General terms and conditions
Applicable to the services of Innobrix.
Smart2IT BV – Hengelo, The Netherlands
Version 1.5 – August 10, 2026
Table of contents
Chapter 1General provisions art. 1–18 Chapter 2Compliance art. 19–22 Chapter 3Cybersecurity art. 23–27 Chapter 4Processing of personal data art. 28–32 Chapter 5Data sharing art. 33–36 Chapter 6Artificial Intelligence (AI) and Software-as-a-Service (SaaS) art. 37–41 Chapter 10Advice art. 59–61 Chapter 12Education and training art. 67–69 Appendix AFair Use Policy art. 1–7 Appendix BSmart2IT Data Processing Agreement art. 1–12General provisions
Article 1 — Applicability of Smart2IT BV Terms and Conditions
1.1 These Smart2IT BV terms and conditions apply to all offers and agreements under which the supplier delivers to the customer.
1.2 The Customer and the Supplier make agreements regarding the mutual services to be delivered, including price and payment and what is or is not included in the price. Everything in these Smart2IT BV Terms and Conditions applies only in the event that no explicit written agreements to the contrary have been made.
1.3 Customer's purchasing or other terms and conditions do not apply and are explicitly rejected.
1.4 If the Supplier makes products or services of a third-party supplier available to the Customer, the (license or sales) terms and conditions of that third-party supplier shall apply with regard to those products or services in the relationship between the Supplier and the Customer, provided that those (license or sales) terms and conditions have been declared applicable by the Supplier and the Customer has been offered a reasonable opportunity to take notice thereof. Provisions in these Smart2IT BV Terms and Conditions that deviate from those other terms and conditions shall not apply in that case. A Customer as referred to in Article 6:235, paragraph 1 or 3, of the Dutch Civil Code cannot invoke a defect in the aforementioned obligation of the Supplier.
1.5 If, for whatever reason, the terms and conditions of a third-party supplier do not apply or no longer apply between the customer and the supplier, these Smart2IT BV Terms and Conditions shall apply in full.
1.6 If any part of these Smart2IT BV Terms and Conditions is void or annulled, the remainder of these Smart2IT BV Terms and Conditions shall remain in full force and effect. In that case, the Supplier and the Customer shall attempt to reach new, comparable provisions by mutual agreement to replace the void or annulled provisions.
Article 2 — Offers
2.1 All offers and other statements by the Supplier are without obligation, unless otherwise indicated in writing by the Supplier. The Customer guarantees the accuracy and completeness of the information provided by or on behalf of the Customer to the Supplier upon which the Supplier has based its offer, with the exception of obvious typographical errors.
Article 3 — Price and payment
3.1 All prices are in euros, excluding VAT and excluding other product- or service-specific levies imposed by a government.
3.2 The Customer cannot derive any rights from a quotation issued by the Supplier. A budget disclosed by the Customer shall only constitute a (fixed) price agreement if this has been expressly agreed in writing between the parties.
3.3 If the Customer consists of multiple (legal) persons, each of those (legal) persons is jointly and severally liable to the Supplier for the performance of the agreement.
3.4 With regard to the services performed by the Supplier and the amounts owed by the Customer in connection therewith, the data from the Supplier's records constitute full proof, without prejudice to the Customer's right to provide counter-evidence.
3.5 In the event of a periodic payment obligation on the part of the Customer, the Supplier may adjust the applicable prices and rates in writing and in accordance with the index or other measure included in the Agreement, at the period specified in the Agreement. If the Agreement does not expressly provide for the possibility of adjusting the prices or rates, the Supplier may adjust the applicable prices and rates in writing, observing a notice period of at least three months and no more than once a year. If, in the latter case, the Customer does not wish to agree to the adjustment, the Customer may terminate the Agreement in writing within thirty days after notification of the adjustment, effective from the date on which the new prices and/or rates would take effect. Price increases from third parties may be passed on to the Customer.
3.6 The parties shall determine in the agreement the date or dates on which the Supplier invoices the Customer for the agreed services. Amounts due shall be paid by the Customer in accordance with the agreed payment terms or those stated on the invoice. The Customer may not suspend payments or set off amounts due.
3.7 If the Customer fails to pay the amounts due, or fails to pay them on time, the Customer shall owe statutory interest for commercial agreements on the outstanding amount, without the need for a reminder or notice of default. If payment by the Customer remains outstanding following a reminder or notice of default, the Supplier may hand over the claim to a debt collection agency, and the Customer shall be obliged, in addition to the total amount then due, to reimburse all reasonable judicial and extrajudicial costs, including all costs calculated by external experts. This is without prejudice to the Supplier's other statutory and contractual rights.
Article 4 — Duration of the agreement
4.1 If the agreement between the parties is a continuous agreement, the duration agreed upon by the parties shall apply. If no duration has been agreed upon, the duration of one year shall apply.
4.2 Unless provided otherwise by law, a fixed-term agreement shall be automatically renewed each time for the original contract duration, unless the Customer or Supplier terminates it in writing no later than 90 days before the end of the contract date.
Article 5 — Confidentiality
5.1 The Customer and the Supplier shall ensure that all data they receive from each other and which they know or ought reasonably to know to be confidential remains secret. This does not apply if it is necessary to disclose such confidential information to a third party in the following cases:
1. pursuant to a judicial decision, a statutory provision, or an order of
an authority;
2. for making reports to relevant authorities;
3. for the proper execution of the agreement.
The party receiving confidential data shall use it only for the purpose for which the data was provided. Data is in any event confidential if one of the parties has clearly designated it as such. If disclosure to a third party is permitted pursuant to the agreement, the Customer shall ensure that this third party is also bound to confidentiality.
5.2 The Supplier guarantees that the persons who process personal data for the Customer under its responsibility have a duty of confidentiality.
5.3 The Customer acknowledges that the content of the products and services, including the software, made available by or through the Supplier, is always confidential. These contain trade secrets of the Supplier, its suppliers, or the creators of the products and services.
Article 6 — Reservation of title and
rights, suspension and transfer of risk
6.1 All goods delivered to the Customer shall remain the property of the Supplier until the Customer has fully paid all amounts due to the Supplier under the agreement. If the Customer acts as a reseller, he may sell and deliver the goods subject to the Supplier's retention of title, but only to the extent that this is customary within his normal business operations.
6.2 The proprietary consequences of the retention of title of goods intended for export shall be governed by the law of the State of destination, if that law contains provisions more favorable to the supplier in this respect.
6.3 Rights are, where applicable, granted or transferred to the Customer subject to the condition that the Customer has paid all amounts due under the Agreement.
6.4 Until the Customer has paid all amounts due, the Supplier may retain any items, data, documents, or software received or created by the Supplier in the context of the Agreement, even if the Supplier is required to surrender or transfer them, or suspend its services.
6.5 The risk of loss, theft, embezzlement, or damage to goods, data, security devices, documents, or software created, supplied, or used within the framework of the agreement passes to the Customer as soon as they are in the actual possession of the Customer, or of someone acting on behalf of the Customer.
Article 7 — Intellectual property
7.1 All intellectual property rights to anything developed or made available to the Customer pursuant to the agreement – such as software, websites, data files, databases, equipment, training materials, tests and examination materials, or other materials such as analyses, designs, documentation, reports, quotations, and preparatory materials – remain entirely in the hands of the Supplier, its licensors, or its suppliers. The Customer receives only the rights of use expressly granted in these Smart2IT BV Terms and Conditions, the written agreement concluded between the parties, and by mandatory law. Any right of use granted to the Customer is non-exclusive, non-transferable, non-pledgeable, and non-sublicensable.
7.2 The Customer is not permitted to make changes to the provided material, to use it for AI training purposes, or to apply scraping, mining, or similar techniques.
7.3 If the Supplier is willing to commit to transferring an intellectual property right, it is bound to do so only if this has been agreed in writing and expressly. If the parties agree in writing that an intellectual property right in software, websites, data files, equipment, know-how, or other works or materials is to be transferred to the Customer, the Supplier retains the option and the right to:
1. the underlying components (such as designs, algorithms, documentation, works,
protocols or standards) to use and/or exploit for other purposes or for third parties without any restriction;
2. the general ideas, principles or programming languages used in or underlying
are involved in the development of any work to use and/or exploit for other purposes, for themselves or for third parties;
3. to undertake developments for oneself or a third party that are similar to or derived from those
which are or have been done for the benefit of the client.
7.4 The Customer may not remove, add, or modify (or have removed or modified) any mentions regarding the confidential nature, copyrights, trademarks, trade names, or other intellectual property rights in the services, software, websites, data files, equipment, or other works or materials.
7.5 The Supplier shall indemnify the Customer against any claim by a third party based on the assertion that software, websites, data files, equipment, or other materials developed by the Supplier itself infringe upon an intellectual property right of such third party, provided that the Customer informs the Supplier in writing without delay of the existence of the claim, and leaves the content of the claim and the handling of the matter, including the making of any settlements, entirely to the Supplier. The Customer shall provide the Supplier with all powers of attorney, information, and cooperation necessary to defend itself against such claims. This obligation to indemnify shall cease to apply if the alleged infringement (i) relates to works or materials made available to the Supplier by the Customer itself, for example for use, modification, processing, or maintenance, or (ii) relates to modifications that the Customer has made or had made to the software, websites, data files, equipment, or other works or materials without the Supplier's written consent. If it is irrevocably established in court that the software, websites, data files, equipment, works, or other materials developed by the Supplier itself infringe upon any intellectual property right belonging to a third party, or if the Supplier itself is of the opinion that such an infringement is likely to occur, the Supplier shall, where possible, ensure that the Customer can continue to use the delivered items or something functionally equivalent. Other or further obligations to indemnify are excluded.
7.6 The Customer warrants that no third-party rights oppose the provision to or processing by the Supplier of equipment, software, material intended for websites, data and/or other materials, designs and/or other works. This also includes ensuring the proper licenses or permissions. The Customer indemnifies the Supplier against any claim by a third party based on the assertion that such provision, use, maintenance, modification, processing, installation, or integration infringes any right of that third party.
7.7 The Supplier is entitled to use the Customer's trademark, logo, or name in its external communication.
Article 8 — Performance of services
8.1 The Supplier shall use its best efforts to perform services with care, where applicable in accordance with the agreements and procedures recorded in writing with the Customer. All services provided by the Supplier are performed on the basis of a best-efforts obligation, unless and to the extent that the Supplier has expressly committed to a result in the written agreement and that result is described with sufficient specificity in the agreement.
8.2 If the Customer deviates from the Supplier's advice or recommendations, or if the Customer chooses to proceed with a wish or instruction despite the Supplier having indicated that it is unrealistic, unsuitable, or technically unfeasible, the Supplier shall not be liable for any potential consequences, such as damage or additional work.
8.3 If the agreement has been entered into with a view to performance by one specific person, the Supplier is nevertheless always entitled to replace this person with one or more other persons with the same and/or similar qualifications.
8.4 The Supplier is not obliged to follow instructions from the Customer in the performance of its services, in particular if these instructions concern changes or additions to the content or scope of the agreed services. However, if such instructions are followed, the Supplier may charge its customary rates for such activities.
8.5 At the Customer's request, the Supplier shall endeavor to cooperate within a reasonable period with exit activities necessary for the transition to a third-party supplier or to the Customer. The Supplier may charge its customary rates for such activities.
8.6 The Supplier is not obliged to perform data conversion, unless this has been expressly agreed in writing with the Customer.
Article 9 — Service Level Agreement
9.1 Any agreements regarding a service level (Service Level Agreement) shall only be expressly agreed upon in writing. The Customer shall at all times inform the Supplier without delay of all circumstances that affect or may affect the service level and its availability.
9.2 If agreements have been made regarding a service level, the availability of software, systems, and related services shall be measured to the exclusion of downtime announced in advance by the supplier for preventive, corrective, or adaptive maintenance or other forms of service, as well as circumstances beyond the supplier's control. Subject to proof to the contrary provided by the customer, the availability measured by the supplier shall constitute conclusive evidence.
Article 10 — Information and other cooperation obligations
10.1 The parties acknowledge that the Supplier is dependent, in part, on proper and timely mutual cooperation and information exchange with the Customer for the performance of its activities. The Customer shall at all times provide all reasonable cooperation and information in a timely manner.
10.2 The Customer guarantees the accuracy, completeness, quality, relevance, and representativeness of the data, information, designs, and specifications provided by or on its behalf to the Supplier. If such information provided by the Customer contains discernible inaccuracies, the Supplier shall inquire about this with the Customer.
10.3 The Supplier is not obliged to warn the Customer of risks that lie outside the scope of the agreement. If the Supplier nevertheless issues a warning or makes a statement, this is done without obligation and without any obligation or liability arising therefrom for the Supplier.
10.4 In the interest of continuity, the Client shall designate a contact person or contact persons to act as such for the duration of the Supplier's work. The Client's contact persons shall possess the necessary experience, specific subject matter expertise, and insight into the objectives desired by the Client.
10.5 The Customer bears the risk of the selection of the items, goods and/or services to be supplied by the Supplier. The Customer shall at all times exercise the utmost care to ensure that the performance requirements are accurate and complete. Dimensions and data stated in drawings, images, catalogues, websites, quotations, advertising material, standardisation sheets, etc., are not binding on the Supplier, unless expressly stated otherwise by the Supplier.
10.6 If the Client engages personnel and/or auxiliary persons in the execution of the agreement, this personnel/these auxiliary persons shall possess the necessary knowledge and experience.
10.7 In the event that Supplier employees perform work at the Customer's location, the Customer shall provide the necessary facilities, such as a workspace with computer and network facilities, in a timely manner and free of charge. The Supplier shall not be liable for damage or costs due to transmission errors, malfunctions, or the unavailability of these facilities, unless the Customer proves that such damage or costs are the result of intent or willful recklessness on the part of the Supplier's management.
10.8 The Client's workspace and facilities shall comply with all legal requirements. Prior to the commencement of the work, the Client shall make the house rules, information rules, and security rules applicable within its organization known to the employees deployed by the Supplier. The Client shall indemnify the Supplier against claims from third parties, including employees of the Supplier, who suffer damage in connection with the execution of the agreement as a result of acts or omissions of the Client or of unsafe situations within its organization.
10.9 The Customer is responsible for the management, including control of the settings, and the use of the products or services supplied by the Supplier and the manner in which the results of the products and services are utilized. The Customer is also responsible for instructing and the use by users.
10.10 The Customer shall provide the necessary equipment, infrastructure, and supporting software, whether on-premise or in the cloud, and shall install, set up, configure, parameterize, and tune the necessary (supporting) software on the infrastructure under its management, convert any data, and provide backups; and, if necessary, adapt and keep up-to-date the infrastructure, equipment, other (supporting) software, and operating environment used in connection therewith, and achieve the interoperability desired by the Customer.
10.11 Available user documentation will be provided by the Supplier in Dutch or English in a format to be determined by the Supplier. The Customer will assess the user documentation provided by the Supplier for suitability for its users and, if necessary, provide an explanation.
Article 11 — Project and steering groups
11.1 When both parties participate in a project or steering group with one or more employees deployed by them, the provision of information shall take place in the manner agreed for the project or steering group.
11.2 Decisions taken in a project or steering group in which both parties participate shall bind the Supplier only if that decision was reached in the manner agreed in writing between the parties or, in the absence of written agreements to that effect, if the Supplier has accepted the decisions in writing. The Supplier is not obliged to accept or implement a decision if, in its opinion, doing so is incompatible with the content and/or proper execution of the agreement.
11.3 The Client warrants that the persons designated by the Client to be part of a project or steering group are authorized to make decisions binding on the Client.
Article 12 — Amendments and additional work
12.1 If, at the request or with the prior consent of the Customer, the Supplier has performed work or other services that fall outside the content or scope of the agreed work and/or services, such work or services may be reimbursed by the Customer according to the agreed rates and, failing that, according to the Supplier's customary rates. The Supplier is not obliged to comply with such a request and may require that a separate written agreement be concluded for this purpose.
12.2 The Client acknowledges that changes (may) lead to additional work or the shifting of (delivery) periods and (completion) dates. The new (delivery) periods and (completion) dates indicated by the Supplier replace the previous ones.
12.3 To the extent that a fixed price has been agreed, the Supplier shall, upon request, inform the Customer in writing of the financial consequences of the additional work or services referred to in this article.
Article 13 — Termijnen
13.1 The Supplier shall endeavor reasonably to observe, as far as possible, the (delivery) periods and/or (completion) dates stated by the Supplier or agreed upon between the parties, whether or not these are final deadlines. Intermediate (completion) dates stated by the Supplier or agreed upon between the parties shall be considered target dates, shall not be binding on the Supplier, and shall always be of an indicative nature.
13.2 If there is a risk of exceeding any deadline, the Supplier and the Customer shall enter into consultation to discuss the consequences of the delay for further planning. In all cases – including when the parties have agreed on a final (delivery) deadline or (completion) date – the Supplier shall only be in default due to exceeding the time limit after the Customer has given him written notice of default, in which the Customer sets the Supplier a reasonable period to remedy the shortcoming (with regard to the agreed terms) and this reasonable period has expired. The notice of default must contain as complete and detailed a description of the shortcoming as possible, so that the Supplier is given the opportunity to respond adequately.
13.3 If it has been agreed that the performance of the agreed work will take place in phases, the Supplier may postpone the commencement of the work belonging to a phase until the Customer has approved the results of the preceding phase in writing.
13.4 The Supplier is not bound by any (completion) date or (delivery) period, whether or not a final date, if the parties have agreed to a modification of the content or scope of the agreement (additional work, change of specifications, etc.) or a change in the approach to the execution of the agreement, or if the Customer fails to fulfill its obligations arising from the agreement, or fails to do so in a timely or complete manner. The fact that (the demand for) additional work arises during the execution of the agreement does not constitute grounds for the Customer to terminate or dissolve the agreement.
Article 14 — Dissolution and cancellation of the agreement
14.1 Termination of the agreement due to an attributable failure to perform the agreement is only possible if the other party, in all cases following a written notice of default as detailed as possible in which a reasonable period is set for remedying the failure, is in attributable default in the performance of essential obligations under the agreement. Payment obligations and all obligations regarding cooperation and/or the provision of information by the Customer or a third party to be engaged by the Customer shall in all cases be considered essential obligations under the agreement.
14.2 If, at the time of dissolution, the Customer has already received services in performance of the agreement, these services and the related payment obligations shall not be subject to reversal, unless the Customer proves that the Supplier is in default with respect to the substantial part of those services. Amounts invoiced by the Supplier prior to the dissolution in connection with what it has already properly performed or delivered in execution of the agreement shall remain due and payable in full, subject to the provisions of the preceding sentence, and shall become immediately due and payable at the time of dissolution.
14.3 If an agreement which, by its nature and content, does not terminate upon completion, has been entered into for an indefinite period, it may be terminated in writing by either party after due consultation and stating the reasons. If no notice period has been agreed between the parties, a reasonable period must be observed upon termination. The Supplier shall not be liable for any compensation for damages due to termination.
14.4 The Client is not entitled to terminate prematurely a contract for services entered into for a fixed term, or a contract that ends upon completion.
14.5 A party may terminate the agreement in whole or in part in writing with immediate effect without notice of default if at least one of the following circumstances occurs: (i) the other party is granted a suspension of payments – whether provisional or not – (ii) bankruptcy is applied for in respect of the other party or (iii) the other party's business is liquidated or terminated other than for the purpose of reconstruction or merger of businesses. Supplier may also terminate the agreement in whole or in part with immediate effect without notice of default if the decisive control over the Customer's business changes directly or indirectly, but shall not do so on unreasonable grounds. As a result of termination as referred to in this paragraph, Supplier shall not be obliged to refund any monies already received or to pay compensation.
14.6 As soon as the Customer is irrevocably in a state of bankruptcy, the Customer's right to use the granted intellectual property rights on the products and services, such as the use of software and other usage rights, as well as the Customer's right to access and/or use the services, shall terminate, without any act of termination on the part of the Supplier being required for this purpose.
Article 15 — Supplier's liability
15.1 The total liability of the Supplier for an attributable failure or on any legal basis whatsoever, including non-performance of any warranties or indemnities, is limited to compensation for damages as set out in this article.
15.2 Direct damage is limited to a maximum of the amount of the price agreed for that agreement (excl. VAT). If the agreement is primarily a long-term agreement with a term of more than one year, the price agreed for that agreement shall be set at the total of the fees (excl. VAT) agreed for one year. The total liability of the Supplier for direct damage, on whatever legal basis, shall in no event exceed €
amount to 500.000 (five hundred thousand euros).
15.3 Damage resulting from death, bodily injury, or material damage to property is limited to €1.750.000 (one million seven hundred and fifty thousand euros).
15.4 Indirect damage, consequential damage, lost profits, lost savings, diminished goodwill, damage due to business interruption, damage resulting from claims by customers of the Customer, damage related to the use of items, materials or third-party software prescribed by the Customer to the Supplier, and damage related to the engagement of suppliers prescribed by the Customer to the Supplier are excluded.
15.5 Articles 15.2 through 15.4 inclusive are without prejudice to the other exclusions and limitations of liability of the supplier described in these Smart2IT BV Terms and Conditions.
15.6 The exclusions and limitations referred to in Articles 15.2 to 15.5 inclusive shall cease to apply if and to the extent that the damage is the result of intent or willful recklessness on the part of the Supplier's management.
15.7 Unless performance by the Supplier is permanently impossible, the Supplier's liability for attributable failure to perform an agreement arises only if the Customer immediately gives the Supplier written notice of default, setting a reasonable period for remedying the default, and the Supplier continues to be in attributable default in the performance of its obligations even after that period. The notice of default must contain as complete and detailed a description of the default as possible, so that the Supplier is given the opportunity to respond adequately.
15.8 A condition for the emergence of any right to compensation is always that the Customer reports the damage to the Supplier in writing as soon as possible after it occurs. Any claim for compensation against the Supplier shall lapse twenty-four months after the claim arises, unless the Customer has instituted legal proceedings for compensation for the damage before the expiration of that period.
15.9 The Customer shall indemnify the Supplier against all third-party claims for product liability resulting from a defect in a product or system supplied by the Customer to a third party which included equipment, software, or other materials supplied by the Supplier, unless and to the extent that the Customer proves that the damage was caused by such equipment, software, or other materials.
15.10 All limitations and exclusions of liability mentioned in these Smart2IT BV Terms and Conditions also apply to the benefit of all (legal) persons engaged by the Supplier and/or its supplier(s) in the performance of the agreement.
Article 16 — Force Majeure
16.1 If a party is prevented from doing so by force majeure, it shall not be obliged to perform any obligation, including any statutory and/or agreed warranty obligation. Force majeure on the part of the supplier shall include, but not be limited to: (i) force majeure of the supplier's subcontractors, (ii) the failure of subcontractors to properly perform obligations prescribed by the customer to the supplier, (iii) defects in goods, equipment, software or materials of third parties the use of which has been prescribed by the customer to the supplier, (iv) government measures, including import and trade restrictions, (v) fire, power failure, (vi) failure of the digital infrastructure and telecommunication facilities, (vii) strikes or a pandemic, (viii) (cyber)crime, (cyber)vandalism, war or terrorism and (ix) general transport problems.
16.2 If a force majeure situation lasts longer than sixty days, either party has the right to dissolve the agreement in writing. In that case, what has already been performed under the agreement shall be settled proportionally, without the parties owing each other anything else.
Article 17 — Transfer of rights and obligations
17.1 The Customer shall not sell, transfer, or pledge the rights and obligations it has under an agreement to a third party without the Supplier's prior consent.
17.2 The Supplier is entitled to sell, transfer or pledge its claims for payment of fees to a third party.
Article 18 — Applicable law and disputes
18.1 The agreements between supplier and customer are governed by Dutch law. The applicability of the Vienna Sales Convention 1980 is excluded.
18.2 Disputes between the parties shall be settled by arbitration in accordance with the Arbitration Rules of the Stichting Geschillenoplossing Automatisering (www.sgoa.eu). This is without prejudice to the fact that both parties also have the right to request interim relief in (arbitral) summary proceedings and the right to take precautionary legal measures. The place of arbitration is Amsterdam, or another place as stated in the Arbitration Rules.
18.3 If a dispute falls within the jurisdiction of the Dutch sub-district court, each party may, notwithstanding Article 18.2, choose to bring the case as a sub-district case before the legally competent court in the Netherlands. This option lapses as soon as arbitration proceedings concerning that dispute have previously been initiated in accordance with Article 18.2. If the case has previously been brought before the legally competent court with due observance of the provisions of this Article 18.3, the sub-district court of that court shall be competent to hear and decide the case.
18.4 In the event of a dispute, each party may initiate ICT mediation in accordance with the ICT Mediation Regulations of the Foundation for Dispute Resolution in Automation (Stichting Geschillenoplossing Automatisering). The other party is legally obliged to actively participate in such mediation. Active participation entails at least attending one joint meeting of mediators and parties to give this out-of-court form of dispute resolution a chance. After that first joint meeting of mediators and parties, each party may decide to terminate the mediation at any time. The provisions of this paragraph do not preclude a party who deems it necessary from initiating (arbitral) summary proceedings or taking precautionary legal measures.
Compliance
Article 19 — Requirements for the use of products and services
19.1 The Customer shall use all products and services only in accordance with the purpose intended by the Supplier or Manufacturer. The Supplier is not liable for damages resulting from any other use, even if this was foreseeable.
19.2 If the Customer desires specific certification upon entering into an agreement, the Supplier may suffice with alternative certification to which materially comparable requirements have been set.
19.3 Before putting a product or service into use, the Customer shall verify whether it complies with the applicable legislation and is accompanied by the appropriate documentation, such as technical and user information, declarations of conformity or certifications, including CE markings.
19.4 Given the large amount of (sector-specific) legislation, the Supplier cannot guarantee that a product or service complies with, or will continue to comply with, all laws and regulations that the Customer must comply with when using the product or service. The Supplier does not guarantee that the product or service will be adapted in a timely manner to changes in laws and regulations.
19.5 If the Customer can demonstrate that, pursuant to changed laws or regulations, it is essential for the Customer or the Supplier that the Supplier makes adjustments to products or services developed by the Customer or makes documentation available, the Customer shall inform the Supplier of this in writing and in as much detail as possible. The parties shall subsequently enter into consultation regarding whether, how, and within what timeframe the Supplier and the Customer can comply with such laws or regulations. If the Supplier is willing to adapt its product or service to the changes required by law for the Customer, or to expand it for that purpose with additional products and services from the Customer or a third party, the Supplier may charge costs for this in line with its customary rates. If the Supplier cannot or will not reasonably comply with the legislation required by the Customer and the Customer demonstrates that it has no other option than to comply with the necessary legislation, the Customer shall inform the Customer of this. Each party shall then have the right to terminate that part of the agreement that does not comply with the said laws or regulations in accordance with the applicable agreements. As a result of this termination, the Supplier shall not be obliged to refund any monies already received or to pay compensation.
19.6 If there is a legal obligation for the Customer to have Supplier’s employees participate in security awareness programs, the Supplier is willing to have its employees directly involved in providing services to the Customer participate in such awareness programs, provided that this does not place a disproportionate burden on the Supplier’s organization. The Supplier may charge reasonable costs for this. If the Supplier can demonstrate that employees have already attended similar awareness programs at the Supplier or at third parties, the Customer agrees that further participation in awareness programs is not necessary.
Article 20 — Data Processing
20.1 The responsibility for the data processed using a product or service of the Supplier lies with the Customer. The Customer warrants to the Supplier that the content, use, and/or processing of the data is not illegal or unlawful and does not infringe upon any right of a third party. In particular, the Customer shall respect the intellectual property rights and other rights of third parties, respect the privacy of third parties, not distribute data in violation of the law, not gain unauthorized access to systems, not distribute viruses or other harmful programs or data, and refrain from committing criminal offenses, distributing terrorist content, or violating any other legal obligation. The Customer shall indemnify the Supplier against all claims by third parties, on whatever grounds, in connection with the processing of data or the performance of the Agreement, unless the Customer proves that the facts underlying the claim are attributable to the Supplier.
Article 21 — Notice and Action
21.1 The Supplier may deploy measures and instruments for the purpose of content moderation. The Supplier is not obliged to actively monitor or investigate illegal or unlawful activities. Intervention or monitoring by the Supplier does not alter this.
21.2 Unless otherwise agreed, the contact details known to the Customer shall serve as the central point of contact for communication with the Supplier.
21.3 The Supplier may at any time take measures, whether or not in response to a notification from a third party, for example via a complaint handling system, to comply with applicable laws and regulations, to prevent (imminent) liability towards third parties, to limit the consequences thereof, or to comply with instructions or requests from an authority. These measures may consist, for example, of (temporarily) deleting or rendering data inaccessible, suspending customers, restricting access to or use of the service, or (partially) suspending or terminating it. If possible, the Supplier may first request the Customer in writing to delete specific data. In that case, the Customer shall immediately delete the relevant data from the Supplier's systems.
21.4 The Supplier cannot be required to conduct extensive legal research to form an opinion regarding the validity of third-party claims or the Customer's defense, or to be involved in any way in a dispute between a third party and the Customer. The Customer shall handle any conflict with a third party directly itself and inform the Supplier in writing, sufficiently substantiated with documentation.
21.5 The Supplier is not liable for any damage arising from this article.
Article 22 — Provision of information to
authorities, right of inspection and cooperation
22.1 If the Customer makes a notification to an authority in connection with a product or service based on a request, instruction, legal obligation, or order to provide information, the Customer shall notify the Supplier thereof without delay. The Customer shall enable the Supplier to provide the necessary information for the request or notification.
22.2 If there is a statutory obligation for the Supplier to share certain information, an obligation to demonstrate compliance by the Supplier with certain (security) obligations, a statutory right of audit, or a right of access to certain locations, the parties shall make further agreements regarding this. Failing this, the procedure described below shall apply.
22.3 The Customer shall first send the Supplier a written request, as detailed as possible, for the provision of the information or obligation to cooperate required by law. The Supplier shall make the mandatory information available within a reasonable period. This information may include the submission of relevant certification, a valid Data Pro Verified label, or an audit report (Third Party Memorandum) prepared by an independent expert commissioned by the Supplier. If the Customer's request concerns a data sharing request as referred to in the Data Act, the procedure described in Chapter 5 shall apply.
22.4 If, despite the aforementioned information, the Customer is nevertheless unable to comply with its legal obligations or with instructions from a competent authority, or if a contractual right to audit or access to specific locations has been agreed upon, the Customer may have an audit performed at its own expense at most once a year – or at least not more frequently than strictly necessary – or, if reasonably possible, gain access to the locations where the services are provided for an inspection. The audit or inspection must be performed by an independent, certified external expert with demonstrable experience in this field. The audit or inspection is limited to verifying whether the Supplier complies with its legal obligations towards the Customer or the agreements set out in the contract. The expert is bound by a duty of confidentiality and reports only what is necessary for the information obligation towards a competent authority or if he observes an attributable deficiency. The expert shall provide a copy of the report to the Supplier. The Supplier may refuse an expert, audit, instruction, or access if, in its opinion, this is contrary to legislation, if the expert impairs its competitive position, or if it constitutes an impermissible infringement of the security measures taken.
22.5 The Parties shall enter into consultation as soon as possible regarding the findings in the report. The Parties shall follow up on the proposed improvement measures set out in the report to the extent that this can reasonably be expected of them. The Supplier shall implement the proposed improvement measures to the extent that, in its judgment, they are appropriate, taking into account the risks associated with its product or service, the state of the art, the implementation costs, the market in which it operates, and the intended use of the product or service.
22.6 The Supplier shall, if necessary and legally required for the Customer, reasonably provide further information and assistance in the event of an incident involving the Supplier's product or service.
22.7 The Supplier may charge the Customer for the reasonable costs incurred in carrying out this article.
22.8 If the Supplier makes a notification, whether mandatory or not, to or cooperates with a request from an authority, the Supplier shall not be liable for damage to the Customer or a third party as a result of the notification or the cooperation provided.
22.9 The Customer is not entitled to recover from the Supplier any administrative fine imposed on it by an authority on any legal grounds whatsoever.
Cybersecurity
Article 23 — Security level
23.1 The cybersecurity of the products and services shall comply with the security specifications agreed upon in writing between the parties. In the absence of an expressly defined method of security, the cybersecurity shall meet a level that is not unreasonable, having regard to the state of the art, the implementation costs, the nature, scope and context known to the Supplier and the purpose intended by the Supplier of the product or service and the data contained therein, the probability and severity of use foreseeable to the Supplier and associated risks, the consequences of incidents and the rights and freedoms of data subjects. The Supplier does not warrant that the cybersecurity will be effective under all circumstances.
Article 24 — Use of protective equipment
24.1 The security measures provided to the Customer via the Supplier, including Multi-Factor Authentication, encryption, access or identification means, codes, or certificates, are confidential and shall be treated as such by the Customer. The security measures shall only be disclosed to persons specifically authorized by the Customer. The Supplier is entitled to modify or replace assigned security measures. The Customer is responsible for the management of the security measures and authorizations, including the timely provision, modification, and revocation thereof. The Customer shall ensure proper access credentials management, including the use of strong passwords and password management.
24.2 The Supplier is not liable for damage or costs resulting from the use or misuse of access or identification codes, certificates, or other security means, unless the misuse is the direct result of intent or willful recklessness on the part of the Supplier's management.
Article 25 — Responsibilities
25.1 If the security or testing thereof, for example by means of Threat Led Penetration Tests (TLPTs), relates to software, equipment, or infrastructure that was not supplied to the Customer by the Supplier itself, the Customer warrants that all necessary licenses or approvals have been obtained to be permitted to perform said services. The Supplier shall not be liable for damages arising in connection with the performance of such services. The Customer shall indemnify the Supplier against any legal claim on any grounds whatsoever in connection with the performance of such services.
25.2 It is for the Customer to assess whether the products and services are appropriate and proportionate given the security risks to its organization, in its context as a whole, and whether appropriate technical and organizational measures have been taken to comply with the statutory security requirements applicable to it and to ensure that the rights of data subjects are sufficiently safeguarded. The Customer shall adequately secure its own systems and infrastructure and ensure sufficient backups.
25.3 If the Customer is of the opinion that the security measures taken by the Supplier are insufficient to meet its minimum statutory requirements, the Customer shall inform the Supplier thereof in writing and in as much detail as possible. Article 19.5 shall apply accordingly.
25.4 The Customer shall disclose information from the Supplier regarding vulnerabilities, incidents, risk mitigation, and corrective measures to its users where necessary.
25.5 The Customer shall report incidents, possible security breaches, vulnerabilities, or security gaps to the Supplier or Manufacturer as soon as possible.
25.6 If the Customer discovers a potential infringement, vulnerability, or gap in a product or service of which the Supplier is not the manufacturer, and no contact address of the manufacturer of the product or service has been made available to the Customer, the Customer may submit the report to the Supplier via the Supplier's usual channels, so that the Supplier can forward the report to the appropriate contact person at the manufacturer.
Article 26 — Changes to security
26.1 The Supplier may at any time take technical and organizational measures to protect the products and services to which the Customer has (direct or indirect) access. These measures may also be deployed to monitor compliance with the agreed restrictions on content, duration of the right of use, or the purpose of the products or services.
26.2 The Supplier is entitled to adjust the security measures at any time if this is necessary due to changing legislation or circumstances in order to maintain an appropriate level of security. The Supplier shall record significant changes to the security and shall notify the Customer of those changes where relevant.
26.3 The Supplier or an authority may provide instructions to the Customer, for example regarding the execution of security updates or the modification of settings of security measures, aimed at preventing or minimizing incidents or the consequences of incidents that could compromise security. If the Customer fails to comply with such instructions from the Supplier or an authority, or fails to do so in a timely manner, the Supplier shall not be liable, and the Customer shall indemnify the Supplier against any damage that may arise as a result.
26.4 The Customer shall not remove or circumvent (or have removed or circumvented) any security measures, means, or technical facilities. In addition, the Customer shall not use coercive measures or exploit gaps in the Supplier's technical infrastructure.
26.5 The Customer may request the Supplier to take further security measures. The Supplier is not obliged to implement such changes. Only after the modified security measures desired by the Customer have been agreed upon in writing is the Supplier obliged to implement these security measures. The Supplier may charge its customary rates for the security updates made available by it or changes to the security implemented at the request of the Customer.
Article 27 — Backups
27.1 Only if the services explicitly include the creation of backups of customer data in writing, the Supplier shall create a backup of the Customer's data, observing the periods agreed upon in writing, and failing that, at least once a week, insofar as the data is located on infrastructure managed by the Supplier. In the absence of agreements regarding the retention period, the Supplier shall retain the backup for the period customary at the Supplier. The Supplier shall store backups carefully and with due care. Only if agreed in writing is the Supplier obliged to apply data segmentation or other mechanisms when creating backups that allow individual customer data to be restored separately. If the Supplier creates backups for the Customer, and potentially applies data segmentation or other mechanisms, the Supplier may charge its customary rates for this. The Supplier is not obliged to restore corrupted or lost data other than – where possible – restoring the last available backup of the data in question. If no data segmentation or other data separation mechanism has been agreed upon, restoring a customer-specific backup may not be possible.
27.2 If the Supplier offers a technical capability that allows the Customer to make backups of its data itself, the Customer shall ensure that backups of its data are made sufficiently frequently.
27.3 The Client remains responsible for compliance with all statutory administrative and retention obligations applicable to him, even after the completion of the services.
Processing of personal data
Article 28 — Algemeen
28.1 The Supplier processes the personal data on behalf of the Customer in accordance with the agreed written instructions from the Customer.
28.2 The Customer, or its client, is the controller within the meaning of the GDPR, has control over the processing of the personal data, and determines the purpose and means of the processing of the personal data.
28.3 The Supplier is a processor within the meaning of the GDPR and therefore has no control over the purpose and means of processing the personal data and consequently makes no decisions regarding, among other things, the use of the personal data.
28.4 The Supplier implements the GDPR as set out in these terms and conditions and in the agreement.
28.5 The Customer warrants to the Supplier that it acts in accordance with the GDPR and that the use and/or processing of the personal data is not unlawful and does not infringe upon any right of another.
28.6 Unless explicitly stated otherwise in the agreement, the supplier's product or service is not designed for the processing of special categories of personal data, data concerning criminal convictions or offences, or government-issued personal identification numbers.
Article 29 — Infringements relating to personal data
29.1 If the Supplier discovers a personal data breach, it shall inform the Customer without undue delay. If no specific agreements have been made in the agreement regarding the method of reporting, the Supplier shall contact the Customer in the usual manner.
29.2 It is up to the controller (customer, or its client) to assess whether the personal data breach about which the supplier has informed must be reported to the authority or the data subject(s). Reporting personal data breaches remains at all times the responsibility of the controller (customer or its client). The supplier is not obliged to report personal data breaches to the authority and/or the data subject(s).
29.3 The Supplier shall, if necessary, provide further information regarding the personal data breach and shall cooperate in providing the necessary information to the Customer for the purpose of notification to the competent authority or the data subject(s).
29.4 The Supplier may charge the Customer for the reasonable costs incurred in this regard.
Article 30 — Obligations upon termination
30.1 Upon termination of the Data Processing Agreement, the Supplier shall, within a reasonable period, delete all personal data held by it and received from the Customer in such a manner that it can no longer be used and is no longer accessible (render inaccessible), or, if agreed, return it to the Customer in a machine-readable format. The Supplier may charge its customary rates for this.
30.2 The provisions of Article 30.1 shall not apply if a statutory regulation prevents the Supplier from wholly or partially deleting or returning the personal data. In such a case, the Supplier shall continue to process the personal data only to the extent necessary pursuant to its legal obligations. The provisions of Article 30.1 shall also not apply if the Supplier is the controller within the meaning of the GDPR with respect to the personal data.
Article 31 — Rights of data subjects and Data
Protection Impact Assessment (DPIA)
31.1 The Supplier shall, where possible, cooperate with reasonable requests from the Customer relating to rights of data subjects invoked by data subjects at the Customer. If the Supplier is approached directly by a data subject, it shall, where possible, refer the data subject to the Customer.
31.2 If the Customer is required to do so under the GDPR, the Supplier shall, following a reasonable request to that effect, cooperate with a Data Protection Impact Assessment (DPIA) or a subsequent prior consultation.
31.3 The Supplier may charge its customary rates for the activities referred to in this article.
Article 32 — Sub-processors
32.1 The Supplier has stated in the agreement whether, and if so which, third parties (sub-processors) the Supplier engages in the processing of personal data.
32.2 The Customer authorizes the Supplier to engage other sub-processors to perform its obligations arising from the agreement.
32.3 The Supplier shall inform the Customer of any change in the third parties engaged by the Supplier. The Customer has the right to object to the aforementioned change by the Supplier.
Data sharing
Article 33 — General provisions on data sharing
33.1 If no specific written agreements regarding access to data have been made, the Customer may submit a request for data sharing to the Supplier via the Supplier's usual channels. The Supplier will only process requests that have been submitted in writing with sufficient detail. The Supplier has the right to verify whether the request has been lawfully submitted and (to what extent) it is obliged to comply with such a request. Upon request, the Customer shall provide all necessary information to assess the lawfulness and scope of the request. If the Supplier itself does not have access to the relevant data and is therefore unable to comply with the request, it shall, where possible, provide reasonable assistance in referring the Customer to the relevant party(ies).
33.2 The Supplier shall make available data that it is required to provide pursuant to the Data Act in a common machine-readable format. The Supplier is not obliged to implement the data at the data recipient.
33.3 Customer shall ensure that it and the data recipient and/or third party comply without delay with requests from the Supplier under Section 11 of the Data Act.
33.4 The Supplier may, to the extent permitted by law, charge the Customer and the Data Recipient switching costs or (ongoing) data extraction costs and a reasonable fee for making the data available, or charge costs for additional services relating to the data sharing request at its customary rates.
Article 34 — Data sharing at affiliated parties
products and related services (IoT)
34.1 In the event of a request for data sharing regarding connected products and related services, the Supplier is only obliged to make available the readily available data concerning the performance, use, and environment of connected products and/or related services and, if necessary, the relevant metadata. In any event, this data does not include information derived from or arising from such data, nor data concerning the content. The Supplier is exempt from sharing the data referred to in this article if it is a smaller enterprise, as defined in Section 7 of the Data Act, or if the customer itself has direct access to this data.
34.2 Supplier may, in accordance with Sections 4 and 5 of the Data Act, establish rules regarding the making available, use, or further sharing of data referred to in this section to Customer or a third party, in particular if this could undermine the security requirements of the connected product or related service, or if the data sharing affects trade secrets. Customer shall ensure that data provided to a third party is not further shared.
34.3 The Customer may not use the data to develop (or have developed) a product or service that competes with the product or service from which the data originate, or to gain insight into the economic situation, assets, and production methods of the manufacturer or supplier.
Article 35 — Data sharing upon exit or in the event of continuous parallel operation
use of data processing services (cloud services)
35.1 If the Customer makes a request for data sharing with data processing services, the Supplier shall provide at least the exportable data for the purposes of this request, to the extent that it does not concern internal data posing a risk of breach of a trade secret or assets or data protected by intellectual property rights. The Supplier is not obliged to make data available or to facilitate this for testing and evaluation purposes.
35.2 If the Customer makes a request for data sharing to data processing services, he shall indicate in detail:
1. which data processing service(s) are concerned;
2. or whether the customer wishes to switch data processing service(s) and/or wishes to cancel and wants the data
have it deleted (exit), or that the customer wishes to continue using the data processing service(s) of the supplier (in parallel); and
3. to which party(ies) the data must be transferred, including
relevant contact details.
35.3 If the Customer does not indicate within the notice period how it wishes the data sharing request to be executed, the Supplier may consider the request as a request to have the data erased and to terminate the data processing service (exit).
35.4 The transition period commences no later than two months after receipt of the request for data sharing. The transition period lasts a maximum of 30 days. If this is not technically feasible, the Supplier may inform the Customer within 14 working days of receiving the request about an alternative transition period, which shall not exceed seven months. The Customer may submit a single written request, as detailed as possible, for a reasonable extension of the transition period.
35.5 During the transition period, the Supplier shall endeavor to take the necessary measures to execute the data sharing request, exercise due care to maintain business continuity, continue to provide the services under the Agreement, and maintain the agreed or a comparable level of security. In the event of a switch to another data processing service, the Supplier shall also provide reasonable assistance and relevant information regarding known risks to the continuity of the data processing service.
35.6 If the Supplier provides custom work, it is not obliged to facilitate functional equivalence in the use of the new data processing service. Nor is the Supplier obliged in that case to ensure compatibility with common specifications based on open interoperability specifications or harmonised interoperability standards. If the Supplier provides custom work, the Supplier may charge costs for executing the data sharing request at its customary rates.
Article 36 — Termination of data processing services (exit)
36.1 If, in the data sharing request for data processing services, the Customer has also indicated a desire to terminate (exit), the agreement for the terminated data processing service(s) shall terminate by early termination after the end of the transition period, notwithstanding Article 14 of these Smart2IT BV Terms and Conditions, provided that the switch has been successfully completed. If, in the data sharing request, the Customer has indicated that it does not wish to switch, the agreement shall terminate by early termination two months after receipt of the request. The agreement between the parties for the supply of other products and services shall remain in force, unless the Customer also explicitly terminates the agreement for the supply of those other products and services in accordance with the agreed termination arrangements.
36.2 After the end of the transition period, the Customer may request its data during the retrieval period applied by the Supplier. This retrieval period amounts to at least 30 days after the expiration of the transition period.
36.3 After the expiration of the retrieval period applied by the Supplier and following a successful transition, the Supplier shall, to the extent possible, delete the Customer's exportable data and digital assets in such a manner that they can no longer be used and are no longer accessible (render inaccessible), unless a statutory retention obligation applies to the Supplier.
36.4 In the event of early termination as referred to in this article, the Supplier reserves the right to invoice the agreed fees that it could have charged up to the date of the originally agreed termination date as compensation for early termination.
Artificial Intelligence (AI) and
Software-as-a-Service (SaaS)
Article 37 — Artificial Intelligence (AI)
37.1 If the Supplier makes AI available, the Customer must use it in accordance with the purpose intended by the Provider and any instructions for use. If the Customer acts in contravention of the foregoing resulting in the AI application changing into a high-risk AI system, the obligations under Section 25, paragraph 2 of the AI Act shall not apply. The Supplier may at any time take corrective measures or withdraw, deactivate, or recall the AI application if the AI application is no longer in accordance with the intended purpose, or if the Customer is considered a provider through its own actions. In that case, the Supplier shall not be liable for any damages.
37.2 The Customer is aware of the characteristic feature of AI that it may contain a changing and self-learning technique, whereby the outcomes and conclusions of AI are constantly evolving and subject to change. Outcomes may vary depending on the input and context, whereby AI, even after deployment at the Customer, may exhibit adaptability, generate different results upon repeated application, and exhibit 'model drift'. Therefore, the Supplier does not warrant that the results of the AI application will be effective or accurate under all circumstances or over time.
37.3 Unless expressly agreed otherwise in writing, the Customer is not permitted to place its name or trademark on the AI application or to make substantial changes thereto.
37.4 If the (sub)supplier has established a monitoring system, it is entitled to use the information in the AI application for the purpose of monitoring. The Customer shall cooperate in this by granting access to the AI application for the purpose of monitoring.
37.5 As soon as the Customer becomes aware of a serious incident, or is of the opinion that the AI application poses a risk within the meaning of Section 79 of the AI Act, he shall immediately report this first to the provider or supplier. The Customer shall only report a serious incident to the competent authority if he can demonstrate that he cannot reach the provider of the AI application within the reporting period.
37.6 If the Supplier makes products and services available, the Customer may not use or integrate them into other AI applications without the explicit written permission of the Supplier. If the Supplier is willing to grant permission for this, and the Customer and Supplier are legally obliged to make further agreements in that case, the Supplier is entitled to charge costs for this at its customary rates. Such further agreements shall not prejudice intellectual property rights, confidential business information, and trade secrets.
37.7 The Client shall ensure sufficient human supervision of the use of AI.
37.8 The Customer shall ensure an adequate level of AI literacy among its staff and other persons who deploy the AI application on its behalf.
37.9 Depending on the manner in which (parts of) the AI application are made available, the other articles in this or the subsequent chapters may also apply – in addition to all previous chapters – supplementing this article.
Article 38 — Implementation of SaaS service
38.1 For the purposes of these Smart2IT BV Terms and Conditions, SaaS means: the remote provision and maintenance of functionality by the Supplier via the Internet or another data network, without a physical medium or download of the underlying software being made available to the Customer. This functionality may contain (parts of) AI.
38.2 The Supplier provides the SaaS service on behalf of the Customer. The Customer may use the SaaS service exclusively for the benefit of its own organization and only to the extent necessary for the use intended by the Supplier. The Customer is not permitted to allow third parties to use the SaaS service provided by the Supplier.
38.3 The Supplier may make changes to the content or scope of the SaaS service. If such changes are substantial and result in a change to the procedures applicable at the Customer, the Supplier shall inform the Customer thereof as soon as possible. The costs of these changes shall be borne by the Customer. In the event that substantial costs are involved, the Customer may terminate the agreement in writing effective from the date on which the change takes effect, unless this change relates to changes in relevant legislation or other regulations issued by authorities, or the Supplier bears the costs of this change.
38.4 The Supplier may continue the execution of the SaaS service using a new or modified version of the underlying software. The Supplier is not obliged to maintain, modify, or add specific features or functionalities of the service for the Customer.
38.5 The Supplier may temporarily disable the SaaS service, in whole or in part, for maintenance or other forms of service. The Supplier shall keep the downtime as short as possible and preferably at times when the SaaS service is typically used least intensively.
38.6 The Supplier is not obliged to provide the Customer with a physical medium or download of the underlying software.
38.7 In the absence of further agreements in this regard, the Customer shall itself further configure, set up, parameterize, and tune the SaaS service, convert any data and upload it, create backups, and, if necessary, adapt and keep up-to-date the infrastructure, equipment, other (support) software, and user environment used in connection therewith.
Article 39 — Warranty
39.1 The Supplier does not warrant that the SaaS service is error-free and functions without interruptions. The Supplier will endeavor to the best of its ability to prevent errors as referred to in Article
44.3 to rectify defects in the underlying software within a reasonable period, insofar as the underlying software concerns software developed by the Supplier itself and the relevant errors have been reported to the Supplier in writing by the Customer with a detailed description. Where appropriate, the Supplier may postpone the rectification of the errors until a new version of the underlying software is put into use. The Supplier does not guarantee that errors in the SaaS service that were not developed by the Supplier itself will be remedied. The Supplier is entitled to implement temporary solutions, program workarounds, or problem-avoiding limitations in the SaaS service. If (a part of) the SaaS service was developed at the Customer's request, the Supplier may charge the Customer for the costs of rectification in accordance with its customary rates. The Supplier is not obliged to rectify imperfections other than those referred to in this article. In the event that the Supplier is willing to perform rectification activities regarding other imperfections, the Supplier is entitled to charge a separate fee for this at its customary rates.
39.2 Based on the information provided by the Supplier regarding measures to prevent and limit the consequences of malfunctions, errors and other imperfections in the SaaS services, corruption or loss of data, or other incidents, the Customer shall identify the risks to its organization and, if necessary, take additional measures.
39.3 If the Customer is subject to significant dependency and risks to continuity in the event of incidents and calamities, the Supplier is prepared, at the Customer's request and to a reasonable extent, to cooperate with further measures to be taken by the Customer to mitigate these risks, subject to (financial) conditions to be set by the Supplier. Such agreements may, for example, concern the periodic or real-time return of data to the Customer or to a third party. Such additional services are not automatically part of the service provision.
39.4 The Supplier is not obliged to restore corrupted or lost data other than – where possible – restoring the last available backup of the data in question. If no data segmentation or other data separation mechanism has been agreed upon, restoring a customer-specific backup may not be possible.
Article 40 — Commencement of services; remuneration
40.1 The SaaS service to be provided by the Supplier (and any associated support) shall commence within a reasonable period after the conclusion of the Agreement. Unless otherwise agreed, the SaaS service shall commence upon the Supplier making available the means to gain access to the SaaS service. The Customer shall ensure that, immediately after the conclusion of the Agreement, it has at its disposal the facilities required for the use of the SaaS service.
40.2 The Customer owes the fee for the SaaS service as set out in the agreement. In the absence of an agreed payment schedule, all amounts relating to the SaaS service provided by the Supplier are due in advance on a monthly basis.
Article 41 — Additional provisions
41.1 The following Articles apply mutatis mutandis to the SaaS service: 42.3, 42.5, 42.8, 44.1 (with the exception of reference to Article 48), 44.11, 56.4, 57.1, 57.2, 70.2 and 70.4. In these Articles, the words 'software' shall be read as 'SaaS service' and 'delivery' as 'commencement of service provision'.
Advice
Article 59 — Implementation of advice
59.1 The Supplier shall carry out the consultancy entirely independently, at its own discretion and not under the supervision or direction of the Client, as a result of which there is no provision of manpower as described in Chapter 11.
59.2 The Supplier is not bound by a duration for the assignment, as the completion of an assignment in the field of consultancy depends on various factors and circumstances, such as the quality of the data and information provided by the Client and the cooperation of the Client and relevant third parties.
59.3 The services provided by the Supplier are performed exclusively on the Supplier's usual working days and hours.
59.4 The use that the Customer makes of advice or a report issued by the Supplier is at all times at the Customer's risk. The burden of proof that the (manner of) advice does not comply with what has been agreed in writing or with what may be expected of a reasonably acting and competent supplier rests entirely with the Customer, without prejudice to the Supplier's right to provide counter-evidence by all means.
59.5 Without the prior written consent of the Supplier, the Customer is not entitled to make any statement to a third party regarding the working methods, methods and/or techniques of the Supplier and/or the content of the advice or reports of the Supplier. Furthermore, the Customer shall not provide the advice or reports of the Supplier to a third party or otherwise make them public.
Article 60 — Reporting
60.1 The Supplier shall periodically inform the Client regarding the execution of the consultancy services in the manner agreed upon in writing. The Client shall notify the Supplier in writing in advance of circumstances that are (or may be) of importance to the Supplier, such as the method of reporting, the issues to which the Client wishes attention, the Client's prioritization, the availability of the Client's resources and personnel, and special facts or circumstances that may be unknown to the Supplier. The Client shall ensure the further dissemination and familiarization of the information provided by the Supplier within the Client's organization, assess this information partly on the basis thereof, and inform the Supplier accordingly.
Artikel 61 - Betaling
61.1 If no express payment schedule has been agreed, all fees relating to advice provided by the Supplier as referred to in this chapter shall be due in arrears on an annual basis each calendar month.
Education and training
Article 67 — Registration and cancellation
67.1 Registration for a training course must be made in writing and is binding upon confirmation by the supplier.
67.2 The Customer bears the responsibility for the selection and suitability of the training course for the participants. The lack of required prior knowledge on the part of a participant does not affect the Customer's obligations under the agreement. The Customer is permitted to replace a participant in a training course with another participant after obtaining prior written consent from the Supplier.
67.3 If, in the Supplier's opinion, the number of registrations warrants it, the Supplier is entitled to cancel the course, combine it with one or more other courses, or schedule it for a later date or time. The Supplier reserves the right to change the location of the course. The Supplier is entitled to make organizational and substantive changes to a course.
67.4 The consequences of cancellation of participation in a training course by the Customer or participants are governed by the rules customary at the Supplier. A cancellation must always be made in writing and prior to the training course or the relevant part thereof. Cancellation or non-attendance does not affect the payment obligations that the Customer has under the agreement.
Article 68 — Implementation of training
68.1 The Customer accepts that the Supplier determines the content and depth of the training.
68.2 The Customer shall inform the participants about and monitor the participants' compliance with the obligations under the agreement and the (behavioral) rules prescribed by the Supplier for participation in the training.
68.3 If the Supplier uses its own equipment or software during the execution of the training, the Supplier does not guarantee that this equipment or software is error-free or functions without interruptions. If the Supplier conducts the training at the Customer's location, the Customer shall ensure the availability of suitable training space and working equipment and software. If the facilities at the Customer prove to be inadequate and the quality of the training cannot be guaranteed as a result, the Supplier is entitled not to start, to shorten, or to discontinue the training.
68.4 Administering an examination or test is not a standard part of the agreement.
68.5 The Customer owes a separate fee for the documentation, training materials, or resources made available or produced for the training. The foregoing also applies to any training certificates or duplicates thereof.
68.6 If the training is offered by means of e-learning, the provisions of Chapter 6 shall apply accordingly as far as possible.
Article 69 — Price and payment
69.1 The Supplier may require the Customer to pay the fees due in this regard prior to the commencement of the training. The Supplier may exclude participants from participation if the Customer has failed to ensure timely payment, without prejudice to all other rights of the Supplier.
69.2 If the Supplier has conducted a preliminary investigation for a training plan or training advice, the costs associated with this may be charged separately.
69.3 Unless the Supplier has expressly indicated that the training is exempt from VAT within the meaning of Article 11 of the Turnover Tax Act 1968, the Customer shall also owe VAT on the remuneration. After entering into the agreement, the Supplier is entitled to adjust its prices in the event of any change to the VAT regime for training established by or pursuant to law.
Fair Use Policy
To guarantee a safe, reliable, and fair service for all our users, we have established this Fair Use Policy (FUP). This FUP is intended to prevent abuse and ensure an optimal experience for all users of our Software as a Service (SaaS) solutions.
Article 1 — Purpose of the Fair Use Policy
1.1 This Fair Use Policy is designed to:
1. To prevent unfair or excessive use of our services.
2. To ensure the integrity and performance of our platform.
3. To guarantee an equal and reliable experience for all our customers.
Article 2 — Permitted Use
2.1 The SaaS solution is intended for normal business use in accordance with the function and objective of the service. “Normal use” refers to the average usage patterns of customers.
Article 3 — Unauthorized Use
3.1 The following use is considered a violation of this Fair Use Policy:
1. Excessive Use: activities that place an exceptionally high load on the system
cause and/or negatively affect the service provided to other users.
2. Automation: the use of bots, scripts, or other automated tools that
gain access to services outside the intended functionality.
3. Abuse of functionalities: the intentional misuse of system resources, APIs, or
other functionalities of the service.
4. Harmful activities: carrying out actions that compromise the security, integrity or
could jeopardize the availability of our services, such as hacking, the spread of malware, or DDoS attacks.
5. Illegal activities: use of our services for activities that are contrary to the law
or the rights of others, including, but not limited to, intellectual property rights, privacy rights, or rights to honor and reputation.
Article 4 — Monitoring and Enforcement
4.1 Smart2IT BV reserves the right to monitor usage patterns to ensure compliance with this Fair Use Policy.
4.2 Upon detection of a violation, Smart2IT BV reserves the right to take appropriate measures, including but not limited to:
1. Restricting access to certain services or functions.
2. Temporarily or permanently suspending the account.
3. Termination of the service without prior notice.
Article 5 — Notification and Action
5.1 In the event of a violation, in most cases we will try to notify the customer in advance and work together to resolve the problem.
5.2 If the situation requires serious or urgent action to ensure the performance, integrity, and security of our platform, we may intervene immediately without prior notice.
Article 6 — Amendments to the Fair Use Policy
6.1 Smart2IT BV reserves the right to modify this Fair Use Policy at any time. Changes will be published on this page, and it is the user's responsibility to stay regularly informed of these terms.
Article 7 — Contact Information
7.1 For questions or comments regarding this Fair Use Policy, please contact our support team at info@smart2it.nl. By using the software services of Smart2IT BV, you agree to the terms of this Fair Use Policy.
Smart2IT Data Processing Agreement
Version 1.4 — 19 September 2024.
Article 1 — Definitions
GDPR: Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).
Data Subject: the person to whom Personal Data relates, including the Customer's Employee and users of (a) Product(s).
User: a natural person employed by or working for the Customer, who makes use of a Product.
Employee: a natural person employed by or working for the Client.
Client: the organization with whom Smart2IT has concluded an Agreement.
Agreement: the agreement between Customer and Smart2IT regarding the use of (a) Product(s).
Personal Data: the personal data processed by Smart2IT in the context of the execution of the Agreement with the Customer, as further set out in Article 2.1 of this Data Processing Agreement.
Product(s): the (online) applications and other products or services offered by Smart2IT, such as Innobrix.
Smart2IT: Smart2IT BV, established and having its registered office at Diamantstraat 3, 7554 TA Hengelo, registered with the Chamber of Commerce under number 75030829.
Processor Agreement: the present Processor Agreement, which is to be regarded as an agreement between the Client and Smart2IT within the meaning of Article 28(3) of the GDPR.
Article 2 — Processing of personal data
2.1 The types of Personal Data that are (or may be) processed by Smart2IT through the various Products are listed in Appendix 1.
2.2 Smart2IT will process the Personal Data disclosed to it exclusively on the basis of written instructions from the Customer and solely within the framework of the execution of the Agreement, unless a provision of Union law or Member State law applicable to Smart2IT obliges it to process. In that case, Smart2IT shall notify the Customer of that legal requirement prior to processing, unless such legislation prohibits such notification for compelling reasons of public interest.
2.3 Smart2IT has no control over the purpose and means of the processing of Personal Data. Nothing in this Data Processing Agreement is intended to transfer control over the Personal Data to Smart2IT in any way.
2.4 Smart2IT is not permitted to use the Personal Data:
1. to process for own purposes;
2. to process for purposes other than or beyond that reasonably necessary in the context
of the execution of the Agreement;
3. to provide to third parties or to grant third parties access insofar as this is not permitted on
basis of the Agreement, the Data Processing Agreement, a mandatory legal provision, a court order and/or a request to that effect from (supervisory or investigative) authorities.
Article 3 — Requests from data subjects, DPIA and audit
3.1 Smart2IT shall, where possible, cooperate with reasonable requests from the Customer relating to rights of Data Subjects invoked with the Customer. If Smart2IT is approached directly by a Data Subject, it shall refer the Data Subject to the Customer as soon as possible.
3.2 Smart2IT shall provide the Customer, at its request, with the necessary information enabling the Customer to form an opinion regarding Smart2IT's compliance with the provisions of this Data Processing Agreement and/or applicable laws and regulations regarding the processing and protection of personal data.
3.3 The Client has the right to have the compliance of Smart2IT with the obligations arising from this Data Processing Agreement and applicable laws and regulations regarding the processing and protection of personal data verified by an independent expert bound by confidentiality, at most once a year. This audit, including inspection, may in any event take place upon a concrete suspicion of non-compliance with this Data Processing Agreement. Smart2IT shall cooperate with the audit, make all information reasonably relevant to the audit available as timely as possible, and grant the Client or an independent expert access to its offices, workspaces, processes, and systems. The costs of the audits performed on behalf of the Client shall be borne by the Client.
3.4 If the audit report of the independent expert referred to in Article 3.3 indicates that the measures and provisions taken by Smart2IT do not sufficiently comply with this Data Processing Agreement or the GDPR, Smart2IT shall immediately implement the proposed corrective measures insofar as, in its opinion, they are appropriate, taking into account the processing risks associated with the Product, the state of the art, the implementation costs, and the market in which it operates.
3.5 Smart2IT reserves the right to charge the Customer for the reasonable costs incurred by it in connection with the provisions of Articles 3.1 and 3.2.
Article 4 — Confidentiality
4.1 Smart2IT is obliged to keep the personal data confidential and will ensure that the persons authorized to process the personal data have committed themselves in writing to observe confidentiality. Smart2IT also ensures that access to the Personal Data is only available to persons involved in the execution of the Agreement who require access to the Personal Data for that purpose, and that consultation thereof by other unauthorized persons is not possible.
4.2 This duty of confidentiality shall continue to exist even after the termination of this Data Processing Agreement, except insofar as it concerns information that has already become publicly known, other than as a result of a breach of the aforementioned duty of confidentiality.
Article 5 — Smart2IT Security Measures
5.1 Smart2IT shall implement appropriate technical and organizational measures, which shall include, inter alia, the measures referred to in Appendix 2. In Smart2IT's judgment, taking into account the factors referred to in paragraph 2, the described security measures shall provide a level of security commensurate with the risk.
5.2 When implementing the security measures, Smart2IT has taken into account the state of the art, the implementation costs of the security measures, the nature, scope and context of the processing operations, the purposes and intended use of the Product, the processing risks and the risks to the rights and freedoms of Data Subjects varying in probability and severity that it may expect given the intended use of the Product.
Article 6 — Obligation to report data breaches
6.1 Smart2IT maintains an overview of every breach of the (technical and organizational) security measures taken by Smart2IT that (potentially) affects the Personal Data.
6.2 Smart2IT shall inform the Customer within 24 hours as soon as it ascertains that a security breach of the Personal Data has occurred. This provision of information shall be such that the Customer is able to comply with its obligations under Article 33 and Article 34 of the GDPR.
6.3 Smart2IT shall at all times keep the Customer fully informed regarding the progress of the remediation and all relevant developments concerning the breach referred to in paragraph 1 and the consequences thereof. Smart2IT shall take all measures that can reasonably be expected of it to remedy, where applicable, or to limit as much as possible, the adverse consequences of the security breach referred to in paragraph 2.
6.4 Smart2IT is not permitted to communicate with the Data Subject and/or supervisory authorities in the context of a breach as referred to in paragraph 2 other than on the instruction of the Customer or with its express and explicit consent.
Article 7 — Sub-processor relationship
7.1 Smart2IT hereby obtains permission to outsource parts of the processing of Personal Data to the sub-processors named in Part A of Appendix 3 to this Data Processing Agreement during the term of the Agreement.
7.2 Smart2IT hereby obtains permission to outsource the processing activities included in Part B of Annex 3 to sub-processors referred to in paragraph 1.
7.3 Smart2IT shall inform the Customer of intended changes regarding the addition or replacement of sub-processors for the execution of the processing activities included in Part B of Appendix 3, offering the Customer the opportunity to terminate the Agreement if it objects to the change.
7.4 Smart2IT guarantees that all sub-processors engaged by it commit – where relevant – to the same or a comparable level of security regarding the protection of Personal Data as the level of security to which Smart2IT is bound towards the Customer pursuant to this Data Processing Agreement and, more specifically, Appendix 3.
Article 8 — International traffic
8.1 Smart2IT shall ensure that any processing of Personal Data carried out by or on behalf of Smart2IT, including by third parties engaged by it, in connection with the execution of the Agreement, takes place within the European Economic Area (EEA) or to or from countries or organisations that offer a guaranteed level of protection in accordance with the GDPR.
8.2 Without the Customer's prior written consent, Smart2IT may therefore not transfer or store Personal Data in a country or organisation outside the EEA or make Personal Data accessible from a non-EEA country, unless a guaranteed level of protection is provided or a provision of Union law or Member State law applicable to Smart2IT obliges it to process. In that case, Smart2IT shall notify the Customer of that legal requirement prior to processing, unless that legislation prohibits such notification for compelling reasons of public interest.
Article 9 — Liability and Indemnification
9.1 The Customer guarantees that the data processing takes place in accordance with the law. This means that the Customer guarantees that he has the right to collect (or have collected) the Personal Data and is entitled to process (or have processed) this Personal Data.
9.2 Smart2IT guarantees the correct compliance with the obligations under the Data Processing Agreement. This Data Processing Agreement forms an integral part of the Agreement between the Client and Smart2IT, and the (total) liability of Smart2IT is (thereby) limited in accordance with the provisions of its General Terms and Conditions.
9.3 In the event of liability of Smart2IT towards two or more customers arising from or related to the same event or series of events, the total liability of Smart2IT shall never exceed €50.000 (excl. VAT), which amount shall be distributed by Smart2IT proportionally among the customers.
9.4 Smart2IT shall never be liable for any administrative fine or penalty payment imposed on the Customer by the supervisory authority – including in any event the Dutch Data Protection Authority.
Article 10 — Duration of Processor Agreement
10.1 This Data Processing Agreement enters into force upon acceptance by a User on behalf of the Customer and is entered into for the duration of the Agreement. By virtue of this acceptance, any data processing agreement previously concluded between the parties shall cease to exist.
10.2 As soon as the Agreement is terminated or ends, for whatever reason, this Data Processing Agreement shall remain in force as long as Personal Data is processed by Smart2IT, after which this Data Processing Agreement shall terminate by operation of law.
10.3 After the termination of this Data Processing Agreement, Smart2IT shall delete all Personal Data within 45 days and, at the Customer's request, declare that it has done so, unless the parties have expressly agreed otherwise. Smart2IT may charge the reasonable costs incurred in connection with any return of Personal Data to the Customer.
10.4 Smart2IT retains a copy of the Personal Data only if it is required to do so pursuant to a mandatory legal provision.
10.5 Anything in this Data Processing Agreement that is by its nature intended to remain in force after the termination of the Data Processing Agreement shall remain in force between the Parties after its termination. Such obligations include, among others, the confidentiality provision.
Article 11 — Amendments and order of precedence
11.1 Amendments to and additions to this Data Processing Agreement are only valid if they have been agreed upon in writing between the parties.
11.2 In the event of a conflict between the provisions of the Agreement and this Data Processing Agreement, the provisions of this Data Processing Agreement shall prevail. In the event of a conflict between the provisions of the applicable general terms and conditions, the provisions of this Data Processing Agreement shall prevail.
Article 12 — Applicable law and competent court
12.1 This Data Processing Agreement is governed exclusively by Dutch law.
12.2 All disputes between the parties arising from or related to this Data Processing Agreement shall be submitted to the competent court of the District Court of Almelo, unless mandatory law designates another court.
Article Appendix 1 — Types of Personal Data
The types of Personal Data listed below may be processed by Smart2IT in the context of the Products under which these types of Personal Data are listed. Smart2IT processes this Personal Data solely when the Customer actually purchases the relevant Product. Some functionalities of Products and/or support may be of limited use in the absence of certain data.
A. All Products:
1. First name, prefix, surname User;
2. User Email Address;
3. User IP address;
4. User Role;
5. Documents, messages, and media added by Users;
6. User last login time;
7. User Phone Numbers.
B. Innobrix:
1. User's residential address and postal code.
Article Appendix 2 — Security measures
Smart2IT's applications are hosted in the data centers of TransIP, Hetzner, and Amazon due to their expertise and certifications, including ISO 27001:2013, NEN 7510:2017, and ISO 9001:2015. Both the data and the applications are hosted within the European Union. Access to Smart2IT's hosting is secured with two-factor authentication and is accessible only to Smart2IT employees responsible for its management. Smart2IT's applications are accessible only via a secure connection using TLS/SSL (SHA-256 bit). Users can log in with an email address and password, or a login from Apple, Google, or Microsoft, among others. A backup of the data is made several times a week. This backup does not contain customer data segmentation. This backup data is stored encrypted at a separate hosting location, which is certified with the same certifications as described above. Smart2IT may modify the security measures, provided this does not compromise the security of the services.
Article Appendix 3 — Overview of sub-processors
A. Specific sub-processors — The Customer hereby authorizes Smart2IT to, for the
execution of the Agreement to make use of the following sub-processors:
1. TransIP
2. Hetzner
3. Mail Chimp
4. Hubspot
5. Google (Analytics)
6. Autodesk® (Revit® add-in)
B. Overview of services for which sub-processors may be engaged — Customer provides
Smart2IT hereby grants permission to outsource the following services to sub-processors for the execution of the Agreement:
1. Hosting
2. Sending emails and messages
3. Support
4. onboarding
5 Analytics
6. Model edits
