Legal
General Terms and Conditions
Platform and Services
- Version
- j
- Date
- 05 October 2026
- Vendor
- ModernPath OyBusiness ID 3567407-2 / VAT FI35674072Kimmeltie 10, 90630 OULU, Finland
These General Terms and Conditions ("GTC") govern access to and use of the ModernPath Platform (software-as-a-service) and related professional services provided by Vendor to a business customer ("Customer").
The GTC form part of the Agreement between Vendor and Customer together with the applicable Service Specification(s), the Data Processing Agreement ("DPA"), and the accepted offer ("Offer").
1.Definitions
1.1 "Affiliate" means an entity that controls, is controlled by, or is under common control with a party.
1.2 "Agreement" means the documents described in Section 2.
1.3 "Authorized User" or "User" means an individual member of Customer Personnel who is authorized by Customer to access the Services under Customer’s account for Customer’s business operations, including providing services to Clients. Authorized Users do not include Client Personnel or other third parties unless they hold a separate valid license or subscription for the Platform.
1.4 "Customer Content" means data, materials, code, repositories, documentation, tickets, prompts, inputs, and other content submitted to or made available to the Services by or on behalf of Customer.
1.5 "Input" means Customer Content provided to the Services. "Output" means content generated by the Services in response to Input.
1.6 "Documentation" means Vendor’s then-current documentation for the Services.
1.7 "Connected Work Management Environment" means each separately administered external ticketing, issue-tracking, backlog-management, project-management, service-management, or requirements-management environment that is connected to the Platform for reading, syncing, indexing, analyzing, creating, updating, or otherwise acting on work-management records. Examples include a Jira site or workspace, an Azure DevOps organization or equivalent workspace, a ServiceNow instance, or another comparable third-party work-management environment. Multiple projects, boards, queues, or workspaces within the same separately administered environment count as one Connected Work Management Environment unless the applicable Offer or Price List expressly states otherwise.
1.8 "Customer-Controlled Deployment" means a deployment of the Platform in infrastructure controlled by, dedicated to, or separately designated for Customer, including customer cloud, private cloud, dedicated hosted infrastructure, or on-premises deployment.
1.9 "Price List" means Vendor’s then-current commercial price list for the Services, including available Subscription Periods, Renewal Periods, term-based discounts, chargeable metrics, counting rules, and token or resource pricing models, as incorporated into the Agreement under Section 2.
1.10 “Renewal Period" means the renewal period for the relevant ordered Services as stated in the Offer or, if none is stated, the renewal period determined under Section 11.
1.11 "Separate Environment" means a separately provisioned, independently configured, and independently operated instance of the Platform or a Hosted Environment, whether production, staging, test, disaster-recovery, or otherwise. Each Separate Environment counts separately unless the applicable Offer or Price List expressly states otherwise.
1.12 "Subscription Period" means the initial or renewal period for the relevant ordered Services as stated in the Offer and applicable Price List.
1.13 "Professional Services" means consulting, implementation, training, project work, Kickstart, Kickstart Plus, Managed AI Development, and other services described in an Offer and/or SOW.
1.14 "Services" means the Platform and/or Professional Services ordered by Customer.
1.15 "Usage Limits" means the usage limits and metered limits applicable to the ordered Services, as defined in the Service Specification, Offer, and/or applicable Price List, including limits or charges by Users, lines of code, Connected Work Management Environments, Customer-Controlled Deployments, Separate Environments, or other stated metrics.
1.16 "Vendor Technology" means the Platform, software, processes, methods, templates, workflows, tooling, orchestration logic, interfaces, documentation, and any improvements thereof owned or licensed by Vendor or its licensors/suppliers, excluding Customer Content and Customer-specific Work Product (as defined below).
1.17 "Work Product" means deliverables created specifically for Customer under paid Professional Services (e.g., analyses, documentation, architectural materials, plans, recommendations, code and code modifications, scripts, or configurations), as identified in the applicable Offer and/or SOW.
1.18 "Approved Jurisdiction" means a jurisdiction and Customer/Users not prohibited by applicable sanctions/export restrictions and not prohibited by Vendor’s legal/compliance obligations.
1.19 "Platform" means software-as-a-service products provided by Vendor digitally to Customer over the Internet and, where separately agreed, through a Customer-Controlled Deployment or other separately agreed deployment model.
1.20 “Confidential Information” means all non-public information disclosed by or on behalf of a party (“Disclosing Party”) to the other party (“Receiving Party”), whether in written, electronic, oral, visual, or other form, that is designated as confidential or that reasonably should be understood to be confidential given the nature of the information and the circumstances of disclosure. Confidential Information includes, without limitation, business plans, technical information, product information, security information, pricing, and the terms of the Agreement.
1.21 “Customer Confidential Information” means Confidential Information disclosed by or on behalf of Customer, including Customer Content and Customer source code.
1.22 “Representatives” means a party’s employees, officers, directors, affiliates, agents, contractors, subcontractors, advisors (including legal and financial advisors), and other service providers who have a legitimate need to know Confidential Information for purposes related to the performance or receipt of the Services under the Agreement.
1.23 "Client" means any customer, client, or end customer to whom Customer provides services or deliverables.
1.24 "Client Personnel" means any employee, contractor, or subcontractor of a Client.
1.25 "Customer Personnel" means Customer’s employees and individual contractors or subcontractors engaged by Customer who act for and under the direction and supervision of Customer.
2.Agreement structure and precedence
2.1 The Agreement consists solely of: (a) the Offer accepted by Customer, including any applicable SOW attached to or referenced by the Offer; (b) the applicable Service Specification(s); (c) the DPA, for personal data processing matters; (d) these GTC; and (e) the applicable Price List, for commercial matters only to the extent referenced in the Offer, Service Specification, or these GTC. Customer acknowledges that Vendor’s then-current privacy notice (the “Vendor Privacy Notice”) applies to Vendor’s independent-controller processing of personal data and is referenced for informational purposes only, and not as a contractual term of this Agreement; as between Customer and Vendor, the DPA shall govern any processing of personal data by Vendor on behalf of Customer in connection with the Services. For clarity, no OEM Agreement or VAR Agreement forms part of a direct Customer Agreement.
2.2 Offer scope (commercial particulars only). The parties agree that each Offer is intended to include only the following items (the “Permitted Order Matters”): (a) the Services ordered; (b) subscription start date, Subscription Period, and Renewal Period; (c) fees, currency, invoicing cadence, and payment terms; (d) the applicable Price List or Price List reference; (e) chargeable metrics, quantities, metering selections, and any quantity changes, including Users, lines of code, Connected Work Management Environments, Customer-Controlled Deployments, Separate Environments, and any other agreed metrics; (f) selected support or service level options expressly offered by Vendor; (g) Professional Services scope and pricing model, as described in an attached or referenced SOW; (h) hosting, region, cloud environment, and other configuration selections expressly offered by Vendor; (i) approved expense budget or handling for Professional Services; and (j) Customer’s opt-out of marketing or reference rights, if exercised.
2.3 No deviation from legal terms via Offer. Except for Permitted Order Matters, an Offer does not amend or override the GTC, Service Specification(s), or DPA. Any term in an Offer (including any added clauses, customer procurement terms, purchase-order terms, click-through or portal terms, or handwritten changes) that purports to modify intellectual property, confidentiality, data protection, acceptable use, warranties, indemnities, limitations of liability, governing law, dispute resolution, or any other legal terms is void and of no effect unless set out in a separate written amendment that (i) expressly identifies the sections being amended, and (ii) is signed by Customer and an Authorized Vendor Signatory. For purposes of this Section, “Authorized Vendor Signatory” means Vendor’s CEO, CFO, General Counsel, or another Vendor officer expressly authorized in writing to amend the Agreement. Customer acknowledges that Vendor sales personnel, resellers, channel partners, and other representatives are not authorized to agree to deviations from the legal terms except through such an amendment. An authorized reseller or other channel partner may present or sign an Offer on behalf of Vendor only to the extent separately authorized by Vendor, and no such authorization permits amendment of the legal terms of the Agreement unless expressly approved in writing by an Authorized Vendor Signatory.
2.4 Precedence. If there is a conflict, the following order of precedence applies, to the extent of the conflict:
(a) the DPA prevails for Processing of Customer Personal Data;
(b) the applicable SOW prevails over the Service Specification solely for project-specific Professional Services scope, milestones, dependencies, delivery dates, and objective acceptance criteria expressly stated in that SOW;
(c) the Service Specification prevails for standardized service descriptions, support levels, deployment options, usage definitions, and counting rules;
(d) the Offer prevails only for Permitted Order Matters selected for the specific transaction; and
(e) these GTC prevail in all other respects. No Offer or SOW amends legal terms except by a written amendment signed by an Authorized Vendor Signatory.
The Vendor Privacy Notice does not form part of the Agreement and does not affect the foregoing order of precedence.
3.Eligibility and compliance
3.1 Business customers only. Customer represents it is acting in the course of business and not as a consumer.
3.2 Authority. Each person accepting the Agreement represents they have authority to bind the relevant party.
3.3 Approved Jurisdictions. Customer will ensure the Services are used only from Approved Jurisdictions. Vendor may decline to provide Services where required for compliance.
4.Services
4.1 Platform subscription. During the applicable Subscription Period, Vendor grants Customer a non-exclusive, non-transferable right for Authorized Users to access and use the Platform for Customer’s business operations, including providing services to Clients, subject to the Agreement and Usage Limits. Customer may use the Platform in performing services for any number of Clients, subject only to the aggregate Usage Limits and chargeable metrics under the Agreement and provided Customer has all required rights and permissions for the relevant Customer Content. No such use grants any access or use right to Client Personnel or other third parties. Any such party that wishes to access or use the Platform must hold its own valid license or subscription.
4.2 Professional Services. Vendor will provide Professional Services as described in an Offer and/or SOW using commercially reasonable skill and care. Vendor may provide Professional Services through affiliates/subcontractors, and Vendor will cause them to comply with applicable confidentiality and security obligations. Vendor shall restrict the access to Customer Content to personnel who require such access to perform the Professional Services and who are bound by written confidentiality obligations no less protective than those in this Agreement. Vendor shall comply with the Customer’s security and access control policies when accessing Customer Content, provided that such policies have been communicated to Vendor in writing in advance.
4.3 Changes to Services; Customer termination right. Vendor may update, modify, replace, or discontinue all or part of the Services (including features, models/providers, integrations, and user interface) from time to time. If Vendor makes a change that materially reduces the core functionality of the Services purchased under the applicable Offer, Vendor will use commercially reasonable efforts to notify Customer in advance (except where changes are required for security, legal compliance, or to address an operational emergency). Customer may terminate the affected Services at will by written notice to Vendor following such change, and Customer’s sole and exclusive remedy for such change is termination of the affected Services. If Customer has prepaid fees for the terminated period, Vendor will refund the unused portion on a pro-rata basis.
5.Customer responsibilities
5.1 Customer responsibilities. Customer is responsible for: (a) Users’ compliance with the Agreement; (b) ensuring it has all rights, permissions, and authority necessary to provide Customer Content, including any third-party or client code, data, documentation, tickets, prompts, or other materials, and to permit Vendor to process it as contemplated by the Agreement; (c) maintaining appropriate security controls, access management, and configurations for Customer accounts and connected systems; (d) reviewing, testing, validating, and approving Output, including code and documentation, before use, deployment, or reliance; (e) ensuring Customer’s use of the Services and any Output complies with applicable laws and regulations and Customer’s internal policies, standards, and requirements; and (f) not permitting any customer, client, end customer, or other third party to access or use the Platform without a separate valid license or subscription, except that Customer may authorize its employees, contractors, and subcontractors at any tier to access and use the Platform under Customer’s license or subscription solely on Customer’s behalf to develop, maintain, or support Customer’s own products and services, whether for internal use or commercial offering. Such persons are Users for purposes of the Agreement, remain subject to the applicable license or subscription limits, and may not use that access for their own purposes or for other customers. Customer remains responsible for their compliance with the Agreement.
6.AI-specific terms (probabilistic outputs; human review)
6.1 Probabilistic systems. Customer acknowledges the Services use probabilistic AI systems (including large language models). The same or similar Input may produce different Output at different times.
6.2 No guarantee of correctness. Output may be incomplete, inaccurate, non-functional, insecure, biased, or otherwise unsuitable for Customer’s purposes.
6.3 Customer responsibility. Customer is solely responsible for reviewing, testing, validating, and approving Output (including code) before use, deployment, or reliance, including in production environments.
6.4 Safeguards. Vendor and its suppliers/service providers implement safeguards and controls intended to improve safety and reliability; however, Customer remains responsible for decisions and actions taken based on Output.
6.5 Open-source and third-party rights. Output may include or resemble third-party content and may be subject to third-party licenses. Customer is responsible for license compliance, security scanning, and verification.
7.Usage Limits and enforcement
7.1 Usage Limits. Customer’s use of the Services is subject to the Usage Limits and chargeable metrics stated in the Service Specification, Offer, and applicable Price List.
7.2 Measurement. Usage measurement rules and counting rules, including counting of Users, lines of code, Connected Work Management Environments, Customer-Controlled Deployments, Separate Environments, and any other ordered metrics, are defined in the Service Specification and/or applicable Price List. Vendor may update reasonable measurement methodologies prospectively, provided no completed billing period is retroactively restated except to correct manifest error.
7.3 Overuse and excess quantities. If Customer exceeds ordered quantities or Usage Limits, Vendor may require Customer to purchase additional quantities, reduce use to the ordered scope, apply any overage or quantity-adjustment mechanism expressly stated in the Offer or Price List, throttle usage, and/or suspend access for material or persistent overuse.
7.4 No circumvention. Customer will not circumvent or attempt to circumvent Usage Limits or technical restrictions. Such circumvention is a material breach.
8.Acceptable Use and Fair Use Policy
8.1 Lawful use. Customer will not use the Services in violation of applicable law or third-party rights.
8.2 Prohibited conduct. Customer will not, and will not permit any User, Affiliate, contractor, service provider, or other third party to:
(a) introduce malware, exploit vulnerabilities, or attempt unauthorized access;
(b) reverse engineer, decompile, disassemble, decode, decrypt, inspect, observe, benchmark, or otherwise attempt to derive, discover, reconstruct, access, view, or obtain any source code, object code, underlying structure, sequence, organization, non-public APIs, non-public interfaces, data models, schemas, architecture, workflows, prompts, guardrails, policies, model weights, parameters, training methods, trade secrets, or other non-public aspects of the Platform, any Hosted Environment, the Services, or the Vendor Technology;
(c) use any administrative, root, infrastructure, hypervisor, network, storage, backup, logging, monitoring, observability, container, image, artifact, repository, or similar access available in any dedicated, on-premises, customer-cloud, or other customer-controlled deployment to inspect, capture, export, copy, reproduce, analyze, disclose, or otherwise make use of any non-public aspect of the Platform, the Services, or the Vendor Technology, except solely to the limited extent strictly necessary to operate the authorized deployment in accordance with the Documentation and this Agreement;
(d) bypass, disable, defeat, or circumvent any safety mitigation, telemetry, license control, technical restriction, encryption, obfuscation, usage limit, access control, separation mechanism, or security feature of the Services;
(e) copy, modify, adapt, translate, mirror, scrape, frame, republish, distribute, sublicense, disclose, create derivative works from, or otherwise make available any non-public aspect of the Platform, the Services, or the Vendor Technology, except as expressly permitted by this Agreement;
(f) remove, alter, or obscure any proprietary notice, legend, attribution, watermark, or other identifier relating to the Platform, the Services, or the Vendor Technology;
(g) use the Services, the Platform, or any non-public information obtained from them to build, train, benchmark, validate, or improve any competing product, service, model, or system with substantially similar functionality; or
(h) assist, direct, or authorize any person to do any of the foregoing.
8.3 Customer-controlled deployments. Where the Services are deployed in Customer’s environment or in an environment under Customer’s control, including any on-premises, dedicated, or customer-cloud deployment, all software, containers, virtual machines, binaries, images, scripts, configurations, deployment artifacts, logs, technical metadata, and related materials made available as part of such deployment remain Vendor Technology and Vendor Confidential Information. Customer’s administrative, physical, or infrastructure-level access to such environment does not grant Customer any ownership right, inspection right, disclosure right, source-code right, or other right in or to the Platform, the Services, or the Vendor Technology except the limited right to operate the authorized deployment during the applicable term in accordance with this Agreement. Customer shall apply least-privilege controls, restrict such access to personnel with a strict operational need to know, and promptly notify Vendor of any actual or suspected unauthorized access, copying, extraction, disclosure, or use.
8.4 Non-waivable law; prior notice. To the extent Customer believes non-waivable applicable law grants Customer a right to perform any act otherwise restricted by this Section 8, Customer shall first provide Vendor with prior written notice describing the legal basis and the information or access requested in reasonable detail, and shall give Vendor a reasonable opportunity to provide the relevant information or functionality through other means. Customer may not exercise any such claimed right in a manner that exceeds the minimum extent required by such non-waivable law or that permits disclosure of Vendor Confidential Information to any third party except as strictly required by such law.
8.5 Fair Use; protective action. Vendor may throttle, suspend, restrict, or terminate access for unreasonable, abusive, prohibited, or unauthorized use, including attempts to avoid plan limitations or to access, inspect, extract, or misuse non-public aspects of the Platform, the Services, or the Vendor Technology. Vendor’s preferred remedy for ordinary commercial overuse is to discuss an upgrade or revised commercial arrangement; however, Vendor may act immediately where reasonably necessary to protect the Services, Vendor Technology, Vendor Confidential Information, Customer Content, other customers, or third-party provider environments.
9.Support and service levels
Support levels, support hours, and any service level targets are defined in the Service Specification and/or Offer. Response times are targets, not guarantees, and Vendor does not commit to fixed resolution times unless expressly agreed in writing. Support may be delivered by Vendor directly or through designated support providers.
Support “SLA” scope. Any service levels or “SLA” referenced in the Agreement relate solely to support levels (such as support hours and response targets) as set out in the Service Specification and/or applicable Offer. Vendor does not provide any uptime, availability, or service continuity guarantee unless an uptime/availability commitment is expressly stated in the applicable Offer for a specific service or hosted environment.
10.Professional Services delivery and acceptance
10.1 Acceptance-by-silence. Unless the applicable SOW expressly states objective acceptance criteria, test method, and acceptance period for specified Work Product, Work Product is deemed accepted 14 days after delivery unless Customer provides written notice of material non-conformity in reasonable detail.
10.2 Remedy. If Work Product is rejected within the acceptance window for material non-conformity, Vendor will use commercially reasonable efforts to correct and re-deliver.
10.3 Customer dependencies. Customer will provide timely access, decisions, and required credentials. Delays caused by Customer may adjust schedules and fees.
11.Fees, invoicing, and taxes
Fees, currency, Subscription Period, Renewal Period, billing cadence, minimum commitments if any, invoicing schedule, and payment terms are stated in the Offer and applicable Price List. Fees for each Subscription Period are fixed at the rates in effect on the start date of that Subscription Period. At the end of each Subscription Period, the affected Services renew automatically for the Renewal Period stated in the Offer, or if none is stated, for a further period equal to the expiring Subscription Period, unless either party gives at least thirty (30) days’ written notice of non-renewal before the end of the then-current period. Each renewal is priced under the then-current Price List applicable on the renewal start date, including the discount then applicable to the selected Renewal Period. Customer may request a different available Renewal Period before renewal, but any such change requires Vendor’s written confirmation or a renewal Order. Fees exclude VAT and applicable taxes unless stated otherwise.
External Resource fees; tokens. Customer may procure tokens and similar third-party metered resources either by using Customer-provided credentials or provider accounts (“BYOT”) or by purchasing Vendor-provided tokens or resources, as stated in the Offer and applicable Price List. Where Vendor-provided tokens or other External Resources are used, Customer shall pay the corresponding charges separately from subscription fees in accordance with the Offer and applicable Price List. Such charges may vary based on actual consumption, provider pricing, model availability, provider changes, or similar third-party commercial changes, and will be invoiced as stated in the Offer or Price List.
12.Expenses (Professional Services)
12.1 Default rule. Professional Services fees exclude travel, accommodation, and other out-of-pocket expenses. Vendor will not incur billable expenses without Customer’s prior written approval (including email). Approved expenses will be invoiced at cost unless the applicable SOW states a capped budget or a different arrangement.
12.2 Tools; customer-specific items; third-party licenses. Vendor will, at its own cost, provide customary personal working tools and general-purpose software used for Professional Services delivery (e.g., laptops and standard development/communication tools). Customer-specific tools, special equipment, environments, and third-party licenses or paid services required to access or work within Customer’s systems (other than customary computing equipment and standard services) are excluded from Professional Services fees unless expressly included in the SOW. Customer will provide such items directly or reimburse Vendor only if Customer pre-approves the purchase in writing.
Access to Customer source code, repositories, and other Customer intellectual property shall be performed solely through Customer-approved access mechanisms and environments and in accordance with Customer’s applicable security and access control policies.
13.Confidentiality
13.1 Each party ("Receiving Party") will keep confidential the other party’s Confidential Information and use it only to perform under the Agreement. Customer Content is Customer Confidential Information and may contain Customer’s sensitive trade secrets.
13.2 Confidentiality obligations do not apply to information that is publicly available without breach, rightfully received from a third party, already known without restriction, or independently developed without use of Confidential Information.
13.3 Duration. Confidentiality obligations apply during the Agreement and for five (5) years after the later of (a) termination/expiry, or (b) the last disclosure of Confidential Information. Trade secrets remain protected for as long as they remain trade secrets under applicable law.
13.4 Compelled disclosure. A party may disclose Confidential Information to the extent required by law or court order, subject to reasonable notice (where permitted) and cooperation.
13.5. Each party may disclose Confidential Information to its Representatives on a need-to-know basis, provided such Representatives are bound by confidentiality obligations no less protective than those set out herein. Each party remains responsible for its Representatives’ compliance.
14.Intellectual property; Customer Content; Output
14.1 Vendor Technology. Vendor and its licensors retain all right, title, and interest in and to the Vendor Technology. No rights are granted except the limited access and use rights expressly stated in this Agreement.
14.2 Customer Content. Customer retains all right, title, and interest in and to Customer Content. Customer grants Vendor, and Vendor’s Affiliates, subcontractors, licensors, and other service providers engaged in providing the Services, a limited right to access, use, host, transmit, store, copy, disclose, and otherwise process Customer Content solely to provide, operate, host, secure, maintain, support, troubleshoot, and enforce the Services and this Agreement, and to comply with applicable law. Access to Customer Content shall be performed solely through the access mechanisms and environments that Customer makes explicitly available to Vendor and the Services, and in accordance with Customer’s applicable security and access control policies communicated to Vendor in writing in advance.
14.3 Output and Work Product. As between Vendor and Customer, Customer owns all right, title, and interest in and to the Output and Work Product created specifically for Customer under paid Professional Services, whether as a “work made for hire” or pursuant to any other applicable legal basis, to the extent permitted by law and subject to Vendor Technology and third-party rights. Vendor and its licensors retain all right, title, and interest in and to the Vendor Technology. Vendor may use Vendor Technology as a tool, method, system, template, workflow, prompt set, model configuration, or other background technology in creating Output or Work Product. However, except to the extent any Vendor Technology is expressly identified in the applicable Offer, SOW, or deliverable documentation as included in a deliverable or separately licensed to Customer, the Output and Work Product delivered to Customer do not include Vendor Technology, and no ownership of Vendor Technology transfers to Customer merely because it was used to create the Output or Work Product. Customer may deliver Output and Work Product to its own customers or end customers in the ordinary course of Customer’s business, but such delivery does not grant any right to access or use the Platform itself.
14.4 Residual know-how. Vendor may use general knowledge, skills, and experience (including ideas, concepts, and techniques) retained in the unaided memory of its personnel, provided Vendor does not disclose Customer Confidential Information or Customer-specific Work Product in violation of this Agreement. Residual know-how shall not permit Vendor to disclose Customer Confidential Information or reproduce Customer-specific Work Product. For clarity, nothing in this Section grants Vendor the right to use or disclose Customer source code, repositories, or other Customer Confidential Information except as expressly permitted under this Agreement.
14.5 Feedback. If Customer provides feedback, Customer grants Vendor a worldwide, perpetual, royalty-free right to use it without restriction.
14.6 No Implied Licenses. Except as expressly set forth in this Agreement, no intellectual property or other rights are licensed, granted, or transferred by implication, estoppel, or otherwise. Any license to the Vendor Technology shall arise only if and to the extent expressly granted under this Agreement. Any summary ownership statement elsewhere in the Agreement is subject to this Section 14 and does not expand Customer’s rights in Vendor Technology.
14.7 Protection of Vendor Technology. Customer acknowledges that the Vendor Technology embodies valuable trade secrets and other proprietary rights of Vendor and its licensors. Any unauthorized access to, inspection of, extraction of, copying of, disclosure of, or use of the Vendor Technology, including through any customer-controlled deployment or administrative access, is strictly prohibited. If Customer or any person acting on Customer’s behalf obtains access to any non-public aspect of the Vendor Technology other than as expressly permitted under this Agreement, Customer shall immediately cease the relevant activity, promptly notify Vendor, preserve relevant evidence, and, at Vendor’s direction, return, delete, or destroy the relevant materials and certify such return, deletion, or destruction in writing.
15.Data protection
If Vendor processes personal data on Customer’s behalf as part of providing the Services, the DPA applies and is incorporated into the Agreement.
16.Marketing, publicity, and reference rights
16.1 Default reference permission. Unless Customer opts out under Section 16.3, Customer grants Vendor a limited, non-exclusive, worldwide right to identify Customer as a Vendor customer and to use Customer’s name and logo in Vendor marketing materials (including customer lists), subject to Vendor’s confidentiality obligations.
16.2 Reference case. Unless Customer opts out under Section 16.3, Vendor may publish a high-level reference case describing the fact of the relationship, the general nature of the Services provided, and high-level outcomes, provided Vendor does not disclose Customer Confidential Information. Vendor will not publish Customer-specific technical details, security findings, or commercial terms (including pricing) without Customer’s prior written consent.
16.3 Opt-out. Customer may deny the rights in this Section 16 by indicating “no publicity/no reference” in the Offer (or by written notice to Vendor). If Customer opts out, Vendor will not make new uses of Customer’s name or logo or publish new reference case materials. For materials published before the opt-out became effective, Vendor will remove Customer from future publications and, where reasonably practicable, from then-current online marketing pages within a reasonable time.
17.Warranties; disclaimers
17.1 Authority. Each party warrants it has authority to enter into the Agreement.
17.2 Services warranty. Vendor warrants it will provide the Services with commercially reasonable care and skill. Vendor does not warrant that Output will be accurate, complete, or fit for a particular purpose.
17.3 Disclaimer. Except as expressly stated, the Services and Output are provided "as is" and Vendor disclaims all implied warranties to the maximum extent permitted by law.
18.Indemnity
18.1 Customer indemnity. Customer will indemnify Vendor against third-party claims arising from Customer Content, Customer’s products/services, or Customer’s use of the Services in breach of the Agreement or law.
18.2 Vendor IP indemnity. Vendor will defend Customer against third-party claims alleging the Platform (excluding Customer Content and Output) infringes third-party IP rights, and pay final damages or approved settlements. Vendor has no obligation to the extent a claim arises from Customer Content, Output, Customer instructions, modifications not by Vendor, combination with non-Vendor items, or use outside the Agreement.
18.3 Vendor’s defense obligation also applies to claims alleging that Work Product created solely by Vendor infringes third-party intellectual property rights, subject to the same exclusions set forth in this Section.
18.4 Sole remedy. This Section states the parties’ exclusive remedies for third-party IP infringement claims.
19.Limitation of liability
19.1 No indirect damages. Neither party is liable for indirect, incidental, special, consequential, punitive, or exemplary damages (including lost profits, revenue, goodwill, or data), to the maximum extent permitted by law.
19.2 Cap. Except for liability that cannot be limited by law, each party’s total liability under the Agreement is capped at the fees paid by Customer to Vendor in the twelve (12) months preceding the event giving rise to liability.
19.3 Carve-outs. The limitations in Sections 19.1 and 19.2 do not apply to: (a) a party’s gross negligence, willful misconduct, or fraud; (b) Customer’s payment obligations; (c) either party’s breach of Section 13; or (d) Customer’s breach of Section 7.4, Section 8, or either Party’s breach of Section 14, including any unauthorized access to, disclosure of, misuse of, or misappropriation of the Platform, the Services, the Vendor Technology, or Vendor Confidential Information.
20.Term, suspension, and termination
20.1 Term. The Offer states the Subscription Period, Renewal Period, and any non-renewal notice period for recurring Services, and the applicable term for Professional Services. Unless the Offer expressly states a different period, either party may prevent renewal by giving at least thirty (30) days’ written notice before the end of the then-current period.
20.2 Termination for cause. Either party may terminate the affected Services for material breach not cured within thirty (30) days after written notice. Notwithstanding the foregoing, any breach of Section 7.4, Section 8, or Section 14 involving prohibited access, reverse engineering, circumvention, extraction, copying, disclosure, or misuse of the Platform, the Services, the Vendor Technology, or Vendor Confidential Information will be deemed a material breach not subject to any cure period, and Vendor may terminate the affected Services or this Agreement immediately upon written notice.
20.3 Suspension. Vendor may suspend or restrict access immediately if reasonably necessary to address a security emergency, comply with law, stop prohibited use, investigate a suspected breach of Section 7.4, Section 8, or Section 14, protect the integrity or confidentiality of the Services or Vendor Technology, or protect third-party provider environments. Suspension does not waive any other right or remedy.
20.4 Professional Services termination for convenience (optional). Unless the Offer states "non-cancellable", either party may terminate Professional Services for convenience on 30 days’ written notice. Customer remains responsible for fees for work performed and non-cancellable commitments incurred prior to termination. Customer may terminate Professional Services immediately upon written notice if Customer reasonably determines that continued performance poses a material risk to Customer’s intellectual property, confidentiality, or information security.
20.5 Effect of termination; data export and deletion.
(a) Scope. For this Section, “Customer Materials” means Customer Content, customer-specific Output, and Work Product that Customer is entitled to receive under the Agreement, including Customer’s source code, repositories, documentation, customer-specific ledger and project records, and associated customer-specific metadata held by Vendor in connection with the affected Services. Customer Materials exclude Vendor Technology and other customers’ information, without excluding any data or digital assets that applicable law requires Vendor to make exportable.
(b) Export. Upon expiry or termination of the affected Services for any reason, Vendor will make Customer Materials available for secure retrieval in commonly used, machine-readable formats appropriate to the materials. The retrieval period will continue for at least thirty (30) calendar days after the effective expiry or termination date or, where applicable, completion of the switching transitional period, whichever is later. Vendor may provide a secure export instead of continued Platform access. Standard export is included without additional charge. Customer is responsible for downloading and importing the materials; additional migration or conversion services require separate written agreement and may be charged only where permitted by applicable law. Export does not waive outstanding payment obligations.
(c) Deletion. Following the retrieval period, Vendor will securely delete Customer Materials from its active systems within thirty (30) calendar days and ensure deletion by service providers engaged by Vendor. This includes customer-specific copies in hosted storage, development and test environments, caches, indexes, embeddings, and logs. Backup and disaster-recovery copies will be automatically deleted or rendered irretrievable through normal backup rotation within the maximum retention periods expressly specified in the Service Specification or DPA. Until then, those copies will remain protected, will not be used for other purposes, and, if restored for disaster recovery, will be subject to renewed deletion. Any shorter deadline required by applicable law or the DPA applies.
(d) Exceptions and confirmation. Vendor may retain only those Customer Materials whose retention is required by applicable law or a binding legal order, for the required duration and purpose, subject to continuing confidentiality and restricted access. Upon request, Vendor will provide written confirmation of completed deletion, identifying any remaining backup copies, their final deletion deadline, and any legally required retention. This Section does not require Vendor to delete materials held solely in Customer-controlled systems or third-party accounts contracted directly by Customer.
(e) Continuing effect. Ordinary Platform access ends on expiry or termination, subject to this Section and any applicable switching obligations. Authorized export under this Section is permitted notwithstanding Sections 8 and 14 and does not transfer ownership of Vendor Technology. This Section survives expiry or termination. The DPA continues to govern personal-data processing.
21.Subcontractors
21.1 Default. Vendor may use affiliates, subcontractors, licensors, cloud providers, AI model providers, and other services providers in delivering the Services and remains responsible for them as between Vendor and Customer.
21.2 Optional pre-approval. If the Offer and/or SOW states that Customer pre-approval is required for subcontractors performing Professional Services, Vendor will obtain Customer’s prior written consent before engaging such subcontractors.
22.Governing law; arbitration
22.1 Governing law and arbitration. The Agreement is governed by the laws of Finland (excluding conflict of laws rules). Any dispute arising out of or relating to the Agreement will be finally settled by arbitration under the Arbitration Rules of the Finland Chamber of Commerce (FAI). Seat: Helsinki, Finland. Language: English. One arbitrator, unless the FAI rules require otherwise.
22.2 Equitable relief. Each Party acknowledges that that a breach of Section 7.4, Section 8, Section 13, or Section 14 may cause irreparable harm for which monetary damages may be an inadequate remedy. Accordingly, in addition to any other rights and remedies, either Party may seek interim, injunctive, conservatory, or other equitable relief from any court of competent jurisdiction, including pending constitution or completion of any arbitration under this Section 22.
23.Miscellaneous; survival
23.1 Force majeure. Neither party is liable for failure caused by events beyond its reasonable control.
23.2 Assignment. Neither party may assign the Agreement without the other’s consent, except to an Affiliate or successor in a merger or sale of substantially all assets, with notice.
23.3 Entire agreement. The Agreement constitutes the entire agreement and supersedes prior discussions.
23.4 Survival. Sections that by their nature should survive (including confidentiality, IP, limitation of liability, fees due, and dispute resolution) survive termination/expiry.