◦ Legal

Terms of Service

Last updated July 20, 2026

These Terms govern your access to and use of AccessExit, operated by Eastbase Studio. By creating an account or using the service, you agree to these Terms and to our Privacy Policy. If you use AccessExit on behalf of an organization, you agree on its behalf and confirm you have authority to do so.

1. Who we are

AccessExit (“AccessExit,” “we,” “us”) is operated by Eastbase Studio, an independent software studio. You can reach us at support@eastbase.studio for support, privacy, and legal matters.

2. What AccessExit provides

AccessExit is an access-offboarding and access-review tool for small teams. It helps you import people and apps, build an access map, run offboarding cases, assign owners and SLAs, track tasks, upload evidence (files, notes, and links), record manual and API verification, accept named risks, export receipts as CSV or PDF, run quarterly access reviews, and sync and verify limited Google Workspace directory data.

Checklists are generated deterministically from a built-in catalog of common applications. The product has no AI features — determinism is a deliberate trust property.

3. What AccessExit is not

AccessExit is not an identity provider (IdP) or single sign-on service, an HRIS or payroll system, a governance, risk, and compliance (GRC) suite, an audit firm, a legal advisor, or a security consultant. It does not provide legal, security, or audit advice, and it is not an automatic deprovisioning agent for every third-party system.

AccessExit helps you record, coordinate, and prove the offboarding work your team performs. It does not, by itself, remove access from systems it is not connected to.

4. Accounts, workspaces, and admins

  • You must provide accurate account information and keep your credentials secure. You are responsible for activity under your account.
  • A workspace is the shared space for your team. The workspace owner and admins control sensitive actions — running offboarding cases, editing settings, managing people and app data, and managing billing.
  • You are responsible for the people you invite and for the roles you grant them.
  • You must be old enough to form a binding contract in your jurisdiction, and AccessExit is intended only for people aged 16 or older using it for work.

5. Your data — people, apps, access maps, and cases

You own the data you put into AccessExit: your people records, app inventory, account mappings, access maps, offboarding cases, tasks, evidence, and receipts. You grant us the limited license needed to host, process, and operate the service for you — for example, storing files, generating receipts, and sending notifications. How we handle that data, and the roles of controller and processor, are described in the Privacy Policy and Data Processing Terms.

Your responsibility for people and third-party data. AccessExit stores information about employees, contractors, vendors, and other third parties. You are responsible for having the necessary rights, notices, consents, and lawful basis to collect and process that people, app, access, and evidence data through AccessExit, and for keeping it accurate.

6. Evidence — files, notes, links, and audit events

You can attach evidence to tasks as files, notes, and links, and AccessExit records audit events as your team acts. Evidence and audit events are combined into a receipt when a case is closed.

Do not upload sensitive material as evidence. You must not upload secrets, credentials, API keys, access tokens, private keys, payment card data, government IDs, health data, highly sensitive HR records, confidential customer data, or personal data unrelated to offboarding. Redact screenshots and files before uploading unless you have a clear reason and the authority to store the material. AccessExit is not designed to be a vault for secrets or regulated data, and you are responsible for what you upload.

7. Manual tasks, integrations, and verification limits

AccessExit does not automatically revoke, suspend, delete, transfer, rotate, or verify access unless a specific integration or verification feature is enabled and successfully used for that system. Today, the only live directory integration is Google Workspace (read-only directory sync and account-suspension verification); most systems are handled as manual tasks.

For a manual task, your team remains responsible for performing the action in the third-party system and for recording accurate evidence in AccessExit. Marking a task complete records your team’s statement that the work was done; it does not, on its own, change anything in the third-party system.

8. Receipts, accepted risks, and audit disclaimers

A receipt reflects the tasks, evidence, verifications, and accepted risks your team recorded in a case. AccessExit marks a receipt provably closed only when every task is verified or a named person explicitly accepted the risk — and it will not claim “all access removed” otherwise.

“Provably closed” means the case was closed according to the recorded tasks, evidence, verifications, and accepted risks in AccessExit. It is not a guarantee that AccessExit independently verified every system, that no access remains anywhere, or that any evidence is accurate — and it is not an audit certification. You are responsible for the accuracy of the evidence you capture and the actions you mark complete.

9. Google Workspace and third-party services

AccessExit integrates with third-party services at your direction. When you connect Google Workspace, AccessExit may process the authorized directory data you sync — such as user accounts, names, email addresses, account status (including suspension), admin/role flags, and group memberships — for directory sync, access mapping, and account-suspension verification. AccessExit requests read-only, least-privilege scopes (today, read-only Directory user data).

AccessExit’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements. Google Workspace data is used only for the user-facing AccessExit features you authorize.

Your use of any connected third-party service is governed by that provider’s own terms, and we are not responsible for it. Optional sign-in with Google or GitHub is likewise subject to their terms.

10. Plans, billing, beta, cancellation, and refunds

AccessExit offers a Free plan and paid Starter and Team plans. Paid plans are billed monthly through Lemon Squeezy, which acts as our merchant of record. Plan limits (people, apps, cases, and features) are enforced by the product. Billing, cancellation, and refunds are covered by our Refund & Cancellation Policy.

The product is in beta. During the beta, paid plans may be activated manually, and features may change, break, or be removed. We’ll try to give reasonable notice of material changes.

11. Acceptable use

You agree not to:

  • Use the service unlawfully, or upload content you don't have the right to store.
  • Probe, scan, or attempt to breach the security of the service, or disrupt it for other users.
  • Reverse engineer, resell, or build a competing service from the platform, except where that restriction is prohibited by law.
  • Upload malware, or store data the service isn't designed for — for example secrets, credentials, payment card numbers, or unrelated personal data.

12. Exports and deletion

You can export receipts and access reviews to CSV (on paid plans) and delete people, apps, and evidence from within the product. You can delete your workspace at any time. Deletion and retention — including how audit events and deleted evidence are handled — are described in the Privacy Policy.

13. Availability and changes

We may update, suspend, or discontinue features. During beta the service is provided without an uptime commitment. We may change these Terms; if we make material changes we’ll update the date above and, where appropriate, notify you. Continued use after changes take effect means you accept them.

14. Suspension and termination

You can stop using AccessExit and delete your workspace at any time. We may suspend or terminate access if you breach these Terms, misuse the service, or create risk for other users. On termination, your right to use the service ends; you can request an export of your data first, as described in the Privacy Policy.

15. Disclaimers

The service is provided “as is” and “as available,” without warranties of any kind, whether express or implied, including fitness for a particular purpose, merchantability, and non-infringement. AccessExit does not warrant that the service will be uninterrupted or error-free, or that it will detect or remove every instance of retained access.

16. Limitation of liability

To the maximum extent permitted by law, AccessExit and Eastbase Studio will not be liable for any indirect, incidental, special, consequential, or punitive damages, or for lost profits or data. Our total liability for any claim relating to the service is limited to the amount you paid us in the twelve months before the event giving rise to the claim.

17. Governing law

These Terms are governed by the laws of Vietnam, without regard to conflict-of-law rules. The courts of Vietnam have jurisdiction over any dispute relating to these Terms or the service, unless mandatory local law where you live provides otherwise.

18. Contact

Questions about these Terms? Email support@eastbase.studio.