Terms of Service

18. Security

Version 1.0

18.1 Security Commitment

Growwr is committed to maintaining a secure, reliable, and resilient platform that protects the confidentiality, integrity, availability, and resilience of the Services and the information entrusted to us.

Growwr implements and maintains administrative, technical, organizational, and physical safeguards designed to protect the Services and information processed through the Services against unauthorized access, disclosure, alteration, destruction, misuse, loss, corruption, or other security threats.

Although Growwr continually evaluates and enhances its security program, no software, network, infrastructure, cloud environment, or method of electronic transmission or storage is completely secure. Accordingly, Growwr cannot and does not guarantee absolute security.

18.2 Security Program

Growwr maintains a security program designed to protect its platform, infrastructure, users, and data throughout the lifecycle of the Services.

As part of this program, Growwr may implement security measures including, where appropriate:

  • encryption of data in transit and at rest;
  • identity and access management controls;
  • role-based access controls;
  • multi-factor authentication;
  • secure credential management;
  • network segmentation;
  • intrusion detection and prevention systems;
  • vulnerability scanning and management;
  • security logging and monitoring;
  • disaster recovery and business continuity planning;
  • secure software development practices;
  • infrastructure redundancy;
  • regular backups;
  • malware detection and prevention;
  • incident response procedures; and
  • other industry-recognized security safeguards.

Growwr reserves the right to improve, replace, or modify its security measures at any time in response to technological developments, evolving threats, legal requirements, or operational needs.

18.3 User Security Responsibilities

Security is a shared responsibility.

You are solely responsible for maintaining the security of your Account, devices, credentials, and your use of the Services.

You agree to:

  • maintain strong and unique passwords;
  • protect usernames, passwords, passkeys, API credentials, and authentication tokens;
  • enable multi-factor authentication where available or required;
  • secure devices used to access the Services;
  • maintain appropriate antivirus and security software;
  • promptly install software and security updates;
  • restrict unauthorized access to your Account;
  • log out of shared devices where appropriate;
  • safeguard confidential information obtained through the Services; and
  • promptly notify Growwr of any suspected security incident.

Growwr shall not be responsible for losses arising from your failure to maintain appropriate security practices.

18.4 Security Incidents

If you become aware of any actual or suspected:

  • unauthorized access to your Account;
  • credential compromise;
  • attempted or successful cyberattack;
  • data breach;
  • malware infection;
  • phishing attempt;
  • fraud affecting your Account;
  • security vulnerability; or
  • other incident affecting the security of the Services,

you agree to notify Growwr without unreasonable delay using the contact information provided in these Terms or any designated security reporting channel.

Growwr may investigate any reported or suspected security incident and may take any action reasonably necessary to protect the Services, its users, Service Providers, or applicable data.

18.5 Unauthorized Access and Prohibited Security Activities

You shall not, directly or indirectly:

  • attempt to gain unauthorized access to the Services or related systems;
  • bypass or circumvent authentication mechanisms;
  • interfere with security controls;
  • introduce malicious software, viruses, ransomware, spyware, worms, trojans, or other harmful code;
  • exploit or attempt to exploit vulnerabilities;
  • conduct unauthorized penetration testing;
  • perform denial-of-service or distributed denial-of-service attacks;
  • interfere with another user’s Account;
  • harvest authentication credentials;
  • engage in phishing or social engineering;
  • intercept communications;
  • scan or probe Growwr’s infrastructure without authorization; or
  • otherwise compromise or attempt to compromise the security or integrity of the Services.

Any activity prohibited by this Section constitutes a material breach of these Terms and may result in immediate suspension or termination of your Account, legal proceedings, and referral to law enforcement authorities where appropriate.

18.6 Monitoring and Threat Detection

To protect the Services and comply with Applicable Law, Growwr may monitor systems, infrastructure, authentication events, API activity, network traffic, application logs, and operational telemetry for purposes including:

  • cybersecurity;
  • fraud prevention;
  • abuse detection;
  • vulnerability identification;
  • incident response;
  • compliance monitoring;
  • system maintenance;
  • troubleshooting;
  • service reliability;
  • quality assurance; and
  • protecting the integrity of the Services.

Such monitoring shall be conducted in accordance with Applicable Law, the Privacy Policy, and Growwr’s legitimate security interests.

18.7 Security Updates and Maintenance

Growwr may deploy security patches, infrastructure updates, authentication enhancements, software upgrades, configuration changes, emergency fixes, or other maintenance activities without prior notice where reasonably necessary to:

  • address security vulnerabilities;
  • prevent exploitation;
  • protect users;
  • comply with Applicable Law;
  • improve system resilience;
  • maintain service reliability; or
  • respond to emerging cybersecurity threats.

Where reasonably practicable, Growwr will seek to minimize disruption caused by planned maintenance.

18.8 Third-Party Infrastructure and Service Providers

The Services rely upon third-party infrastructure, cloud hosting providers, payment providers, identity verification providers, artificial intelligence providers, communications providers, analytics providers, and other Service Providers.

Although Growwr exercises reasonable care in selecting and managing its Service Providers, Growwr does not control the independent security practices, operational decisions, or security incidents affecting those third parties.

Information regarding Growwr’s Service Providers is available through the Growwr Trust Center.

18.9 Security Investigations

Growwr reserves the right to investigate any activity that it reasonably believes:

  • threatens the security or availability of the Services;
  • violates these Terms;
  • compromises user Accounts;
  • creates cybersecurity risks;
  • interferes with platform operations;
  • violates Applicable Law; or
  • threatens the rights, property, reputation, or safety of Growwr, its users, or third parties.

During an investigation, Growwr may:

  • suspend or restrict Accounts;
  • preserve system logs and evidence;
  • temporarily delay transactions or payouts;
  • request additional information or documentation;
  • disable affected functionality;
  • notify affected users where appropriate;
  • cooperate with regulators or law enforcement agencies where required or permitted by Applicable Law; and
  • take any other action reasonably necessary to protect the Services.

18.10 Security Certifications and Compliance

Growwr continually evaluates and improves its security program in accordance with recognized industry standards and evolving best practices.

Growwr may obtain, maintain, pursue, or publicly reference security certifications, attestations, audit reports, compliance frameworks, or security assessments from time to time.

Unless expressly stated otherwise, references to any certification, audit, assessment, or compliance framework do not constitute a warranty, guarantee, or representation that the Services are immune from security incidents or cyber threats.

18.11 Security Incident Response

Growwr maintains processes designed to identify, assess, contain, investigate, mitigate, and recover from security incidents affecting the Services.

Where required by Applicable Law, Growwr will provide notifications regarding qualifying security incidents or personal data breaches to affected users or competent authorities within the timeframes required by Applicable Law.

Nothing in this Section shall be interpreted as an admission of liability for any security incident.

18.12 No Security Guarantee

You acknowledge and agree that:

  • no cybersecurity program is infallible;
  • no system or network can be guaranteed to be free from vulnerabilities;
  • unauthorized access may occur despite commercially reasonable safeguards;
  • cyber threats continually evolve;
  • interruptions, outages, and security incidents may occur despite reasonable precautions; and
  • Growwr cannot guarantee that the Services will always be secure, uninterrupted, error-free, or immune from cyberattacks.

Users remain responsible for implementing appropriate security measures within their own organizations and devices.

18.13 Reservation of Rights

Growwr reserves the right to implement, strengthen, modify, replace, suspend, or discontinue any security measure, authentication requirement, monitoring capability, access control, or security protocol where reasonably necessary to:

  • protect the Services;
  • respond to cybersecurity threats;
  • comply with Applicable Law;
  • satisfy contractual or regulatory obligations;
  • improve platform security;
  • protect users and Service Providers; or
  • safeguard Growwr’s legitimate business interests.

Nothing in this Section obligates Growwr to maintain any particular security technology, authentication method, certification, or compliance framework indefinitely.