Skip to main content
MentiSec MentiSec
Services Insights About Contact
ET EN
Services Insights About Contact
ET EN
— Legal —

General Terms and Conditions

Version 2.0·Effective from 18 July 2026

The Estonian version of these terms is the legally binding text; this translation is provided for convenience.

01 General

These terms govern the relationship between MentiSec OÜ (registry code 17454509, "MentiSec") and the client ("Client") in connection with the use of mentisec.ee, enquiries, and the provision of services. Project-specific written agreements — scope, deadline, price, liability, warranty — are recorded in a written offer and/or contract, which take precedence over these terms.

02 Scope of services

MentiSec provides:

1. Analysis services — system and business analysis, integration pre-analysis, and security-aware requirements work, delivered as documents, models, recommendations and analyses.

2. Bounded development and migration work — software development, integration and migration work of a scope agreed in writing in advance, for example database-backed web applications, API integrations, and data migration with validation and handover. The exact scope, acceptance criteria, and warranty, support and hosting boundaries of such work are fixed in the offer (see sections 06–07).

Penetration testing, red-team work and deep technical security audits are not MentiSec's own services; where needed, specialised partners are engaged under their own terms, of which the Client is informed beforehand. Where scope, criticality or support needs exceed MentiSec's current capacity, partner involvement is agreed in the offer.

03 Offers and contract formation

A website enquiry is not a binding order but an invitation to negotiate. MentiSec issues a written offer stating assumptions, scope, deadline and price. The contract is concluded when the Client accepts the offer in a form enabling written reproduction (e-mail suffices).

04 Obligations of the parties

MentiSec shall: perform with due professional care; keep the Client's business secrets confidential also after the engagement; and notify the Client without delay of any obstacle to meeting a deadline.

The Client shall: provide reasonable access to the people, documents, systems and environments needed for the work; for development and migration work, make agreed test data and test environments available a reasonable time before testing; answer questions within a reasonable time; and pay invoices when due.

If Client-side delays in providing input extend the project, the effect on schedule and price is agreed in writing before work continues.

05 Fees and invoicing

Fees are agreed in the offer as a fixed price or on a time basis. Prices exclude VAT unless stated otherwise. Default invoicing: 50% advance on start, 50% on handover; monthly invoicing for longer projects. The payment term is 14 days; late interest up to 0.1% per day. If the Client is more than thirty (30) calendar days in arrears, MentiSec may suspend work until payment, having notified the Client in writing.

06 Delivery and acceptance

1. Work is delivered when MentiSec submits it to the Client together with the agreed handover documentation.

2. The Client reviews the work against the agreed requirements within ten (10) working days of delivery, notifying defects in writing with sufficient detail to reproduce them.

3. Acceptance may be refused only for material defects. Minor defects that do not prevent the intended use of the work do not justify refusal; MentiSec remedies them under warranty within an agreed period.

4. Work is deemed accepted when: (a) the Client confirms acceptance; (b) the Client raises no substantiated objections within the period in 06.2; or (c) the Client takes the work into production use.

5. For divisible work, partial acceptance may be agreed, recording the list of defects and the effect on invoicing and warranty.

6. Risk of accidental loss of or damage to the work passes to the Client on acceptance.

07 Warranty (development and migration work)

1. MentiSec warrants development and migration work for twelve (12) months from acceptance, unless agreed otherwise in the offer. Under warranty, MentiSec remedies non-conformities with the agreed requirements free of charge.

2. The warranty does not cover: (a) faults caused by incorrect use, use contrary to the documentation, or damage caused by the Client or a third party; (b) problems arising from the Client's data-entry errors or from inputs of integrated systems where the agreed input validation is in place; (c) faults arising from uncoordinated changes to integrated systems; (d) later changes to requirements and new development needs; (e) defects of third-party components whose correction is outside MentiSec's control.

3. If an issue reported as a warranty case proves to fall outside the warranty, the diagnostic time is billable at the hourly rate fixed in the offer; MentiSec informs the Client before starting billable work.

4. MentiSec responds to a critical defect (the work is unusable or data is at risk) no later than the next working day and begins remedying it at the earliest opportunity. Deadlines for remedying other defects are agreed case by case based on impact.

5. The warranty terminates early if the source code has been modified by or on behalf of the Client without MentiSec's approval.

6. Continuing support, maintenance or availability obligations arise only under a separate written agreement. The Client is responsible for the production environment, hosting and operations unless agreed otherwise in the offer.

08 Intellectual property

1. Documents and artefacts created for the Client (requirements documentation, process descriptions, models, threat models, etc.) pass into the Client's ownership after payment of the final invoice.

2. For software created specifically for the Client, MentiSec: (a) assigns to the Client all economic copyrights; and (b) grants the Client an irrevocable, transferable and sublicensable exclusive licence, worldwide and for the full term of protection, to exercise the licensable rights in respect of the author's moral rights. The assignment and licence take effect upon full payment of the final invoice; until then the Client holds a simple licence to use the software for testing. During the warranty period MentiSec holds a simple licence to use and modify the software for the purpose of fulfilling its warranty obligations.

3. MentiSec retains the right to reuse general-purpose methodologies, templates, components and libraries created before or independently of the project that contain no Client confidential information.

4. Open-source and third-party component licences remain in force; material components and their licence references are listed in the handover documentation. Software is handed over with documented source code.

5. If a claim is brought against the Client alleging that the contractual use of the work infringes a third party's intellectual property rights, MentiSec shall, at its own cost, either contest the claim, replace the disputed part with a functionally equivalent one, or refund the fees paid for that part.

09 Confidentiality

All information exchanged between the parties in connection with a project is confidential. The obligation applies during the engagement and for five (5) years after it ends. A separately concluded NDA prevails.

10 Personal data

Where personal data is processed in the course of the services, the parties determine their roles (controller or processor) and ensure processing in accordance with the GDPR. Where MentiSec processes personal data on the Client's behalf as a processor, the parties conclude a data processing agreement (DPA). See also the privacy policy.

11 Liability

1. A party is liable for breach of contract in accordance with the contract and the law.

2. The parties exclude compensation for loss of profit and non-material damage; each party's total financial liability within a project is capped at the fees paid for that project. These limitations do not apply in the case of intentional breach or where the law precludes limitation of liability.

3. If delivered work does not conform to what was agreed, the Client may require the defects to be remedied free of charge; if MentiSec fails to do so within a reasonable time, the Client may use other remedies provided by law.

12 Force majeure

Non-performance is not a breach if caused by force majeure within the meaning of the Estonian Law of Obligations Act. The other party is notified without delay of the impediment and of its cessation; deadlines are extended by the duration of the impediment.

13 Termination

Either party may terminate with fourteen (14) days' written notice. In the case of a material breach, the contract may be terminated after a written warning and the lapse of a reasonable period to cure. On termination, the Client pays for work performed but not yet invoiced; sections 08–11 survive termination.

14 Governing law and disputes

Estonian law applies. Disputes are first resolved by good-faith negotiations; failing agreement, they are resolved by Harju County Court.

15 Contact

Questions about these terms: [email protected].
MentiSec OÜ · registry code 17454509 · Narva mnt 10, 10124 Tallinn, Estonia.

← Back to home
MentiSec MentiSec
Services
  • System and business analysis
  • System integration
  • Software development
  • System replacement and data migration
  • Software testing
  • Terms of reference and procurement preparation
Insights
  • Articles
Company
  • About
  • Who we fit
  • FAQ
  • Contact
  • Privacy
  • Terms
© 2026 MentiSec OÜ · Reg. code 17454509 · Tallinn, Estonia