Skip to content
Book a demo

General Terms and Conditions aizell® CRM – Subscription (SAAS)

1. Introduction

1.1 These General Terms and Conditions (“GTC”) govern the Customer’s use of the Services and I&A Group AB’s (“I&A”) provision of the Services. The Customer purchases access to the Services directly from I&A or from resellers selected by I&A. These GTC apply regardless of whether the Services have been provided free of charge or for a fee.

1.2 The Services are provided as “Software as a Service”, whereby the Customer, through the Agreement, purchases a subscription to the Services, which are made available online. When the Agreement enters into force, the Customer is granted, through the subscription and as of the Delivery Date, the right to access the Services and to use them in the manner set out in the Agreement. All parts of the Services are governed by the Agreement, including parts that are added, purchased or put into use after the Delivery Date.

1.3 By entering into the Agreement, the Customer accepts these GTC.

2. Definitions

In addition to the terms defined in the body of the Agreement, the following definitions shall have the meanings set out below.

2.1 Subscription Fee: Recurring fees under the Agreement charged by I&A for the Customer’s subscription to the Services.

2.2 User: A natural person, typically an employee of the Customer, who is authorised by the Customer to use the Services for the Customer’s own internal business purposes.

2.3 Agreement: The agreement between I&A and the Customer for the provision of the Services, these GTC and the appendices to the Agreement.

2.4 Documentation: All documentation, including manuals, user guides or other written, electronic or non-electronic descriptions of how the Services are set up and used.

2.5 Customer: The legal entity in whose name an account has been registered in the Services.

2.6 Customer Adaptations: A customer-specific adaptation of the Services for which the Customer does not purchase a separate licence, as further specified in the Agreement. A Customer Adaptation is not a Standard Product.

2.7 Customer Data: All data or information owned by the Customer and transferred by the Customer to or from the Services when the Customer uses the Services for the purpose of having such data or information processed by the Services.

2.8 Delivery Date: The date from which the Services are provided by I&A granting the Customer access to the Services without requiring any specific approval from the Customer.

2.9 I&A Administrator: The person or persons at the Customer responsible for the day-to-day administration of the Services.

2.10 Notices: Notices and information regarding the Services, such as information about operational disruptions, new versions, other information about the software, support, price adjustments or amendments to the GTC.

2.11 Standard Products: The software made available to the Customer by I&A under the Agreement, including fully or partially integrated Additional Services. The Customer purchases licences for Standard Products.

2.12 Support: Assistance provided by I&A to the Customer concerning difficulties in using Standard Products.

2.13 Additional Services: Separate individual functions or functional packages (add-ons) that the Customer may use in return for a Subscription Fee or, alternatively, a separate fee per transaction.

2.14 Services: Standard Products and Customer Adaptations.

2.15 Third-Party Application: Applications, software, websites, services or other solutions belonging to a party other than I&A, or another product defined in the Agreement as a Third-Party Application.

3. I&A’s Obligations

3.1 I&A shall provide the Customer with the Services from the Delivery Date. Additional Services and Customer Adaptations may be made available at a separate time. This shall not affect the Delivery Date.

3.2 I&A provides the Services on a subscription basis. The commitment period follows the contractual period under section 15.2 and is therefore three (3) months from the Delivery Date.

3.3 I&A shall provide the Services in accordance with the methods and standards normally used by I&A to deliver the Services (as set out in the Agreement) and in accordance with applicable rules and principles of good practice in the industry in which I&A operates.

3.4 I&A is entitled to engage subcontractors to fulfil I&A’s obligations under the Agreement. I&A shall be responsible for the performance of contractual obligations carried out by subcontractors as if they had been performed by I&A itself.

3.5 Unless otherwise stated in the Agreement, I&A is entitled, subject to compliance with the parties’ data processing agreement, to provide the Services from another country.

3.6 I&A shall ensure that the Customer has access to the latest versions of the Standard Products. The Customer is entitled to assistance with updates at the applicable consultancy rate or otherwise in accordance with the Agreement.

3.7 I&A continuously works to improve the Services and the Customer’s user experience. I&A shall update the Services (including the Agreement) to the extent I&A considers necessary for the provision of the Services. I&A is also entitled to make other updates or changes to the Services. I&A shall inform the Customer in writing one (1) week before any update or change (including an improvement or addition) to the Services that results in a material change to the Services. The Customer shall be deemed informed of material changes to the Services when I&A has sent a Notice to the I&A Administrator by email or by means of a digital message within the Services.

3.8 When providing the Services, I&A shall maintain adequate administrative, physical and technical security measures. I&A shall regularly perform backups to reduce the risk of loss of Customer Data. In the event of large-scale user errors, the Customer may submit a request to I&A to restore the most recent backup. Restoration entails an additional charge at the applicable consultancy rate.

4. Customer’s Obligations

4.1 The Customer undertakes to use the Services in accordance with the Agreement, applicable laws, regulations or other rules, and to comply with instructions issued by I&A from time to time regarding the use of the Services. The Customer is responsible for ensuring that Users use the Services in accordance with the Agreement.

4.2 When the Customer, by entering into the Agreement, purchases a subscription to the Services, the Customer is entitled, from the Delivery Date, to use the Services during the contractual period for the number of Users for whom the Customer has purchased subscriptions. The Customer may, at any time during the contractual period, increase the number of Users by adding more licences and purchase the right to use fully or partially integrated Additional Services in accordance with the price list applicable from time to time or the Agreement. New Users added shall be included in the same contractual period under section 15.2 as the other Users.

4.3 Only Users with a paid and valid licence are entitled to use the Services. User accounts are created and administered by the Customer. Licences may not be shared or used by more than one User. However, the Customer may freely transfer a licence from one User to another. I&A reserves the right to check the number of licences being used.

4.4 The Customer acknowledges that security and reliability are of the utmost importance to I&A. The Customer therefore undertakes to provide I&A with all information reasonably requested for the purpose of setting up and providing the Services and to promptly notify I&A of changes to such information.

4.4.1 The Customer is responsible for (i) keeping all passwords and account details confidential; (ii) immediately notifying I&A if the Customer suspects or becomes aware of unauthorised access to the Services or any other security incident; and (iii) maintaining and using all equipment, software, applications, communication services and procedures, including the security of the Customer’s IT environment, required to use the Services or otherwise reasonably instructed by I&A from time to time. For the avoidance of doubt, I&A is not responsible for the Customer’s hardware or software, including uploaded files or data, or for unauthorised use of user accounts or the Services.

4.4.2 The Customer shall indemnify and hold I&A harmless against all costs and claims arising from the Customer’s use of the Services in breach of this Agreement, including this section 4.4. A breach by the Customer of this section 4.4 shall constitute a material breach of the Agreement.

4.5 The Customer undertakes to have access to the software, equipment and communication services required to use the Services, such as web browsers, PDF readers, toolbars, antivirus software and firewalls. I&A will provide information about these requirements upon request. The Customer is responsible for ensuring that such third-party software is correctly installed and permits traffic to the web addresses specified by I&A. I&A is not responsible for the performance of internet services or for how internet service providers perform their services. The Customer’s internet access used to access the Services is neither installed, maintained nor established by I&A. I&A has no control over the internet. I&A is not responsible for interruptions or disruptions in the operation of any part of the internet, nor is it responsible for any regulation of the internet.

4.6 The Customer undertakes not to use the Services in any manner (i) that is unlawful or for a purpose for which the Services are not intended, including transmitting or uploading viruses or other harmful files or code; (ii) that may impair the functionality of the Services or in any way harm or disrupt other users and their use of the Services or equipment; (iii) that may be perceived as abusive or offensive in any situation; or (iv) that may otherwise reasonably be expected to adversely affect I&A or the Services or reflect negatively on the goodwill, name or reputation of I&A or the Services. The Customer is responsible for ensuring that Users, when using the Services, do not violate applicable laws, regulations or other rules, including but not limited to the Swedish Act (1960:729) on Copyright in Literary and Artistic Works and the Swedish Marketing Act (2008:486), and that Users do not transmit offensive, threatening, abusive, defamatory or otherwise objectionable data or information to the Services.

4.6.1 If the Customer, in breach of this section 4.6, uses the Services to send unwanted, unsolicited digital communications, such as advertising messages and attempted fraud (spam), to companies and this results in I&A’s sending IP addresses being temporarily blacklisted, for example by Spamcop, I&A is entitled to immediately stop further mailings by the Customer until the cause of the blacklisting has been investigated. If the Customer’s improper use under this section 4.6 also results in hosting providers’ sending IP addresses being blacklisted, the Customer shall reimburse I&A for all costs incurred in changing IP addresses.

4.6.2 The Customer shall not attempt in any way to gain unauthorised access to the Services or information contained in the Services.

4.6.3 The Customer shall not copy, modify, create derivative works of, reverse engineer or otherwise attempt to discover any source code in the Services, or assign, license or transfer any right in the Services or any part of the Services. Nor may the Customer copy, interfere with or otherwise make unauthorised use of certificates or other equipment belonging to a third party.

4.6.4 If the Customer’s improper use of the Services in breach of this section 4.6 results in a court ruling against the Customer or a reprimand from the Swedish Consumer Agency for improper use of the Services, I&A is entitled to terminate the Agreement with immediate effect in accordance with section 15.4. Any fees paid in advance will not be refunded.

4.6.5 I&A accepts no direct or indirect liability for the Customer’s improper use of the Services in breach of this section 4.6 and shall be indemnified and held harmless against all costs and claims arising from the Customer’s use of the Services in breach of the Agreement, including this section 4.6. A breach by the Customer of this section 4.6 shall constitute a material breach of the Agreement.

5. Licence

5.1 The Customer is granted a limited, terminable, non-exclusive and non-transferable licence to use the Services in accordance with the Agreement for the Customer’s internal business operations, in return for payment of the fees under the Agreement or the price list applicable from time to time. Payment of fees under the Agreement and fulfilment of all the Customer’s obligations under the Agreement are necessary conditions for the Customer’s right to use the Services.

5.2 Under no circumstances is the Customer entitled to transfer or assign, in whole or in part, any licence for the Services to a third party (including but not limited to in connection with mergers and demergers, bankruptcy, changes in ownership or control, or to affiliated companies) unless prior written approval has been obtained from I&A.

5.3 The Services are provided as is. The Customer’s right to use the Services is not conditional upon or dependent on any particular version of the Services or functionality at any particular time, but grants access to and the right to use the Services as provided at any given time. The provision of the Services is not conditional upon the delivery of future versions or functionalities, nor is it dependent upon Documentation made available by I&A from time to time.

6. Availability

6.1 I&A shall provide secure delivery of the Standard Products to the Customer.

6.2 The Standard Products are normally available via the internet twenty-four hours a day, seven days a week. I&A (and I&A’s subcontractors) are entitled to take measures affecting this availability if I&A considers them necessary for technical, service, operational or security-related reasons. Planned service interruptions due to system maintenance will be notified to the Customer in advance.

6.3 Unplanned service interruptions may occur. To the extent I&A is responsible for, and able to influence, such interruptions, I&A shall promptly remedy the fault.

7. Support

7.1 The Agreement entitles the Customer to Support. Support is provided to the person at the Customer designated as the I&A Administrator. All Support shall be reasonable in relation to the Subscription Fee.

7.2 Unless otherwise stated in the Agreement, I&A provides Support via the internet, email and telephone (Monday to Friday, excluding public holidays, 08:00–17:00). Support requests submitted by email are normally answered no later than the next business day. Support cases received by telephone are prioritised according to the order in which they are received.

7.3 On the day before a public holiday, I&A reserves the right to keep Support closed. If this occurs, it will be announced on I&A’s website.

7.4 Support for Customer Adaptations is provided at the applicable consultancy rate.

7.5 Support does not include (i) providing instructions or training Users regarding information contained in the Documentation; (ii) providing instructions or training Users regarding other systems and services that may be required for the functionality of the Services (such as web browsers or PDF readers); (iii) making customer-specific adaptations to the Services; (iv) remedying errors caused by actions performed by anyone other than I&A or a subcontractor engaged by I&A, or by careless and/or incorrect handling by the Customer; (v) remedying errors caused by a third-party product or service connected to the Services; (vi) remedying errors resulting from faults in the Customer’s technical equipment; or (vii) errors caused by malicious code. Furthermore, I&A’s Support does not include remedying faults in networks, operating systems or other software provided by third parties. Support therefore does not include Windows, MS Office, printers, email software, etc.

8. Data Processing and Privacy

8.1 The Customer’s use of the Services may involve the transfer of personal data from the Customer to I&A. In such cases, under Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (“GDPR”), I&A shall be regarded as the data processor in respect of personal data processed by I&A on behalf of the Customer under the Agreement, and the Customer shall be regarded as the data controller. In accordance with the requirements of the GDPR, I&A and the Customer shall enter into a data processing agreement governing I&A’s processing of the Customer’s personal data in accordance with the Agreement. The data processing agreement forms an appendix to the Agreement, Appendix 1.

8.2 As between I&A and the Customer, the Customer holds all rights to the Customer Data, and I&A acquires no rights, other than those set out in the Agreement, to the Customer Data or any part thereof. I&A is entitled to use the Customer Data during the term of the Agreement to provide the Services to the Customer.

8.3 I&A shall under no circumstances be responsible for the content of or ownership of the Customer Data. Nor shall I&A be responsible for any instructions regarding processing or measures relating to the Customer Data that the Customer gives to its Users or to I&A, or for other measures carried out by the Customer’s Users when using the Services.

8.4 I&A shall exercise due care to secure transfers of information between the Customer and the Services. However, as the internet is an open system, I&A cannot and does not guarantee that third parties will not be able to obtain possession of or alter the Customer Data or its transmission. I&A shall have no liability for such accidental misuse, disclosure or loss of Customer Data.

8.5 I&A may collect information about the use of the Services through automated data collection tools. I&A collects and uses such information for the purpose of safeguarding, maintaining and improving products and services, and for statistics and various types of analysis. Any personal data collected for the development and improvement of the Services is fully anonymised. I&A may also contact Users with information relevant to the Services and collect information about the use of the Services through automated data collection tools for the purpose of contacting Users with information relevant to the Services, including targeted product news and information about relevant functions in the Services. Such information processing and communication with Users may involve certain processing of personal data for which I&A is the data controller. The Customer hereby expressly consents to I&A processing personal data for communication with Users. I&A shall limit the processing of personal data for this purpose to what is necessary to achieve that purpose. I&A shall apply appropriate security measures to the processing. I&A may engage data processors for the processing. When engaging data processors for such processing of personal data, I&A shall enter into data processing agreements with those data processors. The Customer undertakes to inform Users of I&A’s privacy policy, which describes this processing of personal data.

8.6 Unless otherwise stated in the Agreement, including the data processing agreement, I&A shall not sell, rent, lease or otherwise make Customer Data available to third parties, except in the following circumstances: (i) to comply with applicable laws, regulations, rules or decisions by an authority; (ii) to investigate or prevent security threats or fraud; and (iii) where required in connection with a reorganisation, merger, sale or purchase of all or part of I&A. If I&A discloses Customer Data under this section 8.6, I&A shall, provided that this is consistent with applicable law, notify the Customer that the Customer Data is being disclosed and, to the extent possible, ensure that the receiving party complies with the GTC.

8.7 The Customer may request an export of the Customer Data. Such a request may be made at any time during the term of the Agreement but must be submitted no later than thirty (30) days before the Agreement ends. I&A’s export of Customer Data shall be charged at the applicable consultancy rate in accordance with the current price list. After the Agreement ends, the Customer Data in the Services will be deleted, and it is the Customer’s responsibility to retain the information by other means.

9. Pricing and Payment Terms

9.1 The Customer shall pay the fee for the Services in accordance with the prices made available by I&A from time to time. Any other specific fee for the Services shall be specified in the Agreement.

9.2 I&A continuously develops the Services, resulting in increased functionality for the Customer. I&A reserves the right to change the Subscription Fee annually. Such price adjustment shall be based on (i) a general price adjustment by I&A, or (ii) Statistics Sweden’s Consumer Price Index (“CPI”) in accordance with section 9.2.1. The price adjustment shall take effect at the first invoicing date occurring after the date specified in I&A’s notice of the price adjustment. The Customer shall be notified of the price adjustment at least thirty (30) days before it takes effect.

9.2.1 I&A is entitled, in accordance with this section 9.2, to adjust the Subscription Fee based on the CPI for October of the year defined below as “n-2”. The adjustment shall be based on the percentage change in the CPI for the period between October n-2 and October n-1. If the price change is negative, the current Subscription Fee shall remain unchanged. A CPI-based price adjustment shall therefore be calculated as follows:

(index figure October n-1 / index figure October n-2) * current Subscription Fee = new Subscription Fee

n = the year in which the price adjustment is to take effect

n-1 = the year preceding n

n-2 = the year preceding n-1

9.3 Information about how the Customer wishes to make payment shall be provided to I&A no later than the day before the first invoicing date. Any parts of the Services that are subject to a per-transaction fee shall be charged in arrears unless otherwise stated in the Agreement. Unless otherwise stated in the Agreement, the Subscription Fee shall be charged one (1) month in advance.

9.4 Unless otherwise stated in the Agreement, payment terms are fourteen (14) days. Fees, such as administration fees, shall be charged in accordance with the terms applied by I&A from time to time. VAT shall be added to the stated prices.

9.5 In the event of late or incomplete payment, I&A is entitled to default interest in accordance with the Swedish Interest Act (1975:635) and reminder fees and/or debt collection fees in accordance with applicable laws. If payment has not been received by I&A on the due date and the Customer has failed to remedy the situation despite a reminder from I&A, I&A shall, in addition to any other remedies available under the Agreement, be entitled to (i) suspend the Services and/or (ii) terminate the Agreement with immediate effect in accordance with section 15, provided that the payment obligation is not disputed on objective and reasonable grounds and on the basis of I&A’s breach of the Agreement.

10. Intellectual Property Rights

10.1 I&A, or its licensors, is the sole owner of all intellectual property rights (“IPR”) relating to the Services, including the Documentation and the software included therein. IPR includes, but is not limited to, rights in copyright, patents, trademarks, company names, designs and product designs, source code, databases, business plans and know-how, in all cases regardless of whether such rights are registered, and all applications for any such rights.

10.2 All copyrights, trademarks, registered trademarks, product names, company names or logos appearing in or in connection with the Services are the property of their respective rights holders. I&A is not responsible for links to, or the content of, web pages or Documentation not owned or controlled by I&A that are referenced in the Services or accompanying web pages or Documentation.

10.3 The Customer grants I&A the right to use the Customer’s company name and trademark for marketing purposes.

10.4 The Services may be integrated with Third-Party Applications to make content, products and/or services available to Users. To the extent Third-Party Applications are included in the Services, the Third-Party Application provider’s terms governing use, licensing, liability, correction of errors and IPR shall apply instead of the Agreement. I&A shall therefore not be responsible for damage caused by a Third-Party Application and does not endorse or assume responsibility for the behaviour, functionality or content of any Third-Party Application or any transaction that a User may enter into with the provider of such Third-Party Application.

10.5 The Customer is responsible for damage caused by the Customer to I&A arising from the Customer (i) infringing I&A’s or a third party’s IPR, or (ii) using the Services in breach of section 4.6. The Customer’s liability for damages in respect of such damage shall amount to the greater of: (i) an amount equivalent to the Subscription Fees for five (5) years for the then-current licences, or (ii) the actual damage. The Customer acknowledges that I&A may suffer irreparable harm in the event of infringement of or damage to I&A’s IPR. I&A or its licensors are entitled to take all reasonable measures to protect their commercial interests and property, including all measures available under applicable law, such as interim measures.

11. Liability for Defects and Warranty

11.1 I&A warrants that the Standard Products will function substantially as described in the Agreement. The Customer and I&A agree that the Standard Products and their delivery are not entirely free from errors and that improvements to the Standard Products are an ongoing process. The Customer acknowledges that the Standard Products are delivered as is and are used at the Customer’s own risk.

11.2 I&A does not warrant that the Standard Products (i) will meet the Customer’s specific expectations regarding, for example, purpose or functionality beyond the warranties provided by I&A in the Agreement; (ii) will function correctly with the Customer’s choice of equipment, systems or settings; or (iii) will be uninterrupted or free from errors.

11.3 Neither I&A nor any of its licensors provides any warranty, express or implied, regarding fitness for a particular purpose or system integration capability. I&A makes no representations about the characteristics of the Standard Products other than those specifically stated in the Agreement, and the Customer shall not rely on any representations not expressly stated in the Agreement.

11.4 If the Standard Products do not function in accordance with the limited warranty stated above, I&A shall correct all established errors or defects in the Standard Products at its own expense. I&A shall remedy reported errors in the Standard Products that seriously affect their functionality as soon as possible. However, I&A reserves the right to determine when and how an error shall be corrected and when and how a corrective measure shall be carried out. Errors that do not seriously affect the Customer’s use of the Standard Products and/or the functionality of the Standard Products shall be remedied by I&A no earlier than the next official version of the Standard Products.

11.5 I&A’s liability for defects under section 11.4 applies provided that (i) the Customer notifies I&A of the defect no later than thirty (30) days after the Customer discovered or should have discovered it, and (ii) the Customer provides I&A with the information and data required for I&A to address the defect.

12. Limitation of Liability

12.1 I&A’s liability in respect of damage or other loss (regardless of how such damage or loss is caused, including damage or other loss caused by negligence) arising under or in connection with this Agreement shall be limited as set out below.

12.1.1 Under no circumstances shall I&A be liable for damage caused by or related to (i) third parties, third-party products or services for which I&A is not responsible under the Agreement (including but not limited to Third-Party Applications); (ii) modifications or changes to the Services, or to other services not included in the Services, made in accordance with instructions from the Customer or its suppliers or carried out by anyone other than I&A; or (iii) the Customer’s loss of customers, profit, revenue, savings or goodwill, losses due to network disruptions, or other indirect damage.

12.1.2 I&A’s aggregate and total liability under the Agreement shall, during each contractual period, be limited to an amount corresponding to the Subscription Fees for the Services for that same contractual period.

12.2 In order not to lose its right to damages under this section 12, the Customer shall submit its claim for damages to I&A no later than three (3) months after the Customer became aware or should have become aware of the basis for the claim, and in any event no later than six (6) months from the date on which the damage occurred.

12.3 Except as expressly stated in this Agreement, the Services are provided “as is” and I&A provides no warranties, express or implied, in relation to the Services, including as to completeness, accuracy, reliability, satisfactory quality and/or fitness of the Services for any particular purpose.

12.4 The limitations of liability under this section 12 shall not apply in cases of (i) wilful misconduct or gross negligence, (ii) liability that cannot be limited or excluded under applicable law, and (iii) indemnification under section 13, Indemnification.

13. Indemnification

13.1 The Customer shall defend and indemnify I&A and hold I&A harmless against third-party claims based on the Customer Data or the Customer’s use of the Services in breach of the Agreement violating or infringing that third party’s IPR or applicable law.

13.2 The Customer’s liability under section 13.1 includes all costs, fees, expenses, losses or damages incurred by I&A under a settlement confirmed or ordered in court or arbitration proceedings, or a court judgment or arbitral award, including reasonable legal fees.

13.3 The Customer’s obligation to indemnify and hold I&A harmless under this section 13 applies only if: (i) I&A immediately notifies the Customer in writing of the claims made against I&A; (ii) the Customer is given full control of the legal proceedings and sole decision-making authority in settlement negotiations, and the settlement releases I&A from all liability; and (iii) I&A cooperates with the Customer at the Customer’s expense, for example by following the Customer’s instructions and providing reasonable assistance in relation to the legal proceedings.

14. Confidentiality

14.1 I&A and the Customer undertake not to disclose to any third party, without the other party’s written consent, information about the other party’s business that may constitute business or professional secrets or that is subject to a statutory duty of confidentiality, regardless of whether such information is oral, written, electronic or in any other form (“Confidential Information”). Confidential Information does not include information that a party can demonstrate became known to that party otherwise than through the Agreement or that is publicly known.

14.2 The confidentiality obligation under this section 14 shall not apply where a party is required to disclose information under applicable laws, regulations, rules or decisions by an authority.

14.3 Each party is responsible for its respective employees’ and consultants’ compliance with this section 14 and shall ensure compliance with this section 14.3 through confidentiality undertakings with them or other appropriate measures.

14.4 Each party’s confidentiality obligation under the Agreement shall apply during the term of the Agreement and for a period of five (5) years after the Agreement has ended.

15. Contractual Period and Termination

15.1 The Agreement enters into force when it has been signed by both parties or, alternatively, when the Customer has registered an account in the Services or otherwise commences use of the Services.

15.2 Unless otherwise stated in the Agreement, the Agreement shall remain in force for three (3) months from the Delivery Date. Unless either party has given notice of termination no later than thirty (30) days before the end of this initial period, or any subsequent renewal period if the Agreement has been renewed in accordance with this section 15.2, the Agreement shall automatically renew for a period of three (3) months.

15.3 Termination by the Customer in respect of one or more Users shall be regarded as termination of part of the Agreement and shall therefore be carried out in accordance with section 15.2 above.

15.4 In addition to any other rights under the Agreement, the Customer and I&A are entitled to terminate the Agreement in writing with immediate effect if: (i) the other party materially breaches the Agreement and fails to remedy that breach within thirty (30) days after the breach has been notified in writing; or (ii) the other party is declared bankrupt, enters into liquidation, becomes subject to corporate restructuring proceedings, suspends payments or may otherwise reasonably be assumed to have become insolvent.

15.5 Repeated delays by the Customer in paying fees in accordance with the Agreement shall constitute a material breach of the Agreement.

15.6 Upon termination of the Agreement under section 15.2 and upon termination by I&A under section 15.4, the Customer shall not be entitled to a refund of any fees paid in advance.

15.7 Notice of termination of this Agreement, whether in its entirety or in respect of certain parts or a certain number of Users, shall take effect from the date on which the other party received the notice of termination.

15.8 If notice of termination of the Agreement is given, the Customer’s access to the Services shall be disabled after the Agreement ends. However, upon termination by I&A under section 15.4, I&A is entitled to suspend the Services in their entirety with immediate effect.

15.9 If the Customer withdraws an order after the Agreement has been entered into, I&A reserves the right to invoice actual costs plus 25 per cent of the Subscription Fee for the Services for the first three (3) months.

15.10 An Agreement for which notice of termination has been given may be entered into again. Entering into the Agreement again automatically entails a new commitment period of three (3) months under section 15.2. When entering into the Agreement again, the Customer acknowledges that the Customer Data has been deleted from the Services.

16. Notices

16.1 Notices are published on the website www.aizell.se, sent by email or provided digitally within the Services.

16.2 Notices shall be deemed delivered when they have been published or, if sent by email, when they have been sent by I&A.

16.3 Notices shall take effect immediately unless otherwise specifically stated in the Notice.

16.4 Notices from the Customer to I&A concerning the Agreement shall be sent by email by the I&A Administrator to the address stated on I&A’s website.

17. Miscellaneous

17.1 Conflicting contractual terms. The Agreement and its appendices supplement one another. If the agreement between I&A and the Customer for the provision of the Services and these GTC contain conflicting terms, the agreement between I&A and the Customer for the provision of the Services shall take precedence.

17.2 Amendments to the GTC. I&A reserves the right to amend the GTC and other terms for the provision of the Services by giving thirty (30) days’ notice. If the Customer does not accept such an amendment, the Agreement may be terminated immediately in accordance with section 15.4. If the Customer terminates the Agreement under this section 17.2, the Customer is entitled to a proportionate refund of any fees paid in advance.

17.3 Force majeure. Neither I&A nor the Customer shall be liable for delays or interruptions in the performance of their obligations under the Agreement caused by or arising from a force majeure event, such as an earthquake, riot, labour dispute or other event similarly beyond I&A’s or the Customer’s control.

17.3.1 If legislation, regulations or rules relating to the Services or their provision are amended, or new legislation, regulations or rules enter into force after the Services have been made available on the market, and this prevents I&A from complying with the Customer’s instructions or I&A’s obligations under the Agreement, and/or requires the Services to be suspended, in whole or in part, for a specified or indefinite period, this shall constitute a force majeure event. I&A shall under no circumstances be liable for such a force majeure event. In such cases, the Customer shall be reimbursed for the Subscription Fee paid in advance for the affected Services from the month following the suspension of the Services due to the force majeure event. Beyond this, the Customer shall not be entitled to make further claims against I&A as a result of a force majeure event.

17.4 Surviving obligations. Provisions of the Agreement that by their nature are intended to remain in force after the Agreement ends shall continue to bind the parties after the Agreement has ended, regardless of the reason.

17.5 Invalidity. If a competent court, authority or arbitral tribunal finds any provision of the Agreement to be invalid, in whole or in part, or unenforceable, this shall not affect the validity of the remaining provisions, which shall remain valid and enforceable to the extent permitted by applicable law. In such cases, the provision in question shall be replaced by a provision that achieves the purposes of the original provision to the greatest extent possible.

17.6 Entire agreement. The Agreement constitutes the parties’ entire agreement concerning its subject matter. Any written or oral undertakings and representations preceding the Agreement are replaced by the contents of the Agreement.

18. Governing Law and Disputes

18.1 This Agreement shall be interpreted and applied in accordance with Swedish law.

18.2 Disputes arising out of this Agreement shall be resolved amicably between the parties. If a dispute cannot be resolved amicably, disputes arising out of this Agreement shall be finally settled by arbitration administered by the Arbitration Institute of the Stockholm Chamber of Commerce (SCC).

18.3 The Rules for Expedited Arbitrations shall apply unless the SCC, taking into account the complexity of the case, the amount in dispute and other circumstances, determines that the Arbitration Rules shall apply. In the latter case, the SCC shall also decide whether the arbitral tribunal shall consist of one or three arbitrators. The seat of arbitration shall be Stockholm. The language of the proceedings shall be Swedish and Swedish law shall apply, unless otherwise agreed. The parties undertake, without limitation in time, not to disclose the existence or contents of any arbitral award arising out of this Agreement or information about negotiations, arbitration proceedings or mediation relating to it. The provisions of this section shall not restrict I&A’s right to take necessary legal action before a competent court to recover overdue receivables.

Appendix 1 – Data Processing Agreement aizell

This data processing agreement (the “Agreement”) has been entered into between the Customer (as defined in the General Terms and Conditions aizell CRM – Subscription (SAAS)) and I&A Group AB (“I&A”). The Customer is the data controller and I&A is the data processor, hereinafter referred to as the “Controller” and the “Processor”, respectively, or as a “party” or collectively as the “parties”. For the parties’ cooperation on data protection, for example in connection with data requests and personal data breach notifications, the Processor shall use the Controller’s designated representative under the Main Agreement as the contact person.

1. Background

1.1 The Controller and the Processor have entered into an agreement for a licence or subscription to the Processor’s software products (the “Main Agreement”), which entails the Processor Processing Personal Data on behalf of the Controller.

1.2 The Agreement governs the Processor’s Processing of Personal Data on behalf of the Controller. The parties have entered into this Agreement to comply with the requirements of Applicable Data Protection Legislation.

1.3 This Agreement takes precedence over conflicting or incompatible provisions concerning the Processing of Personal Data in the Main Agreement. This Agreement is dependent upon, and is not valid without reference to, the Main Agreement.

1.4 The parties confirm that their representatives are authorised to enter into the Agreement.

2. Definitions

2.1 In addition to the terms defined in the body of the Agreement, the following definitions shall have the meanings set out below.

2.2 Personal Data: Any information relating to an identified or identifiable person (the data subject).

2.3 Data Subject: An identified or identifiable natural person. An identifiable person is someone who can be identified, directly or indirectly, in particular by reference to an identification number or to one or more factors specific to that person’s physical, physiological, mental, economic, cultural or social identity.

2.4 Processing (of Personal Data): Any operation or set of operations performed on Personal Data, whether or not by automated means, such as collection, recording, organisation, storage, adaptation or alteration, retrieval, consultation, use, transmission, dissemination or otherwise making available, alignment or combination, blocking, erasure or destruction.

2.5 Controller: A natural or legal person, public authority, institution or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data.

2.6 Processor: A natural or legal person, public authority, institution or other body which processes Personal Data on behalf of the Controller.

2.7 Applicable Data Protection Legislation: Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (“GDPR”), and national laws implementing or supplementing the GDPR that apply to the Processing of Personal Data under this Agreement.

2.8 Third Country: A country outside the EU/EEA.

3. Processing of Personal Data

3.1 The Processor shall only Process Personal Data in accordance with this Agreement and documented instructions from the Controller, unless the Processor is required by EU law (including national laws of its Member States) to Process the Personal Data.

3.2 The Controller shall provide the Processor with written instructions on how to carry out the Processing.

3.3 The Processor shall Process Personal Data throughout the contractual term specified in the Main Agreement and for a limited period thereafter (see section 12).

Appendix 1A contains information about the Processing of Personal Data, including i) categories of personal data, ii) categories of data subjects, iii) the nature and purpose of the Processing, iv) the location of the Processing, and v) the duration of the Processing.

4. Processor’s Obligations

By signing the Agreement, the Processor confirms the following.

4.1 The Processor shall only carry out the Processing in accordance with the Agreement and the instructions. For clarity, the Processor may process Personal Data if such processing is required by applicable law to which the Processor is subject. The Processor shall inform the Controller of such requirements unless providing that information is prohibited on important grounds of public interest. When Processing Personal Data under the Agreement, the Processor shall comply with Applicable Data Protection Legislation.

4.2 The Processor shall ensure that all natural persons working under its authority who have access to Personal Data comply with the Agreement and the Controller’s instructions.

4.3 During the Processing, the Processor and its personnel shall observe a duty of confidentiality and secrecy in respect of the Personal Data to which they gain access under this Agreement. This provision shall also apply after the Agreement ends.

4.4 The Processor shall implement the security measures required under Article 32 of the GDPR.

4.5 To the extent possible, the Processor shall assist the Controller in fulfilling its obligations towards Data Subjects by implementing appropriate technical and organisational measures.

4.6 At the Controller’s request, the Processor shall assist the Controller in ensuring compliance with the obligations under Articles 32–36 of the GDPR, taking into account the nature of the processing and the information available to the Processor.

4.7 The Processor shall immediately inform the Controller if the Processor considers the Controller’s instructions unclear or in any way contrary to Applicable Data Protection Legislation. The Processor shall not carry out such an instruction until the Controller has confirmed that the instruction is lawful.

5. Controller’s Obligations

By signing the Agreement, the Controller confirms the following.

5.1 The Agreement fulfils the Controller’s obligation to establish an agreement concerning the Processing of Personal Data under Applicable Data Protection Legislation.

5.2 When using the services provided by the Processor under the Main Agreement, the Controller shall process Personal Data in accordance with Applicable Data Protection Legislation. The Controller is responsible for ensuring that a lawful basis for the Processing exists at all times and for preparing correct instructions so that the Processor (and its subcontractors) can fulfil its undertakings and obligations under the Agreement and, where applicable, the Main Agreement.

5.3 The Controller is authorised to process and disclose the Personal Data covered by the Main Agreement to the Processor (including any subcontractors of the Processor).

5.4 The Controller is solely responsible for the accuracy, integrity, content, reliability and lawfulness of the Personal Data disclosed to the Processor. The Processor shall not be responsible for any consequences arising from Personal Data received proving to be incorrect.

5.5 The Controller has fulfilled its obligations under Applicable Data Protection Legislation to provide Data Subjects with mandatory information about the Processing of Personal Data, the transfer of Personal Data to the Processor and the Processor’s Processing of that Personal Data.

5.6 When using the services provided by the Processor under the Main Agreement, the Controller shall not transfer any sensitive Personal Data to the Processor.

5.7 The Controller shall inform the Processor without delay of any change to its contact person or that person’s contact details.

6. Security Measures

6.1 The Processor shall comply with the general security requirements set out in Article 32 of the GDPR. The Processor shall therefore ensure an appropriate level of security for the Processing, including the confidentiality, integrity and availability of Personal Data, through systematic, organisational and technical measures, taking into account the state of the art and the costs of implementation in relation to the risk associated with the Processing.

6.2 Documentation of this shall be made available at the Controller’s request. The Processor is therefore obliged to give the Controller access to information about security controls and other measures implemented by the Processor to protect Personal Data and comply with Applicable Data Protection Legislation. If the Controller requests information about security controls beyond the standard information provided by the Processor, the Processor may charge the Controller for such additional services and assistance.

6.3 The Processor has developed internal data protection rules intended to protect the confidentiality, integrity and availability of Personal Data. The following measures are particularly important in this context:

  1. Data communications. During external transmission, Personal Data shall be protected against improper access and interference through technical functionality, such as encryption.
  2. Authorisation controls. Access to Personal Data shall be restricted by prohibiting personnel from obtaining, processing and/or using Personal Data without authorisation and for purposes other than delivering the service under the Main Agreement and fulfilling the obligations under this Agreement.
  3. Protection against vulnerabilities. The Processor shall actively work to detect and prevent incidents caused by technical vulnerabilities.
  4. Access protection. Computer equipment and storage media shall be protected against unauthorised use, interference and theft.
  5. Backups. Personal Data shall be backed up regularly. The copies shall be stored separately and well protected so that the Personal Data can be restored after a disruption.
  6. Transfer. Components and systems involved in the processing and transfer of Personal Data between the parties (the Controller and the Processor, including subcontractors) are mapped and documented.

7. Audits and Supervision

7.1 The Processor shall give the Controller access to all information necessary to demonstrate that the obligations under the Agreement have been fulfilled and shall allow for and contribute to audits, including inspections, carried out by the Controller or a third party designated by the Controller.

7.2 The Controller may audit the Processor’s compliance with the Agreement up to one (1) time per year. If required by Applicable Data Protection Legislation, the Controller may require more frequent audits.

7.3 To request an audit, the Controller shall submit a detailed audit plan to the Processor at least four weeks before the proposed audit, specifying its scope, duration and proposed start date. If the audit is to be carried out by a third party, this must, as a general rule, be agreed between the Controller and the Processor. If processing takes place in an environment containing Personal Data originating from other controllers or similar, the Processor may, at its own discretion and for security reasons, decide that the audit shall be carried out by a generally well-regarded auditing firm selected by the Processor.

7.4 If the requested audit has already been carried out and documented in a report under ISAE 3402, ISO or a similar standard by a qualified third-party auditor within the preceding twelve months, and the Processor confirms that the audited controls have not materially changed, the Controller shall accept those results instead of requesting an audit of the controls covered by the report.

7.5 The audit shall be carried out during the facility’s normal business hours in accordance with the Processor’s policies and shall not unreasonably disrupt the Processor’s operations.

7.6 The Controller is responsible for all costs incurred in connection with an audit requested by the Controller and the Processor’s assistance in this respect.

7.7 The Processor shall allow the supervisory authority, or another authority legally entitled to do so, to conduct supervision at the authority’s request in accordance with the legislation applicable from time to time. The Processor and its personnel shall, upon request, cooperate with the supervisory authority in the performance of its tasks.

8. Assistance to the Controller

8.1 Taking into account the nature of the Processing and to the extent possible, the Processor shall assist the Controller through appropriate technical and organisational measures so that the Controller can fulfil its obligation to respond to requests to exercise Data Subjects’ rights.

8.2 To the extent practicable and lawful, the Processor shall notify the Controller of (i) requests for disclosure of Personal Data received from a Data Subject, unless the Controller has authorised the Processor to respond to such a request; and (ii) requests by authorities for disclosure of Personal Data, unless the Controller has authorised the Processor to respond to such a request.

8.3 However, the Processor may be prevented from notifying the Controller due to the confidentiality of a preliminary investigation in a law enforcement matter. The Processor shall not disclose information about this Agreement to authorities in relation to Personal Data, except where required by law or pursuant to a court order, search warrant or similar measure.

8.4 Taking into account the nature of the Processing and the information available to the Processor, the Processor shall assist the Controller in ensuring compliance with the obligations under Applicable Data Protection Legislation, including, where applicable, the Controller’s obligation to i) implement appropriate technical and organisational measures, ii) notify the supervisory authority of personal data breaches, iii) inform Data Subjects of personal data breaches, iv) carry out data protection impact assessments, and v) consult the supervisory authority before Processing.

8.5 The Processor shall notify the Controller in writing without undue delay after becoming aware of a personal data breach. The Processor shall provide the Controller with a description of the personal data breach. If the Processor does not have all relevant information about the personal data breach at the time of its initial notification, the Processor may provide such information in phases.

8.6 The Processor is entitled to charge the Controller for work performed and reasonable costs incurred in connection with the Processor’s assistance as described above and under Applicable Data Protection Legislation. This includes, for example, work and costs arising from Data Subjects requesting access to records concerning the Processing of their Personal Data, erasure of Personal Data, transfer of Personal Data (portability), or the provision of mandatory information to Data Subjects.

9. Use of Subcontractors

9.1 As part of the delivery to the Controller of the services provided by the Processor under the Main Agreement, the Processor is hereby granted general prior written authorisation to use subcontractors to process Personal Data on behalf of the Controller.

9.2 The Processor shall ensure that all subcontractors are bound by written agreements imposing obligations concerning the Processing of Personal Data that are at least equivalent to those set out in this Agreement.

9.3 If a subcontractor fails to fulfil its obligations under Applicable Data Protection Legislation, the Processor shall remain fully liable to the Controller for the performance of the subcontractor’s obligations.

9.4 The Processor shall make available an updated and current list of subcontractors used to perform the services provided by the Processor under the Main Agreement. The list shall include information about the identity of each subcontractor, the contact person at the subcontractor, where the Personal Data is processed and a general description of the type of service each subcontractor provides. The list of subcontractors is available on I&A’s website. By signing this Agreement, the Controller approves the Processor’s use of the listed subcontractors.

9.5 The Processor shall notify the Controller of plans to engage a new subcontractor or replace an existing subcontractor. The Controller may object to such changes. If no objection is made within ten (10) days of receipt of the notice, the Controller shall be deemed not to have objected.

9.6 The Processor is entitled to take appropriate corrective measures in response to such an objection. If the Controller considers that no corrective measures are available, or if the objection has not been resolved within thirty (30) days, the Processor is entitled, by written notice, to terminate the Agreement and, if the Agreement is necessary for the Processor to perform its obligations under the Main Agreement, the Main Agreement.

10. Transfer of Personal Data to Third Countries

10.1 The Processor and its subcontractors may transfer Personal Data to a Third Country to the extent necessary to perform the services provided by the Processor under the Main Agreement and provided that the transfer complies with Chapter V of the GDPR.

10.2 When using standard contractual clauses (Commission Implementing Decision (EU) 2021/91 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council, or decisions and standard contractual clauses replacing them), the Processor or the subcontractor is entitled, at its own discretion, to determine which version and which modules of the standard contractual clauses apply in each individual case.

10.3 In accordance with the requirements of Applicable Data Protection Legislation for transfers based on the implementation of appropriate safeguards, the Processor shall carry out a risk assessment in each individual case to ensure that the legislation of the relevant Third Country does not adversely affect the effectiveness of the appropriate safeguards and that effective legal remedies are available to Data Subjects. Where necessary, the Processor shall identify and implement additional safeguards, such as technical, organisational or contractual measures, to ensure that the level of protection in the relevant Third Country is essentially equivalent to the level of protection within the EU/EEA.

10.4 Section 10.3 and the risk assessments carried out by the Processor under section 10.3 do not limit the Controller’s responsibility for the Processing of Personal Data under Applicable Data Protection Legislation. The Controller acknowledges that it must carry out its own risk assessments and may not rely on the risk assessments carried out by the Processor or any additional safeguards implemented by the Processor as satisfying the requirements applicable to the Controller’s Processing of Personal Data under Applicable Data Protection Legislation.

10.5 At the Controller’s reasonable request, the Processor shall provide an account of the information on which the risk assessment is based. The Controller is entitled to object in writing to the Processor’s risk assessments if they change after the Agreement enters into force and the Controller considers that the new risk assessments do not meet the requirements applicable to the Controller’s Processing of Personal Data under Applicable Data Protection Legislation. The Controller is entitled to request that the Processor take appropriate corrective measures. If the parties do not agree on the risk assessment and/or appropriate corrective measures within thirty (30) days, the Processor is entitled, by written notice, to terminate the Agreement and, if the Agreement is necessary for the Processor to perform its obligations under the Main Agreement, the Main Agreement.

10.6 If the Court of Justice of the European Union, the European Commission or any other competent EU institution, national court or authority finds that the transfer mechanism used for the transfer to a Third Country is invalid or unlawful, the Processor shall ensure that all Processing of Personal Data in a Third Country is based on another valid transfer mechanism.

11. Term

11.1 This Agreement shall remain valid for as long as the Processor processes Personal Data on behalf of the Controller under the Main Agreement.

11.2 This Agreement shall automatically cease to apply when the Main Agreement ends.

12. Measures upon Termination of the Agreement

12.1 Upon termination of this Agreement, the Processor shall, as instructed in writing by the Controller, erase or return all Personal Data Processed on behalf of the Controller under the Agreement, together with all copies of the data, unless storage of the Personal Data is required by Applicable Data Protection Legislation.

12.2 If the Controller has not provided any instructions or responded to the Processor’s request for instructions sixty (60) days after the Agreement ends, the Processor shall return all Personal Data to the Controller and then erase the personal data.

13. Confidentiality

The Processor shall not, during the term of the Agreement or thereafter, provide third parties with information about the Processing of Personal Data carried out under this Agreement or otherwise disclose information received as a result of the Agreement. The confidentiality obligation does not apply to information that the Processor is required to provide to authorities. In addition to this section 13, the confidentiality undertakings in the Main Agreement shall also apply.

14. Amendments and Additions

14.1 Amendments to this Agreement may be made due to changes in legislation, security requirements or other practical circumstances. If an amendment affects the Processing of Personal Data under this Agreement, the other party shall be notified by email to its contact person as specified above. Such notice of amendment shall be deemed accepted by the other party unless that party has raised reasonable objections in writing no later than thirty (30) days from the date of notification.

14.2 If a competent court, authority or arbitral tribunal finds any provision of this Agreement to be unenforceable or invalid, the remaining provisions shall not be affected. The parties shall also replace the unenforceable or invalid provision with a lawful provision that reflects its purpose.

15. Liability

Unless otherwise required by mandatory law, liability for breaches of the provisions of this Agreement shall be governed by the liability clauses in the Main Agreement between the parties. This also applies to breaches committed by the Processor’s subcontractors.

16. Governing Law and Jurisdiction

16.1 This Agreement shall be interpreted and applied in accordance with the governing law provisions of the Main Agreement.

16.2 Disputes arising out of the Agreement shall be finally settled in accordance with the dispute resolution provisions of the Main Agreement.

This Agreement forms an appendix to the Main Agreement. By signing the Main Agreement, the parties accept this Agreement in its entirety.

Appendix 1A – Instructions for the Processing of Personal Data

Categories of Personal Data

The Controller may enter Personal Data into the service provided by the Processor under the Main Agreement. The Personal Data entered into the service is entirely at the Controller’s discretion and may, for example, include the following categories of Personal Data:

  • Name.
  • Telephone number.
  • Email address.
  • Customer history.

Categories of Data Subjects

The Controller may enter Personal Data into the service provided by the Processor under the Main Agreement. The Personal Data entered into the service is entirely at the Controller’s discretion and may, for example, include personal data relating to the following categories of data subjects:

  • The Controller’s employees, customers, suppliers and consultants.
  • Employees of the Controller’s prospective customers.

Nature and Purpose of the Processing

Processing of Personal Data to provide the services supplied by the Processor under the Main Agreement and in accordance with the Controller’s instructions.

Location of the Processing

  • The Processor Processes Personal Data within the EU/EEA.
  • For Processing by subcontractors, see the list of subcontractors.

Duration of the Processing

Processing of Personal Data will take place during the term of the Main Agreement and for a limited period thereafter in accordance with the Agreement. The Processor shall cooperate with the Controller to determine how long the Personal Data shall be stored by the Controller