HONE — TERMS OF SERVICE
(SaaS Subscription Agreement — Business Customers)
Provider: Virtual Data Integration Ltd (trading as "Hone"), a company registered in England and Wales with company number 16747738, whose registered office is at 22 Walbank Grove, Shenley Brook End, Milton Keynes, England, MK5 7WB.
Version 1.1 — effective on publication
What this means (plain-English summary — not part of the operative terms)
These Terms govern your business's use of Hone, our AI-powered recruitment platform. In short: Hone is for businesses only, not consumers. You pay per seat, plus optional metered usage ("Credits") only if you switch overage on — by default your workspace stops at its included limit so you are never billed a surprise. You own your candidate data; we only process it to run the Services and we do not use it to train AI models. Hone uses AI, and AI output can be wrong or incomplete — you must check it, especially for compliance-critical fields like professional registrations, right-to-work and DBS status. Data protection is governed by a separate Data Processing Agreement (DPA), which forms part of this contract. Our liability is limited, we provide the Services with reasonable skill and care, and English law applies. The operative terms below are what actually binds us both.
1. Definitions and interpretation
1.1 In these Terms:
"Acceptable Use Policy" or "AUP" means the restrictions in clause 13.
"Affiliate" means, in relation to a party, any entity that directly or indirectly controls, is controlled by, or is under common control with that party.
"Authorised User" means an individual (an employee, worker or contractor of the Customer) whom the Customer permits to use the Services under a seat, identified as an owner, admin or member.
"Credits" means the usage units consumed by AI-powered actions within the Services, as described in clause 6.
"Customer Data" means all data, including personal data, that the Customer or its Authorised Users upload to, or generate within, the Services, including candidate CVs and candidate records.
"Data Protection Laws" means the UK GDPR (as defined in section 3(10) of the Data Protection Act 2018), the Data Protection Act 2018, the Privacy and Electronic Communications (EC Directive) Regulations 2003, and all other applicable laws and regulatory guidance relating to the processing of personal data, in each case as amended or replaced.
"DPA" means the data processing agreement between the parties (UK GDPR Article 28), available at https://hone.detecktiv.io/legal/dpa, which is incorporated into and forms part of these Terms.
"Fees" means the subscription fees, and any opted-in overage charges, payable for the Services.
"Order Form" means any ordering document (including an Enterprise order form or online plan selection) that references these Terms.
"Plan" means the subscription tier selected by the Customer (Starter, Pro or Enterprise), as described in clause 6.
"Privacy Policy" means the Provider's privacy policy at https://hone.detecktiv.io/legal/privacy.
"Services" means the Hone software-as-a-service platform and related support made available by the Provider, as described in clause 3.
"Sub-processors Page" means the list of the Provider's sub-processors at https://hone.detecktiv.io/legal/sub-processors, which is the authoritative source for the current sub-processor list.
"Subscription Term" means the period for which the Customer has subscribed (monthly or annual), together with any renewals.
1.2 Clause headings do not affect interpretation. "Including", "includes" and "in particular" are illustrative and do not limit the words that precede them. References to legislation are to that legislation as amended, extended or re-enacted. "Writing" includes email and in-product electronic notices.
1.3 If there is a conflict, the following order of precedence applies: (a) an executed Order Form (for the specific matters it addresses); (b) the DPA (for data protection matters); (c) these Terms; (d) the Privacy Policy and any policies referenced in these Terms.
2. The agreement, acceptance and business-only use
2.1 Acceptance. These Terms form a binding contract between the Provider and the Customer when the Customer (through an individual acting on its behalf) clicks to accept them, creates a workspace, or otherwise uses the Services, whichever is earliest.
2.2 Authority. The individual accepting these Terms represents and warrants that they are authorised to bind the Customer organisation. If they do not have that authority, they must not accept these Terms or use the Services.
2.3 Business customers only. The Services are offered and licensed solely for the purposes of a trade, business, craft or profession. By accepting these Terms the Customer confirms that it is entering into this contract in the course of its business and not as a consumer. The Services are not intended for, offered to, or to be used by, individuals acting wholly or mainly outside their trade, business, craft or profession. The Provider may refuse or terminate access where it reasonably believes the Customer is acting as a consumer.
2.4 No consumer rights triggered. Because the Services are supplied on a business-to-business basis, the Consumer Rights Act 2015 and the Consumer Contracts (Information, Cancellation and Additional Charges) Regulations 2013 (including the 14-day cancellation right) do not apply to this contract. This clause does not affect any statutory right that cannot be excluded by law.
3. The Services
3.1 What Hone does. Hone is an AI-powered recruitment platform for recruitment agencies. Its core functions are:
(a) CV ingestion and AI parsing — Authorised Users upload candidate CVs (individually or in bulk, including optional import from the Authorised User's Google Drive), which the Services parse using AI into structured candidate records;
(b) natural-language candidate search — Authorised Users search the candidate pool in plain English, which the Services interpret using AI;
(c) shortlisting, outreach, compliance tracking and CRM — including tracking of professional registrations (for example NMC, GMC, HCPC), card schemes (for example CSCS), right-to-work status, and DBS / criminal-record and safeguarding status;
(d) isolated per-agency workspaces with role-based access (owner, admin, member), team collaboration, and per-workspace data isolation; and
(e) career-path and other AI features powered by third-party AI models.
3.2 Provision. The Provider grants the Customer a non-exclusive, non-transferable, non-sublicensable right for its Authorised Users to access and use the Services during the Subscription Term, solely for the Customer's internal business purposes and subject to these Terms.
3.3 Authorised Users and seats. The Customer is responsible for its Authorised Users' use of the Services and for their acts and omissions as if they were the Customer's own. The Customer must ensure each Authorised User keeps their credentials secure and enables multi-factor authentication where required. Seat entitlements are set by the Plan (clause 6).
3.4 Changes to the Services. The Provider may modify, add to or remove features of the Services from time to time, provided it does not materially degrade the core functionality of the Plan the Customer is paying for during a paid Subscription Term. The Provider will give reasonable notice of any material adverse change.
4. AI features and output — accuracy and Customer review
4.1 AI output is not guaranteed to be correct. Parts of the Services use artificial intelligence, including third-party AI models, to parse CVs, interpret searches and generate content. AI output can be incomplete, inaccurate, out of date or otherwise wrong. The Provider does not warrant the accuracy, completeness or fitness for any particular purpose of any AI output.
4.2 Customer must review before relying. The Customer and its Authorised Users must independently review and verify candidate records, search results and any other AI output before relying on them, and must not rely on AI output alone for compliance-critical decisions, including professional registration status, right-to-work, and DBS / criminal-record or safeguarding checks. The Customer remains responsible for its own recruitment, screening and compliance decisions.
4.3 Dependencies. AI features depend on the availability of third-party AI providers and on the Customer having sufficient Credits. The Provider is not liable for degradation or unavailability of AI features caused by a third-party AI provider or by exhaustion of the Customer's Credits.
5. Free trial
5.1 The Provider may offer a 14-day free trial of the Pro Plan, with no payment card required. Trials are provided on an "as is" basis and the warranty in clause 18.1 and any service commitments do not apply during a trial.
5.2 At the end of the trial the Services will stop unless the Customer selects and pays for a Plan. The Provider may withdraw or change trial terms at any time and may limit trials to one per organisation.
6. Plans, seats and Credits
6.1 Plans. The Services are offered on the following Plans. All prices are in pounds sterling (GBP) and are exclusive of VAT and other applicable taxes (see clause 7.5).
| Plan | Monthly | Annual (2 months free) | Seats | Included AI Credits |
|---|---|---|---|---|
| Starter | £79 / seat / month | £790 / seat / year | up to 5 seats | 2,500 Credits / seat / month |
| Pro | £149 / seat / month | £1,490 / seat / year | unlimited seats | 6,000 Credits / seat / month |
| Enterprise | custom (see Order Form) | custom | negotiated | 25,000 Credits / seat / month (negotiated) |
6.2 Credits. "Credits" are usage units consumed by AI-powered actions. Each AI action debits a cost-weighted number of Credits (for example, CV parsing, natural-language search and career-path generation each have their own Credit cost). Included Credits are allocated per seat per billing period and reset at the start of each billing period. Unused included Credits do not roll over unless stated in an Order Form.
6.3 Hard stop by default. By default, a workspace stops consuming AI actions once its included Credit allocation for the billing period is exhausted ("hard stop"). In that state, AI-powered actions are paused until Credits reset or the Customer adds capacity. Non-AI functions of the Services remain available. The Customer cannot incur overage charges unless it has explicitly enabled overage.
6.4 Optional overage. The Customer may, through the workspace settings, opt in to a metered overage budget. Where overage is enabled, AI actions beyond the included allocation are charged at £0.05 per Credit (excluding VAT), metered and billed in arrears (clause 7.2). The Customer may set and change its overage budget, and may switch overage off, through settings. No overage is charged for any period in which the Customer has not enabled overage.
7. Fees, billing, overage and taxes
7.1 Subscription Fees in advance. Subscription Fees are payable in advance for each Subscription Term (monthly or annual, as selected). Annual Plans are billed for the full year in advance.
7.2 Overage in arrears. Any opted-in overage (clause 6.4) is billed in arrears for the period in which it was incurred.
7.3 Payment processing (Stripe). Payments are processed by Stripe. The Customer authorises the Provider (via Stripe) to charge the Customer's designated payment method for all Fees, opted-in overage and applicable taxes as they fall due. The Customer must keep its payment details current.
7.4 Non-payment. If a payment fails or is overdue, the Provider may, after a reasonable grace period and (where practicable) notice:
(a) place the workspace in a read-only / limited state; and
(b) if the amount remains unpaid, suspend and then terminate the Services.
The Customer's data-export rights in clause 11 survive a read-only state and termination for non-payment (subject to those clauses). The Provider reserves the right to charge interest on overdue sums under the Late Payment of Commercial Debts (Interest) Act 1998.
7.5 VAT and taxes. All prices are exclusive of VAT and any other applicable taxes. The Provider is registered for VAT under number 513 1589 07, and VAT will be added to the Fees at the prevailing rate and shown on invoices. The Customer is responsible for any other taxes, duties or withholdings arising from its purchase, other than taxes on the Provider's income.
7.6 Fee changes. The Provider may change its Fees. Changes take effect from the Customer's next renewal, and the Provider will give reasonable prior notice before the renewal to which they apply. Continuing to use the Services after a change takes effect constitutes acceptance of the revised Fees.
7.7 No refunds. Except where required by law, Fees are non-refundable and there is no refund or credit for partial periods, unused Credits, or seats deactivated mid-term.
8. Term, renewal and cancellation
8.1 Term. These Terms take effect on acceptance (clause 2.1) and continue until all of the Customer's subscriptions have ended or the contract is terminated in accordance with clause 9.
8.2 Renewal. Each Subscription Term renews automatically for a further period of the same length (monthly or annual) at the then-current Fees, unless the Customer cancels before the end of the current Subscription Term or an Order Form states otherwise.
8.3 Cancellation by the Customer. The Customer may cancel its subscription at any time through the Services or by notice. Cancellation takes effect at the end of the then-current Subscription Term. Access continues until then, and no pro-rata refund is given for the remainder of the term, except where required by law.
9. Suspension, termination and insolvency
9.1 Termination for material breach. Either party may terminate these Terms (or the affected subscription) with immediate effect by written notice if the other party is in material breach and, where the breach is capable of remedy, fails to remedy it within 30 days of written notice specifying the breach.
9.2 Termination for insolvency. Either party may terminate these Terms immediately by written notice if the other party becomes insolvent, is unable to pay its debts as they fall due, enters administration, has a receiver or administrative receiver appointed, passes a resolution for winding-up (other than a solvent reorganisation), or suffers any analogous event in any jurisdiction.
9.3 Suspension. The Provider may suspend all or part of the Services, acting proportionately and (where practicable) with prior notice, to address:
(a) a material or urgent breach of these Terms (including the AUP);
(b) a security, integrity or legal risk to the Services, the Provider or other customers; or
(c) non-payment (clause 7.4).
The Provider will restore access promptly once the cause of suspension is resolved. Suspension does not relieve the Customer of its payment obligations for the Services other than to the extent the suspension results from the Provider's own default.
10. Effect of termination and data export
10.1 Access ends. On termination or expiry, the Customer's and its Authorised Users' right to access and use the Services ends.
10.2 Export window. For 30 days after termination or expiry, the Customer may export its Customer Data using the in-product tools, which include: (a) self-service structured export; (b) per-data-subject Subject Access packages, including the underlying CV documents; and (c) a workspace deletion path with a 30-day recovery window followed by permanent erasure.
10.3 Deletion. After the 30-day export window, the Provider will delete Customer Data in accordance with the DPA, subject to any retention required by law and to routine backup cycles from which data is overwritten in the ordinary course.
10.4 Survival. Clauses that by their nature should survive termination (including clauses 1, 4, 7 (for accrued sums), 10, 14, 16, 17, 18, 20, 21 and 24–27) survive.
11. Customer Data — ownership and licence
11.1 Customer owns its data. As between the parties, the Customer owns all right, title and interest in the Customer Data (including candidate CVs and records). The Provider claims no ownership of Customer Data.
11.2 Licence to the Provider. The Customer grants the Provider a non-exclusive, worldwide, royalty-free licence to host, store, copy, process and transmit the Customer Data solely to the extent necessary to provide, support, secure and maintain the Services, and to do so in accordance with the Customer's instructions and the DPA.
11.3 Customer responsibility for its data. The Customer is responsible for the accuracy, quality and legality of the Customer Data and for its right to upload and process it through the Services.
12. Data protection
12.1 Roles. In processing personal data within the Customer Data, the Provider acts as a processor and the Customer acts as the controller. The DPA (UK GDPR Article 28) governs the detail of that processing and is incorporated into these Terms by reference.
12.2 Nature of the data. The Customer acknowledges that the Customer Data is likely to include special category data (UK GDPR Article 9 — for example health information contained in free-text CVs) and criminal offence data (UK GDPR Article 10 / DBS, criminal-record and safeguarding information), alongside identity and contact details, employment and education history, professional registrations and right-to-work information.
12.3 Customer responsibilities as controller. The Customer is responsible for:
(a) establishing and maintaining a lawful basis for its processing (candidate data is typically processed on the basis of legitimate interests; the Customer runs its own legitimate interests assessment and handles data-subject objections), and, for special category and criminal offence data, identifying an appropriate Article 9 / Article 10 condition and the associated Data Protection Act 2018 Schedule 1 condition;
(b) putting in place any Appropriate Policy Document required under Schedule 1 to the Data Protection Act 2018 where it relies on a condition that requires one (this is likely to apply to the processing of criminal offence and safeguarding data, particularly in the education vertical);
(c) providing the required privacy information to candidates and other data subjects; and
(d) ensuring its instructions to the Provider comply with Data Protection Laws.
12.4 No AI training on Customer Data. The Provider does not use Customer Data to train its own or any third party's AI models. Third-party AI providers process Customer Data only to return results for the Customer's requests, and subject to the Provider's contractual controls with those providers.
12.5 Sub-processors. The Provider uses sub-processors to provide the Services under a general written authorisation. The current sub-processors, at the date of these Terms, include Lovable (application hosting), Supabase (database, storage and authentication), Cloudflare (CDN, edge and WAF), Anthropic and Voyage AI (AI processing), Google (Drive/Gmail/Calendar), Stripe (billing), Twilio (SMS to candidates), Sentry (error monitoring), PostHog and Plausible (analytics) and Resend (email). We do not use OpenAI. The authoritative and current list is the Sub-processors Page and DPA Annex 3. International transfers, where they occur, are protected by the UK International Data Transfer Agreement (IDTA) or the EU Standard Contractual Clauses together with the UK Addendum.
12.6 Personal data breach notification. The Provider will notify the Customer without undue delay, and in any event within 48 hours, of becoming aware of a personal data breach affecting the Customer Data, in accordance with the DPA.
13. Security
13.1 The Provider maintains appropriate technical and organisational measures to protect the Customer Data, detailed in DPA Annex 2. These include: row-level security and per-workspace tenancy isolation; least-privilege access controls; multi-factor authentication (available and enforceable); encryption in transit (TLS) and at rest; storage of secrets in a secrets manager (never in source code); Cloudflare edge protection with WAF and bot mitigation; a per-workspace AI kill-switch and usage/spend ceilings; routing of AI provider calls through a single audited control point; an append-only audit-event log (covering access, export, deletion and role changes); managed PostgreSQL with automated backups; and dependency and secret scanning in the CI pipeline.
13.2 The Customer is responsible for security within its control, including managing its Authorised Users, credentials and roles, and enabling multi-factor authentication.
14. Acceptable Use Policy
14.1 The Customer must not, and must ensure its Authorised Users do not:
(a) upload or process data that it has no lawful basis or right to process;
(b) upload malware, or attempt to breach, disable or circumvent the security of the Services, the tenancy isolation, or to access another customer's data;
(c) reverse-engineer, decompile, scrape, resell, or use the Services to build or benefit a competing product or service;
(d) use the Services for any unlawful, fraudulent, discriminatory or harmful recruitment practice, or to send unlawful communications (including unlawful direct marketing under the Privacy and Electronic Communications (EC Directive) Regulations 2003);
(e) exceed documented rate or usage limits, or circumvent, tamper with or falsify the Credit metering; or
(f) use the Services other than for the Customer's internal business purposes as permitted by these Terms.
14.2 The Provider may suspend access under clause 9.3 to address a material or urgent breach of this AUP, acting proportionately.
15. Intellectual property
15.1 Provider IP. The Provider and its licensors own all intellectual property rights in the Services, the underlying software, and all related materials, including any improvements, and all rights not expressly granted to the Customer are reserved. Nothing in these Terms transfers any Provider intellectual property to the Customer.
15.2 Feedback. If the Customer or its Authorised Users provide feedback or suggestions, the Provider may use them freely to improve the Services, without obligation or attribution.
16. Confidentiality
16.1 Each party ("Recipient") must keep confidential all non-public information disclosed by the other ("Discloser") that is marked or ought reasonably to be understood as confidential, and use it only to perform or exercise its rights under these Terms.
16.2 Clause 16.1 does not apply to information that is or becomes public without breach, was lawfully known before disclosure, is independently developed, or is lawfully received from a third party without restriction. A Recipient may disclose confidential information to the extent required by law or a regulator, giving prior notice where lawful to do so.
16.3 Customer Data is the Customer's confidential information and is additionally governed by clauses 11 and 12 and the DPA.
17. Customer indemnity
17.1 The Customer will indemnify the Provider against all losses, damages, liabilities, reasonable costs and expenses arising out of any third-party claim (including any claim, investigation or enforcement action by a data subject or a regulator such as the ICO) to the extent caused by:
(a) the Customer's or its Authorised Users' breach of the AUP (clause 14);
(b) the Customer's lack of a lawful basis or right to upload or process the Customer Data; or
(c) the Customer's breach of its obligations as controller under clause 12 or the DPA.
17.2 This indemnity is subject to the Provider promptly notifying the Customer of the claim, not admitting liability without consent (not to be unreasonably withheld), and giving the Customer reasonable control of the defence and reasonable assistance at the Customer's cost.
18. Warranties and disclaimers
18.1 Provider warranty. The Provider warrants that it will provide the Services with reasonable skill and care.
18.2 Disclaimer. Except as expressly stated in clause 18.1, and to the fullest extent permitted by law, the Services are provided "as is" and the Provider excludes all other warranties, conditions and terms, whether express or implied by statute, common law or otherwise, including any implied warranty of satisfactory quality or fitness for a particular purpose, and any warranty that the Services or any AI output will be uninterrupted, error-free, complete, accurate or fit for the Customer's purposes.
18.3 Non-excludable rights. Nothing in these Terms excludes or limits any liability or right that cannot lawfully be excluded or limited, and nothing affects any statutory right or protection that applies notwithstanding clause 2.4.
19. Availability and support
19.1 Availability. The Provider will use commercially reasonable efforts to make the Services available, but does not guarantee any level of uptime and gives no service credits on self-service Plans. Availability may be affected by planned maintenance, emergency maintenance, and factors outside the Provider's control, including third-party and AI-provider outages. The Provider will endeavour to schedule planned maintenance to minimise disruption. Any committed service level (SLA) applies only if expressly set out in an Order Form.
19.2 Support. The Provider will provide support using commercially reasonable efforts via support@detecktiv.io.
20. Limitation of liability
20.1 Liabilities not excluded. Nothing in these Terms limits or excludes either party's liability for: (a) death or personal injury caused by negligence; (b) fraud or fraudulent misrepresentation; (c) the Customer's payment obligations; (d) the Customer's liability under the indemnity in clause 17; or (e) any other liability that cannot be limited or excluded by law.
20.2 Excluded losses. Subject to clause 20.1, neither party is liable, whether in contract, tort (including negligence), breach of statutory duty or otherwise, for any: loss of profit, revenue, business, anticipated savings or goodwill; loss or corruption of data (beyond the Provider's obligations under clause 12 and the DPA); or any indirect or consequential loss.
20.3 Aggregate cap. Subject to clauses 20.1 and 20.2, each party's total aggregate liability arising out of or in connection with these Terms in any 12-month period is limited to the greater of (a) £50,000 or (b) the total Fees paid or payable by the Customer under these Terms in the 12 months immediately before the event giving rise to the liability.
20.4 Data-protection liability. For clarity, liability for breach of the DPA or Data Protection Laws is subject to the cap in clause 20.3, except to the extent clause 20.1 applies or the DPA expressly provides otherwise.
20.5 Reasonableness. The parties agree that the allocation of risk in this clause 20 is reasonable given the nature of the Services and the Fees, and reflects the availability to each party of its own insurance.
21. Changes to these Terms
21.1 The Provider may update these Terms from time to time. The Provider will give reasonable notice of changes. Material changes take effect at the Customer's next renewal; non-material changes (for example, clarifications or changes required by law) may take effect earlier on notice. Continued use of the Services after a change takes effect constitutes acceptance of the updated Terms.
22. Force majeure
22.1 Neither party is liable for any delay or failure to perform (other than a payment obligation) caused by an event beyond its reasonable control, including acts of God, war, terrorism, epidemic, failure of utilities or telecommunications, and failure or outage of a third-party provider (including AI providers and hosting providers). The affected party will notify the other and use reasonable efforts to mitigate.
23. Notices
23.1 Notices to the Provider must be sent to privacy@detecktiv.io. Notices to the Customer may be given through the Services or to the Customer's account/admin email address. Notices are deemed received when sent, if during business hours, and otherwise at 9am on the next business day. This clause does not apply to the service of documents in legal proceedings.
24. General
24.1 Assignment. The Customer may not assign, transfer or sub-contract any of its rights or obligations without the Provider's prior written consent. The Provider may assign or transfer these Terms to an Affiliate or in connection with a merger, reorganisation or sale of all or substantially all of its business or assets, on notice to the Customer. The Provider may use sub-processors and sub-contractors in accordance with clause 12.5 and the DPA.
24.2 Entire agreement. These Terms, together with the DPA, the Privacy Policy and any Order Form, constitute the entire agreement between the parties and supersede all prior terms, drafts and understandings relating to their subject matter, including any earlier version of the Hone terms of service. Each party confirms it has not relied on any statement or representation not set out in these Terms, but nothing limits liability for fraud.
24.3 Severability. If any provision is held to be invalid or unenforceable, it is severed to the minimum extent necessary and the remaining provisions continue in force.
24.4 Waiver. No failure or delay in exercising a right is a waiver of it, and no single or partial exercise prevents further exercise.
24.5 No partnership or agency. Nothing in these Terms creates a partnership, joint venture, agency or employment relationship between the parties.
24.6 Third parties. Except as expressly stated, a person who is not a party to these Terms has no rights under the Contracts (Rights of Third Parties) Act 1999 to enforce any of its terms.
24.7 No solicitation of a competing product. For the avoidance of doubt, the licence in clause 3.2 is limited to the Customer's internal business use and does not permit any use described in clause 14.1(c).
25. Governing law and jurisdiction
25.1 These Terms, and any dispute or claim (including non-contractual disputes or claims) arising out of or in connection with them or their subject matter, are governed by and construed in accordance with the law of England and Wales.
25.2 The parties irrevocably submit to the exclusive jurisdiction of the courts of England and Wales.
Virtual Data Integration Ltd trading as Hone. Company number 16747738. Registered office: 22 Walbank Grove, Shenley Brook End, Milton Keynes, England, MK5 7WB.