This addendum supplements the Master Terms of Service. It applies when a Customer purchases, accesses, or uses CloudFFL OS.
1. Scope and Definitions
"CloudFFL OS" means CloudFFL's managed business platform for firearms dealers, including the hosted software instance, CloudFFL proprietary modules, documentation, updates, support, and integrations included in the Customer's plan or Order Form.
Capitalized terms not defined in this Addendum have the meanings given in the Master Terms. If this Addendum conflicts with the Master Terms on a matter specific to CloudFFL OS, this Addendum controls.
2. Subscription and Instance Scope
Each CloudFFL OS subscription is assigned to one named Customer and one production CloudFFL OS instance for that Customer's internal business operations. The subscription may be used only by the Customer and at the locations, for the legal entities, and within the operational scope permitted by the selected plan or Order Form.
- A separate business, affiliate, franchisee, client, or unrelated legal entity may not operate under the subscription unless expressly included in the Order Form.
- Additional production instances require a separate subscription or written authorization from CloudFFL.
- Multi-location and multi-company functionality does not by itself expand the licensed Customer, locations, entities, or instances.
- The Customer may not host, operate, white-label, sublicense, or provide CloudFFL OS as a managed service for third parties without a written agreement authorizing that use.
3. Authorized Users
The Customer may permit its employees and contractors to use CloudFFL OS as authorized users for the Customer's internal operations. Contractors must act under the Customer's direction, use the Service only for the Customer, and be subject to confidentiality and security obligations appropriate for their access.
Each human user must use an individual account unless a documented system integration requires a service account. The Customer is responsible for user provisioning, roles, permissions, offboarding, and all activity performed through its accounts. A plan that permits unlimited users or terminals does not permit account sharing or use by additional businesses.
4. Hosting and Dedicated Instance
CloudFFL OS is a managed cloud service. A "dedicated instance" means that the Customer receives a separately provisioned production virtual-machine instance and customer data environment. It does not mean dedicated physical hardware, a wholly separate cloud network, or a separate copy of every CloudFFL control-plane or support system.
CloudFFL may use shared cloud-provider facilities, networking, monitoring, deployment, backup, email, support, security, and management services to operate dedicated customer instances. CloudFFL may select and change hosting providers, regions, infrastructure, or architecture while maintaining materially equivalent service and security objectives.
5. Configuration and Customer Responsibilities
The Customer is responsible for:
- providing accurate business, license, tax, location, employee, and integration information;
- reviewing and approving system configuration before production use;
- maintaining suitable devices, networks, printers, scanners, payment hardware, and internet connectivity;
- configuring roles and limiting access according to job responsibilities;
- reviewing transactions, records, reports, imports, exports, and automated actions for accuracy;
- maintaining independent business-continuity procedures appropriate to its risk; and
- promptly reporting suspected errors, security incidents, or unauthorized access.
6. Updates, Maintenance, and Changes
CloudFFL may install security patches, bug fixes, compatibility updates, platform upgrades, and changes to CloudFFL modules. Scheduled maintenance may temporarily reduce availability. When practical, CloudFFL will provide advance notice of maintenance likely to materially affect production access.
The Customer may not install unapproved modules, modify managed system files, bypass administrative controls, or make changes that impair support, security, upgrades, or licensing. CloudFFL may require removal or isolation of unsupported changes before providing support.
Feature requests and custom development are not included unless identified in an Order Form. CloudFFL may decide whether and how to incorporate requested functionality into the generally available Service.
7. Support
Support channels, hours, response targets, training, onboarding, and professional services are those identified in the Customer's plan, Order Form, or then-current support documentation. Support does not include operating the Customer's business, making legal or compliance decisions, repairing unsupported customizations, or supporting third-party products outside the documented integration scope.
A response target is not a resolution guarantee. An uptime commitment, service credit, or other service-level remedy applies only when stated in a written service-level agreement or Order Form.
8. Backups, Availability, and Recovery
CloudFFL maintains backup, monitoring, and recovery practices appropriate to the Customer's plan and the documented CloudFFL OS service. Backups are a recovery measure, not an archive service or a substitute for Customer review and export of important records.
CloudFFL does not guarantee that every item of Customer Data can be restored, that a restore will reproduce the Service at a particular moment, or that the Service will be uninterrupted. Recovery time, recovery point, backup retention, and availability commitments apply only when expressly stated in an Order Form or service-level agreement.
9. Customer Data, Access, and Export
As between the parties, the Customer owns its Customer Data. CloudFFL owns CloudFFL OS, its proprietary modules, platform configuration, tooling, and other intellectual property. Ownership of Customer Data does not grant the Customer a license to CloudFFL software or source code beyond the right to use the managed Service.
CloudFFL personnel and approved service providers may access Customer Data when reasonably necessary to provide support, maintain or secure the Service, investigate incidents, fulfill Customer requests, or comply with law. Access will be limited to personnel with a business need and appropriate obligations.
During an active subscription, the Customer may use available export tools to export Customer Data in supported formats. Assistance, custom conversion, restoration, or migration services may require a separate Order Form. Exports do not include CloudFFL proprietary software, credentials, internal tooling, or third-party materials that CloudFFL is not permitted to provide.
10. Third-Party Services and Integrations
CloudFFL OS may integrate with services such as compliance platforms, payment processors, marketplaces, shipping providers, distributors, accounting services, email providers, hardware vendors, or other platforms. Unless expressly included in an Order Form, the Customer must obtain and maintain its own third-party accounts, licenses, hardware, fees, permissions, and contractual relationships.
The Customer authorizes CloudFFL OS to exchange Customer Data with enabled third-party services as needed to perform the requested integration. The Customer is responsible for choosing, configuring, and authorizing those services and for reviewing their terms and privacy practices.
CloudFFL is not responsible for third-party approvals, outages, funding decisions, data, fees, policy changes, API restrictions, or discontinued functionality. Integration availability may change when a third party changes or withdraws access.
11. Firearms and ATF Compliance
CloudFFL OS is a business and recordkeeping tool. It is not a law firm, compliance officer, federal firearms license, background-check system, or substitute for the Customer's professional judgment and legal obligations.
The Customer is solely responsible for:
- maintaining all required federal, state, and local licenses and registrations;
- determining whether a transaction, transfer, shipment, return, or other activity is lawful;
- the completeness, accuracy, timing, and retention of A&D records, Forms 4473, NICS-related records, and other required records;
- verifying FFL status, identity, age, residency, eligibility, restrictions, and required documentation;
- configuring workflows, taxes, restrictions, roles, and integrations for its jurisdiction and business;
- conducting required reviews, reconciliations, audits, corrections, and regulatory submissions; and
- responding to inspections, traces, law-enforcement requests, and regulatory inquiries.
A workflow, alert, validation, report, integration, or automated step may assist the Customer but does not guarantee compliance or prevent user, configuration, integration, data, or legal errors.
12. Security
CloudFFL and the Customer share responsibility for security. CloudFFL is responsible for reasonable safeguards within the managed Service. The Customer is responsible for its users, endpoints, local networks, passwords, access decisions, exported data, connected services, and prompt removal of access when a user no longer requires it.
The Customer must not conduct penetration testing, vulnerability scanning, load testing, or other security testing against the managed Service without CloudFFL's prior written authorization.
13. Suspension, Termination, and Offboarding
In addition to the suspension rights in the Master Terms, CloudFFL may restrict access to protect regulated records, prevent unauthorized transactions, address a compromised account, or respond to a third-party service or infrastructure risk.
Following cancellation or termination, CloudFFL may provide a limited period for the Customer to request or complete an available Customer Data export, as described in the Order Form, account notice, or offboarding documentation. The Customer must complete its export before the stated deadline.
After the applicable offboarding and retention period, CloudFFL may deactivate and delete the production instance and Customer Data, subject to legal obligations, dispute holds, security needs, and ordinary backup rotation. Data remaining in backups may persist until those backups expire and will not be restored except for legitimate recovery purposes.
14. Additional Disclaimers and Liability Boundaries
Without limiting the Master Terms, CloudFFL does not warrant a particular regulatory, tax, accounting, inspection, transaction, payment, marketplace, shipping, or business outcome. CloudFFL is not responsible for losses caused by Customer instructions, inaccurate Customer Data, unauthorized users, unsupported changes, third-party services, internet or device failures, or the Customer's failure to review or export records.
The disclaimers, exclusions, and liability cap in the Master Terms apply to CloudFFL OS, including claims involving data loss, restoration, business interruption, compliance features, integrations, and offboarding, to the maximum extent permitted by law.
15. Questions
Questions about this Addendum may be sent to legal@cloudffl.com.