Terms of Service

The agreement between the operating company and a customer using Treica.

Last updated 2026-07-28

Awaiting counsel review.

This document is not legal advice and has not yet been reviewed by a qualified lawyer. Anything shown as "to be supplied" is a value the operating company has yet to provide, and is left visible rather than guessed. Statements about how the product behaves are drawn from the implementation and are accurate.

Agreement

These terms govern use of Treica, provided by Sodasoft LLC, 30 N Gould St, Sheridan, WY 82801, the United States ("we"). By creating or using a workspace you accept them on behalf of your organisation. Anything shown as "to be supplied" is a value the operating company must complete before this document is relied on.

The service

Treica is software that helps a financial entity build and maintain a DORA Register of Information and an ICT third-party governance programme. It performs deterministic validation, produces submission packages, and records an audit trail.

Treica is a tool, not a regulatory filing agent and not a provider of legal, regulatory or audit advice. You remain responsible for the accuracy and completeness of what you record, for the decisions you take, and for filing with your competent authority.

Plans

Every plan includes the whole of what makes a filing correct: all 15 reporting tables and all 120 columns, the full deterministic ruleset, the submission package and filing history, evidence and its integrity verification, the audit trail, and closing the findings validation raises. Plans differ by how many reporting entities a firm has and by the depth of governance around the register - never by whether a submission can be made correctly.

Treica Assist, the AI add-on, is separate from all plans. Nothing required to meet a regulatory obligation depends on it, or on being on a larger plan.

Fees, billing period and notice are set out in your order form and are denominated in EUR. Subscriptions run for a minimum term of 12 months and are not cancellable monthly. Plan prices are published on our website. Where a plan's scope is open-ended the published figure is a starting point rather than the price, and the figure in your order form then depends on the number of reporting entities and the scope of implementation. Implementation is quoted separately against a written scope.

Your responsibilities

  • Keep credentials and API keys confidential, and revoke them when a person or system no longer needs access.
  • Only load data you are entitled to load, and only grant access to people entitled to see it.
  • Use roles and external-auditor grants so that access matches need.
  • Verify any AI-generated suggestion before acting on it.

Acceptable use

You must not attempt to access another customer's workspace, probe or bypass the isolation controls without our written authorisation, upload malicious content, use the service to breach the law, or resell access without agreement.

Automated access must go through the public API using an issued key and must respect the fair use limits described in the Fair Use Policy.

Data and confidentiality

You retain all rights in the content you load. We process it only to provide the service, as described in the Privacy Policy and any data processing agreement between us.

On termination you may export your data. After the period stated in your agreement we will delete or return it.

Rights we grant you under DORA Article 30

You are a financial entity subject to Regulation (EU) 2022/2554 and we are one of your ICT third-party service providers. These clauses give you the contractual rights that regulation requires you to hold, so that your own register can record them truthfully.

  • Access, inspection and audit (Article 30(2)(e)): you, an auditor you appoint, and your competent authority have unrestricted rights of access to, inspection of, and audit of us in relation to the service. We will cooperate fully. These rights are not limited in frequency or scope, and we will not charge for exercising them. Where a full on-site audit is disproportionate, we will agree an alternative assurance method with you, but the right itself is yours to exercise.
  • Information on request: we will provide, at no cost, the information you need to fulfil your own obligations - our sub-processor chain, the locations at which data is processed and stored, our security measures, and our own business continuity and exit arrangements.
  • Sub-outsourcing conditions (Article 30(2)(a) and 30(3)(a)): we will not sub-outsource any part of the service supporting a critical or important function without telling you in advance. Our sub-processors are published at /legal/subprocessors, we will publish an addition before it takes effect, and you have thirty days to object on reasonable grounds. If we cannot resolve your objection you may terminate the affected service without penalty and receive a refund for the unused period. We remain fully responsible for anything a sub-processor does.
  • Service locations (Article 30(2)(c)): the regions in which the service is provided and in which data is processed and stored are stated at /legal/subprocessors, and we will not move them without notifying you first.
  • Incident notification (Article 30(2)(g)): we will notify you without undue delay, and in any event within twenty-four hours of becoming aware, of any incident materially affecting the service or the security of your data, with what we know at that point. We will keep you informed as it develops and will provide the information you need for your own regulatory reporting, including under Article 19.
  • Assistance at no additional cost (Article 30(2)(g)): where an ICT incident relating to the service affects you, we will assist you at no additional cost, or at a cost agreed in advance.
  • Termination (Article 30(2)(f) and 30(3)(f)): you may terminate on written notice if we materially breach applicable law or a regulatory requirement, if circumstances arise that alter the performance of the service including a material change in sub-outsourcing, if there are demonstrated weaknesses in our management of ICT risk, or if your competent authority can no longer effectively supervise us because of the arrangement. You are not required to state a reason of any other kind, and no termination fee applies in these cases.
  • Exit and data return (Article 30(3)(f)): on notice of termination we will continue to provide the service for a transition period you choose of up to six months, on the same terms, so that you can migrate without disruption. Throughout, and for thirty days after the end, your register content, evidence and audit trail remain exportable in full through the interface and the API in open, machine-readable formats. Nothing in our arrangement depends on a proprietary format you cannot read elsewhere.
  • Service levels (Article 30(3)(c)): where your order form states an availability target and support response time, they are contractual and measured monthly. Where it does not, none is committed, and we say so rather than implying one.
  • Business continuity and testing (Article 30(3)(d)): we maintain and test business continuity and disaster recovery arrangements for the service and will share the results of that testing with you on request.
  • Participation in your resilience testing (Article 30(3)(e)): where you are required to include us in threat-led penetration testing or other resilience testing, we will cooperate and participate fully.

Availability and support

We aim for high availability. Any committed availability target and support response time is set out in your order form. We do not publish a separate service level document; if your order form does not state one, none is contractually committed, and we would rather say so than point at a page that promises something we have not agreed.

Warranties and liability

The service is provided without warranty that it will make you compliant or that a submission will be accepted by an authority. Deterministic checks reduce error; they do not replace your own review.

To the extent permitted by law, our aggregate liability under this agreement is limited to the fees paid under this agreement in the twelve months preceding the claim, denominated in EUR. This limit does not apply to: death or personal injury caused by negligence; fraud or fraudulent misrepresentation; wilful misconduct and gross negligence; breach of confidentiality obligations; any liability that cannot be limited or excluded by law, including a data subject's rights under Article 82 of the GDPR.

Termination

Either party may terminate as set out in the order. We may suspend a workspace immediately where use threatens the security or integrity of the service, and will tell you why.

Governing law

These terms are governed by the law of Ireland, with the courts of Ireland having exclusive jurisdiction.