Spendkey SAAS Agreement
PARTIES
(1) Spendkey Limited incorporated and registered in England and Wales with company number13024995 whose registered office is at 213 Kingsbury Road, Sri Abji Bapashree House, Suite 15 I Floor, London NW9 8AQ United Kingdom, (the "Supplier"); and
(2) <insert client name>a company registered in England and Wales under registration number <insert>whose registered address is <insert> (the "Customer")
RECITAL
(A) The Supplier has developed certain software applications and platforms which it makes available to subscribers via the internet on a pay-per-transaction basis for the purpose of categorising and analysing 3rd party expenditure and related activities.
(B) The Customer wishes to use the Supplier's Services in its internal business operations.
() The Supplier hasagreed to provide, and the Customer has agreed to take and pay for theSupplier's Services subject to the terms and conditions of this agreement.
WHEREBY IT IS AGREED as follows:
1. INTERPRETATION
1.1 The definitions and rules of interpretation in this clause apply in this agreement.
“Affiliate” means any subsidiary or parent undertaking of the Customer as defined in s1159 of the Companies Act 2006;
"Authorised Users" means those employees, agents and independent contractors of the Customer who reside in the Territory and who are authorised by the Customer to import Aggregated Annual Spend and Aggregated Annual Documents and use the Services and the Documentation, as further described in clause 2.3.3;
"Business Day" means a day other than a Saturday, Sunday or public holiday in England when banks in London are open for business;
"Confidential Information" means information that is proprietary or confidential and is either clearly labelled as such or identified as Confidential Information in clause 10;
"Customer Data" means the input of Aggregated Annual Spend and Aggregated Annual Documents by the Customer, Authorised Users, or the Supplier on the Customer's behalf into the Spendkey web interface for the purpose of using the Services or facilitating the Customer's use of the Services and shall include all modifications thereof;
"Deliverable" means any materials, software or other output generated by the Supplier or the Supplier Personnel in performing its obligations under this agreement;
"Documentation" means the document or help menu made available to the Customer by the Supplier online via www.spendkey.io or such other web address notified by the Supplier to the Customer from time to time which sets out a description ofthe Services and the user instructions for the Services;
"Effective Date" means the date of this agreement;
"Initial Term" means as set out in schedule 1;
"Normal Business Hours" means 9.00 am to 5.00 pm UK time, eachBusiness Day;
"Renewal Period" has the meaning given in clause 14 (being successive periods of 12 months following the Initial Term);
"Services" means the license services provided by the Supplier to the Customer under this agreement via www.spendkey.io or any other website notified to the Customer by the Supplier from time to time, as more particularly described in the Documentation;
"Software" means the online software applications provided by the Supplier as part of the Services;
"License Fees" means the license fees payable by the Customer to the Supplier for the number of Aggregated Annual Spend and Aggregated Annual Documents used by the Customer, as set out in
Schedule1: Fees;
"Supplier Personnel" means Supplier's directors, officers, employees, agents, contractors and subcontractors and the employees of its agents, contractors and subcontractors;
"Support Services Policy" means the Supplier's policy for providing support in relation to the Services as set out in Schedule 2:Support Services Policy;
"Term" has the meaning given in clause 14 (being the Initial Term together with any subsequent renewals);
“Territory” means EMEA for the purposes of this agreement "Aggregated Annual Spend " means the number of Aggregated Annual Spend purchased by the Customer pursuant to clause 8 which entitle Authorised Users to access the Software, import Customer Data and use the Services and the Documentation in accordance with this agreement;
“Aggregated Annual Documents” means the number of Aggregated Annual Documents purchased by the Customer pursuant to clause 8 which entitle Authorised Users to access the Software, import Customer Data and use the Services and the Documentation in accordance with this agreement;
1.2 Clause, schedule and paragraph headings shall not affect the interpretation of this agreement.
1.3 Any reference to persons includes natural persons, firms, partnerships, limited liability partnerships, companies, corporations, unincorporated associations, local authorities, governments, states, foundations and trusts (in each case whether or not having separate legal personality) and any agency of any of the above.
1.4 A reference to a company shall include any company, corporation or other body corporate, wherever and however incorporated or established.
1.5 Unless the context otherwise requires, words in the singular shall include the plural and in the plural shall include the singular.
1.6 Unless the context otherwise requires, a reference to one gender shall include a reference to all genders.
1.7 A reference to a statute or statutory provision is a reference to it as it is in force as at the date of this agreement.
1.8 A reference to a statute or statutory provision shall include all subordinate legislation made as at the date of this agreement under that statute or statutory provision.
1.9 A reference to writing or written includes faxes but not e-mail.
1.10 References to clauses and schedules are to the clauses and schedules of this agreement; references to paragraphs are to paragraphs of the relevant schedule to this agreement.
2. AGGREGATED ANNUAL SPEND AND AGGREGATED ANNUALDOCUMENTS
2.1 Subject to the Customer purchasing Aggregated Annual Spend and Aggregated Annual Documents in accordance with clause 3 and clause 8.1, the restrictions set out in this clause 2 and the other terms and conditions of this agreement, the Supplier hereby grants to the Customer a non-exclusive, non-transferable right to permit the Authorised Users to access the Software, import Aggregated Annual Spend and Aggregated Annual Documents and to use the Services and the Documentation during the Term solely for the Customer's internal business operations. The licence terms governing the use of the Deliverables is set out in clause 9.4 below.
2.2 In relation to the Aggregated Annual Spend and Aggregated Annual Documents, the Customer undertakes that:
2.2.1 the maximum number of Aggregated Annual Spend and Aggregated Annual Documents that it is authorised to import and use the Services and the Documentation shall not exceed the number of Aggregated Annual Spend and Aggregated Annual Documents it has purchased from time to time;
2.2.2 it shall maintain a written, up to date record of Aggregated Annual Spend and Aggregated Annual Documents and provide such record to the Supplier within 5 Business Days of the Supplier's written request at any time or times;
2.2.3 it shall permit the Supplier to audit the Services in order to establish the use of Aggregated Annual Spend and Aggregated Annual Documents in each Renewal Period. Such audit may be conducted no more than once per year, at the Supplier's expense, and this right shall be exercised with reasonable prior notice, in such a manner as not to substantially interfere with the Customer's normal conduct of business.
2.3 In relation to the Authorised Users, the Customer undertakes that:
2.3.1 it will not allow or suffer any username or password to be used by more than one individual Authorised User unless it has been reassigned in its entirety to another individual Authorised User, in which case the prior Authorised User shall no longer have any right to access or use the Services and/or Documentation;
2.3.2 each Authorised User shall keep a secure password for his use of the Services and Documentation, that such password shall be changed no less frequently than Monthly and that each Authorised User shall keep his password confidential;
2.3.3 it shall maintain a written, up to date list of current Authorised Users and provide such list to the Supplier within 5 Business Days of the Supplier's written request at any time or times;
2.3.4 it shall permit the Supplier to audit the Services in order to establish the use of usernames and passwords of Authorised Users within the Territory. Such audit may be conducted no more than once per year, at the Supplier's expense, and this right shall be exercised with reasonable prior notice, in such a manner as not to substantially interfere with the Customer's normal conduct of business;
2.4 If any of the audits referred to in clause 2.2.3 and 2.3.4 reveal that the maximum number of Aggregated Annual Spend and Aggregated Annual Documents has been exceeded or that any username or password has been provided to any individual outside the Territory, then without prejudice to the Supplier's other rights, the Customer shall promptly disable the import of Aggregated Annual Spend and Aggregated Annual Documents and disable usernames and passwords and the Supplier shall not issue any new Aggregated Annual Spend and Aggregated Annual Documents, usernames and passwords omitted; and
2.5 if any of the audits referred to in clause 2.2.3 and 2.3.4 reveal that the Customer has underpaid License Fees to the Supplier, then without prejudice to the Supplier's other rights, the Customer shall pay to the Supplier an amount equal to such underpayment as calculated in accordance with the prices set out in
2.6 Schedule 1: Fees within 7 Business Days of the date of the relevant audit.
2.7 The Customer shall not:
2.7.1 except as may be allowed by any applicable law which is incapable of exclusion by agreement between the parties:
2.7.1.1 and except to the extent expressly permitted under this agreement, attempt to copy, modify, duplicate, create derivative works from, frame, mirror, republish, download, display, transmit, or distribute all or any portion of the Software and/or Documentation (as applicable) in any form or media or by any means; or
2.7.1.2 attempt to reverse compile, disassemble, reverse engineer or otherwise reduce to human-perceivable form all or any part of the Software; or
2.7.1.3 access all or any part of the Services and Documentation in order to build a product or service which competes with the Services and/or the Documentation; or
2.7.1.4 use the Services and/or Documentation to provide services to third parties; or
2.7.1.5 subject to clause 21.1, license, sell, rent, lease, transfer, assign, distribute, display, disclose, or otherwise commercially exploit, or otherwise make the Services and/or Documentation available to any third party except the Authorised Users, or
2.7.1.6 attempt to obtain, or assist third parties in obtaining, access to the Services and/or Documentation, other than as provided under this clause 2; and
2.8 The Customer shall use all reasonable endeavours to prevent any unauthorised access to, or use of, the Services and/or the Documentation and, in the event of any such unauthorised access or use, promptly notify the Supplier.
2.9 The rights provided under this clause 2 are granted to the Customer and its Affiliates.
3. ADDITIONAL AGGREGATED ANNUAL SPEND AND AGGREGATED ANNUAL DOCUMENTS
3.1 Subject to clause
3.2, the Customer may, from time to time during the Term, purchase additional Aggregated Annual Spend and Aggregated Annual Documents and the Supplier shall grant the import of such additional Aggregated Annual Spend and Aggregated Annual Documents to the Software in accordance with the provisions of this agreement.
3.2 If the Customer wishes to purchase additional Aggregated Annual Spend and Aggregated Annual Documents, the Customer shall purchase these by paying the relevant license fees to the Supplier as per the License Fees outlined in
3.3 Schedule 1: Fees. Any additional Fees will be adjusted on a pro-rata basis, calculated according to the number of months, and rounded up to the nearest whole month, remaining in the period and charged in advance.
4. SERVICES
4.1 The Supplier shall, during the Term, provide the Services and make available the Documentation to the Customer on and subject to the terms of this agreement.
4.2 The Supplier shall use reasonable endeavours to make the Services available 24 hours a day, seven days a week, except for: 4.2.1 planned maintenance carried out during the maintenance window of 10.00 pm to 4.00 am UK time; and
4.2.2 unscheduled maintenance performed outside Normal Business Hours.
4.3 The Supplier will, as part of the Services and at no additional cost to the Customer, provide the Customer with the Supplier's standard customer support services during Normal Business Hours in accordance with Schedule 2:Support Services Policy
4.4 The Supplier may amend the Support Services Policy in its sole and absolute discretion from time to time. The Customer may purchase enhanced support services separately at the Supplier's then current rates.
5. CUSTOMER DATA
5.1 The Customer shall own all right, title and interest in and to all of the Customer Data and shall have sole responsibility for the legality, reliability, integrity, accuracy and quality of the Customer Data.
5.2 In the event of any loss or damage to Customer Data, the Customer's sole and exclusive remedy shall be for the Supplier to use reasonable endeavours to restore the lost or damaged Customer Data. The Supplier shall not be responsible for any loss, destruction, alteration or disclosure of Customer Data caused by any third party (except those third parties sub-contracted by the Supplier to perform services related to Customer Data maintenance and back-up).
5.3 The Customer grants Supplier a worldwide, non-exclusive, limited term licence to access, use, copy, distribute, perform and display Customer Data only as reasonably necessary to provide the Services to Authorised Users in accordance with this Agreement.
5.4 Both Parties will comply with Schedule 3: Personal Data Processing Terms and all applicable requirements of the Data Protection Legislation. This clause 5 and Schedule 3: Personal Data Processing Terms are in addition to, and does not relieve, remove or replace, a Party’s obligations or rights under the Data Protection Legislation.
5.5 The Parties acknowledge that if Supplier processes any Personal Data on the Customer’s behalf when performing its obligations under this Agreement, the Customer is the Controller and Supplier is the Processor for the purposes of the Data Protection Legislation.
5.6 Without prejudice to the generality of clause 5.5, the Customer will ensure that it has all necessary appropriate consents and notices in place to enable lawful transfer of the Personal Data to Supplier for the duration and purposes of this Agreement so that Supplier may lawfully use, Process and transfer the Personal Data in accordance with this Agreement on the Customer’s behalf.
6. SUPPLIER'S OBLIGATIONS
6.1 The Supplier undertakes that the Services will be performed substantially in accordance with the Documentation and with reasonable skill and care.
6.2 The undertaking at clause 6.1 shall not apply to the extent of any non-conformance which is caused by use of the Services contrary to the Supplier's instructions, or modification or alteration of the Services by any party other than the Supplier or the Supplier's duly authorised contractors or agents. If the Services do not conform with the undertaking at clause 6.1, Supplier will, at its expense, use all reasonable commercial endeavours to correct any such non-conformance promptly, or provide the Customer with an alternative means of accomplishing the desired performance. Such correction or substitution constitutes the Customer's sole and exclusive remedy for any breach of the undertaking set out in clause 6.1. Notwithstanding the foregoing, the Supplier:
6.2.1 does not warrant that the Customer's use of the Services will be uninterrupted or error-free; or that the Services, Deliverables and/or Documentation and/or any information obtained by the Customer through the Services will meet the Customer's requirements; or the Services will be free from vulnerabilities; and
6.2.2 is not responsible for any delays, delivery failures, or any other loss or damage resulting from the transfer of data over communications networks and facilities, including the internet, and the Customer acknowledges that the Services and Documentation may be subject to limitations, delays and other problems inherent in the use of such communications facilities.
6.3 This agreement shall not prevent the Supplier from entering into similar agreements with third parties, or from independently developing, using, selling or licensing documentation, products and/or services which are similar to those provided under this agreement.
6.4 This agreement shall not prevent the Supplier from sharing any aggregate, anonymised Customer Data to any third-party providers from time to time and as required by the Supplier. 6.5 The Supplier warrants that it has and will maintain all necessary licences, consents, and permissions necessary for the performance of its obligations under this agreement.
7. CUSTOMER'S OBLIGATIONS
The Customer shall:
7.1.1 provide the Supplier with:
7.1.1.1 all necessary co-operation in relation to this agreement; and
7.1.1.2 all necessary access to such information as may be required by the Supplier; in order to provide the Services, including but not limited to Customer Data, security access information and configuration services;
7.1.2 comply with all applicable laws and regulations with respect to its activities under this agreement;
7.1.3 carry out all other Customer responsibilities set out in this agreement in a timely and efficient manner. In the event of any delays in the Customer's provision of such assistance as agreed by the parties, the Supplier may adjust any agreed timetable or delivery schedule as reasonably necessary;
7.1.4 ensure that the Authorised Users use the Services and the Documentation in accordance with the terms and conditions of this agreement and shall be responsible for any Authorised User's breach of this agreement;
7.1.5 obtain and shall maintain all necessary licences, consents, and permissions necessary for the Supplier, its contractors and agents to perform their obligations under this agreement, including without limitation the Services;
7.1.6 ensure that its network and systems comply with the relevant specifications provided by the Supplier from time to time; and
7.1.7 be solely responsible for procuring and maintaining its network connections and telecommunications links from its systems to the Supplier's data centres, and all problems, conditions, delays, delivery failures and all other loss or damage arising from or relating to the Customer's network connections or telecommunications links or caused by the internet.
8. CHARGES AND PAYMENT
8.1 The Customer shall pay the annual License Fees to the Supplier for the purchased Aggregated Annual Spend and Aggregated Annual Documents within 30 days from the start of each Renewal Period in accordance with this clause 8 and as set out in
8.2 Schedule 1: Fees.
8.3 If the Supplier has not received payment prior to commencement of the use of the Services, and without prejudice to any other rights and remedies of the Supplier:
8.3.1 the Supplier may, without liability to the Customer, disable the Customer's password, account and access to all or part of the Services and the Supplier shall be under no obligation to provide any or all of the Services while the invoice(s) concerned remain unpaid.; and interest shall accrue on a daily basis on such due amounts at an annual rate equal to 5% over the then-current base lending rate of the Supplier's bankers in the UK from time to time, commencing on the due date and continuing until fully paid, whether before or after judgment.
8.4 All amounts and fees stated or referred to in this agreement:
8.4.1 are, subject to clause 13.3.2, non-cancellable and non-refundable;
8.4.2 are exclusive of the applicable value added tax.
8.5 If, at any time whilst using the Services, the Customer exceeds the amount of disk storage space specified in the Documentation, the Supplier shall charge the Customer, and the Customer shall pay, the Supplier's then current excess data storage fees. The Supplier's excess data storage fees current as at the Effective Date are set out in
8.6 Schedule 1: Fees.
8.7 The Supplier shall be entitled to increase the License Fees, the fees payable in respect of the additional Aggregated Annual Spend and Aggregated Annual Documents and Aggregated Annual Documents purchased pursuant to clause 3 and/or the excess storage fees payable pursuant to clause 8.5 at the start of each month from the renewal period upon 30 days' prior notice to the Customer.
8.8 Annual Subscription Fee adjustments – The subscription fees will be fixed for the first 12 months and thereafter be increased annually by United Kingdom Retail Price Index (RPI) plus five percent (5%).
9. PROPRIETARY RIGHTS
9.1 The Customer acknowledges and agrees that the Supplier and/or its licensors own all intellectual property rights in the Services and the Documentation. Except as expressly stated herein, this agreement does not grant the Customer any rights to, or in, patents, copyright, database right, trade secrets, trade names, trademarks (whether registered or unregistered), or any other rights or licences in respect of the Services or the Documentation.
9.2 As set out in clause 5.1, the Customer owns all right, title and interest in and to the Customer Data. Customer grants to Supplier and all Supplier Personnel, or shall procure the grant of, a worldwide, royalty-free, perpetual and irrevocable, non-exclusive, transferable licence to use, modify, adapt, copy and/or create derivative works of any of the Customer Data to the extent required to use, receive and fully enjoy the benefit of the Services, Documentation and/or Deliverables for its normal business purposes.
9.3 Supplier shall own all right, title and interest, including any intellectual property rights, in and to any Deliverables (including any work in progress and documentation of work developed by Supplier or Supplier Personnel in connection with the Services).
9.4 Supplier grants to Customer a worldwide, royalty-free, perpetual and irrevocable, non-exclusive and transferable licence to use the Deliverables solely for the Customer's internal business operations.
10. CONFIDENTIALITY
10.1 Each party may be given access to Confidential Information from the other party in order to perform its obligations under this agreement. A party's Confidential Information shall not be deemed to include information that:
10.1.1 is or becomes publicly known other than through any act or omission of the receiving party;
10.1.2 was in the other party's lawful possession before the disclosure;
10.1.3 is lawfully disclosed to the receiving party by a third party without restriction on disclosure;
10.1.4 is independently developed by the receiving party, which independent development can be shown by written evidence; or 10.1.5 is required to be disclosed by law, by any court of competent jurisdiction or by any regulatory or administrative body.
10.2 Subject to clauses 6.4, 9.2 and 9.4, each party shall hold the other's Confidential Information in confidence and, unless required by law, not make the other's Confidential Information available to any third party, or use the other's Confidential Information for any purpose other than the implementation of this agreement.
10.3 Each party shall take all reasonable steps to ensure that the other's Confidential Information to which it has access is not disclosed or distributed by its employees or agents in violation of the terms of this agreement.
10.4 Neither party shall be responsible for any loss, destruction, alteration or disclosure of Confidential Information caused by any third party not under its control. For the avoidance of doubt the employees, agents and sub-contractors of a party are deemed to be under its control for the purposes of this clause 10.4.
10.5 The Customer acknowledges that details of the Services, and the results of any performance tests of the Services, constitute the Supplier's Confidential Information.
10.6 The Supplier acknowledges that the Customer Data is the Confidential Information of the Customer.
10.7 This clause 10 shall survive termination of this agreement, however arising.
10.8 Customer grants to Supplier a non-exclusive, worldwide, royalty-free right and license to use your company name and logos to identify you as an Spendkey customer. This license will survive after the term.
10.9 Customer agrees that Supplier or any of its Affiliates may, in its discretion, issue an announcement in the form of a press release or media alert, and participate in a video testimonial and a co-hosted webinar that describes your and your Affiliates’ use of the Services. Customer and your Affiliates will provide Supplier and its Affiliates with at least one quote from your and your Affiliates’ c-level employees for use in this announcement. The Customer agrees that in this announcement Spendkey as your and your Affiliates’ “Preferred spend analytics provider”. Spendkey will obtain your approval (which may be via email, and will not be unreasonably withheld, conditioned or delayed) on the final form of these activities. The Customer will work in good faith with Spendkey to enable Spendkey to publish this announcement and testimonial within 90 days of contract start date. The co-hosted webinar will be published within 180 days of the contract start date.
11. USE OF LARGE LANGUAGE MODELS FOR SPEND DATA ANALYSIS
11.1 By providing access to your spend data, the Supplier will use Large Language Models, including but not limited to Chat GPT, BARD, or OpenAI, by for the following purposes:
11.1.1 The Supplier may utilise Large Language Models to process and analyse the spend data provided by the Customer for the purpose of delivering services, improving customer experience, and enhancing the quality of interactions.
11.1.2 Large Language Models may be used to improve the functionality, recommendations, responses, or other outputs within the Service, with a focus on spend data analysis and reporting.
11.2 The Supplier shall take reasonable measures to ensure the confidentiality and security of the spend data accessed or processed using Large Language Models. The Supplier confirms that no personal data, as defined by data protection laws, will be accessed, used, or stored without separate consent. However, the Supplier acknowledges that they cannot guarantee the absolute security and confidentiality of the data due to factors beyond its control.
11.3 The Customer reserves the right to revoke this consent at any time by providing written notice to the Supplier. Upon receiving a written notice, the Supplier will promptly stop using Large Language Models with the spend data provided by the Customer, subject to any legal or contractual obligations.
11.4 By continuing to use the service and providing access to their spend data, the Customer acknowledges that they have read, understood, and agreed to this clause, which requests consent for the use of Large Language Models exclusively for spend data analysis purposes.
12. INDEMNITY
12.1 The Customer shall defend, indemnify and hold harmless and keep indemnified the Supplier and/or all Supplier Personnel against claims, actions, proceedings, losses, damages, expenses and costs (including without limitation court costs and reasonable legal fees) arising out of or in connection with the Customer's and any Authorised User's use of the Aggregated Annual Spend and Aggregated Annual Documents, Services, Deliverables and/or Documentation
12.2 If a claim to which clause
12.1 applies is made against the Supplier and/or any Supplier Personnel, the following procedures apply:
12.2.1 the Supplier shall give the Customer prompt notice of any such claim;
12.2.2 the Supplier provides reasonable co-operation to the Customer in the defence and settlement of such claim, at the Customer's expense; and
12.2.3 the Customer is given sole authority to defend or settle the claim.
12.3 Failure by the Supplier to comply with the indemnification procedures in clause 12.1 does not relieve the Customer of any obligation to indemnify the Supplier and/or any Supplier Personnel in respect of any claim.
12.4 The Supplier shall defend the Customer against any claim that the Services, Deliverables (excluding any Customer Data included in the Deliverables) or Documentation infringes any United Kingdom patent effective as of the Effective Date, copyright, trademark, database right or right of confidentiality, and shall indemnify the Customer for any amounts awarded against the Customer in judgment or settlement of such claims, provided that:
12.4.1 the Supplier is given prompt notice of any such claim;
12.4.2 the Customer provides reasonable co-operation to the Supplier in the defence and settlement of such claim, at the Supplier's expense; and
12.4.3 the Supplier is given sole authority to defend or settle the claim.
12.5 In the defence or settlement of any claim, the Supplier may procure the right for the Customer to continue using the Services, replace or modify the Services, Documentation and/or Deliverables so that they become non-infringing or, if such remedies are not reasonably available, terminate this agreement on two [2] Business Days' notice to the Customer without any additional liability or obligation to pay liquidated damages or other additional costs to the Customer.
12.6 In no event shall the Supplier, its employees, agents and sub-contractors be liable to the Customer to the extent that the alleged infringement is based on:
12.6.1 a modification of the Services, Deliverables or Documentation by anyone other than the Supplier; or 12.6.2 the Customer's use of the Services, Deliverables or Documentation in a manner contrary to the instructions given to the Customer by the Supplier; or 12.6.3 the Customer's use of the Services, Deliverables or Documentation after notice of the alleged or actual infringement from the Supplier or any appropriate authority.
12.7 The foregoing and clause 13.3.2 states the Customer's sole and exclusive rights and remedies, and the Supplier's (including the Supplier's employees', agents' and sub-contractors') entire obligations and liability, for infringement of any patent, copyright, trademark, database right or right of confidentiality.
13. LIMITATION OF LIABILITY
13.1 Nothing in this agreement shall operate so as to exclude or limit the liability of either party to the other for:
13.1.1 fraud;
13.1.2 death or personal injury arising out of that party's negligence; or
13.1.3 any other liability which cannot be excluded or limited by law.
13.2 Except as expressly and specifically provided in this agreement:
13.2.1 the Customer assumes sole responsibility for results obtained from the use of the Services, Deliverables and the Documentation by the Customer, and for conclusions drawn from such use. The Supplier shall have no liability for any damage caused by errors or omissions in any information, instructions or scripts provided to the Supplier by the Customer in connection with the Services, Documentation and/or creation or provision of the Deliverables or any actions taken by the Supplier at the Customer's direction;
13.2.2 all warranties, representations, conditions and all other terms of any kind whatsoever implied by statute or common law are, to the fullest extent permitted by applicable law, excluded from this agreement; and
13.2.3 the Services, Deliverables and the Documentation are provided to the Customer on an "as is" basis.
13.3 Subject to clause 13.1 and clause 13.2:
13.3.1 the Supplier shall not be liable whether in tort (including negligence), breach of statutory duty, contract, misrepresentation (whether tortious or statutory), restitution, under any indemnity or otherwise for any loss of profits, loss of business, depletion of goodwill and/or similar losses or loss or corruption of data or information, or pure economic loss, or for any special, indirect or consequential loss, costs, damages, charges or expenses however arising under this agreement; and
13.3.2 the Supplier's (including any Supplier Personnel's) total aggregate liability in contract (including in respect of the indemnity at clause 12.1), tort (including negligence), breach of statutory duty, misrepresentation (whether tortious or statutory), restitution or otherwise, arising under or in connection with this agreement shall be limited to the total License Fees paid for the Aggregated Annual Spend and Aggregated Annual Documents during the 12 months immediately preceding the date on which the claim arose.
14. TERM AND TERMINATION
14.1 This agreement shall, unless otherwise terminated as provided in this clause 14, commence on the Effective Date and shall continue for the Initial Term. Thereafter, at the Customers discretion may renew for successive periods of 12 months (each a “Renewal Period”).
14.1.1 If either party notifies the other party of termination, in writing, at least 90 days before the end of a Renewal Period, in which case this agreement shall terminate upon the expiry of the relevant Renewal Period; or
14.1.2 otherwise terminated in accordance with the provisions of this agreement;
14.1.3 Initial Term is set out in Schedule 1 – Order and the Initial Term together with any subsequent renewal shall constitute the Term.
14.2 Supplier reserves the right to terminate this Agreement at any time for convenience with 60 days’ notice to Customer provided that Supplier will refund Customer any prepaid Fees prorated to cover the remainder of the term of the Renewal Period, as applicable, after the effective date of termination.
14.3 Without affecting any other right or remedy available to it, either party may terminate this agreement with immediate effect by giving written notice to the other party if:
14.3.1 the other party fails to pay any amount due under this agreement on the due date for payment and remains in default not less than 3 days after being notified in writing to make such payment;
14.3.2 the other party commits a material breach of any other term of this agreement which breach is irremediable or (if such breach is remediable) fails to remedy that breach within a period of 30 days after being notified in writing to do so;
14.3.3 the other party repeatedly breaches any of the terms of this agreement in such a manner as to reasonably justify the opinion that its conduct is inconsistent with it having the intention or ability to give effect to the terms of this agreement;
14.3.4 the other party suspends, or threatens to suspend, payment of its debts or is unable to pay its debts as they fall due or admits inability to pay its debts or is deemed unable to pay its debts within the meaning of the UK Enterprise and Regulatory Reform Act 2013;
14.3.5 the other party commences negotiations with all or any class of its creditors with a view to rescheduling any of its debts, or makes a proposal for or enters into any compromise or arrangement with its creditors other than for the sole purpose of a scheme for a solvent amalgamation of that other party with one or more other companies or the solvent reconstruction of that other party;
14.3.6 a petition is filed, a notice is given, a resolution is passed, or an order is made, for or in connection with the winding up of that other party other than for the sole purpose of a scheme for a solvent amalgamation of that other party with one or more other companies or the solvent reconstruction of that other party;
14.3.7 an application is made to court, or an order is made, for the appointment of an administrator, or if a notice of intention to appoint an administrator is given or if an administrator is appointed, over the other party;
14.3.8 the holder of a qualifying floating charge over the assets of that other party has become entitled to appoint or has appointed an administrative receiver;
14.3.9 a person becomes entitled to appoint a receiver over the assets of the other party or a receiver is appointed over the assets of the other party;
14.3.10 a creditor or encumbrancer of the other party attaches or takes possession of, or a distress, execution, sequestration or other such process is levied or enforced on or sued against, the whole or any part of the other party's assets and such attachment or process is not discharged within 14 days;
14.3.11 any event occurs, or proceeding is taken, with respect to the other party in any jurisdiction to which it is subject that has an effect equivalent or similar to any of the events mentioned in clause 14.3.4 to clause 14.3.10 (inclusive); or 14.3.12 the other party suspends or ceases, or threatens to suspend or cease, carrying on all or a substantial part of its business.
14.4 On termination of this agreement for any reason:
14.4.1 all licences granted under this agreement shall immediately terminate except for any perpetual and irrevocable licences which shall continue notwithstanding the termination of this agreement;
14.4.2 subject to clauses 6.4, 9.2 and 9.4, each party shall return and make no further use of any equipment, property, Documentation and other items (and all copies of them) belonging to the other party;
14.4.3 subject to clauses 6.4, 9.2 and 9.4, the Supplier may destroy or otherwise dispose of any of the Customer Data in its possession.
14.4.4 any rights, remedies, obligations or liabilities of the parties that have accrued up to the date of termination, including the right to claim damages in respect of any breach of the agreement which existed at or before the date of termination shall not be affected or prejudiced.
15. FORCE MAJEURE
The Supplier shall have no liability to the Customer under this agreement if it is prevented from or delayed in performing its obligations under this agreement, or from carrying on its business, by acts, events, omissions or accidents beyond its reasonable control, including, without limitation, strikes, lock-outs or other industrial disputes (whether involving the workforce of the Supplier or any other party), failure of a utility service or transport or telecommunications network, act of God, war, riot, civil commotion, malicious damage, compliance with any law or governmental order, rule, regulation or direction, accident, breakdown of plant or machinery, fire, flood, storm or default of suppliers or sub-contractors, provided that the Customer is notified of such an event and its expected duration.
16. CONFLICT
If there is an inconsistency between any of the provisions in the main body of this agreement and any terms on www.spendkey.io, the provisions in the main body of this agreement shall prevail.
17. VARIATION
No variation of this agreement shall be effective unless it is in writing and signed by the parties (or their authorised representatives).
18. WAIVER
No failure or delay by a party to exercise any right or remedy provided under this agreement or by law shall constitute a waiver of that or any other right or remedy, nor shall it prevent or restrict the further exercise of that or any other right or remedy. No single or partial exercise of such right or remedy shall prevent or restrict the further exercise of that or any other right or remedy.
19. RIGHTS AND REMEDIES
Except as expressly provided in this agreement, the rights and remedies provided under this agreement are in addition to, and not exclusive of, any rights or remedies provided by law.
20. SEVERANCE
20.1 If any provision (or part of a provision) of this agreement is found by any court or administrative body of competent jurisdiction to be invalid, unenforceable or illegal, the other provisions shall remain in force.
20.2 If any invalid, unenforceable or illegal provision would be valid, enforceable or legal if some part of it were deleted, the provision shall apply with whatever modification is necessary to give effect to the commercial intention of the parties.
21. ENTIRE AGREEMENT
21.1 This agreement, and any documents referred to in it, constitute the whole agreement between the parties and supersede any previous arrangement, understanding or agreement between them relating to the subject matter they cover.
21.2 Each of the parties acknowledges and agrees that in entering into this agreement it does not rely on any undertaking, promise, assurance, statement, representation, warranty or understanding (whether in writing or not) of any person (whether party to this agreement or not) relating to the subject matter of this agreement, other than as expressly set out in this agreement.
22. ASSIGNMENT
22.1 The Customer shall not, without the prior written consent of the Supplier, assign, transfer, charge, sub-contract or deal in any other manner with all or any of its rights or obligations under this agreement.
22.2 The Supplier may at any time assign, transfer, charge, sub-contract or deal in any other manner with all or any of its rights or obligations under this agreement.
23. NO PARTNERSHIP OR AGENCY
Nothing in this agreement is intended to or shall operate to create a partnership between the parties, or authorise either party to act as agent for the other, and neither party shall have the authority to act in the name or on behalf of or otherwise to bind the other in any way (including, but not limited to, the making of any representation or warranty, the assumption of any obligation or liability and the exercise of any right or power).
24. NOTICES
24.1 Any notice required to be given under this agreement shall be in writing and sent by recorded delivery post to the other party at its address set out in this agreement, or such other address as may have been notified by that party for such purposes, as set out in this agreement.
24.2 A correctly addressed notice sent by recorded delivery post shall be deemed to have been received at the time at which it would have been delivered in the normal course of post.
25. GOVERNING LAW
This agreement and any dispute or claim arising out of or in connection with it or its subject matter or formation (including non-contractual disputes or claims) shall be governed by and construed in accordance with the laws of England and Wales, excluding any other choice of law or conflict of law rules or provisions (whether England and Wales, foreign or international).
26. JURISDICTION
Each party irrevocably agrees that the courts in the judicial district of London shall have exclusive jurisdiction to settle any dispute or claim arising out of or in connection with this agreement or its subject matter or formation (including non-contractual disputes or claims).
Schedule 1: Fees
The License Fee for the Initial Term are mentioned and agreed between the Supplier and the Customer as provided on www.spendkey.io/pricing
Any variation to the pricing shall be agreed upon and signed by both parties as an addendum to these Terms of Service / SaaS Agreement.
Schedule 2: Support Services
Notes:
• P3 issues reported in the last hour of business day will be considered in next day
• P1 incident SLA will always take priority over other SLAs. For example, during ongoing P1 incident, only SLA for P1 incidents will be in effect and all other SLAs will not be applicable till the time P1 incidents are resolve
Schedule 3: Personal Data Processing Terms
1. Definitions
Any terms not defined in this schedule shall have the meanings given to them in the Contract.
“Processor” means a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller;
“Controller” means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law;
“Data Subject” means the natural person to whom Customer Personal Data relates;
“EEA” means the member states of the European Union, Iceland, Liechtenstein, Norway and Switzerland, and including the United Kingdom after its departure from the European Union
“Personal Data” means any information, including information in electronic form, relating to a natural person who can be identified (a) from those data or (b) from those data and the use of additional information, taking into account all means reasonably likely to be used by anyone to identify the person directly or indirectly and includes, without limitation, first and last names, ID numbers, including government-issued identifiers, personal dates such as birthdates, email addresses, location data, internet protocol address or other online identifiers and information concerning race, ethnicity or mental or physical health. For clarity, Personal Data includes Personal Data that is publicly available and excludes Personal Data that has been anonymised so it’s no longer possible to re-identify a Data Subject from the information, taking into account all means likely reasonably to be used by Processor or anyone else to re-identify them;
“Data Privacy Legislation” means the national law(s) implementing the European Union Data Protection Directive (Directive 95/46/EC) and as from 25 May 2018, the General Data Protection Regulation (EU) 2016/679 (hereafter “GDPR”) including any national law in the execution of the GDPR “Processing” means any operation or set of operations performed on Personal Data, whether or not by automated means, such as accessing, collection, downloading, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, blocking, erasure or destruction;
“Customer Personal Data” means any Personal Data submitted by Customer or any Customer Network Firm to Processor or that is otherwise processed by or on behalf of the Processor in connection with the Services;
“Subprocessor” means anyone engaged by Processor to perform processing that Processor performs on behalf of Customer or any Customer Network Firm;
"Business Day" means any weekday other than a bank or public holiday in England;
‘”Customer Network Firm” means the member firms of the global network of Customer, all members of which are separate, independent legal entities.
2. Scope of processing
Annex I records (i) the types of Personal Data processed by the Service Provider and (ii) the Data Subject and (iii) the nature and purpose of the processing performed by the Service Provider on Customer Personal Data.
3. Supplier’s obligations
3.1 The Service Provider can only act upon specific instructions of Customer, in accordance with the Data Privacy Legislation, and more in particular can only process the Personal Data (including providing the Personal Data to a third party) for the purposes determined by Customer and may not use it for any other purpose whatsoever.
3.2 The Service Provider must process Customer Personal Data only as necessary to provide the Services to Customer or as required by law.
3.3 The Service Provider must implement appropriate technical and organisational measures to prevent unauthorised processing of Customer Personal Data (including accidental or unauthorised disclosure, access, loss, alteration and destruction) taking into account the (i) state of the art, (ii) costs of implementation, (iii) nature of the Customer Personal Data processed and (iv) risks to Data Subjects and that are at least consistent with the security measures prescribed in the Contract.
3.4 The Service Provider must restrict access to Customer Personal Data within the Service Provider’s organisation to personnel who require access to Customer Personal Data to perform the Services and who are obliged to maintain the confidentiality and security of the information.
3.5 The Service Provider must inform Customer promptly, within 24 hours, after becoming aware of accidental or unauthorised destruction, loss, alteration or disclosure of or access to Customer Personal Data (including any Customer personal data processed by a sub-processor), including information about the nature of the incident and Personal Data affected. The Service Provider must take immediate measures to contain the incident and address its underlying causes. The Service Provider must provide reasonable information about remediation on Customer's request.
3.6 The Service Provider may engage sub-processors in connection with the Services. Using sub-processors does not release the Service Provider from its obligations under this schedule and the Service Provider remains primarily and fully liable for the failure of its sub-processors to comply with the obligations of this Appendix.
3.7 The Service Provider must notify Customer of all sub-processors engaged at the date of this schedule and shall thereafter notify Customer at least 30 days before appointing a new sub-processor. Customer may raise reasonable objections to a new sub-processor in which case the Parties will negotiate to reach a mutually acceptable solution. If a mutually acceptable solution is not reached within thirty days of Customer raising the objection, Customer reserves the right to terminate the Services without penalty in accordance with the termination provisions of the Contract.
3.8 The Service Provider must bind each sub-processor to a commitment substantially equivalent to this schedule. For clarity, this must include, where the sub-processor will process Customer Personal Data transferred from the EEA in a country not recognised by the EU Commission as having adequate protection, a commitment to enter into the EU Model Contractual Clauses3 notwithstanding any certification to the EU-U.S. Privacy Shield.
3.9 Subject to clause 3.9, on completion or termination of the Services, the Service Provider must within a reasonable timeframe: (i) follow Customer's instructions regarding return of Customer Personal Data and (ii) delete, and cause sub-processors to delete, all copies of Customer Personal Data remaining in the Service Provider’s (or sub-processor's) possession or control. On Customer's written request, the Service Provider shall provide Customer with information confirming deletion of Customer Personal Data.
3.10 Clause 3.8 does not apply to Customer Personal Data which the Service Provider is required to retain to comply with the law.
3.11 If the Services do not provide Customer with the ability to extract, delete, update or correct Personal Data, the Service Provider must, on Customer's request and as far as possible, assist Customer in addressing the legal rights of Data Subjects, including, without limitation, the right to receive a copy of Personal Data and to have Personal Data corrected, updated or deleted.
3.12 The Service Provider shall provide information, on Customer request, to enable Customer to comply with applicable Privacy Laws where the requested information is in the Service Provider's possession or under its control.
3.13 The Service Provider must inform Customer within 2 business days of receiving a request from a Data Subject relating to their Personal Data and without responding to the request, unless it has been otherwise authorised to do so.
3.14 On Customer's request, and subject to suitable confidentiality obligations, the Service Provider shall make available to Customer information regarding the Service Provider's or any sub-processor's compliance with the obligations set forth in this schedule, in the form of a SOC 2 Type II, SSAE 16 SOC 1 Type II or international equivalent (ISAE 3402 or ASAE 3402), Cobit 5, HIPAA (healthcare), PCI DSS (financial). Customer may in addition request an on-site audit of the Service Provider's or any sub-processor's architecture, systems and procedures relevant to the protection of Personal Data at the locations where Customer Personal Data is stored. Before commencement of any on-site audit, Customer must agree with the Service Provider (or sub-processor) the scope, timing, and duration of the audit in addition to the costs for which Customer shall be responsible.
3.15 The Service Provider must refrain from storing or transferring the Personal Data outside the European Union.
3.16 The Service Provider shall immediately inform Customer in writing if, in its opinion, an instruction under clause 3.13 infringes EU or national Privacy Laws applying to the Service Provider.
3.17 If the Service Provider cannot provide compliance with the Service Provider obligations mentioned in clause 3, for whatever reasons, the Service Provider agrees to inform promptly Customer of its inability to comply, in which case Customer is entitled to suspend and/or terminate the Contract.
3.18 The Service Provider is fully liable for Data Privacy Legislation compliance. Therefore, the Service Provider must comply with these Customer’s Personal Data Processing Terms and all applicable requirements of Data Privacy Legislation and i’s implementing national provisions regarding the nature of the data, the transfers, the scale of the processing and the technical and organizational safeguards in use.
4. Customer Network Firms
Customer Network Firms that are authorised users of the Services provided under the Contract shall be third party beneficiaries of the terms of this schedule.
5. Indemnification
The Service Provider agrees to indemnify and keep indemnified Customer, Customer Network Firms and their respective partners, members, officers, directors, employees, contractors, agents, representatives, successor and assigns ("Indemnitees") from and against all judgments, awards, settlements, liabilities, damages, claims, costs, expenses and other charges, including reasonable attorney's fees, and any penalties and fines incurred by or awarded against any of the Indemnitees, arising out of or related to any action by a supervisory authority or individual in relation to a breach by the Service Provider of the terms of this schedule.
6. Interpretation
Any phrase in the clauses introduced by the term “include”, “including”, “in particular” or similar expression shall be construed as illustrative and shall not limit the sense of the words preceding that term.
7. Survival
The obligations of this schedule survive termination or expiration of the Contract for as long as the Service Provider has Customer Personal Data in its possession or control.
8. Precedence
To the extent any term of the Contract, including the definitions, contradicts anything in this schedule, the parties agree that the terms of this schedule shall prevail.
9. Amendment
No amendment to this schedule will be effective unless it is in writing and signed by both Parties. This schedule may be modified without the consent of any third Party.