TERMS OF SERVICE — EGIRCYS.COM Version: 2026-09-28-b2b-advisory-v2 Date: 28 September 2026 1. Service provider These Terms of Service apply to independent, advisory technical audits supplied through egircys.com by Egidijus Girčys (“I”, “me” or “the provider”). “You” means the business customer identified in the order. Egidijus Girčys Mies-van-der-Rohe-Str. 6 14469 Potsdam Germany hello@egircys.com Lovable and Supabase are third-party products. My audits are independent services, not services sold, endorsed or certified by Lovable or Supabase. Further provider information is in the Impressum / Legal notice . 2. Business customers only These services are offered exclusively to businesses and self-employed professionals purchasing for purposes connected with their commercial or independent professional activity, within the meaning of section 14 of the German Civil Code (BGB). Purchases for predominantly private purposes are not accepted. Before ordering, identify the purchasing business and confirm that you have authority to act for it. A sole proprietor may use their legal name; a VAT identification number is not, by itself, a condition of being a business customer. Contact me before paying if the purpose of your purchase is unclear. A label or checkbox does not change your legal status or waive mandatory rights. If an order is found to be ineligible before work starts, it will be declined or cancelled and any payment refunded in full. Nothing in these terms removes consumer protections that apply by law to an actual consumer transaction. 3. What the audit includes You are buying an assessment and recommendations, not changes to your application. The binding scope is the package or quotation made available before purchase, including the identified project, review areas, exclusions, deliverables, price and delivery commitment. An individually agreed scope takes precedence over these standard terms. Lovable Production Readiness Audit A scoped advisory review of one application and its associated backend. Agreed areas may include source code, authentication, authorization, Supabase policies, payment integration, architecture, existing tests and deployment configuration. “Production readiness” describes the subject of the assessment, not a certification that the product is ready or safe to launch. Supabase Security & RLS Audit A scoped advisory review of one Supabase project and relevant application access paths. Agreed areas may include row-level security, user and tenant boundaries, authentication, storage policies, database functions and privileged access. Each standard package includes a PDF report with prioritized findings, supporting evidence where available, assumptions, material review limitations and recommended actions, plus a 30-minute report walkthrough. The Lovable package includes the Supabase review agreed for that application; there is no need to buy both packages for the same work. Scope limits, including any limits on repositories, tables, roles, functions or workflows, must be disclosed with the offer before payment. Listing a review area is not a promise to examine every line of code or every possible vulnerability. Limitations do not permit me to omit expressly agreed work without your agreement. No implementation is included. I do not patch or deploy code, apply SQL or migrations, change access policies, rotate keys, modify infrastructure, operate the service or implement the report. Penetration testing, active exploitation, load testing, incident response, safety-critical validation, legal or regulatory advice, formal certification, ongoing monitoring and a repeat audit are not part of these packages. 4. Order, price and payment General website descriptions invite an inquiry; a paid order must relate to an identified package or quotation. Before payment you must be shown the agreed scope and deliverables, total payable amount and currency, applicable tax treatment, delivery commitment and these terms. There are no subscriptions or unapproved additional charges. For a fixed-scope payment-link offer, the contract is concluded when an eligible business customer accepts that offer and the payment is successfully confirmed, unless a different acceptance process was expressly stated in the quotation. A failed or pending payment is not a confirmed booking. Stripe processes payment; I remain the service provider. I send an order confirmation by email identifying the purchased scope, price, delivery arrangement and applicable terms version. The payment processor’s receipt records payment and is separate from my service confirmation and onboarding instructions. The agreed terms can be saved before ordering and are supplied with the confirmation. Onboarding cannot unilaterally reduce what you already purchased. If your project falls outside the published eligibility limits, I will explain that before substantive work. You may agree a different scope and price or receive a full refund. No new scope or charge is imposed without your agreement. 5. Read-only access and permitted review We agree the authorized systems, material, access method and confidentiality arrangements before the review. The default is the minimum necessary read-only access or sanitized exports . You must own the material or have authority to permit the review, including compliance with any third-party platform rules. I do not require production administrator access, production write permissions, service-role secrets or live customer exports for a standard audit. Do not send passwords, secret keys, payment credentials or end-user data through ordinary email or checkout. Where an appropriately restricted invitation is unavailable, use a sanitized export instead. The review does not authorize creating or changing customer accounts or records, sending test payments, executing migrations, exploiting a vulnerability, or running tests that could disrupt a service. I can review source code, configuration and existing test evidence without implementing changes. Any limitation on direct verification is documented in the report; untested behavior is not presented as successfully tested. Ordinary authorized access can cause a platform to create its normal access or session logs. “Read-only” describes the permitted review activity, not a promise that a hosting platform will create no technical records. If excessive access, unnecessary personal data or an unsafe review condition is discovered, I will stop the affected activity, notify the nominated contact and agree a safer method. An inability to review agreed material will be disclosed, not silently treated as a successful check. 6. Your information and implementation decisions You provide materially accurate information about the product, roles, ownership rules, intended use and relevant constraints. I may rely on information you supply unless the agreed review gives reasonable grounds to question it; material assumptions and conflicting evidence will be identified. You and your appointed developers remain responsible for deciding, implementing, testing and approving changes. Recommendations and illustrative code or SQL are explanatory material, not production-ready patches approved for direct execution. Before applying a recommendation, your team should assess its suitability for the current version, dependencies and operating requirements, test it in an isolated environment, and maintain appropriate backups and a rollback process. You remain responsible for operating your service, managing credentials and access, backups, ongoing security and compliance, and the decision to launch or continue operating. An audit does not transfer those operational responsibilities to me. These responsibilities do not excuse a failure by me to perform the agreed assessment with appropriate professional care, nor do they remove your rights concerning an incorrect or incomplete agreed deliverable. Any legally relevant contribution to a loss is assessed under applicable law. 7. Point-in-time assessment, not assurance The report concerns the identified version, material, configuration and access available during the agreed review. It is limited to the agreed scope and methods. Systems, threats and dependencies change; a later change can invalidate an earlier conclusion. There is no ongoing duty to monitor or update a completed report unless a separate engagement is agreed. No audit can establish the absence of every defect, vulnerability or misuse. A finding marked low priority, or an area in which no issue was identified, is not a statement that no risk exists. The report distinguishes supported findings, assumptions, potential concerns and areas not directly verified. The audit is not a security certificate, compliance approval, insurance assurance, formal penetration test, financial or legal opinion, or guarantee of uninterrupted operation, data protection, revenue, funding or acceptance by a third party. It does not approve the application for safety-critical use. The absence of an outcome guarantee does not reduce the agreed deliverables or my obligation to perform a competent, appropriately careful review. An apparently urgent material risk identified during that review will be communicated to the nominated contact without unnecessary delay; this is not an incident-response or monitoring service. 8. Delivery, walkthrough and corrections The delivery period and its prerequisites are stated in the offer before payment. The review period begins when the necessary agreed material, permissions, project information and any required NDA or data-processing arrangements are available. If a missing input prevents particular work, I will explain the effect and any reasonable schedule adjustment. This does not excuse unrelated delays on my part. The PDF is supplied electronically to the agreed business contact. We arrange the included 30-minute walkthrough separately. The PDF alone does not mean that an outstanding, included walkthrough has already been supplied. If you do not arrange it immediately, your entitlement does not automatically expire after a short deadline. Please identify missing agreed work, factual errors or delivery problems so they can be investigated. A justified error or omission in my agreed deliverable will be corrected without an additional audit fee. Reviewing newly changed code or an expanded scope is different work and requires a separate agreement. No short notification deadline, automatic acceptance by silence or “as is” label removes statutory remedies. Applicable rights concerning proper performance, correction, price reduction, termination or damages remain available subject to their legal conditions and section 12. If I cannot perform the agreed service, I will inform you and refund undelivered work as described below. 9. Confidentiality, personal data and tools Non-public source code, business information, credentials and findings are confidential and used only for the agreed engagement. Confidentiality continues after completion while the information remains confidential. A separately agreed NDA also applies. Information independently and lawfully known, lawfully obtained from another source, or public without a breach is not treated as confidential merely because it was also supplied during the engagement. Confidential material is disclosed only to persons or providers authorized for the engagement and bound by appropriate duties, or where disclosure is legally required. Legally required disclosure is limited to what is necessary and, where permitted, notified to you. External AI services or other tools that receive confidential project material require advance agreement about the provider, purpose, permitted material and relevant processing arrangements. Accepting these terms, granting repository access or paying is not blanket permission to upload client material to external AI services or authorize model training . I do not authorize client material for model training as part of these audits. Read-only access does not make personal-data processing exempt from data-protection law. The default is to avoid end-user personal data. Where processing on your behalf is necessary, the roles, instructions, safeguards, subprocessors and any required data-processing agreement must be established before that access. A general NDA is not a substitute for a required data-processing agreement. The Privacy Policy describes handling of business contacts, website visits, payments and audit-related personal data. Necessary confidentiality and data-protection obligations are not waived by the advisory nature of the service. 10. Ownership and permitted report use You retain ownership of your existing code, data and other materials. After payment, you have a non-exclusive, perpetual right to use and copy the report for your business and share it confidentially with your personnel, developers and professional advisers. Existing methods, tools and general know-how remain with their respective owners. You may share the complete report with prospective investors or business customers for information, provided its scope, date, assumptions and limitations remain intact. Do not describe it as a certification, endorsement or guarantee, or quote selectively in a way that misrepresents the findings. The report is prepared for the purchasing business and the stated purpose. No contract with, independent assurance to, or intended contractual protection of a third party is created merely by sharing it. A separate reliance engagement is not included. This does not exclude rights that a third party has under mandatory law. 11. Cancellation and refunds You may cancel by emailing hello@egircys.com with the business name and order reference. Do not send full card details. Before substantive technical review starts, you receive a full refund. Routine onboarding, confirming access or signing an NDA alone does not count as substantive review. After work starts, the voluntary cancellation charge is limited to the documented proportionate value of work actually performed, using any milestone prices or effort allocation disclosed and agreed before purchase. No new cancellation rate or allocation may be invented retrospectively. Where the offer did not agree such an allocation, a reasonable amount for completed work must be agreed with you rather than automatically forfeiting the payment. The total retained cannot exceed the agreed fee; unperformed work and profit on that unperformed work are not charged under this voluntary policy. If I cancel because I cannot perform, you receive a refund for work not delivered; if no usable agreed deliverable has been provided, you receive a full refund. Refunds are made without undue delay, normally through the original payment method, and within any applicable mandatory deadline. Statutory termination rights and remedies for defective performance are not replaced by this policy. 12. Liability 12.1 Liability that is not limited I am liable without limitation for intent and gross negligence; for culpable injury to life, body or health; under an expressly assumed guarantee to the extent that the guarantee provides for liability; and where liability is mandatory and cannot be excluded or limited, including any applicable liability under the German Product Liability Act. Mandatory data-protection rights and claims of affected individuals remain unaffected. 12.2 Ordinary negligence and essential obligations Unless section 12.1 applies, liability for ordinary negligence exists only for breach of an essential contractual obligation and is limited to the damage that was foreseeable when the contract was concluded and typical for this type of engagement. An essential obligation is one whose fulfilment makes proper performance of the contract possible and on whose fulfilment the customer may ordinarily rely. This includes competent performance of the expressly agreed assessment and delivery of the agreed report. 12.3 Other obligations Unless section 12.1 applies, liability for ordinary negligence in breach of a non-essential contractual obligation is excluded. The limitations in sections 12.2 and 12.3 apply to contractual and non-contractual damages claims within their lawful scope and, on the same conditions, to persons assisting me in performance. 12.4 Scope of these limits The advisory nature of the audit defines the work undertaken; it does not remove responsibility for performing that work properly. These liability provisions govern damages claims. They do not replace rights to the agreed performance, justified correction or other applicable statutory remedies with a damages-only remedy. Statutory limitation periods are not shortened. Contractual provisions do not waive mandatory rights of affected individuals under data-protection law. 13. Applicable law and disputes German law applies to the contract. Mandatory rules that apply irrespective of the chosen law remain unaffected. If consumer protection applies despite the business-only offer, the choice of law does not deprive the consumer of protections that cannot lawfully be excluded. Jurisdiction is determined by applicable law; these terms do not create an exclusive court clause. Please contact me promptly about a concern so the facts and an appropriate remedy can be discussed. This request does not prevent you from using available legal remedies or contacting a supervisory authority. 14. Terms version and order record This version is 2026-09-28-b2b-advisory-v2 , dated 28 September 2026. The version incorporated into your order applies to that order. Updating the website does not change an existing contract retrospectively. Individually negotiated agreements take precedence as provided by law. You can save this version as a text file . The applicable version is also supplied with the order confirmation. If a standard term is ineffective, applicable statutory rules determine the consequence; an invalid restriction is not automatically rewritten into the widest restriction the law might allow. Questions: hello@egircys.com . See also the Privacy Policy and Impressum / Legal notice .