Terms of Service
Last updated: 31 August 2026
These terms form the agreement between CrossTenant Ltd, a company registered in England & Wales (company no. 17349672), registered office Unit 82a James Carter Road, Mildenhall, Bury St. Edmunds, IP28 7DE, United Kingdom (“CrossTenant”, “we”, “us”) and the organisation that subscribes to the CrossTenant service (“you”, the “Customer”).
In short. CrossTenant is an administration console you use to manage other organisations’ Google Workspace tenants. The most important thing in this agreement is section 4: you must actually be authorised by each organisation you manage, and you are responsible for what your engineers do through the console. Everything else is conventional. This summary is not part of the agreement.
1. Definitions
- Service — the CrossTenant console and any associated software, documentation, and support we provide to you.
- Order — the subscription details agreed between us: the plan, the number of Managed Organisations, the fees, and the term. An Order may be a written quote, an online sign-up, or an exchange of emails confirming those details.
- Managed Organisation — a Google Workspace organisation that you administer through the Service.
- Authorised User — an individual you permit to sign in to the Service (typically your engineers).
- Customer Data — data you or your Authorised Users put into the Service, and data the Service retrieves from a Managed Organisation’s Google Workspace on your instructions.
- DPA — the Data Processing Agreement, which forms part of this agreement.
2. The agreement
This agreement consists of these terms, the DPA, the sub-processor list, and each Order. If they conflict, the Order prevails over these terms for the commercial points it covers, and the DPA prevails over both on data-protection matters. Our privacy policy describes how we handle personal data; it is a notice, not a contractual term.
This agreement starts when you first accept it, sign an Order, or begin using the Service — whichever happens first — and continues for the term described in section 10.
3. The Service and your licence to use it
We grant you a non-exclusive, non-transferable right, for the term of this agreement, to access and use the Service for your internal business purposes: administering the Managed Organisations covered by your Order. That right extends to your Authorised Users, and you are responsible for their acts and omissions as if they were your own.
You must not, and must not permit anyone else to:
- use the Service to access or administer any organisation you are not authorised to administer;
- resell, sublicense, or provide the Service to a third party as a standalone product, except that using the Service to deliver managed services to your own customers is exactly what it is for and is permitted;
- copy, modify, decompile, or reverse-engineer the Service, except to the extent that law expressly permits despite this restriction;
- attempt to circumvent access controls, rate limits, approval gates, or audit logging, or share Authorised User credentials;
- use the Service unlawfully, or in a way that damages the Service or another user’s use of it.
We may change or improve the Service over time. We will not make a change that materially reduces its core functionality during a paid term without giving you notice and, if the change materially disadvantages you, a right to terminate and receive a pro-rata refund of prepaid fees.
Early access, beta, and pilot
We may designate individual features, or by an Order a whole subscription, as “beta”, “early access”, or a “pilot”. Beta features and pilot subscriptions are provided for evaluation: they are supplied “as is”, may change, be suspended, or be withdrawn at any time, may carry reduced or no fees, and are excluded from the warranty in section 13. Your obligations under sections 3, 4, and 5 apply to them in full. Our total aggregate liability arising out of or in connection with a beta feature, or with a subscription an Order designates a pilot, is limited as follows: for a pilot subscription, to the fees actually paid for that subscription; for a beta feature for which an Order allocates a separate fee, to the fees actually paid for that feature; and for a beta feature with no separately allocated fee — including a beta feature made available within a paid subscription at no separately stated charge, and any beta feature provided free of charge — to £100. Where both this paragraph and the cap in section 14 could apply to the same claim, the lower figure applies. This paragraph does not limit the liability that section 14 says cannot be excluded or limited, does not reduce our obligations under the DPA, and liability arising from a breach of the DPA remains governed by section 14 rather than by this paragraph.
4. Your authority over Managed Organisations — the load-bearing clause
The Service performs privileged administration against real Google Workspace tenants belonging to other organisations. You therefore warrant, on an ongoing basis, that:
- you are engaged by each Managed Organisation to provide IT administration services to it;
- you have that organisation’s authority to administer its Google Workspace tenant through a third-party tool, and to authorise CrossTenant’s access to it;
- you have a written agreement with each Managed Organisation that permits the processing described in the DPA, including our engagement as a sub-processor to you (or, where you act as controller, as your processor);
- you have given each Managed Organisation whatever information data-protection law requires it to give its own people about that processing;
- where the optional AI features are used in administering a Managed Organisation, you have given that organisation the notices and warnings appropriate to AI features — including that AI output may contain errors and that an Authorised User reviews and confirms every action before anything is executed — and you will pass equivalent warnings to anyone to whom you present AI output, and will not present AI output as independently verified when it has not been.
We do not independently verify your authority and are not in a position to. A Managed Organisation’s Google Workspace super-administrator grants the access technically (through Google OAuth consent and domain-wide delegation) and can revoke it at any time in their own Google Admin Console; that grant is the technical control, but the contractual authority is yours to hold.
You are responsible for the administrative actions taken through the Service — including their effect on a Managed Organisation’s users, data, and configuration, and including actions that turn out to be mistaken: an operator choosing the wrong account, the wrong setting, or the wrong customer is your error to answer for, not ours. The Service executes the instructions your Authorised Users confirm, and we may rely on an instruction that reasonably appears to come from an Authorised User’s authenticated session. The Service provides controls to help you govern this (per-area role-based access, write confirmation, an approval gate for elevated actions, and a tamper-evident audit log). Whether and how you enable and use those controls is your decision, and using them does not shift responsibility for the underlying action to us.
5. Accounts, access, and security
You are responsible for keeping Authorised User accounts secure, for removing access promptly when someone leaves your organisation or changes role, and for the accuracy of the access policy you configure. Sign-in is through Google or Microsoft identity; we do not hold your users’ passwords.
Tell us promptly at security@crosstenant.com if you believe an account has been compromised or the Service has been misused. How we handle security reports, and what we commit to in return, is set out on our security page.
6. Fees, invoicing, and payment
- Fees are those set out in your Order. Unless the Order says otherwise, the Service is charged per Managed Organisation, per month, in advance.
- All fees are exclusive of VAT and any other applicable taxes, which you pay in addition at the prevailing rate.
- Invoices are payable within 14 days of the invoice date unless the Order states otherwise.
- If you add Managed Organisations during a billing period, we charge for them pro rata from the date they are added.
- We may increase fees on renewal by giving you at least 30 days’ notice before the renewal date. If you do not accept an increase, you may terminate with effect from the end of the current term.
- We may charge interest on overdue amounts at 4% per annum above the Bank of England base rate, accruing daily, under the Late Payment of Commercial Debts (Interest) Act 1998.
7. Suspension
We may suspend your access, or an individual Authorised User’s access, where:
- an invoice is more than 30 days overdue and we have given you at least 7 days’ written notice;
- we reasonably believe continued access presents a security risk to the Service, to you, or to a Managed Organisation;
- we are required to do so by law, or by Google, in respect of the underlying API access.
We will limit any suspension to what is necessary and restore access as soon as the cause is resolved. Suspension does not by itself terminate the agreement or relieve you of fees for the period, except where the suspension was our fault.
8. Availability, maintenance, and support
We will provide the Service with reasonable skill and care. We do not currently offer a contractual uptime commitment or service credits; if your Order includes a service level, that Order prevails. Our published support channels, response targets, and the way we announce planned maintenance and incidents are described on the support page.
The Service depends on Google’s APIs. Where Google changes, deprecates, rate-limits, or interrupts an API, a corresponding feature may be degraded or unavailable. We will tell you when we become aware of a material, lasting change of that kind, and we are not liable for the underlying Google outage itself.
9. Data protection and Customer Data
Each party will comply with applicable data-protection law. In relation to personal data within Managed Organisation data, the Managed Organisation is the controller, you act on its instructions, and we process on yours. The DPA governs that processing and forms part of this agreement; it also sets out our security measures, our use of sub-processors, and our breach-notification commitment.
As between you and us, you retain all rights in Customer Data. You grant us the limited right to process it as necessary to provide the Service, and for no other purpose. We do not use Customer Data to train machine-learning models, we do not sell it, and we do not use it for advertising.
We keep the current list of sub-processors at crosstenant.com/subprocessors. We will give at least 30 days’ notice before adding a new sub-processor that will process Managed Organisation personal data, and you may object on reasonable data-protection grounds as described in the DPA.
10. Term, renewal, and termination
Unless your Order says otherwise, the subscription runs month to month and renews automatically at the end of each month.
- You may terminate for convenience on 30 days’ written notice, effective at the end of the then-current term. Fees already paid for that term are not refundable except where this agreement expressly says otherwise.
- Either party may terminate immediately on written notice if the other commits a material breach that is not remedied within 30 days of being asked to remedy it, or becomes insolvent, enters administration, or ceases to carry on business.
- We may terminate immediately if you breach section 4 (authority over Managed Organisations) or section 3 (use restrictions) in a way that cannot be remedied.
- We may terminate for convenience on 90 days’ written notice, refunding any prepaid fees for the period after termination.
What happens on termination
- Your right to use the Service ends and Authorised User access is withdrawn.
- You should revoke CrossTenant’s access to each Managed Organisation’s Google Workspace tenant. You can do this yourself at any time, without us, in the Google Admin Console.
- We delete the stored authorisation credentials and the configuration held for you — ordinarily within 30 days, and sooner on request.
- We retain the write-audit log for its stated retention period (a maximum of 24 months from the entry date), after which it is deleted automatically. We keep it because it is the accountable record of administrative actions taken against Managed Organisations, which is of continuing importance to you and to them. The DPA describes this and the basis for it.
- Accrued rights, and the sections that by their nature should survive (including 9, 11, 12, 13, 14, 15, and 16), survive termination.
11. Intellectual property
We own the Service, all software and materials comprising it, and all intellectual property rights in them. Nothing in this agreement transfers those rights to you. You own Customer Data and your own systems, and nothing transfers those rights to us.
If you send us feedback or suggestions about the Service, we may use them without obligation or payment. We will not identify you as the source without your permission.
12. Confidentiality
Each party may receive information from the other that is marked confidential or that a reasonable person would understand to be confidential — including, for us, information about Managed Organisations and their security posture. Each party will use the other’s confidential information only to perform this agreement, protect it with at least reasonable care, and disclose it only to people who need it and are bound by equivalent obligations. These obligations do not apply to information that is public through no breach, was already lawfully held, or is independently developed; and they do not prevent a disclosure required by law, provided the disclosing party gives notice where it lawfully can.
13. Warranties and disclaimers
We warrant that we will provide the Service with reasonable skill and care, and that we have the right to grant the licence in section 3.
Beyond that, and to the fullest extent the law allows, the Service is provided “as is”. We do not warrant that it will be uninterrupted or error-free, that it will detect every security issue in a Managed Organisation, or that its reports, posture scores, benchmark results, or AI output are complete or free from error. The Service is a tool to support professional judgement, not a substitute for it — and its AI features are advisory only: they can propose an action but never perform one, and an Authorised User reviews and confirms every action.
AI features — acknowledgments and the enforced review gate
The Service includes optional AI features. You acknowledge that:
- AI output is generated by statistical models and may be inaccurate, incomplete, misleading, or out of date;
- an Authorised User must review AI output and apply their own professional judgement before acting on it, and you must not represent AI output as having been independently verified when it has not been;
- responsibility for the decisions taken and actions executed on the strength of AI output rests with you, as section 4 describes; and
- where you use AI output in services to a Managed Organisation, the flow-down notice obligation in section 4 applies.
The review the second acknowledgment requires is not left to promise alone: it is enforced by the Service as a technical control. The AI features are advisory by design — the assistant can draft or propose an action but cannot execute one; every action requires an Authorised User’s explicit confirmation; elevated actions can additionally be held for a second operator’s approval; and AI-assisted actions are flagged as such in the audit log. That enforced gate is how the Service is built. It does not weaken the acknowledgments above or the disclaimers in this section, and it does not transfer to us responsibility for an action an Authorised User has confirmed.
We are not affiliated with, endorsed by, or sponsored by Google. Your and each Managed Organisation’s use of Google Workspace is governed by their own agreements with Google, not by this one.
14. Liability
Neither party excludes or limits its liability for:
- death or personal injury caused by its negligence;
- fraud or fraudulent misrepresentation;
- any other liability that cannot lawfully be excluded or limited.
Subject to that, and to the fullest extent the law allows, neither party is liable to the other for loss of profit, loss of revenue, loss of anticipated savings, loss of business or goodwill, loss or corruption of data or software, or any indirect or consequential loss, however arising.
The exclusion of loss or corruption of data above does not apply to a claim arising from our breach of the DPA. Where our breach of the DPA causes loss or corruption of personal data we process for you, your remedies for that breach — including damages and any other financial compensation — remain available and recoverable, subject to the cap in the next paragraph, and are not excluded or reduced by that exclusion.
Subject to the two paragraphs above, each party’s total aggregate liability arising out of or in connection with this agreement, whether in contract, tort (including negligence), breach of statutory duty or otherwise, is limited to the total fees paid or payable by you under this agreement in the twelve months immediately before the event giving rise to the claim.
Your obligation to pay fees, and your liability under section 15 (indemnity), are not subject to that cap.
15. Indemnity
You will indemnify us against losses, damages, and reasonable costs (including reasonable legal fees) we incur from a third-party claim arising out of:
- your not holding the authority warranted in section 4 in respect of a Managed Organisation;
- your or an Authorised User’s use of the Service in breach of section 3; or
- your breach of your own obligations as a controller or processor in respect of Managed Organisation personal data, other than to the extent caused by our breach of the DPA.
We will notify you promptly of any such claim, not admit liability without your consent (not to be unreasonably withheld), and let you control the defence with our reasonable cooperation at your cost.
16. Changes to these terms
We may update these terms. For a material change we will give you at least 30 days’ notice by email to your billing contact and by updating the “last updated” date above. If a material change materially disadvantages you, you may terminate before it takes effect and we will refund prepaid fees for the period after termination. Continuing to use the Service after a change takes effect means you accept it.
17. General
- Assignment. Neither party may assign this agreement without the other’s consent, not to be unreasonably withheld, except that either party may assign it to a successor to substantially all of its business or assets on notice.
- Sub-contracting. We may use sub-processors and sub-contractors, and remain responsible for their performance. Sub-processors that handle personal data are governed by the DPA and listed at /subprocessors.
- Entire agreement. This agreement is the whole agreement between us on its subject matter and replaces any earlier discussions. Neither party relies on any statement not set out in it. This does not limit liability for fraud.
- No partnership. Nothing here creates a partnership, joint venture, or employment relationship, or makes either party the agent of the other.
- Third parties. A person who is not a party has no right under the Contracts (Rights of Third Parties) Act 1999 to enforce any term.
- Severance. If any provision is held unenforceable, it is modified to the minimum extent necessary, or severed, and the rest continues in force.
- Waiver. A failure or delay in exercising a right is not a waiver of it.
- Force majeure. Neither party is liable for failure or delay caused by an event beyond its reasonable control, provided it tells the other and works to resume performance. This does not excuse payment obligations.
- Notices. Notices to us go to toby@crosstenant.com and to the registered office above; notices to you go to your billing contact’s email address. Email notice is effective when sent, unless the sender receives a delivery failure.
- Publicity. We will not name you as a customer publicly without your prior written consent.
- Governing law. This agreement and any dispute arising out of it (including non-contractual disputes) are governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction.
18. Contact
CrossTenant Ltd, Unit 82a James Carter Road, Mildenhall, Bury St. Edmunds, IP28 7DE, United Kingdom. General and contractual: toby@crosstenant.com. Security: security@crosstenant.com. Data protection: privacy@crosstenant.com.