Terms of Service
These Terms of Service govern access to and use of the TideWater intelligence platform, including the Sonar and Atlas modules, provided by TideWater.
TideWater is available by invitation to organizations. Access is granted under an agreement with the organization you belong to. By using the service you agree to these terms. If you do not agree, do not use the service.
1. The Agreement and the Parties
These terms form an agreement between the provider of TideWater, reachable at contact@tidewater-intelligence.com, and the organization that has been granted access to TideWater, together with each individual user acting on behalf of that organization.
Access is by invitation only. There is no self-service sign-up and no public pricing. Commercial terms, service levels, and any variation of these terms are agreed in writing with the customer organization. Where a signed organization agreement conflicts with these terms, the organization agreement prevails for that customer.
If you use the service as a member of an organization, that organization is responsible for your use of it and can control, suspend, or revoke your access.
2. Description of the Service
TideWater consists of two modules:
- Sonar collects content from the sources you configure, matches it against your keyword rules, and delivers alerts, translations, reports, and exports. Supported sources are Telegram channels, Bluesky profiles, and RSS or Atom feeds.
- Atlas presents collected material as a graph of messages, senders, and links, and supports saved investigations with pinned evidence and notes.
Notifications can be delivered to the dashboard, Telegram, email, webhooks, SMS, and Signal groups, depending on what your organization has enabled and what you have consented to.
The service is under active development and is currently at an alpha stage. Features may change, and behaviour described in product documentation may be adjusted as the platform evolves.
3. Access, Accounts, and Authentication
3.1 Eligibility
You must be at least 16 years old and authorized by your organization to use the service. Accounts are issued through invitation by an organization administrator.
3.2 Authentication
Sign-in uses a third-party OAuth identity provider or, where your organization has configured it, enterprise single sign-on over OIDC or SAML. Your use of those providers is governed by their own terms. Your organization may require multi-factor authentication and end-to-end encryption, with an enforcement date and a grace period.
3.3 Your responsibilities
- Keep your credentials, second factors, and recovery codes secure.
- Do not share your account. Everything done under your account is attributed to you.
- Report suspected unauthorized access to us immediately.
- Provide accurate information and keep it up to date.
3.4 Encryption keys
Where end-to-end encryption is enabled, your private key is generated in your browser and stored on your device. We cannot recover it. If you lose it, records encrypted to your key alone are unrecoverable, subject to any organization master key your organization holds.
4. Organization Customers and Administrators
Organization administrators and owners can add and remove members, assign roles, enforce security policies, view activity and security logs, configure SIEM export, set usage limits, request channel limit increases, and manage organization consents. Where end-to-end encryption is enabled, the organization holds a master key that allows it to recover its own encrypted records.
The organization is the controller for the monitoring it configures. It is responsible for deciding what may lawfully be monitored, for instructing us accordingly, and for handling requests from the people whose content it collects.
If your organization ceases to be a customer, access for its members ends and its data is handled under the retention rules in the privacy policy and the organization agreement.
5. Acceptable Use
5.1 Permitted uses
You may use the Service for:
- Lawful monitoring of public Telegram channels, public Bluesky profiles, and RSS or Atom feeds that your organization is entitled to monitor
- Open-source intelligence, situational awareness, and threat and risk monitoring
- News, media, and information-environment monitoring
- Security operations, incident response, and protective intelligence
- Research and analysis, including graph analysis of collected material in Atlas
- Internal reporting and distribution of findings within your organization, subject to your own legal obligations
5.2 Prohibited uses
You may NOT use the Service to:
- Break any applicable law, regulation, sanction, or export control
- Monitor any source your organization has no lawful basis to monitor, or process content for a purpose your organization cannot justify
- Target individuals for harassment, stalking, intimidation, doxxing, or discrimination
- Suppress, endanger, or retaliate against journalists, human rights defenders, activists, or minority groups
- Circumvent access controls, authenticate as another person, or collect content that is not publicly accessible to the connected account
- Breach the terms of Telegram, Bluesky, or any feed publisher whose content you access through the service
- Re-identify, enrich, or combine collected content in a way that is unlawful in your jurisdiction
- Resell, sublicense, or provide the service to a third party without a written agreement permitting it
- Reverse engineer the service, extract its source code, or use it to build a competing product
- Circumvent rate limits, usage caps, quotas, or any technical control
- Upload malware, attempt to disrupt the service, or probe its security without written authorization
- Use the service in a way that endangers the safety of any person
We may investigate suspected breaches and may suspend access while we do so. Serious breaches, in particular those that put people at risk, will result in termination.
6. Lawful Monitoring Obligations
The service collects content published by people who are not our customers and who have no relationship with us. That places specific obligations on you:
- You must have a lawful basis for monitoring each source you configure, and for the purpose you are pursuing.
- Where collected content reveals political opinions, religious or philosophical beliefs, ethnic origin, trade union membership, health, or sexual orientation, you must have a condition under Article 9 of the GDPR, or the equivalent under the law that applies to you, before processing it further.
- You must apply proportionality: monitor no more than your purpose requires, and stop when the purpose ends.
- You must handle requests from the people whose content you collect, including requests to access, correct, erase, or object. We will pass requests we receive to you and support you in answering them.
- You must not use the service to build evidence for, or otherwise facilitate, unlawful surveillance or persecution.
You are responsible for these obligations. We provide tooling, consent gating, retention controls, and audit logging to support you, but we cannot assess the lawfulness of your monitoring on your behalf.
7. Third-Party Platforms and Services
7.1 Source platforms
When you monitor Telegram, you must comply with the Telegram Terms of Service. When you monitor Bluesky, you must comply with the Bluesky terms and the rules of the AT Protocol host serving the content. When you monitor an RSS or Atom feed, you must comply with the terms of the publisher that operates it, including any restriction on automated retrieval or redistribution.
Source platforms can change or withdraw access at any time. We do not control them and cannot guarantee continued availability of any source.
7.2 Delivery services
SMS, email, and Signal notifications are delivered through third-party delivery services, identified in the privacy policy and the sub-processor register. Delivery is subject to the availability and terms of those services.
7.3 AI services
Translation and, where enabled, message classification run on models hosted on our own infrastructure. AI reports, briefings, keyword suggestions, and channel discovery use an external AI model provider, named in the sub-processor register. AI output is machine generated, can be wrong, and must be verified before it is relied on. Reports cite the underlying alert or source message so that verification is possible.
7.4 Endpoints you configure
Webhook endpoints, enterprise identity providers, and customer-operated graph databases are chosen and controlled by you. You are responsible for their security and for the lawfulness of sending data to them.
8. Customer Data and Content
8.1 Your configuration data
You retain ownership of the data you provide: sources, keywords, dashboards, notes, investigations, and reports. You grant us the license necessary to host and process that data in order to provide the service, and for no other purpose.
8.2 Monitored content
Content collected from Telegram, Bluesky, and RSS feeds belongs to its original authors and publishers. The service gives you access to it for your monitoring purposes only. You are responsible for respecting the rights that attach to it, including copyright and database rights.
8.3 Integrity features
Saved messages are hashed so that later modification can be detected, and earlier versions are archived when upstream content is edited. These features support evidential handling but are not a warranty of authenticity of the underlying content.
8.4 We do not train on your data
We do not use your content or your monitored material to train models, and we do not make it available to other customers.
9. Intellectual Property
The service, including its software, design, documentation, name, and marks, belongs to us and is protected by intellectual property law. You receive a limited, non-exclusive, non-transferable right to use it for the term of your organization agreement, and nothing more.
If you send us feedback or suggestions, we may use them to improve the service without obligation to you.
10. Data Protection and Data Processing Agreement
Our handling of personal data is described in the Privacy Policy, which forms part of these terms. It sets out the controller and processor roles, the legal bases, the sub-processor register, the international transfers, and the retention periods that apply.
Where we process personal data on behalf of a customer organization, we do so as a processor and act only on the documented instructions of that organization. Organization customers may request a data processing agreement, including the sub-processor register and the standard contractual clauses where they apply, by writing to contact@tidewater-intelligence.com. Where a signed data processing agreement is in place, it governs the processing and prevails over this section.
11. Commercial Terms
TideWater has no self-service purchase, no published price list, and no card payment in the product. Fees, term, renewal, and any usage allowances are set out in the agreement with your organization and invoiced under it.
Some technical limits are enforced in the product, for example AI token allowances, the number of seats in an organization, and an optional cap on monitored channels per organization. Administrators can request a change to those limits through the product, and we may approve or decline it.
For commercial enquiries, write to contact@tidewater-intelligence.com.
12. Availability, Changes, and Support
12.1 Availability
We aim for high availability but do not guarantee uninterrupted service unless a service level is agreed in your organization agreement. Planned maintenance is announced where practical.
12.2 Monitoring is best effort
Collection depends on third-party platforms, network conditions, and rate limits imposed by those platforms. Gaps can occur. A newly added source only produces alerts for content that arrives after it was added, although its earlier content may still be collected and made searchable. Do not rely on the service as the sole safeguard for a life-safety or legal-deadline dependent process.
12.3 Changes
We may modify, add, or withdraw features. Where a change materially reduces functionality your organization depends on, we will give notice under the organization agreement.
12.4 Support access
Support may request a session that shows your view of the product in order to diagnose a problem. Section 14 of the privacy policy describes how those sessions are approved, limited, and audited.
13. Disclaimers and Limitation of Liability
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW:
Where your organization agreement sets a different liability regime, that agreement controls.
14. Indemnification
You agree to indemnify us against claims, losses, and reasonable costs arising from:
- Your use of the service in breach of these terms.
- Monitoring you carried out without a lawful basis, or processing of collected content for an unlawful purpose.
- Your breach of the rights of a third party.
- Your breach of the terms of a source platform or feed publisher.
15. Suspension and Termination
15.1 By you
You may close your account at any time from account settings or by contacting us. Your organization may end its agreement in accordance with that agreement.
15.2 By us
We may suspend or terminate access where:
- These terms are breached, in particular section 5 or section 6.
- Use of the service creates a risk to a person or to the platform.
- We are required to do so by law or by a source platform.
- Fees due under the organization agreement remain unpaid.
Where practical we give notice and an opportunity to remedy. Where the risk is immediate we may suspend first and explain afterwards.
15.3 Effect
- Access ends.
- Data is deleted or anonymized under the retention rules in the privacy policy. Audit records that must be preserved are anonymized rather than deleted.
- Amounts already due remain payable.
- Provisions that by their nature should survive, including sections 8, 9, 13, 14, and 16, continue to apply.
16. Governing Law and Disputes
16.1 Informal resolution
Before starting formal proceedings, contact us at contact@tidewater-intelligence.com and allow 30 days to resolve the matter directly.
16.2 Governing law
These terms are governed by the law of Denmark, excluding its conflict of law rules and the United Nations Convention on Contracts for the International Sale of Goods. The courts of Denmark have jurisdiction, without prejudice to any mandatory right a consumer may have to bring proceedings in their own country of residence.
17. Changes to These Terms
We may update these terms. The current version is published here with the date it took effect. Material changes are notified to organization administrators before they take effect. Continued use after that date means the updated terms are accepted.
18. Miscellaneous
18.1 Entire agreement
These terms, the privacy policy, and any signed organization agreement or data processing agreement form the entire agreement between the parties on this subject.
18.2 Severability
If a provision is held unenforceable, the rest remains in force and the unenforceable provision is replaced by the closest enforceable equivalent.
18.3 No waiver
A failure to enforce a right is not a waiver of that right.
18.4 Assignment
You may not assign these terms without our written consent. We may assign them in connection with a merger, acquisition, or sale of the business.
18.5 Force majeure
Neither party is liable for a failure caused by an event beyond its reasonable control, including the acts of a source platform or a network operator.
19. Contact
For questions about these terms:
By using TideWater, you acknowledge that you have read and understood these Terms of Service and agree to be bound by them.