01Parties & the agreement
These terms ("Terms") form a binding agreement between CINDA Pty Ltd (ACN to be inserted), an Australian company ("CINDA", "we", "us"), and the customer named in the order ("Customer", "you").
By signing an order, ticking the acceptance box at sign-up, or using the CINDA service, you agree to these Terms.
02Your account
You'll create an account, nominate one or more authorised users, and connect your Xero organisations. You are responsible for:
- Keeping your sign-in credentials confidential and turning on multi-factor authentication.
- The actions of anyone you authorise on the account.
- Telling us promptly if you suspect unauthorised access to your account.
03What CINDA does
For the duration of your subscription, CINDA will:
- Take a daily, encrypted snapshot of the records in your connected Xero organisations.
- Hold those snapshots in the storage option you have selected (Option A, B or C — see clause 6).
- Index the snapshots so you can search by record, field, date, or audit-trail event.
- Provide a console you can use to view a snapshot or restore a record.
- Maintain a verified integrity record of every snapshot using cryptographic manifests.
CINDA does not provide accounting, bookkeeping, tax, financial or legal advice. CINDA is not a substitute for your Xero subscription.
04Your responsibilities
- Maintain your own active Xero subscription for the organisations you ask us to back up.
- Have authority to authorise CINDA to read those Xero organisations.
- Comply with all laws applicable to the data you ask us to back up — including the Privacy Act, tax record-keeping obligations, and any industry-specific rules.
- For Option A and Option B, keep your storage target online, secure and accessible to CINDA's snapshot agent.
- Test your restore process periodically. We recommend at least once a year. We provide a guided restore-test workflow in the console.
05Xero connection — read-only, always
CINDA connects to your Xero organisation via Xero's OAuth 2.0 authorisation flow, using the read-only scopes appropriate to the record domains in scope of the service. We do not request, accept, or use any write scope. CINDA cannot create, modify, or delete records in your Xero file. Disconnecting CINDA in Xero's "Connected apps" screen stops further snapshots immediately.
06Storage & encryption keys
You choose where your snapshots live when you order the service:
- Option A — Your local infrastructure. Snapshots are written directly to a storage target you operate (NAS, SAN, on-prem server). CINDA does not retain a copy and is not responsible for the availability, durability or security of your storage target.
- Option B — Your private cloud. Snapshots are written to a storage bucket in your own cloud tenancy (AWS, Azure, GCP, R2, B2). You hold the credentials. CINDA holds metadata only.
- Option C — CINDA private cloud. Snapshots are written to CINDA's managed Australian-sovereign storage in Sydney, in immutable WORM mode. Pricing applies per the order.
Snapshots are encrypted with AES-256 before being written, and TLS 1.3 in transit. For Option B and C, you may elect to hold your own encryption keys ("BYO keys"). If you do, you accept that CINDA cannot recover your snapshots if you lose those keys.
07Restores
Restores are initiated by you, in the console, by an authorised user. CINDA will:
- Verify the integrity of the snapshot you select.
- Export the requested records in the formats supported by the service (CSV, structured JSON, or Xero-compatible re-import bundles).
- Provide reasonable guidance on re-importing the records into Xero.
Because Xero does not provide a write API for every record type, the final re-import step may require manual action by you, your accountant or your bookkeeper. CINDA does not warrant that every record can be re-imported into Xero exactly as it appeared on the date captured. We do, however, warrant that the data we have captured is complete, accurate to what Xero exposed at snapshot time, and tamper-evident.
08Fees & payment
- Fees are stated in your order, in Australian dollars, exclusive of GST.
- Subscriptions are billed monthly or annually as set out in the order.
- Invoices are payable within 14 days of issue.
- Late payment may attract interest at the Reserve Bank of Australia cash rate plus two per cent, calculated daily.
- We may suspend the service for accounts more than 60 days overdue. We will not delete any backup during a suspension; cancellation requires written notice.
- We may adjust fees annually with at least 60 days' written notice. If you do not accept the new fees, you may terminate without penalty before they take effect.
09Availability
CINDA targets 99.9% availability of the snapshot scheduler and the restore service, measured monthly, excluding scheduled maintenance announced at least 72 hours in advance. Live availability and historical incident reports are published on our status page.
A daily snapshot is considered delivered if it completes successfully within 24 hours of its scheduled window. If a snapshot fails repeatedly, we will investigate and remediate; we will not be liable for failures caused by Xero's API, your storage target, or factors outside our reasonable control.
10Intellectual property
CINDA owns the software, console, scheduler, indexer, and all documentation. You receive a non-exclusive, non-transferable licence to use them for the term of your subscription. You may not reverse-engineer, resell, sublicense or copy the software except as the law expressly allows.
Your data — your Xero records, your snapshots, your account information — remains yours.
11Confidentiality
Each party will keep the other's confidential information confidential and use it only to perform this agreement. The data we back up for you is treated as your confidential information at all times, and we are bound by it as a recipient of confidential information of a particularly sensitive kind. We may disclose confidential information only as compelled by a valid legal process, and only after notifying you where permitted.
12Privacy
Personal information is handled in accordance with our Privacy Policy, which forms part of these Terms. To the extent CINDA acts as an APP entity holding your contacts' personal information for the purpose of providing the service, we do so as your processor and only on your documented instructions.
13Warranties
We warrant that the service will be provided with reasonable skill and care.
Other than as expressly stated in these Terms, the service is provided "as is". CINDA does not warrant that the service will be uninterrupted or error-free, that every Xero record will be perfectly captured in every circumstance, or that any particular outcome will be achieved by using the service.
Nothing in these Terms excludes, restricts or modifies any guarantee, condition, warranty, right or remedy implied or imposed by the Australian Consumer Law or any other applicable law that cannot lawfully be excluded.
14Liability
To the maximum extent permitted by law:
- Neither party is liable for indirect, consequential, special or punitive loss, or for loss of profit, revenue, goodwill or anticipated savings.
- CINDA's total aggregate liability arising out of or in connection with this agreement, however arising, is capped at the fees you have paid CINDA in the 12 months immediately preceding the event giving rise to liability.
- Nothing in this clause limits liability for fraud, wilful misconduct, breach of confidentiality, or any liability that cannot lawfully be limited.
15Term, suspension & termination
- The subscription runs for the initial term in your order, then renews for successive 12-month terms unless either party gives at least 30 days' written notice before renewal.
- Either party may terminate immediately for material breach not remedied within 14 days of written notice, or for insolvency.
- On termination or expiry, your access to the console ends. For 30 days you may request an export of your snapshots; after 30 days we will securely delete them, except as legally required to retain.
16Changes to these terms
We may update these Terms to reflect changes to the service, legal requirements, or business practice. For changes that materially reduce your rights or increase your obligations, we will give at least 30 days' prior notice and you may terminate without penalty before they take effect. For all other changes, the updated Terms apply from their published effective date.
17General
- Governing law. These Terms are governed by the laws of New South Wales, Australia. The parties submit to the exclusive jurisdiction of the courts of New South Wales.
- Force majeure. Neither party is liable for a failure to perform caused by an event outside their reasonable control.
- Assignment. Neither party may assign without consent, except CINDA may assign to a successor in a merger or sale of substantially all of its assets.
- Notices. Notices to CINDA may be sent to info@cinda.io. Notices to you may be sent to the email on your account.
- Entire agreement. These Terms, the Privacy Policy, and the order form the entire agreement between the parties on this subject matter.
18Definitions
- Snapshot — a complete, encrypted, point-in-time copy of the in-scope record domains of a Xero organisation, taken once daily.
- Xero organisation — an entity within your Xero account billed by Xero as a separate organisation file.
- Order — the document or online sign-up confirming the licence tier, storage option and term.
- Storage target — the location where snapshots are written, as elected in the order.
- Authorised user — a person you designate as entitled to use the console on your behalf.
- Confidential information — non-public information disclosed by one party to the other, marked or reasonably understood to be confidential.
About this draft
This is a plain-English draft prepared as a starting point. It should be reviewed by Australian commercial counsel before publication — particularly the liability cap, the warranties around restore accuracy and Xero API behaviour, and any sector-specific obligations (e.g. financial-services, healthcare) you may inherit as a custodian of your customers' data.