Last updated: 30 July 2026. Placing an order implies unreserved acceptance of these terms.
1. Provider
Tenovia is published and operated by DEXTA CONSEIL, a French simplified joint-stock company with a single shareholder, registered office 200 rue de la Croix Nivert, 75015 Paris, registered with the Paris trade and companies register, SIRET 101 388 254 00019, NAF code 70.22Z, EU VAT number FR31101388254, hereinafter the Provider. Contact: hello@tenovia.eu.
2. Purpose and scope
These terms govern the sale and performance of Tenovia configuration audit services. They apply to any order placed on tenovia.eu, to the exclusion of any other document, including the Client purchasing terms.
3. Business customers only
The service is intended exclusively for businesses acting for the purposes of their professional activity. By placing an order, the Client declares acting in that capacity. Consumer protection rules, in particular the fourteen-day withdrawal right, do not apply.
4. Description of the services
An environment means one Microsoft 365 tenant or one Google Workspace domain. An organisation running both counts as two environments.
One-time audit: a single collection of the entire applicable CIS framework, a report with time-stamped evidence, a prioritised remediation plan costed in person-days, the mapping of each gap to NIS2, DORA, ISO/IEC 27001 and GDPR requirements, and a commented working session.
Continuous subscription: everything in the one-time audit, plus a monthly collection, an alert when a control regresses, comparison between two runs, and evidence history kept for the duration of the subscription.
Collection is read-only, through application programming interfaces. No script is run inside the Client environment and no password is handed over to the Provider.
5. What is not included
Carrying out the remediation is not included. The plan is delivered, its implementation belongs to the Client or to its managed service provider. The Provider may take it on, under a separate engagement and a separate quotation.
Some framework recommendations cannot be measured through an interface and are handled as guided checks, whose verdict and evidence are entered by the auditor or by the Client. The report explicitly distinguishes them from technical readings.
6. Order and formation of the contract
The Client selects the package and the tier matching the number of licensed users in the environment, guests excluded, provides billing details, accepts these terms by ticking the box, then pays through the secure payment page. The contract is formed when the payment provider confirms the payment.
The tier is set at the start and does not change mid-term. An inaccurate declaration of the number of users, established during collection, entitles the Provider to invoice the difference corresponding to the actual tier.
7. Prices, taxes and payment
Prices are expressed in euros and exclude tax. French value added tax at the applicable rate is added at payment. Businesses established in another European Union member state providing a valid EU VAT number are invoiced under the reverse charge mechanism. Clients established outside the European Union fall outside the scope of French VAT.
The one-time audit is payable in full at order. The continuous subscription is payable annually in advance. Payment is processed by Stripe Payments Europe. No card data passes through the Provider servers.
Under article L.441-10 of the French commercial code, late payment automatically triggers penalties at the European Central Bank refinancing rate increased by ten points, together with a fixed recovery indemnity of forty euros.
8. Term, renewal and termination
The one-time audit ends when the report is delivered.
The continuous subscription runs for twelve months, tacitly renewed for identical periods. Either party may end it in writing to hello@tenovia.eu, at the latest thirty days before the anniversary. Termination takes effect at the end of the current period, with no refund of amounts already paid.
The amount paid for a one-time audit is deducted from the first year of subscription if the Client subscribes within ninety days of delivery.
9. Client obligations
The Client declares holding the rights necessary to have the designated environment audited, and being able to consent to it. The Client appoints an authorised contact, sets up the read-only permissions described during scoping, and answers the Provider requests within reasonable time.
The Client is responsible for the confidentiality of console access, in particular the second factor and the recovery codes, and informs the Provider without delay of any suspected compromise.
10. Provider obligations
The Provider undertakes to perform the services in accordance with professional standards. The Provider is bound by a best-efforts obligation, not an obligation to achieve a result.
The report records a configuration state on the date of collection, against a public framework. It is neither a certification, nor an attestation of regulatory compliance, nor a guarantee against a security incident. Client compliance with NIS2, DORA, ISO/IEC 27001 or the GDPR remains the Client sole responsibility.
11. Confidentiality
Each party undertakes to keep confidential the information received from the other, during the contract and for five years after its end. Audit findings are disclosed to no third party and are not used as a commercial reference without prior written agreement.
12. Personal data
For collection data, the Provider acts as processor under article 28 GDPR, on the documented instructions of the Client. The Provider processes that data solely for the audit, uses only the sub-processors listed in the privacy policy, applies appropriate technical measures, and deletes raw records at the agreed retention deadline, thirty days by default.
13. Intellectual property
The report and the remediation plan become the Client property upon full payment. The method, the control grids, the scoring rules and the platform code remain the exclusive property of the Provider. No licence over those elements is granted to the Client.
14. Liability
The Provider liability, on any ground, is limited to direct damages and capped at the amount excluding tax actually paid by the Client over the twelve months preceding the triggering event.
Indirect damages are excluded, in particular loss of business, loss of data, commercial or reputational harm, and the consequences of a cyberattack suffered by the Client. These limitations do not apply in case of gross negligence or wilful misconduct, nor where the law sets them aside.
Any claim must be brought within twelve months of the triggering event, failing which it is time-barred.
15. Exit and data return
At the end of the contract, the Client may request the return of its reports in Excel and PDF format, within thirty days of the term. After that period, data is deleted under the conditions set out in the privacy policy.
16. Force majeure
Neither party is liable for a failure caused by a force majeure event within the meaning of article 1218 of the French civil code, including a lasting outage of the Microsoft or Google interfaces on which collection depends.
17. Governing law and disputes
These terms are governed by French law. The parties will seek an amicable solution before any action. Failing agreement within sixty days, exclusive jurisdiction is granted to the Paris commercial court, including where there are multiple defendants, third-party proceedings or urgent applications.
These terms are a translation provided for convenience. In case of discrepancy, the French version prevails.