ADVCY Client Terms
Last updated: 31 August 2026
These Client Terms govern the provision of ADVCY services to business customers.
1. Parties
These terms are entered into between:
ADVCY Ltd, a company registered in England and Wales under company number 16926771, whose registered office is at 40 Queens Road, Teddington, England, TW11 0LR (“ADVCY”);
and
the organisation identified as the customer in an Order Form, proposal, statement of work or other agreement referring to these terms (“Client”).
Together, the parties are the “Parties”.
2. Agreement
The agreement consists of:
- the applicable Order Form;
- any agreed statement of work;
- the Data Processing Addendum;
- these Client Terms; and
- any other document expressly incorporated by reference.
If there is a conflict, the documents take precedence in the order above unless expressly stated otherwise.
3. Services
ADVCY provides technology that helps organisations communicate with and support audiences through digital channels. Services may include:
- AI-powered concierge services;
- WhatsApp and other messaging integrations;
- Apple Wallet and Google Wallet passes;
- digital pass creation and management;
- event communications;
- member and community communications;
- pass verification;
- event recommendations;
- matchmaking;
- dashboards;
- analytics;
- integrations; and
- related professional services.
The exact Services purchased by Client are specified in the Order Form.
4. Client responsibility for its use of ADVCY
Client is responsible for determining:
- the purpose for which it uses the Services;
- which people it communicates with;
- what Client Data is supplied;
- what communications are sent;
- the content of those communications;
- the appropriate lawful basis for processing;
- whether marketing consent is required;
- its retention requirements;
- who may receive Client Data; and
- whether additional industry-specific rules apply.
Client must use the Services lawfully.
5. Data supplied by Client
Client warrants that Client Data supplied to ADVCY has been collected and disclosed lawfully. Where required, Client will provide affected individuals with appropriate privacy information.
Client must not provide ADVCY with information it is not entitled to process.
6. Controller and processor roles
Unless otherwise agreed for a specific processing activity, Client acts as controller of Client Personal Data and ADVCY acts as processor.
Where Client acts as processor for another controller, ADVCY may act as Client’s subprocessor.
ADVCY acts independently as controller for limited purposes relating to:
- its own customer account administration;
- billing;
- security;
- fraud and abuse prevention;
- legal compliance;
- corporate records; and
- management of its own business.
The Data Processing Addendum applies to Client Personal Data processed by ADVCY as processor.
7. Client privacy notice
Client must ensure that individuals using a Client-branded ADVCY experience receive appropriate privacy information at or before the time required by law.
For a wallet deployment, this should normally identify:
- Client as controller;
- ADVCY as technology provider/processor;
- the purposes of the Pass;
- the categories of information used;
- service communications;
- any marketing;
- applicable verification activity;
- relevant third parties;
- retention;
- data-subject rights; and
- any location processing.
ADVCY may provide template notices, but Client remains responsible for the accuracy of Client-specific information and its legal basis as controller.
8. Direct marketing
Client is responsible for ensuring that direct marketing sent through the Services complies with applicable data-protection and electronic-marketing law.
Client acknowledges that both the organisation instigating marketing and, in some circumstances, the organisation sending marketing can have legal responsibilities. Client must therefore not instruct ADVCY to send direct marketing unless Client has established an appropriate legal basis and all required permissions.
Where consent is required, Client must ensure it is:
- freely given;
- specific;
- informed;
- unambiguous;
- recorded; and
- capable of easy withdrawal.
Consent to contractual terms must not be treated as marketing consent. Installing a wallet pass must not, by itself, be treated as consent to unrelated marketing.
Client must promptly honour opt-outs, objections and withdrawals.
ADVCY may refuse, suspend or stop a campaign where it reasonably believes the campaign would breach applicable law, these Terms or applicable platform rules.
9. Service messages
Client may use the Services for genuine operational and administrative communications connected with an existing service, event, ticket, membership or relationship.
Client must not disguise promotional communications as service messages. Where a message contains material intended to advertise or promote an additional product, service, event, sponsor, offer or campaign, Client must assess it as direct marketing.
10. Apple Wallet
Client acknowledges that Apple Wallet change messages are intended for important or time-sensitive pass updates. Client must not instruct ADVCY to use Apple Wallet change messages for advertising, direct marketing or other non-critical communications.
Examples of appropriate update notifications may include:
- material event timing changes;
- changed access information;
- venue changes;
- gate, room or stage changes;
- cancellation information; or
- other important changes to information represented by the Pass.
ADVCY may prevent a Client communication from being sent through an Apple Wallet change message where it reasonably believes it is promotional or inconsistent with Apple’s rules.
11. Google Wallet
Where supported, Google Wallet may permit Client to send messages that trigger notifications. Client acknowledges that:
- Google controls aspects of notification delivery and presentation;
- notification permissions are controlled by the user and Google;
- applicable Google Wallet quotas and anti-spam restrictions apply;
- links must comply with Google’s applicable rules; and
- marketing law continues to apply independently of technical capability.
ADVCY may impose lower frequency limits where reasonably necessary to protect user experience, deliverability or platform compliance.
12. Location relevance
Client may instruct ADVCY to include venue coordinates or other relevance information in a digital pass. Where Apple or Google determines on the user’s device or within its own Wallet service whether the Pass is nearby, ADVCY will not represent this as ADVCY collecting the user’s precise location unless location information is actually returned to ADVCY.
13. Precise location processing
Client must not instruct ADVCY to collect, receive, store or profile precise or live location information unless the processing has been expressly agreed.
Before activating such functionality, Client must:
- identify the purpose;
- establish an appropriate lawful basis;
- satisfy any applicable PECR requirements;
- provide clear just-in-time information;
- obtain separate consent where required;
- specify retention;
- identify third-party recipients;
- assess security risk; and
- complete any legally required DPIA.
ADVCY may require evidence of this assessment before enabling the functionality.
14. Pass verification
Where a Pass is used for access, redemption or verification, Client may permit authorised parties to verify it. Client must ensure that every third-party verifier has an appropriate legal and contractual basis for receiving relevant information.
ADVCY will, where reasonably practicable, design verification to minimise the information disclosed. A verifier should normally receive only what is needed to determine matters such as:
- validity;
- entitlement;
- status;
- redemption;
- relevant event;
- checkpoint; or
- other information necessary for verification.
Client must not require unnecessary contact, conversational or profile information to be exposed to scanners.
15. Children
If Client intends to offer a Service to children or knows that children are likely to use it, Client must inform ADVCY before launch.
The Parties will assess appropriate safeguards, including where relevant:
- age-appropriate design;
- transparency;
- profiling;
- marketing;
- parental involvement;
- data minimisation; and
- DPIA requirements.
16. Special category data
Client must not intentionally supply or instruct ADVCY to collect special category personal data unless this is expressly included in the agreed Services.
Client is responsible for establishing an applicable Article 6 lawful basis and Article 9 condition where required.
17. AI functionality
ADVCY may use third-party or proprietary AI functionality to provide the Services. Unless expressly agreed otherwise:
- Client Personal Data will only be used to provide, secure and support the Services;
- ADVCY will not sell Client Personal Data;
- ADVCY will not use Client Personal Data to train a public foundation model;
- significant automated decisions will not be introduced without appropriate assessment; and
- the relevant subprocessor arrangements are governed by the DPA.
AI-generated outputs can be incorrect. Client is responsible for determining where human review is appropriate for high-impact information.
18. Client Content
“Client Content” means content supplied, approved or made available by Client, including:
- names;
- trademarks;
- logos;
- photographs;
- artwork;
- event information;
- schedules;
- sponsor content;
- promotional material;
- text;
- databases; and
- other materials.
Client retains ownership of Client Content.
Client grants ADVCY a non-exclusive, worldwide, royalty-free licence during the Agreement to host, copy, adapt, format, transmit, display and otherwise use Client Content solely as reasonably necessary to provide the Services.
Client warrants that it has all rights and permissions necessary for ADVCY to use Client Content in this way.
19. ADVCY intellectual property
ADVCY retains all right, title and interest in:
- the ADVCY platform;
- source code;
- APIs;
- software;
- infrastructure;
- workflows;
- prompts;
- templates;
- systems;
- documentation;
- know-how;
- models developed by ADVCY;
- methodologies; and
- technology.
Except for rights expressly granted under the Agreement, no ADVCY intellectual-property rights transfer to Client.
20. Licence to Client
During the Agreement, ADVCY grants Client a limited, non-exclusive, non-transferable licence to access and use the Services for the purposes set out in the Order Form.
Client may allow authorised employees, contractors and service providers to use the Services on its behalf. Client remains responsible for their compliance with the Agreement.
21. Restrictions
Client must not:
- reverse engineer the Services except where law expressly prevents restriction;
- attempt to circumvent security controls;
- resell the Services unless agreed;
- use the Services unlawfully;
- send malicious code;
- interfere with platform operation;
- use the Services to harass or unlawfully discriminate;
- use ADVCY to send unlawful spam;
- impersonate another organisation; or
- use the Services in a way likely to cause ADVCY to breach applicable platform rules.
22. Client Data
As between ADVCY and Client, Client retains all rights in Client Data.
ADVCY may use Client Data only:
- to provide the Services;
- on Client’s documented instructions;
- to secure and support the Services;
- where necessary to comply with law; and
- as otherwise expressly permitted by the Agreement.
23. Anonymised data
ADVCY may create genuinely anonymised and aggregated information from use of the Services where individuals are no longer identifiable.
ADVCY may use genuinely anonymised information to:
- measure product performance;
- improve ADVCY;
- understand usage patterns;
- benchmark services; and
- produce aggregated industry insight.
ADVCY will not intentionally re-identify genuinely anonymised data.
24. Security
ADVCY will maintain technical and organisational measures appropriate to the risk, including as relevant:
- encryption in transit;
- appropriate encryption at rest;
- least-privilege access;
- authentication controls;
- secrets management;
- logging and monitoring;
- secure development practices;
- backup and recovery;
- vulnerability management;
- incident response; and
- subprocessor controls.
Further information is available at advcy.ai/data-protection.
25. Confidentiality
Each Party will:
- protect the other Party’s Confidential Information using reasonable care;
- use it only in connection with the Agreement; and
- disclose it only to people who need it and are subject to appropriate confidentiality obligations.
Confidentiality obligations do not apply to information that:
- is lawfully public;
- was lawfully known without restriction;
- is independently developed;
- is lawfully received from a third party; or
- must be disclosed by law.
26. Subprocessors
Client gives ADVCY general authorisation to use subprocessors to provide the Services. ADVCY will:
- maintain an up-to-date subprocessor list;
- impose appropriate data-protection obligations on subprocessors;
- remain responsible for subprocessor performance to the extent required by applicable law; and
- provide a mechanism for Client to receive notice of material new subprocessors.
Further terms appear in the DPA. The current list is published at advcy.ai/subprocessors.
27. Third-party platforms
The Services may depend on third-party platforms including:
- Apple;
- Google;
- Meta;
- messaging platforms;
- telecommunications providers;
- cloud platforms;
- ticketing providers; and
- Client-selected integrations.
ADVCY is not responsible for an interruption or restriction caused by a third-party platform outside ADVCY’s reasonable control. Client acknowledges that third-party platform terms, functionality and APIs can change.
28. Availability and offline operation
ADVCY will use reasonable skill and care to provide the Services. Unless a specific SLA is included in an Order Form, ADVCY does not guarantee a particular percentage uptime.
For clarity:
- Installed Pass availability — an already-installed pass may remain available on a supported device when that device is offline.
- Connected functionality — pass issuance, new downloads, updates, verification, analytics, notifications and dynamic functionality may depend on network and third-party availability.
An offline Pass should therefore not be interpreted as evidence that ADVCY’s live platform is available.
Scheduled maintenance, emergency maintenance and failures of third-party services outside ADVCY’s reasonable control are excluded from any availability commitment unless expressly agreed otherwise.
29. Pass loss, theft and misuse
Client is responsible for establishing its commercial policy for:
- lost devices;
- stolen devices;
- transferred passes;
- duplicated credentials;
- compromised passes; and
- replacement or reissue.
Where technically supported, ADVCY may provide revocation or reissue functionality. ADVCY cannot guarantee prevention of unauthorised use before a compromised Pass is identified and revoked.
30. Fees
Client will pay the fees specified in the Order Form.
Unless stated otherwise:
- fees are exclusive of VAT;
- invoices are payable within the period stated on the invoice or Order Form;
- usage above agreed allowances may be charged at the applicable rate; and
- third-party pass-through charges may be invoiced where specified.
31. Taxes
Client is responsible for applicable taxes other than taxes imposed on ADVCY’s net income.
32. Suspension
ADVCY may suspend affected Services where reasonably necessary to:
- address a security threat;
- prevent unlawful activity;
- prevent abuse;
- comply with law;
- comply with a platform requirement; or
- address material overdue payment following reasonable notice.
Where reasonably practicable, ADVCY will limit suspension to the affected functionality.
33. Warranties
Each Party warrants that it has authority to enter into the Agreement.
ADVCY warrants that it will provide the Services with reasonable skill and care.
Except where expressly stated and to the extent permitted by law, other implied warranties are excluded.
34. ADVCY IP indemnity
ADVCY will defend Client against a third-party claim that Client’s authorised use of the ADVCY proprietary Services infringes that third party’s UK intellectual-property rights and will pay damages finally awarded or settlements approved by ADVCY.
This does not apply where the claim results from:
- Client Content;
- Client instructions;
- unauthorised modification;
- combination with technology not supplied or approved by ADVCY; or
- continued use after ADVCY has provided a reasonable non-infringing alternative.
ADVCY may modify or replace affected functionality or terminate it and refund prepaid unused fees where a commercially reasonable alternative is not available.
35. Client indemnity
Client will defend ADVCY against third-party claims arising from:
- Client Content infringing third-party rights;
- unlawful Client instructions;
- Client’s failure to obtain required marketing permission;
- Client’s unlawful supply of Client Personal Data;
- Client’s unauthorised use of third-party trademarks or content; or
- Client’s material breach of applicable law through use of the Services.
This indemnity does not apply to the extent a claim was caused by ADVCY’s breach of the Agreement.
36. Excluded liability
Nothing in the Agreement excludes or limits liability for:
- death or personal injury caused by negligence;
- fraud or fraudulent misrepresentation; or
- another liability which cannot legally be excluded.
Subject to the preceding paragraph, neither Party will be liable for:
- indirect or consequential loss;
- loss of anticipated savings;
- loss of opportunity; or
- loss of goodwill,
except to the extent such loss forms part of an amount payable to a third party under an indemnity expressly given in the Agreement.
37. Liability caps
Unless an Order Form states otherwise:
General Cap
Each Party’s aggregate liability arising out of or relating to the Agreement will not exceed 100% of the fees paid or payable by Client under the Agreement during the 12 months immediately preceding the event giving rise to liability.
Enhanced Cap
Each Party’s aggregate liability for:
- breach of confidentiality;
- breach of the Data Processing Addendum; and
- the indemnities expressly provided in these Terms,
will not exceed 200% of the fees paid or payable during that 12-month period.
The caps do not apply to liability that cannot lawfully be limited.
38. Term
The Agreement begins on the date specified in the Order Form and continues for the agreed initial term.
Renewal terms, if any, will be specified in the Order Form.
39. Termination for breach
Either Party may terminate the Agreement if the other Party materially breaches it and, where the breach can be remedied, fails to remedy the breach within 30 days after receiving written notice.
Either Party may terminate immediately if the other becomes insolvent or ceases business, subject to applicable insolvency law.
40. Effect of termination
On termination:
- Client’s right to use the Services ends;
- outstanding amounts become payable;
- each Party will return or delete Confidential Information where appropriate; and
- Client Personal Data will be dealt with according to the DPA.
Clauses intended by their nature to survive termination will continue.
41. Force majeure
Neither Party is liable for failure or delay caused by events outside its reasonable control. This can include:
- widespread internet outages;
- telecommunications failure;
- third-party cloud outages;
- government action;
- natural disaster;
- war;
- civil disturbance; or
- widespread platform failure.
The affected Party must take reasonable steps to mitigate the effect.
42. Assignment
Neither Party may assign the Agreement without the other’s prior written consent, not to be unreasonably withheld.
Either Party may assign the Agreement as part of a bona fide corporate reorganisation, merger, acquisition or sale of substantially all of the relevant business, provided the assignee is capable of performing the Agreement.
43. Notices
Contractual notices must be sent to the contact identified in the Order Form or another address notified in writing.
44. Entire agreement
The Agreement constitutes the entire agreement relating to its subject matter and supersedes prior discussions relating to that subject matter.
Nothing excludes liability for fraud or fraudulent misrepresentation.
45. No partnership or agency
Nothing in the Agreement creates a partnership, joint venture or agency relationship between the Parties.
46. Third-party rights
Unless expressly stated, no person other than the Parties has a right to enforce the Agreement under the Contracts (Rights of Third Parties) Act 1999.
47. Severability
If a provision is held invalid or unenforceable, the remaining provisions continue in effect.
48. Governing law
The Agreement is governed by the laws of England and Wales.
The courts of England and Wales have exclusive jurisdiction.