Powering meetings at flagship Hyve events Find out what's involved

Terms & Conditions – Enterprise

Last updated: 1 July 2026

Table of contents

  1. Customer Support (Enterprise Full Service)
  2. Security and GDPR
  3. Insurance
  4. Terms and Conditions
    1. Background
    2. Agreed Terms
      1. Definitions
      2. Licence Acceptance
      3. Licence
      4. External Interfaces
      5. Services
      6. Finance and revenue
      7. Organiser Account
      8. Intellectual Proprietary Rights
      9. Restrictions
      10. Confidentiality and Publicity
      11. Data Protection
      12. Warranties
      13. Term and Termination
      14. Limitation of Liability
      15. General
      16. ExpoPlatform Code of Conduct Statement
      17. Use of Optional Platform Features
  5. Appendix I. ExpoPlatform Data Protection Addendum
    1. Personal data/Processor
    2. Platform Usage data
    3. European union standart contractual clauses for restricted data transfers
      1. Section I
      2. Section II
      3. Section III
      4. Section IV

1. Customer Support (Enterprise Full Service)

The key phases for launch are below and we will assign a Technical Account Manager who will be responsible for onboarding you and supporting you throughout each phase of  the project and will be reviewing and monitoring the progress and delivery.

The key phases of the project delivery are:

  • Definition of the Requirements
  • Platform Configuration
  • Planning  of the Delivery Schedule (organiser launch, public launch, launch stages and functionality)
  • Testing and Readiness Assessment
  • Public Launch
  • Analysis and Review

During the set-up and training phase the Organiser will be trained on use of the purchased system modules as defined in Your Agreement and will also be provided with reference materials and guides

Details of included support are as follows:

Set-Up SupportThe EP team will complete the initial set up which includes:

  • Home page template populated with the content you provide
  • Website wireframe set up
  • Platform settings configured according to your requirements
  • Initial data import
  • Initial sponsorship set up
  • Mobile app set up (if applicable)

After training has been completed and the visitor launch has taken place, the site will be deemed to have been handed over with your team then taking ownership of the website and ongoing site updates and the Technical Account Manager supporting you as needed

Project ManagementA Technical Account Manager will be assigned to your account and will lead your implementation.

Email access and 1 project call per week, leading up to the event, are included.

One set of platform trainings included (can be recorded to share with other team members)

Event Days SupportUp to 3 days of real-time support during event days via Discord (or via EP staff onsite at the event if contracted in advance)
Ongoing SupportOngoing access to the Technical Account Manager managing your account via email

The site will be shutdown 2 weeks post-contract date and all integrations will be disabled unless other arrangements are made in advance. The mobile app will be removed from app stores 1 month post-event unless other arrangements are made in advance however where a container app is being used, the container app will remain in the app stores through the life of the contract.

2. Security and GDPR

ExpoPlatform fully complies with GDPR regulations and is sufficiently flexible to allow the organiser to handle the GDPR requirements correctly for their specific event needs.

Users are able to opt out of networking during sign-up, and at any point later from within their profile. These consents (consent and withdrawal of consent) are recorded explicitly with a date/time stamp. An organiser is able to extract all data relating to a user or data subject by downloading a report from the entire instance of a user’s profile. This includes: visitor profile; threads and messages they started, commented on or are mentioned in; recorded exhibitor interactions the user may have had.  Profiles can also be permanently deleted along with the user’s personal details.

In keeping up with the latest security standards, our platform uses SSL encryption whenever possible, and supports the custom installation of SSL certificates for client domains. We use a combination of open-source and proprietary technologies hosted on one of the most secure operating systems in the world – Linux. Our servers are provisioned by Amazon Web Services with a proven track record and a guarantee of 99.99% uptime on instances.

‌We have also undergone extensive penetration tests with clients such as Accenture and CNH Industrial, and adhere to the most stringent corporate security criteria. We constantly review our security policy and measures that are in place, and release security patches for our system as needed without disruption to our clients and their events.

3. Insurance

We current have the following levels of insurance cover:

PolicyCoverInsurer
Professional Indemnity£3,000,000‌ESNO040410011
Employer’s liability cover‌£10,000,000‌ESNO040410011
Public liability cover‌£1,000,000‌ESNO040410011
Cyberinsurance£3,000,000ESNO040410011

4. Terms and Conditions

4.1. Background

The Parties hereby agree that the Provider shall supply the Organiser with website hosting and related services on the terms and conditions set out in this Agreement.

The Provider shall license use of the Platform and Documents to you on the basis of this Licence. The Provider shall not sell the Platform or Documents to you. At all times, the Provider remains the owner of the Platform and Documents.

You are licensed to use the Platform only if you accept all of the terms and conditions set out below.

4.2. AGREED TERMS

4.2.1. Definitions

The following definitions apply in this Agreement:

  • Account: means the account with the Organiser;
  • Affiliate: any entity that Controls, is Controlled by, or is under common Control with, a Party;
  • Applicable law: means applicable laws, statutes, directives, regulations or any other legislation, codes of practice or regulatory rules in force during the term of this agreement in England and Wales, or in any other applicable legal jurisdiction;
  • Change of Control: any transaction or series of transactions resulting in a change in Control of a Party, including a change in the legal or beneficial ownership of more than 50% of its voting shares, a merger, consolidation or scheme of arrangement, or a sale or transfer of all or substantially all of its assets or business;
  • Control: has the meaning given in section 1124 of the Corporation Tax Act 2010;
  • Confidential Information: any and all information, whether technical or commercial (including all specifications, drawings and designs within the exhibition web platform) disclosed in writing, on disc, orally or by inspection of documents or during the course of the performance of this Agreement between the Parties, where the information is:(a) identified as confidential at the time of disclosure; or(b) proprietary in nature or is, or ought reasonably to be considered confidential given the nature of the information or the circumstances of disclosure.

    For the avoidance of doubt, the Platform content, the Platform software and Documentation which exist prior to the Effective Date shall be deemed to be Confidential Information belonging to the Provider.

  • Customer Data: the data inputted by the Permitted Users, or the Organiser on the Permitted User’s behalf for the purpose of using the Platform or facilitating the Permitted User’s use of the Platform.
  • Data Protection Legislation: unless and until the General Data Protection Regulation ((EU) 2016/679) (GDPR) is no longer directly applicable in the UK, the GDPR and any national implementing laws, regulations and secondary legislation, as amended or updated from time to time, in the UK; and then any successor legislation to the GDPR or the Data Protection Act 2018.
  • Delegate: any person that participates in an Event and is thereby a customer of the Organiser and a visitor to the Platform.
  • Documentation: any written, explanatory materials provided to the Organiser by the Provider in connection with this Agreement and relating to the operation or use of the Platform software, and any copies thereof, including, but not limited to all documentation available at: http://help.expoplatform.com/
  • Effective Date: Date contract was signed. Please refer to the order form.
  • Events: All events organised by Organiser for which the Platform is or will be deployed.
  • Exhibitor: Any company that participates in an Event as a sponsor or an exhibitor, and is thereby a client of the Organiser and an exhibitor on the Platform.
  • Intellectual Property Rights: patents, utility models, rights to inventions, copyright and neighbouring and related rights, moral rights, trademarks and service marks, business names and domain names, rights in get-up and trade dress, goodwill and the right to sue for passing off or unfair competition, rights in designs, rights in computer software, database rights, rights to use, and protect the confidentiality of, confidential information (including know-how and trade secrets) and all other intellectual property rights, in each case whether registered or unregistered and including all applications and rights to apply for and be granted, renewals or extensions of, and rights to claim priority from, such rights and all similar or equivalent rights or forms of protection which subsist or will subsist now or in the future in any part of the world.
  • Materials: the content provided to the Provider by the Organiser from time to time for incorporation in the Platform.
  • Platform Specification: the specification for the Platform referred to in clause 2.
  • Project: means all processes involved in the completion of the Platform.
  • Project Plan: the timetable for setting up the Platform and performing the Services.
  • Permitted User: the Organiser’s employees, agents and independent contractors, Delegates or Exhibitors who are authorised by the Organiser to use the Platform and the Documentation.
  • Platform: the website and/or networking platform provided to the Organiser by the Provider for use on relevant Events. The platform is to be hosted by the Provider pursuant to this Agreement including the web portal and any mobile applications deployed by the Provider for the Organiser.
  • Registration: any person that registers for an Event and is thereby a client of the Organiser and a visitor to the Platform.
  • Services: the hosting and related services to be provided pursuant to this Agreement as described in clause 5.
  • Scope of Services: hosting and related services to be provided pursuant to this Agreement as described in the BUDGET & SCOPE section of the proposal which defines the Initial Order order, and the services described in any supplementary order forms which defines Additional Orders (see Appendix II for template).

4.2.2. Licence Acceptance

By signing this Agreement, you indicate your acceptance of this Licence Agreement and the limited warranty and limitation of liability set out in herein.  Such acceptance is either on your own behalf or on behalf of any corporate entity which employs you or which you represent (a “Corporate Licensee”). In this Licence Agreement, “you” includes both the reader and any Corporate Licensee.

4.2.3. Licence

4.2.3.1. Subject to the terms and conditions of this Agreement, the Provider hereby grants the Organiser a non-exclusive, limited, non-sub-licensable, non-transferable and revocable license, to:

4.2.3.1.1. remotely access (i.e. on a SaaS basis) the Platform and use it for internal business purposes, using your own network and systems; and

4.2.3.1.2. use the Documentation for your internal business purposes.

4.2.3.2. The Organiser may only use the Platform in accordance with the Documentation, subject to the use limitations indicated in this Agreement and in accordance with Applicable Laws. Nothing herein shall prevent, nor be deemed as preventing the Organiser from negotiating and/or entering into agreements with third parties with respect to the subject matter of this Agreement.

4.2.4. External Interfaces

4.2.4.1. The Organiser acknowledges that in order to utilise the Platform according to the Organiser’s requirements, the Platform will interface with external programs which are not distributed by the Provider as part of the licence (“External Programs”).

4.2.4.2. The Organiser hereby represents and warrants that it has obtained all the required rights and authorisations from the owners and/or licensors of the External Programs to interface the Platform with the External Programs and that such interface does not constitute an infringement of any right of a third party. The Organiser hereby agrees to defend, indemnify and hold harmless the Provider from all damages, liabilities, costs, and expenses (including attorney’s fees) arising from claims or allegations related to or in connection with use of the External Programs including but not limited to the Organiser’s failure to comply with the aforesaid requirements.

4.2.4.3. The Organiser acknowledges that its use of the Platform will be web-based and only (except for cases where specific mobile applications are provided by Provider) for all Permitted Users, using the Organiser’s hardware, software and communication systems.

4.2.5. Services

The Provider shall provide the Services, as set out in the Initial Order and any Additional Orders, by deploying, hosting, and providing to the Organiser technical support as is reasonably required by the Organiser for the Platform.

4.2.6. Finance and revenue

4.2.6.1. In consideration of payment by the Organiser of the agreed licence fee and the Organiser agreeing to abide by the terms of this Licence Agreement, the Provider hereby grants to the Organiser a non-exclusive, non-transferable licence as set out in clause 3 to use the Platform and the Documentation.

4.2.6.2. The Organiser agrees that any additional work performed by the Provider upon the Organiser’s written request shall be mutually agreed in writing and billed for separately.

4.2.6.3. The credit note may be used solely as a set-off against payments due for future services provided by the Provider. Any credit note issued by the Provider to the Organiser shall not constitute an obligation of the Provider to make any cash payment.

4.2.6.4. All invoices shall be due within 14 days of issue. All late payments shall incur daily interest at 8% above the base rate of the Bank of England. The Provider reserves the right to suspend provision of services when any invoices are overdue by more than 20 calendar days until such invoices are paid in full or in the event of non-payment termination under clause 13.2. The Organiser shall pay the interest together with the overdue amount. The Parties agree that the right to claim interest under this clause is a substantial remedy for late payment and is not in substitution for any statutory right to claim interest under the Late Payment of Commercial Debts (Interest) Act 1998.

4.2.6.5. All invoices should be settled as per the currency invoiced; any bank charges associated with the payment are the responsibility of the Organiser.

4.2.6.6. Any credit note issued by the Provider shall be valid for a period of six (6) months from the date of issuance, and in any event no later than (3) months from the end of the Provider’s financial year. Any unused portion of the credit note after the expiry of this period shall automatically lapse and shall not be subject to any refund, compensation, or further use.

4.2.6.7 Each year, in order to continue investing to bring you the best and most reliable software, alongside the latest technologies and services. We adjust the prices of some of our products and services in line with the Consumer Price Index (CPI) rate of inflation, plus 3.9%.

4.2.7. Organiser Account

4.2.7.1. The Platform may only be used through the account. The Account may only be accessed by the Organiser’s Permitted Users, who are explicitly authorised by the Organiser to use the Platform.

4.2.7.2. The Organiser will ensure that the Permitted Users keep the account login details secure at all times and comply with the terms of this Agreement. The Organiser shall remain at all times fully responsible for any breach of this Agreement by a Permitted User. Any unauthorised access or use of the account or the Platform must be immediately reported to the Provider.

4.2.8. Intellectual Proprietary Rights

4.2.8.1. Any and all right, title and interest in and to the Platform, and the Documentation, including any modifications to the Platform that are developed by or for the Provider and all associated Intellectual Property Rights, are and shall at all times remain the sole and exclusive property of the Provider. The Organiser is granted no title or ownership rights in or to the Platform.

4.2.8.2. The Programs contain trade secrets of the Provider, including but not limited to the structure, organisation, design engineering details, the source code of the Platform and other data pertaining to the Platform and proprietary information owned by the Provider and is protected, inter alia, by copyright laws and international trade provisions.

4.2.8.3. The Organiser will take no action which adversely affects the Provider’s Intellectual Property Rights in the Platform and the Organiser must treat the Platform like any other copyrighted material and the Organiser may not copy or distribute the Platform software or the Documentation electronically or otherwise, for any purpose.

4.2.8.4. The Organiser shall promptly notify the Provider in writing of any infringement or other violation of the Provider’s Intellectual Property Rights to which it becomes aware.

4.2.9. Restrictions

4.2.9.1. Except as expressly set out in this Agreement or as permitted by any local law, the Organiser undertakes as follows:

(a) not to copy the Platform or Documentation except where such copying is incidental to normal use of the Platform, or where it is necessary for the purpose of back-up or operational security;

(b) not to rent, lease, sub-license, loan, translate, merge, adapt, vary or modify the Platform or Documentation;

(c) not to make alterations to, or modifications of, the whole or any part of the Platform, nor permit the Platform or any part of it to be combined with, or become incorporated in, any other programs;

(d) not to disassemble, decompile, reverse-engineer or create derivative works based on the whole or any part of the Platform nor attempt to do any such thing except to the extent that (by virtue of section 296A of the Copyright, Designs and Patents Act 1988) such actions cannot be prohibited because they are essential for the purpose of achieving inter-operability of the Platform with another software program, and provided that the information obtained by the Organiser during such activities:

(i) is used only for the purpose of achieving inter-operability of the Platform with another software program; and

(ii) is not unnecessarily disclosed or communicated without our prior written consent to any third party; and

(iii) is not used to create any software which is substantially similar to the Platform;

(e) to keep all copies of the Platform secure and to maintain accurate and up-to-date records of the number and locations of all copies of the Platform;

(f) to supervise and control use of the Platform and ensure that the Platform is used by your employees and representatives in accordance with the terms of this Agreement;

4.2.10. Confidentiality and Publicity

4.2.10.1. The Parties agree to keep confidential the existence and contents of this Agreement, the Confidential Information as well as any information of whatever nature concerning the business, finances, assets, liabilities, dealings, transactions, know-how, customers, suppliers, processes or affairs of the other Party and the Parties agree not to disclose or otherwise make available the same to a third party without the prior written consent of the other Party.

4.2.10.2. The obligations of confidentiality in clause 10 shall continue in force for a period of three (3) years from the Effective Date and shall not be affected by the expiry of termination of this Agreement.

4.2.10.3. The obligations set out in clause 10 shall not apply to Confidential Information or any other information that the receiving Party can demonstrate:

  • is or has become publicly known other than through breach of clause 10; or
  • was in the possession of the receiving Party prior to disclosure by the other Party; or
  • was received by the receiving Party from an independent third party who has full right of disclosure; or
  • was required to be disclosed by a governmental authority, provided that the Party subject to such requirement to disclose gives the other prompt written notice of the requirement.

4.2.10.4. All media releases, public announcements and public disclosures by the Parties relating to this Agreement or its subject matter, including promotional or marketing material, shall be coordinated between them and mutually approved in writing prior to release.

4.2.11. Data Protection

4.2.11.1. Under the Data Protection Legislation, the Provider is required to provide the Organiser with certain information about who the Provider is, how personal data is processed of those individuals who use the Platform and the Documentation and for what purposes and those individuals’ rights in relation to their personal data and how to exercise them. This information is provided in https://expoplatform.com/privacy-policy and it is important that the Organiser reads that information.

4.2.11.2. Both parties will comply with all applicable requirements of the Data Protection Legislation. This clause 11.2 is in addition to, and does not relieve, remove or replace, a party’s obligations under the Data Protection Legislation. In addition, both parties subscribe to the Data Processing Agreement Addendum as described in Appendix I.

4.2.11.3. The Provider warrants that to the extent it processes any Personal Data on behalf of the Organiser:

  • it shall only process such Personal Data for the purposes of fulfilling its obligations under this Agreement; and
  • it has in place appropriate technical and organisational security measures against unauthorised or unlawful processing of Personal Data and against accidental loss or destruction of, or damage to, Personal Data.

4.2.11.4. Without prejudice to the generality of clause 11.2, the Organiser will ensure that it has all necessary appropriate consents and notices in place to enable lawful transfer of the personal data to the Provider for the duration and purposes of this agreement so that the Provider may lawfully use, process and transfer the personal data in accordance with this agreement on the Organiser’s behalf.

4.2.11.5. The Organiser consents to the Provider appointing the current third-party processors of Personal Data under this agreement listed at https://expoplatform.com/privacy-policy/  and any other additional third-party processors appointed by the Provider from time to time, provided that the Provider will give to the Organiser a prior written 60 days’ notice to advise of any such additional third-party processors and the Organiser does not object to the appointment of any such additional third-party processors during the 60 days’ notice period.The Provider confirms that it has entered or (as the case may be) will enter with each of the third-party processors into a written agreement substantially on that third party’s standard terms of business incorporating terms which are substantially similar to those set out in this clause 11. As between the Provider and the Organiser, the Provider shall remain fully liable for all acts or omissions of any third-party processor appointed by it pursuant to this clause 11.

4.2.11.6. The Organiser and the Permitted Users shall own all right, title and interest in and to all of the Customer Data and shall have sole responsibility for the legality, reliability, integrity, accuracy and quality of all such Customer Data.

4.2.11.7. The Organiser agrees to indemnify and keep indemnified the Provider and defend it at the Organiser’s own expense against all costs, claims, damages or expenses incurred by the Supplier or for which the Provider may become liable due to any failure by the Organiser or its employees or agents to comply with any of the Organiser’s obligations under this clause 11.

4.2.12. Warranties

4.2.12.1. Each of the Parties warrants to the other that it has full power and authority to enter into and perform this Agreement.

4.2.12.2. The Provider shall perform the Services with reasonable care and skill and in accordance with generally recognised commercial practices and standards.

4.2.12.3. The Provider warrants that the operation of the Platform will be uninterrupted and free of errors and material defects under normal use, and that the Platform will perform substantially in accordance with the Platform Specification for the duration of this Agreement. The Warranty Period applies for the duration of this Agreement.

4.2.12.4. If, within the Warranty Period, the Organiser notifies the Provider in writing of any defect or fault in the Platform as a result of which it fails to perform substantially in accordance with the Documentation, the Provider will, at its sole option, either repair or replace the Platform, provided that the Organiser shall make available all the information that may be necessary to help the Provider remedy the defect or fault, including providing sufficient information to enable the Provider to recreate the defect or fault.

4.2.12.5. The Warranty in clause 12.3 shall not apply if the defect or fault in the Platform results from you having altered or modified the Platform or if the defect or fault in the Platform results from you having used the Platform in any way that results in a breach of the terms of this Agreement.

4.2.13. Term and Termination

4.2.13.1. The Agreement shall automatically renew for successive terms of the same duration as the initial term (each, a “Renewal Term”) unless:

4.2.13.1.1. either party notifies the other party of termination, in writing, at least 3 months’ notice before the end of the Initial Term or any Renewal Period, in which case this agreement shall terminate upon the expiry of the applicable Initial Term or Renewal Period; or

4.2.13.1.2. otherwise terminated in accordance with the provisions of this Agreement and the Initial Term together with any subsequent Renewal Periods shall constitute the Term.

4.2.13.2. Without affecting any other right or remedy available to it, either Party may terminate this Agreement with immediate effect by giving written notice to the other Party if:

  • the other party fails to pay any amount due under this Agreement on the due date for payment and remains in default not less than 15 days after being notified in writing to make such payment;
  • the other Party commits a material breach of any terms of this Agreement which breach is irremediable or (if such breach is remediable) fails to cure that breach within a period of 14 days after being notified in writing to do so;
  • the other party repeatedly breaches any of the terms of this Agreement in such a manner as to reasonably justify the opinion that its conduct is inconsistent with it having the intention or ability to give effect to the terms of this Agreement;
  • the other party suspends, or threatens to suspend, payment of its debts or is unable to pay its debts as they fall due or admits inability to pay its debts or is deemed unable to pay its debts; or
  • in the event of fraud, wilful misconduct or gross negligence of the other Party.

4.2.13.3. On expiry or termination of this Agreement:

  • all licences granted by the Provider under this Agreement shall terminate immediately;
  • the Organiser shall immediately cease all activities authorised by this Agreement;
  • the Organiser must immediately and permanently delete or remove the Platform software from all computer equipment in your possession, and immediately destroy or return to us (at our option) all copies of the Platform and Documentation then in the Organiser’s possession, custody or control and, in the case of destruction, certify to us that you have done so;
  • the Provider shall provide all such assistance as is requested by the Organiser to transfer the hosting of the Platform to the Organiser or another service provider, subject to payment of the Provider’s expenses reasonably incurred; and
  • any provision of this Agreement that expressly or by implication is intended to come into or continue in force on or after termination or expiry of this agreement shall remain in full force and effect.

4.2.13.4. Termination or expiry of this Agreement shall not affect any rights, remedies, obligations or liabilities of the Parties that have accrued up to the date of termination or expiry, including the right to claim damages in respect of any breach of the Agreement which existed at or before the date of termination or expiry.

4.2.14. Limitation of Liability

4.2.14.1. The Organiser acknowledges that the Platform has not been developed to meet any specific requirements, including any particular cybersecurity requirements that might exist under law or otherwise. Therefore, it is  the  responsibility of the  Organiser to ensure that the facilities and functions of the Platform as described in the Documentation meet the requirements of the Organiser, Exhibitor or Delegate.

4.2.14.2. The Platform and Documentation is for internal business use only, and the Organiser agrees not to use the Platform or the Documentation for any re-sale purpose.

4.2.14.3. The Provider shall not in any circumstances whatever be liable to the Organiser, whether in contract, tort (including negligence), breach of statutory duty, or otherwise, arising under or in connection with the Agreement for:

(a) loss of profits, sales, business, or revenue;

(b) business interruption;

(c) loss of anticipated savings;

(d) loss or corruption of data or information;

(e) loss of business opportunity, goodwill or reputation; where any of the losses set out in Clause 14.3(a) to Clause 14.3(e) are direct or indirect; or

(f) any special, indirect or consequential loss, damage, charges or expenses.

4.2.14.4. Other than the losses set out in clause 14.3 (for which the Provider is not liable), the Provider’s maximum aggregate liability under or in connection with this Agreement whether in contract, tort (including negligence) or otherwise, shall in all circumstances be limited to a sum equal to 100% of the Licence Fee. This clause shall not apply to clause 14.5.

4.2.14.5. Nothing in this Agreement shall limit or exclude any liability for:

(a) death or personal injury resulting from the Provider’s negligence;

(b) fraud or fraudulent misrepresentation;

(c) any other liability that cannot be excluded or limited by English law.

4.2.15. General

4.2.15.1. This Agreement is made exclusively for the benefit of the Parties to it and does not confer any rights on any third party other than the Delegates in respect of the data protection provisions set forth in clause 11 pursuant to the Contracts (Rights of Third Parties) Act 1999.

4.2.15.2. No variation of this Agreement shall be effective unless it is in writing signed by and on behalf of both of the Parties. The expression “variation” as used in the preceding sentence includes, but is not limited to supplement, deletion or replacement, however effected. Variation of this Agreement cannot be effected via email.

4.2.15.3. The Provider may engage third party consultants or subcontractors at its own cost, including but not limited to companies with which the Provider may have an alliance, to perform the services under this Agreement in whole or in part on behalf of the Provider but shall remain fully responsible for the provision of all its services as set out in this Agreement.

4.2.15.4. This Agreement is entered into in the English language. Should there be any discrepancy between this Agreement and any translation of it into any language other than English, the original English text shall prevail.

4.2.15.5. This Agreement and any document expressly referred to in it constitutes the entire agreement between the Parties and supersedes and extinguishes all previous agreements, promises, assurances, warranties, representations and understandings between the Parties, whether written or oral, relating to its subject matter. The Organiser agrees that it shall have no remedies in respect of any statement, representation, assurance or warranty (whether made innocently or negligently) that is not set out in this Agreement or any document expressly referred to in it. The Organiser agrees that it shall have no claim for innocent or negligent misrepresentation or negligent misstatement based on any statement in this Agreement or any document expressly referred to in it.

4.2.15.6. If the Provider fails to insist that the Organiser performs any of the Organiser’s obligations under this Agreement, or if the Provider does not enforce its rights against the Organiser, or if the Provider delays in doing so, that will not mean that the Provider has waived its rights against the Organiser and will not mean that the Organiser does not have to comply with those obligations. If the Provider does waive a default by the Organiser, it will only do so in writing signed by the Provider, and that will not mean that the Provider will automatically waive any later default by the Organiser.

4.2.15.7. Each of the conditions of this Agreement operates separately. If any court or competent authority decides that any of them are unlawful or unenforceable, the remaining conditions will remain in full force and effect.

4.2.15.8. The Organiser may not assign, novate, transfer, charge or otherwise deal with its rights or obligations under this Agreement, in whole or in part, without the prior written consent of the Provider, such consent not to be unreasonably withheld, conditioned or delayed. Any purported assignment in breach of this clause is void. This clause is subject to clause 4.2.15.13.

4.2.15.9. This Agreement does not, and shall not be construed to create any relationship, partnership, joint venture, employer-employee, agency, or franchisor-franchisee relationship between the Parties.

4.2.15.10. The Provider will not be liable for any delay or failure to provide the Services resulting from circumstances or causes beyond the reasonable control of the Provider.

4.2.15.11. This Agreement may be executed in electronic counterparts, each of which counterpart, when so executed and delivered, shall be deemed to be an original and all of which counterparts, taken together, shall constitute but one and the same agreement.

4.2.15.12. Any dispute arising out of or in connection with this Agreement, including any question regarding its existence, validity or termination, shall be referred to and finally resolved by arbitration under the LCIA Rules, which Rules are deemed to be incorporated by reference into this clause. The seat, or legal place, of arbitration shall be London. The language to be used in the arbitral proceedings shall be English. The governing law of the contract is the substantive law of England. The Parties both irrevocably agree to the exclusive jurisdiction of the courts of England and Wales.

4.2.15.13. Change of Control. A Change of Control of either Party shall not constitute a breach of this Agreement, shall not require the consent of the other Party, and shall not of itself give either Party any right to terminate, suspend or vary this Agreement, to renegotiate the fees payable under it, or to withhold or delay payment of any sums due.
Without limiting the foregoing, a Change of Control of the Organiser, including any acquisition of the Organiser or of any event, business or portfolio to which this Agreement relates, shall not affect the continuation of this Agreement, and the Agreement shall continue in full force and effect for the remainder of the then-current Term. The Organiser shall notify the Provider in writing within 30 days of any Change of Control affecting it.
The Provider may, without the consent of the Organiser, assign, novate or otherwise transfer this Agreement in its entirety, together with all of its rights and obligations under it, to any Affiliate or to any successor, acquirer or transferee in connection with a merger, acquisition, corporate reorganisation, Change of Control or sale of all or substantially all of its shares, assets or business, provided that the transferee assumes the Provider’s obligations under this Agreement. The Organiser consents in advance to any such novation and agrees to execute any document reasonably required to give effect to it. The Provider shall notify the Organiser of any such transfer as soon as reasonably practicable.
This clause does not affect either Party’s right to give notice of non-renewal in accordance with clause 4.2.13.1, or either Party’s rights of termination under clause 4.2.13.2. This Agreement binds and benefits each Party’s permitted successors and assigns.

4.2.16. ExpoPlatform Code of Conduct Statement

4.2.16.1. The ExpoPlatform team is central to its mission of helping organizers reinvent their business, transform their events into smart events and enhance customer value through year-round communities.

We expect our team to act professionally and courteously in their dealings with all clients and we expect that all of our team will be treated professionally and courteously in return.

This Client Code of Conduct (“the Code”) is fundamental to furthering ExpoPlatform’s mission and its successful collaboration with clients and applies to all ExpoPlatform clients and their representatives.

As an ExpoPlatform client, you are expected to conduct yourself and your business ethically and with integrity. You are also expected to act professionally and courteously in your dealings with all ExpoPlatform employees.

If you are reviewing the Code on behalf of a company or other entity, you represent and warrant that you have authority to bind that company or other entity to the Code and by agreeing to the Code, you are doing so on behalf of that company or entity (and in such event all references to “you” in the Code refer to both you and that company or entity).

4.2.16.2. Purpose

The purpose of the Code is to provide guidance to our clients so that they understand ExpoPlatform’s expectations regarding a client’s behavior when dealing with ExpoPlatform personnel and our expectations that each of our clients use only ethical business practices and are fully compliant with all applicable laws and regulations.

4.2.16.3. Guidance for Clients

In order to be in alignment with ExpoPlatform’s core values, clients must:

  • Act professionally and courteously at all times to all ExpoPlatform personnel
  • Respect ExpoPlatform employees’ non-working hours and previously scheduled meetings
  • Not attempt to intimidate or harass, sexually or otherwise, any ExpoPlatform employee
  • Not use profane, hostile or aggressive language with ExpoPlatform employees
  • Not engage in conduct which is fraudulent, corrupt, deceptive, misleading or harmful to the public or to the events industry
  • Not engage in any conduct which is in violation of applicable anti-bribery/anti-corruption laws and regulations, trade controls (import/export) regulations, economic sanctions or other applicable sanctions regulations

4.2.16.4. Failure to Comply

Failure to comply with the Client Code of Conduct may result in ExpoPlatform refusing to engage in any further dealings with the client, whether on the current project or on future projects.

4.2.16.5. Acknowledgment

I understand that my compliance and my company’s compliance with the Code is a condition of ExpoPlatform providing services to me and/or my company.

I understand that ExpoPlatform expects the highest degree of professional ethics and integrity from its clients and I agree to treat all ExpoPlatform employees with dignity, professionalism and respect.

I acknowledge that the Code does not identify every possible action that may violate the Code and that ExpoPlatform reserves the right to refuse to provide any future services for conduct which it deems in violation of the Code.

I have carefully read and I understand the Code. I support these professional standards for ExpoPlatform and for myself and for my company, and will act in accordance with them and ensure that others in my company do as well.

4.2.17. Use of Optional Platform Features

Our platform includes optional features that involve the sending of SMS and What’sApp messages.

These features are entirely optional, and you are not obligated to use them, however if you choose to enable and use any of these features, you agree to be billed for the cost of the messages sent through the platform.

The cost for each SMS message will be the relevant outbound country cost shown here + 50% to cover the additional fees ExpoPlatform incurs for taxes, support, infrastructure and other AWS costs.

The cost for each What’sApp message will be as outlined here + 50%.

The total amount will be billed to you after your event has ended.

5. Appendix I. ExpoPlatform Data Protection Addendum

5.1. PERSONAL DATA / PROCESSOR

I. The purpose of these clauses is to define the conditions under which the processor Expoplatform (“Processor” or “Service Provider”) undertakes to carry out the personal data processing operations defined below on behalf of the Organiser, the data controller.

As part of their contractual relationship, the parties undertake to comply with the regulations in effect applicable to personal data processing and in particular, Regulation (EU) 2016/679 applicable from 25 May 2018 (hereinafter the “General Data Protection Regulation” or “GDPR”).

Under the terms of this rider, the following terms are defined as follows:

  • “data controller”: the natural person or legal entity, public authority, service or other organisation which, solely or jointly with others, determines the purposes and methods of processing; where said processes and methods are determined by European Union law or the law of a Member State, the controller may be appointed or the specific criteria applicable to their appointment may be provided for by European Union law or the law of a Member State.
  • “processor”: the natural person or legal entity, department or other organisation that processes personal data on behalf of the data controller.

II.Description of the processing carried out by processors

The processor is authorised to process personal data on behalf of the data controller that are necessary to provide the services described in the Budget & Scope section of the proposal document as well as any supplementary order forms (see template in Appendix II).

The details of the processing carried out by processors are as follows:

Nature of the operations carried out on the data (e.g. data storage)Please refer to the scope of services in the proposal and contract document
Purpose(s) of processingRegistration and/or participation in an event.
Categories of personal data processedFirst name, last name, email, and other data as required by the data controller
Categories of persons concernedDelegates
Period of data retention or criterion justifying the retention of data (separate from the term of the contract)3 years

This rider is valid as a written instruction for the processing of data by the processor.

III. Processor’s obligations in respect of the data controller

The processor undertakes to:

1. process the data solely for the purpose(s) of delivering the service

2. process the data in accordance with the data controller’s documented instructions. If the processor considers that an instruction constitutes an infringement of the General Data Protection Regulation or any other provision of European Union law or the law of Member States on data protection, the data processor shall apply best effort to inform the data controller of this. The responsibility for ensuring compliance with such regulations rests with the data controller.

3. unless otherwise specifically and expressly authorised by the data controller, process data exclusively within the territory of an EEA Member State. The processor undertakes not to disclose, make accessible or transfer any of the data controller’s data, to any processing organisation or processor based in a country located outside the EEA, except with the data controller’s prior written consent.

In the event of a transfer outside the EEA, authorised by the data controller, said transfer may only take place within the strict limits necessary for the performance of the services, and provided said transfer is towards a State whose legislation in respect of personal data protection has been recognised by the European Commission as offering an equivalent level of protection, or is governed by standard contractual clauses issued by the European Commission or is carried out on the basis of any other alternative arrangements recognised by the General Data Protection Regulation, subject to data controller’s prior agreement to said arrangements in writing.

4. put in place processes and practices that maintain the confidentiality of the personal data processed under this contract

5. ensure that those authorised to treat personal data according to this contract:

  • undertake to respect confidentiality or are subject to an appropriate statutory confidentiality obligation
  • receive the necessary training in respect of personal data protection

6.take account of data protection principles and data protection by default from the design stage onward of tools, products, applications and services

IV. Data subjects’ right to information

It is the data controller’s responsibility to provide information relating to the data processing carried out by it to the data subjects concerned by the processing operations at the time the data are collected. The Service Provider shall provide all reasonable assistance and tools to ensure that such information can be easily accessed.

V. Exercise of individual rights

So far as possible, the processor shall assist the data controller in fulfilling its obligation to respond to requests to exercise their rights by data subjects, including rights of access, correction, deletion and opposition, right to restriction of processing, right to data portability and right not to be the subject to an automated individual decision (including profiling).

VI. Notification of breaches of personal data

The processor shall notify the data controller of any personal data breach within a maximum of 24 hours after becoming aware of it, by e-mail to the data protection officer. Said notification must be accompanied by any documentation that may be useful in enabling the data controller to inform the relevant regulatory authority of the breach, if applicable.

The processor shall, throughout the period of the Contract, set up and maintain a process and procedures to manage security incidents (including, in particular, breaches of personal data) and ensure continuity of service in accordance with industry standards. Requests from the data controller relating to security shall be treated diligently by the processor.

In the event of a presumed or proven security incident or breach of personal data in the Service Provider’s system, the processor shall advise the data controller immediately and at the latest, within 24 hours following the occurrence of the security incident or breach of personal data.

Immediately after said notification, the Parties will coordinate their actions in order to investigate the security incident concerned. The processor undertakes to cooperate fully with the data controller, at its own expense, to help it to manage the situation, including but not limited to:

(i) helping it with any investigation;

(ii) providing the data controller or an independent third party appointed by the data controller with physical access to the facilities and operations concerned;

(iii) organising interviews with the employees of the data controller and all other appropriate individuals; and

(iv) providing all registers, logs, files, data communications and other relevant documents necessary for compliance with laws, regulations and industry standards or as required by the data controller.

The processor will also provide all reasonable assistance to the data controller in the case of a notification in respect of any action the latter may be obliged or may choose to take in respect of a personal data breach. The processor undertakes not to inform third parties, including the persons concerned, of any breach of personal data without having obtained the prior consent of the data controller in writing, except in the cases provided for in the General Data Protection Regulation or other applicable laws.

The processor shall take the appropriate measures, at its own expense, to mitigate the consequences of any security incident and remedy it, and shall make all the amendments it judges necessary in order to avoid any re-occurrence of an incident of this kind. The processor shall assist the data controller, at its own expense, with restoring the data controller’s data in the event of a data loss caused by any failure to fulfil its regulations in respect of the Contract.

The processor shall cooperate and provide the data controller with the necessary assistance in respect of any complaint formulated by a data subject or any investigation or request issued by a regulatory authority with regard to the General Data Protection Regulation or any other applicable regulation.

The processor shall maintain a record of security incidents and make this available to the data controller, including but not limited to breaches of personal data, and shall document all relevant information concerning the circumstances of said incidents and breaches, the harm caused and corrective measures taken to mitigate their effects, as well as the actions and measures taken to avoid any repetition of such incidents or breaches.

VII. Assistance from the processor in relation to the data controller’s fulfillment of its obligations

The processor shall cooperate with the data controller and use its best endeavours to help the data controller prove that it is compliant with all its legislative and regulatory obligations, notably in respect of the General Data Protection Regulation.

VIII. Retention of data

Once the provision of services relating to the processing of these data is complete, the processor undertakes to:

  • Destroy all personal data or
  • At any time, at the data controller’s written request and at the latest, within 15 calendar days of the end of the Contract, the processor undertakes to return the data controller’s personal data, in a legible or interoperable form agreed between the Parties and to destroy all copies (paper or electronic) of the data controller’s personal data that it may hold.

This clause will remain in effect after the expiry or termination of the Contract for any reason whatsoever. This clause is subject to applicable data retention laws and obligations of the data processor.

IX. Register of categories of processing activities

The processor declares that it holds a written record of all categories of processing activities carried out on behalf of the data controller including:

(a) the name and contact details of the data controller on behalf of whom it is acting, any processors and, if applicable, the data protection officer;

(b) the categories of processing activities carried out on behalf of the data controller;

(c) if applicable, any transfers of personal data to a third country or international organisation, including the identification of said third country or international organisation and, in the case of transfers referred to in clause 49, paragraph 1, second subparagraph of the General Data Protection Regulation, documents attesting to the existence of appropriate guarantees;

(d) as far as possible, a general description of technical and organisational security measures, including but not limited, as required, to:

  • pseudonymisation and encryption of personal data;
  • means of guaranteeing the constant confidentiality, integrity, availability and resilience of processing systems and services;
  • means of re-establishing the availability of personal data and access thereto in an appropriate time frame in the event of a physical or technical incident;
  • a procedure for regularly testing, analysing and evaluating the effectiveness of technical and organisational measures to ensure the security of processing.

X. Data controller’s obligations in respect of the processor

The data controller undertakes, throughout the term of the contract, to:

  1. 1. provide the processor with the data referred to in clause II;
  2. 2. document in writing any additional instructions regarding the processing of data by the processor;
  3. 3. ensure, prior to and during the period of processing, compliance with the obligations set out in the General Data Protection Regulation by the controller

5.2. PLATFORM USAGE DATA

Anonymous data regarding clicks and behaviour of users, and is anonymised for the sole purpose of making improvements to the platform itself.

The full usage data can be exported by Organisers as required.

5.3. EUROPEAN UNION STANDARD CONTRACTUAL CLAUSES FOR RESTRICTED DATA TRANSFERS

5.3.1. SECTION I

Clause 1. Purpose and scope

(a) The purpose of these standard contractual clauses is to ensure compliance with the requirements of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation) for the transfer of personal data to a third country.

(b) The Parties:

(i) the natural or legal person(s), public authority/ies, agency/ies or other body/ies (hereinafter “entity/ies”) transferring the personal data, as listed in Annex I.A. (hereinafter each “data exporter”), and

(ii) the entity/ies in a third country receiving the personal data from the data exporter, directly or indirectly via another entity also Party to these Clauses, as listed in Annex I.A. (hereinafter each “data importer”)
have agreed to these standard contractual clauses (hereinafter: “Clauses”).

(c) These Clauses apply with respect to the transfer of personal data as specified in Annex I.B.

(d) The Appendix to these Clauses containing the Annexes referred to therein forms an integral part of these Clauses.

Clause 2. Effect and invariability of the Clauses

(a) These Clauses set out appropriate safeguards, including enforceable data subject rights and effective legal remedies, pursuant to Article 46(1) and Article 46 (2)(c) of Regulation (EU) 2016/679 and, with respect to data transfers from controllers to processors and/or processors to processors, standard contractual clauses pursuant to Article 28(7) of Regulation (EU) 2016/679, provided they are not modified, except to select the appropriate Module(s) or to add or update information in the Appendix. This does not prevent the Parties from including the standard contractual clauses laid down in these Clauses in a wider contract and/or to add other clauses or additional safeguards, provided that they do not contradict, directly or indirectly, these Clauses or prejudice the fundamental rights or freedoms of data subjects.

(b) These Clauses are without prejudice to obligations to which the data exporter is subject by virtue of Regulation (EU) 2016/679.

Clause 3. Third-party beneficiaries

(a) Data subjects may invoke and enforce these Clauses, as third-party beneficiaries, against the data exporter and/or data importer, with the following exceptions:

(i) Clause 1, Clause 2, Clause 3, Clause 6, Clause 7;

(ii) Clause 8 – Module One: Clause 8.5 (e) and Clause 8.9(b); Module Two: Clause 8.1(b), 8.9(a), (c), (d) and (e); Module Three: Clause 8.1(a), (c) and (d) and Clause 8.9(a), (c), (d), (e), (f) and (g); Module Four: Clause 8.1 (b) and Clause 8.3(b);

(iii) Clause 9 – Module Two: Clause 9(a), (c), (d) and (e); Module Three: Clause 9(a), (c), (d) and (e);

(iv) Clause 12 – Module One: Clause 12(a) and (d); Modules Two and Three: Clause 12(a), (d) and (f);

(v) Clause 13;

(vi) Clause 15.1(c), (d) and (e);

(vii) Clause 16(e);

(viii) Clause 18 – Modules One, Two and Three: Clause 18(a) and (b); Module Four: Clause 18.

(b) Paragraph (a) is without prejudice to rights of data subjects under Regulation (EU) 2016/679.

Clause 4. Interpretation

(a) Where these Clauses use terms that are defined in Regulation (EU) 2016/679, those terms shall have the same meaning as in that Regulation.

(b) These Clauses shall be read and interpreted in the light of the provisions of Regulation (EU) 2016/679.

(c) These Clauses shall not be interpreted in a way that conflicts with rights and obligations provided for in Regulation (EU) 2016/679.

Clause 5. Hierarchy

In the event of a contradiction between these Clauses and the provisions of related agreements between the Parties, existing at the time these Clauses are agreed or entered into thereafter, these Clauses shall prevail.

Clause 6. Description of the transfer(s)

The details of the transfer(s), and in particular the categories of personal data that are transferred and the purpose(s) for which they are transferred, are specified in Annex I.B.

Clause 7 – Optional. Docking clause

(a) An entity that is not a Party to these Clauses may, with the agreement of the Parties, accede to these Clauses at any time, either as a data exporter or as a data importer, by completing the Appendix and signing Annex I.A.

(b) Once it has completed the Appendix and signed Annex I.A, the acceding entity shall become a Party to these Clauses and have the rights and obligations of a data exporter or data importer in accordance with its designation in Annex I.A.

(c) The acceding entity shall have no rights or obligations arising under these Clauses from the period prior to becoming a Party.

5.3.2. SECTION II – OBLIGATIONS OF THE PARTIES

Clause 8. Data protection safeguards

The data exporter warrants that it has used reasonable efforts to determine that the data importer is able, through the implementation of appropriate technical and organisational measures, to satisfy its obligations under these Clauses.

8.1 Instructions

(a) The data exporter has informed the data importer that it acts as processor under the instructions of its controller(s), which the data exporter shall make available to the data importer prior to processing.

(b) The data importer shall process the personal data only on documented instructions from the controller, as communicated to the data importer by the data exporter, and any additional documented instructions from the data exporter. Such additional instructions shall not conflict with the instructions from the controller. The controller or data exporter may give further documented instructions regarding the data processing throughout the duration of the contract.

(c) The data importer shall immediately inform the data exporter if it is unable to follow those instructions. Where the data importer is unable to follow the instructions from the controller, the data exporter shall immediately notify the controller.

(d) The data exporter warrants that it has imposed the same data protection obligations on the data importer as set out in the contract or other legal act under Union or Member State law between the controller and the data exporter.

8.2 Purpose limitation

The data importer shall process the personal data only for the specific purpose(s) of the transfer, as set out in Annex I.B., unless on further instructions from the controller, as communicated to the data importer by the data exporter, or from the data exporter.

8.3 Transparency

On request, the data exporter shall make a copy of these Clauses, including the Appendix as completed by the Parties, available to the data subject free of charge. To the extent necessary to protect business secrets or other confidential information, including personal data, the data exporter may redact part of the text of the Appendix prior to sharing a copy, but shall provide a meaningful summary where the data subject would otherwise not be able to understand its content or exercise his/her rights. On request, the Parties shall provide the data subject with the reasons for the redactions, to the extent possible without revealing the redacted information.

8.4 Accuracy

If the data importer becomes aware that the personal data it has received is inaccurate, or has become outdated, it shall inform the data exporter without undue delay. In this case, the data importer shall cooperate with the data exporter to rectify or erase the data.

8.5 Duration of processing and erasure or return of data

Processing by the data importer shall only take place for the duration specified in Annex I.B. After the end of the provision of the processing services, the data importer shall, at the choice of the data exporter, delete all personal data processed on behalf of the controller and certify to the data exporter that it has done so, or return to the data exporter all personal data processed on its behalf and delete existing copies. Until the data is deleted or returned, the data importer shall continue to ensure compliance with these Clauses. In case of local laws applicable to the data importer that prohibit return or deletion of the personal data, the data importer warrants that it will continue to ensure compliance with these Clauses and will only process it to the extent and for as long as required under that local law. This is without prejudice to Clause 14, in particular the requirement for the data importer under Clause 14(e) to notify the data exporter throughout the duration of the contract if it has reason to believe that it is or has become subject to laws or practices not in line with the requirements under Clause 14(a).

8.6 Security of processing

(a) The data importer and, during transmission, also the data exporter shall implement appropriate technical and organisational measures to ensure the security of the data, including protection against a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access to that data (hereinafter “personal data breach”). In assessing the appropriate level of security, they shall take due account of the state of the art, the costs of implementation, the nature, scope, context and purpose(s) of processing and the risks involved in the processing for the data subject. The Parties shall in particular consider having recourse to encryption or pseudonymisation, including during transmission, where the purpose of processing can be fulfilled in that manner. In case of pseudonymisation, the additional information for attributing the personal data to a specific data subject shall, where possible, remain under the exclusive control of the data exporter or the controller. In complying with its obligations under this paragraph, the data importer shall at least implement the technical and organisational measures specified in Annex II. The data importer shall carry out regular checks to ensure that these measures continue to provide an appropriate level of security.

(b) The data importer shall grant access to the data to members of its personnel only to the extent strictly necessary for the implementation, management and monitoring of the contract. It shall ensure that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

(c) In the event of a personal data breach concerning personal data processed by the data importer under these Clauses, the data importer shall take appropriate measures to address the breach, including measures to mitigate its adverse effects. The data importer shall also notify, without undue delay, the data exporter and, where appropriate and feasible, the controller after having become aware of the breach. Such notification shall contain the details of a contact point where more information can be obtained, a description of the nature of the breach (including, where possible, categories and approximate number of data subjects and personal data records concerned), its likely consequences and the measures taken or proposed to address the data breach, including measures to mitigate its possible adverse effects. Where, and in so far as, it is not possible to provide all information at the same time, the initial notification shall contain the information then available and further information shall, as it becomes available, subsequently be provided without undue delay.

(d) The data importer shall cooperate with and assist the data exporter to enable the data exporter to comply with its obligations under Regulation (EU) 2016/679, in particular to notify its controller so that the latter may in turn notify the competent supervisory authority and the affected data subjects, taking into account the nature of processing and the information available to the data importer.

8.7 Sensitive data

Where the transfer involves personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, genetic data, or biometric data for the purpose of uniquely identifying a natural person, data concerning health or a person’s sex life or sexual orientation, or data relating to criminal convictions and offences (hereinafter “sensitive data”), the data importer shall apply the specific restrictions and/or additional safeguards set out in Annex I.B.

8.8 Onward transfers

The data importer shall only disclose the personal data to a third party on documented instructions from the controller, as communicated to the data importer by the data exporter. In addition, the data may only be disclosed to a third party located outside the European Union (in the same country as the data importer or in another third country, hereinafter “onward transfer”) if the third party is or agrees to be bound by these Clauses, under the appropriate Module, or if:

(i) the onward transfer is to a country benefitting from an adequacy decision pursuant to Article 45 of Regulation (EU) 2016/679 that covers the onward transfer;

(ii) the third party otherwise ensures appropriate safeguards pursuant to Articles 46 or 47 of Regulation (EU) 2016/679;

(iii) the onward transfer is necessary for the establishment, exercise or defence of legal claims in the context of specific administrative, regulatory or judicial proceedings; or

(iv)  the onward transfer is necessary in order to protect the vital interests of the data subject or of another natural person.

Any onward transfer is subject to compliance by the data importer with all the other safeguards under these Clauses, in particular purpose limitation.

8.9 Documentation and compliance

The data importer shall only disclose the personal data to a third party on documented instructions from the controller, as communicated to the data importer by the data exporter. In addition, the data may only be disclosed to a third party located outside the European Union (in the same country as the data importer or in another third country, hereinafter “onward transfer”) if the third party is or agrees to be bound by these Clauses, under the appropriate Module, or if:

(i) the onward transfer is to a country benefitting from an adequacy decision pursuant to Article 45 of Regulation (EU) 2016/679 that covers the onward transfer;

(ii) the third party otherwise ensures appropriate safeguards pursuant to Articles 46 or 47 of Regulation (EU) 2016/679;

(iii) the onward transfer is necessary for the establishment, exercise or defence of legal claims in the context of specific administrative, regulatory or judicial proceedings; or

(iv)  the onward transfer is necessary in order to protect the vital interests of the data subject or of another natural person.

Any onward transfer is subject to compliance by the data importer with all the other safeguards under these Clauses, in particular purpose limitation.

8.10 Documentation and compliance

(a) The data importer shall promptly and adequately deal with enquiries from the data exporter or the controller that relate to the processing under these Clauses.

(b) The Parties shall be able to demonstrate compliance with these Clauses. In particular, the data importer shall keep appropriate documentation on the processing activities carried out on behalf of the controller.

(c) The data importer shall make all information necessary to demonstrate compliance with the obligations set out in these Clauses available to the data exporter, which shall provide it to the controller.

(d) The data importer shall allow for and contribute to audits by the data exporter of the processing activities covered by these Clauses, at reasonable intervals or if there are indications of non-compliance. The same shall apply where the data exporter requests an audit on instructions of the controller. In deciding on an audit, the data exporter may take into account relevant certifications held by the data importer.

(e) Where the audit is carried out on the instructions of the controller, the data exporter shall make the results available to the controller.

(f) The data exporter may choose to conduct the audit by itself or mandate an independent auditor. Audits may include inspections at the premises or physical facilities of the data importer and shall, where appropriate, be carried out with reasonable notice.

(g) The Parties shall make the information referred to in paragraphs (b) and (c), including the results of any audits, available to the competent supervisory authority on request.

Clause 9. Use of sub-processors

(a) The data importer has the controller’s general authorisation for the engagement of sub-processor(s) from an agreed list. The data importer shall specifically inform the controller in writing of any intended changes to that list through the addition or replacement of sub-processors at least [Specify time period] in advance, thereby giving the controller sufficient time to be able to object to such changes prior to the engagement of the sub-processor(s). The data importer shall provide the controller with the information necessary to enable the controller to exercise its right to object. The data importer shall inform the data exporter of the engagement of the sub-processor(s).

(b) Where the data importer engages a sub-processor to carry out specific processing activities (on behalf of the controller), it shall do so by way of a written contract that provides for, in substance, the same data protection obligations as those binding the data importer under these Clauses, including in terms of third-party beneficiary rights for data subjects. The Parties agree that, by complying with this Clause, the data importer fulfils its obligations under Clause 8.8. The data importer shall ensure that the sub-processor complies with the obligations to which the data importer is subject pursuant to these Clauses.

(c) The data importer shall provide, at the data exporter’s or controller’s request, a copy of such a sub-processor agreement and any subsequent amendments. To the extent necessary to protect business secrets or other confidential information, including personal data, the data importer may redact the text of the agreement prior to sharing a copy.

(d) The data importer shall remain fully responsible to the data exporter for the performance of the sub-processor’s obligations under its contract with the data importer. The data importer shall notify the data exporter of any failure by the sub-processor to fulfill its obligations under that contract.

(e) The data importer shall agree a third-party beneficiary clause with the sub-processor whereby – in the event the data importer has factually disappeared, ceased to exist in law or has become insolvent – the data exporter shall have the right to terminate the sub-processor contract and to instruct the sub-processor to erase or return the personal data.

Clause 10. Data subject rights

(a) The data importer shall promptly notify the data exporter and, where appropriate, the controller of any request it has received from a data subject, without responding to that request unless it has been authorised to do so by the controller.

(b) The data importer shall assist, where appropriate in cooperation with the data exporter, the controller in fulfilling its obligations to respond to data subjects’ requests for the exercise of their rights under Regulation (EU) 2016/679 or Regulation (EU) 2018/1725, as applicable. In this regard, the Parties shall set out in Annex II the appropriate technical and organisational measures, taking into account the nature of the processing, by which the assistance shall be provided, as well as the scope and the extent of the assistance required.

(c) In fulfilling its obligations under paragraphs (a) and (b), the data importer shall comply with the instructions from the controller, as communicated by the data exporter.

Clause 11. Redress

(a) The data importer shall inform data subjects in a transparent and easily accessible format, through individual notice or on its website, of a contact point authorised to handle complaints. It shall deal promptly with any complaints it receives from a data subject.

(b) In case of a dispute between a data subject and one of the Parties as regards compliance with these Clauses, that Party shall use its best efforts to resolve the issue amicably in a timely fashion. The Parties shall keep each other informed about such disputes and, where appropriate, cooperate in resolving them.

(c) Where the data subject invokes a third-party beneficiary right pursuant to Clause 3, the data importer shall accept the decision of the data subject to:

(i) lodge a complaint with the supervisory authority in the Member State of his/her habitual residence or place of work, or the competent supervisory authority pursuant to Clause 13;

(ii) refer the dispute to the competent courts within the meaning of Clause 18.

(iii) the onward transfer is necessary for the establishment, exercise or defence of legal claims in the context of specific administrative, regulatory or judicial proceedings; or

(iv) the onward transfer is necessary in order to protect the vital interests of the data subject or of another natural person.

(d) The Parties accept that the data subject may be represented by a not-for-profit body, organisation or association under the conditions set out in Article 80(1) of Regulation (EU) 2016/679.

(e) The data importer shall abide by a decision that is binding under the applicable EU or Member State law.

(f) The data importer agrees that the choice made by the data subject will not prejudice his/her substantive and procedural rights to seek remedies in accordance with applicable laws.

Clause 12. Liability

(a) Each Party shall be liable to the other Party/ies for any damages it causes the other Party/ies by any breach of these Clauses.

(b) Each Party shall be liable to the data subject, and the data subject shall be entitled to receive compensation, for any material or non-material damages that the Party causes the data subject by breaching the third-party beneficiary rights under these Clauses. This is without prejudice to the liability of the data exporter under Regulation (EU) 2016/679.

(c) Where more than one Party is responsible for any damage caused to the data subject as a result of a breach of these Clauses, all responsible Parties shall be jointly and severally liable and the data subject is entitled to bring an action in court against any of these Parties.

(d) The Parties agree that if one Party is held liable under paragraph (c), it shall be entitled to claim back from the other Party/ies that part of the compensation corresponding to its / their responsibility for the damage.

(e) The data importer may not invoke the conduct of a processor or sub-processor to avoid its own liability.

Clause 13. Supervision

(a) The supervisory authority with responsibility for ensuring compliance by the data exporter with Regulation (EU) 2016/679 as regards the data transfer, as indicated in Annex I.C, shall act as competent supervisory authority.

(b) The data importer agrees to submit itself to the jurisdiction of and cooperate with the competent supervisory authority in any procedures aimed at ensuring compliance with these Clauses. In particular, the data importer agrees to respond to enquiries, submit to audits and comply with the measures adopted by the supervisory authority, including remedial and compensatory measures. It shall provide the supervisory authority with written confirmation that the necessary actions have been taken.

5.3.3. SECTION III – LOCAL LAWS AND OBLIGATIONS IN CASE OF ACCESS BY PUBLIC AUTHORITIES

Clause 14. Local laws and practices affecting compliance with the Clauses

(a) The Parties warrant that they have no reason to believe that the laws and practices in the third country of destination applicable to the processing of the personal data by the data importer, including any requirements to disclose personal data or measures authorising access by public authorities, prevent the data importer from fulfilling its obligations under these Clauses. This is based on the understanding that laws and practices that respect the essence of the fundamental rights and freedoms and do not exceed what is necessary and proportionate in a democratic society to safeguard one of the objectives listed in Article 23(1) of Regulation (EU) 2016/679, are not in contradiction with these Clauses.

(b) The Parties declare that in providing the warranty in paragraph (a), they have taken due account in particular of the following elements:

(i) the specific circumstances of the transfer, including the length of the processing chain, the number of actors involved and the transmission channels used; intended onward transfers; the type of recipient; the purpose of processing; the categories and format of the transferred personal data; the economic sector in which the transfer occurs; the storage location of the data transferred;

(ii) the laws and practices of the third country of destination– including those requiring the disclosure of data to public authorities or authorising access by such authorities – relevant in light of the specific circumstances of the transfer, and the applicable limitations and safeguards;

(iii) any relevant contractual, technical or organisational safeguards put in place to supplement the safeguards under these Clauses, including measures applied during transmission and to the processing of the personal data in the country of destination.

(с) The data importer warrants that, in carrying out the assessment under paragraph (b), it has made its best efforts to provide the data exporter with relevant information and agrees that it will continue to cooperate with the data exporter in ensuring compliance with these Clauses.

(d) The Parties agree to document the assessment under paragraph (b) and make it available to the competent supervisory authority on request.

(e) The data importer agrees to notify the data exporter promptly if, after having agreed to these Clauses and for the duration of the contract, it has reason to believe that it is or has become subject to laws or practices not in line with the requirements under paragraph (a), including following a change in the laws of the third country or a measure (such as a disclosure request) indicating an application of such laws in practice that is not in line with the requirements in paragraph (a). The data exporter shall forward the notification to the controller.

(f) Following a notification pursuant to paragraph (e), or if the data exporter otherwise has reason to believe that the data importer can no longer fulfil its obligations under these Clauses, the data exporter shall promptly identify appropriate measures (e.g. technical or organisational measures to ensure security and confidentiality) to be adopted by the data exporter and/or data importer to address the situation, if appropriate in consultation with the controller. The data exporter shall suspend the data transfer if it considers that no appropriate safeguards for such transfer can be ensured, or if instructed by the controller or the competent supervisory authority to do so. In this case, the data exporter shall be entitled to terminate the contract, insofar as it concerns the processing of personal data under these Clauses. If the contract involves more than two Parties, the data exporter may exercise this right to termination only with respect to the relevant Party, unless the Parties have agreed otherwise. Where the contract is terminated pursuant to this Clause, Clause 16(d) and (e) shall apply.
not in line with the requirements in paragraph (a). The data exporter shall forward the notification to the controller.

Clause 15. Obligations of the data importer in case of access by public authorities

15.1 Notification

(a) The data importer agrees to notify the data exporter and, where possible, the data subject promptly (if necessary with the help of the data exporter) if it:

(i) receives a legally binding request from a public authority, including judicial authorities, under the laws of the country of destination for the disclosure of personal data transferred pursuant to these Clauses; such notification shall include information about the personal data requested, the requesting authority, the legal basis for the request and the response provided; or

(ii) becomes aware of any direct access by public authorities to personal data transferred pursuant to these Clauses in accordance with the laws of the country of destination; such notification shall include all information available to the importer.

(iii) The data exporter shall forward the notification to the controller.

(b) If the data importer is prohibited from notifying the data exporter and/or the data subject under the laws of the country of destination, the data importer agrees to use its best efforts to obtain a waiver of the prohibition, with a view to communicating as much information as possible, as soon as possible. The data importer agrees to document its best efforts in order to be able to demonstrate them on request of the data exporter.

(c) Where permissible under the laws of the country of destination, the data importer agrees to provide the data exporter, at regular intervals for the duration of the contract, with as much relevant information as possible on the requests received (in particular, number of requests, type of data requested, requesting authority/ies, whether requests have been challenged and the outcome of such challenges, etc.). The data exporter shall forward the information to the controller.

(d) The data importer agrees to preserve the information pursuant to paragraphs (a) to (c) for the duration of the contract and make it available to the competent supervisory authority on request.

(e) Paragraphs (a) to (c) are without prejudice to the obligation of the data importer pursuant to Clause 14(e) and Clause 16 to inform the data exporter promptly where it is unable to comply with these Clauses.

15.2 Review of legality and data minimisation

(a) The data importer agrees to review the legality of the request for disclosure, in particular whether it remains within the powers granted to the requesting public authority, and to challenge the request if, after careful assessment, it concludes that there are reasonable grounds to consider that the request is unlawful under the laws of the country of destination, applicable obligations under international law and principles of international comity. The data importer shall, under the same conditions, pursue possibilities of appeal. When challenging a request, the data importer shall seek interim measures with a view to suspending the effects of the request until the competent judicial authority has decided on its merits. It shall not disclose the personal data requested until required to do so under the applicable procedural rules. These requirements are without prejudice to the obligations of the data importer under Clause 14(e).

(b) The data importer agrees to document its legal assessment and any challenge to the request for disclosure and, to the extent permissible under the laws of the country of destination, make the documentation available to the data exporter. It shall also make it available to the competent supervisory authority on request. The data exporter shall make the assessment available to the controller.

(c) The data importer agrees to provide the minimum amount of information permissible when responding to a request for disclosure, based on a reasonable interpretation of the request.

5.3.4. SECTION IV – FINAL PROVISIONS

Clause 16. Non-compliance with the Clauses and termination

(a) The data importer shall promptly inform the data exporter if it is unable to comply with these Clauses, for whatever reason.

(b) In the event that the data importer is in breach of these Clauses or unable to comply with these Clauses, the data exporter shall suspend the transfer of personal data to the data importer until compliance is again ensured or the contract is terminated. This is without prejudice to Clause 14(f).

(c) The data exporter shall be entitled to terminate the contract, insofar as it concerns the processing of personal data under these Clauses, where:

(i) the data exporter has suspended the transfer of personal data to the data importer pursuant to paragraph (b) and compliance with these Clauses is not restored within a reasonable time and in any event within one month of suspension;

(ii) the data importer is in substantial or persistent breach of these Clauses; or

(iii) the data importer fails to comply with a binding decision of a competent court or supervisory authority regarding its obligations under these Clauses.

In these cases, it shall inform the competent supervisory authority and the controller of such non-compliance. Where the contract involves more than two Parties, the data exporter may exercise this right to termination only with respect to the relevant Party, unless the Parties have agreed otherwise.

(d) Personal data that has been transferred prior to the termination of the contract pursuant to paragraph (c) shall at the choice of the data exporter immediately be returned to the data exporter or deleted in its entirety. The same shall apply to any copies of the data. The data importer shall certify the deletion of the data to the data exporter. Until the data is deleted or returned, the data importer shall continue to ensure compliance with these Clauses. In case of local laws applicable to the data importer that prohibit the return or deletion of the transferred personal data, the data importer warrants that it will continue to ensure compliance with these Clauses and will only process the data to the extent and for as long as required under that local law.

(e) Either Party may revoke its agreement to be bound by these Clauses where (i) the European Commission adopts a decision pursuant to Article 45(3) of Regulation (EU) 2016/679 that covers the transfer of personal data to which these Clauses apply; or (ii) Regulation (EU) 2016/679 becomes part of the legal framework of the country to which the personal data is transferred. This is without prejudice to other obligations applying to the processing in question under Regulation (EU) 2016/679.

Clause 17. Governing law

These Clauses shall be governed by the law of the EU Member State in which the data exporter is established. Where such law does not allow for third-party beneficiary rights, they shall be governed by the law of another EU Member State that does allow for third-party beneficiary rights. The Parties agree that this shall be the law of Finland.

Clause 18. Choice of forum and jurisdiction

(a) Any dispute arising from these Clauses shall be resolved by the courts of an EU Member State.

(b) The Parties agree that those shall be the courts of Finland.

(c) A data subject may also bring legal proceedings against the data exporter and/or data importer before the courts of the Member State in which he/she has his/her habitual residence.

(d) The Parties agree to submit themselves to the jurisdiction of such courts.