Skip to contentAbout Fig Group

Fig Master Subscription Agreement - FAQ.

Plain-English FAQ for the Fig Master Subscription Agreement.

Last updated: 14th July 2026

Thanks for reviewing Fig's contract terms. This FAQ explains, in plain English, what our subscription covers and answers the questions we're asked most often. This FAQ is for information only - it doesn't form part of, or override, the Master Subscription Agreement.

1. What am I buying?

A subscription to the Fig Platform - a cloud-hosted compliance, governance and risk-management application - together with whichever Fig Software components (Endpoint Agent, Cloud Agent, Data Scanner, Vulnerability Scanner) you've selected. If you're an MSP, your subscription also gives you the right to provide the Fig Platform to your own End Customers under the MSP Partner Agreement. Standard support is included; Premium and Enhanced support tiers are optional upgrades. Fig is also an IASME-licensed Cyber Essentials certification body - if you've engaged us for certification or assessment services, those are covered separately, not by this subscription.

2. What data does Fig collect?

That depends on how you configure the platform and which integrations you turn on. The Endpoint and Cloud Agents collect configuration, security-posture and telemetry data from the devices and cloud accounts you point them at; the Data Scanner only looks at the file shares, mailboxes or repositories you designate. We also collect ordinary account and usage data (logins, feature usage) to run and improve the platform.

3. Does Fig sign a Data Processing Agreement (DPA)?

Yes - our DPA is incorporated into the Master Subscription Agreement automatically; you don't need to negotiate a separate one. It covers roles, security measures, breach notification, sub-processors and international transfers. See our DPA.

4. Will Fig process particularly sensitive data - health records, card data?

Only if it's present in the data sources you choose to scan (for example, the Data Scanner could flag PCI-format data or special category data if it exists in a file share you've pointed it at). Fig doesn't require or specifically request this data, and you control what's in scope.

5. Is my data shared with third parties?

Only with the Sub-processors who help us run the platform (hosting, monitoring, support tooling, email delivery) - our current list is at www.figgroup.co.uk/subprocessors, and we'll notify you before adding a new one. We never sell customer data, and anything we publish about aggregate usage is anonymised.

6. Does Fig use AI, and does it train on my data?

Some optional features use AI models (currently via providers including Anthropic, OpenAI and Mistral), only where you've enabled the relevant feature - you can turn these off. Your data is never used to train third-party or Fig's own AI models.

7. How is my data protected?

Encryption in transit and at rest, tenant isolation between customers, MFA-gated internal access, continuous monitoring, and annual third-party penetration testing, among other measures - see our DPA and Trust Centre (www.docs.figgroup.co.uk) for full detail and current certifications.

8. What happens to my data when my subscription ends?

You can export your data at any time during your subscription, and you have 30 days after termination to request an export, which we'll provide within a further 30 days. After that, we delete Customer Data on the schedule set out in our DPA (active systems within 30 days of the export window closing; backups age out within 12 months).

9. Can I cancel for convenience part-way through my term?

Not under the standard terms. Our subscriptions run for the fixed initial term in the Order Form and then renew annually. If notice of non-renewal is given during the first 3 calendar months of the initial term, at least 30 days' notice is required; after those first 3 months, at least 60 days' notice is required. In either case, the cancellation takes effect at the end of the current subscription term rather than ending it early.

Some promotional Order Forms may expressly include a separate early-exit right, for example during an initial 3-month free period. That right applies only where the Order Form specifically includes it, and the Order Form will set out how and when it can be used.

10. Does Fig offer indemnification?

Yes - an IP-infringement indemnity covering your authorised use of the Fig Services, which is standard SaaS market practice. We don't offer indemnities beyond IP claims and the other specific matters set out in the Master Subscription Agreement.

11. Is there a cap on Fig's liability?

Yes, a cap based on the fees you've paid, with a higher cap for confidentiality and data-protection breaches - this is standard for SaaS providers and reflected in how we price the service. Full detail is in the Master Subscription Agreement.

12. Can I run my own audit of Fig?

You (or an independent auditor you choose) can request a compliance audit once a year under the DPA, or rely on the materials in our Trust Centre - security reports, penetration-test summaries, and sub-processor information - which is usually the faster route.

13. Is there a Service Level Agreement?

Yes - a 99.5% monthly uptime commitment with service credits if we miss it. See our SLA.

14. Will my price jump on renewal?

Any increase is capped at the greater of 5% or the previous year's UK CPI, and we'll give you at least 60 days' notice before it applies.

15. I'm an MSP - what's my relationship with Fig's End Customers, and what's theirs with Fig?

Your End Customers contract with you, not with Fig - Fig has no direct commercial relationship with them except for the limited data-protection commitments described in our MSP Partner Agreement and DPA. You're responsible for your own End-Customer agreements, service commitments, and support relationship; we support you, and you support them.

16. What about the Vulnerability Scanner - is there anything I need to authorise before using it?

Yes - you (and, if you're an MSP, your End Customer) need to verify ownership of any asset before running a Standard or Aggressive scan, and keep records of that authorisation. Full detail is in our Product-Specific Terms.


Questions not answered here? Email legal@figgroup.co.uk.