Awarely Monitor
AwarelyMonitor
Legal center

Terms and Conditions

These Terms and Conditions ("Terms") govern your access to and use of the Awarely Monitor CVE monitoring service ("Service") operated by MUNTEANU C. D. MIHAI PERSOANĂ FIZICĂ AUTORIZATĂ, trading as MONITOR AWARELY ("Company", "we", "us", or "our"), a Persoană Fizică Autorizată registered in Romania. By accessing or using our Service, you acknowledge that you have read, understood, and agree to be bound by these Terms.

Last Updated: August 3, 2026Effective Date: August 3, 2026

1. Definitions and Legal Entity

1.1 "Service"The Awarely Monitor CVE monitoring platform, including the web dashboard, API access, alert systems, and all related features.
1.2 "User" or "Customer"Any individual or legal entity that creates an account, accesses, or uses the Service.
1.3 "Subscription"The paid or trial access tier selected by the User (Free Trial, Starter, or Pro).
1.4 "CVE Data"Common Vulnerabilities and Exposures data aggregated from sources including NVD, CISA KEV, EUVD, and GitHub Security Advisories.
1.5 "API"The programmatic interface providing access to CVE data for Pro subscribers.
1.6 "Personal Data"Has the meaning given under Regulation (EU) 2016/679 (General Data Protection Regulation - GDPR).
1.7 "DPA"A separate Data Processing Agreement made available for organization customers where MONITOR AWARELY processes customer data on the customer's behalf.

2. Company Information

The Service is provided by:

Legal EntityPFA (Persoană Fizică Autorizată)
Legal NameMUNTEANU C. D. MIHAI PERSOANĂ FIZICĂ AUTORIZATĂ
Trade NameMONITOR AWARELY
Tax IdentifierCUI: 53962936 (Romanian clients) · EU VAT (VIES): RO54197611 (EU clients outside Romania)
Registered AddressBucurești, Sector 1, Bulevardul Bucureștii Noi, Nr. 136, Cod poștal 012366, România
CountryRomania, European Union
Trade RegisterRomanian Trade Register (ONRC) registration number: F2026008193001
Contact Emailmonitor@awarely.ro
VAT StatusFor in-app card purchases, Stripe Managed Payments (Link as merchant of record) handles VAT/tax collection and tax invoices at checkout. For direct B2B contracts, invoices and tax documentation are issued directly by MONITOR AWARELY.

3. Account Registration and Eligibility

3.1 Age RequirementYou must be at least 16 years old (or the age of digital consent in your jurisdiction) to use this Service.
3.2 Accurate InformationYou must provide accurate, complete, and current information during registration and maintain its accuracy.
3.3 Account SecurityYou are responsible for maintaining the confidentiality of your account credentials and for all activities under your account. Notify us immediately of any unauthorized access.
3.4 AuthenticationAccount authentication is brokered through AWS Cognito. You may register with email/password, use Google sign-in, or—where an eligible organization has been provisioned—use one customer-configured enterprise OIDC identity provider such as Microsoft Entra ID, Okta, or Google Workspace. We do not receive the password used at Google or at the enterprise identity provider. You and, where applicable, your organization are responsible for securing the selected identity provider, assignments, MFA policy, and recovery process.
3.5 One Account Per UserEach user may maintain only one account. Creating multiple accounts to abuse trial periods or circumvent restrictions is prohibited.
3.6 Organization UseIf using the Service on behalf of an organization, you represent that you have authority to bind that organization to these Terms.
3.7 Organization AdministrationOwners and administrators have different permissions. Owners alone may rename the organization, remove users, assign roles and select a successor when deleting an owner account. Administrators may invite users and manage the operational features made available to their role, including billing, alerts, reports, integrations and API keys. Ownership is transferred only as part of deleting the current owner account. You are responsible for choosing administrators, managing their permissions, and ensuring their actions are authorized.

4. Service Description and Subscription Tiers

4.1 Free Trial14-day trial with Pro-tier product features, including dashboard access, automated CVE updates from source synchronization every two hours, and all dashboard filters. Enterprise SSO remains separately provisioned. Trial accounts are limited to one per user/organization. Deleting your account ends the trial immediately: any remaining trial days are forfeited and are not restored, transferred, or credited. If you register again with the same email address within 90 days of deleting an account, you may create and use that account on the Free tier, but no new free trial is granted. To apply this rule we keep, for 90 days, a pseudonymous marker derived from your email address, described in the Privacy Policy.
4.2 Starter Subscription (€59/month)For small teams. Includes shared team access for up to five users in total, including the owner, email alerts for Critical severity CVEs, CSV and XLSX export, watched filters and search, 90-day retention, and a date-range audit/evidence export. No Slack/Teams/webhook alerts and no API access.
4.3 Pro Subscription (€199/month)For security teams. Includes shared team access for up to five users in total, including the owner; Email, Slack, Teams Workflows and signed outbound webhook alerts; Critical instant / High daily / Medium weekly cadence; 12-month retention; scheduled and on-demand workflow/evidence reports; Jira and Linear ticket creation; asset inventory and exposure evidence; audit trail; watched products; assisted enterprise OIDC SSO for one supported provider; and API access (50k requests/month). The current Offer page provides the operational feature detail and dependencies.
4.4 Data SourcesCVE data is aggregated from NVD (National Vulnerability Database), CISA KEV (Known Exploited Vulnerabilities), EUVD (ENISA), and GitHub Security Advisories. We do not guarantee completeness or accuracy of third-party data.
4.5 Availability and MaintenanceThe Service is made available on a best-effort basis. We do not guarantee minimum uptime, uninterrupted availability, error-free operation, recovery time, recovery point, or that a feature, alert, report, integration, API response, or data-source update will be available at a particular time. We may change, maintain, suspend, or restrict the Service where reasonably necessary. We may give advance notice of planned maintenance when reasonably practicable.
4.6 Support; No Commercial SLASupport requests sent through the Service or to monitor@awarely.ro are handled on a best-effort basis. Unless a separately negotiated written agreement expressly states otherwise, no service-level agreement applies: we do not guarantee support hours, response time, resolution time, fix timeframe, availability, uptime, RTO, RPO, or a particular support outcome. An acknowledgement, product message, or severity label is not a contractual service commitment. The in-product remediation-target or “SLA” tracking feature is a workflow tool and does not create a commercial SLA, compliance certification, or obligation for MONITOR AWARELY. Mandatory legal obligations are not excluded.
4.7 Service Changes and DependenciesWe may add, modify, replace, limit, or discontinue features, plans, integrations, data sources, rate limits, and technical requirements where reasonably necessary for security, legal, operational, or product reasons. Third-party services and data sources may change or become unavailable without our control. We will give reasonable notice of a material adverse change where practicable, and mandatory consumer remedies remain unaffected.

5. Acceptable Use Policy

You agree to use the Service only for lawful purposes. You shall NOT:

5.1Use the Service for any illegal purpose or to violate any laws or regulations.
5.2Attempt to gain unauthorized access to the Service, other accounts, or connected systems.
5.3Interfere with or disrupt the Service, servers, or networks.
5.4Use automated tools to scrape, crawl, or extract data beyond API rate limits.
5.5Resell, redistribute, or commercially exploit CVE data without authorization.
5.6Share account credentials or API keys with unauthorized parties.
5.7Use the Service to conduct attacks, exploit vulnerabilities, or engage in malicious activities.
5.8Reverse engineer, decompile, or attempt to extract source code from the Service.
5.9Upload, transmit, or process content or personal data unless you have all necessary rights, permissions, notices, and lawful bases to do so.
5.10Submit payment-card data, authentication secrets, special-category personal data, criminal-offence data, or other highly sensitive data unless the Service expressly requests it or we separately agree in writing.

6. API Terms (Pro Subscribers)

6.1 Rate LimitsAPI access is subject to rate limiting. Current limits are specified in the API documentation and may be adjusted.
6.2 API KeysAPI keys are confidential and must not be shared. You are responsible for all API usage under your key.
6.3 AttributionWhen displaying CVE data obtained via API, you must attribute the data sources (NVD, CISA, EUVD, GitHub) appropriately.
6.4 No API SLAAPI access is subject to Section 4.6. It does not include a Service Level Agreement, guaranteed capacity, response time, availability, or support commitment unless a separately negotiated written agreement expressly states otherwise.

7. Intellectual Property

7.1 Our RightsThe Service, including its design, code, features, and documentation, is owned by MUNTEANU C. D. MIHAI PFA (MONITOR AWARELY) and protected by Romanian, EU, and international intellectual property laws.
7.2 CVE DataCVE data is sourced from public databases. Original data from NVD, CISA, EUVD, and GitHub remains subject to their respective terms and licenses.
7.3 Limited LicenseWe grant you a limited, non-exclusive, non-transferable, revocable license to access and use the Service for its intended purpose.
7.4 FeedbackAny feedback or suggestions you provide may be used by us without obligation to compensate you.
7.5 Customer DataAs between you and MONITOR AWARELY, you retain your rights in data and content you lawfully submit to the Service. You grant MONITOR AWARELY and its authorized providers a non-exclusive, worldwide, limited license to host, copy, process, transmit, display, and otherwise use that data only as necessary to provide, secure, support, and improve the Service, follow your configurations, and comply with law. You represent that you have authority to grant this license.

8. Payment, Billing, and Contracting

Awarely Monitor offers two billing channels: self-serve card payment in the app (processed by Stripe under its Managed Payments program) and direct B2B invoicing contracted with MONITOR AWARELY (typically for institutions):

8.1 Card checkout and merchant of recordWhen you subscribe by card in the app, checkout is operated by Stripe Managed Payments and Link (Sold through Link, LLC) acts as the merchant of record for the payment. Your card statement shows a descriptor beginning with LINK.COM*, and you accept Link's consumer terms at checkout for the payment relationship. The Awarely Monitor service itself is provided by MONITOR AWARELY under these Terms.
8.2 Direct B2B ContractsAlternatively, customers (typically institutions) may contract directly with MONITOR AWARELY. In that arrangement MONITOR AWARELY is the contractual counterparty responsible for billing, invoicing, and the subscription relationship, and payment is made outside the app under the agreed terms.
8.3 PricingPrices are presented in EUR, exclusive of taxes. For card checkout, applicable VAT/sales tax is calculated and shown at checkout; business buyers can enter their company name and VAT/tax ID there. For direct B2B contracts, taxes follow the billing documents issued by MONITOR AWARELY.
8.4 Billing Cycle and RenewalCard subscriptions renew automatically monthly or annually, according to the interval and price shown and accepted at checkout or selected later in the billing portal, until cancelled. Renewal and payment notifications are handled by Link/Stripe. Direct B2B subscriptions are billed on the schedule agreed with MONITOR AWARELY.
8.5 Failed and Overdue PaymentsFor card subscriptions, Link/Stripe retries failed payments; if payment ultimately fails, the subscription ends and the account reverts to the Free tier. For direct B2B arrangements, failed or overdue payments may result in suspension or downgrade.
8.6 CancellationCard subscriptions can be cancelled at any time from Settings > Subscription > Cancel renewal; the application sends the request directly to Stripe and confirms the scheduled end date. Access continues until the end of the paid period. Customers may also manage Managed Payments subscriptions through Link. Direct B2B cancellations follow the agreed contract.
8.7 RefundsSee the Refund Policy. For card purchases, refunds are handled through Stripe/Link as merchant of record; for direct B2B invoicing, refund requests are handled by MONITOR AWARELY.
8.8 Taxes and InvoicesFor card purchases, indirect tax compliance is handled under Stripe Managed Payments and receipts/tax invoices are issued and emailed by Link/Stripe. For direct B2B contracts, invoices and tax documentation are issued directly by MONITOR AWARELY.
8.9 Payment Instrument DataMONITOR AWARELY never collects or stores full payment card numbers, CVC/CVV, or expiry details. Card details are entered on Stripe's hosted checkout and never reach MONITOR AWARELY systems. MONITOR AWARELY receives from Stripe only what is needed to activate your plan: subscription status, period dates, and customer/subscription identifiers.
8.10 Plan and Billing-Interval ChangesWhere the billing portal permits a plan or billing-interval change, the price, effective date, proration, credits, and taxes displayed by Stripe/Link before confirmation govern that change. You are responsible for reviewing the checkout or portal summary before confirming.

9. Data Protection and Privacy

9.1 GDPR ComplianceWe process personal data in accordance with Regulation (EU) 2016/679 (GDPR) and Romanian Law 190/2018. See our Privacy Policy for comprehensive details.
9.2 Controller and Processor RolesMUNTEANU C. D. MIHAI PFA (MONITOR AWARELY) acts as independent controller for account creation, authentication, security logging, fraud prevention, tax/accounting, billing administration, and website/app operations. Where we process organization customer data on behalf of a business customer to provide the Service, we act as processor to the extent required by GDPR.
9.3 Data ProcessingWe process only the personal data necessary to provide the Service, support the customer relationship, secure the platform, and meet legal obligations. This may include processor-side service operations for business customers and controller-side records maintained by MONITOR AWARELY.
9.4 Sub-processors and VendorsWe use AWS services for infrastructure, Cognito authentication, and Amazon SES transactional email. Stripe/Link handles self-serve card payments under Managed Payments. Cookiebot, Google Analytics and optional Google sign-in are used where relevant to our own site/app operation. An enterprise OIDC identity provider is configured and controlled by the organization customer. Processor-side providers, independent-controller vendors, customer-configured identity providers and customer-configured destinations are described more precisely in our Privacy Policy and, where signed, the DPA.
9.5 Data SecurityWe implement reasonable technical and organizational measures designed to protect the Service and the personal data under our control. See our Privacy Policy for the current description of those measures.
9.6 Your RightsUnder GDPR, you have rights to access, rectify, erase, restrict, port, and object to processing of your personal data. See our Privacy Policy or contact us to exercise these rights.
9.7 Cookie ConsentWe use Cookiebot for cookie consent management. Non-essential cookies (including Google Analytics) require your explicit consent before being set.
9.8 DPA PrecedenceWhere a signed DPA applies to an organization customer, that DPA governs MONITOR AWARELY's processor-side obligations for that customer relationship.

10. Disclaimers and Limitations

10.1 No Security GuaranteeThe Service provides CVE information for awareness purposes. It does not guarantee protection against vulnerabilities or security incidents.
10.2 Third-Party DataCVE data is sourced from third parties. We do not warrant its accuracy, completeness, or timeliness.
10.3 As-Is ServiceTHE SERVICE IS PROVIDED "AS IS" AND "AS AVAILABLE" WITHOUT WARRANTIES OF ANY KIND, EXPRESS OR IMPLIED, TO THE MAXIMUM EXTENT PERMITTED BY LAW.
10.4 Limitation of LiabilityTO THE MAXIMUM EXTENT PERMITTED BY LAW, MONITOR AWARELY SHALL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, OR LOSS OF PROFITS, DATA, OR BUSINESS OPPORTUNITIES.
10.5 Liability CapTo the maximum extent permitted by law, MONITOR AWARELY’s aggregate liability arising out of or relating to the Service, these Terms, and all related claims shall not exceed the amounts paid by you for the Service in the twelve (12) months preceding the event first giving rise to liability, or €100, whichever is greater. Multiple claims do not increase this cap.
10.6 ExceptionsNothing limits liability that cannot be excluded by law, including for death, personal injury, fraud, or willful misconduct. Consumer protection rights under EU law are not affected.
10.7 Customer ResponsibilitiesYou remain responsible for your security decisions, risk assessments, patching, incident response, legal and regulatory obligations, backup and continuity arrangements, and for reviewing third-party CVE data before acting on it. You must not submit passwords, API keys, payment-card data, or other unnecessary sensitive information in a support request. The Service is not emergency response, legal advice, security certification, or a substitute for professional assessment.
10.8 IndemnificationTo the maximum extent permitted by law, you agree to defend, indemnify, and hold harmless MONITOR AWARELY (MUNTEANU C. D. MIHAI PFA), its owner, and its personnel from and against any third-party claims, demands, proceedings, losses, liabilities, damages, fines, penalties, costs, and expenses (including reasonable legal fees) arising out of or related to: (a) your use or misuse of the Service; (b) your violation of these Terms or applicable law; (c) any content, files, inventory data (such as SBOM, package manifests, or asset lists), or other material you upload, submit, or process through the Service, including any claim that it infringes or misappropriates a third party's intellectual property, privacy, confidentiality, or other rights, or that you lacked the right to provide it; (d) your unauthorized scanning, monitoring, or testing of systems, networks, or assets you do not own or are not authorized to assess; or (e) your violation of the rights of any third party. We may, at our option, assume the exclusive defense and control of any matter subject to indemnification, in which case you agree to cooperate with us. This obligation does not apply to the extent a claim results solely from MONITOR AWARELY's own willful misconduct, and nothing in this clause limits the mandatory rights of consumers under EU law.
10.9 Integrations and Customer DestinationsIf you enable Slack, Microsoft Teams, Jira, Linear, browser push, a webhook, or another third-party destination, you instruct us to transmit configured data to that destination. You are responsible for the destination account, recipients, permissions, retention, terms, security, and lawfulness. We are not responsible for a third party’s acts, omissions, availability, or use of data after lawful delivery, except to the extent mandatory law provides otherwise.

11. Term, Termination, and Data Export

11.1 TermThese Terms remain effective until terminated by either party.
11.2 Your Termination RightCard subscriptions can be cancelled at any time from Settings > Subscription > Cancel renewal or through Link; access continues until the end of the paid period. For direct B2B arrangements, you may request cancellation by contacting MONITOR AWARELY through the Settings support tab or at monitor@awarely.ro; the cancellation date follows the applicable contract and mandatory law.
11.3 No Fixed Notice PeriodNo fixed minimum notice period applies to your cancellation unless mandatory law or a separately agreed enterprise arrangement requires otherwise.
11.4 Data ExportAt any time, you may export the account data currently made available in Settings > Privacy & Data. The export currently includes your profile, preferences, alert settings, subscription details, billing metadata under our control, and the audit events generated for your account; it does not include another user's audit trail.
11.5 Account Deletion and RetentionDeleting your account removes your login access and starts our internal cleanup process for data under our control. If the organization has an active Stripe card subscription, deletion cancels it immediately to prevent further renewal; paid access ends immediately and the remaining paid period is not automatically refunded, without limiting mandatory rights or the Refund Policy. If you want to use the remaining paid period, use Cancel renewal first and delete the account after that period ends. Some records may be retained, restricted, anonymized, or kept in backups where required for legal, tax, security, fraud-prevention, or operational reasons.
11.6 Suspension and Termination by UsWe may suspend, restrict, downgrade, or terminate access immediately where reasonably necessary to address a security risk, suspected fraud or abuse, illegal activity, non-payment, a material breach, harm to the Service or others, or a binding legal request. Where the issue can reasonably be cured, we may give an opportunity to cure. We may otherwise discontinue an account or the Service with 30 days’ notice, subject to mandatory law and any agreed paid-period or refund rights.
11.7 Migration AssistanceWe do not charge a separate fee for the currently available self-service export feature. Custom migration, onboarding, or switching assistance is not included unless separately agreed.
11.8 Payment and Billing Data RequestsMONITOR AWARELY handles the billing records under its control; requests should be directed to monitor@awarely.ro. For card purchases, payment records and tax invoices are held by Stripe/Link as merchant of record — requests regarding that payment data can also be addressed to Stripe/Link support.
11.9 SurvivalProvisions regarding intellectual property, limitations of liability, indemnification, data retention obligations, and governing law survive termination.

12. Governing Law and Disputes

12.1 Governing LawThese Terms are governed by the laws of Romania and applicable mandatory European Union law.
12.2 JurisdictionDisputes shall be subject to the exclusive jurisdiction of Romanian courts, unless mandatory consumer protection laws of your residence country provide otherwise.
12.3 Consumer RightsIf you are an EU consumer, you benefit from mandatory consumer protection laws of your country of residence. Nothing in these Terms affects or limits your statutory consumer rights.
12.4 14-Day Withdrawal RightIf you are an EU consumer, any mandatory 14-day withdrawal right for a distance contract applies according to applicable law. The permanently available “Withdraw from contract here” footer link opens our authenticated online function at /withdrawal, which records the unequivocal statement and timestamp and issues a downloadable electronic confirmation. Email and other legally valid notice methods remain available. If you expressly request immediate performance during that period, you may owe a proportionate amount for service already supplied; any loss of the withdrawal right applies only where all legally required requests, acknowledgements, and confirmations have been obtained. Our voluntary 14-day first-payment refund in the Refund Policy does not reduce statutory rights.
12.5 ADR / Consumer ComplaintsThe former EU Online Dispute Resolution platform is no longer in service. We are not currently committed or obliged to use a specific ADR entity unless mandatory law requires otherwise. You may contact us first at monitor@awarely.ro.
12.6 Payment DisputesContact MONITOR AWARELY first at monitor@awarely.ro — most billing issues are resolved fastest this way. For card purchases, disputes and chargebacks are handled by Stripe under Managed Payments, and Link support handles payment-relationship questions; card disputes can take weeks and may lock the payment method at checkout while open.

13. Legal Framework References

13.1 GDPRPersonal data processing is described in our Privacy Policy and is intended to be interpreted consistently with Regulation (EU) 2016/679 and Romanian Law 190/2018.
13.2 Consumer LawWhere applicable, mandatory consumer rules, including Directive 2011/83/EU as implemented in Romania by OUG 34/2014 and Romanian rules for digital content and digital services, including OUG 141/2021, prevail over conflicting contractual wording.
13.3 NIS2The Service may support internal vulnerability-monitoring workflows relevant to NIS2, but using the Service alone does not create, certify, or prove NIS2 compliance.
13.4 ePrivacyCookie consent and analytics loading are managed through Cookiebot and the controls described in our Privacy Policy.
13.5 E-commerce RulesOnline contracting and trader information are intended to be interpreted consistently with Romanian e-commerce rules, including Law 365/2002 where applicable.
13.6 Other Mandatory LawIf other mandatory EU or Romanian rules apply to your use of the Service, those mandatory rules prevail over conflicting contractual terms.

14. General Provisions

14.1 ModificationsWe may modify these Terms with advance notice for material changes via email and/or a prominent notice in the Service. If you do not agree with the revised Terms, you should stop using the Service and cancel before the changes take effect. Where mandatory law requires a different acceptance mechanism, that law prevails.
14.2 SeverabilityIf any provision is found invalid or unenforceable, the remaining provisions continue in full force and effect.
14.3 Entire AgreementThese Terms, our Privacy Policy, any signed DPA, and direct billing documents issued by MONITOR AWARELY constitute the contractual framework regarding the Service.
14.4 No WaiverFailure to enforce any provision does not waive our right to enforce it later.
14.5 AssignmentYou may not assign your rights under these Terms without our consent. We may assign our rights in connection with a merger, acquisition, or sale of assets, with appropriate notice.
14.6 Force MajeureNeither party is liable for failures due to circumstances beyond reasonable control, including natural disasters, war, terrorism, government actions, or infrastructure failures.
14.7 LanguageThese Terms are available in English and Romanian. Both versions are legally binding. In case of conflict, the English version prevails for non-Romanian speakers.
14.8 ConfidentialityEach party must use reasonable care to protect non-public business, technical, security, and commercial information received from the other and use it only for the relationship, except where disclosure is authorized, already public without breach, independently developed, lawfully obtained from another source, or legally required. A recipient may disclose such information to personnel and providers who need it and are bound by appropriate confidentiality duties.

15. Contact Information

For questions about these Terms:

MUNTEANU C. D. MIHAI PERSOANĂ FIZICĂ AUTORIZATĂ

Trading as: MONITOR AWARELY

ONRC: F2026008193001 · CUI: 53962936 · EU VAT (VIES): RO54197611

București, Sector 1, Bulevardul Bucureștii Noi, Nr. 136, Cod poștal 012366, România

Romania, European Union

monitor@awarely.ro

https://monitor.awarely.ro

For our data protection practices, please review our Privacy Policy.

For refund terms, please review our Refund Policy.

For organization customer processor terms, please review our Data Processing Agreement.