These Terms are intended to be read with the specific Order and other documents actually agreed for a service. References to a feature do not mean it is available, included or approved for every use.
Mandatory rights come first. Nothing here excludes a legal duty, remedy or right that cannot lawfully be waived.
01Who we are, scope and acceptance
1.1 The contracting company#
ISIKKO is a brand operated by WIMD Technologies Private Limited, an Indian company. References to ISIKKO, the Company, we, us or our mean that legal entity, and do not automatically include a payment partner, travel supplier or independently operated vendor. The company and reporting details appear in the Contact and complaints section of this document.
1.2 Who these terms cover#
These Terms govern authorised use of the ISIKKO public website, Resources, travel directory and, when incorporated into an accepted Order, the ISIKKO business software and related services. Some provisions apply only to paying Clients, Vendors, API users or particular modules, as indicated. Merely reading the public website does not create a paid subscription, payment mandate or exclusive business relationship.
1.3 Meaningful acceptance#
An authorised person must accept the applicable version through an explicit acceptance step, a signed Order or another legally valid agreement before a paid service is supplied under these Terms. That person represents that they have authority to bind the Client. We may keep proportionate evidence of the accepted version, date, account and acceptance event. A preselected checkbox or silence alone is not an affirmative purchase instruction.
1.4 Existing agreements and non-waivable rights#
Publication of a new version does not, by itself, amend a previously signed agreement, retrospectively change a completed booking or waive an accrued claim. These Terms do not restrict rights or remedies that applicable law does not permit the parties to exclude, including applicable consumer, privacy, payment-dispute and regulatory rights. Business-only provisions do not automatically apply to a Traveller acting as a consumer.
1.5 Acceptance records and incorporated terms#
Before acceptance, the Company must make the applicable version and incorporated documents reasonably accessible for review and retention, identify the contracting entity and material charges, and draw attention to any business arbitration and liability provisions. An acceptance record should identify the Client, authorised person, Order, document version, acceptance method and time, with proportionate technical evidence of the event. Accessing an API or an authenticated page may implement an already accepted Agreement, but is not by itself conclusive proof that a person agreed to previously undisclosed terms. Neither an automatically generated record nor a preselected control substitutes for legally valid authority and assent.
02Definitions and interpretation
2.1 Client#
The legal person that accepts an Order for Services. A sole proprietor contracts in their own legal capacity. An employee or representative accessing a Client account is an Authorised User and is not automatically the contracting Client.
2.2 Vendor#
A travel agent, tour operator, accommodation provider, transport or fleet operator, destination management company or other business that lists, sells, arranges or fulfils its own goods or services using the Platform. A Vendor may also be a Client.
2.3 Traveller and User#
Traveller means a person making an enquiry, booking or payment for travel services, or the person for whom a booking is made. User means anyone using a relevant ISIKKO website, account or function. These descriptions do not determine a person's statutory consumer status.
2.4 Authorised User and Affiliate#
An Authorised User is an individual the Client permits to use its account within the purchased scope. An Affiliate is a legal entity controlling, controlled by, or under common control with the Client. Control means the ability to direct management or policies. Affiliate access is permitted only when the Order includes it; an unrelated franchisee, hotel, agent or contractor is not automatically an Affiliate.
2.5 Platform and Services#
Platform means the ISIKKO websites, applications, interfaces and related systems that we operate. Services means the software access, implementation, support, API access, integration or professional work expressly included in an accepted Order. A product description or roadmap is not itself an Order.
2.6 Order and Agreement#
Order means an accepted order form, subscription checkout, statement of work, work order or module schedule that identifies the parties and purchased scope. Agreement means the Order, the version of these Terms incorporated into it and any applicable addenda actually made available and accepted by the parties.
2.7 Client Data and Personal Data#
Client Data means information, records, files, images, configurations and other content submitted by or for the Client for processing through the Services. Personal Data means information relating to an identifiable individual, including information treated as personal or sensitive personal data by applicable law. Neither description removes the rights of the individuals concerned.
2.8 Payment Partner and Travel Supplier#
Payment Partner means a bank, acquiring institution, authorised payment aggregator, payment gateway, card network or other payment provider involved in a transaction. Travel Supplier means the person responsible for providing the booked travel service. Their identities and roles must be clear in the relevant checkout, booking terms or payment schedule.
2.9 Security Incident and Confidential Information#
Security Incident means a confirmed or reasonably suspected compromise affecting the confidentiality, integrity or availability of relevant systems or data, including unauthorised access, disclosure, alteration, loss or disruptive misuse. Confidential Information has the meaning and exclusions in the Confidentiality section. Routine blocked attempts do not necessarily amount to a personal-data breach, but may require investigation.
2.10 Other expressions#
DPA means a data processing addendum actually agreed between the parties. SLA means an expressly agreed service level agreement. Business Day means a day other than Saturday, Sunday or a public holiday at the Company's registered office in India. Unless stated otherwise, days are calendar days; headings aid navigation and do not replace the operative clauses. References to law include applicable amendments and commencement provisions.
2.11 Credentials and Platform Records#
Credentials means passwords, session identifiers, access and refresh tokens, API keys, signing secrets, private cryptographic keys, certificates and other authentication or authorisation material. Platform Records means system-generated activity logs, transaction references, timestamps, usage measurements, administrative events, diagnostics and security records. A record may contain Client Data or Personal Data; describing it as a Platform Record does not remove the rights or safeguards applicable to that information.
2.12 Transaction Fees and external services#
Transaction Fee means a Company service fee calculated by a billable event or usage unit expressly defined in the Order, such as an eligible booking, request, message or signature. It is distinct from Traveller funds and a Payment Partner's charges. An external service is a separately supplied bank, gateway, network, cloud, communications, identity, supplier or other service used with the Platform. A provider acting on our behalf remains subject to our applicable provider-management responsibilities.
03Contract documents and order of priority
3.1 Documents must exist and be accessible#
No undisclosed DPA, SLA, policy, price list or third-party agreement is incorporated merely because it is mentioned here. Before acceptance, the Client must receive or be able to access the relevant documents. A Privacy Policy explains personal-data handling; it is not a substitute for the commercial Agreement or for a DPA where one is required.
3.2 Priority in a conflict#
Mandatory law prevails. Subject to it, a signed amendment prevails over the provision it expressly changes; an agreed DPA governs a conflict about processing Personal Data; an agreed payment schedule governs the specific payment arrangement; an agreed SLA governs its expressly committed service levels; and an Order's expressly negotiated terms prevail over these general Terms for their subject matter. These Terms govern remaining matters. Neither party's purchase-order boilerplate overrides an accepted Agreement unless expressly agreed.
3.3 Scope, affiliates and subcontractors#
The Client is responsible for use by its Authorised Users and permitted Affiliates within its control, and must communicate relevant obligations to them. Access for an Affiliate does not create a separate licence or increase usage allowances. A reseller or contractor may bind the Company only within authority expressly given by the Company; statements by an unauthorised intermediary do not amend the Agreement.
3.4 No automatic exclusivity#
The relationship is non-exclusive unless a separate, lawful and specifically negotiated provision says otherwise. The Client may use other services. It must not share its credentials, resell access or transfer an account outside the agreed scope. No general restriction on competing services is created by these Terms.
04Services, implementation and product changes
4.1 What is included#
The Order must identify the purchased modules, permitted accounts or users, implementation responsibilities, dependencies, support scope, delivery assumptions and charges. Demonstrations, sample screens and general marketing descriptions do not promise that every feature, integration or payment method is included. The Client should raise any essential requirement before acceptance.
4.2 Implementation and custom development#
The parties will cooperate on agreed implementation milestones. The Client must provide timely and lawful data, decisions, access and approvals reasonably needed for the work. Custom development, migrations, acceptance criteria, ownership of bespoke deliverables and additional work require a written scope. A delay caused by an unmet dependency may require a documented revision to the plan and, if agreed, charges; silence does not authorise unlimited billable work.
4.3 Changes and supported versions#
We may maintain, patch and improve the Services. Except for urgent security, legal or third-party changes, we will give reasonable notice of a material change requiring Client action. We will not use a routine update to materially reduce an expressly purchased core function during a prepaid committed term without providing an equivalent alternative or addressing termination and any refund due under the Agreement. Supported API versions and deprecation dates must be communicated through the applicable documentation or notice.
4.4 Preview and forthcoming features#
Trials, beta features and preview integrations must be identified as such and may have additional limitations stated before use. Do not use them for production payments or sensitive records unless expressly approved for that use with appropriate safeguards. A coming-soon reference, including to messaging or electronic-signature products, does not create a release-date commitment. Optional functionality is governed by this Agreement only when actually enabled and lawfully supplied.
05Eligibility, onboarding and business verification
5.1 Authority and age#
A person opening a business account or accepting an Order must be at least eighteen years old and legally capable of entering the Agreement. The Client must have the registrations, authority and permissions needed for its business and for the proposed use. A booking may include a minor Traveller, but that does not authorise a minor to create an independent business account.
5.2 Accurate verification information#
The Client must provide accurate business identity, ownership, authorised-signatory, contact, tax and bank details reasonably required for onboarding, fraud prevention or applicable partner and legal requirements. We may request proportionate supporting evidence and verify it through lawful sources. Additional payment-partner KYC or merchant underwriting may be required; an ISIKKO account or directory listing is not a guarantee of payment approval.
5.3 Changes, impersonation and access disputes#
Promptly update changes in ownership, authorised contacts, licences, bank accounts or business status. Do not impersonate another business, conceal a prohibited activity or provide altered verification documents. We may pause a sensitive change or account recovery while reasonably checking authority. Where competing parties claim an account, we may preserve records and restrict changes until reliable authority or a binding direction resolves the dispute.
5.4 Data minimisation in verification#
Provide verification documents only through an approved collection method, and only to the extent needed. Do not send full card details, passwords, one-time codes or unnecessary identity records through email, public forms or support messages. Where a legally accepted masked or alternative document is sufficient, unnecessary identifiers should not be collected.
06Account access and Client security responsibilities
6.1 Named users and least privilege#
Use individual authorised accounts and the minimum permissions needed for each role. Do not share administrator credentials or permit unrelated businesses to operate through the Client's account. Review access periodically and remove it promptly when a person changes role, leaves the business or no longer needs it. The Client must control the contractors and integrations it authorises.
6.2 Credentials and authentication#
Protect passwords, API keys, recovery codes, devices and email accounts used for authentication. Enable multi-factor authentication where available, and comply with additional authentication controls required for the purchased service. Never disclose a one-time password, UPI PIN, card PIN or recovery secret to a person claiming to be ISIKKO support. Password reuse, shared mailboxes and unreviewed browser extensions increase account risk.
6.3 Devices, networks and delegated access#
Maintain supported software, security updates and proportionate endpoint protections on systems used to access the Services. Secure local exports and restrict remote-support access. A consultant, marketing agency or software provider given access by the Client must comply with the relevant confidentiality and security obligations. The Company remains responsible for its own personnel and service providers as required by the Agreement and law.
6.4 Sensitive actions and compromise#
Review recipient, amount, booking, refund, bank-account and permission changes before approving them. Use independent verification for unusual payment or bank-change requests rather than relying only on the message that requested the change. Notify us without undue delay of suspected account compromise, revoke exposed access where possible and preserve relevant evidence. Responsibility is allocated according to cause, control, the Agreement and law; use of a credential is not irrebuttable proof that every action was authorised.
6.5 Additional verification and recovery#
We may require re-authentication, multifactor authentication, token expiry or additional authority checks for account recovery, administrator changes, data exports, refunds or other high-risk actions. A recovery request does not authorise bypassing tenant boundaries or transferring control to an unverified claimant. The Client must keep recovery channels secure, promptly remove compromised sessions and cooperate with proportionate verification. We will not request disclosure of a password or one-time payment authentication code as a condition of support.
07Vendor, booking and Traveller responsibilities
7.1 The underlying travel service#
Unless an accepted Order or booking expressly identifies the Company as the supplier, the Vendor or named Travel Supplier provides and is responsible for the underlying travel service. The Vendor must disclose who contracts with the Traveller and who handles fulfilment, cancellation and complaints. Providing software does not by itself make ISIKKO the tour operator, hotel, transport operator, insurer or guarantor of a supplier's performance. This allocation does not displace any duty imposed on ISIKKO by its actual role or applicable law.
7.2 Accurate offers and informed purchase#
The Vendor must keep descriptions, availability, inventory, eligibility, material restrictions, taxes, compulsory charges and total prices accurate. Before purchase, disclose cancellation, refund, rescheduling, no-show, delivery or fulfilment conditions and the responsible contact. Do not create false scarcity, fabricate reviews, conceal fees, preselect paid extras or use misleading comparisons. A displayed discount must have an honest basis.
7.3 Confirmation and operational checks#
An enquiry, quote, payment attempt or provisional reservation is not necessarily a confirmed booking. Confirmation depends on the disclosed supplier and payment conditions. The Vendor must reconcile inventory, supplier acknowledgements, payments and changes, and promptly resolve duplicate bookings, stale prices, failed confirmations and overselling. Travellers should review names, dates, destination, eligibility and booking conditions before confirming.
7.4 Licences, safety and lawful fulfilment#
The Vendor is responsible for its required travel, accommodation, vehicle, driver, insurance, tax and other business authorisations; the safety and suitability of its services; and accurate representations about those matters. Visa, entry, health, baggage and travel-document requirements must be checked with the relevant authorities or supplier. ISIKKO does not provide emergency assistance unless separately contracted. Immediate safety threats should be reported to the appropriate emergency authority.
7.5 Customer information and records#
Collect only information reasonably needed for the booking or another lawful, disclosed purpose. Obtain authority to enter information for other Travellers and the necessary parent or guardian permissions for children. Record customer instructions, acceptance, invoices, delivery evidence and changes accurately and retain them only as required. Do not use a booking or directory enquiry as unrestricted permission to market, sell data or disclose identity documents.
7.6 Vendor disclosures and customer care#
Where required for its role, the Vendor must supply its correct legal and trading names, geographic address, customer-care and grievance details, applicable registration or licence particulars, and material sales conditions for display before a Traveller commits. It must keep those disclosures current and maintain a usable complaint process after fulfilment or account closure. Visa or foreign-exchange services may be offered only with the authority required for that activity. A listing, account or integration does not grant that authority or transfer the Vendor's underlying service obligations to ISIKKO.
08Fees, billing, taxes and disputes
8.1 Agreed charges#
The applicable Order must state subscription, implementation, usage, transaction and other charges, including what is included and what attracts additional fees. Unless agreed otherwise, Company invoices are in Indian Rupees and payable within fifteen days after receipt. Charges for the Company's software are distinct from Traveller funds, supplier charges and charges imposed by Payment Partners.
8.2 Taxes and lawful deductions#
Fees are exclusive of applicable GST and other transaction taxes unless expressly stated as inclusive. The Client must provide correct invoicing and tax details and pay applicable taxes other than taxes on the Company's own income or payroll. Any withholding required by law may be made with timely remittance and the appropriate certificate. A contractual payment clause does not require either party to disregard a statutory withholding obligation.
8.3 Invoice disputes#
Notify us of a good-faith billing discrepancy within ten Business Days of receipt where reasonably possible, with the invoice reference, disputed amount and explanation. Pay undisputed amounts when due, and cooperate in reconciliation. Missing that administrative period does not automatically waive a legal claim, an error discovered later or a right that cannot be waived. We will not knowingly recover the same charge twice.
8.4 Overdue amounts#
Contractual interest or late charges apply only at the rate clearly specified in the accepted Order, and only to the extent lawful; these Terms create no unstated percentage or automatic penalty. We may give notice and use the payment-breach process before suspending for undisputed overdue amounts. Reasonable recovery costs may be claimed only where recoverable under the Agreement and law. Mandatory statutory interest rules, where applicable, remain unaffected.
8.5 Third-party charges and price changes#
Usage-dependent gateway, messaging, hosting, domain or other third-party charges must be disclosed through the Order or an accepted change. We will distinguish an agreed resale price from a charge expressly represented as reimbursement at cost. No undisclosed markup, retroactive rate increase or open-ended automatic pass-through is authorised by this clause. Prospective renewal prices and cancellation choices must be communicated before a renewal becomes binding.
8.6 Billable events and itemised usage#
For transaction or usage pricing, the Order must define the billable event, unit, rate, billing period, minimum commitment if any, and treatment of failed, duplicate, retried, cancelled, refunded or reversed events. A bank authorisation, captured payment, settled payment and booking are not interchangeable units. Invoices should identify the agreed fixed charges, usage quantities, rates, applicable taxes and adjustments with sufficient information for reasonable reconciliation. Monthly itemisation applies where that billing arrangement is agreed. Platform Records may support measurement but do not conclusively defeat reliable evidence of an error or authorise an undefined charge.
8.7 Platform fees, customer refunds and approved credits#
A refund of the Vendor's travel charge does not automatically reverse a Company service fee already properly earned under an agreed billing rule. Conversely, an event that is not billable under that rule must not be charged merely because a Traveller paid. Discretionary credits, rebates or fee waivers must be recorded by an authorised Company representative with their scope and conditions; an informal third-party promise is not sufficient. This does not make a mandatory refund, correction or remedy depend on discretionary approval.
09Subscriptions, cancellation and software-fee refunds
9.1 Term and renewal#
The subscription start date, committed term, billing cycle and any renewal mechanism must be stated in the Order. Automatic renewal or recurring debit requires a clear prior agreement and any legally required mandate, notice and cancellation facility. Silence does not create a new recurring payment mandate. Turning off renewal ordinarily stops the next renewal, rather than cancelling charges already properly accrued.
9.2 Voluntary cancellation#
A Client may request cancellation through the agreed account or support channel. For a clearly disclosed prepaid business licence, voluntary cancellation or non-use ordinarily does not create a pro-rata refund during the committed term unless the Order says otherwise. This does not permit charges for an unaccepted renewal, a duplicate or erroneous payment, or a service that we are legally required to refund.
9.3 Company breach or withdrawal#
If the Client validly terminates because of our uncured material breach, or we discontinue the purchased service for convenience during a prepaid term without an equivalent agreed replacement, the Client is entitled to the unused prepaid portion for the affected service, subject to any more favourable mandatory remedy. Separately delivered and accepted implementation work is not automatically refundable merely because an ongoing subscription ends.
9.4 Refund requests and timing#
Send the invoice or transaction reference, amount and reason through the contact channel. We will assess the request, explain the outcome and communicate the processing period. Approved refunds will be initiated without undue delay and within applicable legal or payment-partner timelines, normally to the original payment method; an alternative requires a lawful, verified arrangement. We cannot guarantee the time another bank takes to display a credit.
9.5 No blanket exclusion of remedies#
Nothing here excludes a refund or other remedy required by consumer law, a court, regulator, applicable payment rules or an express written commitment. Travel-booking refunds are distinct from software-subscription refunds and follow the disclosed supplier conditions and mandatory law. An early-termination amount is recoverable only if specifically agreed, proportionate and legally recoverable; describing it as liquidated damages does not automatically make a penalty enforceable.
10Payment services, authorisation and fund flow
10.1 Identify the actual arrangement#
Before enabling a payment flow, the applicable payment schedule and checkout must identify the merchant, Payment Partner, payee, settlement arrangement, charges and responsible complaint channel. The parties must use only a lawfully approved arrangement. These Terms do not authorise the Company to aggregate, hold, lend, invest or settle customer funds where a regulatory authorisation or different agreement is required.
10.2 No implied regulated status#
A payment integration or use of the word payments does not represent that ISIKKO is a bank, an RBI-authorised payment aggregator, a wallet issuer, a lender, an escrow trustee or an insurer. The Company's actual activities determine its legal responsibilities. No regulatory approval, deposit insurance, guaranteed settlement or guaranteed recovery is implied by a dashboard, payment link, directory profile or marketing description.
10.3 Partner terms and merchant approval#
Payment acceptance may require a separate merchant agreement, KYC, underwriting, transaction restrictions and compliance with the Payment Partner's rules. A partner may reject, delay, reverse or investigate a transaction in accordance with its agreement and law. We do not promise that every Vendor, payment mode, currency, card, geography or transaction will be accepted. The Vendor must not conceal its activity or process for unapproved third-party merchants.
10.4 Authenticating and verifying payments#
Use the approved hosted checkout or other authorised method. Never upload card security codes, PINs, one-time codes, full magnetic-stripe data or payment passwords into ISIKKO fields, logs, notes, chats or APIs. Do not treat a screenshot, browser redirect or unverified callback as proof of final payment. Confirm status through the designated server or Payment Partner record before fulfilling a booking, and reconcile failures, reversals and duplicates.
10.5 Fraud, cross-border and prohibited use#
Do not use the Platform for fictitious sales, money laundering, unauthorised collections, cash advances disguised as purchases, sanctions evasion or other unlawful transfers. Cross-border transactions may be enabled only within an approved arrangement and applicable foreign-exchange and trade rules. We may request transaction evidence, apply proportionate safeguards or restrict suspicious functionality. These measures do not guarantee fraud detection and do not excuse the Company's own legal duties.
10.6 Status labels and direct-settlement arrangements#
Payment labels in the Platform report the relevant workflow or provider status; a displayed balance is not necessarily a deposit held by ISIKKO, and paid does not by itself prove final settlement. Where the approved partner agreement provides for direct settlement, the Payment Partner settles to the Vendor's verified account under that agreement, while the Company's own fees follow the separately accepted billing arrangement. This clause describes how such an arrangement must operate; it does not establish that every enabled payment flow uses it. The checkout and payment schedule must accurately disclose the actual flow, responsible entities and any permitted exception before use.
11Booking refunds, chargebacks and settlement disputes
11.1 Customer-facing responsibility#
The Vendor must operate a fair cancellation and refund process consistent with its disclosed booking terms and law, and give Travellers a usable complaint channel. It must not refuse a legally required refund merely because a supplier or intermediary is involved. ISIKKO will assist with information or technical action within its agreed role; the relevant merchant and Payment Partner remain responsible for their own obligations.
11.2 Evidence and response#
Keep accurate booking confirmations, customer authorisations, invoices, cancellation communications and fulfilment evidence. Respond to a chargeback or refund enquiry within the applicable partner deadline using truthful, relevant and lawfully collected information. Do not fabricate evidence, harass a complainant, require withdrawal of a lawful complaint as a condition of a refund, or resubmit a disputed charge without authority.
11.3 Reserves, recovery and adjustments#
Any rolling reserve, settlement hold, debit, set-off or recovery from merchant funds must be supported by the specific payment agreement and law, with the relevant basis and procedure disclosed where permitted. These general Terms grant no unrestricted right to seize Traveller funds or treat them as the Company's revenue. Incorrect or duplicate adjustments must be investigated and corrected. Refunds, reversals and claims must be reconciled to prevent double recovery.
11.4 Failed transactions and continuing rights#
A technical failure or pending status may require partner or bank reconciliation rather than a second payment. The User should retain the reference and report the issue through the designated channel. This Agreement does not shorten a cardholder's, bank customer's or consumer's statutory or scheme-based dispute period, prevent contact with a bank or regulator, or transfer another party's legal responsibility to the Traveller.
12APIs, webhooks and third-party integrations
12.1 Authorised scope#
Use documented interfaces only for the Client's authorised business purpose and within the purchased permissions, rate limits and usage allowances. Do not bypass tenant boundaries, enumerate other customers' records, misrepresent identity, share a master key with unrelated businesses or expose administrative tokens in browser code, public repositories or mobile applications. Possession of an identifier or URL does not confer access rights.
12.2 Secure implementation#
The party building an integration must protect its credentials and endpoints, validate incoming data, enforce appropriate access checks and keep dependencies maintained. Where supported or required by the integration, verify webhook signatures, timestamps and replay protection; use encrypted transport; apply least-privilege permissions; and rotate or revoke exposed secrets. A successful HTTP response alone is not proof of a valid booking, authorised refund or settled payment.
12.3 Retries, duplicates and synchronisation#
Build transaction-sensitive integrations to handle retries, timeouts, duplicate messages, ordering changes and partial failure. Use the documented idempotency and reconciliation mechanisms where provided. Check the authoritative state before repeating a payment, booking or cancellation. The Client must test its own integration and monitor data mapping, inventory synchronisation and error handling; we remain responsible for the interfaces and obligations we expressly supply.
12.4 External accounts and permissions#
Connecting another provider authorises the data exchange and actions described in the connection flow, not unlimited access for unrelated purposes. The Client must have authority to connect that account, review requested permissions and disconnect access when no longer needed. External providers may change or discontinue their services. Their own terms and privacy practices govern their independent services; we must still take reasonable care in selecting and managing providers acting on our behalf.
12.5 Limits and automated cost#
Respect documented resource limits and restrictions on bulk export, crawling, message volume, compute and storage. Unexpected automation can cause excessive usage charges or affect other customers. We may rate-limit or isolate abusive traffic proportionately, notify the Client where practicable, and help identify the source. Additional charges require the applicable agreed pricing; an attack does not create an automatic right to bill arbitrary amounts.
12.6 Binding instructions to the correct record#
An integration must validate that the tenant, account, booking, customer, currency, amount and transaction reference belong together before it changes a material record or initiates an action. Validate authority on the server; a client-supplied identifier, redirect parameter or successful request is not an independent authorisation. Keep request and response secrets out of ordinary logs, restrict outbound destinations where appropriate, and reconcile asynchronous events against the authoritative record. The party implementing these controls remains responsible within its actual scope; this clause does not certify an untested integration.
13Acceptable use and prohibited conduct
13.1 Lawful, honest use#
Use the Services lawfully and in a manner that respects others' rights. Do not submit fraudulent bookings, unlawful offers, misleading business information, stolen content, forged documents or material that you do not have authority to process. Do not facilitate prohibited financial activity, exploitation, harassment, discrimination contrary to law, threats, doxxing or unlawful disclosure of personal information.
13.2 Protecting systems and other users#
Do not introduce malicious code, perform unauthorised scanning or exploitation, interfere with availability, attempt credential stuffing, defeat authentication, exfiltrate data, alter audit records or access another tenant's information. Do not evade a suspension through another account or disguise malicious traffic as normal use. Approved security testing must follow the separate testing provisions below.
13.3 Restrictions on copying and automation#
Do not reverse engineer, decompile or circumvent technical protection except where an applicable law grants a right that cannot be excluded. Do not reproduce or resell the software, systematically extract protected datasets, harvest contact information for unsolicited outreach, or use automation to imitate users deceptively. Ordinary search indexing and attributed summarisation of public pages remain permitted within lawful access, published crawler rules and applicable intellectual-property rights; this permission does not extend to private accounts or Personal Data harvesting.
13.4 Content affecting safety and identity#
Do not upload unlawful sexual content, child sexual abuse material, non-consensual intimate imagery, malicious impersonation, unlawful synthetic media or instructions intended to facilitate illegal harm. Preserve legally required labels or provenance on synthetic material and make truthful disclosures where required. We may restrict content or accounts and respond to competent authorities in accordance with the moderation, incident and legal-process provisions; no restriction prevents a lawful complaint or protected disclosure.
13.5 Examples of prohibited technical abuse#
Without specific written authorisation for a defined security assessment, prohibited interference includes the following conduct when directed at systems, information or actions the person is not authorised to access or test. This list clarifies the restrictions above; it does not remove a non-excludable legal right or prohibit ordinary permitted use.
- Credential stuffing, password spraying, brute force, session hijacking, token replay, impersonation or privilege escalation.
- SQL or NoSQL injection, command or template injection, cross-site scripting, unsafe deserialisation, server-side request forgery, path traversal, file inclusion or remote-code execution.
- Forging or tampering with host headers, origin checks, callback parameters, webhook signatures, payment references or refund instructions to obtain an unauthorised result.
- Cross-tenant enumeration, extraction or modification; interception of confidential traffic; or use of another person's credentials or signing material.
- Denial of service, traffic flooding, queue or storage exhaustion, cryptomining, ransomware, backdoors or malicious file uploads.
- Deletion, falsification or evasion of audit logs, evidence, rate limits, bot protections or other access and integrity controls.
14ISIKKO application and platform security obligations
14.1 Risk-based safeguards#
For systems and processing under our control, we will maintain reasonable technical and organisational safeguards appropriate to the information, service and risks involved, and comply with applicable security law and any expressly agreed controls. Safeguards must be reviewed as threats and the service change. This is a contractual responsibility, not a statement that software can be made immune to every attack or that the Client assumes all security risk.
14.2 Access and tenant boundaries#
Safeguards should address authentication, least-privilege access, administrative access review, logical separation of customers, secure session handling and controlled support access. Our personnel should access Client Data only when authorised for support, operations, security, legal compliance or another agreed purpose, and be subject to confidentiality obligations. A shared infrastructure model does not authorise access across customer accounts.
14.3 Secure development and maintenance#
Our security programme must address secure configuration, validation of untrusted input, authorisation of object and business-function access, dependency and vulnerability management, secret handling, change control and appropriate testing. We will assess reported vulnerabilities and prioritise remediation according to risk and impact. No specific patch deadline, penetration-test frequency or technical implementation is promised unless expressly agreed or legally required.
14.4 Data and operational protection#
Safeguards must address appropriate protection of data in transit and at rest, backup and recovery arrangements, detection of relevant security events, evidence preservation and incident response. The applicable DPA or security schedule should describe material controls and any agreed data location, retention or recovery requirement. We will not materially reduce agreed protection during the term without a lawful basis and appropriate notice or agreement.
14.5 Evidence, certifications and limitations#
An ISO standard, SOC report, PCI standard, OWASP reference, payment-partner integration or security statement is not a claim that ISIKKO holds a certification, passed a particular audit or provides a specified assurance unless we supply current evidence identifying its scope. A public website review does not certify separate payment, identity or vendor applications. The Client should obtain the appropriate evidence before relying on a particular security or regulatory requirement.
14.6 Protective monitoring and sensitive security information#
Subject to applicable privacy law and disclosed purposes, we may analyse proportionate login, IP, device, request, API, administrative and transaction metadata to investigate misuse and protect the Services. We may apply traffic filtering, access challenges, rate limits and other proportionate controls without disclosing detection thresholds, exploitable findings, private keys or another tenant's information. We will provide appropriate assurance through controlled summaries or other suitable evidence where required. Protection of sensitive security information does not excuse a legally required notification, disclosure or lawful regulatory audit.
15Security incidents, fraud reports and cooperation
15.1 Report promptly and safely#
Notify the designated security contact without undue delay when you become aware of a suspected compromise affecting the Services, credentials or relevant data. Include the affected account or service, approximate time, observed behaviour and a safe contact method. Do not send passwords, authentication codes, full payment credentials or unnecessary personal records. An urgent report need not wait for a complete forensic investigation.
15.2 Containment and notification#
We will assess credible reports, take proportionate containment and remediation measures within our control, and notify an affected Client without undue delay when a Security Incident affecting its data or service requires notification under law or the Agreement. Information may be supplied in stages as facts become available. Notifications should describe the known nature, impact, measures taken and actions the Client should consider, subject to lawful restrictions and protection of other users.
15.3 Independent legal duties#
Each party must make its own required regulatory, law-enforcement, individual or payment-partner notifications within the applicable deadlines. Contractual approval, confidentiality, an incomplete investigation or a partner's response does not extend a statutory deadline. The parties will reasonably cooperate, but neither may appoint itself as the other's legal representative or publicly attribute responsibility without a reliable basis. This does not restrict truthful legally required reporting.
15.4 Evidence and account restrictions#
Preserve relevant logs, transaction references and communications securely, limit access to those who need them, and avoid unnecessary copying of affected data. We may revoke keys, reset sessions, restrict an integration, pause a risky action or isolate affected functionality where reasonably necessary. Where lawful and practicable, we will explain the restriction and restoration requirements. Incident costs and liability follow the Agreement, causation and law, not an automatic presumption against either party.
16Responsible disclosure, security testing and audits
16.1 Good-faith reporting#
We welcome good-faith reports of suspected vulnerabilities through the designated security contact. Describe a reproducible issue using the least intrusive evidence reasonably needed. If you unexpectedly encounter another person's data, stop accessing it, do not copy or disclose it unnecessarily, and report the exposure promptly. A vulnerability report is not permission to access additional records or demand payment.
16.2 Testing requires an agreed scope#
Obtain written approval before intrusive testing, automated vulnerability scanning, exploitation, social engineering, credential attacks, load testing or testing an integration beyond your own authorised account. Approval must identify assets, methods, timing and limits; it does not authorise testing a Payment Partner or another third party. We do not promise a bounty or reward unless an applicable programme expressly provides one.
16.3 Coordinated disclosure#
Please allow a reasonable opportunity to investigate and coordinate publication of technical details so that users are not exposed unnecessarily. This request does not prevent reporting to regulators, law enforcement, professional advisers or other disclosures protected by law. We will not threaten proceedings solely because a person makes a lawful, good-faith vulnerability report; unauthorised harmful conduct is a separate matter, and we cannot bind another organisation.
16.4 Customer and regulatory assurance#
Reasonable requests for security assurance may be met through questionnaires, control summaries or available independent reports under confidentiality restrictions. An on-site or technical audit requires an agreed scope that protects other customers and service availability, unless law grants broader access. These arrangements must not obstruct a regulator's lawful access or a non-waivable audit right. A custom audit or remediation engagement requires an agreed commercial scope.
16.5 Client compliance information#
We may request information reasonably necessary to assess suspected misuse, an incident, a binding regulatory request or a material security concern affecting the Services. Requests must be proportionate to the issue and protect unrelated Client information; they do not authorise us to enter or test the Client's systems without permission. The Client must respond honestly and reasonably cooperate. Any broader inspection, intrusive test or separately chargeable assurance work requires a lawful basis and an agreed scope.
17Privacy, processing roles and lawful data use
17.1 Separate purposes and responsibilities#
The Company's Privacy Policy must explain its own collection and use of information, such as business contacts, account administration, website enquiries and security records. Where we process Traveller or other Personal Data on a Client's instructions, the parties must document their respective roles, purposes and obligations. Describing a party as a processor does not remove duties imposed by its actual decisions or applicable law.
17.2 Instructions and a DPA#
Before processing Personal Data on the Client's behalf where an additional arrangement is required, agree a DPA or appropriate processing schedule. It should identify the subject matter, duration, data categories, affected individuals, documented instructions, permitted providers, safeguards, assistance, transfers, incident reporting, return or deletion and audit rights. These Terms do not represent that an unattached DPA already exists or that a vague reference supplies missing details.
17.3 Authority, transparency and minimisation#
The Client must have a lawful basis and provide required notices for data it asks us to process, including customer, employee, driver and representative data. Obtain consents or other authorisations where required, keep suitable evidence, and respect changes or withdrawal where applicable. Submit accurate data only for a necessary, disclosed purpose. These Terms are not blanket consent from Travellers or authority to sell, profile or market to them.
17.4 Children and restricted information#
Do not knowingly enable an unauthorised child account or process children's information without the applicable parent or guardian safeguards. Do not upload sensitive identity, health, biometric, financial or other high-risk information into a module not approved for that purpose. Where such information is necessary for a lawful travel function, the parties must agree proportionate safeguards and collection limits. Full card credentials and payment authentication secrets remain prohibited.
17.5 Providers, locations and assistance#
We may use appropriately contracted providers for the agreed service, subject to applicable law and the DPA. Material provider, transfer and location arrangements must be disclosed as required and assessed against any agreed restriction. We do not promise that all data remains in India unless that has been expressly agreed and verified. The parties will reasonably assist each other with lawful access, correction, deletion, consent, grievance and other data-rights requests without exposing another person's information.
17.6 Applicable law and permitted use#
Each party must comply with privacy and data-protection requirements applicable to its role and in force at the relevant time, including applicable Information Technology Act requirements and the Digital Personal Data Protection Act and rules as their relevant provisions commence. We will not use identifiable Client Data for unrelated advertising, sale or external model training without separate lawful authority and required transparency. A contractual allocation cannot waive an individual's statutory rights or a regulator's powers.
18Records, logs, retention and legal holds
18.1 Purpose-based retention#
Retention must follow the relevant purpose, applicable law, the Privacy Policy, the DPA and the purchased service, rather than an assumption that all information can be kept indefinitely. Different periods may apply to operational data, financial records, security logs, consent evidence, support cases and backups. The parties must document the applicable schedule and implement access restrictions for retained information.
18.2 Security and statutory records#
Where applicable, the Company and Client must meet requirements for secure logging, clock synchronisation, evidence preservation and prescribed storage locations, including relevant CERT-In directions. Statutory or regulatory retention may continue after account cancellation or a deletion request. A minimum retention requirement for a particular record does not justify retaining unrelated information or keeping it available for general marketing.
18.3 Legal holds and disclosure#
We may preserve specifically relevant records when required by law, a binding request, an actual dispute or a reasonably anticipated legal claim, subject to necessity and appropriate safeguards. We may disclose information in response to valid legal process, limiting disclosure to its lawful scope. Where permitted, we will notify the affected Client. Confidentiality does not prevent required cooperation with a competent authority.
18.4 Backups and deletion limits#
Deletion from active systems may not immediately remove a record from protected backups, where a documented rotation cycle applies. Retained backup copies must remain protected, not be used for unrelated purposes and be deleted or overwritten through the applicable cycle unless law requires preservation. We will explain any applicable retention exception rather than represent that information has been deleted from systems where it is still lawfully retained.
18.5 Integrity of electronic evidence#
The parties may rely on relevant Platform Records as evidence of acceptance, instructions, access, transactions or communications, subject to applicable evidentiary requirements. Preserve the original record or a reliable reproduction, relevant version and timestamp, source and extraction information, and a traceable account of material corrections or transfers where necessary. When producing electronic evidence, the responsible party must meet any applicable certificate, authenticity, integrity or other requirement, including under the Bharatiya Sakshya Adhiniyam, 2023 where it applies. These Terms do not make a log conclusive, create an irrebuttable presumption of authority, or determine admissibility in place of the competent court or tribunal.
19Confidentiality and permitted disclosure
19.1 Protected information#
Confidential Information includes non-public business, financial, customer, technical, security, product and operational information disclosed in connection with the Agreement that is identified as confidential or should reasonably be understood to be confidential. It includes non-public Client Data, credentials, security findings and negotiated commercial terms. Personal Data remains subject to applicable privacy obligations whether or not marked confidential.
19.2 Exceptions#
Information is not confidential to the extent the recipient can show that it was already lawfully known without restriction, independently developed without use of the disclosed information, received lawfully from a third party without a confidentiality duty, or made public without the recipient's breach. Approval to disclose one item is not approval to disclose unrelated information.
19.3 Protection and limited use#
Use the other party's Confidential Information only to perform the Agreement, exercise lawful rights or meet legal obligations. Protect it with reasonable care, and at least the care used for comparable information of your own. Share it only with personnel, permitted Affiliates, advisers and service providers who need it and are bound by appropriate duties. Each party remains responsible for persons under its control as provided by law and the Agreement.
19.4 Compelled disclosure and duration#
A recipient may make a legally required disclosure, with prior notice where lawful and practicable and disclosure limited to what is required. Confidentiality continues after termination for as long as the information remains confidential; trade secrets remain protected while they qualify as trade secrets. Return or destruction is subject to lawful retention and backup limits, and must not obstruct protected disclosures, statutory complaints or regulatory investigations.
20Intellectual property, Client Data and public content
20.1 Company and licensor rights#
The Company and its licensors retain their rights in the Platform, software, documentation, designs, methods and general improvements, except for rights expressly transferred by a signed agreement. Subject to the Agreement, the Client receives a limited, non-exclusive right to access and use purchased Services for its permitted business purposes during the term. Payment of a subscription does not transfer source code or ownership of the Platform.
20.2 Client ownership and service licence#
The Client and its licensors retain their rights in Client Data, branding and supplied materials, subject to individuals' rights in Personal Data. The Client grants only the permissions reasonably needed to host, process, transmit, display, secure and support those materials for the agreed service and lawful retention. The Company receives no general right to sell the Client's data, publish private records or exploit its brand for unrelated promotion.
20.3 Public listings and trademarks#
When the Client requests a public listing, website or campaign, it authorises display of the supplied content and marks for that purpose and represents that it has the necessary rights. Use of a Client logo as a customer endorsement, case study or unrelated advertisement requires separate approval. Either party must stop unauthorised use and cooperate on correction or removal of infringing material.
20.4 Feedback, statistics and third-party materials#
We may use voluntarily supplied product feedback to improve the service without an obligation to purchase the suggestion, but this does not transfer ownership of underlying Client Data or permit disclosure of confidential information. Reporting based on aggregated or anonymised service data must not reasonably identify the Client, its staff or Travellers, or permit their re-identification. Third-party and open-source materials remain subject to their applicable licences.
20.5 Resources and infringement reports#
Public Resources provide general information, not individual legal, tax, financial or travel-safety advice. Lawful quotation, linking and attributed summarisation do not authorise wholesale republication of protected material or misuse of a person's data. An infringement report should identify the claimant, protected work or right, relevant URLs, basis of authority and requested action. We will assess credible reports under applicable law and the moderation process.
20.6 Operational records and permitted processing#
The Company retains its rights in its diagnostic methods, software-generated technical arrangements and proprietary know-how, subject to embedded Client Data, Personal Data and lawful access rights. No blanket ownership claim over every log or generated business record overrides those rights. We may format, cache, index, resize, transmit and display Client materials only as reasonably needed for the agreed service or the public listing or campaign the Client authorised. Separate promotional use, data sale or model-training rights are not granted by an operational processing permission.
21Messaging, marketing and social-platform connections
21.1 Only enabled and authorised services#
Messaging, campaign, social-publishing or contact-import functions apply only when the relevant module and integration are actually enabled. The Client must have authority to connect the sender identity, business account, phone number, domain or social page. A connection to WhatsApp, LinkedIn or another provider does not imply that the provider endorses ISIKKO or will approve the Client's account, campaign or content.
21.2 Consent and communication preferences#
The sender must obtain the notices, permissions, consents, sender registrations and approved templates required for the channel, purpose and jurisdiction, and maintain appropriate evidence. Honour opt-outs and applicable do-not-disturb preferences. For regulated SMS or voice campaigns, meet applicable TRAI and telecom requirements. Publicly available contact information, a purchased list or a past booking is not unrestricted permission for promotional outreach.
21.3 Channel rules and truthful messages#
Comply with the provider's current business, messaging, advertising, commerce and developer policies, including permitted content, identity, message categories, approved templates, sending windows, data-use restrictions and pricing. Do not use misleading sender identities, fake urgency, unlawful claims or automation designed to defeat a restriction. The Company may refuse or pause an unlawful campaign; the Client remains responsible for claims and recipient permissions it supplies.
21.4 Delivery and privacy#
Delivery, display, reach and engagement depend in part on networks, recipient settings, provider approval and reputation controls, and are not guaranteed unless expressly agreed. Service-related notices are distinct from optional promotional messages. Do not place unnecessary sensitive data in a message or send it to an unverified recipient. An enabled communications function is not a replacement for the sender's published privacy notice or the recipient's legal rights.
22Automation, AI-assisted features and electronic records
22.1 Human responsibility for consequential actions#
Where an automated or AI-assisted feature is enabled, the Client must use it within its disclosed purpose and keep appropriate human review over consequential actions, including pricing, customer commitments, payments, refunds, access grants and legal documents. Do not allow an agent to operate outside the permissions and approval limits you intend. Recommendations, summaries and generated content can be incomplete, inaccurate or unsuitable.
22.2 Input data, confidentiality and generated content#
Do not submit information to an external AI or automation provider without authority and an assessment of its data practices. We must disclose relevant external processing and obtain the authorisations required by the Agreement and law. The Client must verify generated claims, rights, dates, calculations and translations before use. Preserve required synthetic-content disclosures; do not create deceptive impersonations or conceal information that must be labelled.
22.3 No implied professional advice or training permission#
Automated outputs do not provide a legal opinion, compliance certification, audit assurance, credit decision or guarantee of a commercial result. Enabling a feature does not, by itself, authorise us to use identifiable Client Data to train an external general-purpose model. Any such separate use requires an express arrangement, an appropriate lawful basis and required notices or consents.
22.4 Electronic signatures and evidence#
Any electronic-signature module applies only when released and separately enabled. Suitability depends on the document, signature method, identity checks, authority, stamping, registration and applicable law; not every instrument may be executed electronically. Do not assume that a click, scanned signature or automated output meets every legal requirement. Electronic records and audit trails may support evidence, but their admissibility and weight are determined under applicable law, not conclusively by these Terms.
22.5 Signing authority and tamper protection#
A person using a signing workflow must have authority for the relevant party and document. Do not sign in another person's name without authority, misuse a signing certificate, disclose private signing material, replace the agreed document after execution or falsify an audit trail. A correction or amendment should preserve the original version and follow a lawful, traceable approval process. The parties must satisfy applicable stamping, witnessing, registration and electronic-evidence requirements; a workflow status or completion certificate does not itself establish that every such requirement has been met.
23Directory listings, reviews and content moderation
23.1 Meaning of listings and status#
A directory entry may contain information from the business or other lawful sources. An unclaimed entry is not a verified business, and submitting a claim does not itself establish ownership. Any verification label must state or link to its actual basis and scope; it is not a guarantee of licensing, solvency, safety or service quality. Users should independently verify material facts before a transaction.
23.2 Corrections, reviews and paid placement#
A business may request correction or removal of inaccurate or unlawfully published information, subject to proportionate verification and applicable rights. Reviews must reflect genuine experience and disclose material incentives where required. We may reject fabricated or abusive submissions and identify sponsored placement appropriately. Payment must not be represented as independent verification or an undisclosed favourable ranking.
23.3 Reports and decisions#
Report allegedly unlawful, infringing, impersonating or otherwise prohibited content with the relevant URL, explanation and safe supporting evidence. We may assess, restrict, remove, preserve or restore content according to the facts, applicable law and the affected parties' rights. Where appropriate and lawful, we will give reasons and a way to seek review. We must act within any applicable statutory timetable, including shorter urgent-content deadlines; an internal review is not a basis to ignore them.
23.4 Intermediary status is not blanket immunity#
Any legal protection for hosting third-party information depends on the applicable law, the Company's actual role and compliance with required conditions. These Terms do not create immunity for our own conduct or guarantee that every listing or submission is lawful. Moderation discretion must not be used to suppress a lawful complaint, compel a false review or defeat mandatory rights.
24Availability, support, backups and force majeure
24.1 Service levels must be agreed#
Support hours, response targets, availability commitments, maintenance notice, recovery objectives and service credits apply only as stated in an agreed SLA or Order or required by law. We will perform our agreed obligations with reasonable care and skill. A marketing reference to secure, reliable or available services does not by itself promise uninterrupted operation, a particular uptime percentage or a fixed disaster-recovery outcome.
24.2 Operational resilience#
We and the Client must maintain continuity arrangements proportionate to our respective responsibilities. The Client should keep appropriate independent business records and a practical fallback for urgent operations, especially where network access is unavailable. The Company's backup arrangements do not remove its own recovery duties or guarantee recovery of every version. Any agreed backup, restore, export or retention requirement must be documented, tested as appropriate and matched to the purchased service.
24.3 Maintenance and third-party disruption#
We may carry out planned or urgent maintenance and will give reasonable notice where practicable. An external dependency may fail or change, but we remain responsible for commitments we have undertaken and the reasonable management of providers acting for us. A credit is the exclusive remedy for a service-level miss only if clearly agreed and legally effective; it cannot exclude a non-waivable remedy or automatically excuse another material breach.
24.4 Events outside reasonable control#
A party is excused from affected performance only to the extent an event beyond its reasonable control prevents it despite reasonable precautions and mitigation. It must notify the other party where practicable, explain the impact and work to restore performance. An avoidable security failure, lack of reasonable maintenance or ordinary financial difficulty is not automatically force majeure. Payment for Services already properly supplied remains due; charges for unavailable future performance are addressed under the Agreement and law.
24.5 Prolonged interruption#
If a qualifying event materially prevents the affected Services for more than thirty consecutive days, either party may terminate the affected Order by written notice. Accrued obligations, lawful refunds, return of information and continuing safeguards must be addressed fairly under the Agreement. A force-majeure clause does not permit either party to ignore mandatory security, reporting, consumer or payment obligations.
24.6 Safety-critical reliance#
Unless specifically contracted with safeguards suitable for that purpose, the Platform is not designed to be the sole control for an emergency, life-safety, vehicle-safety or other safety-critical operation. The Vendor must maintain appropriate human supervision, emergency channels and independent operational checks. This restriction does not excuse a defect, misrepresentation or duty for which the Company remains responsible under the Agreement or law.
25Suspension and termination
25.1 Proportionate suspension#
We may restrict the relevant account, action, content or service when reasonably necessary to address a credible security threat, fraud, unlawful conduct, material misuse, a binding direction or a material payment default after the applicable notice. Restrictions should be no broader or longer than reasonably needed. Where lawful and safe, we will give notice, reasons and a practical route to remedy the problem or seek review.
25.2 Breach and opportunity to cure#
Unless an Order lawfully provides otherwise, a party claiming a material breach must give written notice describing it. The breaching party has ten days after receipt to cure an undisputed payment breach and thirty days to cure another remediable material breach. If it is not cured within that period, the non-breaching party may terminate the affected Order by written notice. Immediate action remains available for a non-remediable material breach, urgent security risk or legal requirement.
25.3 Client cancellation and business closure#
The Client may request cancellation or non-renewal in accordance with the purchased term and the cancellation provisions. We may terminate where the Client ceases business or a lawful insolvency-related basis permits termination, subject to applicable insolvency protections and restrictions. Termination does not erase properly accrued charges, accepted refunds, existing customer responsibilities or either party's legal duties.
25.4 No indefinite or punitive lockout#
Where practicable and lawful, the Client should retain a secure way to obtain necessary records or resolve active transactions during a restriction. We may limit access that would create a material security, privacy or legal risk, but must not use a dispute as an unrestricted right to retain customer funds or defeat statutory data rights. Account restoration may require remediation, authority checks, payment of undisputed amounts or replacement of compromised credentials.
26Service exit, export and deletion
26.1 Plan the handover#
Before the service ends, the parties should identify active bookings, pending refunds or disputes, scheduled campaigns, integration credentials, domains and records requiring transfer. The Vendor remains responsible for its ongoing commitments to Travellers. The Company will reasonably cooperate within the agreed scope and will not represent that ending software access automatically cancels an underlying travel booking.
26.2 Access to Client Data#
Unless a different lawful arrangement is agreed, the Client may request one export of the Client Data then available in the service in a commonly used, supported format within thirty days after termination. We will provide a secure, proportionate method or explain any restriction required by law, security or another person's rights. An export need not include source code, another customer's data, internal security tooling or proprietary system metadata not part of Client Data.
26.3 Charges and disputed debt#
Ordinary supported export assistance is included unless a different price was clearly agreed in advance. Bespoke conversion, substantial transition work or extended access may require a separate accepted scope and charge. An unpaid invoice does not justify withholding information that law requires us to provide or preventing an individual from exercising non-waivable rights. Debt recovery and the lawful handling of data are separate obligations.
26.4 After export or the agreed period#
We will delete or return Client Data in accordance with the applicable DPA, retention schedule and law, subject to limited backup cycles and lawful holds. We will explain relevant exceptions on request and provide reasonable confirmation of action where agreed. The Client must remove unneeded access, rotate or revoke integrations, retain required business records securely and stop using the Services and licensed materials when its rights end.
27Warranties, responsibilities and service limitations
27.1 Mutual authority and lawful performance#
Each party represents that it has authority to enter and perform the Agreement and will comply with laws applicable to its own activities. The Client represents that it has the rights and permissions needed for materials and instructions it supplies. The Company remains responsible for the obligations it actually undertakes and for exercising the level of care required by the Agreement and applicable law.
27.2 No guaranteed business result#
We do not promise a particular increase in bookings, revenue, search ranking, advertising reach, collections, supplier acceptance or other business outcome. Analytics and recommendations depend on the quality and completeness of underlying information and should be checked before consequential decisions. Directory information and third-party content require independent verification where material.
27.3 Technical and third-party limits#
The Services cannot be guaranteed free of every error, interruption, vulnerability or malicious action. External networks, devices and providers can affect performance. Except for express commitments and non-excludable obligations, no additional implied warranty is given to the extent lawfully excludable. This clause does not excuse our breach, misrepresentation, failure to use required care or failure to meet an expressly agreed security obligation.
27.4 Mandatory remedies remain#
Nothing in these Terms makes a User assume liability for our fraud, unlawful conduct or another responsibility that cannot lawfully be shifted. Consumer guarantees, statutory refunds, data-protection remedies and applicable payment protections are preserved. A general as-is description of public information does not override a paid-service commitment or a mandatory obligation.
28Third-party claims and indemnities
28.1 Client responsibility for specified claims#
Subject to the liability provisions and applicable law, the Client will indemnify the Company against a third-party claim to the extent caused by the Client's unlawful or infringing supplied material, lack of necessary authority or consent, fraud, material misuse, unlawful data instructions, or breach of its Vendor obligations. Covered Vendor matters include attributable service non-fulfilment, unsafe service, injury or property damage, customer refund or chargeback responsibility, and missing business authorisations. The undertaking covers reasonable documented defence costs and amounts finally awarded or agreed through the defence procedure. It does not shift the Company's own breach, negligence, contribution to the loss or non-transferable regulatory duties to the Client, and a mere allegation does not establish indemnity liability.
28.2 Company intellectual-property responsibilities#
The Company must have the rights needed to supply the Services and remains responsible for its express commitments and liability under applicable law. A separate undertaking to defend or indemnify a Client against software intellectual-property claims applies only if expressly included in the accepted Order or addendum, which must identify its scope, exclusions, procedure and financial limit. These general Terms do not create an additional open-ended duty to fund every third-party claim against the Client. This does not disclaim a non-excludable infringement remedy or the Company's own contractual responsibility.
28.3 Response to an infringement claim#
If a credible infringement claim affects the Services, we may obtain continued-use rights or provide a materially equivalent lawful replacement or modification. If neither is commercially reasonable, we may terminate the affected Service and refund its unused prepaid fees, subject to any greater express or mandatory remedy. The Client must reasonably cooperate to avoid continued unlawful use after a substantiated notice and suitable instructions. These measures do not establish the claim's validity or make a refund the exclusive remedy unless that limitation is expressly agreed and legally effective.
28.4 Fair defence procedure#
The protected party must give prompt notice, reasonable cooperation and an opportunity for the indemnifying party to manage the defence with competent counsel, subject to conflicts of interest and legal requirements. Late notice reduces the undertaking only to the extent it materially prejudices the defence. No settlement may impose an admission, non-monetary duty or unreimbursed payment on the protected party without its consent. Neither party must indemnify a criminal penalty, regulatory sanction or other amount where indemnification would be unlawful.
29Allocation and limitation of liability
29.1 Application to business claims#
The contractual limitations in this section apply to claims between the Company and a Client acting for business purposes, to the extent permitted by law and subject to any expressly negotiated different limit. They do not automatically apply to a Traveller's statutory consumer claim or override obligations owed directly to a regulator, affected individual or other person under mandatory law.
29.2 Ordinary aggregate cap#
Subject to the exceptions below, each party's aggregate liability arising from or relating to the affected Order, across all claims and legal theories, will not exceed the Company service fees paid or properly payable and attributable to the affected Services for the six months immediately before the first event giving rise to the claim. If the affected Services began less than six months earlier, use that shorter period. Allocate a multi-period prepaid fee proportionately across its covered service period so annual billing does not arbitrarily remove the cap's fee base. Exclude Traveller funds, taxes and separately identified third-party pass-through amounts. Related events are treated together without multiplying the cap. This is a commercial allocation for an accepted paid business Order, not a six-month deadline to bring a claim.
29.3 Excluded categories of loss#
Subject to the exceptions below, neither party is liable to the other for indirect or consequential loss, including lost opportunity, anticipated profit or goodwill, to the extent such exclusion is lawful. A loss is not automatically indirect simply because it concerns data or a service interruption. Reasonable direct costs of investigating, containing, restoring or remedying an attributable breach remain assessable under the Agreement and applicable limit.
29.4 Matters not limited#
Nothing in the Agreement excludes or limits liability for fraud, fraudulent misrepresentation, wilful misconduct, gross negligence, death or personal injury caused by negligence, or another liability that applicable law does not permit to be limited. The cap does not reduce properly due service fees, accepted refund obligations, or an obligation to return funds or property belonging to another person. Non-waivable consumer, privacy, security and regulatory obligations remain unaffected.
29.5 Data and security claims#
There is no blanket exclusion for data breaches or cyber incidents. Liability depends on the duty, cause, contribution and applicable law. Any separate cap for confidentiality, data protection, security or indemnity must be expressly agreed, and cannot constrain a regulator's powers or an individual's non-waivable rights. Where law requires a greater remedy than these Terms permit, that law prevails.
29.6 Mitigation and no double recovery#
A claimant must take reasonable steps to limit avoidable loss, and a court or tribunal may take contributory conduct into account as law permits. A party may not recover the same loss twice through damages, a refund, service credit, insurance recovery or indemnity. Nothing makes liability depend solely on what our own logs say, deems our determination conclusive, or requires a claimant to surrender a lawful complaint.
29.7 Intentional misuse and the Vendor's own customer duties#
Subject to applicable law, the ordinary contractual cap does not protect a party from liability for deliberate credential theft, intentional cross-tenant access, deliberate tampering with payments or evidence, or knowing misappropriation of the other party's intellectual property. Accidental security failures remain assessed under the other liability provisions rather than being labelled intentional merely because an incident occurred. The Company's software-fee cap does not cap a Vendor's separate obligations to its Travellers or a Payment Partner. Any additional or different business indemnity cap must be stated in an expressly accepted schedule; it is not created by an undisclosed policy.
30Contact details, complaints and legal notices
30.1 Company and reporting details#
Use the Company and reporting contacts displayed with this section. Formal notices should identify the relevant account or Order, sender's authority, issue and requested action. A published general contact is not a claim that a particular individual has been appointed as the statutory grievance officer. The Company must keep any legally required officer, designation and contact disclosures accurate and accessible.
30.2 Complaint information and handling#
Please provide the relevant booking, invoice, transaction or content reference, a concise account of the issue and a safe reply channel. We may request proportionate verification before disclosing account information. We will acknowledge and address complaints within the timetable required by the law applicable to the complaint and our role, keep the complainant informed where appropriate, and use any shorter urgent timetable that applies. No internal escalation step extends a statutory deadline.
30.3 The right recipient#
A Traveller should also contact the named Vendor for fulfilment or booking issues, and the relevant bank or Payment Partner for payment issues within its role. This does not prevent a complaint to ISIKKO about our own service or conduct. A fraud or security emergency should use the security channel and, where appropriate, the relevant bank, law-enforcement or emergency authority. Do not wait for ordinary support to protect a compromised payment instrument.
30.4 Notices and continuing rights#
We may send account, service and Agreement notices to the authorised contact supplied by the Client or through another agreed, accessible channel, with proof of dispatch or receipt where appropriate. Keep those details current; delivery failure must not be treated as conclusive acceptance of a material change. These Terms do not stop a person approaching a consumer commission, court, regulator, law-enforcement agency or another competent body, or require a complaint to remain secret where disclosure is lawful.
30.5 Routing and proof of notices#
Where a complaint principally concerns a Vendor's travel service, we may forward the information reasonably needed to that Vendor and request a response, subject to privacy and confidentiality requirements. The complainant need not exhaust that route before using a mandatory remedy. Formal notices should be sent to the agreed notice address or, if none is specified, the Company's published registered office with a copy to its designated grievance or legal channel. Keep evidence of the notice and delivery. Electronic acknowledgement may support receipt, but a failed delivery, automated status or changed contact address is not conclusively effective notice in disregard of the Agreement or law.
Company and reporting contacts
- Legal entity
- WIMD Technologies Private Limited
- Company identification number
- U72200HR2015PTC057286
- Registered office
- J1905, AIG Park Avenue, Gaur City 1 Sector 4, West, Greater Noida, Uttar Pradesh – 201318, India
- General enquiries
- social@isikko.com
+91 88600 00832 - Grievance officer
- Himanshu Aggarwal — Grievance Officer and Chief Information Security Officer (CISO)
- Grievance contact
- himanshu@isikko.com
+91-8860000832 - Security reporting
- himanshu@isikko.com
- Payment arrangement
- Customer payments settle directly from the Payment Partner to the Vendor's verified account under the applicable partner agreement. ISIKKO's service fees are billed separately under the accepted Order.
Do not include passwords, one-time codes, full card details or unnecessary identity documents in a report. Ask for a suitable secure transfer method if sensitive evidence is needed.
31Governing law and dispute resolution
31.1 Indian law and competent forums#
The Agreement is governed by the laws of India, subject to non-waivable protections applicable to the relevant person and transaction. Courts or statutory forums with jurisdiction under applicable law remain available for matters not validly referred to arbitration. These Terms do not purport to confer jurisdiction on a court that lacks it or require every consumer or data-rights dispute to be brought in the Company's preferred city.
31.2 Good-faith discussion#
For an ordinary business-contract dispute, the parties should first send a written notice and attempt a good-faith resolution through authorised representatives for up to thirty days. This process does not prevent urgent protective relief, a mandatory complaint, or steps needed to avoid expiry of a limitation period. No statutory time limit is shortened or paused merely by this clause.
31.3 Arbitration for an accepted business Agreement#
Where a Client acting for business purposes expressly accepts an Order incorporating these Terms, including this arbitration provision, a dispute between that Client and the Company arising from the affected Agreement, including its existence, interpretation, performance, breach or termination, will be referred to arbitration to the extent legally arbitrable. A differently negotiated written dispute provision prevails. The Arbitration and Conciliation Act, 1996, as applicable and amended, governs the arbitration. Merely browsing the website, receiving an invoice or making a Traveller enquiry does not create this arbitration agreement; legally valid written or electronic acceptance and the Client representative's authority remain necessary.
31.4 Appointment and fair procedure#
The tribunal will consist of one independent and impartial arbitrator appointed by mutual agreement. If the parties cannot agree within thirty days after receipt of a valid request for appointment, or within another legally applicable period, either party may seek appointment through the process permitted by the Arbitration and Conciliation Act, 1996. Neither party has an unrestricted unilateral appointment right. The arbitrator must satisfy applicable independence, impartiality and disclosure requirements. The tribunal will determine its procedure and costs subject to that Act, the valid arbitration agreement and each party's right to a fair opportunity to present its case.
31.5 Seat, language and competent courts#
The legal seat of the business arbitration is New Delhi, India, and its language is English, unless a different written dispute provision governs. A remote hearing or a hearing at another agreed location does not by itself change that legal seat. Competent courts at New Delhi will exercise supervisory jurisdiction arising from the agreed seat, subject to any mandatory statutory allocation. For disputes outside a valid arbitration agreement, only courts or statutory forums that have jurisdiction under applicable law may act; this clause does not create jurisdiction where law provides none.
31.6 Protected remedies, award and confidentiality#
Either party may seek urgent interim or protective relief from a competent court or tribunal as permitted by law. The award is binding subject to available statutory challenge, correction and enforcement procedures. Nothing requires a Traveller or other person to surrender a non-waivable consumer, privacy, regulatory or other statutory remedy, or prevents reporting an offence. Confidentiality of proceedings remains subject to legal duties, professional advice, protection or enforcement of rights and lawful disclosures. Good-faith discussions do not suspend a statutory limitation period or require delay of a necessary protective filing.
32Changes, assignment and general provisions
32.1 Changes to these Terms#
We may propose updated Terms and publish a version and effective date. For existing paid Services, a material contractual change must follow the accepted Agreement and applicable notice or consent requirements; it is not automatically binding merely because a web page changed. Changes should operate prospectively. Where law or the Agreement requires a choice to reject, cancel or not renew, we will provide it without disguising an additional charge or removing an accrued right.
32.2 Independent parties#
The parties are independent contractors. The Agreement does not by itself create a partnership, employment relationship, franchise, fiduciary appointment or authority for one party to bind the other. A specific agency or payment role exists only where law and an express arrangement establish it. Nothing removes obligations arising from the parties' actual conduct.
32.3 Assignment and subcontracting#
Neither party may transfer the Agreement without the other's prior written consent, not to be unreasonably withheld, except to a lawful successor in a merger, reorganisation or transfer of substantially all relevant business assets that assumes the obligations. The assigning party must give appropriate notice and respect confidentiality, data-transfer and regulatory restrictions. Subcontracting an activity does not by itself release the responsible party from its obligations. An account transfer still requires authority and security checks.
32.4 Entire agreement and specific amendments#
The accepted Agreement records the parties' understanding of its subject matter and replaces prior proposals on that same matter only to the extent lawfully agreed. A material amendment must be made through an authorised written or legally valid electronic process. No entire-agreement clause excludes liability for fraud or another non-waivable representation, and a marketing statement cannot override a specifically agreed commitment.
32.5 Severability, waiver and interpretation#
If a provision is unenforceable, it is restricted or severed only to the extent necessary, and the remaining provisions continue where legally possible. Failure to exercise a right promptly is not a general waiver; a waiver must relate to the particular right and circumstances. English is the working language of these Terms and any English Agreement, but legally required language access, disclosures and interpretation protections are not excluded.
32.6 Electronic copies and survival#
Agreements may be executed in legally permitted counterparts and retained electronically with appropriate integrity and access safeguards. Clauses intended to operate after expiry continue to the extent necessary, including accrued payment and refund duties, confidentiality, intellectual property, lawful record retention, data return, indemnities, liability and applicable dispute provisions. Survival does not create a perpetual right to use Personal Data for a new purpose.
