Vous devez activer les cookies pour accéder à ce site.
Effective October 1, 2026
Please read this Master Software and Services Agreement (the “Agreement”) carefully. This Agreement governs the provision and use of the Software and Services identified in the applicable Order Form, including SaaS Deployments and On-Premise Deployments, as specified in that Order Form.
This Agreement is entered into between the customer entity identified in the applicable Order Form (“Customer”) and the Newforma entity identified in that Order Form (“Supplier”).
This Agreement applies to Order Forms agreed upon from October 1st, 2026. Existing customers with a prior agreement remain subject to the legacy terms: Newforma Terms and Conditions (Legacy), Terms and Conditions for Newforma Project Center, Terms and Conditions for Newforma Konekt, Terms and Conditions for Newforma ConstructEx
Customer must accept this Agreement before accessing or using the Software or Services, whether by signing an Order Form incorporating this Agreement or otherwise expressly accepting this Agreement electronically. Any individual accepting this Agreement on behalf of Customer represents and warrants that they have authority to bind Customer to its terms.
If Customer and Supplier have entered into a separate written agreement expressly governing the relevant Software or Services, that separate agreement applies instead, unless the parties expressly agree otherwise in writing. Individual Users accessing or using the Software or Services on Customer’s behalf must comply with the terms applicable to their use under Customer’s agreement.
Individual Users accessing the Software or Services under Customer’s agreement must comply with the terms applicable to their use; they are not required or authorised to replace or amend Customer’s agreement.
If you do not agree to the applicable terms, or do not have the necessary authority to accept this Agreement on Customer’s behalf, please click “Cancel” or “Back”, where available, and do not proceed with acceptance or access to or use of the Software or Services under this Agreement.
This Agreement is made between
(1) The Newforma entity identified in an Order Form (the “Supplier”); and
(2) The Customer entity identified in an Order Form (the “Customer”).
(A) This Master Software and Services Agreement (the "Agreement") is entered into by and between the Supplier and the Customer (each a "Party" and collectively the "Parties") for the purpose of establishing the terms and conditions under which the Supplier will provide certain services to the Customer.
(B) The Supplier is engaged in the business of providing software for the architecture, engineering, construction and owner/operator industry, offering project information management and collaboration solutions and the Customer desires to engage the Supplier to provide these services as further described in one or more Order Forms.
(C) In the event of any conflict or inconsistency between the terms and conditions of this Agreement and those of any Order Form, the terms and conditions of this Agreement shall prevail unless explicitly stated otherwise in the applicable Order Form.
(D) This Agreement shall be effective as of the date specified in an Order Form (the "Effective Date").
1. Definitions
Affiliate of a party means any third-party that, directly or indirectly, through one or more intermediaries, Controls, is Controlled by, or is under Common Control with, the first party.
Agreement or Master Software and Services Agreement means this agreement, including all schedules, exhibits, and attachments hereto, as may be amended from time to time in accordance with its terms.
AI Functionality means, solely for the purposes of this Agreement, any feature, capability or component of the Service that uses (a) generative artificial intelligence to generate content, including text, images, audio, video or code, in response to inputs or instructions; or (b) agentic artificial intelligence to plan and execute tasks or actions with a degree of autonomy in pursuit of specified objectives.
AI-Generated Content means any text, data, reports, images, or other materials generated through the Customer’s authorised use of the AI Functionality
Beta Services means any Service or functionality made available free of charge (excluding any free of charge functionality included by the Supplier as part of a Service for which Fees are paid by the Customer) or identified by Supplier as “alpha”, “beta”, “preview”, “early access”, “trial”, “evaluation”, “pilot”, “experimental” which are made available to the Customer for testing, evaluation or feedback purposes or otherwise as not generally available
Business Day means any day other than a Saturday, Sunday or statutory holiday in the jurisdiction of the Supplier entity specified in the Order Form
Confidential Information means any non-public information, data, or materials, in any form or medium, that are disclosed or made available by one Party to the other Party in connection with this Agreement, and which are marked or otherwise identified as confidential or proprietary, or which should reasonably be understood to be confidential or proprietary given the nature of the information and the circumstances of its disclosure.
Control means, in relation to an entity, the direct or indirect ownership of more than 50% of its voting rights, the right to appoint or remove a majority of its board of directors or equivalent governing body, or the power to direct its management and policies, whether through ownership, contract or otherwise. “Controls”, “Controlled” and “under common Control” shall be interpreted accordingly.
Customer Data means Customer's confidential, proprietary or trade secret information and any trademarks, copyrights or patents of Customer used in connection with the Services and any records or information created in the course of use of the Services by Customer and its Users.
Customer Content means all information, data, documents, images and other materials uploaded, submitted or otherwise made available to the Services by or on behalf of Customer for hosting, storage, processing or display by Supplier in connection with providing the Services.
Data Protection Laws means all laws, regulations, legally binding regulatory requirements and legally binding guidance relating to privacy, data protection, cybersecurity, confidentiality, data governance and the Processing of Personal Data, to the extent applicable to a party’s activities under this Agreement, including, without limitation:
(a) the GDPR and applicable national implementing legislation;
(b) the UK GDPR and the Data Protection Act 2018;
(c) the Swiss Federal Act on Data Protection;
(d) the California Consumer Privacy Act, as amended by the California Privacy Rights Act, and other applicable United States federal and state privacy laws;
(e) Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation, including Quebec’s Act respecting the protection of personal information in the private sector, as amended by Law 25;
(f) Australia’s Privacy Act 1988 (Cth), including the Australian Privacy Principles, and applicable state and territory privacy legislation; and
(g) Singapore’s Personal Data Protection Act 2012,
together with any applicable implementing regulations, in each case as amended, extended, replaced or superseded from time to time.
Deployment Model means either:
(a) SaaS Deployment – where the Software is hosted by or on behalf of Supplier and accessed remotely by Customer; or
(b) On-Premise Deployment – where Software is installed and operated within Customer's own environment or infrastructure.
Documentation means all materials supplied to Customer including any and all manuals, training materials, guides, or other materials that describes the functionality and/or specifications of the Software and Services.
Fees means the fees payable by the Customer to the Supplier for the Services, as set forth in the applicable Statement of Work or Order Form.
Force Majeure Event means any event or circumstance beyond the reasonable control of a Party, including but not limited to acts of God, natural disasters, wars, riots, strikes, epidemics, pandemics, or governmental actions.
Hosted Services means the SaaS Deployment services provided by Supplier.
Intellectual Property Rights or IPR means all patents, copyrights, trademarks, trade secrets, and other intellectual property rights, whether registered or unregistered, and all applications and registrations thereof.
Licence Term means the period during which Customer is entitled to use On-Premise Software.
Major Version means a version of the Software that contains substantial new functionality, material changes to its architecture, functionality or user interface, or other significant enhancements, or which Supplier designates as a major version by changing the whole-number component of the version number. For example, from version 3.x to version 4.0. A Major Version does not include Updates, patches, bug fixes, security fixes or other minor improvements made within the same whole-number version.
Malicious Code means any software, script, program, or code segment that is intentionally designed to cause damage to a computer system, network, or data; to disrupt operations; to gain unauthorized access; or to perform any other activity without the knowledge or consent of the user, including, but not limited to Viruses, Worms, Trojans, Ransomware, Spyware, Logic bombs, Backdoors or any other form of harmful or unauthorized code
Order Form means a document executed by the Parties setting out any Software to be supplied by the Supplier, together with any use limitations and price to which these terms and conditions apply.
Personal Data means any information relating to an identified or identifiable natural person, as defined under applicable Data Protection Laws.
Services means any software, hosting, maintenance, support, consulting services, implementation services, training services, SaaS services, cloud services or other services identified in an Order Form
Service Level Agreement (SLA) means the document outlining the service levels, response times, and uptime commitments provided by Supplier as updated from time to time.
Software means any computer program(s) Licensed or provided by the Supplier as identified in an Order Form. The term “Software” includes any Updates or other modifications, including custom modifications.
Statement of Work or “SOW” means a document agreed in writing by the parties under this Agreement that describes the Services to be provided, together with any applicable deliverables, responsibilities, dependencies, assumptions, timetable, acceptance criteria, Fees and payment terms. Each Statement of Work forms part of, and is governed by, this Agreement.
Subscription Term means the period during which Customer is entitled to access the Services.
Supplier Content means Supplier’s computer programs, formats, reports, information and data used to render the Services or made available to Customer and its Users.
Support Policies means the policies and procedures governing technical support provided by Supplier for its platform and services, as updated from time to time.
Term means the duration of this Agreement, as specified in Section 3 (Term and Termination).
Update means any bug fix, patch, correction, maintenance release, security update, minor enhancement or modification to the Software or Services made generally available by Supplier.
Upgrade means any major release, version change, new module, new functionality or material enhancement designated by Supplier as a new version, release or upgrade.
User means any individual whom Customer authorises to access or use the Service on its behalf, including any employee, officer, contractor or consultant of Customer or its permitted Affiliates, and any external project participant, in each case subject to the access rights, licence quantities and other restrictions specified in this Agreement and the applicable Order Form.
1.1. Unless the context otherwise requires, words in the singular shall include the plural and vice versa, and words importing any gender shall include all genders.
1.2. References to sections, clauses, and schedules are to sections, clauses, and schedules of this Agreement unless otherwise specified.
1.3. The definitions in this section shall apply throughout this Agreement, unless the context requires otherwise.
2. Services
Supplier shall provide the Software and/or Services described in one or more Order Forms. The nature and scope of Supplier's obligations shall depend upon the Deployment Model specified in the applicable Order Form.
2.1. Order Forms.
(a) From time to time, the Parties may execute Order Forms that will describe the specific Services to be performed by the Supplier and applicable fees payable by the Customer.
(b) Each Order Form shall be governed by the terms and conditions of this Agreement.
(c) In the event of any conflict or inconsistency between the terms and conditions of this Agreement and those of any Order Form, the terms and conditions of this Agreement shall prevail unless explicitly stated otherwise in the applicable Order Form.
2.2. Performance of Services and Support.
(a) For SaaS Deployments, Supplier shall be responsible for hosting, availability and operation of the Hosted Services.
(b) For On-Premise Deployments, Customer shall be responsible for the operation, security and maintenance of Customer's environment, including all infrastructure and software unless otherwise specified in the Order Form.
(c) The Supplier shall perform the Services in a professional and workmanlike manner, in accordance with generally accepted industry standards and practices and in compliance with all applicable laws and regulations.
(d) The Supplier will use reasonable endeavours to provide product support as set forth in the Support Policies and availability commitments, if any, for SaaS deployments in line with the applicable Service Level Agreements. Customer acknowledges and agrees that Supplier may update the Support Policies and/or a Service Level Agreement from time to time, provided that any changes will not materially degrade the level of support during the Term. Support shall be provided in accordance with the Support identified in the applicable Order Form. Any Service Level Agreement shall apply only where expressly identified in an Order Form.
(e) SaaS Deployments. For SaaS Deployments, the Supplier shall:
Use reasonable endeavours to ensure the availability of the SaaS Services in accordance any contracted service availability levels, including any agreed uptime commitment;
i. maintain appropriate systems and processes to monitor the availability and performance of the SaaS Services;
ii. respond to and manage incidents affecting the SaaS Services in accordance with industry best practice; and
iii. use commercially reasonable efforts to restore the SaaS Services following any unplanned interruption as soon as reasonably practicable.
(f) On-Premise Deployments. For On-Premise Deployments, the Supplier's service level commitments shall be limited to:
i. responding to support requests in accordance with industry best practices; and
ii. providing maintenance services, including the provision of updates, patches, bug fixes and other maintenance releases.
(g) Where the Software is deployed on-premises, the Supplier does not warrant or commit to any service availability, uptime or incident response service levels in respect of the Customer's hosting environment or infrastructure, except to the extent that an incident is directly attributable to the Software or the Supplier's maintenance services.
(h) Implementation and Consulting Services. In connection with the Services, Supplier shall provide Customer with the standard level of implementation, deployment, configuration and/or training services, as applicable, that Supplier generally provides to customers for the relevant Service and as specified in the applicable Order Form. Such services may be provided directly by Supplier or through its authorised service business partners.
Any additional implementation, deployment, configuration, training, consulting or other professional services requested by Customer (collectively, "Consulting Services") shall be subject to mutual agreement between the parties and documented in an applicable Order Form or Statement of Work, which shall specify, as applicable, the scope, deliverables, responsibilities, fees and other terms applicable to such Consulting Services.
Customer shall provide Supplier, in a timely manner, with all information, access, personnel, decisions, approvals and cooperation reasonably necessary for Supplier to perform the Consulting Services.
Unless otherwise specified in the applicable Order Form or statement of work, any Consulting Services purchased by Customer that have not been performed within twelve (12) months following the date on which such Consulting Services were ordered shall expire and be forfeited, except to the extent that the failure to perform such Consulting Services within that period is attributable to Supplier's breach of this Agreement.
(i) Support. Supplier shall use reasonable endeavours to provide product support in accordance with the Support Policies and any applicable Service Level Agreement. Customer acknowledges and agrees that Supplier may update the Support Policies and/or any applicable Service Level Agreement from time to time, provided that no such update shall materially degrade the overall level of support provided to Customer during the applicable Term. Support shall be provided in accordance with the Support identified in the applicable Order Form.
2.3. Customer Obligations and Customer Data Usage.
(a) The Customer shall provide the Supplier with all necessary cooperation, information, and assistance as reasonably required by the Supplier in the planning, preparation and performance of the Services.
(b) For On-Premise Deployments Customer shall provide: (i) suitable infrastructure; (ii) supported operating systems; (iii) supported database platforms; (iv) network connectivity; (v) backup facilities; and (vi) security controls.
(c) The Customer shall be responsible for (i) all items identified as such in an Order Form; (ii) all items reasonably considered to be the responsibility or obligation of the Customer given the relationship contemplated under this Agreement; and (iii) all items not identified as Supplier responsibilities (each a “Customer Obligation”).
(d) The Supplier shall have no liability for any delay, cost or other loss arising directly or indirectly as a result of the Customer’s failure to perform any Customer Obligation.
(e) Licence to use Customer Data. Subject to the rights expressly granted to the Supplier under this Agreement, as between the parties, Customer retains all rights, title and interest in Customer Data. Customer grants Supplier a non-exclusive, worldwide licence during the Term, together with any applicable, the retrieval, transition and retention periods set out in clauses 3.5.2 and to the extent Customer Data falls within the definition of Confidential Information, for so long as required under clause 6.3 below, to access, host, store, copy, transmit and otherwise process Customer Data to the extent necessary to provide, maintain, support and secure the Service, perform its obligations under this Agreement and comply with applicable law. Supplier may permit its subcontractors to exercise these rights solely for those purposes, subject to appropriate confidentiality and data protection obligations. Any processing of personal data shall be governed by the applicable Data Processing Addendum.
(f) Supplier may collect and use technical, diagnostic and usage information relating to the operation and use of the Service to monitor performance, maintain security and develop and improve its products and services. To the extent such information contains Customer Data or personal data, it remains subject to the confidentiality obligations in this Agreement and the applicable Data Processing Addendum.
(g) Supplier may also generate and use aggregated and anonymised statistics derived from Customer Data and use of the Service for analytics, benchmarking and product improvement, provided that such statistics do not identify, and cannot reasonably be used to identify, Customer, any User or any other individual, or disclose Customer’s Confidential Information.
(h) Supplier shall not attempt to re-identify any person from such statistics. Supplier shall not sell Customer Data or use it to train or fine-tune any general-purpose or shared artificial intelligence or machine-learning model, or permit any third party to do so, without Customer’s prior written consent. This restriction does not prevent processing Customer Data through AI Functionality to provide the Service in accordance with this Agreement.
2.4. Change Management.
(a) Either Party may request changes to the scope of Services by submitting a written change request to the other Party.
(b) The Parties shall negotiate in good faith to agree upon any changes to the scope of Services, as well as any adjustments to the fees, timelines, or other terms and conditions that may be necessary as a result of such changes.
(c) No change to the scope of Services shall be effective unless and until the Parties have executed a written amendment or addendum to the applicable Order Form.
2.5. Free, Trial and Beta Services.
Beta Services are provided solely for evaluation and testing and must not be used for production or business-critical purposes.
Beta Services are provided “as is” and “as available”, without any representation, warranty, commitment or guarantee of any kind, whether express, implied, statutory or otherwise. To the fullest extent permitted by applicable law, Supplier disclaims all warranties relating to Beta Services, including warranties of satisfactory quality, merchantability, fitness for a particular purpose, accuracy, reliability, availability, security, non-infringement and freedom from defects or errors. Any service levels, support commitments, availability commitments, warranties or remedies otherwise set out in this Agreement do not apply to Beta Services.
Customer acknowledges that Beta Services may be incomplete, contain errors, operate inconsistently, be materially modified or discontinued without notice, and result in the loss or corruption of data. Customer uses Beta Services entirely at its own risk and shall maintain appropriate backups and safeguards.
To the fullest extent permitted by applicable law, Supplier shall have no liability arising out of or in connection with Customer’s access to or use of, or inability to access or use, any Beta Services, whether in contract, tort (including negligence), misrepresentation, breach of statutory duty or otherwise. Nothing in this clause excludes or limits liability that cannot lawfully be excluded or limited.
Supplier may modify, suspend or discontinue any Beta Service, or restrict Customer’s access to it, at any time and without liability. Unless expressly agreed otherwise in writing, Supplier is under no obligation to release a generally available version of any Beta Service or to preserve any data processed through it. This clause prevails over any inconsistent warranty, service-level or liability provision in the Agreement.
The Customer’s right to use Beta Services will expire on the date that a version of the Beta Services becomes generally available to customers, provided that in the event that the Beta Services are rolled out and become available as a Service under this Agreement, additional terms, conditions, and fees shall apply as provided for in an Order Form.
2.6. Artificial Intelligence Functionality
(a) AI Functionality and Regulatory Classification. The parties acknowledge that certain features of the Services may include AI Functionality to assist with automation, analysis or recommendations. The AI Functionality is designed to support, and not replace, human judgment and shall be used only for the purposes and in the manner described in the Documentation. AI Functionality excludes the Service’s core search, classification and filing functionality. Where generative or agentic features supplement or interact with such core functionality, only those generative or agentic features constitute AI Functionality; their integration does not, of itself, bring the underlying core functionality within this definition. This clause 2.6a) and the definition of AI Functionality is not intended to determine whether any functionality constitutes artificial intelligence under applicable law or limit either party’s obligations under applicable law.
The Supplier does not intend or authorise the AI Functionality to be used for any practice prohibited under, or for any use classified as high-risk under, Regulation (EU) 2024/1689 (the “EU AI Act”).
The regulatory classification of the AI Functionality and the obligations applicable to each party shall be determined by reference to its intended purpose, functionality and actual context of use. The Supplier shall comply with the obligations applicable to it in its capacity as provider of the AI Functionality, and the Customer shall comply with the obligations applicable to it in its capacity as deployer.
The Customer shall not modify the AI Functionality, materially change its intended purpose, or use it in a manner that would cause it to become a prohibited or high-risk AI system without the Supplier’s prior written agreement.
If the AI Functionality becomes subject to additional registration, conformity-assessment, transparency, CE-marking or other regulatory requirements because of a change in applicable law, regulatory guidance, the AI Functionality or its intended use, the Supplier may implement such modifications, safeguards or usage restrictions as are reasonably necessary to ensure compliance. The Supplier shall give the Customer reasonable notice of any resulting material change to the AI Functionality.
(b) Transparency. Supplier shall make available a general description of the AI Functionality sufficient to enable the Customer to understand its purpose, the main parameters influencing its operation, and any significant limitations.
The Customer acknowledges that AI Functionality is an integral part of the Services and that the Services are not offered without it, and that AI Functionality produces outputs generated from statistical patterns in data which may not always be accurate, complete or suitable for reliance without human review.
Where the Services provide administrative controls to disable a particular AI feature, the Customer may use those controls, and Supplier shall not process Customer Data through that feature while it remains disabled by the Customer. Supplier does not undertake to make the Services, or any feature of them, available without AI Functionality. The Customer acknowledges that disabling a feature may limit or disable certain functionality or performance elements of the Services, that Supplier shall not be liable for any resulting reduction in functionality, and that disabling a feature does not relieve the Customer of any payment obligations under the Agreement unless expressly stated otherwise in the Order Form
(c) Human Oversight. The AI Functionality is designed to support, not replace, human judgment. The Customer shall ensure that appropriately qualified personnel review, interpret, and validate any AI-Generated Content before relying upon them for any decision or action that may have legal, financial, or operational effect.
(d) Permitted Use and Compliance. The Customer shall not use the AI Functionality:
(i) to make decisions that produce legal or similarly significant effects on individuals;
(ii) in any context classified as “prohibited” or “high-risk” under the EU AI Act or other equivalent legislation;
(iii) ) for any unlawful, discriminatory, or infringing purpose;
(iv) to train, develop, or improve other AI models or datasets; or
(v) in breach of applicable law, regulation, or data-protection requirements.
The Customer remains solely responsible for ensuring that its use of the AI Functionality complies with all applicable laws and maintains adequate human oversight.
(e) Data and Model Improvement. Unless agreed between the parties in writing, Supplier shall not use, or permit any third party to use, Customer Data, including prompts, inputs, uploaded files, metadata or AI-Generated Content derived from Customer Data, to train, retrain, fine-tune, develop or improve any artificial-intelligence or machine-learning model. Supplier may use de-identified and aggregated operational telemetry that cannot identify the Customer or reveal or enable reconstruction of Customer Data solely to monitor the security, reliability, usage and performance of the Services, but not for model training. Subject to the Customer’s written authorisation, neither Supplier nor any of its service providers shall use Customer Data or AI-Generated Content to train, retrain, fine-tune, develop or improve any model that is made available to, produces outputs for, or otherwise serves any other customer or third party. Except as directed by Customer or its Users through the sharing features of the Services, Supplier shall not disclose, reproduce, retrieve, include or otherwise surface any Customer Data or Customer proprietary content, in whole or in part, in any output, response, service or functionality made available to another customer or third party. Supplier shall maintain appropriate technical and organisational safeguards to segregate Customer Data and prevent cross-customer disclosure
(f) Disclaimer and Limitation. The AI Functionality is provided “as is”. Supplier does not warrant that AI-Generated Content will be accurate, reliable, unbiased, or fit for any particular purpose. To the fullest extent permitted by law, Supplier shall have no liability for any loss or damage arising from the Customer’s reliance on or use of AI-generated outputs, except to the extent caused by Supplier’s willful misconduct or fraud.
(g) Modifications. Supplier may modify, update, or discontinue any AI Functionality where reasonably necessary to maintain security, accuracy, or compliance with applicable law. Supplier shall provide reasonable notice to the Customer of any change that materially affects the performance or behaviour of the AI Functionality.
(h) AI-Generated Content.
(i) Ownership of Outputs – As between the parties, the Customer owns all rights, title, and interest in any AI-Generated Content, subject to Supplier’s rights in the AI Functionality and its underlying technology. Supplier retains all rights, title and interest in and to the algorithms, models, software, and system logic that produce such outputs.
(ii) Licence to Supplier – The Customer grants Supplier a non-exclusive, royalty-free licence to use AI-Generated Content solely to the extent necessary to generate, deliver, secure, troubleshoot and support that AI-Generated Content and the AI Functionality for the Customer. This licence does not permit Supplier or any third party to use AI-Generated Content to train, retrain, fine-tune, develop or improve any artificial-intelligence or machine-learning model, to provide any benefit to another customer, or to disclose or surface the AI-Generated Content to another customer or third party except as directed by Customer or its Users through the sharing features of the Services or as expressly authorised by the Customer in writing.
(iii) Restrictions and Responsibility – The Customer is responsible for reviewing AI-Generated Content before relying upon it and for ensuring that its use, publication, or distribution of such content complies with applicable law (including data-protection, IP, and publicity rights). Supplier does not guarantee that AI-Generated Content will be free from infringement of third-party rights or that it will achieve any particular result.
(i) Authorised Service Providers: Supplier may permit third parties with whom the Supplier has entered a commercial arrangement to deliver services to or on behalf of the Supplier (each an ‘Authorised Service Provider’) to access and process Customer Data solely to the minimum extent necessary to provide the services allocated to that Authorised Service Provider in the applicable Order Form, Statement of Work, Data Processing Addendum or subprocessor list, including the AI Functionality. Each Authorised Service Provider shall: (a) process Customer Data only on Supplier’s documented instructions; (b) use Customer Data only for the relevant Customer and not for its own purposes; (c) not use Customer Data or AI-Generated Content to train, fine-tune, develop or improve any AI or machine-learning model except to the extent expressly authorised by the Customer in writing and then only in accordance with Supplier's documented instructions; (d) not disclose Customer Data to another person except as expressly permitted under the Data Processing Addendum or as directed by Customer or its Users through the sharing features of the Services; (e) maintain appropriate confidentiality, security, segregation, retention and deletion controls; and (f) return or delete Customer Data when its access is no longer required. Supplier shall remain responsible under the Agreement for each Authorised Service Provider’s processing of Customer Data. Except for access by the Authorised Service Providers expressly permitted under this clause i) Supplier shall not sell, license, disclose, transfer or otherwise make Customer Data available to any third party, except as directed by Customer or its Users through the sharing features of the Services or as expressly authorised by the Customer in writing or required by applicable law. Supplier shall not permit any Authorised Service Provider to use Customer Data for its own purposes or for the benefit of any person other than Customer.
(j) On Premise to Cloud Migration: The terms of this clause 2.6 shall apply to all access to and processing of Customer Data in connection with any on-premise to cloud migration performed by or on behalf of Supplier (‘Cloud Migration’), including extraction, copying, transfer, staging, transformation, testing, validation, hosting, support and post-migration deletion. Cloud Migration does not grant Supplier or any Authorised Service Provider any additional right to use Customer Data. All Customer Data processed during Cloud Migration shall remain subject to the Agreement and the Data Processing Addendum
2.7. Updates, Upgrades and New Releases
2.7.1. General
Supplier may develop, release and make available Updates and Upgrades from time to time in accordance with its product roadmap and support policies.
Nothing in this Agreement shall obligate Supplier to develop any particular Update, Upgrade, functionality or feature.
2.7.2. SaaS Deployments
Where the applicable Order Form specifies a SaaS Deployment:
(a) Supplier may deploy Updates to the Hosted Services automatically;
(b) Customer acknowledges that Updates may modify functionality, user interfaces, workflows, reports or features, provided that Supplier shall not materially reduce the core functionality of the Hosted Services during the applicable Subscription Term;
(c) Supplier may deploy security patches, vulnerability fixes and other critical Updates immediately where reasonably necessary to protect the security, integrity or availability of the Hosted Services;
(d) Supplier shall use reasonable endeavours to provide advance notice of any material Upgrade that may significantly affect Customer's use of the Hosted Services; and
(e) all Updates made available by Supplier during the Subscription Term shall form part of the Services and shall be subject to this Agreement.
2.7.3. On-Premise Deployments
Where the applicable Order Form specifies an On-Premise Deployment:
(a) Supplier shall make available to Customer those Updates and Upgrades included within the support and maintenance services purchased under the applicable Order Form;
(b) Customer shall be responsible for installing, deploying and implementing Updates and Upgrades unless Supplier has agreed in writing to provide implementation services;
(c) Supplier shall not be responsible for any failure of the Software resulting from Customer's failure to install recommended security Updates within a reasonable period after release;
(d) Supplier may require Customer to install specified Updates as a condition of receiving support where such Updates address security vulnerabilities, legal compliance requirements or material defects; and
(e) all Updates and Upgrades provided under this Agreement shall be deemed part of the Software and licensed subject to the terms of this Agreement.
2.7.4. Exclusions
Unless expressly stated in an Order Form:
(a) new products;
(b) separately licensed modules;
(c) third-party software;
(d) professional services; and
(e) custom developments created specifically for Customer,
shall not be included within any entitlement to Updates or Upgrades.
2.7.5. Support Lifecycle
Supplier shall continue to support only the then-current Major Version and at least one immediately preceding supported version unless otherwise specified in the Support Policies.
2.7.6. Compatibility
Supplier shall not be responsible for any incompatibility arising from:
(a) modifications made by Customer or any third party;
(b) Customer's failure to install supported Updates;
(c) unsupported operating systems, databases, infrastructure or third-party software; or
(d) use of the Software or Services other than in accordance with the Documentation.
2.7.7. Reservation of Rights
Supplier reserves the right to modify, enhance, replace or discontinue features, functionality or components of the Software or Services, provided that Supplier shall not materially diminish the overall functionality purchased by Customer during the applicable Subscription Term or Licence Term.
2.8. Delivery and Installation (On-Premise Deployments)
2.8.1. Application
This clause applies only where the applicable Order Form specifies an On-Premise Deployment.
2.8.2. Delivery
Supplier shall deliver the Software and Documentation by electronic download or such other delivery method as specified in the applicable Order Form.
Delivery shall occur when Supplier makes the Software, together with any applicable licence keys, activation credentials or other information necessary to install and use the Software, available to Customer.
2.8.3. Installation
Unless otherwise expressly stated in the applicable Order Form:
(a) Customer shall be responsible for installing, configuring and deploying the Software within its own environment in accordance with the Documentation;
(b) where Supplier has agreed to provide installation, implementation or configuration services, such services shall be provided in accordance with the applicable Order Form or any agreed Statement of Work; and
(c) Customer shall provide all reasonable cooperation, access, personnel and technical information reasonably required for Supplier to perform any agreed installation or implementation services.
Supplier shall not be responsible for delays arising from Customer's failure to satisfy its obligations under this clause.
2.8.4. Acceptance
The Software shall be deemed accepted immediately upon Delivery.
Customer acknowledges that the Software is a standard commercial off-the-shelf product and that no acceptance testing or acceptance procedure shall apply unless the Parties expressly agree otherwise in the applicable Order Form or a Statement of Work.
Customer's use of the Software following Delivery shall constitute acceptance of the Software for the purposes of this Agreement.
2.8.5. Defects
Acceptance of the Software shall not limit or affect Customer's rights under the warranties expressly provided in this Agreement or any support and maintenance services purchased under the applicable Order Form.
2.9. Hosting Locations and Changes
Supplier may host and process Customer Content using its own infrastructure or third-party hosting providers. Unless a specific hosting location is expressly agreed in the Order Form or Data Processing Addendum, Supplier may change its hosting provider and hosting locations from time to time, including by migrating the Services to another cloud platform, provided that the change does not materially reduce the security or functionality of the Services and complies with the Data Processing Addendum and applicable Data Protection Laws.
Supplier shall give Customer at least 30 days’ prior notice of any change of hosting provider or migration of Customer Content to a different country, by email or through its Trust Centre or an in-product notification. Where a change is urgently required for security reasons or to comply with applicable law, Supplier may give shorter notice and shall notify Customer as soon as reasonably practicable. Any agreed data residency restrictions, requirements governing international transfers of Personal Data, and rights relating to the appointment or replacement of subprocessors shall continue to apply in accordance with the Data Processing Addendum.
3. Term and Termination
3.1. Agreement Term
This Agreement shall commence on the Effective Date and shall remain in force until terminated in accordance with its terms.
Unless otherwise terminated in accordance with this Agreement, this Agreement shall continue for so long as any Order Form, Subscription Term, Licence Term, support service or maintenance service remains in effect.
3.2. SaaS Deployments
Where the applicable Order Form specifies a SaaS Deployment:
(a) the Subscription Term shall be the period specified in the applicable Order Form;
(b) upon expiry of the Subscription Term, the Subscription Term shall automatically renew for successive periods of twelve (12) months (each a "Renewal Term"), unless either Party provides written notice of non-renewal not less than ninety (90) days before the expiry of the then-current Subscription Term;
(c) where the applicable Order Form provides for user-based, consumption-based or usage-based licensing, Supplier may perform an annual true-up to reflect actual usage during the preceding Subscription Term and invoice the Customer for any additional Fees arising from such increased usage; and
(d) any reduction in licensed quantities, Users or usage commitments shall require Supplier's prior written agreement unless otherwise expressly provided in the applicable Order Form.
3.3. On-Premise Subscription Licences
Where the applicable Order Form specifies an On-Premise Deployment on a subscription basis:
(a) the Licence Term shall be the period specified in the applicable Order Form;
(b) Customer's right to use the Software shall continue only during the Licence Term and any Renewal Term;
(c) the Licence Term shall automatically renew for successive periods of twelve (12) months unless either Party gives written notice of non-renewal not less than ninety (90) days before the expiry of the then-current Licence Term;
(d) support and maintenance services shall renew concurrently with the Licence Term unless otherwise stated in the applicable Order Form; and
(e) upon expiry or termination of the Licence Term, Customer shall immediately cease use of the Software and comply with the exit obligations set out in this Agreement
3.4. Termination for Cause.
(a) Either Party may terminate this Agreement, effective upon written notice to the other Party, if the other Party:
(i) materially breaches this Agreement, and such breach is incapable of cure, or with respect to a material breach capable of cure, the other Party does not cure such breach within ten (10) Business Days after receipt of written notice of such breach;
(ii) becomes insolvent or admits its inability to pay its debts generally as they become due;
(iii) becomes subject, voluntarily or involuntarily, to any proceeding under any domestic or foreign bankruptcy or insolvency law;
(iv) makes an assignment for the benefit of creditors; or
(v) has a receiver, trustee, or similar agent appointed with respect to substantially all of its assets or business.
(b) Acceleration of Fees on Termination for Cause: If Supplier terminates this Agreement or any Order Form for cause arising from Customer’s breach, all Fees payable under this Agreement and every Order Form, including all Fees that would have become payable during the remainder of each then-current Subscription Term or other committed term, shall become immediately due and payable, whether or not those Fees have been invoiced. Customer acknowledges that such Fees represent the agreed consideration for its committed term and are not contingent on its continued use of the Services. Termination shall not relieve Customer of its obligation to pay those Fees, and all amounts paid or payable shall be non-cancellable and non-refundable. This clause is without prejudice to Supplier’s other rights and remedies, provided that Supplier shall not recover more than once in respect of the same loss or payment obligation. For the avoidance of doubt, the accelerated Fees do not include fees attributable solely to an unexercised renewal term or optional services not ordered by Customer.
3.5. Effects of Termination.
3.5.1. General
Upon expiry or termination of this Agreement or any Order Form:
(a) all accrued rights and liabilities of the Parties shall remain unaffected;
(b) Customer shall pay all Fees and other amounts properly due and payable up to the effective date of expiry or termination; and
(c) those provisions which are expressly or by implication intended to survive expiry or termination shall continue in full force and effect.
3.5.2. SaaS Deployments
Where the applicable Order Form specifies a SaaS Deployment:
(a) Customer's right to access and use the Hosted Services shall automatically cease on the effective date of expiry or termination of the applicable Subscription Term unless otherwise expressly agreed by the Parties;
(b) Following expiration or termination of the applicable Services, Supplier shall, for 30 days, make Customer Content available for retrieval by Customer in a reasonably accessible format, subject to applicable law. Customer is responsible for retrieving its Customer Content within that period. Any additional migration or extraction assistance shall be subject to separate agreement and applicable charges. Subject to any earlier return or deletion required under the Data Processing Addendum, Supplier shall delete Customer Content from its active systems within 90 days after the end of that retrieval period. Supplier may retain:
(i) copies contained in backups or disaster recovery systems until overwritten or deleted in accordance with its ordinary backup retention cycle; and
(ii) Customer Content to the extent and for so long as retention is required by applicable law or a binding legal preservation obligation.
Any retained Customer Content shall remain subject to the confidentiality and security obligations under this Agreement and the Data Processing Addendum, shall be isolated from ordinary operational use, and shall be processed only for the purpose justifying its retention. If a backup is restored, Supplier shall reapply the relevant deletion requirements. Supplier shall delete retained Customer Content when the applicable retention period or obligation ends and, upon Customer’s written request, confirm completion of deletion, identifying any permitted retention that remains outstanding.
To the extent Customer Content contains Personal Data, its return, deletion and retention shall be governed by the Data Processing Addendum, which shall prevail in the event of any conflict.
(c Customer acknowledges that, following deletion of Customer Data in accordance with this clause, such data may not be capable of recovery.
3.5.3. On-Premise Subscription Licence
Where the applicable Order Form specifies an On-Premise Deployment on a subscription basis:
(a) Customer's licence to use the Software shall terminate immediately upon expiry or termination of the applicable Licence Term;
(b) Customer shall immediately cease all use of the Software;
(c) Customer shall uninstall and permanently remove the Software from all servers, virtual machines, devices, environments and backup systems under its control, except to the extent retention is required by applicable law;
(d) Customer shall destroy or permanently delete all copies of the Software and Documentation in its possession or control, except one archival copy retained solely for legal or regulatory compliance purposes; and
(e) upon Supplier's written request, Customer shall provide written certification signed by an authorised officer confirming compliance with this clause.
4. Fees and Payment
4.1. Fees
(a) The fees payable by the Customer to the Supplier for the Services shall be set forth in the applicable Order Form.
(b) The Supplier may increase the fees annually upon written notice to the Customer, provided that such increase shall not exceed 10%.
(c) All Fees paid or payable under this Agreement are non-refundable and non-creditable, except as expressly set forth in this Agreement. Services must be used within the applicable Subscription Term. Upon expiration or termination of the Subscription Term, Supplier shall have no obligation to provide, and the Customer shall have no right to access or use, any unused Services. No refund, credit, or extension shall be provided for Services not used within the Subscription Term
4.2. Payment Terms
(a) The Customer shall pay all undisputed invoices within 30 days of the invoice date.
(b) Payments shall be made in the currency stated on the Order Form by wire transfer or other method agreed upon by the Parties.
(c) If the Customer disputes any portion of an invoice, it shall notify the Supplier in writing within 15 days of receipt of the invoice, identifying the reason for the dispute and the amount being disputed. The undisputed portion of the invoice shall be paid in accordance with Section 4.2(a)
4.3. Invoicing
(a) The Supplier shall invoice the Customer for the full Fees due for the applicable Subscription Term, licence Term, Order Form, or Statement of Work upon signature, regardless of when the Term commences, unless otherwise specified in the applicable Order Form. Renewal Terms shall be invoiced in full at or before commencement.
(b) Invoices shall include a detailed breakdown of the Services provided, the applicable fees, and any additional information reasonably required to enable the Customer identify the Services to which the invoice applies.
4.4. Taxes and Expenses
(a) All fees are exclusive of any applicable taxes, which shall be paid by the Customer.
(b) The Supplier shall be entitled to reimbursement for reasonable out-of-pocket expenses incurred in providing the Services, subject to the Customer's prior written approval, such approval not to be unreasonably withheld or delayed.
4.5. Late Payment
(a) The Supplier may charge interest on any undisputed amount not paid by its due date, accruing daily from the due date until payment in full, whether before or after judgment, at an annual rate of four (4) percentage points above the applicable reference rate, subject to the maximum rate permitted by applicable law. The reference rate shall be determined by the currency of the overdue invoice as follows: (a) for GBP, the Bank of England Bank Rate; (b) for EUR, the European Central Bank’s main refinancing operations rate; (c) for USD, the effective federal funds rate published by the Federal Reserve Bank of New York; and (d) for any other currency, the principal monetary policy rate published by the central bank responsible for that currency. The reference rate shall apply as varied from time to time and shall be deemed to be zero if negative. If a reference rate is discontinued, its officially designated successor shall apply or, if none exists, the Supplier may specify a reasonably comparable replacement by written notice to the Customer.
4.6. Records
(a) The Supplier shall maintain complete and accurate records relating to the Services and the fees charged under this Agreement.
5. Intellectual Property Rights
5.1. Ownership of Pre-existing IPR
(a) Except as otherwise provided in this Agreement, as between Supplier and Customer, the Services (including without limitation, the Software, Supplier Content (and Updates) and Documentation are and shall remain the property of Supplier.
(b) Subject to the foregoing, each Party shall retain all right, title, and interest in and to its respective Pre-existing IPR. "Pre-existing IPR" means any Intellectual Property Rights owned or controlled by a Party prior to the Effective Date or developed independently of this Agreement.
(c) No ownership rights in the Software are transferred.
(d) On-Premise Software is licensed, not sold.
5.2. Ownership of Newly Developed IPR
(a) The Supplier shall retain all right, title, and interest in and to any Intellectual Property Rights developed by the Supplier in the course of providing the Services ("Newly Developed IPR").
5.3. Use Rights Granted
5.3.1. Grant of Rights
Subject to the terms of this Agreement, payment of the applicable Fees and the limitations set out in the relevant Order Form, Supplier grants Customer a non-exclusive, non-transferable, non-sublicensable right to use the Software and/or Services during the applicable Term solely for Customer's internal business purposes.
The scope of the rights granted shall depend on the Deployment Model specified in the applicable Order Form.
5.3.2. SaaS Deployment Rights
Where the applicable Order Form specifies a SaaS Deployment, Supplier grants Customer a non-exclusive, non-transferable right, during the Subscription Term, to access and use the Hosted Services and the Software incorporated within those Hosted Services for Customer's internal business operations, subject to any usage limits, User limits, storage limits or other restrictions specified in the Order Form.
Customer shall not:
(a) permit any person other than its Users to access the Hosted Services;
(b) rent, lease, sublicense, sell, distribute, assign, timeshare or otherwise make the Hosted Services available to any third party except as expressly permitted under this Agreement;
(c) attempt to gain unauthorised access to the Hosted Services or related systems or networks;
(d) copy, modify, adapt, reverse engineer, decompile or otherwise attempt to derive the source code of the Software except to the extent such restriction is prohibited by applicable law; or
(e) use the Hosted Services in excess of any usage limitations specified in the applicable Order Form.
5.3.3. On-Premise Deployment Rights
Where the applicable Order Form specifies an On-Premise Deployment, Supplier grants Customer a non-exclusive, non-transferable licence during the applicable licence term specified in the Order Form to install, execute and use the Software in object code form solely for Customer's internal business purposes and subject to the licence metrics, authorised environments and other restrictions specified in the Order Form.
Unless otherwise stated in the Order Form:
(a) the Software may only be installed on the number of servers, virtual machines, instances or environments expressly authorised in the Order Form;
(b) the Software may only be used in production, test, development and disaster recovery environments reasonably required for Customer's internal business operations;
(c) Customer shall not exceed any licensed user, device, project, transaction, processor, server or other usage metric specified in the Order Form;
(d) Customer shall not copy the Software except as reasonably necessary for installation, backup and disaster recovery purposes;
(e) Customer shall not copy, modify, adapt, reverse engineer, decompile or otherwise attempt to derive the source code of the Software except to the extent such restriction is prohibited by applicable law; and
(f) Customer shall not use the Software to provide services to third parties, operate a service bureau, commercial hosting service or outsourcing service without Supplier's prior written consent.
5.3.4. Affiliate Use Rights
Unless expressly prohibited in the applicable Order Form, Customer may permit its Affiliates to use the Software or Services, provided that:
(a) such Affiliates remain an Affiliate of the Customer;
(b) such use is solely for the Affiliates' internal business purposes;
(c) Customer remains responsible for all acts and omissions of its Affiliates; and
(d) any licence metrics, user counts or usage limits shall be aggregated across Customer and its Affiliates unless otherwise stated in the Order Form.
No Affiliate shall acquire any independent rights under this Agreement.
5.3.5. Disaster Recovery Rights
Customer may maintain a reasonable number of backup copies of the Software and may install the Software in a designated disaster recovery environment solely for business continuity purposes.
Except during a genuine disaster recovery event, failover test or planned business continuity exercise, the disaster recovery environment shall not be used concurrently with the production environment if such concurrent use would cause Customer to exceed the licence metrics specified in the applicable Order Form.
Any use of the disaster recovery environment shall remain subject to the restrictions and limitations set out in this Agreement and the applicable Order Form.
5.3.6. Reservation of Rights
Except for the rights expressly granted under this Agreement, Supplier reserves all rights, title and interest in and to the Software, Services, Documentation, Supplier Content and all associated Intellectual Property Rights. No rights are granted by implication, estoppel or otherwise.
5.3.7. Customer Responsibility for Environment
For On-Premise Deployments, Customer shall be solely responsible for providing and maintaining the infrastructure, operating systems, databases, networks, security controls and other technical environments required for operation of the Software, unless Supplier has expressly agreed otherwise in the applicable Order Form.
5.4. Third-Party IPR
(a) Unless otherwise agreed in a Order Form, the Supplier shall obtain all necessary licenses and permissions for the use of any third-party Intellectual Property Rights incorporated into the Software or Services.
(b) The Customer shall obtain all necessary licenses and permissions for the use of any third-party Intellectual Property Rights not incorporated into the Services, but required to enable the Customer to use such Services.
6. Confidentiality
6.1. The Receiving Party shall:
(a) Keep the Confidential Information strictly confidential and not disclose it to any third party without the prior written consent of the Disclosing Party, except as permitted under this Agreement;
(b) Use the Confidential Information solely for the purposes of performing its obligations or exercising its rights under this Agreement;
(c) Protect the Confidential Information with at least the same degree of care as it uses to protect its own confidential information of a similar nature, but no less than a reasonable degree of care; and
(d) Limit access to the Confidential Information to those of its employees, agents, and subcontractors who have a need to know for the purposes of this Agreement and who are bound by written confidentiality obligations no less stringent than those set forth herein.
6.2. The obligations of confidentiality set forth in this Section 6 shall not apply to information that:
(a) Is or becomes publicly available through no fault of the Receiving Party;
(b) Is rightfully received by the Receiving Party from a third party without breach of any confidentiality obligation;
(c) Is independently developed by the Receiving Party without use of or reference to the Confidential Information; or
(d) Is required to be disclosed by law or court order, provided that the Receiving Party gives the Disclosing Party prompt written notice of such requirement and cooperates with the Disclosing Party's efforts to limit or prevent such disclosure.
6.3. Upon the expiration or termination of this Agreement, or upon the Disclosing Party's request, the Receiving Party shall promptly return or destroy (at the Disclosing Party's option) all Confidential Information in its possession or control, including all copies thereof, and provide written certification of such return or destruction. Notwithstanding the foregoing, the Receiving Party may retain Confidential Information to the extent that it: (a) is contained in routine backup or disaster recovery systems and cannot reasonably be selectively deleted, provided that it is deleted or overwritten in accordance with the Receiving Party’s normal retention cycles and is not accessed or used except for recovery purposes; (b) is required to be retained by applicable law, regulation, court order or a legal hold reasonably imposed in connection with actual or anticipated proceedings, for so long as that requirement or hold applies; or (c) is reasonably necessary to continue providing any Services that remain in effect or to perform any agreed transition or exit services, solely for those purposes and for so long as necessary. Any retained Confidential Information shall remain subject to the confidentiality and security obligations under this Agreement and shall be returned or destroyed when the applicable retention exception ceases to apply. Any certification shall identify the categories of Confidential Information retained and the applicable grounds for retention. The retention and deletion of personal data shall remain subject to the applicable Data Processing Addendum and applicable data protection law.
6.4. The Receiving Party acknowledges that any breach of this Section 6 may cause irreparable harm to the Disclosing Party, for which monetary damages may be inadequate. Accordingly, the Disclosing Party shall be entitled to seek injunctive relief or other equitable remedies in addition to any other remedies available at law or in equity.
6.5. The obligations of confidentiality set forth in this Section 6 shall survive the expiration or termination of this Agreement for a period of 5 years, except that those obligations shall continue: (a) for trade secrets, for so long as the relevant information qualifies as a trade secret under applicable law; and (b) for source code and Customer Data, indefinitely, in each case subject to the exclusions in 6.2 above.
6.6. If any Confidential Information constitutes Personal Data (as defined in the Data Protection Laws), the Parties shall comply with the provisions set forth in a relevant Data Processing Addendum.
7. Data Protection and Information Security
7.1. The parties acknowledge that the nature and extent of Supplier's processing of Personal Data may vary depending upon the
Deployment Model and Services purchased. The terms of the relevant Data Processing Addendum, shall apply where applicable.
7.2. General Security Obligations
Each Party shall implement and maintain appropriate technical and organisational measures designed to protect Confidential Information, Personal Data and business systems against unauthorised access, disclosure, alteration, loss, destruction, misuse or other unlawful processing, taking into account the nature of the information, the risks presented and generally accepted industry standards.
Each Party shall maintain policies and procedures appropriate to its role under this Agreement relating to information security, access control, business continuity and incident management.
7.3. SaaS Deployments
Where the applicable Order Form specifies a SaaS Deployment, Supplier shall be responsible for the security, operation and maintenance of the Hosted Services and the infrastructure used to provide them, including:
(a) management and security of the hosting environment;
(b) physical and logical security of Supplier-controlled systems and networks;
(c) implementation of reasonable access-control measures;
(d) monitoring, logging and security management of the Hosted Services;
(e) backup and recovery procedures for Customer Data maintained within the Hosted Services;
(f) deployment of security patches and Updates to the Hosted Services;
(g) malware protection measures within Supplier-controlled environments; and
(h) maintenance of business continuity and disaster recovery procedures appropriate to the Hosted Services.
Customer shall be responsible for:
(i) managing Users and User permissions;
(ii) maintaining the security of User credentials and authentication mechanisms under Customer's control;
(iii) configuring the Hosted Services in accordance with Supplier's Documentation;
(iv) securing Customer devices, networks and systems used to access the Hosted Services; and
(v) ensuring the legality and accuracy of Customer Data uploaded to the Hosted Services.
7.4. On-Premise Deployments
Where the applicable Order Form specifies an On-Premise Deployment, Customer shall be responsible for the operation, security and maintenance of the environment in which the Software is installed and operated, including but not limited to:
(a) servers, virtual machines and infrastructure;
(b) operating systems;
(c) databases;
(d) networks and firewalls;
(e) endpoint protection and anti-malware measures;
(f) identity and access management;
(g) backup and recovery procedures;
(h) disaster recovery arrangements;
(i) physical security of Customer facilities; and
(j) implementation of security patches and Updates made available by Supplier.
Supplier shall be responsible only for:
(k) the security of the Software as supplied by Supplier;
(l) correcting verified security vulnerabilities within supported versions of the Software in accordance with Supplier's support policies; and
(m) providing security-related Updates and patches where available.
Supplier shall have no responsibility for security incidents arising from Customer's infrastructure, systems, configurations, third-party software or failure to implement Updates made available by Supplier.
7.5. Security Incidents
Each Party shall notify the other Party without undue delay upon becoming aware of any actual or reasonably suspected security incident affecting the Software, Services, Customer Data or Confidential Information that may materially impact the other Party.
Each Party shall cooperate reasonably with the other Party in investigating, mitigating and remediating any such security incident.
7.6. Use of Third-Party Service Providers
Supplier may utilise third-party hosting providers, infrastructure providers, subcontractors or service providers in connection with the provision of the Services, provided that Supplier remains responsible for their performance to the extent required under this Agreement.
7.7. No Absolute Security Guarantee
Customer acknowledges that no software, service, network or information system can be guaranteed to be completely secure. Except as expressly provided in this Agreement, Supplier does not warrant that the Software or Services will be free from all vulnerabilities, unauthorised access attempts or security incidents.
7.8. Shared Responsibility Model
The Parties acknowledge that effective information security depends upon the cooperation of both Parties and that responsibility for information security is allocated between the Parties in accordance with the Deployment Model specified in the applicable Order Form.
8. Warranties and Disclaimers
8.1. The Supplier warrants that the Services will be performed in a professional and workmanlike manner, in accordance with generally accepted industry standards and practices, and in compliance with all applicable laws and regulations.
8.2. The Supplier further warrants that the Services provided hereunder will conform in all material respects to the Documentation and neither delivery of the Services nor the Customer’s use of the Services will infringe upon or violate any Intellectual Property Rights of any third party.
8.3. The Supplier warrants that it has used up to date commercially available scanning tools to prevent the introduction of Malicious Code.
8.4. In the event of a breach of the warranties set forth in this Section 8, the Supplier shall, at its own expense and as the Customer's sole and exclusive remedy, use commercially reasonable efforts to re-perform or correct the non-conforming Services, or if such efforts are unsuccessful, refund the Fees paid by the Customer relating only to the non-conforming Services.
8.5. EXCEPT FOR THE EXPRESS WARRANTIES SET FORTH IN THIS SECTION 8, THE SUPPLIER MAKES NO OTHER WARRANTIES, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO ANY IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, OR NON-INFRINGEMENT. THE SUPPLIER DOES NOT WARRANT THAT THE SERVICES WILL BE ERROR-FREE OR UNINTERRUPTED, OR THAT ALL ERRORS WILL BE CORRECTED. THE SUPPLIER'S WARRANTIES ARE SUBJECT TO COMPLIANCE WITH ALL APPLICABLE LAWS AND REGULATIONS, AND THE SUPPLIER DOES NOT WARRANT THAT THE SERVICES WILL COMPLY WITH LAWS OR REGULATIONS IN JURISDICTIONS OTHER THAN THOSE SPECIFIED IN THIS AGREEMENT. THE SUPPLIER SHALL NOT BE LIABLE FOR INFRINGEMENT OF ANY THIRD-PARTY INTELLECTUAL PROPERTY RIGHT CAUSED BY CHANGES MADE TO THE SOFTWARE, SERVICES BY THE CUSTOMER WITHOUT THE SUPPLIER’S PRIOR WRITTEN CONSENT OR DURING ANY UNAUTHORISED USE OR USE OUTSIDE THE SCOPE OF THE LICENCE GRANTED TO THE CUSTOMER UNDER THIS AGREEMENT. THE SUPPLIER MAKES NO WARRANTIES WITH RESPECT TO ANY THIRD-PARTY PRODUCTS OR SERVICES THAT MAY BE USED IN OR IN CONJUNCTION WITH THE SERVICES.
9. Limitation of Liability
9.1. Subject to Clause 9.2, the Supplier's total aggregate liability to the Customer arising out of or in connection with this Agreement, whether in contract, tort (including negligence), breach of statutory duty, or otherwise, shall be limited to 100% of the Fees paid by the Customer to the Supplier in respect of the Service to which the claim relates in the 12-month period immediately preceding the event giving rise to the claim. Neither Party shall be liable to the other Party for any indirect, special, consequential, or punitive damages, including but not limited to loss of profits, business, revenue, goodwill, or anticipated savings, even if such Party has been advised of the possibility of such damages.
9.2. The limitations and exclusions of liability set forth in Clause 9.1 shall not apply to:
(a) Liability arising from death or personal injury caused by the negligence of a Party or its employees, agents, or subcontractors;
(b) Liability arising from fraud or fraudulent misrepresentation;
(c) Any other liability that cannot be limited or excluded by applicable law.
9.3. The Supplier shall maintain appropriate insurance coverage, including but not limited to professional liability and cyber liability insurance, with reputable insurers to cover its potential liabilities under this Agreement.
10. Indemnification
10.1. Indemnification by the Supplier. The Supplier shall indemnify, defend, and hold harmless the Customer, its Affiliates, and their respective officers, directors, employees, and agents (collectively, the "Customer Indemnified Parties") from and against any and all claims, demands, suits, actions, proceedings, losses, liabilities, damages, costs, and expenses (including reasonable attorneys' fees) (collectively, "Claims") arising out of or relating to:
(a) Any actual or alleged infringement or misappropriation of any intellectual property rights by the Supplier or the Services;
(b) Any violation of applicable laws or regulations by the Supplier or its personnel in connection with the performance of the Services.
10.2. Indemnification by the Customer. The Customer shall indemnify, defend, and hold harmless the Supplier, its Affiliates, and their respective officers, directors, employees, and agents (collectively, the "Supplier Indemnified Parties") from and against any and all Claims arising out of or relating to:
(a) Any actual or alleged infringement or misappropriation of any intellectual property rights by the Customer, Customer Data or materials provided by the Customer;
(b) Any violation of applicable laws or regulations by the Customer or its personnel in connection with the receipt of the Services.
10.3. Indemnification Procedures. The indemnified party shall promptly notify the indemnifying party in writing of any Claim for which indemnification is sought, and the indemnifying party shall have the right to control the defense and settlement of such Claim, provided that the indemnifying party shall not settle any Claim without the indemnified party's prior written consent (which shall not be unreasonably withheld, conditioned, or delayed), unless such settlement includes a full and unconditional release of the indemnified party from all liability and does not impose any obligations or restrictions on the indemnified party.
10.4. Exclusions and Limitations. Neither party shall be obligated to indemnify the other party to the extent that the Claim arises from the negligence, willful misconduct, or fraud of the indemnified party or its personnel. In addition, the Supplier shall have no obligation to indemnify the Customer to the extent that a Claim arises from: (a) any modification of the Services made by or on behalf of the Customer without the Supplier’s authorisation; (b) the use of the Services in combination with products or services not supplied or authorised by the Supplier, where the Claim would not have arisen but for that combination; (c) Customer Data; (d) any output generated by AI Functionality; (e) use of the Services other than in accordance with the Documentation; or (f) the Customer’s failure to implement the latest version, update or modification of the Software made available by the Supplier, where implementation would have avoided the alleged infringement, provided that the Supplier notified the Customer of the need to implement it to avoid infringement and afforded the Customer a reasonable opportunity to do so.
10.5. Remedies. If the Services or Software become, or in the Supplier’s reasonable opinion are likely to become, the subject of a Claim alleging infringement of a third party’s intellectual property rights, the Supplier may, at its option and expense: (a) procure for the Customer the right to continue using the affected Services or Software; (b) modify them so that they become non-infringing; or (c) replace them with a non-infringing alternative, provided that any modification or replacement does not materially reduce the affected functionality. If none of these remedies is reasonably practicable, the Supplier may terminate the affected Services or Software subscription on written notice and refund any prepaid fees attributable to the period after termination. The Customer shall cease using the affected Services or Software upon such termination. Any termination under this paragraph shall not affect the Supplier’s indemnification obligations in respect of Claims arising from use before termination, subject to the exclusions and limitations in this Agreement.
10.6. Survival. The indemnification obligations set forth in this Section 10 shall survive the termination or expiration of this Agreement.
11. Force Majeure
11.1. If a Force Majeure Event occurs, the affected Party shall promptly notify the other Party in writing of the nature and expected duration of the Force Majeure Event and shall use reasonable efforts to mitigate the effects of the Force Majeure Event and resume performance as soon as reasonably possible.
11.2. During the continuance of a Force Majeure Event, the affected Party's obligations under this Agreement shall be suspended to the extent that they are affected by the Force Majeure Event, provided that the suspension shall not affect the other Party's obligations, except to the extent that they are dependent on the suspended obligations.
11.3. If a Force Majeure Event continues for a period of three (3) consecutive months, either Party may terminate this Agreement by giving one (1) month’s written notice to the other Party.
11.4. Upon termination of this Agreement due to a Force Majeure Event, the Supplier shall be entitled to payment for Services performed up to the date of termination, and the Parties shall have no further obligations under this Agreement, except for any obligations that expressly survive termination.
11.5. Notwithstanding the foregoing, a Force Majeure Event shall not include financial difficulties, labor disputes involving the affected Party's personnel, or events caused by the affected Party's negligence or willful misconduct.
11.6. Neither Party shall be liable for any delay or failure in performance caused by a Force Majeure Event, provided that the affected Party has complied with its obligations under this Section 11.
12. Suspension of Services
12.1. Where the Software is deployed on the Customer's infrastructure or in an environment not hosted or controlled by the Supplier, the Supplier may, where permitted under this Agreement, suspend the provision of support and maintenance services.
12.2. Where the Software is provided as a SaaS offering, the Supplier may suspend the provision of Services, in whole or in part, upon written notice to the Customer, in the event of:
(a) Non-payment by the Customer of any undisputed invoice within thirty (30) days after the due date;
(b) A material breach by the Customer of any term or condition of this Agreement, which remains uncured for a period of ten (10) Business Days after written notice thereof from the Supplier; or
(c) The Customer's failure to provide the Supplier with necessary information, access, or cooperation required for the Supplier to perform the Services.
(d) An actual or reasonably suspected security incident, vulnerability or threat affecting the Services, Customer Data or the Supplier’s systems, where the Supplier reasonably considers suspension necessary to protect the security, integrity or availability of those Services, data or systems. Where urgent action is required, the Supplier may suspend the affected Services immediately without prior notice, provided that it notifies the Customer as soon as reasonably practicable thereafter. Any suspension under this paragraph shall be limited in scope and duration to what is reasonably necessary to address the relevant risk, and the Supplier shall restore the affected Services as soon as reasonably practicable once that risk has been adequately addressed. Suspension shall not relieve the Supplier of any applicable incident notification or other obligations under this Agreement or the Data Processing Addendum.
12.3. The Supplier's notice of suspension shall specify the grounds for suspension and, in the case of a remediable breach, shall provide the Customer with a reasonable cure period of not less than ten (10) Business Days to remedy the breach or make the required payment.
12.4. If the Customer fails to remedy the breach or make the required payment within the specified cure period, the Supplier may suspend the provision of Services until the breach is remedied or payment is made, without further notice.
12.5. During any period of suspension, the Supplier's obligations to provide the Services shall be suspended, but the Customer's payment obligations for Services rendered prior to the suspension shall remain in effect.
12.6. Upon the Customer's remedy of the breach or payment of outstanding invoices, the Supplier shall promptly resume the provision of Services. The Supplier may charge the Customer a reasonable fee for the resumption of Services, if applicable.
12.7. If the suspension period exceeds ninety (90) days, the Supplier may terminate this Agreement or the affected Statement(s) of Work for cause, without further liability, by providing written notice to the other Party.
12.8. The Supplier shall be indemnified and held harmless by the Customer from and against any claims, losses, or damages arising from the suspension of Services due to the Customer's breach or non-payment, subject to the limitations of liability set forth in this Agreement.
13. Dispute Resolution
13.1. In the event of any dispute arising out of or in connection with this Agreement, the Parties shall first attempt in good faith to resolve the dispute through negotiations between senior representatives of each Party. If the dispute is not resolved within thirty (30) days of written notice of the dispute, either Party may refer the matter to non-binding mediation administered by the American Arbitration Association (AAA) or another mutually agreed mediation provider in the applicable jurisdiction. The mediation shall be conducted in English and each Party shall bear its own costs, with the mediator’s fees shared equally between the Parties.
13.2. If the dispute is not resolved through mediation within sixty (60) days after appointment of the mediator, either Party may commence litigation in the courts defined in 14.9 below and each Party irrevocably submits to the exclusive jurisdiction and venue of such courts.
13.3. Nothing in this clause shall prevent either Party from seeking interim, injunctive or equitable relief in any court of competent jurisdiction.
14. General Provisions
14.1. Assignment and Subcontracting
(a) Save as set out herein and in 14.1(b) below, neither Party shall assign, transfer, charge, or deal in any other manner with this Agreement or any of its rights and obligations under this Agreement without the prior written consent of the other Party, which shall not be unreasonably withheld or delayed, except to a successor in title to all or substantially all of the business of that party or as part of a corporate action, reorganization or restructure.
(b) The Supplier may subcontract the performance of any of its obligations under this Agreement to a third party, provided that the Supplier shall remain fully responsible for the acts and omissions of such third party as if they were its own acts and omissions. This right is subject to any requirements relating to the appointment of subprocessors under the applicable Data Processing Addendum.
14.2. Notices
(a) Any notice or other communication required or permitted under this Agreement shall be in writing and may be delivered personally, sent by pre-paid first-class post, recorded delivery or commercial courier to the relevant Party’s registered office or such other address as that Party designates by written notice, or sent by email. Notices by email to the Supplier shall be sent to notices@newforma.com , and notices by email to the Customer shall be sent to the contact email address specified in the applicable Order Form or otherwise designated by the Customer for contractual notices. Either Party may update its contact details by written notice to the other.
(b) The Supplier may also provide notices concerning the operation, security, support or functionality of the Services, including maintenance, updates and changes to subprocessors, by publication in its Trust Centre at https://trust.newforma.com or through an in-product notification accessible to the Customer’s designated administrator. Notices of breach, suspension, termination or non-renewal, claims under this Agreement, and changes to fees or contractual terms must be delivered personally, by post, courier or email in accordance with this paragraph. Any additional notification requirements under the Data Processing Addendum shall continue to apply.
(c) A notice or communication shall be deemed received: (i) if delivered personally, when left at the relevant address; (ii) if sent by pre-paid first-class post or recorded delivery, at 9.00 am on the second Business Day after posting; (iii) if sent by commercial courier, when delivery is recorded by the courier; (iv) if sent by email, at the time of transmission, provided that the sender does not receive an automated delivery failure notification; or (v) if provided through the Trust Centre or an in-product notification, when made available through that channel. If receipt would otherwise occur outside 9.00 am to 5.00 pm on a Business Day at the recipient’s location, the notice shall be deemed received at 9.00 am on the next Business Day at that location. The Customer shall keep its contact details current and ensure that its designated administrators monitor the applicable notification channels.
(d) This clause does not apply to the service of legal proceedings or other documents in any legal action.
14.3. Audit
Supplier may audit Customer's compliance with licence metrics upon reasonable notice no more than once annually.
14.4. Entire Agreement and Amendments
(a) This Agreement, including any Order Forms, Schedules, Statements of Work and Data Processing Addendum constitutes the entire agreement between the Parties and supersedes and extinguishes all previous agreements, promises, assurances, warranties, representations, and understandings between them, whether written or oral, relating to its subject matter.
(b) No variation of this Agreement shall be effective unless it is in writing and signed by the Parties or their authorized representatives.
14.5. Severability
If any provision or part-provision of this Agreement is or becomes invalid, illegal, or unenforceable, it shall be deemed modified to the minimum extent necessary to make it valid, legal, and enforceable. If such modification is not possible, the relevant provision or part-provision shall be deemed deleted. Any modification to or deletion of a provision or part-provision under this clause shall not affect the validity and enforceability of the rest of this Agreement.
14.6. Waiver
No failure or delay by a Party to exercise any right or remedy provided under this Agreement or by law shall constitute a waiver of that or any other right or remedy, nor shall it prevent or restrict the further exercise of that or any other right or remedy. No single or partial exercise of such right or remedy shall prevent or restrict the further exercise of that or any other right or remedy.
14.7. Relationship of the Parties
Nothing in this Agreement is intended to, or shall be deemed to, establish any partnership or joint venture between the Parties, constitute either Party the agent of the other, or authorize either Party to make or enter into any commitments for or on behalf of the other Party.
14.8. Survival
Any provision of this Agreement that expressly or by implication is intended to come into or continue in force on or after termination or expiry of this Agreement shall remain in full force and effect.
14.9. Governing Law and Jurisdiction
This Agreement and any dispute or claim arising out of or in connection with it, its subject matter or formation (including any non-contractual disputes or claims) shall be governed by and construed in accordance with the laws of the jurisdiction of the Supplier entity specified in the Order Form. Each Party irrevocably submits to the exclusive jurisdiction of the courts of that jurisdiction to settle any dispute or claim arising out of or in connection with this Agreement, its subject matter or formation (including any non-contractual disputes or claims).
14.10 Embargoed Countries. The Customer shall not access, use, export, re-export, distribute or otherwise make available the Services, directly or indirectly, to any person or entity located in, ordinarily resident in, or organised under the laws of any country or territory that is subject to comprehensive trade sanctions or embargoes imposed by the United Kingdom, United States, Canada, European Union or other applicable governmental authority (“Embargoed Countries”), or to any person or entity appearing on any applicable restricted or denied party list. The Customer represents and warrants that neither it nor any of its Users are located in, under the control of, or acting on behalf of any such person, entity or jurisdiction. The Supplier may suspend or terminate access to the Services immediately if it reasonably believes a breach of this clause has occurred.
14.11 Compliance with US Export Regulations. The Customer shall comply with all applicable export control and economic sanctions laws and regulations of the United States and any other applicable jurisdiction in connection with its access to and use of the Services, including the US Export Administration Regulations (EAR) and regulations administered by the US Department of the Treasury’s Office of Foreign Assets Control (OFAC). The Customer shall not, directly or indirectly, export, re-export, transfer, provide access to or otherwise make available the Services or any related technical data in violation of such laws or regulations, including to any prohibited jurisdiction, entity or individual. The Customer represents and warrants that it is not named on, or owned or controlled by any person or entity named on, any US government restricted party list. The Supplier may suspend or terminate access to the Services immediately if it reasonably believes a breach of this clause has occurred.
14.12. Counterparts
This Agreement may be executed in any number of counterparts, each of which when executed and delivered shall constitute a duplicate original, but all the counterparts shall together constitute one agreement.
14.13. Third-Party Rights
A person who is not a Party to this Agreement shall not have any rights to enforce any term of this Agreement.
14.14. Ethical Conduct
Each Party shall, and shall ensure that its employees, agents, and subcontractors shall, comply with all applicable laws, regulations, and general ethical standards in their performance under this Agreement, including but not limited to anti-bribery and anti-corruption laws, data protection laws, and laws relating to human rights and modern slavery.