This English version is provided for information purposes. In the event of any discrepancy, the French version prevails.
These general terms and conditions of sale apply to any agreement concluded between NET COMPUTER GROUP SA and a business Client for the services and products marketed under the Cloudbizz, Neoo, Neoo Apps & Desktop, Serenia, Ovastack and neoo. brands. The special terms (offer, purchase order and their annexes) may derogate from them; in the event of any conflict, the special terms prevail.
Article 1 — Definitions
For the purposes of this Agreement and its annexes, the terms used have the meaning given to them by Regulation (EU) 2016/679 of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter the “GDPR”). Capitalised terms have the following meaning:
- The Agreement
- These general terms and conditions, the special terms and their annexes.
- The Client
- Any signatory who has entered into the Agreement in order to benefit from the Provider’s Services.
- The Data Centre(s)
- Digital Realty Brussels BRU1 (Wezembeekstraat 2 bus 1, 1930 Zaventem) and Digital Realty Brussels BRU3 (Mercuriusstraat 27, 1930 Zaventem).
- The Provider
- NET COMPUTER GROUP SA, a public limited company (société anonyme) incorporated under Belgian law, whose registered office is at Steenweg op Brussel 213, 1780 Wemmel, registered with the Crossroads Bank for Enterprises (CBE) under number 0822.883.860, which markets its services in particular under the Cloudbizz, Neoo, Neoo Apps & Desktop, Serenia, Ovastack and neoo. brands.
- The Fee
- The price agreed in consideration for the Services, as set out in Article 4 of the Agreement.
- The Regulation
- Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.
- The Services
- All services provided by the Provider to the Client under the Agreement.
- The Products
- All software solutions or hardware components delivered by the Provider under the Agreement.
- SLA
- The specifications of the service levels to be provided by the Provider to the Client.
- Client Data
- Data in the form of files, documents or databases.
- Reversibility Option
- The option to be exercised by the Client at the end of the Agreement, whatever the cause, in order to recover its Data.
Article 2 — Purpose of the Agreement
2.1. The Provider grants the Client a non-exclusive licence to use the Cloudbizz platform and the Provider’s IT infrastructure covered by the Agreement, within the limits set out below.
To this end, the Provider also provides maintenance and backup (“back-up”) services for the Data stored by the Client, within the limits of what is stated in Article 2.3 below and in Article 1 of the special terms, including, where applicable, the possibility for the Client to ask the Provider, on an ad hoc basis, to restore specific backups.
The provision of this platform, the supply of the maintenance and backup services and, more generally, all the services performed by the Provider are hereinafter collectively referred to as the “Services”.
2.2. The Client enjoys only a personal, non-exclusive and temporary right to use the Services, in accordance with Article 3 of the Agreement. The Client shall not grant to any third party whatsoever, for resale purposes, the rights it holds under the Agreement. The Client must be the end user of the Services.
The backup (“back-up”) service provided by the Provider depends on the subscription plan chosen by the Client. The retention period for this data is limited to 7 (seven) calendar days, excluding any additional options provided for in the subscription; at the end of this period, the data is destroyed or deleted without further notice. The backup arrangements are described in the backup policy.
2.3. The Services offered by the Provider are presented on the Cloudbizz website, while the Services ordered by the Client and their prices are set out in Article 1 of the special terms.
2.4. The purpose of these general terms and conditions is to define the conditions under which the Provider delivers the Products and performs the Services that are entrusted to it by the Client and that the Provider accepts.
2.5. Unless otherwise agreed in writing by the Provider, orders only become final once the Provider has sent the order confirmation to the Client. The order forms on the website constitute a request for an offer: they do not bind either party before such confirmation.
2.6. The lead times for delivery of the Products or provision of the Services are given for information purposes only. In the event of late delivery or provision, whatever the cause, the Client may not claim any compensation, cancel the order or terminate the Agreement without the Provider’s prior written consent.
2.7. Any lack of conformity that existed at the time of delivery and that the Client could reasonably have noticed is deemed to have been accepted immediately if the Client was present at delivery. If the Client was absent at delivery, or if the Products have to be unpacked or assembled by the Client itself, the Client must notify the Provider of any comments by registered letter within 8 working days of delivery. In the event of a lack of conformity of a Product, the Provider shall replace it as soon as possible.
2.8. Risk passes to the Client, even in the case of carriage-paid or free-to-domicile delivery, as soon as the Products are handed over to the shipper, the carrier or the person collecting them, the Products always travelling at the Client’s risk. This rule also applies in the event of partial delivery.
2.9. The precise arrangements for performing and monitoring the Services are, where applicable, detailed for each Service in the purchase order.
Article 3 — Term of the Agreement
3.1. Unless otherwise provided in the special terms, the Agreement is concluded for a minimum term of 12 months, starting on the date of signature and ending on 31 December of the following calendar year.
3.2. Unless either party has notified, by registered letter confirmed by email, its intention not to renew the Agreement at least three months before the contractual expiry date, the Agreement is renewed for successive further periods of 12 months, each starting on 1 January and ending on 31 December, on the same terms, except as regards the Fee, in accordance with Article 4 below.
3.3. Each party is entitled to terminate the Agreement as of right and with immediate effect if the other party commits a serious breach of its contractual obligations. A serious breach includes, in particular, any breach that makes the continuation of the contractual relationship immediately impossible, such as a party remaining in default of one of its obligations more than 30 days after having been given formal notice to comply with it.
3.4. The Agreement terminates automatically if either party becomes insolvent, is declared bankrupt, becomes subject to judicial reorganisation proceedings, goes into liquidation or becomes subject to any other equivalent measure resulting in the definitive loss of the other party’s confidence.
Article 4 — Fee and invoicing
4.1. In consideration for the Services, the Client shall pay the Provider the amounts corresponding to the products ordered, within 15 (fifteen) days of receipt of each invoice from the Provider (hereinafter the “Fee”).
4.2. The Fee, exclusive of taxes, is set according to:
- (i) the type and frequency of the Services ordered by the Client, as defined in Article 1 of the special terms on the basis of the subscription plan and options chosen by the Client; and
- (ii) the number of users subscribed to the Services through the Client, a subscription meaning the monthly subscription, for a minimum term of 12 months unless otherwise provided in the special terms, to one or more services offered by the Provider.
4.3. Any reduction in the Fee resulting from the number of subscribed users applies only for as long as that number remains the same, or at least within the band corresponding to the price obtained. If it turns out that a reduction has been applied without this criterion actually being met, the Provider is entitled to invoice the portion of the Fee that it had unduly waived.
4.4. Invoicing takes place on a monthly basis. Any invoice not disputed by the Client within 8 days is deemed to have been accepted.
Without prejudice to any other rights and remedies of the Provider, any sum owed by the Client under the Agreement shall bear, from its due date, automatically and without formal notice, interest at the rate of 8% (eight per cent) per year, any month begun being counted in full.
For each payment reminder, a flat-rate administrative charge of EUR 75 (seventy-five) is automatically added to the next invoice, in addition to the monthly instalment of the Fee. In the event of a repeat occurrence, this amount is doubled to EUR 150 (one hundred and fifty).
4.5. In the event of tacit renewal of the Agreement, the Fee is calculated on the basis of the rates applicable on the renewal date, as notified by the Provider 3 (three) months before that date and published on the Provider’s website. The costs borne by the Provider vary from year to year, in particular depending on the prices charged for the use of products from third-party publishers, including Microsoft, which the Provider does not own.
4.6. Unless otherwise agreed in writing by the Provider, for any order that includes hardware delivered and/or installed:
- (i) a deposit of 30% of the total amounts to be invoiced may be requested when the order is placed;
- (ii) the Products sold remain the exclusive property of the Provider until the Client has paid the sale price in full. In the event of non-payment by the due date, the Provider reserves the right, without prior formal notice, to take back the Products delivered.
4.7. Invoicing terms for Microsoft subscriptions (CSP / NCE)
Microsoft subscriptions and licences supplied by the Provider (in particular Microsoft 365 and Azure) are invoiced in accordance with Microsoft’s billing rules applicable to the Cloud Solution Provider (CSP) programme and the New Commerce Experience (NCE) model. For the subscriptions concerned, the rules below prevail over any conflicting clause of these terms.
General principle
- The billing period corresponds to the full calendar month, from the first to the last day of the month.
- The invoice is issued monthly, at the beginning of the month, and amounts are invoiced in advance for the coming monthly period.
- Activations and cancellations follow the Microsoft rules described below.
Activation of a licence
- Billing starts on the day the licence is activated.
- The first month is invoiced pro rata to the number of days remaining until the end of the calendar month.
- This pro rata amount appears on the following month’s invoice, under the heading “Initial period adjustment”.
- Example: a licence activated on 20 October results in the remaining days of October being invoiced on the invoice of 1 November.
Monthly renewal
- Any licence that is active on the first day of the month is invoiced for the full month.
- No reduction or pro rata adjustment is applied in the event of deactivation or deletion during the month.
- Monthly invoices are drawn up on the basis of the status of the licences on the first day of the month.
Cancellation or deletion
- If a licence is cancelled during the month, the full month remains payable.
- In accordance with Microsoft’s policy, no refund is made for the remaining period of the month; the cancellation takes effect for the following month.
Due date
- Invoices are issued on the first day of each month and cover the period from the first to the last day of the month concerned.
- Amounts relating to subscriptions governed by CSP/NCE are payable upon receipt of the invoice.
- Any month begun is payable in full.
| Date | Client action | Invoicing |
|---|---|---|
| 20/10 | Licence activated | Pro rata from 20 to 31 October on the invoice of 01/11 |
| 01/11 | Licence active | Month of November invoiced in full |
| 11/11 | Cancellation | Month of November payable in full, effective end on 30/11 |
| 01/12 | Licence deleted | No further invoicing from December |
Article 5 — Data Centres
5.1. The Client’s data is stored on servers owned by the Provider, located in the Digital Realty Brussels BRU1 (Wezembeekstraat 2 bus 1, 1930 Zaventem) and Digital Realty Brussels BRU3 (Mercuriusstraat 27, 1930 Zaventem) Data Centres.
5.2. The Provider has the right to change the location of the Data Centre(s) without having to notify the Client or seek its authorisation, provided that:
- (i) the new location is within the territory of the European Union;
- (ii) the new location offers at least equivalent protection with regard to the protection of personal data.
5.3. The Provider may move the Data Centre(s) outside the territory of the European Union only after:
- (i) having notified the Client in writing at least 3 (three) months in advance;
- (ii) having given the Client the opportunity to terminate the Agreement early and without compensation on account of this relocation, within 30 (thirty) days of the notification; early termination of the Agreement does not, however, release the Client from its obligation to pay the Provider’s outstanding invoices.
5.4. The Provider may move the Data Centre(s) outside the territory of the European Union, to a country that does not ensure an adequate level of protection, only after (i) having obtained the Client’s prior written authorisation and (ii) having implemented appropriate safeguards or binding corporate rules in accordance with the Regulation.
5.5. Where a processor for the Data Centres is added or replaced, the Provider carries out the necessary prior checks to ensure that this processor is able to comply with the same data protection obligations as those set out in the Agreement, and in particular to provide sufficient guarantees as to the implementation of appropriate technical and organisational measures, so that the processing meets the requirements of the Regulation.
Article 6 — Service hours and response times
The Provider uses its best efforts to guarantee access to its infrastructure 24 hours a day, 7 days a week. Access may, however, be temporarily suspended, in particular due to technical work aimed at improving the system or any maintenance operation. The Provider uses its best efforts to keep the duration of any suspension of the Services to a minimum. In the event of planned maintenance, the Client is informed directly and at least 24 hours in advance, except in cases of force majeure.
In view of the foregoing, the availability target for the Services is 99.5%, excluding any specific SLA. The availability level is calculated on a monthly basis. Any enhanced commitments subscribed to are described in the Service Level Agreement.
The foregoing is without prejudice to any Internet connection problems that depend on the access provider with which the Client has taken out its subscriptions.
Article 7 — Fate of the data at the end of the Agreement
At the end of the Agreement, the Client may request either the deletion of all its data or the recovery of all its data and files stored with the Provider under the Agreement (hereinafter the “Reversibility Option”).
On pain of forfeiture, the Reversibility Option must be exercised within 3 (three) months of the expiry of the Agreement, whatever the cause, and be notified by registered letter with acknowledgement of receipt.
If the Reversibility Option is exercised, the Provider destroys the existing copies, unless Union law or the law of a Member State requires the data to be retained.
Failing notification of the Reversibility Option, the Client is deemed to have waived its data, which may then be destroyed by the Provider without further notice, under conditions that ensure its confidentiality.
During the performance of the Agreement, the Client may at any time exercise a partial Reversibility Option in respect of the data and files stored with the Provider.
The costs of transferring the Client’s data are invoiced on the basis of a flat fee of EUR 250 per transfer. Data return services are subject to full payment of all outstanding invoices of the Provider still owed by the Client.
Article 8 — Information to the Client
The Client acknowledges that it has verified that the Services are suited to its needs and that it has received from the Provider all the information and advice necessary to verify, before signing the Agreement, that the Agreement meets its needs. It therefore releases the Provider from any liability in this respect, provided that the Provider has not been consulted.
Article 9 — Obligations and liabilities of the parties
A) Obligations and liabilities of the Provider
9.1. The Provider undertakes to exercise all the care and diligence necessary to provide a quality service. The obligation undertaken by the Provider in connection with the services covered by the Agreement is an obligation of result limited to the service level provided for in Article 6.
9.2. The Provider is furthermore released from all liability where the Services cannot be guaranteed due to the occurrence of one or more of the following events:
- (i) the impossibility of installing the Client’s software on the Provider’s servers; the compatibility of software that has not been validated by the Provider cannot be guaranteed;
- (ii) deterioration of the Services caused by the Client or by a person for whom it is responsible, and/or failure to follow the advice given;
- (iii) misuse of the servers and software by the Client or by a person for whom it is responsible;
- (iv) the partial or total destruction of information transmitted or stored as a result of errors directly or indirectly attributable to the Client or to a person for whom it is responsible;
- (v) total or partial failure by the Client or by a person for whom it is responsible to comply with an obligation, and/or the failure of Internet network operators, in particular the Client’s Internet access provider; the Provider expressly draws the Client’s attention to the fact that the Services depend on other technical operators and that the Provider can under no circumstances be held liable for the failure of those operators;
- (vi) force majeure in the broadest sense;
- (vii) the characteristics of the Internet, with which the Client declares itself to be fully familiar; in particular, the Provider cannot be held liable for the content of the information transmitted, disseminated or collected, its use and its updating, or for any file, in particular address files, sound, text, image, design element or data accessible on a website, on any basis whatsoever; for any misappropriation of passwords, confidential codes and, more generally, of any information that is sensitive for the Client, the management of which is the sole responsibility of the Client, the Provider for its part taking the security measures specific to the Services; or for the untimely disclosure of confidential information concerning the Client following a system defect or hacking.
B) Obligations and liabilities of the Client
9.3. The Client is solely responsible for the use that it makes, and that is made, of the Services. It shall indemnify the Provider against any claim or demand by third parties, on any basis whatsoever, that may be brought against the Provider.
9.4. The Client is responsible for the websites, for the content of the information transmitted, disseminated or collected, for its use and its updating, and for any file, in particular address files, that it consults, compiles or uses in connection with the use of the Services.
9.5. The Client undertakes to respect the rights of third parties, in particular personality rights and intellectual property rights such as copyright, patents and trademarks. If it wishes to host third-party software not supplied by the Provider on the servers made available to it, the Client shall verify that such hosting is not prohibited by the licence for that software and shall hold the Provider harmless against any claim or action by the publisher alleging that such hosting was not authorised.
9.6. The Client is responsible for the security of its accounts and/or websites. In the event of hacking, the Client shall immediately inform the Provider, identify the vulnerability and fix it, the Provider being fully released from any liability in this respect.
9.7. The Client undertakes to ensure strict and full compliance with the provisions of the Agreement, in particular the acceptable use policy.
9.8. The Provider reserves the right, in the cases provided for by applicable law, to cooperate with administrative and judicial authorities and to respond to their orders or requests for information, provided that these comply with the law. In this context, it may be required to disclose information about the Client to those authorities and/or to interrupt the Services, without the Client being entitled to make any claim or receive any compensation. Likewise, the Provider reserves the right to remove from its servers any software that the Client has asked it to host if the publisher of that software so requires and reasonably demonstrates to the Provider that such hosting by a third party was not authorised by the licence granted to the Client.
9.9. The Client undertakes to safeguard the brand image of Cloudbizz in particular and of NET COMPUTER GROUP SA in general.
9.10. In the case of an on-site installation:
- (i) the Client makes available all the resources necessary to perform the Services, in particular in terms of people and information;
- (ii) unless otherwise agreed between the parties, the Client has backup copies of all the systems on which the Provider is to work, as well as antivirus programs that are installed and up to date.
Article 10 — Support availability
10.1. Any failures or disruptions of the Services must be reported immediately to the Provider’s technical support, by email to support@cloudbizz.com or by telephone on +32 2 305 74 05. The Provider is bound by an obligation of means: it deploys all its human and technical resources to perform the Agreement.
10.2. The Provider’s services are normally available from Monday to Friday, from 9 am to 6 pm, excluding weekends and public holidays (hereinafter the “Normal Availability Hours”). Outside these hours, the Provider’s services can be reached only in an emergency, by telephone on +32 2 305 74 05.
10.3. Outside Normal Availability Hours, any support intervention under this Article is subject to a minimum charge of EUR 95, in addition to the basic hourly rate increased by 50%, unless the need for such intervention results from a matter attributable to the Provider.
10.4. In the case of a disaster recovery system (DRS) covered by an SLA, the time taken to resolve a problem by means of a workaround may not exceed 48 hours, compliance with this time limit constituting an obligation of result.
Article 11 — Insurance
The Client shall indemnify the Provider against any claim or demand by third parties in connection with the services provided by the Client, excluding the Services purchased from the Provider.
To this end, the Client warrants that it holds and will maintain in force, at its own expense, adequate and sufficient insurance cover for the type of activity it carries out, in accordance with the regulations in force and the standards of a prudent and diligent business carrying out that type of activity.
The insurance policy includes, as a minimum, comprehensive multi-risk business cover and general third-party liability insurance. On the date on which the Agreement enters into force, the Client shall provide proof of payment of the premium and an insurance certificate evidencing the required cover, which includes a clause providing that the Provider will be notified in writing at least two months before the cancellation of, or any material change to the terms of, the cover.
Failure by the Client to take out insurance in accordance with this Article results in the termination of the Agreement as of right for serious breach.
Article 12 — Limitation of liability clause
The Provider can under no circumstances be held liable for indirect damage such as, in particular, loss of earnings, commercial loss, increased overheads, disruption of scheduling, damage to brand image, or loss of profit, customers or anticipated savings, or for claims made by a third party against the Client.
For any damage occurring and established during the term of the Agreement and resulting from a proven breach by the Provider of its obligations, the amount of compensation payable in respect of any liability of the Provider may not exceed an amount equivalent to the annual Fee, calculated on the basis of the invoices issued and paid during the 12 months preceding the date of the breach.
In addition, on pain of forfeiture, any claim must be notified to the Provider within 72 calendar hours of becoming aware of the event likely to give rise to its liability.
Article 13 — Termination as of right
13.1. The parties expressly agree that, should the Agreement be terminated owing to the fault of one of them, the defaulting party shall compensate the other party for the damage suffered, without such compensation exceeding an amount equivalent to the annual Fee, calculated on the basis of the invoices issued during the 12 months preceding the date of compensation.
13.2. Failure to pay by its due date an invoice relating to a monthly instalment of the Fee entitles the Provider, after formal notice, either to suspend the Services covered by the invoice or to terminate the Agreement owing to the Client’s fault.
In addition to non-payment of the Fee, the following situations constitute, by express agreement, grounds for termination as of right:
- (i) failure by the Client to comply with any of the obligations undertaken in Article 9 of the Agreement;
- (ii) the dissemination by the Client of any content likely to give rise to civil and/or criminal liability;
- (iii) failure to respect the Provider’s intellectual property rights;
- (iv) in general, any serious or repeated breach of any provision of the Agreement.
The Agreement is suspended or terminated if the Client has not remedied its breaches within 48 hours of the Provider sending a reminder to that effect.
Article 14 — Use of name
In order to promote the Cloudbizz platform, the Provider is authorised to use the Client’s name.
Article 15 — Confidentiality
15.1. The parties shall preserve the confidentiality of all information of which they become aware in connection with the Agreement and shall ensure that the members of their staff who have access to personal data in the performance of their duties are aware of and comply with the obligations relating to the confidentiality of such data.
15.2. The Provider ensures that all persons authorised to process the data:
- (i) are informed of the confidential nature of the data;
- (ii) have received appropriate training on the applicable personal data protection legislation;
- (iii) are subject to authentication and login procedures in order to access the data.
15.3. The Provider implements access controls and policies designed to restrict access to the Client’s personal data to those employees who need to process such data in order to provide the Services. When access to such data is no longer necessary for the performance of the Services, the Provider immediately revokes that access privilege.
Article 16 — Protection of personal data
In the context of their contractual relationship, the parties undertake to comply with the regulations applicable to the processing of personal data, in particular the Regulation. In this respect, the Provider acts as processor and the Client as controller.
16.1. Purposes of the processing. The Provider processes data only to the extent necessary for the performance of the Services described in the Agreement. The processing consists of any activity carried out in accordance with the Client’s instructions and necessary for the provision of the Services. Unless expressly agreed, the Provider shall not process the data for any other purpose.
As part of its support activities, the Provider may, at the Client’s request, need to process personal data, in particular during a remote control session. In all cases, it is for the Client to control such access and its duration according to the objectives pursued. At the end of its intervention, the Provider does not retain any personal data of the Client.
16.2. Duration of the processing. The duration of the processing is limited to the term of the Agreement. The Provider’s obligations relating to the processing end once the Client has exercised the Reversibility Option or, failing that, upon the deletion or destruction of the data provided for in Article 7.
16.3. Types of data and categories of data subjects. The type of data processed is not defined. Given the nature of the Services, the personal data processed may be varied and depends on the Client’s use of the Services. The categories of data subjects may also be varied (customers, prospects, employees, suppliers or others).
16.4. Obligations of the Provider
(i) Compliance with the Client’s instructions. The Provider processes personal data only for the purposes strictly necessary for the performance of its obligations and on documented instructions from the Client, in accordance with the Agreement or with instructions given by any other means during its performance, unless required to do so by Union or Member State law to which it is subject. In such a case, the Provider shall inform the Client of that legal requirement before the processing, unless that law prohibits such information on important grounds of public interest.
(ii) Assistance with the exercise of data subjects’ rights. The Provider assists the Client, insofar as possible and by appropriate technical and organisational measures, in responding to requests from data subjects seeking to exercise the rights laid down in Chapter III of the Regulation. Where applicable, this assistance is invoiced on the basis of the hours worked.
(iii) Assistance with compliance with Articles 32 to 36 of the Regulation. Taking into account the nature of the processing and the information available to it, the Provider assists the Client, at the Client’s request:
- in implementing the technical and organisational measures ensuring an appropriate level of security, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing, as well as the risks, of varying likelihood and severity, for the rights and freedoms of natural persons;
- in connection with the notification of a data breach to the supervisory authority and/or to the data subjects;
- where applicable, in carrying out a data protection impact assessment or a prior consultation of the supervisory authority.
Where applicable, this assistance is invoiced on the basis of the hours worked.
(iv) Record of processing activities. The Provider maintains a record of processing activities in accordance with Article 30(2) of the Regulation, covering all categories of activities carried out on behalf of the Client and containing:
- the name and contact details of the Client, of any processors and, where applicable, of the data protection officer;
- the categories of processing carried out on behalf of the Client;
- where applicable, transfers of data to a third country or an international organisation, including the identification of that third country or international organisation and, for the transfers referred to in the second subparagraph of Article 49(1) of the Regulation, the documents attesting to the existence of appropriate safeguards.
(v) Data protection by design and by default. For its tools, products, applications and services, the Provider takes into account the principles of data protection by design and data protection by default.
16.5. Obligation of the Client. The Client ensures that the data it collects and processes is collected and processed in accordance with the Regulation and the applicable laws.
16.6. Security measures. The Provider takes appropriate technical and organisational measures to ensure a level of security appropriate to the risk and to prevent any breach of security leading to the accidental or unlawful destruction, loss, alteration or unauthorised disclosure of, or access to, data transmitted, stored or otherwise processed. In particular, the Provider takes the following measures, as required:
- (i) the pseudonymisation and encryption of personal data;
- (ii) the means to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;
- (iii) the means to restore the availability of and access to personal data in a timely manner in the event of a physical or technical incident;
- (iv) a process for regularly testing, analysing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing.
The technical and organisational measures are described in Annex 1 — Security measures. The Provider is not solely responsible for security: certain aspects fall within the Client’s responsibility, and Annex 1 defines the respective responsibilities of the parties.
16.7. Data breach
(i) Security incident management policy. The Provider applies a security incident management policy that specifies the procedures to be followed to identify and respond to incidents. It includes guidelines on the types of incidents to be notified to the Client, according to their potential impact on the data, on how to notify them and on the information to be provided.
(ii) Notification. In the event of a data breach, or where circumstances indicate that such a breach is likely to occur, the Provider informs the Client immediately after becoming aware of it, by an email marked “high importance” and “immediate follow-up”. This email includes at least: a summary, the circumstances and nature of the incident, the content and quantity of the data concerned, the categories and number of data subjects concerned, the likely consequences, the measures taken or proposed to remedy the breach and, where appropriate, to mitigate its adverse effects, the date and time of the incident and of its detection, and the name and contact details of the data protection officer or another contact point. The Provider answers any further questions from the Client and takes all reasonable measures required by the Client to remedy the breach and limit its effects.
16.8. Audit and inspection by the Client. Where the Client requires an audit, it shall inform the Provider at least five (5) working days in advance and ensure that the audit does not unreasonably interfere with the Provider’s activities. The Provider cooperates with the audits and inspections carried out by the Client or by an auditor mandated by the Client, and makes available to the Client, on request, all information necessary to demonstrate compliance with its obligations and to allow for audits, including inspections. The conclusions of the audit report are communicated to the Provider in order to define, where applicable, an action plan; in the event of non-compliance, the parties agree on the corrective measures and the time frame for their implementation. Audits are entirely at the Client’s expense; any involvement of the Provider’s technical resources beyond three (3) hours is invoiced at the rate set out in the special terms.
16.9. Subcontracting. The Provider may use a subcontractor to perform all or part of the Services (general authorisation). It informs the Client of any intended changes concerning the addition or replacement of subcontractors. Where such a subcontractor processes personal data, the Provider ensures that it complies with the conditions of Article 28 of the Regulation, and the Provider remains fully liable to the Client for the performance of the subcontractor’s obligations.
16.10. Legal obligations and requests from authorities. The Provider does not disclose personal data to authorities of third countries, unless this is necessary to comply with a valid and legally binding judgment, order or request, and then only to the extent necessary. Unless legally prohibited, it informs the Client in advance so as to enable the Client to object to such disclosure.
16.11. Liability. Without prejudice to Article 12, each party is responsible, as far as it is concerned, for compliance with the Regulation; the contractual obligations of the parties may not prevent the performance of their respective legal obligations. With regard to third parties, the Provider may be held liable only for material or non-material damage caused by a breach of the Regulation, where it has not complied with the obligations specifically incumbent on it as a processor or has acted outside or contrary to the lawful instructions of the Client, and unless it proves that it is in no way responsible for the event giving rise to the damage.
Article 17 — Staff
Throughout the term of the Agreement and for the 24 (twenty-four) months following its termination, for any reason whatsoever, the parties mutually undertake not to hire or offer to hire, in any capacity whatsoever, any person who works or has worked on behalf of the other party.
Minimum compensation equal to six (6) months of the gross remuneration of the employee or collaborator concerned is payable as compensation for the loss caused, in particular the loss of profits and projects, prospecting, selection and training costs and the loss of know-how, without prejudice to the right of the injured party to establish its actual loss.
Article 18 — Non-competition clause
The parties undertake not to approach each other’s respective customers or enter into contracts with them throughout the term of the Agreement and for six months following its expiry, for any reason whatsoever.
Article 19 — Contractual amendments
Any amendment to the Agreement may only be made in a written document signed by both parties. No amendment may be inferred from the passivity of the parties or from mere tolerance, regardless of its frequency and duration, the parties always remaining free to demand strict application of the clauses that have not been expressly amended.
Article 20 — Invalidity of a clause
The invalidity of one or more clauses of the Agreement does not render the Agreement as a whole invalid. The invalid clause is deemed not to have been written only to the extent of its unlawfulness, the parties undertaking to replace it with an economically equivalent clause.
Article 21 — Election of domicile
For the performance of the Agreement, the Client elects domicile at its registered office as stated in the special terms, for the entire term of the Agreement and for all its consequences. The Client may notify the Provider of a new election of domicile, provided that the address is in Belgium.
Article 22 — Governing law and choice of forum
The Agreement is governed by Belgian law. Any dispute relating to its performance or interpretation falls within the exclusive jurisdiction of the courts and tribunals of the judicial district of Brussels, ruling in French.
Article 23 — Miscellaneous
23.1. In the event of any conflict between the Agreement and any prior agreement, the Agreement prevails. In the event of any conflict between the Agreement and the annex constituting the SLA, the Agreement prevails.
23.2. In the event of any conflict between the Provider’s general terms and conditions of sale and the Client’s general terms and conditions of purchase, the former prevail.
23.3. Unless otherwise stipulated, any notification is validly made to the email addresses indicated in the special terms. Insofar as possible and where necessary, the parties confirm such notification by ordinary post sent to their respective registered offices.
Article 24 — Product warranty
The warranty for the Product, its components and labour is the warranty granted by the manufacturer of the Product, excluding any costs incurred by the Client. The Provider can under no circumstances be bound by a warranty exceeding that of the manufacturer. The warranty does not cover damage resulting from improper use, normal wear and tear, faulty or negligent handling or the addition of parts during the warranty period, which are not attributable to the Provider.