller.

8.2 Data Present in the Target / in Reports

To the extent that Collected Data may contain personal data (e.g. displayed emails, names, page content), the User declares to have a legal basis for requesting the analysis and, where applicable, to have informed the data subjects in accordance with GDPR.

Qualification (by default): Purple Scan acts as a processor of the User for the processing of Collected Data carried out at the request and on behalf of the User, and commits to:

Applicable details (nature/purposes, data categories, security measures, subprocessors) may be specified in a "Processing Agreement" / DPA annex made available by Purple Scan and deemed accepted with these terms.

9. Illegal Content - Notification / Removal

The Service may store, at the User's request and/or during a Scan, technical copies (captures, source code, excerpts) that may include third-party content.

Purple Scan:

10. Best Efforts Obligation - No Guarantee of Results

The Service is provided "as is". Purple Scan is bound by a best efforts obligation, and does not guarantee:

Reports do not replace a complete human audit or the User's continuous security controls.

11. Liability - Limitations

11.1 Principle

Purple Scan shall not be held liable for indirect damages (loss of revenue, loss of opportunity, damage to reputation, data loss, etc.) resulting from use of the Service.

11.2 Cap

Unless mandatory legal provisions provide otherwise, Purple Scan's total liability for one (1) Scan or subscription is capped at the amount excluding tax paid by the User to Purple Scan over the twelve (12) months preceding the triggering event, or 500 euros, whichever is lower.

11.3 Legal Exclusions

No limitation applies in case of gross negligence/willful misconduct, nor for liabilities that cannot be excluded by law.

12. Indemnification (Defense and Guarantee)

The User is solely responsible for Targets submitted to the Service and for the legitimacy of audit authorization.

The User agrees to defend, indemnify and hold harmless Purple Scan (officers, employees, contractors) from any claim, action, conviction, costs (including attorney fees) resulting notably from:

Purple Scan will notify the User of any claim and will cooperate reasonably; the User may not settle without Purple Scan's prior written consent if the settlement imposes an obligation on Purple Scan (publication of apologies, acknowledgment of liability, injunction, etc.).

13. Suspension - Termination

Purple Scan may immediately suspend access to the Service, interrupt a Scan or terminate the contract in case of:

14. Confidentiality

Each party agrees to keep confidential non-public information exchanged in connection with the Service (including Reports), for 2 years after termination of the contract, unless legally required.

15. Applicable Law - Dispute Resolution

These Scan Terms are governed by French law, subject to mandatory public order rules and directly applicable European regulations.

Any dispute relating to their validity, interpretation or performance shall be subject to the exclusive jurisdiction of the courts of Paris, including in case of multiple defendants or third-party claims.

16. Contact - Reports

Support: [email protected]

Manifestly illegal content report: [email protected]

Security (vulnerability report): [email protected]

See also our Privacy Policy for information on how we collect and process your personal data.