for MEF LSO API OIT Service
All rights reserved by Amartus Ltd. | 1st October 2021.
For the purposes of this Agreement:
- Amartus – Amartus Limited with headquarter located at 4/5 Burton Hall Road, Sandyford Industrial Estate, Sandyford, Dublin 18, Ireland;
- Amartus Email Address – firstname.lastname@example.org
- Authorized Email Address – Subscriber’s email address associated by the Subscriber with the Service;
- Confidential Information – all and any information given in writing, orally, by electronic data transmission or by any other means transferred by either party, regardless of whether the information is marked as proprietary or confidential; such information shall include, but is not be limited to, any information related to the Service or the disclosing party’s business, operations, processes, plans, product information, know-how, trade secrets, software, rules and concepts, documentation, customers or business affairs;
- Content – any information or data, including Personal Data, that is processed in connection with Service;
- Description– information about the Service provided at Description URL
- GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation);
- Personal Data – personal data within the meaning of Article 4(1) of the GDPR whose controller in the light of GDPR is Subscriber;
- Price List –remuneration that shall be paid, that is described in the Registration Portal at Customer Portal.
- Subscriber and is the overall entity who wishes to sell or buy services to/from partners via an MEF LSO APIs.
- Subscriber Personal Data – data described in annex 1 of the Amartus DPA, available at DPA URL and any other Personal Data Processed by Amartus or on behalf of the Subscriber pursuant to this Agreement.
- Testing Services – services that may be ordered by the Subscriber with the use of Portal and which can be accessed at the specific URL sent to the Authorized Email Address.
- Customer Portal – https://mef-oit.amartus.com
- Support Portal – https://mef-oit.atlassian.com/servicedesk/customer/portals
- Agreement URL – https://amartus.com/mef-oit-agreement
- DPA URL – https://amartus.com/mef-oit-dpa
- Description URL – https://amartus.com/mef-oit-description
- Support URL – https://amartus.com/mef-oit-support
2. General provisions
- This Agreement defines the rules of the provision of Service and use of Service by Subscriber. This Agreement takes effect when the person clicks the “I accept” button or similar in the registration form indicated in clause 2.5. Agreement remains in force until
- Rights concerning the Service are reserved and protected by copyright laws and treaties around the world.
- In order to use the Service, Subscriber shall be a member in good standing within the meaning of bylaws of MEF Forum, a California non-profit mutual benefit corporation, as indicated at: https://www.mef.net/mef-bylaws/ , throughout the whole period of this Agreement.
- Registration to the Service is carried out via an online registration form found at the Customer Portal.
- In order to register, the Subscriber shall provide required data in the registration form mentioned in clause 2.4, including an Authorized Email Address. Providing incomplete, incorrect or false data may prevent from registration and using Service.
- Amartus reserves the right to review the correctness of data provided in the registration form, especially by requesting specific data from the Subscriber. If Subscriber does not meet requirements for Subscriber, Amartus is allowed to prevent Subscriber from using Service.
- Acceptance of the Agreement means in particular that:
- any person acting on behalf of the Subscriber is duly authorized to represent the Subscriber,
- the Subscriber takes responsibility for use of the Service,
- the data provided in the registration form is correct.
- From the date of the successful registration as indicated in clause 2.4-2.6, the Customer Portal allows the Subscriber to order Testing Services. Testing Services shall be provided from the date of sending by Amartus specific URL to the Authorized Email Address till the time indicated in the Portal.
- Each person concluding this Agreement hereby represents and warrants that he or she has the authority to bind the Subscriber on behalf of which he or she has accepted the Agreement.
- Subscriber shall use the Service for its own benefit only. The Subscriber cannot resell, reproduce, duplicate, copy, sell, transfer, trade, re-provision, redistribute, or rent the Service, any portion of the Service, use of the Service, or access to the Service.
3. Use of Service
- The Subscriber shall comply with the Agreement and all laws, rules and regulations applicable to the Subscriber’s use of the Service, including any laws applicable to the Subscriber or the Subscriber’s industry.
- It shall be prohibited to use with regard to the Service any Content which Amartus objectively deems inappropriate, including Content that:
- is unethical or misleading,
- is offensive or threatens the privacy of persons,
- refers to illegal activities or incitement to illegal conduct in violation of applicable law, especially which infringes copyrights of third parties, brands, patents or other rights owned by third parties,
- represents harmful conduct or fraud that may lead to legal proceedings against Amartus, MEF or any other third party.
- The Subscriber shall not:
- undertake any action to undermine the integrity systems, network, software application or computing devices used in connection with the Service or any other client, nor gain unauthorized access to any system,
- breach any security or authentication measures used in connection with the Service, or probe, test, or scan the vulnerability of the Service, or any part of it,
- engage in any behaviour that may interfere with the proper functioning of the Service,
- attempt to modify, distribute, alter, tamper with, repair, reverse engineer, disassemble, decompile or apply any other process or procedure to derive the source code of any software included in Service or create derivative works of any data included in the Service,
- use the Service in any manner contrary to the intended purpose of the Service.
- disclose any Confidential Information in the way that violates section 8, including disclosure of any deliverables of the Service; however, the Subscriber may disclose deliverables of the Service to the third party, provided that the Subscriber and the third party are using Testing Services provided by Amartus at the time of disclosure of deliverables by the Subscriber.
4. Amartus obligations
- Amartus shall render the Service for the benefit of the Subscriber only. Rendering the Service means providing Amartus access to the Service. The Subscriber shall undertake all activities that are necessary to use the Service. The details of the Service are indicated in Description of Service, found at Description URL
- Amartus shall comply with laws applicable to the provision of Service. Amartus shall not comply with any laws applicable to the Subscriber or the Subscriber’s industry that are not applicable to IT service providers.
- The Subscriber hereby agrees that the Service may be provided with the engagement of subcontractors. Amartus indicates, that part of the Service is currently provided by Amazon Web Services EMEA SARL (38 Avenue John F. Kennedy, L-1855, Luxembourg) which is subject to AWS Customer Agreement Terms, which can be viewed at https://aws.amazon.com/agreement/. Subscriber acknowledges to have taken notice thereof and to accept the same without reservation. Amartus shall have no liability whatsoever for any damages or any other consequences that may incur as a result of the unavailability or malfunctioning of services provided by Amazon Web Services EMEA SARL due to their non- or improper performance.
- In relation to any part of Service, Amartus shall not be subject to any general monitoring obligation. Amartus shall not control or monitor the conduct or the actions put in place by the Subscriber. Therefore, Amartus shall not control or monitor the Content.
- Amartus may change or remove any functionality of Service or subcontractors used to deliver the Service at any time. Amartus may notify in writing the Subscriber of any material change or removal of any functionality; Subscriber is allowed to submit a complaint in such case according to section 11. Amartus bears no liability in the event of such change or removal.
- In order to maintain the performance and security of Service, Amartus performs scheduled maintenance. During such scheduled maintenance, the Service may be completely or partially unavailable to the Subscriber. The scheduled maintenance will take place at the date and time agreed in writing with the Subscriber.
- Following the date of Service termination, Amartus shall delete any Content, including any cached or backup copies, within 6 months. The Subscriber agrees that Amartus has no additional obligation to continue to hold, export or return Content. Prior to this, the Subscriber may, at its own discretion, download a copy of all the Content. Details of deletion of Content is given in Amartus DPA found at DPA URL.
5. Subscriber’s obligations
- The Subscriber shall pay remuneration in accordance with this Agreement.
- The Subscriber shall be liable and responsible for activities that occur under the Subscriber’s account in the Service.
- The Subscriber shall maintain the confidentiality of all information associated with the use of the Service according to Section 8. The Subscriber shall take appropriate actions to secure and protect access to Service.
- The Subscriber shall notify Amartus about any possible misuse of the Service or authentication credentials and of any security incident related to the Service.
- The Subscriber shall pay Amartus the remuneration for Testing Services as described in the Price List shown in Customer Portal URL. Registration indicated in clauses 2.4-2.6 is free of charge.
- Notwithstanding clause 13.4, Amartus may unilaterally increase or add new fees by giving at least 30 days prior notice in writing. If the specific Testing Services are being performed, increase or new fees concerning such Testing Services shall be applicable after the end of the term of performance of the above-mentioned Testing Services.
- All amounts payable under the Agreement shall be paid without set-off or counterclaim and without any deduction or withholding.
- All fees are exclusive of indirect taxes, levy or similar government charges that may be assessed by any jurisdiction. The Subscriber will pay all applicable indirect taxes that Amartus is legally obliged or authorized to collect from the Subscriber. If under applicable law, the Subscriber is required to withhold any tax on payment, then the amount of the payment will be automatically increased to totally offset such tax, so that the amount actually remitted, net of all taxes, equals the amount invoiced.
- If the Subscriber delays payment of applicable fees, the Subscriber is obliged to pay late payment interest rates according to the applicable law.
7. Privacy and security
- Content shall be used by Amartus only to provide or maintain the Service and as necessary to comply with the law or a binding order of a government body.
- Amartus shall treat Personal Data in accordance with the Agreement, including the data processing agreement provided as shown in DPA URL
- The Subscriber shall have all the necessary consents to enable Amartus to process Personal Data the Subscriber is willing to use with regard to the Service.
- The Subscriber is responsible for safe and secure access and use of Service and Content. The Subscriber acknowledges that Amartus shall be not liable if the Subscriber’s access and use are not safe and secure, including access and use from a public WLAN or Subscriber’s environment that is not configured in a secure and safe manner.
- In respect of the Confidential Information that is disclosed with regard to this Agreement, the receiving party shall:
- keep the Confidential Information strictly confidential and secret,
- make use of the Confidential Information only for the purpose of the Agreement,
- not disclose any Confidential Information to any third party without prior written consent from the other party.
- It shall be expressly agreed that Amartus is allowed to disclose the Confidential Information to its subcontractors.
- The obligations indicated in clause 1 above do not apply if:
- Confidential Information were publicly available when disclosed or thereafter become publicly available by the disclosure thereof without breach of any of the provisions of Agreement,
- Confidential Information were in possession of the receiving party without an obligation of confidentiality and not acquired directly or indirectly from the disclosing party,
- Confidential Information were legally obtained from a source other than the disclosing party without an obligation of confidentiality and where such a source is in lawful possession of the said information,
- Confidential Information were developed by the other party independently without any breach of the Agreement hereof and without the use of the Confidential Information received from the disclosing party,
- Confidential Information are subject to an obligation to be disclosed by law or any regulatory or government authority.
- In no event shall either party be liable to the other for special, indirect, punitive or consequential damages, or for any loss of profits relating to the obligations set forth hereunder.
- The total aggregate liability of Amartus with regard to this Agreement shall not exceed the lesser of $1,000 or the remuneration paid by the Subscriber within the first 12 months when the Agreement is in force. The limitations in this section 9 do not apply to liability for death or personal injury caused by Amartus gross negligence, fraud or fraudulent misrepresentation or any other liability which may not be limited or excluded by law.
- Amartus shall be not liable if:
- inability to use the Service is a result of maintenance, suspension, change or removal of any part of the Service,
- there was unauthorized access Service that led to alteration, deletion, destruction, damage, loss, or failure to store Content,
- an event is caused by an Internet access problem or related problems beyond the demarcation point of Service,
- Subscriber fails to adhere to any required configurations for the use of the Service or inputs bad data,
- there was an illegal or unlawful use of the Service,
- service provided to the Subscriber is marked by Amartus as a beta version” or “trial version” of the Service.
- The Subscriber shall indemnify and hold Amartus harmless and its affiliates and their respective employees, staff, subcontractors, customers and third parties from all claims and defend every claim in relation to the non- or improper performance of Agreement at the Subscriber’s sole expense. The Subscriber shall have the right to settle any claim only with the prior written consent of Amartus. Amartus shall notify the Subscriber about every claim in relation to the Subscriber without undue delay.
- Service is provided to the Subscriber “as is” and Amartus gives no warranty of any kind in relation to the Service and additional services or works indicated in section 12. However, the Service is provided with specific parameters (SLA) as provided in the Description of Service.
- Amartus gives no express or implied warranties including, but not limited to, express or implied warranties (or any terms, conditions, representations, undertakings or warranties which might otherwise be implied by statute, common law or the law of equity) of completeness, satisfactory quality, fitness for a particular purpose, non-infringement, compatibility, and accuracy regarding the Service
- Neither party shall be liable to the other party for failure to perform its obligations hereunder if and to the extent that such failure to perform results from causes beyond its control including, without limitation, power or telecommunication interruptions, civil disturbances, fires, acts of God, compliance with any regulation or requirement of any governmental body or agency.
10. Termination and suspension
- Either party may terminate the Agreement only in the following situations:
- in case of breach of this Agreement and if the breach is not curable or was not cured by the party in forty-five (45) days upon delivery of the notice in writing from the other party about a breach of this Agreement, the other party may terminate the Agreement with 30-days notice period,
- in case of a material breach of the Agreement by the party, the other party may terminate the Agreement without notice period.
- Amartus may terminate the Agreement without notice period, in case of termination of “Onboarding and interop test partner agreement” between Amartus and MEF Forum, a California non-profit mutual benefit corporation.
- Termination notice under this Agreement shall be in writing sent to Authorized Email Address or Amartus Email Address, otherwise null and void.
- Amartus may suspend part or whole Service if:
- the Subscriber’s use of the Service poses a security risk to the Service or Subscriber’s use of the Service could adversely impact systems or data of Amartus, its subcontractors or any Amartus client,
- in case of lack of payment of any part of due remuneration – if Amartus sends a notification in writing to the Subscriber about due payment and Subscriber does not pay the due payment within 30 days from receipt of notification.
- If Amartus suspends part or whole Service:
- the Subscriber remains responsible for all fees incurred during the period of suspension as if the Service had been provided,
- the Subscriber will not be entitled to any kind of compensation and suspension will be not considered as non-performance or improper performance of the Agreement, taking into consideration that it will result from circumstances for which only the Subscriber bears the responsibilities.
11. Complaints procedure
- Complaints concerning the Service may be submitted to the Amartus Email Address
- The complaint shall include:
- the name of the Subscriber,
- email address,
- telephone number,
- a precise description of any irregularities in the provision of the Service and the date of occurrence and duration of the irregularities indicated or invoice number, the date of its issuance and the irregularity found in the invoice.
- A complaint shall be submitted within a month from the date when the Service was improperly rendered or from the date of delivery of the invoice which contains irregularity.
- Amartus shall consider complaints and provide the Subscriber with a response within 30 days from the date of receiving the complaint from the Subscriber unless the Subscriber does not describe the subject of the complaint in a manner as provided in this Agreement. In this case, the period for considering the complaint begins on the day when the Subscriber provides the missing information.
- In complicated cases, the period referred to in clause 4 above may be extended to 45 days.
12. Additional services
As indicated in clause 4.1, the Subscriber shall undertake all activities that are necessary to use the Service. However, the Subscriber may assign Amartus with operating the Service on behalf of the Subscriber according to the separate agreement.
- The Subscriber shall not assign or otherwise transfer any rights and obligations under the Agreement without the prior written consent of Amartus. Amartus may assign any rights and obligations under the Agreement without the Subscriber’s consent to any affiliated company, especially in case of merger, acquisition, consolidation or similar transaction or to any purchaser of all or part of Amartus assets or to any similar successor.
- Parties agree that the Agreement is governed by the laws of Ireland. The parties agree that all disputes shall be resolved exclusively by the court in Dublin, Ireland.
- The Subscriber shall not imply any relationship or affiliation between Amartus and the Subscriber. The Subscriber shall not misrepresent or embellish the relationship between the Subscriber and Amartus, including by expressing or implying that Amartus supports, sponsors, endorses, or contributes to the Subscriber or the Subscriber’s business endeavours.
- Amartus may modify the Agreement at any time by posting a revised version at Agreement URL Amartus may, at any time, modify any information on the website to which reference is made in Agreement. However, Amartus may provide at least 30 days advance notice for changes to the Agreement. By continuing to use the Service after the effective date of any modifications to the Agreement, the Subscriber agrees to be bound by the modified Agreement.
- All amendments to the Agreement proposed by the Subscriber require the prior written consent of Amartus otherwise null and void.
- Any communication between the Subscriber and Amartus shall be done in English.
- If this Agreement indicates that activity shall be done in writing or in written form, such activity may be done by sending by Amartus information to Authorized Email Address.
- This Agreement constitute the entire agreement between Subscriber and Amartus, supersedes and replaces any prior or contemporaneous communications, understanding, representations or agreements between the Parties, whether oral or written and sets forth the entire complete and exclusive agreement and understanding between the Parties relating to the subject matter hereof.
- If any provision in the Agreement is found to be illegal or invalid, that clause shall be deemed removed and the remainder shall be unaffected. The parties shall endeavour to agree on an alternative clause having like effect, as a substitute for the provision that has been removed.
DATA PROCESSING AGREEMENT
This data processing agreement concerns commissioned processing of personal data according to the following sections.
The following regulations apply to all services of processing performed by Amartus for the Subscriber and to all activities in which employees of Amartus or third parties commissioned by Amartus may come into contact with personal data of the Subscriber.
In this data processing agreement, the terms “Process/Processing”, “Data Controller”, “Data Processor”, “Data Subject”, and “Personal Data Breach” shall have the same meaning as in the GDPR. Other definitions indicated in the Agreement shall apply.
- In the course of providing the services to the Agreement, Amartus may Process Subscriber Personal Data indicated in Annex 1 as Data Processor on behalf of the Subscriber. Amartus shall Process Subscriber Personal Data only for performance of the Agreement.
- The Subscriber represents and warrants that is the Data Controller or Data Processor of the Subscriber Personal Data and Processes them in accordance with the applicable law including GDPR.
- Amartus shall only Process the types of Subscriber Personal Data relating to the categories of Data Subjects as set out in Annex 1.
- Whenever the Subscriber modifies the list of Subscriber Personal Data indicated in Annex 1, the Subscriber is obliged to inform Amartus in writing in order to obtain Amartus consent for Processing of such modified Subscriber Personal Data.
- The Parties agree that Subscriber Personal Data shall be Processed in accordance with the Subscriber’s instructions, which shall be sent to the Amartus Email Address. Instruction relating to a change of scope or manner of provision of the services means assigning Amartus with additional works or services for which Amartus may claim additional remuneration.
- Amartus shall obligate all persons authorized to Process Subscriber Personal Data to confidentiality or ensure that they are subject to an appropriate statutory duty of confidentiality.
Term of the processing; deletion and return of Subscriber Personal Data
- The Subcriber Personal Data shall be Processed during the period of the provision of the services on the basis of the Agreement.
- Amartus makes available return of Subscriber Personal Data in accordance with the clause 4.7 of the Agreement. After the period indicated in clause 4.7 of the Agreement, Subscriber Personal Data shall be deleted.
Technical and organizational measures
- Amartus shall implement appropriate technical and organisational measures as indicated in Annex 2.
- Amartus is allowed to implement alternative adequate measures to those indicated in Annex 2 without necessity to amend this data processing agreement. The safety level of the measures shall not be undercut.
Cooperation with regard to Personal Data
- Amartus shall assist Subscriber as indicated in article 28.3 GDPR.
- If providing co-operation, assistance, support, report, providing details, information or adjustments requested by the Subscriber relating to Processing of Subscriber Personal Data, especially indicated in article 28.3.e-28.3 of GDPR, whatever is the basis for such activity of Amartus, generate or would generate any additional costs of Amartus or requires the involvement of additional resources, the Subscriber shall cover any reasonable costs specified by Amartus.
- Amartus is obliged to inform the Subscriber with undue delay if Amartus becomes aware of a personal data breach that has taken place with regard to this data processing agreement.
- Subscriber shall have the right to conduct an audit subject to the following terms and conditions:
- Amartus may make participation in such audit conditional upon prior execution of an appropriate confidentiality agreement;
- during an audit the Subscriber shall comply with internal procedures of Amartus;
- audit should not be conducted more frequently than once per calendar year and should not last longer than 1 day;
- Subscriber shall notify its intention to conduct an audit at least 30 days before the proposed date of an audit by sending an e-mail to Amartus Email Address;
- each party shall cover its own costs connected with an audit.
- The Subscriber does hereby give its consent to Processing of Subscriber Personal Data by subcontractors engaged in the light of the Agreement at the date of conclusion of the Agreement.
- The Subscriber gives its consent to engage another subcontractor for Processing of Subscriber Personal Data upon notification of the subcontractor to the Subscriber at least 14 days in advance by sending an e-mail to Authorized Email Address.
- Any Processing of Subscriber Personal Data to a third country or an international organisation by Amartus shall take place in compliance with Chapter V of GDPR. There is no requirement to obtain consent for the Processing of Personal Data in a third country or by an international organization apart from the consent mentioned in sections 1-2 above.
- The Parties agree that this data processing agreement shall be governed by the law applicable to the Agreement and will be subject to the jurisdiction agreed in the Agreement.
- Liability of either Party to the other Party to this data processing agreement for violation of applicable legislation relating to the Processing of Subscriber Personal Data or this data processing agreement shall be limited or excluded in accordance with the provisions of the Agreement.
- Termination or expiration of the Agreement shall result in termination or expiration of this data processing agreement, without the necessity for making any additional statements. Termination of this data processing agreement before termination of the Agreement is excluded.
- Categories of Data Subjects and type of Personal Data
- email address
- postal address
- phone number
- phone number extension
2. Categories of Data Subjects covered by this data processing agreement:
- …users of the Service
- …persons who are involved in the accounting process
Technical and organizational measures
Taking into account the state of the art, nature, scope, and purposes of the processing of personal data as well as the risk of infringements of rights and freedoms of natural persons, the data processor implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk levels for systems used and data categories. Therefore the data processor shall apply technical and organisational measures that ensure confidentiality, integrity, accountability and continuity of processed data. Such measures shall include:
- Making sure that only the persons who hold appropriate authorisations have access to the premises in which personal data is processed. Other persons may be present in the premises where data is processed only in the company of an authorised person;
- Locking of the premises being the data processing area for the time the employees are absent, in a manner preventing third party access;
- Use of locked cabinets and safes for document protection;
- Use of a paper shredder to effectively dispose of documents containing personal data;
- Protect the local area network against any actions initiated from the outside with the use of firewall hardware and software;
- Making backup files;
- Protection of the hardware used at the data processor’s against malware;
- Securing access to the company’s equipment with passwords;
- Use of data encryption to transmit data;
- Use of data encryption in the drives of the computers in which personal data may be stored.