These Terms and Conditions (the "T&Cs") are entered into between you ("Client") and fielddrive BV, a company incorporated under the laws of Belgium, having its registered office at Mechelsesteenweg 303, 2830 Willebroek, Belgium, trading as 'fielddrive' ("fielddrive"). In consideration of the mutual covenants set forth herein and any applicable fees, the parties agree as follows:
A. fielddrive shall provide the professional services described in the order form agreed and executed between the parties ("Order Form").
B. In return for the agreed services, Client shall pay fielddrive a fee as set forth in the "Order Confirmation" section of the Order Form. Payments shall be made within 15 (fifteen) days from the date of receipt of the invoice, or within such other period as may be specified in the applicable Order Form.
1. SCOPE OF APPLICATION
1.1 These Terms and Conditions are applicable to all Order Forms, Products and Services offered or otherwise made available by fielddrive, except where we have explicitly stated otherwise in writing.
1.2 The Client agrees to waive its own general and special terms and conditions, even where it is stated therein that only those conditions may apply and even if such terms and conditions were not protested by fielddrive.
1.3 The performance of each obligation under these T&Cs is strictly limited to what is expressly indicated in the Order Form.
2. DEFINITIONS
2.1 "Client" means the legal entity identified in the Order Form as the client.
2.2 "Client Data" means all data entered and/or otherwise provided by the Client or the Users when using the Products and/or Services and as processed or stored by fielddrive as a result of the Client and/or the User using the Products and Services. Client Data shall also include output data resulting from the use of the Products and Services by the Client and the Users.
2.3 "Confidential Information" of a party means the information of such party disclosed to the other party during the negotiation or execution of the Order Form and these T&Cs between the parties, whether in written, oral, electronic or other form, and which (i) is explicitly marked as confidential or proprietary, (ii) should reasonably be considered confidential, or (iii) is traditionally recognized to be of a confidential nature, regardless of whether or not it is expressly marked as confidential.
2.4 "Documentation" means all technical and functional information made available by fielddrive to the Client relating to the Products and/or Services.
2.5 "Effective Date" unless indicated otherwise, means the date on which the last party has signed these T&Cs.
2.6 "Event" means the event for which the Products and Services are ordered, as described in the Order Form.
2.7 "Fees" means all amounts payable by the Client pursuant to the Order Form.
2.8 "fielddrive Software" means fielddrive's proprietary Software as a Service platform and/or any other proprietary software or applications of fielddrive.
2.9 "Force Majeure Event" means a temporary or permanent inability of a party to fulfil its obligations, resulting from unavoidable and external facts and circumstances reasonably beyond the control of that party. The following events, but not limited hereto, can be considered a Force Majeure Event: war or war risk, insurrection or public revolt, fire caused by an outside calamity, an import or export embargo imposed by the government, internet failure, hosting failure, floods, explosion, weather conditions, strike or social action, curtailment of transportation facilities and otherwise all events qualified by both parties as a Force Majeure Event in mutual agreement.
2.10 "Hardware Equipment" means certain hardware equipment provided to the Client, as specified in the Order Form.
2.11 "Intellectual Property Rights" means any (a) copyrights, patents, database rights and rights in trademarks, designs, know-how and trade secrets (whether registered or unregistered); (b) applications for registration, and the right to apply for registration, renewals, extensions, continuations, divisions, reissues, or improvements for or relating to any of these rights; and (c) all other intellectual or industrial property rights and equivalent or similar forms of protection existing anywhere in the world.
2.12 "Location" means the location and/or venue where the Event takes place, as described in the Order Form.
2.13 "Materials" means all materials, including, but not limited to all hardware equipment and software platform specified in the Order Form and sold by fielddrive to the Client.
2.14 "Party" means the Client and/or fielddrive.
2.15 "Personnel" means employees, independent staff members, subcontractors, consultants, and any other natural or legal person directly or indirectly involved in the provision of the performance of the Services under these T&Cs.
2.16 "Products" means individually or collectively, as appropriate, the Software, Hardware Equipment, Materials and Documentation.
2.17 "Order Form" means a written proposal of fielddrive with respect to the Products and the Services, which sets out the applicable commercial and specific terms. Any order form is subject to these Terms and Conditions.
2.18 "Services" means the professional services performed by fielddrive, as specified in the Order Form, such as, but not limited to, the set-up, monitoring and operation of the Software, Hardware Equipment, project management and on site and/or remote (technical) support.
2.19 "Software" means the fielddrive's software made available by fielddrive to the Client under these T&Cs.
2.20 "T&Cs" means these general terms and conditions entitled 'Terms and Conditions fielddrive BV' and any annexes or other contractual documentation agreed in writing between the Parties.
2.21 "User" means an end user of the Products and Services having access thereto via the Client.
3. ORDER FORM
3.1 An Order Form is only valid for the duration as determined in the Order Form.
3.2 If the Order Form has not been signed by both Parties before its validity date, fielddrive shall in no way be bound by the Order Form and the specific conditions and performance modalities contained therein.
4. SOFTWARE LICENSE
4.1 fielddrive hereby grants to the Client a personal, restricted, non-transferable, non-exclusive, license to use the Software for the internal business purposes of the Client during the Term and in accordance with the applicable Documentation.
4.2 Within the scope of this license, Users are permitted to have access to and to use the Software, under the conditions as mentioned in these T&Cs.
4.3 The extent of the license granted under these T&Cs is restricted to the scope expressly set forth therein, and there are no implied licenses under these T&Cs.
4.4 Except to the extent expressly permitted in these T&Cs or required by law, the Client shall not: (i) sub-license, assign, distribute, transfer, sell, lease, or otherwise deal in or encumber its right to access and use the Software, or use the Software on behalf of any third party or make them available to any third party, nor allow or permit a third party to do any of the same; (ii) permit any unauthorized person to access or use the Software; (iii) republish or redistribute any content or material from the Software; (iv) make back-up copies of the Software without fielddrive's prior written authorization; (v) reproduce, arrange, modify or alter the Software, including for the purpose of correcting errors, or create derivative works based on the Software or enable a third party to perform such acts; (vi) remove or alter any copyright or other proprietary notice on the Software; (vii) use the Software for (a) any activity that is in breach of the law, public order or public morality, (b) unsolicited commercial communications (e.g. spam); (c) collecting or harvesting personal information in breach of the law (e.g. phishing); or, (d) any activity that is offensive, defamatory, harmful to minors, indecent, illegal, in breach of third-party rights or otherwise objectionable.
4.5 The Client shall comply with all applicable laws relating to the use of the Software. The Client shall not use the Software for any illegal, unauthorized or otherwise improper purposes, or use the Software in a manner that fails to comply or is inconsistent with any part of the Documentation or these T&Cs.
4.6 The Client has no right to access the software code (including object code, intermediate code and source code) of the Software and Third-Party Software.
4.7 The Client must comply with all relevant policies which are designated and made available to the Client in electronic way or via the Software, and must ensure that all Users comply with these policies.
4.8 Access and usage of the Third-Party Software is subject to these T&Cs.
5. CHANGE IN SERVICES
5.1 Delivery
5.1.1 The Hardware Equipment and the Materials shall be as described in the Order Form and shall be delivered at the Location. Unless agreed otherwise shipping and transportation costs are not included in the total Fees mentioned in the Order Form and shall be invoiced separately at cost (increased with any handling fees as indicated in the Order Form). Any applicable customs costs are exclusively borne by the Client.
5.1.2 The Hardware Equipment and the Materials shall be delivered by fielddrive in the state in which they are at the moment of delivery ('as is'), and therefore with all visible and invisible errors and defects. Any claim from the Client relating to the delivered Hardware Equipment and/or the Materials must be formulated promptly and in writing before the Event they are provided or offered for takes place. Such claims do not in any circumstances suspend the payment obligation of the Client.
5.1.3 The Hardware Equipment shall be made available to the Client for the duration of the Event, as set out in the Order Form, and shall remain the sole and exclusive property of fielddrive.
5.1.4 fielddrive retains ownership of the Materials at all times.
5.1.5 The Client undertakes to promptly return the Hardware Equipment to fielddrive upon expiry or termination of these T&Cs/Order Form or upon completion of the Event for which such Hardware Equipment was provided. In the event the Client fails to fulfil its obligations under these T&Cs, fielddrive shall be entitled to recover or repossess the Hardware Equipment, with or without prior notice, subject to applicable law.
5.2 Care, use and maintenance of Hardware Equipment
5.2.1 Under no circumstances shall fielddrive hardware badging products (kiosk, badgebox) be used in conjunction with an alternative or competitive badging software product to its own.
5.2.2 If the Client elects not to have a fielddrive staff person on-site to install, monitor and uninstall the Hardware Equipment ordered by the Client, the following conditions will apply: (a) the Client shall safeguard the Hardware Equipment and keep the Hardware Equipment in good condition; (b) the Client shall ensure that the Hardware Equipment shall only be operated by competent employees and used solely in the conduct of its business; (c) the Client and its employees shall use the Hardware Equipment carefully and properly, and in compliance with the Documentation and all applicable legislation and regulations; (d) the Client agrees to keep and use the Hardware Equipment only at the Location; (e) the Client shall not make any alterations or additions to the Hardware Equipment without fielddrive's prior written consent.
5.2.3 The Client shall be liable for all reparation and/or replacement costs in case the Hardware Equipment is damaged or lost. Such costs shall be charged at the full cost for the replacement and/or reparation (as applicable) of the Hardware Equipment. The Client shall immediately notify fielddrive of any damage to the Hardware Equipment by written notice. fielddrive shall have the right to determine at its sole discretion whether or not the Hardware Equipment is economically repairable, and if so, which repair method to use. Any fees paid by the Client for lost Hardware Equipment shall not be refunded, even if the Hardware Equipment is found and returned at a later time.
5.2.4 The Client agrees to use the Hardware Equipment only in accordance with the Documentation and any instructions provided by fielddrive.
5.2.5 The Client must comply with all relevant usage policies which are designated and made available to the Client (in writing (electronically or on paper) or via the Software), and must ensure that all persons using the Hardware Equipment or having access to the Hardware Equipment comply with these usage policies.
5.2.6 The Client shall not use the Hardware Equipment and Materials for the following purposes: (a) for illegal purposes, to perform acts that could be contrary to the applicable law (criminal or otherwise) or that could be prejudicial to fielddrive, other clients or third parties; (b) for purposes or applications other than those approved by fielddrive; (c) in a way that disrupts the Software; (d) to transmit any unlawful, prejudicial or harassing material, unauthorized advertising, spam or material that may infringe Intellectual Property Rights or other rights of fielddrive or third parties, or material that contains viruses or other harmful computer code or files; (e) to copy or reverse engineer the Products; (f) to directly or indirectly prepare competing or derivative products; and/or (g) to resell the Hardware Equipment or the Services to third parties.
6. SERVICES
6.1 General
6.1.1 fielddrive shall perform the Services as specified in the Order Form.
6.1.2 fielddrive shall perform the Services under these T&Cs to the best of its abilities and will, in so far reasonably possible, take into account the technical instructions and guidelines it receives from the Client.
6.1.3 Unless agreed otherwise, all costs made by fielddrive necessary for the performance of the Services, such as but not limited to travel costs and hotel accommodation costs shall be invoiced based on the fixed prices and/or hourly rates set out in the Order Form.
6.1.4 The Services are either to be performed (i) at the Location or (ii) on a remote basis, as agreed between the Parties and as indicated in the Order Form. When the Services are to be performed at the Location, the Client guarantees that the Location and facilities are in compliance with all requirements of applicable law. The Client shall notify fielddrive of the applicable policies and safety procedures applicable at the Location prior to the start of the Services.
6.1.5 The Client undertakes to indemnify fielddrive against all claims of third parties, including the Personnel of fielddrive, who suffered damages in connection with the performance of the obligations under these T&Cs and resulting from an act or omission of the Client or from unsafe situations at the Location where the Services are to be performed.
6.1.6 The Client shall cooperate in good faith with fielddrive and provide all information as requested by fielddrive or as otherwise necessary for the performance of the Services.
6.1.7 fielddrive shall provide the Services within the limits of these T&Cs and the information provided by the Client. The Client warrants the accuracy and completeness of information, requirements, specifications and any other information provided by the Client to fielddrive.
6.1.8 fielddrive may rely on Personnel for the performance of these T&Cs. fielddrive reserves the right (i) to determine which Personnel shall be assigned to the performance of the Services, and (ii) to replace, at its sole discretion, this Personnel throughout the Term.
7. CHANGE PROCEDURE
7.1 If, after execution of these T&Cs, the Client requires any additional services, the Parties may mutually agree to such additional services by way of executing an addendum agreement.
7.2 All such modifications to the initial agreed scope shall, subject to the both Parties reaching an agreement in writing in this respect, be governed by these T&Cs and by any additional terms specifically agreed to in writing by between the Parties.
7.3 In the absence of a written agreement with respect to the requested modifications, fielddrive shall only be liable to perform the obligations agreed upon in these T&Cs.
8. PAYMENT TERMS
8.1 The Client shall pay the Fees within fifteen (15) days from the date of receipt ofthe invoice, or within such other period as may be specified in the applicable Order Form. In the event of any conflict or inconsistency between the paymenttimelines set out in these T&Cs and the applicable Order Form, the terms ofthe relevant Order Form shall prevail.
8.2 in accordance with the payment schedule set out in the Order Form.
8.3 All payments under these T&Cs shall be done by bank wire, using such payment details as notified by fielddrive to the Client.
8.4 All fees payable to fielddrive under the Order Form and these T&Cs shall bepaid without the right to set off or counter claim and free and clear of all deductions or withholdings whatsoever, unless the same are required by law, in which case the Client undertakes to pay fielddrive such additional amounts as are necessary in order that the net amounts received by fielddrive after all deductions and withholdings shall not be less than such payments would have been in the absence of such deductions or withholding. Sums stated to bepayable under the Order Form and these T&Cs do not include any applicable value added tax or other taxes, which shall be additionally charged to theClient. The Client is responsible for payment of all general, state or localimport, usage, value added, withholding or other taxes associated with thesupply or use of the Products or Services. The Client shall promptly reimburse fielddrivefor any such taxes or duties paid by fielddrive.
8.5 Client undertakes to make all payments within fifteen (15) days after the invoice date and in the currency of the signed off Order Form, unless Parties have agreed otherwise in writing. In the event of late payment, all payment obligations of the Client to fielddrive will immediately become due and payable and fielddrive reserves the right to declareany discounts allowed to be forfeit.
8.6 In case there are any outstanding amounts,fielddrive shall have the right (without prejudice to its other rights andremedies) to suspend, partly or fully, the execution of its obligations underthese T&Cs, without incurring any liability to the Client by reason of anysuch suspension.
8.7 The amount of any invoice which has notbeen paid within fifteen (15) days from the invoice date shall automatically be subject to a late payment interest at the rate of 12% (twelve percent) perannum. If Client fails to pay any outstanding amounts within fifteen (15) days from receipt of a written default notice, fielddrive shall be entitled to suspend its obligations and the Client’s rights here under until receipt of payment of such outstanding amounts.
8.8 Each invoice made by fielddrive shall be deemed to have been accepted by the Client if it is not disputed within ten(10) days after the invoice date of the disputed invoice by registered letter sent to fielddrive wherein the reason for the dispute is explained.
8.9 In case the Client is declared to be in astate of bankruptcy, applies for a suspension of payments, is subjected to ageneral seizure of assets, goes into liquidation or is dissolved, all amounts payable under these T&Cs shall become due immediately.
9. INTELLECTUAL PROPERTY RIGHTS
9.1 fielddrive alone (and its licensors, where applicable) shall own all right, title and interest, including all related Intellectual Property Rights, in and to the Products and the Services and any suggestions, ideas, enhancement requests, feedback, or recommendations provided by the Client relating to the Service.
9.2 Nothing in these T&Cs shall convey to the Client any rights of ownership in or related to the Hardware Equipment, the Software, the Services or the Intellectual Property Rights owned by fielddrive or its licensors.
9.3 The fielddrive name, the fielddrive logo, and the product names associated with the Products and the Services are trademarks of fielddrive or third parties, and no right or license is granted to use them.
9.4 The Client agrees not to remove, suppress or modify in any way any proprietary marking, including any trademark or copyright notice, on or in the Products and Services, or visible during their operation.
10. CLIENT DATA
10.1 fielddrive does not own any Client Data and agrees to treat the Client Data as Confidential Information.
10.2 fielddrive may retain Client Data during the term of these T&Cs. All Client Data is either deleted or anonymized after 30 days following the last event day according to fielddrive's Data Privacy Policy.
10.3 The Client hereby grants to fielddrive a non-exclusive license to copy, reproduce, store, distribute, publish, export, adapt, edit and translate (i) Client Data and (ii) any documents, materials (such as sponsoring messages, print templates, corporate identity guidelines, etc.) ("Marketing Materials") made available to fielddrive by the Client to the extent reasonably required for the performance of fielddrive's obligations and the exercise of fielddrive's rights under these T&Cs. The Client also grants to fielddrive the right to sub-license these rights to its subcontractors to the extent reasonably required for the performance of fielddrive's obligations and the exercise of fielddrive's rights under these T&Cs.
10.4 The Client acknowledges and agrees that, for the performance of the obligations under the T&Cs and in order to use the Products and/or Service, specific Client Data can be disclosed to third party service providers, sub-processors, or any other recipients as reasonably necessary. Any such disclosure shall not constitute a breach of confidentiality, provided such disclosure is carried out in accordance with the DPA (as defined hereinbelow).
10.5 The Client warrants to fielddrive that the Client Data and Marketing Materials when used by fielddrive in accordance with these T&Cs shall not infringe the intellectual property rights or other legal rights of any person or third party, and will not breach the provisions of any law, statute or regulation, in any jurisdiction and under any applicable law and shall indemnify and hold harmless fielddrive in case of any third-party claim relating to fielddrive's use of the Client Data and Marketing Materials in accordance with these T&Cs.
11. DATA PROTECTION
The Parties shall enter into a data processing addendum (the "DPA") of even date with these T&Cs which is annexed herewith as Annexure A, which shall form an integral part of these T&Cs.
12. CONFIDENTIAL INFORMATION
12.1 Each Party shall treat all Confidential Information received from the other Party as confidential, keep secret such Confidential Information and shall not disclose it to any third party, other than its agents, employees, advisors or consultants where such disclosure is necessary for the performance of the obligations under these T&Cs and only in case such agents, employees, advisors or consultants are bound by a confidentiality obligation at least as strict as included in this article.
12.2 Confidential Information disclosed under these T&Cs shall not be used by the other Party for any purpose other than as required for the performance of its obligations under these T&Cs.
12.3 Both Parties shall take precautions to maintain the confidentiality of all Confidential Information and, in particular, each Party agrees: (a) to keep the Confidential Information confidential, and not, without the prior written consent of the disclosing Party, to disclose directly or indirectly the Confidential Information to any third party; (b) not to use the Confidential Information directly or indirectly for any purpose other than in connection with execution of the purposes of these T&Cs; (c) to exercise at least the same degree of care with respect to the Confidential Information as the receiving Party uses in handling its own or proprietary or confidential information.
12.4 The provisions of this article shall not apply to any Confidential Information which: (a) is published or comes into the public domain other than by a breach of these T&Cs; (b) can be proven to have been known by the receiving Party before disclosure by the disclosing Party; (c) is lawfully obtained from a third party other than by a confidentiality breach of such third party; or (d) can be shown to have been created by the receiving Party independently of the disclosure.
12.5 The receiving Party may disclose Confidential Information to the extent required in accordance with a judicial or other governmental order, provided that the receiving Party: (a) gives the disclosing Party reasonable notice prior to such disclosure to allow it a reasonable opportunity to seek a protective order or equivalent, unless the receiving Party is legally prohibited from doing so; (b) reasonably cooperates with the disclosing Party in its reasonable efforts to obtain a protective order or other appropriate remedy; (c) discloses only that portion of the Confidential Information that is legally required to disclose; and (d) uses reasonable efforts to obtain reliable written assurance from the applicable judicial or governmental entity that it will afford the Confidential Information the highest level of protection available under applicable law or regulation.
12.6 The undertaking in this article shall come into force as from the period of negotiations between the Parties, shall replace any prior non-disclosure agreement signed between the Parties (if applicable) and shall survive during five (5) years after the termination or expiration of these T&Cs.
13. MUTUAL INDEMNIFICATION
13.1 Client shall indemnify and hold fielddrive, its licensors and each such Party's parent organizations, subsidiaries, affiliates, officers, directors, employees and agents harmless from and against any and all claims, costs, damages, losses, liabilities and expenses (including attorneys' fees and costs) arising out of or in connection with any claim arising from Client's breach of these T&Cs, including a breach of any warranties given by the Client.
13.2 fielddrive shall indemnify and hold Client and its parent organizations, subsidiaries, affiliates, officers, directors, employees and agents harmless from and against any and all claims, costs, damages, losses, liabilities and expenses (including attorneys' fees and costs) arising out of or in connection with: (a) any claim alleging that the Products provided under these T&Cs directly infringe an Intellectual Property Right of a third party and excluding (i) any claims resulting from the Client's unauthorized use of the Products, (ii) the Client's or any third party's modification of the Products, (iii) the Client's failure to use the most recent version of the Products, or (iv) Client's use of the Products in combination with any non-fielddrive products or services; (b) any grossly negligent or more culpable act or omission of fielddrive or its personnel in connection with the performance of these T&Cs.
13.3 The indemnification obligations set out in this Clause shall be subject to the indemnified Party: (a) giving prompt written notice of the claim to the indemnifying Party; (b) giving the indemnifying Party sole control of the defense and settlement of the claim (provided that the indemnifying Party may not settle or defend any claim unless it unconditionally releases Client of all liability); (c) providing reasonably information and assistance to the indemnifying Party; and (d) not compromising or settling such claim.
14. LIMITATION OF LIABILITY
14.1 The limitations and exclusions of liability set out in this article govern all liabilities arising under these T&Cs or relating to the subject matter of these T&Cs, except to the extent expressly provided otherwise in these T&Cs.
14.2 To the maximum extent permitted under applicable law, fielddrive shall only be liable for direct damages and fielddrive's aggregate liability under these T&Cs shall not exceed the Fees paid by the Client to fielddrive under these T&Cs for the Event.
14.3 Under no circumstances shall fielddrive be liable to the Client for (i) any indirect, punitive, special consequential or similar damages (including damages for loss of profit, lost revenue, loss of business, loss or corruption of data, loss of customers and contracts, loss of goodwill, the cost of procuring replacement goods or services, and reputational damage) whether arising from negligence, breach of contract or of statutory duty or otherwise howsoever, (ii) damages resulting from a fault or negligence of the Client or the Client's Users, or (iii) compensation of any direct and indirect damages caused in whole or in part by Products supplied or created by third parties.
14.4 Each Party shall have the duty to mitigate damages. The exclusions and limitations of liability under this article shall operate to the benefit of fielddrive's affiliates and subcontractors to the same extent such provisions operate to the benefit of fielddrive.
14.5 The Products and Services may be subject to limitations, delays, and other problems inherent in the use of the provided electrical services, internet and electronic communications. fielddrive shall not be liable for any delays, delivery failures, or other damage resulting from such problems.
14.6 fielddrive makes no warranties, expressed or implied, oral or written, in fact, by operation by law or otherwise, except as herein expressly stated.
15. INSURANCE
Both Parties shall maintain during the term of these T&Cs, all necessary insurance (including, without limitation, to protect against any and all claims for injury or damages to persons and property arising in any manner in connection with these T&Cs) and shall provide to the other Party with a certificate of insurance evidencing such coverage upon written request.
16. TERM & TERMINATION
16.1 These T&Cs enter into force at the Effective Date and is concluded for the duration as set out in the Order Form ("Term").
16.2 The Client may terminate these T&Cs without penalty by written notice if the Event is cancelled due to a Force Majeure Event.
16.3 In the event of termination by Client pursuant to Clause 16.2, fielddrive shall refund to Client all deposits and prepayments, provided that fielddrive may offset any and all reasonable expenses accrued up to that time in the performance of these T&Cs (the "Expenses"). To the extent that no prepayments or deposits have been made by Client prior to the termination, Client shall reimburse fielddrive for any such Expenses.
16.4 Notwithstanding anything set out in Clause 16.7, the Client acknowledges and agrees that any use of the Products outside the scope of the Order Form and these T&Cs or any breach by the Client of any applicable law, shall entitle fielddrive to immediately terminate (or alternatively, at fielddrive's option, suspend) the license granted hereunder and/or these T&Cs for Material Breach by the Client, without any formalities or indemnities being required and without prejudice to any other right or remedy available to fielddrive pursuant to these T&Cs or under applicable law.
16.5 fielddrive reserves the right to terminate these T&Cs for Client's failure to make any scheduled payment in which event the entire contract sum shall immediately become due.
16.6 Except as set forth in this Clause, neither Party may terminate these T&Cs for convenience without the express, written consent of the other Party. In the event the Client wishes to cancel these T&Cs, the following cancellation fees shall apply:
In addition, the Client shall reimburse fielddrive for all expenses incurred by fielddrive, with an offset of the payments made by the Client up to the time of cancellation.
16.7 Either Party may immediately terminate these T&Cs without any judicial intervention, without being liable for compensation and without prejudice to its rights to damages and any other rights remedies and/or claim to which it may be entitled by law upon providing to the other Party with prior written notice of termination if: (i) the other Party performs a Material Breach to any provision of these T&Cs and fails to cure such Material Breach within twenty (20) calendar days after receipt of written notice of a Material Breach to the breaching Party (provided that in case of an uncurable Material Breach, the breaching Party on receipt of the notice of Material Breach shall communicate in writing to the non-breaching Party the uncurable nature of such Material Breach, in which case the termination will be effective from the date of receipt of such communication from the breaching Party or twenty (20) calendar days after the receipt of notice of Material Breach whichever is earlier), (ii) the other Party becomes insolvent, is subject to voluntary or involuntary bankruptcy, insolvency or similar proceeding or otherwise liquidates or ceases to do business, or (iii) the other Party breaches the clauses with respect to Intellectual Property Rights or Confidential Information.
Where (i) "Material Breach" by fielddrive shall mean any malfunction of the fielddrive Software, Materials and Hardware Equipment solely due to any act or omission of fielddrive that results in the cancellation of an Event and shall include breach of intellectual property of fielddrive by the Client; or any breach of data privacy or security obligations by the Client; or non-payment of any Fees payable to fielddrive or any breach of applicable law by the Client.
16.8 Upon expiry or termination of these T&Cs for whatever reason: (a) the Client's right to use the Products and Service will automatically cease and all licenses granted to the Client pursuant to these T&Cs shall automatically terminate; (b) each Party will return, within reasonable time of such termination or expiration all Confidential Information and fielddrive shall, in so far reasonably possible, return all Client Data except as required to comply with any applicable legal or accounting record keeping requirement; (c) the Client shall promptly pay fielddrive all Fees and other amounts earned by or due to fielddrive in respect of the Products or Services, up to and including the date of termination.
17. MISCELLANEOUS
17.1 Entire agreement These T&Cs along with the Order Form constitute the entire agreement and understanding between the Parties with respect to the subject matter hereof and supersedes all prior oral or written agreements, representations or understandings between the Parties relating to the subject matter hereof. No statement, representation, warranty, covenant or agreement of any kind not expressly set forth in these T&Cs/Order Form shall affect, or be used to interpret, change or restrict, the express clauses of these T&Cs/Order Form.
17.2 Amendment & Waiver These T&Cs may be modified or amended only by fielddrive with or without prior written notice to the Client.
17.3 Severability If any provision of these T&Cs is determined to be illegal, void, invalid or unenforceable, in whole or in part, the remaining provisions shall nevertheless continue in full force and effect. The provisions found to be illegal, invalid or unenforceable shall be enforceable to the full extent permitted by applicable law. Each Party shall use its best efforts to immediately negotiate in good faith a valid replacement provision with an equal or similar economic effect.
17.4 Survival Expiration, termination or cancellation of these T&Cs shall be without prejudice to the rights and liabilities of each Party which have accrued prior to the date of termination, and shall not affect the continuance in force of the provisions of these T&Cs which are expressly or by implication intended to continue in force, including, without limitation, the provisions relating to Intellectual Property Rights, Confidential Information and Liability.
17.5 Assignment fielddrive may assign or transfer the rights under these T&Cs to any third party. The Client shall not assign or otherwise transfer any of its rights or obligations under these T&Cs without fielddrive's prior written consent. fielddrive's consent should be requested by registered letter, disclosing the identity of the prospective transferee. Subject to any restrictions on assignment herein contained, the provisions of these T&Cs shall inure to the benefit of and shall be binding upon the Parties hereto and their respective heirs, legal representatives, successors and assignees.
17.6 Force Majeure fielddrive shall not be liable for any delay in performing, or failure to perform, any of its obligations under these T&Cs due to a Force Majeure Event.
17.7 Publicity fielddrive shall have the right to use any trademarks, logos or other marks of the Client (including the Client's corporate name) for client references on fielddrive's website, social media announcements and sales presentations, unless specified otherwise by the client.
17.8 Relationship between the Parties The relationship between fielddrive and the Client is that of independent contractors. Neither Party is agent for the other and neither Party has any authority to make any contracts, whether expressly or by implication, in the name of the other Party, without that Party's prior written consent for express purposes connected with the performance of these T&Cs.
17.9 Non-solicitation Under no circumstance shall the Client approach any of fielddrive's staff members during the Term of these T&Cs with the intent of offering employment unless previously agreed with fielddrive.
17.10 Notices Unless explicitly stated otherwise in these T&Cs, any notice required to be served by these T&Cs shall in first instance be given by electronic mail to the email addresses set out in the Order Form. All notices given by electronic mail, shall only be valid upon confirmation of receipt expressly given by electronic mail by the receiving Party. Any notices can be given in writing and served by personal delivery or registered letter, addressed to either Party at its address given in the Order Form or to such other address as a Party may designate by notice hereunder.
17.11 Interpretation In these T&Cs (unless the context requires or permits otherwise): (a) reference to any statute or statutory provision includes a reference to that statute or statutory provision as from time to time amended, extended or re-enacted; (b) words importing the singular include the plural, words importing any gender include every gender and words importing persons include bodies corporate and incorporate; and each case vice versa; (c) the headings or captions to the articles are for ease of reference only and shall not affect the interpretation or construction of these T&Cs.
17.12 Applicable law and jurisdiction These T&Cs shall be governed by and construed in accordance with the laws of Belgium and the Parties hereto submit to the exclusive jurisdiction of the courts of Antwerp, division Antwerp (Belgium). The United Nations Convention for the International Sale of Goods shall not apply to these T&Cs.
ANNEXURE A : FIELDDRIVE DATA PROCESSING ADDENDUM
This Data Processing Addendum (hereinafter the "DPA" or "Addendum") with its annexures and appendix is part of the terms and conditions ("T&C(s)") and any other agreement wherein fielddrive and its affiliates have agreed to provide its Services to the Client of an event by fielddrive to reflect the parties agreement to collection and processing of the Client's Personal Data ("Client Personal Data").
1. Commencement
This DPA shall come into effect on the same date ("Effective Date") as the T&C and form an integral part of the T&Cs. The Client and fielddrive shall be each referred to as "Party" or collectively as "Parties".
In the event of a conflict between the terms and conditions of this Addendum, or the T&Cs, the Order Form, or any other documentation, the terms and conditions of this Addendum shall prevail with respect to the subject matter of processing of Client Personal Data.
2. Definitions
All capitalized terms not defined herein shall have the meaning set forth in the T&Cs. For the purposes of this Addendum, the following terms shall have the following meanings:
A. "Affiliate" means any legal entity directly or indirectly controlling, controlled by or under common control with a party to the T&Cs, where "control" means the ownership of a majority share of the stock, equity, or voting interests of such an entity.
B. "Applicable Data Protection Laws" means all data protection or privacy laws and regulations applicable to the Processing of Personal Data under the DPA, including but not limited to:
- EU Data Protection Laws, including but not limited to General Data Protection Regulation (GDPR) and any other laws pertaining to data protection in any territory of the world that may be applicable to the processing of Personal Information (also known as "Personal Data") under the Privacy Policy
- California Consumer Privacy Act (CCPA), including amendments and final regulations
- California Privacy Rights Act (CPRA), effective from 1st January, 2023
- UK GDPR
- Saudi Arabia's ("KSA") Personal Data Protection Law ("PDPL")
- Personal Data Protection Law, Federal Decree Law No. 45 of 2021
- Lei Geral de Proteção de Dados (LGPD), Brazil
- Personal Data Protection Act (the "PDPA"), Singapore
- Personal Information Protection and Electronic Documents Act (PIPEDA), Canada
C. "Controller" means the entity which, alone or jointly with others, determines the purposes and means of the processing of Personal Data. The definition of Controller has meaning given to it under Article 2(7) of EU Data Protection Law.
D. "Client" means the Organizer that has entered into the T&Cs with fielddrive to use/access fielddrive Services to host on site events; this term shall include its employees, independent contractors, consultants, Affiliates, successors and assigns using/accessing the product and/or Services.
E. "Exhibitor" means a person, firm or company that showcases its products or services at an exhibition event that has been organized by the Client. The Client provides exhibition spaces for each person/firm/company to set up their booths and stands.
F. "Client Personal Data" means any Personal Data that the Client shares with or permits fielddrive to access, store, host, modify, share, delete and/or further Process for the performance of the Services, which includes the Personal Data of End Users/Attendees and Exhibitors at onsite event organized by the Client that is processed by fielddrive, more particularly described in this DPA.
G. "Data Subject" means the identified or identifiable person to whom Personal Data relates to.
H. "Data Breach" shall mean a data breach, as defined in the EU GDPR.
I. "Attendees" means the clients and all individuals who shall, from time to time, be attending or participating in the events organized by the Client using fielddrive Services and are part of Client Personal Data under this DPA.
J. "EU Data Protection Laws" or "GDPR" means (i) prior to 25 May 2018, Directive 95/46/EC of the European Parliament and of the Council on the protection of individuals with regard to the processing of personal data and on the free movement of such data, including any applicable national implementations thereof; and (ii) on and after 25 May 2018, Regulation 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC ("General Data Protection Regulation" or "GDPR"), as amended, replaced or superseded, as well as any other applicable data protection laws and/or regulations in force in EU Member States.
K. "End Users" constitutes the Data Subjects of Client, who are Attendees, Exhibitors, any other personnel authorized by the Client to attend the event organized by the Client.
L."Equivalent Protection Area" means the area that comprises (a) countries within the European Union, including Iceland, Liechtenstein, and Norway, and (b) countries that the European Commission may from time to time recognize as ensuring an adequate level of protection as provided for in article 45 of the GDPR, which includes Switzerland and the United Kingdom.
M. "Personal Data" means any information relating to a Data Subject; an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person. This includes any special categories of Personal Data defined in Art. 9 of the GDPR, data relating to criminal convictions and offenses or related security measures defined in Art. 10 of the GDPR and national security numbers defined in Art. 87 of the GDPR and national supplementing law.
N. "Processor" or "Data Processor" means a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller and as instructed by the Controllers, usually for specific purposes and services accessible to the Controller. The definition of Processor has meaning given to it under Article 2(8) of EU Data Protection Law.
O. "Sub-processor" means any person appointed by or on behalf of the Processor, or by or on behalf of an existing Sub-processor, to process Personal Data on behalf of the Controller, as defined in Art. 28(4) of EU Data Protection Laws. Current list of fielddrive's sub-processor is available at https://www.fielddrive.com/sub-processors which may be updated by fielddrive from time to time.
P. "Standard Contractual Clauses" means the contractual clauses set out in Annex I to this DPA pursuant to the European Commission's decision (EU) 2021/914 of 4 June 2021 on Standard Contractual Clauses for the transfer of Personal Data to Processors established in third party countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council (the "EU SCCs"), which do not ensure an adequate level of protection, and any further approved set of contractual clauses as approved by the competent authority from time to time.
Q. "Security Incident" means any confirmed breach of security that leads to the accidental, or unlawful destruction, loss, alteration, use, unauthorized disclosure of or access to Personal Data.
R. "Services" means the provision of onsite and offsite event services provided by fielddrive which includes but is not limited to; data integration, live badging, tracking and tracing facilities, event intelligence products and services that are set forth in the T&Cs or associated fielddrive order form and further set forth in this DPA.
S. "Transfer" means any Processing, which includes accessing, sharing, disclosing or otherwise making Personal Data available, whether by a fielddrive Affiliate, its suppliers or the Client, from another location than where the Processing initially occurs, which includes:
- any transfer of Client Personal Data from the Client to fielddrive;
- an onward transfer of Client Personal Data from fielddrive to a fielddrive Affiliate; or
- an onward transfer of Client Personal Data from fielddrive and/or a fielddrive Affiliate to another Sub-Processor ”,
- in each case, where such Transfer would be prohibited by Applicable Data Protection Laws (or by the terms of data transfer agreements put in place to address the data transfer restrictions of Data Protection Laws) in the absence of appropriate safeguards and any lawful mechanisms for such Transfers, which includes the use of Standard Contractual Clauses.
T. "UK Data Protection Laws" means the GDPR as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018 in the UK ("UK GDPR") and the Data Protection Act 2018.
3. Applicability of DPA
3.1 Events held by fielddrive can be attended by individuals from around the world. fielddrive's processing of Client Personal Data is subject to privacy and data protection laws in England and the European Union irrespective of Client's location, and depending on where Client and attendees of an Event are located, various different jurisdictions' privacy and data protection laws may also apply.
4. fielddrive Data Processing Details
4.1 Subject-matter: Processing of data related to the Services as described in the T&Cs and the Privacy Policy of fielddrive.
4.2 Nature and purpose: Processing data for the purpose of managing and providing fielddrive product and services as agreed between the Parties to the T&Cs.
4.3 Duration: This DPA will be applicable and be in effect from the date it has been signed by both Parties until the T&Cs expires or until the Data Processor's obligation to perform services under the T&Cs terminates for any reason, except for the provisions of the T&Cs and the DPA that continue to run after termination. In the event of any breach of any obligations under this DPA by the Controller or Processor, the Parties may impose termination of the T&Cs along with this DPA. Notwithstanding the duration mentioned in the T&Cs, this DPA will be applicable until the anonymization, return, or deletion of Client Personal Data in accordance with this DPA.
4.4 Types of personal data:
"Attendee Data" and "Speaker Data" such as (a) image; (b) contact details and address; (c) first and last name; (d) alias; (e) event participation and registration data; and (f) additional information provided independently by individuals in connection with Client's events.
"Event Content" which includes (a) first and last name and email of Client's invitees to the Client's event; and (b) personal data embedded in Client event related content.
"Exhibitor Data" such as (a) image; (b) contact details and address; (c) first and last name; (d) alias; (e) event participation and registration data; and (f) additional information provided independently by individuals in connection with Client's events.
4.5 Categories of Data Subject:
- Attendees,
- individuals in Event Content,
- Exhibitors.
5. Roles and Responsibilities of fielddrive during Processing of Client Data
5.1 The subject matter and details of the processing are described in this DPA.
5.2 Client Personal Data is being processed by fielddrive as part of providing access and use of product and services of fielddrive to the Client, Attendees, Exhibitors and any other individual authorized by the Client, further specified in the T&C.
❖ Roles of Parties
5.3 fielddrive is a data processor of Client Personal Data and shall processPersonal Data on behalf of the Client and process the ClientPersonal Data under the instructions of the Client, in accordance with Article28(1) of EU Data Protection Laws for providing its Services as described in this DPA.
5.4 Client is the data controller as applicable, of the Client Personal Dataunder Applicable Data Protection Laws.
❖ Legal basis/ lawful basis for processing of Client Personal Data
5.5 fielddrive processes Client Personal Data under contractual obligationand in no event will fielddrive process the Client Personal Data for its ownpurposes or those of any third party.
5.6 The details of processing Client Personal Data are enumerated below in this DPA and theAppendix I attached to this DPA.
5.7 Client acknowledges and agrees that anyProcessing under this DPA may also be carriedout by any fielddrive Affiliate, and fielddrive Affiliateshall assume the obligations of fielddrive,in its capacity of Processor, for any such Processing under this DPA.
5.8 Each Party will comply with the obligations applicable to it under theApplicable Data Protection Laws with respect to the processing of that ClientPersonal Data and Personal Data of an individual.
6. fielddrive Obligations as Processor of Client Personal Data
6.1 fielddrive’s obligations
fielddrive shall:
- only process Client Personal Data for the purposes set forth in the T&Cs and this DPA,
- and only in accordance with the lawful, documented instructions of Client (including with regard to transfers of Client Personal Data to a third country), unless fielddrive is required to process Client Personal Data by the Applicable Data Protection Laws to which fielddrive is subject (in such a case, fielddrive shall inform the Client of that legal requirement before processing, unless applicable law prohibits such information);
- only act on the Client's instructions, which may be specific or of a general nature as set out in this DPA or as otherwise notified by the Client to fielddrive from time to time and not for fielddrive's own purposes;
- refrain from processing Client Personal Data and notify the same to the Client immediately, if the instruction to process Client Personal Data by the Client infringes with the Applicable Data Protection Laws;
- keep all Client Personal Data confidential, and ensure to only provide access to authorized employees, agents, suppliers, contractors, consultants and subcontractors who are authorized and have a need to access such data, complying with the same degree of confidentiality as under this DPA;
- fielddrive shall ensure that its relevant employees, agents and contractors receive appropriate training regarding their responsibilities and obligations with respect to the processing, protection and confidentiality of Client Personal Data;
- implement all appropriate technical, physical and organizational measures to ensure a level of security appropriate to the level of risk to Client Personal Data as required by Applicable Data Protection Laws;
- comply with the terms of the T&Cs including, without limitation, while providing access to usage of the product and Services, and for back-up and recovery, cyber security, operations, control, improvements and development of the product and Services, fraud and service misuse prevention and legal and administrative proceedings;
- unless permitted by the Client, not: (a) sell Personal Data, nor (b) collect, retain, use, or disclose Client Personal Data that it has access to for any purpose other than for the specific purpose of performing the Services specified in the T&Cs and this DPA. Unless otherwise permitted by the Client, fielddrive shall not use any Client Personal Data for its own commercial benefit. Except as otherwise instructed, the Client hereby authorizes fielddrive to create de-identified or anonymized data for the purpose of improving the Services and the product and conduct analytics and reports on the use of the product and Services;
- comply with other reasonable written instructions provided by the Client in writing where such instructions are consistent with the terms of the T&Cs and comply with all Applicable Data Protection Laws.
- process Client data (business representative of the Client) for its own legitimate purposes, as an independent Controller, solely when the Processing is strictly necessary and proportionate, and if the Processing is for one of the following exhaustive list of purposes:
- sales pitching and management, billing, account, and Client relationship management (marketing communication with procurement) and related Client correspondence (mailings about for example necessary updates);
- complying with and resolving legal obligations under Applicable Data Protection Laws, provide services to Data Subjects located in the EU or monitors theirbehaviors, appoint a Representative located in the EU to enable Data Subjectsto exercise their rights and make such information available to Data Subjectsin an appropriate manner, other tax requirements, agreements and disputes;
- anonymize and/or use aggregate data for
- improving andoptimizing the performance and core functionalities of accessibility, privacy,security, and the IT infrastructure efficiency of fielddrive Services;
- internal reporting, financial reporting, budget planning, capacity planning andbuilding, and forecast modeling (including product strategy);
- receiving andusing Feedback for fielddrive's overall service improvement; and
For more details on how fielddrive processes data as a controller, kindly refer to fielddrive's privacy policy on the fielddrive domain website.
6.2 When acting as an independent Controller, fielddrive will not process Client Personal Data for any purposes other than the above list of legitimate purposes.
7. Client Obligations as Controller of Client Personal Data
7.1 The Client represents and warrants that it has undertaken to provide all necessary notices to End-Users and received all necessary permissions and consents, as required for fielddrive to Process the Client Personal Data under this DPA and pursuant to the Applicable Data Protection Laws in their respective country and state (if applicable).
7.2 The Client represents and warrants that it has complied with all information provision obligations under the Applicable Data Protection Laws.
7.3 To accomplish Client's notice andconsent obligations under Applicable Data Protection Laws, the Clientmay refer to fielddrive's privacy policy. However, it is clear that fielddriveas a Data Processor does not bear the obligation for information provisionand obtaining consent of individuals who attend theevent organized by the Client, except for fielddrive personnel, under theApplicable Data Protection Laws and only provides a notice as Processor for theClient’s convenience to explain the various processing activities, functionalities and measuresand features available on the products and services provided by fielddrive. Inno event, shall fielddrive’s privacy policy be construed as legal advice norreplacing the Client’s privacy notice.
7.4 Responsibilities of Client:
- instructs fielddrive (and authorizes fielddrive to instruct each Sub-processor) to :
- Process Client Personal Data in a manner that is in compliance with the Applicable Data Protection Laws; and
- in particular, transfer Client Personal Data to any country or territory, as reasonably necessary for the provision of the Services and consistent with the T&Cs;
- warrants and represents that it is and will at all relevant times remain duly and effectively authorized to give the instruction set out in Clause 5; and
- warrants and represents that it has complied with Applicable Data Protection Laws in respect of any obligations that it has under Applicable Data Protection Lawswith respect to it being the Controller of Client Personal Data. The Clientfurther represents and warrants that it has collected the Client Personal Datain accordance with Applicable Data Protection Laws.
7.5 As Client is the Controller of Personal Data of Data Subjects, it is the responsibility of the Client to ask for consent from Attendees for new types of data processing, nor shall fielddrive process Client Personal Data for any "further" or "compatible" purposes (within the meaning of Articles 5(l)(b) and 6(4) GDPR) other than those specified in this DPA.
7.6 Client's instructions to fielddrive for the Processing of Client Personal Data shall comply with Applicable Data Protection Laws. Client shall be responsible for the Client Personal Data and the means by which Client acquired Client Personal Data.
8. Rights of Data Subjects
8.1 fielddrive, depending on the nature of processing, must provide reasonable and timely assistance to Client (at Client's expense) to enable Client to respond to any Data Subject rights under Applicable Data Protection Law (including its rights of access, to rectification, to erasure, to restriction, to objection, and data portability, as applicable).
8.2 If fielddrive's Privacy Team receives a request from a data subject that relates to Client Personal Data, fielddrive will: (a) advise the data subject to submit their request to Client; (b) notify Client; and (c) not otherwise respond to that data subject's request without authorization from Client. Clients will be responsible for responding to any such request, and where necessary, fielddrive will provide complete assistance in responding to the Data Subject requests. fielddrive reserves the right to reimbursement from Client for the reasonable cost of any time, expenditures or Fees incurred in connection with such assistance provided to Client.
9. Cooperation and Assistance
9.1 fielddrive will provide the Client with commercially reasonable cooperation and assistance in relation to handling the inquiries/requests from End Users regarding their Personal Data to the extent legally required and to the extent Client is unable to Process such End User request through the features available on the product, if the Client has requested, in writing, fielddrive's assistance. The Client is liable to reimburse fielddrive for any costs and expenses related to the provision of such assistance.
9.2 This includes responding to inquiries from authorities and data subjects and, where applicable, to provide reasonable support to the Client in case of data breaches and notifications to authorities and/or data subjects, with data protection impact assessments or to consult authorities.
9.3 It is clarified that fielddrive or any of its Sub-processors shall not respond to that request except as required by Applicable Data Protection Laws to which fielddrive or any of its Sub-processors is subject, as applicable, in which case fielddrive shall to the extent permitted by Applicable Data Protection Laws inform Client of that legal requirement before fielddrive or any of its Sub-processors responds to the request.
10. Authority of Client to Issue Instructions and Assistance
10.1 The Client shall issue instructions to fielddrive in writing/via email. fielddrive will duly cooperate with and make commercially reasonable efforts to assist the Client in complying with Client's obligations pursuant to the Applicable Data Protection Laws, considering the nature of processing, technical and organizational feasibility, and the information available to fielddrive. The Client shall reimburse costs and expenses for any cooperation and assistance services provided to the Client in that regard.
11. fielddrive Personnel
11.1 Limitation of Access: fielddrive shall take reasonable steps to ensure the reliability of any employee, agent or contractor of fielddrive who may have access to the Client Personal Data, ensuring in each case that access is strictly limited to those individuals who need to know/access the relevant Client Personal Data, as strictly necessary for the purposes of the T&Cs, and to comply with Applicable Data Protection Laws in the context of that individual's duties to fielddrive, as applicable, ensuring that all such individuals are subject to required confidentiality obligations.
11.2 Contractual Obligation: fielddrive shall also impose required contractual obligations upon its Personnel who are engaged in the Processing of Client Personal Data regarding obligations under Applicable Data Protection Laws and thus bind the Personnel to the same obligations that fielddrive has with respect to the Processing of Client Personal Data.
12. Approved Sub-processing
12.1 Client acknowledges, agrees and authorizes, that fielddrive may engage Sub Processors for certain Processing activities as required from time to time on Client's behalf in accordance with this Clause 12 and subject to the terms and any restrictions in the T&Cs.
12.2 Clients approve the Authorized Sub-processors.
12.3 fielddrive may continue to use those Sub-processors already engaged by fielddrive as at the date of this DPA, subject to fielddrive in each case as soon as practicable meeting the obligations set out in Clause13.
12.4 fielddrive shall notify the Client of the appointment of any new Sub-processors, including full details of the Processing to be undertaken by the Sub-processors within 30 (thirty) days of such appointment. If, within 10 (ten) days of receipt of that notice, Client notifies fielddrive in writing of any objections (on reasonable grounds) to the proposed appointment, fielddrive shall work with Client in good faith to make available a commercially reasonable change in the provision of the Services which avoids the use of that proposed Sub-processors.
12.5 With respect to each Sub-Processor, fielddrive shall:
- fielddrive shall ensure that Authorized Sub-processors have executedconfidentiality agreements that prevent them from unauthorized Processing of ClientPersonal Data both during and after their engagement by fielddrive.
- ensure that the arrangementbetween on the one hand (a) fielddrive, and on the other hand theSub-processor, is governed by a written contract including terms which offer atleast the same level of protection for Client Personal Data as those set out inthis Addendum and meet the requirements of article 28(3) of the GDPR;
- if that arrangement involves a Transfer, fielddrive shall ensure thatthe Standard Contractual Clauses are at all relevant times incorporated intothe agreement between on the one hand (a) fielddrive and on theother hand the Sub-processor, or before the Sub-processor first Processes ClientPersonal Data procurethat it enters into anagreement incorporating the Standard Contractual Clauses with the Client; and
- provide to Client for reviewsuch copies of fielddrive's agreements, as applicable, with Sub-processors(which may be redacted to remove confidential commercial information notrelevant to the requirements of this Addendum) as Client may request from timeto time.
- fielddrive shall communicate the request made by the data subjectregarding any data subject rightsregarding their personal data in accordance with the Applicable Data Protection Laws.
13. fielddrive's Security Responsibilities
13.1 Data Protection Law to each of its Sub-Processor to whom the personal data have been disclosed unless this proves impossible or involves disproportionate effort.
13.2 Taking into account the current state of the art, best industry standards the costs of implementation and the nature, scope, context and purposes of Processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons,fielddrive shall in relation to the Client Personal Data implement appropriate technical and organizational measures to ensure a levelof security appropriate to that risk, including, as appropriate, the measures referred to in Article 32(1) of the GDPR and equivalent provisions under theApplicable Data Protection Regulations, including, but not limited to, the“Security Measures” set out in Annex II to the Standard Contractual Clauses. Clientacknowledges that the Security Measures are subject to technical progress anddevelopment and that fielddrive may update or modify the Security Measures from time to time, provided that such updates and modifications do not degrade or diminish the overall security of the Services.
13.3 fielddrive will maintain administrative, physical and technical safeguards to ensure a level of security including the anonymization, pseudonymization and encryption of Client Personal Data and protection of the security, confidentiality, and integrity of Client Personal Data. fielddrive shall monitor compliance with these safeguardsand will not in any case, decrease the overall security during the Terms of the T&Cs.
13.4 fielddrive shall provide for regular testing, assessing and evaluatingthe effectiveness of technical and organizational measures for ensuring thesecurity of the processing.
13.5 In assessing the appropriate level of security, fielddrive shall take account in particular of the risks that are presented by Processing, inparticular from a Personal Data Breach.
13.6 fielddrive shall provide to the Client at reasonable intervals (which may be redacted to remove confidential commercial information not relevant to the requirements of this Addendum), the most recent version of fielddrive’s information security policy, as Client may request from time to time.
14. Client's Security Responsibilities
14.1 Without prejudice to fielddrive's obligations under this Clause (security), the Client:
- shall remain solely responsible for its use of the Services, including: (a) making appropriate use of the Services to ensure a level of security appropriate to the risk in respect of the Client Personal Data; (b) securing the account authentication credentials, systems and devices Client uses to access the Services; and (c) backing up the Client Personal Data; and
- acknowledges that fielddrive has no obligation to protect Client Personal Data that Client elects to store or transfer outside of fielddrive's and its Subprocessors' systems.
15. Supervisory Power of Client and Audits
15.1 Upon Client's written request, at reasonable intervals, fielddrive shall make available to Client (which is not a competitor of fielddrive) information necessary to demonstrate compliance with this Addendum, and shall allow for and contribute to audits, including inspections, by the Client or an auditor mandated by the Client, at the Client's cost, in relation to the Processing of the Client Personal Data by fielddrive and their Sub-processors, provided that such audit right is available to the Client once yearly.
15.2 Information and audit rights of the Client only arise under Clause 16.1 to the extent that the T&Cs does not otherwise give them information and audit rights meeting the relevant requirements of Data Protection Law (including, where applicable, article 28(3)(h) of the GDPR).
15.3 Client or an auditor mandated by the Client undertaking an audit shall give fielddrive a notice of 30 (thirty) days prior to any audit or inspection which is to be conducted and shall make (and ensure that each of its mandated auditors makes) reasonable endeavors to avoid causing any damage, injury or disruption to fielddrive's premises, software, equipment, Personnel and/or business while its personnel are on those premises in the course of such an audit or inspection.
15.4 It is expressly clarified that fielddrive will not be able to provide access to its product operated by fielddrive or otherwise let the auditors interact with the product.
15.5 Client shall ensure that any such auditor as engaged by the Client shall perform the audit in compliance with this DPA, and Applicable Data Protection Laws.
15.6 fielddrive, and its Sub-processors need not give access to its premises for the purposes of such an audit or inspection:
- to any individual unless he or she produces reasonable evidence of identity and authority; or outside normal business hours at those premises, unless the audit or inspection needs to be conducted on an emergency basis and Client undertaking an audit has given notice to fielddrive that this is the case before attendance outside those hours begins.
16. 1Personal Data Breach Management and NotificationBreach prevention and management
16.1 fielddrive will continue to maintain Security Incident management policies and procedures to the extent required by law and shall promptly notify Client of any Personal Data Breach which fielddrive or any Sub-processor becomes aware of.
16.2 fielddrive shall provide the Client with sufficient information regarding the Personal Data Breach enabling the Client to meet any obligations to report such Personal Data Breach to any authorities or inform the End-Users of such Personal Data Breach.
Remediation
16.3 fielddrive will make reasonable efforts to identify and, to the extent such Personal Data Breach is caused by a violation of the requirements of this DPA by fielddrive, remedy the cause of such Personal Data Breach. fielddrive will provide reasonable assistance to Client in the event that Client is required under Applicable Data Protection Laws to notify a regulatory authority or any Data Subjects of a Personal Data Breach.
16.4 fielddrive shall provide notification of a Personal Data Breach in the following manner:
- fielddrive shall, to the extent permitted by Applicable Data Protection Laws, notify Client without undue delay, after fielddrive's confirmation or reasonable suspicion of a Personal Data Breach impacting Client Personal Data of which fielddrive is a Processor;
- fielddrive will notify the occurrence of the Personal Data Breach to the email address of the Client's Account owner.
16.5 As part of above notification, fielddrive shall provide:
- a description of the nature of the Personal Data Breach including the volume and type of Client Personal Data affected and the categories and approximate number of individuals concerned;
- the likely consequences of the Personal Data Breach; and
- a description of the measures taken or proposed to be taken to address the Personal Data Breach, including, where appropriate, measures to mitigate its possible adverse effects.
17. Data Protection Impact Assessments and Prior Consultations
17.1 fielddrive shall provide reasonable assistance to the Client with any data protection impact assessments, and prior consultations with any supervisory authority or other competent data privacy authorities, which the Client reasonably considers to be required as under article 35 or 36 of the GDPR or equivalent provisions of the Applicable Data Protection Laws, in each case solely in relation to Processing of Client Personal Data by, and taking into account the nature of the Processing and information available to fielddrive, fielddrive Affiliate, or any Sub-processor.
18. Deletion, Retention and Return of Client Personal Data
18.1 fielddrive shall retain the Client Personal Data for a period of 30 days from the date of termination of this DPA. Post 30 days, the data will be completely anonymized by fielddrive.
18.2 fielddrive shall not use this data for any purpose apart from retaining it for the Client.
18.3 The Client can request fielddrive at any point in time to delete and/or return all data by way of a written request or instruction, which shall be processed by fielddrive immediately upon receipt of such request. The Client can always exercise its right to data return and erasure by contacting us at privacy@fielddrive.com, and the same shall be communicated to all sub-processors that process and retain fielddrive's Client Data. It shall be Client's exclusive responsibility to secure all necessary data/information from the Client's Account prior to such deletion, including the Personal Data of End Users.
Data Retention
18.4 Copies or duplicates of the data shall never be created, except when Client agrees that fielddrive may retain copies of Client Personal Data as necessary in connection with its routine backup and archiving procedures. The data retention of Client Personal Data shall remain anonymous in such a manner that the data no longer constitutes personal data.
18.5 fielddrive and its Sub-processors may retain Client Personal Data to the extent required by Applicable Data Protection Laws and other applicable laws and always provided that fielddrive and its Sub-processors shall ensure the confidentiality of all such Client Personal Data and shall ensure that such Client Personal Data is only Processed as necessary for the purpose(s) specified in the Applicable Data Protection Laws requiring its storage and for no other purpose.
Disclosure to Competent Authorities
18.6 fielddrivemay disclose Client Personal Data, (a) if required by a summon/subpoena or other judicial oradministrative order, or if otherwise requiredby the Applicable Data Protection Laws and other applicable laws if any.
19. Cross-border Data Transfers
19.1 TheParties acknowledge and agree that in the event that Client transfers ClientPersonal Data to fielddrive, fielddrive makes routine transfers of ClientPersonal Data in the normal course of business to itself orits Affiliates and/ Sub-processors, andthese transfers include may ClientPersonal Data wherein Applicable DataProtection Laws apply to, such transfers, to any countries which donot ensure an adequate level of data protection, be undertaken by Processorthrough one of the following mechanisms:
- Where a Data Transfer occurs for which the Client are acting as Controller and provide Client Personal Data of EU/ EEA and Swiss Data Subjects to fielddrive as a processor under this DPA, then any Data Transfers that occur of such data shall be governed by the Standard Contractual Clauses set forth in Annex I to this Addendum.(EU Standard Contractual Clauses (Module 2: Controller to Processors), any change on the sub-processor list will be informed to the Client by fielddrive here.
- Appendix AnnexI to the SCC will be completed with the information that Client will be thedata exporter and fielddrive shall be the data importer of Client Personal data.
- Appendix Annex II contains the security measures adopted by fielddriveto keep Client Personal Data safe and secure.
- For international data transfer as per UK GDPR, where a Transfer occurs for whichthe Client is acting as a Controller and provide Client Personal Data of UK Data Subjects to fielddrive acting as a Processor under this DPA, then any Transfers which occur of such data shall be governed by the EEAcontroller to processor SCCs incorporating the amendments set out in clause 3.a. and the UK Addendum set forth in AnnexureII.
19.2 Where Client permits the transfer of the Client Personal Data outside the Equivalent Protection Area (European Union, Iceland, Lichtenstein, Norway, or the United Kingdom (the "EEA")), the Transfer should be based on the Standard Contractual Clauses or via any other lawful transfer mechanism. The Client's approval is given at the effective date in accordance with the instructions and processing activities as set out in this DPA.
19.3 To the extent that any chosen lawful mechanism provided above is no longer valid, the Client shall implement any appropriate alternative transfer mechanism to comply with Applicable Data Protection Laws.
19.4 Subject to Clause 19.1, the Client (as "data exporter") and fielddrive and their Sub-processors, as appropriate, (as "data importer") hereby enter into the Standard Contractual Clauses in respect of any Transfer from the Client to fielddrive or their Sub-processors.
19.5 The Standard Contractual Clauses shall come into effect under Clause19.1 on the later of:
(i) the dataexporter becoming a party to them;
(ii) the dataimporter becoming a party to them; or
(iii) commencement ofthe relevant Transfer.
19.6 Clause 19.1 shall not apply to a Transfer unless its effect, together with other reasonably practicable compliance steps, is to allow the relevant Transfer to take place without breach of Applicable Data Protection Laws.
19.7 Before fielddrive provides its Services to the Client in accordance with the present T&Cs, if the Client concludes, based on its current or intended use of the Services, that the alternative transfer mechanism and/or Standard Contractual Clauses, as applicable, do not provide appropriate safeguards for Client Personal Data, then Client may immediately terminate the applicable T&Cs and for convenience choose to do so by notifying fielddrive.
20. General Terms
20.1 If the Client Personal Data with fielddrive is jeopardized due to attachment or confiscation, insolvency proceedings or due to other events or measures of third parties, fielddrive shall immediately notify (i) the Client thereof, and (ii) all institutions or persons competent or concerned that the Client as the Controller as defined in the Applicable Data Protection Laws holds the exclusive sovereignty over and exclusive title to the data.
20.2 Each Party shall keep a record of their processing activities. They agree to co-operate with the Data Protection Authority/Supervisory Authority when required to do so.
20.3 fielddrive may designate a representative as laid down in Art 27 Paragraph 1 GDPR in the European Union, as applicable.
21. Governing Law and Jurisdiction
21.1 Governing law and jurisdiction shall be as set out in the T&Cs.
22. Order of Precedence
22.1 Nothing in this Addendum reduces fielddrive's obligations under the T&Cs in relation to the protection of Personal Data or permits fielddrive to Process (or permit the Processing of) Personal Data in a manner which is prohibited by the T&Cs. In the event of any conflict or inconsistency between the provisions of this Addendum and the Standard Contractual Clauses, the Standard Contractual Clauses shall prevail.
22.2 In the event of inconsistencies between the provisions of this Addendum and any other agreements between the Parties, including the T&Cs and including (except where explicitly agreed otherwise in writing, signed on behalf of the Parties) agreements entered into or purported to be entered into after the date of this Addendum, the provisions of this Addendum shall prevail.
ANNEX I
I. Standard Contractual Clauses
II. TECHNICAL AND ORGANIZATIONAL MEASURES INCLUDING TECHNICAL AND ORGANIZATIONAL MEASURESTO ENSURE THE SECURITY OF THE DATA
1. Information Security Program
fielddrive has implemented and maintains appropriate technical andorganizational measures designed to protect Client Personal Information asrequired by Applicable Data Protection Law(s) across the globe. fielddrive isin the process of getting certified on ISO 27001:2022 and ISO 27701:2019 standards and agrees to regularly test,assess, and evaluate the effectiveness of its Information Security and Privacy Program to ensure the security and privacy of the data Processing.
2. Encryption
- All data flow in data pipelines is encrypted using a secure channel like TLS1.2+/SSL 3.0/ HTTPS.
- Data whether atrest or in motion is completely encrypted by using industry standard AES-256encryption algorithm at rest and in transituses SHA-256 with RSA encryption. All the static filesstored on AWS S3 are using AES-256 encryption.
- fielddrive hasa password masking technique for the data lifecycle to ensure a secure key management process.
3. Application Security
- We regularlyconduct security training such as the OWASP Secure Coding practices to raise and keep awareness in the fielddrive development team and use best practices for building secure applications. The fielddrive teamconducts Whitebox testing on each code release. The fielddrive security teamuses Burp Suite Professional software to test for all vulnerabilities from timeto time as per fielddrive policies and procedures.
- fielddrive’s code is stored in a code repository system hosted by our cloud data center provider. fielddrive adopts a strict,least access privileges principle for access to the code. Commits to production code are strictly reviewed, and approval is restricted to just CTO /Lead-DevOps, (after passing Unit Testing and QA in Test and Staging).
- The data stored on production servers is accessible only to qualified personnel on a need to know basis. No other workforce member of fielddrive has access to Client Data unless access permission is granted by the CTO to resolve any technical issue or fordebugging.
- The fielddriveproduction environment is logically segregated from the staging and development environment with concepts of virtual private cloud and subnets.There is an hourly backup of the database data at secured cloud storage of cloud service provider(AWS).
- Connection to the fielddrive web-app via HTTPS by using the latest version of Transport Layer Socket (TLS) like TLS 1.2+ and above.
4. Application Access
- Role-based access and least access privileges principle provision while creating an account to ensure an appropriate level of accessto the fielddrive account
- Provision to disable/delete users
- Session Management: Every time a fielddrive user signs into the fielddrive account, the system assigns a new session identifier for the user. The session identifier is a 64-byte random generated value to protect the account against brute force attacks.
- All user passwords are hashed before they are stored.
5. Infrastructure and Network Security
- Since the fielddrive platformis hosted on AWS, numeroussecurity controls are implementedusing AWS Managed Services like AWS GuardDuty, AWS Shield, AWC VPC and securitygroups, along with AWS CloudWatch. and AWS CloudTrail. These managed serviceshelp fielddrive to have robustIntrusion Detection System (IDS) and Intrusion Prevention System (IPS) in bothProduction and Non-Production environments. Notifications from these tools aresent to the fielddrive securityand DevOps team so that they can take appropriate action. On top of that, fielddrive is in the processof implementing an ApplicationPerformance Management (APM) Tool which provides us real time notification ofany changes/ amendments to the production and non-production environment.
- fielddrive is in the process of implementing the CrowdStrike Falcon Intelligent End-point Detection and Response (EDR)on our public facing criticalsystems both in production and non-production environments andregularly monitors them.
- fielddrive regularlyupdates network architecture schema and maintainsan understanding of the data flows between its systems.Firewall rules and access restrictions are reviewed for appropriateness on aregular basis.
6. Operational Security
- fielddrive runsan annual training program for its employees to treat data protection andsecurity as the highest priorities. fielddrive is committedto implement tightersecurity standards acrosspolicies, procedures, technology, and people on an ongoing basis.
- fielddrive runsVulnerability Assessment Penetration Testing (VAPT) on a Yearly basis through a third-party serviceprovider plus in-housesecurity team also runs VAPT as and whenthere is any change in the infra or a new code is released to ensure the sanityof the program.
- Applicationsand servers are regularly patched to provide ongoing protection from exploits.
- All of fielddrive Client Data is hosted in a secure cloud data center serviceprovider (AWS) and alsologically segregated by the fielddrive application.
ANNEX II : UK INTERNATIONAL DATA TRANSFER ADDENDUM
To the extent that fielddrive is a recipient of Personal Data governed by UK GDPR in a country that is not recognized as providing an adequate levelof protection for Personal Data as described in the UK GDPR, the Parties agree to abide by the EU SCCs together with the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (version B1.0, in force March 21,2022):
The UK Addendum is incorporated into the Addendum by reference. Capitalized terms used but not defined in this addendum will have the meaning provided in the Addendum and the DPA.
The UK Addendum is deemed completed as follows:
- fielddrive isacting as the Importer and Client is acting as the Exporter. The same will be populated in the UK Addendum(attached above) in Table 1 of the Addendum.
- The Partiesagree the UK Addendum is appended to the EU SCCs and will be detailed in Table 2 of the UK Addendum.
- The Partiesagree to populate table 3 in accordance with the EU SCC.
- The Partieselect that neither party may end the UK Addendum with respect to Section 19 ofthe UK Addendum.
