Terms and
conditions.

The terms on which we provide ArdaForm to businesses. Version 1.0, effective 8 October 2026.

§
Who we are ArdaForm is a trading name of Tominko Ltd, a private limited company registered in England and Wales under company number 12089741. Registered office: 23 Bilston Street, Dudley, England, DY3 1JA. You can reach us through the contact form.

1. About these terms

1.1 These terms form a contract between Tominko Ltd ("we", "us", "our") and the business that opens or uses an ArdaForm account ("you", the "Customer"). They apply to every part of the platform we make available: the portal at portal.ardaform.net, the device control plane, the HTTP API at api.ardaform.net, the ArdaPlayer runtime, device images and installers, downloads, documentation, and any related support (together, the "Services").

1.2 You accept these terms when you create an account, accept an invitation, or use the Services, whichever happens first. If you accept them on behalf of an organisation, you confirm that you have authority to bind it.

1.3 The Services are for business use only. By accepting these terms you confirm you are acting in the course of a trade, business, craft or profession and not as a consumer. We do not contract with consumers.

1.4 If we have signed a separate written agreement or order form with you, that document takes priority over these terms where the two conflict. Nothing else — including terms on your purchase orders, invoices or website — forms part of our contract, even if we do not object to it.

2. Definitions

  • Account — your tenant on the portal, including its projects, branches, devices, users and settings.
  • Application — the HTML, CSS, JavaScript, assets and manifest you supply for us to package and deliver to Devices, from any source including a connected Git repository.
  • Customer Data — any data you, your users, your Applications or your Devices submit to or through the Services, including datasets, records, files, settings, logs and webhook payloads.
  • Device — any hardware on which the ArdaPlayer runtime is installed and enrolled to your Account.
  • End User — any person who interacts with a Device or with an Application, including your staff, customers and members of the public.
  • Package — the plan and limits that apply to your Account (for example, numbers of devices, projects, users, storage and API access), as shown in the portal or agreed with us in writing.
  • Preview Feature — any part of the Services labelled In progress, Planned, preview, beta or early access, or any feature that is not described as Working.

3. The Services and early access

3.1 We will provide the Services with reasonable skill and care, in accordance with the description of them in the portal and on this site as it stands at the time.

3.2 The platform is in active development. We publish what is working, in progress and planned on our roadmap. Preview Features are provided "as is", may be incomplete or contain errors, may change or be withdrawn at any time without notice, and are excluded from any commitment in these terms about availability or performance. Do not rely on a Preview Feature for anything where its failure would cause you loss.

3.3 We may change, improve, replace or discontinue any part of the Services. If a change materially reduces the functionality of a feature you are paying for and that is not a Preview Feature, we will give you at least 30 days' notice where reasonably possible, and you may cancel under clause 9.4 and we will refund the fees you have paid in advance for the period after the change takes effect.

3.4 Unless we have expressly agreed a service level with you in writing, we do not guarantee that the Services will be available at any particular time, uninterrupted or error-free. We may suspend the Services for maintenance, upgrades or emergency work, and will try to keep planned interruptions short.

3.5 The Services rely on third-party infrastructure including hosting providers, Cloudflare (network protection and object storage) and, where you connect it, GitHub. We are not responsible for failures or changes of those third parties that are outside our reasonable control.

4. Your account

4.1 You must provide accurate information when you register and keep it up to date.

4.2 You are responsible for everything done through your Account, including by your users, by anyone using an API key, webhook key or device installation code issued to your Account, and by your Devices. Keep passwords, API keys and codes secret, give access only to people who need it, and remove access promptly when it is no longer needed.

4.3 Tell us without delay through the contact form if you suspect any unauthorised access to your Account, an API key or a Device. Revoking a compromised key or removing a compromised Device in the portal is your responsibility and should be done immediately.

5. Devices, remote actions and hardware

5.1 You choose and are responsible for your hardware. Unless we have agreed in writing to supply hardware, we do not supply, warrant or support any Device, display, peripheral, network or power supply. Device images and installers are provided for the hardware we describe as supported; using them on anything else is at your own risk.

5.2 Installing a device image or running the installer erases the target storage. You are responsible for confirming the correct target and for backing up anything on it first.

5.3 Actions taken through the Services — including deploying an Application, applying settings, rebooting, shutting down, running console commands, taking screenshots, changing log levels, and removing or wiping a Device — are taken on your instructions. A wipe is irreversible: it removes the Device's enrolment and local data, and we cannot recover it. Where the Services make a best effort to deliver data from a Device before a wipe, that is not a guarantee that all data will be delivered.

5.4 You are responsible for having the right to install the runtime on and remotely manage each Device you enrol, including any consent required from the Device's owner, from End Users or from employees, and for any notices required where a Device captures screenshots, logs, location or other information.

5.5 Device location shown in the portal is an approximation derived from network information and may be wrong. Do not rely on it to locate a Device.

6. Prohibited and high-risk uses

6.1 The Services are not designed, tested or certified for high-risk use, and you must not use them where failure, delay or error could lead to death, personal injury, serious physical or environmental damage — including medical devices or patient care, life support, emergency services, vehicle, aircraft or rail control, industrial safety or interlock systems, fire or security alarm systems, or control of hazardous processes. If you do, you do so entirely at your own risk and clause 11 applies in full.

6.2 We are not a payment processor, payment service provider or financial institution. If an Application takes payments, you are solely responsible for the payment arrangements and for compliance with any applicable standard, including PCI DSS. Do not use Customer Data fields, settings, logs or webhooks to store or transmit full card numbers, card security codes or authentication credentials of End Users.

6.3 You must not, and must not let anyone else:

  • use the Services for anything unlawful, fraudulent, harmful, or in breach of anyone else's rights, or to distribute malware or unlawful content;
  • use the Services to collect or process personal data without a lawful basis, or to carry out covert surveillance of any person;
  • attempt to access accounts, devices or data that are not yours, or test, probe or circumvent the security of the Services, without our prior written permission;
  • interfere with or place unreasonable load on the Services, including by excessive API, webhook or connection traffic;
  • use webhooks or any outbound feature to send unsolicited messages or to attack, scan or overload any third-party system;
  • copy, modify, decompile, reverse engineer or create derivative works of the Services, the runtime or the package format, except to the extent the law expressly allows despite this restriction;
  • resell, sublicense, rent or provide the Services to third parties as a service in their own right, except as part of your own product or service delivered on Devices you manage, or as we otherwise agree in writing;
  • use the Services in breach of UK or other applicable export control or sanctions laws, or for the benefit of any sanctioned person or territory; or
  • use the Services to build a competing product, or benchmark them for publication, without our prior written consent.

7. Your Applications and Customer Data

7.1 You own your Applications and Customer Data. You grant us a worldwide, non-exclusive, royalty-free licence for the duration of the contract (and for any period afterwards set out in clause 15) to host, copy, store, transmit, package, encrypt, sign, process and display them, solely as needed to provide, secure and support the Services and to comply with the law.

7.2 You are solely responsible for your Applications and Customer Data: their content, accuracy, quality, legality and security; their behaviour on Devices; and the rights you need in them. We do not review, test or approve Applications. The signature we apply when packaging an Application shows that it was packaged by our platform; it does not mean we have checked, endorsed or accept responsibility for its content or behaviour.

7.3 We never run code from your repositories on our infrastructure — we package files only. Anything that needs building must be built by you before it reaches the Services.

7.4 You are responsible for anything a connected source (such as a GitHub repository or branch) delivers. A change pushed to a connected branch may be deployed to every Device on the corresponding branch automatically and within seconds. You are responsible for your own review and release controls before code reaches a connected branch.

7.5 Keep your own backups. The Services are not a backup or archive service. We take reasonable steps to protect stored data, but you must keep your own copies of your Applications and of any Customer Data you cannot afford to lose.

7.6 Where you configure a webhook, you direct us to send the data concerned to the destination you specify. You are responsible for that destination, for the security of any key you supply to it, and for the lawfulness of sending that data there. We store webhook signing keys so the platform can use them; you must not reuse a key that protects anything else.

7.7 We may remove or disable access to any Application or Customer Data if we reasonably believe it breaches these terms or the law, or if we are required to by law or a competent authority. We will tell you when we do unless we are prevented from doing so.

8. Data protection

8.1 Each of us will comply with the data protection law that applies to it, including the UK GDPR and the Data Protection Act 2018 ("Data Protection Law").

8.2 For personal data contained in Customer Data, you are the controller and we are your processor. You are responsible for having a lawful basis for that processing, for giving End Users any notices they are entitled to, and for answering their requests. Schedule 1 sets out the terms on which we process that data on your behalf.

8.3 We are a controller of the personal data we collect to run our relationship with you, such as account holders' names, sign-in information and billing details, and of security and operational logs about use of the Services. Our privacy notice describes that processing.

9. Fees, payment and renewal

9.1 Subscriptions. Paid Packages are sold as subscriptions, charged in advance for the billing period you choose when you order (for example, monthly or annually), at the price shown in the portal when you order. Prices are in pounds sterling and exclude VAT and other applicable taxes, which are added where they apply.

9.2 Payment on order. You pay for the first billing period by card, or another method we offer, when you place the order. Payments are taken by our payment provider, Stripe. Your paid Package is activated once the payment succeeds. We do not receive or store your full card details.

9.3 Automatic renewal. Your subscription renews automatically at the end of each billing period for another period of the same length, at the price then in force. By ordering, you authorise us, through our payment provider, to charge the payment method on file on each renewal date without asking you again, until you cancel. You are responsible for keeping that payment method valid and up to date.

9.4 Cancelling. You may cancel at any time in the portal. Cancelling stops future renewals and takes effect at the end of the billing period you have already paid for. Your paid Package stays available until then. When it ends, your Account moves to the free package we offer at that time, if there is one; if there is not, clause 15 applies. Where your use is above the limits of the package you move to, the Services may restrict or refuse what is over those limits.

9.5 Failed payments. If a renewal payment fails, our payment provider will retry it automatically during a retry period of up to 14 days, and we may ask you to update your payment details. The Services continue during the retry period. If no payment has succeeded by the end of the retry period, your subscription is cancelled and clause 9.4 applies from that date, as if you had cancelled it yourself. Any amount that remains owed is still payable.

9.6 Upgrades and downgrades. An upgrade takes effect immediately, and you will be charged straight away a pro-rated amount for the rest of the current billing period. A downgrade takes effect from your next renewal date; there is no refund or credit for the current period.

9.7 Price changes. We may change our prices on at least 30 days' notice. A new price applies from your first renewal after the notice period ends. If you do not accept it, cancel before that renewal.

9.8 Refunds. Payments are non-refundable, including for partial billing periods, cancellations and unused allowances, except where these terms say otherwise or where the law requires a refund. If you dispute a valid charge with your card issuer instead of contacting us first, we may suspend your Account under clause 13 until the dispute is resolved.

9.9 Receipts. A receipt or VAT invoice for each payment is issued electronically through our payment provider.

9.10 Use beyond your Package limits may be refused by the Services. Where we have agreed charges for additional use, you will pay them.

9.11 During any period in which we provide the Services to you free of charge, including early access or a free package, we may change or end that arrangement at any time, and clause 11.5 applies.

9.12 Your payment provider's own terms apply to its processing of your payments. We are not responsible for its acts or omissions, including a payment it declines.

10. Intellectual property

10.1 We and our licensors own all intellectual property rights in the Services, including the portal, control plane, API, the ArdaPlayer runtime, device images, the package format, documentation and the ArdaForm name and logo. Except for the rights expressly granted in these terms, no rights are transferred to you.

10.2 While your Account is active and you are complying with these terms, we grant you a non-exclusive, non-transferable, revocable licence to install and use the ArdaPlayer runtime, device images and other software we make available for download, in object-code form only, on Devices enrolled to your Account, solely to use the Services. The licence ends automatically when your Account ends.

10.3 Some components of the Services are open-source software licensed under their own terms. Those terms apply to those components, and nothing in these terms restricts rights you have under them.

10.4 If you give us feedback or suggestions, we may use them freely without obligation to you.

11. Liability — please read this carefully

11.1 Nothing in these terms limits or excludes liability for death or personal injury caused by negligence, for fraud or fraudulent misrepresentation, for breach of the terms implied by section 2 of the Supply of Goods and Services Act 1982, for your obligation to pay fees, for your liability under clause 12, or for any other liability that cannot be limited or excluded by law.

11.2 Subject to clause 11.1, we will not be liable to you, whether in contract, tort (including negligence), breach of statutory duty, misrepresentation or otherwise, for any:

  • loss of profits, revenue, sales or business;
  • loss of anticipated savings;
  • loss of, damage to or corruption of data, software or Applications;
  • loss of goodwill or reputation;
  • business interruption, downtime of Devices, or wasted management or staff time;
  • costs of procuring substitute services, hardware, site visits or engineers; or
  • indirect, special or consequential loss of any kind,

in each case whether or not foreseeable and whether or not we were told it might happen.

11.3 Subject to clauses 11.1 and 11.2, our total aggregate liability arising out of or in connection with these terms and the Services, in each contract year, will not exceed the greater of (a) the total fees you paid to us in respect of the Services in the 12 months immediately before the event giving rise to the claim, and (b) £100.

11.4 Subject to clause 11.1, we will not be liable for any loss arising from: your Applications or Customer Data; any remote action taken through your Account (clause 5.3); code delivered by a connected source (clause 7.4); hardware, networks, power or third-party services not provided by us; your failure to keep backups (clause 7.5); use contrary to clause 6; Preview Features; or any failure to follow our documentation or reasonable instructions.

11.5 Subject to clause 11.1, where we provide any part of the Services free of charge, including during early access, we provide it "as is" and will have no liability to you in connection with it.

11.6 Except as expressly set out in these terms, all warranties, conditions and other terms implied by statute or common law — including as to satisfactory quality, fitness for a particular purpose, and that the Services will be uninterrupted, secure or error-free — are excluded to the fullest extent permitted by law.

11.7 Subject to clause 11.1, any claim against us must be notified to us in writing within 12 months of the date on which you became aware, or ought reasonably to have become aware, of the facts giving rise to it, and otherwise it is waived.

11.8 You agree that these limits are reasonable, taking into account the nature of the Services, the fees charged, your ability to obtain insurance, and your control over your Applications, Devices and Customer Data.

12. Your indemnity

12.1 You will indemnify us, and our officers, employees and contractors, against all claims, losses, damages, fines, penalties, costs and expenses (including reasonable legal fees) arising out of or in connection with:

  • your Applications or Customer Data, including any claim that they infringe a third party's rights or break the law;
  • your Devices, their operation, or their use by End Users;
  • your breach of clause 4, 5, 6, 7 or 8, or of Data Protection Law; or
  • any claim by an End User, your own customer or any other third party relating to your product or service.

12.2 We will notify you promptly of any such claim, allow you to conduct its defence at your cost, and give you reasonable help at your cost. We will not settle such a claim without your consent, not to be unreasonably withheld.

13. Suspension

13.1 We may suspend all or part of the Services, or access by any user, key or Device, immediately and without liability, if we reasonably believe: there is a threat to the security or integrity of the Services or of other customers; you are in breach of clause 4, 6 or 7; suspension is required by law or a competent authority; or you have disputed a valid charge as described in clause 9.8.

13.2 We will give notice where we reasonably can, keep the suspension no wider or longer than necessary, and lift it once the reason has been resolved. Fees continue to be payable during a suspension caused by you.

13.3 During a suspension, Devices may continue to run the Application they already hold, but will not receive updates, settings, files or remote actions, and data they send may not be accepted.

14. Term and termination

14.1 These terms start when you accept them and continue until terminated.

14.2 You may cancel a paid Package at any time under clause 9.4, and close an Account that has no paid Package at any time. We may terminate for convenience on 30 days' notice; if we do, we will refund any fees you have paid in advance for the period after termination.

14.3 Either of us may terminate immediately by notice if the other: commits a material breach that is not capable of remedy, or that is not remedied within 14 days of being asked to; or becomes insolvent, enters administration, liquidation or any arrangement with its creditors, or ceases to trade.

14.4 We may terminate immediately by notice if you breach clause 6, or if we stop providing the Services generally (in which case we will give you as much notice as is reasonably possible and refund any fees paid in advance for the period after termination).

15. What happens when the contract ends

15.1 On termination: all licences granted to you end; you will pay all outstanding fees; Devices will stop receiving updates, settings, files and remote management from the Services, and you are responsible for whatever they then do; and you must stop using the runtime and device images.

15.2 For 30 days after termination (other than termination for breach of clause 6), you may export your Customer Data using the tools in the Services. After that period we will delete Customer Data from our active systems, except where we are required by law to keep it. Copies in backups are deleted on their normal rotation. We have no obligation to keep any data after that period.

15.3 Clauses that by their nature are intended to survive termination — including clauses 7.1 (as needed for deletion), 9, 10, 11, 12, 15, 17 and 18 — continue in force.

16. Confidentiality

16.1 Each of us will keep the other's confidential information secret, use it only to perform or receive the Services, and disclose it only to employees, contractors and advisers who need to know it and are bound by equivalent obligations, or as required by law or a competent authority.

16.2 This does not apply to information that is or becomes public through no fault of the recipient, was lawfully held before disclosure, is independently developed, or is lawfully received from a third party without restriction.

17. Events outside our control

17.1 We will not be in breach of these terms or liable for any failure or delay caused by events beyond our reasonable control, including failures of the internet, telecommunications, power or third-party hosting, storage or network providers; cyber-attacks, including denial-of-service attacks; acts of government or regulators; fire, flood, storm, epidemic, war, terrorism, civil unrest or industrial action.

18. General

18.1 Changes to these terms. We may update these terms. We will give at least 30 days' notice of a change that materially affects you, by notice in the portal or to your Account's owner. Changes required by law, or that relate to new features, may take effect sooner. If you continue to use the Services after a change takes effect, you accept it; if you do not accept it, you may cancel under clause 9.4 or close your Account before it takes effect. The version in force is the one published on this page.

18.2 Notices. We may give you notices through the portal or to the contact details of your Account's owner. You may give us notices through the contact form or by post to our registered office.

18.3 Assignment and subcontracting. You may not assign or transfer your rights or obligations without our prior written consent. We may assign or transfer ours to a successor of our business, and may use subcontractors, remaining responsible for them.

18.4 Entire agreement. These terms, any written agreement or order form referred to in clause 1.4, and the documents they refer to are the entire agreement between us. Each of us agrees that it has not relied on any statement, promise or representation not set out in them, including any statement on this website about future features or timescales. Nothing in this clause limits liability for fraud.

18.5 Severance. If any provision is found invalid or unenforceable, it will be modified to the minimum extent needed to make it valid, and the rest of these terms will continue in force.

18.6 Waiver. A failure or delay in exercising any right is not a waiver of it.

18.7 Third-party rights. No one other than you and us has any right to enforce these terms under the Contracts (Rights of Third Parties) Act 1999, except the people indemnified in clause 12.

18.8 No partnership. Nothing in these terms creates a partnership, joint venture or agency between us.

18.9 Governing law and jurisdiction. These terms and any dispute or claim (including non-contractual ones) arising out of or in connection with them are governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction.


Schedule 1 — Data processing terms

This schedule applies where we process personal data on your behalf as your processor under clause 8.2, and forms the terms required by Article 28 of the UK GDPR.

Scope

  • Subject matter and duration — provision of the Services, for as long as you use them and the period in clause 15.2.
  • Nature and purpose — hosting, storage, transmission, packaging, synchronisation to Devices, remote management, logging and delivery to destinations you configure.
  • Types of personal data — whatever you or your Applications choose to put into Customer Data, together with Device logs, screenshots and console output you request.
  • Data subjects — your users, staff, customers and other End Users, as determined by you.

Our obligations

S1.1 We will process that personal data only on your documented instructions — which are these terms and your use and configuration of the Services — unless required to do otherwise by law, in which case we will tell you first unless the law forbids it. We will tell you if we believe an instruction breaks Data Protection Law.

S1.2 We will ensure that people authorised to process the data are bound by confidentiality.

S1.3 We will take appropriate technical and organisational measures to protect the data, as described on our security page, which we may improve over time but will not materially weaken.

S1.4 You give us general authorisation to use sub-processors, including our hosting provider, Cloudflare (network and object storage) and, where you connect it, GitHub. We will impose data protection terms on each sub-processor that are no less protective than these, remain responsible for them, and tell you of any intended change so that you can object on reasonable grounds; if we cannot reasonably accommodate the objection, your remedy is to cancel under clause 9.4 or close your Account.

S1.5 Where a sub-processor transfers personal data outside the UK, we will ensure the transfer is covered by an appropriate safeguard under Data Protection Law, such as adequacy regulations or the UK International Data Transfer Addendum.

S1.6 Taking into account the nature of the processing, we will give you reasonable assistance, at your cost where the assistance is more than minimal, with data subjects' requests, security, breach notification, data protection impact assessments and consultation with the Information Commissioner.

S1.7 We will notify you without undue delay after becoming aware of a personal data breach affecting that data, with the information reasonably available to us.

S1.8 At the end of the Services, we will delete the data as set out in clause 15.2, unless the law requires us to keep it.

S1.9 We will make available the information reasonably necessary to demonstrate compliance with this schedule, and allow audits by you or an auditor you mandate on at least 30 days' notice, no more than once a year, during business hours, at your cost and subject to reasonable confidentiality obligations — or more often where required by a regulator or following a personal data breach.

Your obligations

S1.10 You warrant that you have a lawful basis for all processing you instruct, that you have given all required notices, and that your instructions comply with Data Protection Law. You will not use the Services to process special category or criminal offence data unless you have confirmed the Services are appropriate for it and have put the necessary safeguards in place.

Tominko Ltd · Company no. 12089741 · Registered in England and Wales · Version 1.0 · Effective 8 October 2026