Aiden General Terms and Conditions (Last updated: February 2025)
These General Terms and Conditions describe the rights and restrictions applicable to the use of products and services provided by Aiden. This document contains the following sections:
- Part A: General Provisions Special Provisions:
- Part B: Maintenance and Software Programmes Agreement
- Part C: Service Agreement
- Part D: Hardware and System Software Agreement
- Part E: Private Cloud Agreement
- Part F: Data Processing Agreement
The General Provisions apply to all use, support, and maintenance of all software, custom software, and all other services provided by Aiden. The Special Provisions specifically relate to the purchase of the particular product or service by the Customer from Aiden.
Part A: Aiden Netherlands B.V. – General Provisions
Introduction
Aiden is an IT company that provides services in the areas of implementation, support, consultancy, hosting, and maintenance of its own software systems as well as third-party software systems. These General Terms and Conditions apply to the Agreement under which Aiden supplies its Products and/or Services to the Customer, as well as to any related offers, proposals, and quotations. By ordering and/or using the Products and/or Services, the Customer expressly confirms that they have received these General Terms and Conditions, have read and understood them, and have accepted them unconditionally prior to requesting the Products and/or Services. Consequently, the Customer waives the applicability of their own general and/or specific terms and conditions, even if such terms and conditions state that they take precedence or are attached to the order form. The General Terms and Conditions will be available for consultation on Aiden’s website (www.aiden.eu) and all components of the Agreement will refer to these General Terms and Conditions. In the event of any contradictions between the provisions of these General Terms and Conditions and (if applicable) the Special Terms and Conditions, the relevant provisions of the Special Terms and Conditions shall prevail. The Agreement(s) shall take precedence over the General Terms and Conditions and (if applicable) the Special Terms and Conditions.
DEFINITIONS
a) Aiden: Aiden Netherlands B.V., a limited liability company under Dutch law, registered at Rijnzathe 36, 3545 PV De Meern (Netherlands), registered with the Chamber of Commerce under the number 69505160 with VAT number NL8578.97.949.B01, including its affiliated companies.
b) General Terms and Conditions: The current general terms and conditions of Aiden.
c) Special Terms and Conditions: The specific agreements, terms, and conditions relating to the provision of Products and/or Services by Aiden to the Customer, including ancillary agreements such as a service level agreement and/or data processing agreement.
d) Services: All services provided by Aiden to the Customer, including but not limited to consultancy, secondment, implementation, support, advice, licensing, hosting, and maintenance of proprietary software and third-party software.
e) Intellectual Property Rights: Any patents, patent applications, trademarks, trade names, copyrights, registered or unregistered designs and models, licences, inventions, approvals, procedures, documentation, know-how (including but not limited to trade secrets and other non-patented or non-patentable registered or confidential information, systems, or procedures), as well as any other similar rights and registered knowledge or other intellectual or industrial property rights.
f) Customer: The natural or legal person holding a company number who enters into an Agreement with Aiden for professional purposes.
g) Agreement: The legally binding agreements between the Parties concerning the supply of Products and/or Services by Aiden to the Customer, consisting of: (i) the quotation (if any) issued by Aiden; (ii) the order form (if any); (iii) these General Terms and Conditions; and (iv) the Special Terms and Conditions (if any).
h) Party: Either the Customer or Aiden individually.
i) Parties: The Customer and Aiden together.
j) Privacy Legislation: The General Data Protection Regulation (2016/679) of 25 May 2018, along with national privacy and data protection laws, such as the Dutch General Data Protection Regulation Implementation Act of 16 May 2018.
k) Products: All products provided by Aiden to the Customer, including but not limited to proprietary and third-party software and infrastructure.
l) Working Day or Working Days: Any day other than a Saturday, Sunday or a recognised public holiday in the Netherlands.
1. Conditions for the conclusion of the Agreement
1.1. All offers and other statements made by Aiden to the Customer are without obligation unless explicitly stated otherwise in writing by Aiden.
1.2. All prices and/or rates included in a binding quotation prior to the Agreement shall remain valid for a period of thirty (30) days from the date of the quotation date, unless otherwise specified by Aiden in the quotation.
1.3. The Agreement becomes binding on the Parties only after it has been entered into and signed in writing by both Parties or confirmed by both Parties in a designated digital customer environment. This provision does not affect the automatic renewal of the Agreement when ordering and/or maintaining a Product and/or Service.
1.4. The Customer shall provide Aiden with all information that Aiden deems necessary or is legally required to request in order to conclude the Agreement with the Customer, as stated on the Order Form or as otherwise communicated. This includes any documents that Aiden deems necessary to verify the identity of the Customer (or its representative and/or their authority to represent the customer). The Customer is solely responsible for providing true, complete, and accurate information.
1.5. If the Customer enters into the Agreement on behalf of its affiliated companies, such affiliated companies shall be bound by the Agreement, and the Customer shall be jointly and severally liable for the fulfilment of all obligations under the Agreement, including payment obligations, on behalf of the affiliated company.
1.6. Aiden reserves the right, without any obligation to provide compensation, to refuse to enter into an agreement in the following situations:
(i) if the Order Form is incomplete or the Customer has failed to provide all required information;
(ii) if the Customer has provided inaccurate information or misused such information;
(iii) if there are serious indications of fraud, financial instability, or significant doubts about the Customer’s solvency, which may be derived from previous payment defaults; Aiden is entitled to request additional documents from the Customer to confirm its solvency;
(iv) if the Customer has failed to comply with other agreements entered into with Aiden or its affiliated companies; and/or
(v) for technical reasons.
2. Delivery
2.1. Aiden shall provide the Products and/or Services in the manner and/or format specified in the Agreement.
2.2. Aiden shall install the Products at the Customer’s premises only if this has been expressly agreed in writing between the Parties. In the absence of such an agreement, the Customer shall be responsible for installing, configuring, and, if necessary, adjusting the equipment and operating environment used for the Products.
2.3. Aiden shall make reasonable efforts to adhere to the delivery periods stated or agreed between the Parties as closely as possible. These delivery periods are indicative in nature, can never be considered binding or of the essence, and do not impose any obligation on Aiden unless expressly agreed otherwise in writing in the Agreement. Delivery periods are always expressed in Working Days and commence upon Aiden’s receipt of all information necessary for the full execution of the order and after full payment of the agreed price, unless expressly agreed otherwise in writing.
2.4. Aiden shall not be the bound by a delivery period agreed in writing in the following cases: (i) in the event of force majeure as stipulated in Article 21; (ii) due to the actions of third parties on whom Aiden depends for the delivery of the Products and/or Services; (iii) in case of modifications and/or additional work requested by the Customer during the performance of the Agreement; and/or (iv) in case of non-compliance with the Agreement by the Customer.
2.5. Under no circumstances shall a delay in the intended delivery period give rise to a claim for damages or the termination of the Agreement at Aiden’s expense. If any delivery period is exceeded, the Parties shall consult in good faith to discuss the consequences of the delay for further planning.
2.6. If the Parties have agreed that the delivery of the Products and/or Services will take place in phases, Aiden shall be entitled to postpone the commencement of work for a subsequent phase until the Customer has accepted the results of the previous phase in accordance with Article 4.
2.7. Aiden shall use reasonable endeavours to perform its obligations with due care, where appropriate, in accordance with the arrangements and procedures laid down in writing with the Customer in the Agreement. All obligations of Aiden are best-efforts obligations, unless and to the extent that Aiden has expressly guaranteed a specific result in the Agreement, and such result is sufficiently defined in the Agreement.
2.8. Aiden shall endeavour to follow Customer’s instructions in performing the Agreement, unless they would be manifestly unreasonable. If these instructions involve additional work for Aiden, what is agreed in Article 3 shall apply.
2.9. To facilitate the performance of the Agreement, if at any time Customer observes any (possible) non-conformity of the Products and/or Services prior to delivery, Customer shall notify Aiden within two weeks of delivery.
2.10. The risk of loss, theft, misappropriation, or damage of items, data (including but not limited to user names, codes, and passwords), documents, software, or data files produced for, delivered to, or used by the Customer in the performance of the Agreement shall pass to the Customer at the moment they come under the Customer’s actual control or that of their representative.
3. Amendments and additional work
3.1. Additional work refers to any activities resulting from requests by the Customer that lead to a modification, of any scope, in the agreed work to be performed.
3.2. If Aiden performs work or provides additional services beyond the agreed scope of the Agreement at the request of or with the prior consent of the Customer, the Customer shall compensate Aiden for such work or services in accordance with the rates agreed upon between the Parties or, in the absence of such agreed rates, at Aiden’s standard rates.
3.3. Aiden is not obliged to comply with such a request and may require the Parties to enter into a separate written agreement for this purpose.
3.4. The Customer acknowledges and accepts that modification and additional work may result in adjustments to the delivery timelines. The new delivery timelines indicated by Aiden shall replace the previous ones, with Article2 applying accordingly.
4. Acceptance
4.1. The Products and/or Services shall be deemed accepted by the Customer in the manner specified in the Agreement.
4.2. If no explicit acceptance terms are set out in the Agreement, the following procedure shall apply: if the Customer does not submit a written objection to Aiden within ten (10) Working Days from the delivery date of the Products and/or Services, the delivered Products and/or Services shall be deemed to be definitively and irrevocably accepted, including all visible defects. After this period, the Customer shall no longer be entitled to claim performance, repair, or compensation for damages.
4.3. In the event of such a written objection, Aiden shall endeavour to remedy any non-conformity as soon as possible, after which the Products and/or Services shall be deemed accepted.
4.4. Minor defects, which are defined as defects that by their nature and/or quantity do not reasonably prevent the operational use of the Products and/or Services (for example, defects that are non-essential to the functionality of the Products and/or Services) shall not constitute grounds for withholding acceptance. This does not affect Aiden’s obligation to make all reasonable efforts to rectify such defects.
5. Service level
5.1. Agreements regarding a particular service level for a Service to be provided by Aiden can only be established in writing as part of the Agreement. The Customer shall promptly inform Aiden of any circumstances that affect or may affect the service level and its availability.
5.2. The availability of software, systems, and related services shall be measured excluding any pre-announced service downtime by Aiden due to preventive, corrective, adaptive, or other maintenance, as well as any circumstances beyond Aiden’s control. Subject to evidence to the contrary, the availability as measured by Aiden shall be the sole evidence for the Customer.
6. Staff
6.1. Aiden shall use its own employees, supervisors, and auxiliary resources. Aiden shall determine which employees are assigned to perform the Agreement. Aiden is at all times entitled to replace the employees working on behalf of the Customer.
6.2. Aiden is responsible for the administration, planning, and timekeeping of the work performed on behalf of the Customer.
6.3. Aiden shall carry out the work entirely independently. Aiden’s employees shall never be considered employees of the Customer and shall work exclusively under Aiden’s authority and supervision. Customer agrees not to exercise any part of the employer’s authority over Aiden’s employees, as such authority is vested solely in Aiden. The Customer may only provide organisational directions, but shall not issue instructions to Aiden’s employees regarding the performance of their work, nor is the Customer authorised to request any employee to perform additional work without Aiden’s prior consent.
6.4. The Customer may only issue the following types of instructions: (a) general instructions and (technical) guidelines to the extent necessary for the execution of the Agreement, including: (i) instructions relating to the execution of the Agreement, but excluding instructions on how to achieve the intended result; (ii) instructions regarding the Customer’s normal working hours, but excluding regulations concerning working time rules, which remain Aiden’s sole responsibility; (iii) instructions regarding the correct use of the Customer’s machines, equipment, materials and documents; (iv) instructions regarding access to the Customer’s premises and facilities, including instructions to carry and visibly display a valid identification badge at all times; (v) instructions regarding the specific context and procedures of the Customer that must be taken into account in the performance of the Agreement (e.g., existing health and safety requirements, other ongoing projects that affect the service schedule, etc.); (vi) instructions regarding the delivery timeline; and (b) instructions to Aiden’s employees regarding compliance with the Customer’s obligations and responsibilities for the welfare of Aiden’s employees while present at the Customer’s premises.
6.5. The Customer is not permitted to directly instruct Aiden’s employees on how they perform their work. This is particularly important when the Parties collaborate using methodologies such as the Scrum methodology, in which ongoing consultation between the Parties during the execution of the Agreement is required to achieve the desired end result. To ensure maximum value for the Customer, Aiden’s independence must be maintained. The Customer expressly agrees to this.
6.6. Aiden shall ensure that its employees working at the Customer’s premises comply with the applicable laws and regulations at the Customer’s location regarding working conditions, safety, and the environment. The Customer shall provide these rules to Aiden no later than at the time of entering into the Agreement and shall also communicate them to Aiden’s employees at the first opportunity.
6.7. The Customer shall, at its own expense, provide Aiden’s employees performing work at the Customer’s premises with the tools and resources necessary for executing the Agreement. These tools shall remain the property of the Customer.
7. Third-party suppliers and subcontracting
7.1. If and to the extent that Aiden supplies Products and/or Services from third-party suppliers to the Customer, the terms and conditions of the respective third-party suppliers shall apply to the relationship between Aiden and the Customer, superseding any conflicting provisions in these General Terms and Conditions, provided that Aiden has informed the Customer of the applicability of the third-party supplier’s terms and has supplied those terms to the Customer prior to the conclusion of the Agreement. Aiden is entitled to amend these third-party terms if the respective third-party supplier modifies its own terms. Such amendments shall take effect on the date specified in Aiden’s notification.
7.2. Aiden shall be bound only by the same warranty obligations for the delivery of Products and/or Services as those to which its third-party supplier is bound towards Aiden, as communicated to the Customer.
7.3. If, for any reason, the terms of the third-party supplier are deemed inapplicable or are declared void in the relationship between the Parties, the provisions of these General Terms and Conditions shall remain fully applicable.
7.4. If a Product and/or Service supplied by Aiden consists of multiple independently functioning products or services, Aiden shall be responsible only for ensuring the proper functioning of the integrated elements that ensure interoperability between the individual products and services. Aiden shall not be liable for the functioning of Products and/or Services in combinations or environments that it has not advised.
7.5. Aiden reserves the right to engage third-party suppliers not previously specified in the quotation or Agreement(s) in the execution of the Agreement. The applicability of any additional terms and conditions from such other third-party suppliers shall be communicated by Aiden to the Customer in accordance with Article 7.1.
7.6. If Aiden relies on an external party to deliver a Product and/or Service ordered by the Customer, Aiden’s obligation to deliver shall be subject to the express suspensive condition of availability. This means that the Agreement shall only take effect once Aiden confirms with the external party that the Product and/or Service is available at the price previously established by Aiden and paid by the Customer. The price paid by the Customer before the fulfilment of the suspensive condition shall be regarded as a deposit. Aiden undertakes to verify the availability of the Product and/or Service with the external party within five (5) Working Days after receiving the deposit. If the ordered Product and/or Service is unavailable at the time Aiden consults the external party, the Agreement shall be deemed null and void, and Aiden shall refund the deposit to the Customer without any further obligations between the Parties. If the ordered Product and/or Service is available but at a different price, the Agreement shall be deemed null and void. Aiden shall then offer the Customer the choice to accept the revised price, thereby establishing a new Agreement, or to terminate the Agreement.
8. Information and cooperation obligations
8.1. The Parties undertake to cooperate in good faith under the Agreement to ensure the smooth execution of its terms. The Parties shall regularly consult on all aspects that may influence changes in the environment of the Agreement.
8.2. The Customer undertakes to inform Aiden of all relevant files, documents, or other information that may affect the conditions for the execution of the Agreement. The Customer guarantees the accuracy and completeness of this information.
8.3. The selection of the Products and/or Services, the analysis of their technical characteristics, their compatibility with the Customer’s environment, and their configuration in all circumstances fall under the exclusive responsibility of the Customer, without prejudice to Aiden’s duty of information.
8.4. The Customer is responsible for obtaining and maintaining, at its own expense, all licences, registrations, permits, or approvals necessary for fulfilling its obligations under the Agreement.
8.5. The Customer shall ensure that all users who have access to the Product and/or Service comply with the obligations arising from the Agreement and accept liability for any breaches.
9. Project and steering groups
9.1. If both Parties participate in a project or steering group with one or more employees appointed by them, the provision of information shall take place in the manner agreed upon for the project or steering group in the Agreement.
9.2. Decisions made within a project or steering group in which both Parties participate shall only be binding on Aiden if the decision-making process follows the terms explicitly agreed upon in writing between the Parties in the Agreement and if the minutes of the meeting are signed for approval by the authorised representatives of both Parties. In the absence of written agreements on the decision-making process, decisions shall only be binding on Aiden if they have been explicitly accepted in writing by Aiden through its authorised representatives. Aiden shall never be obliged to accept or implement a decision if, in its opinion, such a decision is incompatible with the content and/or proper execution of the Agreement.
9.3. The Customer warrants that the individuals appointed by it to participate in a project or steering group are authorised to make binding decisions on behalf of the Customer.
10. Prices and rates
10.1. The prices of the Products and/or Services are stated in the Agreement in euros (€) and are exclusive of VAT, delivery and transport costs, and any other taxes and charges payable by the Customer. Any additional costs shall only be charged to the Customer by Aiden with the Customer’s prior approval.
10.2. If the Customer has a periodic payment obligation, Aiden may adjust the applicable prices and rates on the annual anniversary of the Agreement, using the Dutch Central Bureau of Statistics (CBS) Consumer Price Index (CPI) percentage for the relevant year as a guideline. If the Agreement does not expressly provide for the possibility of adjusting the prices or rates, Aiden shall still have the right to adjust the applicable prices and rates by giving written notice to the Customer with a minimum notice period of three (3) months.
11. Invoicing and payment
11.1. The Products and/or Services shall be invoiced in the manner specified in the Agreement.
11.2. Fees and licence charges for Products shall be invoiced immediately upon delivery.
11.3. The invoicing of the Products and/or Services provided by Aiden shall be based on the records contained in Aiden’s administrative systems, with the Customer always having the right to provide evidence to the contrary.
11.4. The Customer shall pay invoices within fourteen (14) days from invoice date, using the payment method and account details specified by or on behalf of Aiden. The Customer shall bear all costs associated with the payment of the invoice.
11.5. The Customer must submit any complaint regarding an invoice from Aiden within eight (8) days of receipt. After this period, the invoice shall be deemed irrevocably accepted by the Customer. Any undisputed portion of the invoice shall be considered accepted and must be paid within the standard payment term. If the Customer’s complaint proves unfounded, the disputed amount shall become immediately payable.
11.6. Aiden reserves the right to conduct a financial assessment of the Customer both before and during the term of the Agreement. If serious doubts arise regarding the Customer’s solvency, Aiden shall be entitled to amend the payment terms, impose additional interim payments, or require advance payments, bank guarantees, or any other financial security.
11.7. The Customer shall not be entitled to offset and amounts payable to Aiden under the Agreement against any amounts that Aiden may owe to the Customer under this or any other Agreement.
11.8. In the event of late payment of any outstanding amounts, the Customer shall, by operation of law and without the need for a formal notice, be liable to pay commercial interest, as well as a compensation fee of ten (10) percent of the total outstanding invoice amount, with a minimum charge of fifty (50) euros. This shall be without prejudice to Aiden’s right to claim judicial collection costs incurred due to the non-payment or any other damages not solely caused by the non-payment of the invoice.
11.9. In the event of late, incomplete, or non-payment of any overdue invoice, or failure by the Customer to fulfil its essential obligations under the Agreement, all outstanding but not yet due invoices shall become immediately payable.
12. Retention of title
12.1 All Products delivered to the Customer shall remain the property of Aiden until all amounts due by the Customer to Aiden under the Agreement for the relevant Product have been paid in full. Any rights granted or assigned to the Customer under the Agreement shall be subject to the condition that the Customer has paid all amounts due under the Agreement in full.
13. Intellectual property
13.1. All Intellectual Property Rights in the Products and Services existing at the time the Agreement was entered into or those arising under the Agreement (including all documents prepared by Aiden in connection with the Agreement) are and shall remain the exclusive property of Aiden, its affiliated companies, its licensors and/or third-party suppliers. The Customer may only obtain limited rights of use, which are non-exclusive, non-transferable, non-pledgeable, and non-sublicensable, unless otherwise agreed by the Parties in writing.
13.2. If Aiden agrees to transfer an Intellectual Property Right, such a transfer shall only be valid if expressly agreed in writing in the Agreement. Such a transfer shall not affect Aiden’s right or ability to use and/or exploit for other purposes, and without limitation, the components, general principles, ideas, designs, algorithms, documentation, works, programming languages, protocols, standards, and other underlying elements of such developments, either for itself or for third parties. Furthermore, such a transfer shall not affect Aiden’s right to develop for itself or for a third party similar or derivative works to those made or to be made for the benefit of the Customer.
13.3. The Customer shall not remove or alter (or cause to be removed or altered) any indications regarding the confidential nature of the Products. Aiden may implement technical protections in the Products and/or Services to safeguard its Intellectual Property Rights and to enforce any agreed limitations on content, duration, or access to the Products and/or Services. The Customer shall not remove, disable, or circumvent such protections.
13.4. Aiden shall indemnify the Customer against any third-party claim alleging an infringement of Intellectual Property Rights in the Products and/or Services developed by Aiden, provided that the Customer: (i) promptly notifies Aiden in writing of the claim and its details; (ii) grants Aiden exclusive control over the defence and settlement of the claim; (iii) provides Aiden with all necessary cooperation and powers of attorney to handle the matter; and (iv) does not take any action that may prejudice Aiden’s legal position. Aiden’s indemnification obligation shall not apply if the alleged infringement: (i) arises from materials (including software) provided by the Customer for use, adaptation, processing, or maintenance; or (ii) results from any modifications made or incorporated by the Customer without Aiden’s prior written consent. If a court irrevocably determines that such an infringement has occurred, or if Aiden believes there is a substantial likelihood of an infringement claim, Aiden shall, where possible, ensure that the Customer can continue using the Services. Any further or additional indemnification obligation for alleged infringement of a third party’s Intellectual Property Rights is expressly excluded.
13.5. The Customer warrants that no third party has any objection to the Customer providing Aiden with equipment, software, materials, data files, designs, or similar items for use, maintenance, processing, installation, or integration in connection with the Agreement. The Customer shall indemnify Aiden against any claim alleging that such provision constitutes an infringement of a third party’s rights.
13.6. The Customer agrees that Aiden may use the Customer’s logo, name, and logotype in connection with the existence of the Agreement and in external commercial communications.
14. Software
14.1. If Aiden provides its own software or third-party software as part of its Products and/or Services, such software (including user documentation) shall be licensed directly to the Customer by Aiden or its third-party supplier (hereinafter the “Licensor”). The Customer expressly acknowledges that this software contains technical and confidential information that is the property of the Licensor. By executing the Agreement, installing the software, or using the Products and/or Services, the Customer (and its end users) accept the applicable End User License Agreement (EULA), where relevant. Acceptance of the EULA creates a binding agreement between the Customer and, on the one hand, its end users, and, on the other, the Licensor. Notwithstanding this, the Customer shall always comply with the agreed restrictions on the right to use the software, regardless of their nature or scope.
14.2. Non-compliance with the EULA shall be considered a material breach of contract, entitling Aiden to terminate the Agreement. The Customer shall be liable for any breaches of the EULA committed by its end users and/or third parties engaged by the Customer.
14.3. If, for any reason, the relevant third-party terms are deemed inapplicable or are declared unenforceable between the Customer and Aiden, the provisions of these General Terms and Conditions shall remain fully applicable.
14.4. The software licence is strictly limited to the object code of the software. The source code, along with any related technical documentation, shall not be made available to the Customer.
14.5. If the software is licensed by a third-party supplier of Aiden, the Customer acknowledges and agrees that Aiden provides no warranty, indemnification, or compensation for the software and expressly disclaims all liability regarding its quality and performance under the applicable EULA.
14.6. If the Parties have agreed that the software may only be used in combination with certain hardware, the Customer shall be permitted, in the event of hardware failure, to use the software on alternative hardware of equivalent specifications for the duration of the failure.
14.7. Aiden may require the Customer not to activate or use the software until the Customer has obtained the necessary activation codes or licences from Aiden, its third-party supplier, or the software manufacturer.
14.8. Aiden shall always be entitled to implement technical measures to protect the software from unauthorised use or use in a manner or for purposes other than those agreed between the Parties. The Customer shall not remove, disable, or circumvent any such protection mechanisms.
14.9. The Customer may use the software exclusively within and for the benefit of its own business or organisation, and only to the extent necessary for its intended purpose. The Customer shall not use the software for third parties, including but not limited to Software as a Service (SaaS) or outsourcing purposes.
14.10. The Customer is not permitted to sell, rent out, transfer, or grant limited rights over the software or its media, nor to make it available to third parties in any manner, for any purpose, or under any title. The Customer shall also not allow third parties, whether remotely (online) or otherwise, to access the software or host it with a third party, even if such third party uses the software solely for the Customer’s benefit.
14.11. Upon request, the Customer shall fully cooperate with any audit or investigation conducted by or on behalf of Aiden to verify compliance with the agreed usage restrictions. The Customer shall, upon Aiden’s first request, grant access to its premises and systems, including where necessary through user licences.
14.12. Aiden shall not be obliged to provide maintenance or support for the software unless explicitly agreed in writing in the Agreement.
14.13. Aiden shall not be liable for the misuse of the software or its improper installation by the Customer; modifications made to the software by the Customer; security breaches, including but not limited to viruses, malware, ransomware, or similar threats. Unless expressly agreed in writing, Aiden does not guarantee that the software provided will be compatible with the Customer’s existing hardware.
14.14. Immediately upon termination or expiry of the Agreement for any reason, the Customer shall return all copies of the software in its possession to Aiden, unless Aiden instructs the Customer to destroy them. The Customer shall provide written confirmation of such destruction without delay. Aiden shall not be obligated to assist with data conversion or migration to another system upon or after termination of the Agreement, unless explicitly agreed otherwise in writing.
15. Confidentiality
15.1. All information and data exchanged between the Parties or obtained by them in the context of the Agreement shall always be treated as confidential throughout the duration of the Agreement and for a period of five (5) years following its termination. The Customer acknowledges that software provided by Aiden is inherently confidential and contains trade secrets belonging to Aiden, its third-party suppliers, or the software manufacturer. Each Party undertakes not to disclose such information or data to third parties without the prior written consent of the other Party, except: where disclosure is required by law, court order, or for the proper execution of the Agreement, in which case the disclosing Party shall, where possible, promptly notify the other Party in writing and cooperate to maintain confidentiality; where disclosure is required for the performance of the Agreement, provided that reasonable safeguards are in place to ensure confidentiality. The Parties shall take all reasonable and industry-standard measures to safeguard trade secrets, including requiring employees and third parties to comply with these confidentiality obligations.
15.2. Confidential information remains the property of the disclosing Party. Its disclosure does not imply any transfer or granting of any (ownership) rights.
15.3. The Parties shall not be held liable for the other Party’s use of the confidential information.
16. Non-solicitation of personnel
16.1. The Customer shall not, during the full term of the Agreement and for a period of eighteen (18) months following its termination, employ, engage, or otherwise directly or indirectly hire or use the services of any employees of Aiden (including employees, consultants, or others). If the Customer acts in breach of Article 16 of the Agreement, it shall be liable to pay Aiden compensation amounting to 50% of the maximum contractual price under this Agreement (excluding VAT), which shall be no less than twelve (12) times the monthly remuneration that such an employee received in their last full month of employment with Aiden, without prejudice to Aiden’s right to claim additional damages.
17. Privacy and data protection
17.1. The Parties undertake to comply with their obligations under Privacy Legislation. The Parties are required to provide each other all necessary cooperation and information to enable the other Party to fulfil its obligations under Privacy Legislation.
17.2. If Aiden acts as a processor of personal data on behalf of the Customer, the Data Processing Agreement shall apply.
18. Security
18.1. If Aiden is required under the Agreement to provide any form of information security, such security shall comply with the specifications regarding security as agreed in writing between the Parties. Aiden does not guarantee that the information security will be effective in all circumstances. If the Agreement does not explicitly define a specific method of security, the security measures implemented shall be reasonable, taking into account the state of technology, implementation costs, the nature, scope, and context of the information to be secured as known to Aiden, the intended purpose and normal use of the Products and/or Services, the likelihood and severity of foreseeable risks, the sensitivity of the data, and the costs associated with implementing security measures.
18.2. Any access or identification codes, certificates, or other security credentials provided to the Customer by or on behalf of Aiden shall be treated as confidential and shall only be disclosed to authorised personnel within the Customer’s organisation. Aiden shall be entitled to modify any assigned access or identification codes and certificates. The Customer shall be responsible for managing authorisations and for granting and revoking access and identification codes in a timely manner.
18.3. If security measures or testing thereof relate to software, equipment, or infrastructure not supplied to the Customer by Aiden, the Customer shall ensure that all necessary licences or approvals have been obtained for such services to be lawfully performed. The Customer shall indemnify Aiden against any claims arising in connection with the performance of such services.
18.4. Aiden shall be entitled, but not obliged, to adjust its security measures from time to time if necessary due to changing circumstances.
18.5. The Customer shall adequately secure its systems and infrastructure and shall at all times have effective antivirus software in operation.
18.6. Aiden may, but shall not be obliged to, provide the Customer with security-related instructions aimed at preventing or minimising incidents or the consequences of incidents that may compromise security. If the Customer fails to follow such instructions from Aiden or a relevant government authority, either in whole or in part, Aiden shall not be liable for any resulting damage, and the Customer shall indemnify Aiden against any resulting claims.
18.7. Aiden shall at all times be entitled to implement technical and organisational measures to protect equipment, data files, websites, software made available, or other works to which the Customer is given direct or indirect access, including in relation to any agreed limitations on the content or duration of the Customer’s right to use such objects. The Customer shall not remove or circumvent, or cause to be removed or circumvented, any such technical protections.
19. Backup
19.1. If, under the Agreement, Aiden’s services to the Customer include making backups of the Customer’s data, Aiden shall create a full backup of the Customer’s data in its possession at the intervals agreed in writing between the Parties, or in the absence of such an agreement, once per week. Aiden shall retain the backup for the agreed period or, if no retention period has been specified, for the duration of the Agreement.
19.2. The Customer remains solely responsible for complying with all statutory administrative and record-keeping obligations applicable to it.
20. Liability
20.1. In all cases, except in the event of fraud, wilful misconduct, or deliberate recklessness on the part of Aiden or one of its employees, Aiden’s liability shall be limited to the compensation of foreseeable, direct damage suffered by the Customer, up to a maximum amount equal to the contractual price agreed for that Agreement (excluding VAT). If the Agreement is of indefinite duration, the contractual price shall be calculated as the total fees (excluding VAT) due for one (1) year. In no case shall Aiden’s total liability for direct damages, on any legal basis, exceed €100,000.00 (one hundred thousand euros).
20.2. Aiden’s total liability for damage resulting in death or personal injury is limited to €1,250,000.00 (one million two hundred fifty thousand euros).
20.3. Aiden shall under no circumstances be liable for any indirect damage, including but not limited to consequential damage, loss of profit, missed savings, loss of goodwill, business interruption, claims by the Customer’s customers, damage related to the use of third-party materials, software, or suppliers prescribed by the Customer, or any damage resulting from destruction, loss, or corruption of data and documents.
20.4. Aiden shall not be liable for any damages or costs resulting from the use or misuse of access or identification codes or certificates, unless the misuse is the direct result of wilful misconduct or deliberate recklessness by Aiden.
20.5. Aiden’s liability for damage caused by or related to Products or Services supplied by third-party suppliers shall be limited in accordance with the terms and conditions of the third-party supplier and up to the amount for which the third-party supplier has accepted liability. If the Agreement does not expressly reference the terms and conditions of the third-party supplier, Aiden’s liability for such damage caused by or related to third-party products or services, regardless of the cause or legal basis, shall be limited to direct damage and shall not exceed €10,000.00 (ten thousand euros).
20.6. The provisions of this article, as well as all other limitations and exclusions of liability stated in the Agreement, shall also apply for the benefit of all (legal) persons engaged by Aiden and its third-party suppliers in the performance of the Agreement.
20.7. The Customer shall indemnify and hold Aiden harmless against any third-party claims, regardless of their cause, that arise in connection with the performance of the Agreement, unless and to the extent that the Customer proves that the damage was caused by Aiden’s actions or omissions.
20.8. If the Customer fails to fulfil, fails to fulfil on time, or fails to fully fulfil one or more of its statutory or contractual obligations towards Aiden, the Customer shall be liable to compensate all damage suffered by Aiden as a result. This provision does not limit Aiden’s right to assert other claims against the Customer.
20.9. The Customer shall be liable towards Aiden for all direct and indirect damage suffered by Aiden, its employees, third parties, or their property, where such damage is caused by the Customer, its personnel, or third parties engaged by the Customer.
21. Force majeure
21.1. The Parties shall not be liable to each other for the consequences of force majeure, which renders the full or partial performance of their obligations reasonably (temporarily) impossible. Force majeure shall include, but is not limited to, any event beyond the reasonable control of the Parties, including but not limited to strikes, lock-outs, power failures, interruptions in transport and distribution, acts of war or terrorism, fire, (inter)national government measures or legislative changes, system failures, employee illness, industrial action or labour disputes, disruption of internet, data network or telecommunication facilities, (cyber)crime, (cyber)vandalism, hacking, business disruptions or production failures, epidemics, pandemics, and similar events.
21.2. The Parties shall be released from all obligations towards each other for the duration of such a force majeure situation. However, the Customer’s payment obligations for Products and/or Services not affected by the force majeure situation, as well as all the Customer’s obligations to cooperate and/or provide information shall not be subject to force majeure.
21.3. If a force majeure situation lasts longer than sixty (60) days, either Party shall have the right to terminate the Agreement in writing. In such a case, any services already performed under the Agreement shall be settled proportionally, without either Party owing any further compensation to the other.
22. Duration, Suspension and Termination of the Agreement
22.1. Unless otherwise specified in the Agreement, the Agreement shall be entered into for a renewable term of one (1) year from the date of signature. This term shall be automatically renewed for successive periods of one (1) year, unless either Party provides written notice at least six (6) months before the end of the respective term, stating its intention not to renew the Agreement.
22.2. Aiden may automatically and immediately suspend the performance of its obligations if the Customer fails to fulfil its contractual obligations and does not rectify this situation within ten (10) Working Days following the dispatch of a formal notice of default from Aiden. This suspension shall end once the Customer has complied with its obligations
22.3. The Customer shall not be entitled to suspend its payment obligations to Aiden or to offset any counterclaims against amounts due to Aiden, unless and to the extent that Aiden has expressly acknowledged such counterclaims in writing.
22.4. Aiden shall have the right to immediately and unilaterally terminate the Agreement, without prior notice of default and without prior judicial intervention, by means of written notice to the Customer, without being liable for any compensation to the Customer, if the Customer materially breaches any of its obligations under the Agreement, and: performance of the obligation has become permanently impossible, or; performance can no longer reasonably be expected, or; if the breach is still capable of remedy, the Customer fails to remedy the breach within fourteen (14) days after receiving a formal notice of default from Aiden. In such cases, Aiden reserves the right to claim compensation from the Customer for any damages suffered as a result of the termination.
22.5. Aiden may terminate the Agreement if the licences under which Aiden provides its Products and/or Services are revoked or terminated by their licensor(s), without being liable to the Customer for any compensation.
22.6. Aiden shall have the right to immediately and unilaterally terminate the Agreement, without prior notice of default and without prior judicial intervention, by means of written notice to the Customer, if the legal status of the Customer changes as a result of a merger, division, transfer, acquisition, or change of control, or if the Customer ceases its activities, becomes insolvent, undergoes judicial reorganisation, is declared bankrupt, is dissolved, has a pledge able special administrator appointed, or undergoes any similar procedure.
22.7. If Aiden decides to discontinue the provision of a specific Product(s) and/or Service, it shall notify the Customer in writing at least six (6) months in advance. Aiden shall not be required to pay the Customer any compensation for such termination.
22.8. Termination of the Agreement shall render all outstanding but not yet due invoices immediately payable.
23. Applicable law and disputes
23.1. The Agreement and its interpretation shall be exclusively governed by Dutch law. Foreign laws and treaties, including the United Nations Convention on Contracts for the International Sale of Goods (CISG), are expressly excluded, as well as any existing or future international regulations concerning the sale of movable goods that may be excluded by the Parties.
23.2. In the event of a dispute between the Parties regarding the formation, performance, interpretation, or termination of the Agreement, the Parties undertake to first attempt to resolve the matter amicably.
23.3. Disputes that cannot be resolved amicably shall be exclusively settled by the competent court in Amsterdam.
24. Miscellaneous
24.1. If any provision of the Agreement or these General Terms and Conditions is found to be wholly or partially void or unenforceable, the remaining provisions shall remain in full force and effect. The Parties undertake to consult with each other to establish new provisions to replace the void or unenforceable provisions, preserving the original intention of the Parties as much as possible.
24.2. The failure of either Party to exercise any of its rights under the Agreement shall not be interpreted as a waiver of such rights.
24.3. The Agreement constitutes the entire contractual relationship between the Parties and supersedes all prior oral or written agreements between the Parties.
24.4. The Agreement may only be amended in writing with the mutual consent of both Parties.
24.5. The Customer shall not transfer its rights and obligations under the Agreement to any third party without Aiden’s prior written consent. Aiden shall be entitled to assign the Agreement to affiliated companies without the Customer’s consent.
24.6. To the extent that the Agreement contains rights or obligations for third parties, such third parties shall not become parties to the Agreement upon acceptance of such rights or obligations. Article 6:254 of the Dutch Civil Code is expressly excluded.
25. Amendment of the General Terms and Conditions
25.1. Aiden may amend and/or supplement the General Terms and Conditions at any time (for example, due to technical reasons or legal requirements). The amended General Terms and Conditions shall take effect on the date specified in the notice announcing the amendments. Any use of the Products and/or Services after such amendment and/or supplement shall be interpreted as the Customer’s acceptance of the amended and/or supplemented General Terms and Conditions. If the Customer does not accept the amended and/or supplemented General Terms and Conditions, it may terminate the Agreement within seven (7) days without any compensation being due, effective from the date of termination.
Part B: Special Provisions Relating to the Use and Maintenance of SAP and Aiden software (Maintenance and Software Programme Agreement)
The terms and conditions set out in Part B shall, in addition to the General Terms and Conditions, apply if the Aiden Agreement (also) relates to use and maintenance of SAP and Aiden software.
26. Limited Right of Use
26.1. The right of use applies solely to the delivered version of the software. The Customer shall only be entitled to use new versions if it has also entered into a maintenance contract for SAP Software, in which case the usage regulations set out in this Agreement shall apply equally to such new versions.
26.2. Unless otherwise agreed, the Software Products may only be used productively in one (1) installation. An installation is defined as the set of components that have direct and indirect access to a database instance. The right of use is further limited to Named Users, meaning employees of the Customer or its subsidiary (as defined in Article 2: 24a of the Dutch Civil Code) who are authorised to use the Software Products.
27. Copyright
27.1. The Software Products may or may not contain modified or unmodified Open-Source Software. Aiden has complied with all applicable modification rules governing the use of Open-Source Software. Likewise, the Customer acknowledges its obligation to comply with such rules. This Open-Source Software, whether modified or not, is made available to the Customer free of charge under an Open-Source licence. The one-off or periodic licence fee stated in the Agreement is not payable for the provision of Open-Source Software, whether modified or not, but rather for the delivery of proprietary software, documents, scripts, and other materials developed by the producer.
28. Customer Responsibility
28.1. The Customer is responsible for the selection, use, and correct application of the Software Products within its organisation, including their integration and interaction with other systems. The Customer shall ensure that the users have completed appropriate training in the use and application of the Software Products. The Customer is also responsible for the administration, calculation methods applied, and the adequate security of data, including the implementation of the necessary organisational security measures.
28.2. The Customer is familiar with the functional characteristics of the Software Products and is responsible for ensuring that the Software Products meet its requirements and needs. Aiden does not guarantee that the Software Products will operate error-free or without interruption. The Customer may enter into a maintenance agreement with Aiden for the correction of errors.
28.3. The Customer shall ensure that the hardware and operating system software required for the use of the Software Products are fully installed and operational.
29. Maintenance
29.1. The Customer shall establish a helpdesk for end users, which will serve as the point of contact for all communication between the Customer and Aiden and/or SAP regarding maintenance. This helpdesk shall also be responsible for preparing Support Case Reports concerning errors in SAP Software (Level 0 support for error resolution) and for the installation of new software versions and releases.
29.2. In order to ensure that the development of SAP Software meets the highest quality standards and keeps pace with technological advancements, Aiden shall make available new and improved releases of SAP Software to the Customer as soon as they become generally available from SAP. Functional improvements are included as part of SAP Software maintenance.
29.3. Aiden shall use SAP’s procedures, methods, and tools for pro-active error recognition and resolution and may inform the Customer about possible errors and solutions related to SAP Software. Errors concerning SAP Software shall be reported via the SAP Service Web Portal in accordance with SAP’s prescribed method. Aiden and the Customer may agree in writing on an alternative method of reporting errors. SAP recognises four levels of support for error resolution: Level 0 (Customer): Documentation of an issue in the Support Case Report; Level 1 (Aiden): Verification of completeness Support Case Report and acceptance of the issue; Level 2 (Aiden): Reproduction, isolation, and root cause determination, and; Level 3 (SAP): Acceptance of the issue and development support. Levels 1 and 2 shall be performed by Aiden. Support at each level shall commence only after the completion of all tasks from the preceding level.
29.4. To ensure optimal performance of Aiden Software, Aiden shall provide corrective maintenance for Aiden Software. Aiden shall identify and fix errors in Aiden Software, provided such errors are reproducible, after they have been reported by the Customer in the prescribed manner. Errors concerning Aiden Software shall be reported via the Aiden Service Web Portal. Functional improvements shall be made available as new versions from time to time, subject to additional fees.
29.5. Maintenance shall be provided remotely. If the Customer specifically requests on-site maintenance, and if Aiden deems this necessary for technical reasons, maintenance may be performed at the Customer’s location at the applicable hourly rates, which shall be charged based on actual costs incurred.
29.6. Errors may be reported on Working Days between 08:30 and 17:30. Aiden shall advise the Customer on how to resolve, avoid, or work around the issue until a new version of the Software Products is generally available, which contains a fix for the reported issue. The Customer must report errors in the prescribed manner, as set out in Clauses 29.3 and 29.4. An error report shall only be processed if the error is reproducible.
29.7. The Customer shall maintain an adequate network connection (with sufficient response time) for remote support with Aiden and/or SAP and shall ensure the availability of a modern web browser.
29.8. SAP recognises four (4) categories of errors: Very High, High, Medium and Low, as defined in the SAP Service Web portal. Provided that SAP Software errors are reported in accordance with the prescribed method, Aiden shall commence Level 1 error resolution within one (1) hour of receiving the Support Case Report. After acceptance of the report: For Very High category errors, Level 2 error resolution shall begin immediately; for all other error categories, Level 2 error resolution shall commence in consultation with the Customer, depending on availability and category. If Development Support from SAP (Level 3) is required, SAP shall begin resolving Very High category errors within one (1) hour of accepting the report. For errors in other categories, SAP shall communicate a start time within 24 hours of acceptance. Aiden is dependent on SAP for resolving SAP Software issues, and the response times stated above may be modified by SAP with a notice period of three (3) months.
29.9. Maintenance is only available if and to the extent that the Customer has a valid right to use the Software Products for which maintenance is requested. Maintenance shall be provided only for the most recent version of the Software Products.
29.10. The maintenance agreement for the Software Products shall have an initial term of two (2) full calendar years, plus any remaining months of the current calendar year. Thereafter, maintenance shall be automatically renewed for successive one (1) year periods, unless either Party terminates maintenance in writing via registered mail. Termination must be made at the end of a calendar year, with at least three (3) months’ notice, and shall apply to all Software Products covered under maintenance.
29.11. Aiden reserves the right to terminate SAP Software maintenance at any time if SAP ceases to provide maintenance to Aiden. In such cases, the Customer may continue SAP Software maintenance directly with SAP or another certified SAP service centre.
29.12. The following services are not included in the maintenance fees: advice on usage and application of the Software Products, diagnosis, troubleshooting, and resolution of issues not attributable to Aiden, including improper use of Software Products by the Customer, incorrect or incomplete implementation of Software Products, defective interfaces with other systems, incorrect data imports, issues caused by third-party software, hardware failures, defects in operating systems and/or database systems.
Part C: Special Provisions Relating to SAP and Aiden Software Services (Service Agreement)
The terms set out in Part C shall, in addition to the General Terms and Conditions, apply if the Aiden Agreement (also) relates to services concerning the installation and implementation of SAP software products and Aiden Software, training, installation of hardware, and the system software required for the operation of SAP and Aiden Software.
30. Scope and Modification of Scope
30.1. If, at the time of entering into this Agreement, the scope of the project is not yet fully defined, the Parties acknowledge the necessity and feasibility of modifying the Project Definition during the positioning phase of the project. During this phase, Aiden and the Customer shall jointly document the required adjustments and modifications identified in Version 1 of the Project Definition. These modifications shall be recorded as they arise during the execution of the positioning phase. The revised Version 2 of the Project Definition shall then be confirmed by both Parties. Version 2 of the Project Definition shall be appended to and form an integral part of the Agreement.
30.2. If either Party wishes to modify Version 2 of the Project Definition during the project, a written request must be submitted to the other Party.
30.3. The receiving Party shall respond within a reasonable period after receipt of such a request, indicating the extent to which the proposed change is acceptable. If Aiden receives the request, it shall also indicate to what extent the requested change will impact the agreed terms, including costs and project planning. A Party may only reject a request for modification if it can provide a valid reason for doing so.
30.4. Any agreement regarding changes to the scope, including the financial implications, modifications to the project plan, and other relevant conditions, shall only take effect once confirmed by both Parties.
31. Delays in Execution
31.1. The project shall be carried out in accordance with the planning specifications stated in the Project Definition. In the event of a delay, both Parties shall endeavour to take the necessary measures, including but not limited to deploying additional resources, to adhere as closely as possible to the project schedule.
31.2. Aiden shall propose the measures that should be taken to maintain the project schedule. If Aiden recommends certain measures in writing, including but not limited to the deployment of additional resources, the Customer shall implement such recommendations, without prejudice to its other rights or obligations under the Agreement and related Annexes.
32. Delivery and Acceptance
32.1. The delivery times specified in the Project Definition shall be regarded as an estimate of the time required for Aiden to complete the agreed services. Exceeding a delivery time shall not constitute a failure by Aiden to fulfil its obligations concerning the services.
32.2. Once the project has been executed, Aiden and the Customer shall observe the following test and acceptance procedures: – Once the project is complete, Aiden shall notify the Customer in writing. – Upon receipt of this notification, the Customer shall immediately conduct the necessary acceptance tests to determine whether the project has been executed in accordance with the Project Definition and any modifications agreed upon by the Parties. – If the results of the acceptance test are satisfactory, the Customer shall immediately notify Aiden in writing that the project has been approved. The Customer may not refuse approval on the basis of an error, defect, or shortcoming that does not materially affect the operation or functionality and causes only minor disruptions, unless Aiden has failed to achieve a result explicitly specified in the Project Definition or agreed modifications. – If the results of the acceptance test are not satisfactory, the Customer shall provide Aiden with a complete list of errors, defects, and shortcomings in writing. Aiden shall rectify these within one (1) month after receiving the list. Aiden shall notify the Customer in writing once the errors, defects, and shortcomings have been resolved. The Customer may then request a new acceptance test, in which case the provisions of this article shall apply again. – If the Customer fails to notify Aiden within one (1) month after receiving Aiden’s notification that the project is complete, regarding whether the project has been approved, the Customer shall be deemed to have accepted the project. The same applies if the Customer does not notify Aiden in writing within one (1) month after receiving confirmation from Aiden that the errors, defects, and shortcomings have been resolved.
32.3. If it has been agreed that the services or project will be carried out in phases, Aiden may postpone the commencement of services for the next phase until the Customer has approved the results of the previous phase in writing and paid the corresponding invoices.
33. Defects
33.1. In the event of a Defect arising as a result of any action performed by Aiden, Aiden shall attempt to remedy the Defect as soon as possible. Aiden shall not be obliged to remedy Defects that were not caused by Aiden or its personnel. However, at its own discretion and where deemed appropriate, Aiden may attempt to remedy such Defects at the service rates applicable at that time.
34. Prices and Costs
34.1. The Customer shall compensate Aiden for services on a post-calculation basis, as stated in the applicable Aiden price list at the time; the prices are based on hourly rates. If a specific number of hours has been agreed for a particular project, this number shall serve only as an estimate, and the actual number of hours worked shall be invoiced on a post-calculation basis.
34.2. If the Customer unilaterally changes the scheduled time for Aiden to perform services within five (5) Working Days before the agreed start date of such services, the Customer shall be liable for the full amount originally agreed for those services.
35. Training
35.1. Training on the use and application of SAP software shall be provided by Aiden upon request of the Customer, subject to payment of the applicable rates. Training sessions shall take place at Aiden’s offices or, if specifically agreed, on the customer’s premises.
Part D: Special Provisions Relating to theSupplyof Hardware and System Software (Hardware and System Software Agreement)
The terms set out in Part D shall, in addition to the General Terms and Conditions, apply if the Aiden Agreement (also) relates to a Hardware and System Software contract between the Parties.
36. Delivery
36.1. Specified delivery times are approximate and provided as estimates; exceeding these timeframes shall not constitute default on the part of Aiden. Except in cases of wilful misconduct or gross negligence by Aiden, the Customer shall never be entitled to compensation for any damage resulting from the delayed or late delivery of hardware and/or system software.
37. Documentation
37.1. Aiden shall make available the standard documentation provided by the supplier for the Hardware Products in the form of at least one (copy of a) manual.
38. Transport and Transfer of Risk
38.1. Delivery shall take place at Aiden’s offices, unless Aiden and the Customer have explicitly agreed otherwise. Aiden shall arrange for transportation to the Customer’s location, and the cost of transportation, including insurance, shall be included in the hardware price, unless otherwise specified in the Agreement. Risk shall transfer upon delivery of the Hardware Products to the agreed address (ground floor only). The Customer is obliged to immediately inspect the Hardware Products upon receipt at its premises and to notify Aiden of any damage.
38.2. A Hardware Product shall be deemed accepted on the actual delivery date at the Customer’s premises or, if Aiden has contractually agreed to perform an installation, on the date of completion of the operational installation. After acceptance, no repair of defects or malfunctions shall be possible unless covered under warranty or maintenance.
38.3. Hardware products may only be returned after obtaining Aiden’s prior written consent.
39. Maintenance
39.1. If the Customer requires maintenance or an extended warranty, Aiden shall arrange such services with the supplier on behalf of the Customer, after which the Customer shall enter into a maintenance contract directly with the supplier. Based on agreements between Aiden and the supplier, Aiden shall invoice the Customer for the maintenance services, and the Customer shall be liable to pay Aiden the maintenance fees.
40. Sizing Advice
40.1. At the Customer’s request, Aiden shall provide advice regarding the server sizing in relation to the number of concurrent users. Aiden shall provide such advice based on SAP’s sizing specifications, as made available by SAP from time to time. Aiden shall not be responsible for the accuracy or completeness of the specifications provided by SAP.
Part E:Special Provisions Relating to Private Cloud Services (Private Cloud Agreement)
The terms set out in Part E shall, in addition to the General Terms and Conditions, apply if the Aiden Agreement (also) relates to a Private Cloud Services contract between the Parties.
41. Service Level of Processing
41.1. The buildings and facilities of the data centre, where Aiden’s computer systems are housed, are designed in accordance with Tier 3 Classification for data centres and are staffed 24 hours a day, 7 days a week. Aiden’s helpdesk is staffed by Aiden employees during business hours (08:30 – 17:30) on working days (excluding Saturdays, Sundays, and officially recognised Dutch public holidays) and is available for telephone support during these hours (Management Window). Outside these hours, specialists remain on standby for unforeseen incidents (Incident Intervention Window).
41.2. Aiden’s systems are available for application processing 24 hours a day, 7 days a week, excluding scheduled maintenance periods. The operating hours are agreed with the Customer as specified in the Data Processing Agreement. Scheduled maintenance will, where possible, be planned outside of regular operating hours or, where feasible, outside the Customer’s business hours. Aiden reserves the right to schedule maintenance activities during the Management Window if necessary.
41.3. Maintenance of the system environment shall be carried out by experienced Aiden personnel in accordance with the guidelines provided by the manufacturer.
41.4. The relevant components of the service are structured to meet at least the following availability levels: 1. Facilities (including power supply and cooling) 99.99%, 2. Internet connectivity 99.9%, 3. Hardware infrastructure 99.8%, 4. Applications 99.8%. Based on this, Aiden guarantees an overall availability of 99.5% for the application operating hours, measured over consecutive six-month periods, except during scheduled maintenance and incidents as referred to in Clause 41.2. The first six-month period starts from the commencement date as defined in the Private Cloud Agreement.
41.5. The system environment made available to the Customer by Aiden is determined based on the official hardware specifications of SAP and sizing specifications for Microsoft Remote Desktop Services and internet applications from HP, Lenovo, and IBM. The relevant variables are specified in the key performance indicators of the processing environment.
41.6. Aiden has entered into a maintenance agreement with a service provider, ensuring 24/7 availability for the resolution of hardware failures.
41.7. A full copy of all modified files is made once every 24 hours. These copies are replicated to a secondary computer system located in a separate Tier 3 data centre. The minimum distance between both data centres is 4.5 km. The retention period for these daily copies is 31 days.
41.8. Downtime or disruptions caused by deficiencies in the Customer’s local hardware, failures due to malfunctioning connectivity between the Customer’s location and the data centre, and exceeding the key performance indicators specified in the processing environment, which may affect service levels, shall not be attributed to Aiden.
41.9. The Customer acknowledges that Aiden is dependent on SAP in certain situations for the proper functioning and service level of SAP application processing. If an issue or defect is suspected to be within the source code, Aiden shall not be held liable, except for its obligation to coordinate maintenance activities and implement reasonable workarounds where possible.
42. Recovery and Contingency
42.1. If the Customer’s data is lost or becomes unusable, Aiden shall ensure that, upon detection of this issue, data is technically restored within a minimum of 8 hours (if detected during the Management Window) or within a minimum of 16 hours (if detected during the Incident Intervention Window). Recovery shall be performed using the most recent available copy.
43. Warranties
43.1. The Customer warrants that it shall strictly comply with the terms and conditions regarding the provision of usage rights and maintenance for SAP and Aiden software, as set forth in a separate agreement.
43.2. Aiden warrants that the Computer Systems located in the data centres shall be maintained in such a state that the number of error notifications and system downtime due to Computer System failures shall remain within the permitted levels.
44.Processing Service Costs and Fees
44.1. The rates for the services to be provided by Aiden are set forth in the Private Cloud Agreement. All amounts are exclusive of VAT and any other government-imposed levies.
44.2. The processing rates specified in the Private Cloud Agreement do not include: – Cost of connectivity between Customer’s location and the data centre. – Costs of storage media made available to the Customer and the associated transport costs. – Maintenance of applications that were not provided by SAP or Aiden. – Microsoft Office software licenses and maintenance. – Costs for programming assistance and custom software development. – Costs for the Customer’s hardware and software. – Costs of modems/routers at the Customer’s location. – Functional consultancy, including implementation support. – Any other costs explicitly payable by Customer in accordance with the provisions of this Agreement.
44.3. If the number of Named Users or the number of administrations changes, Aiden shall adjust the monthly processing fee accordingly. If the adjustment results in a reduction in the number of Named Users or administrations, the adjustment shall only be implemented once the agreed minimum number of Named Users and administrations has been reached. The Customer must notify Aiden in writing in advance of any changes in the number of Named Users and administrations. Aiden shall provide the Customer with a proposal for the revised processing fee.
44.4. The provision of a test environment and the technical setup of a new version of the applications are included in the monthly processing fee. This shall generally take place once per year.
44.5. In the event of changes to the key performance indicators of the processing environment, as defined in the Data Processing Agreement and not covered under Clause 44.3, Aiden may, if such changes impact the processing environment, reasonably adjust the monthly processing fees on an interim basis.
45. The Customer’s Responsibilities
45.1. The Customer shall ensure that its employees involved in the execution of this Agreement follow the relevant training courses, which shall be determined in mutual consultation with Aiden. The Customer shall at all times appoint an administrator, who shall act as the main point of contact for Aiden regarding all aspects related to service execution.
45.2. The version of the applications specified in the Data Processing Agreement shall be made available by Aiden as long as SAP maintains it. The Customer shall adopt new versions in a timely manner.
45.3. The Customer is solely responsible for the proper functioning of the locally installed hardware and software at its premises, unless explicitly stated otherwise in the Data Processing Agreement.
45.4. If the configuration of the application or its use by the Customer demonstrably has a negative impact on Aiden’s processing environment, Aiden may, after consultation, prescribe changes to the configuration or usage.
45.5. The data shall remain the property of the Customer. Upon termination of this Agreement and payment of all outstanding invoices, the data shall be returned to Customer, and all duplicates shall be destroyed.
45.6. Any batch processes (jobs) shall be started and scheduled by the Customer within the agreed times.
45.7. Any irregularities must be reported to the helpdesk within the agreed times. Only reported incidents shall be considered in measuring service availability.
Part F: Data Processing Agreement
The terms set out in Part F shall, in addition to the General Terms and Conditions, apply if Aiden acts as a processor of personal data on behalf of the Customer.
46. Definitions
46.1. In these Special Provisions on Data Protection, in addition to the definitions (written in lower case) as used in the applicable data protection legislation (for example, data subject, processing, etc.), the following terms (written in uppercase) shall have the following meanings, regardless of whether they are used in plural or singular: – Breach: A security breach that accidentally or unlawfully results in the destruction, loss, alteration, or unauthorised disclosure of, or access to, transmitted, stored, or otherwise processed Personal Data. – Agreement: the (main) agreement concluded between the Processor and the Controller. – Personal Data: The personal data as defined under the Applicable Law that is processed by the Processor on behalf of the Controller for the purposes of the Agreement. – Applicable Law: The applicable data protection laws and regulations, including the General Data Protection Regulation (Regulation (EU) 2016/679 of 27 April 2016) on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, repealing Directive 95/46/EC (the GDPR), and any national implementing legislation (the UAVG) as applicable from the date of enforcement.
46.2. Controller: The Customer.
46.3 Processor: Aiden Netherlands B.V. (Aiden).
47. Execution of Processing
47.1. If and to the extent that the assignment under the Agreement includes the Processing of Personal Data by the Processor on behalf of the Controller, the provisions of this Annex shall apply.
47.2. The Processor shall process the Personal Data under the responsibility of the Controller on the Controller’s written instructions (including the assignment as stated in the Agreement, the instructions in this Annex, and any additional written instructions agreed upon), or where required by law (including compliance with a valid judicial order, a binding instruction from an authority, or a lawful request from a competent supervisory body such as the Dutch Data Protection Authority (Autoriteit Persoonsgegevens)). This is without prejudice to the Controller’s responsibility to ensure that its instructions comply with Applicable Law. If these instructions exceed the contractual obligations of the Processor under the Agreement (including this Annex), and result in additional costs or impact the agreed timelines, the obligation to carry out such instructions shall only arise once the Parties have reached a written agreement on these aspects.
47.3. The Processor shall process the Personal Data in a proper and careful manner, as further specified in the Agreement and this Annex, and in compliance with Applicable Law. The processing shall relate to the specified processing purposes, categories of Personal Data and data subjects, and the processing activities as defined by the Controller and set out in Table A of this Annex.
47.4. The Controller shall be responsible for providing Personal Data accurately and completely. The Controller is also obliged to verify the accuracy and completeness of the processed Personal Data.
47.5. The Controller warrants to the Processor that the content, usage, and assigned processing activities do not violate any laws or the rights of data subjects, and that the Personal Data has been obtained lawfully, in compliance with all legal requirements, particularly those under Applicable Law.
47.6. The Processor shall, where reasonably within its control, and taking into account the nature of the Processing, assist the Controller by implementing appropriate technical and organisational measures, to the extent possible, to help the Controller fulfil its legal obligations under Applicable Law. This includes, where relevant, conducting a Data Protection Impact Assessment (DPIA) under Article 35 GDPR, and facilitating the exercise of data subjects’ rights under Applicable Law. The Processor shall be entitled to charge the Controller for the reasonable costs associated with such assistance.
48. Security of Personal Data
48.1. The Processor shall implement appropriate technical and organisational security measures, that, considering the current state of technology and associated costs, correspond to the nature of the Personal Data and the assignment in which the data is processed. These measures are intended to protect the Personal Data against loss or unlawful processing, in accordance with Article 13 of the Dutch Data Protection Act (Wbp) and Article 32 of the GDPR, as further detailed in the following section. 48.2. The security measures implemented by the Processor shall include:
48.2.1. Access control:
48.2.1.1. Physical access control to infrastructure:
48.2.1.1.1. Adequate physical protection of the premises and equipment where Personal Data is stored (such as access security, temperature regulation, and measures to prevent and combat fire and water damage).
48.2.1.2. Logical access control (system access control):
48.2.1.2.1. The installation and maintenance of an up-to-date system to protect access to Personal Data using an appropriate authentication method, such as a username and password.
48.2.1.2.2. Protection of the system used for processing Personal Data, including up-to-date virus, trojan, and malware detection software.
48.2.1.2.3. Monitoring and logging of system access, including checks for unauthorised access attempts, such as failed login attempts and unauthorised access attempts.
48.2.1.2.4. Designation of employees under the direct authority (supervision and control) of the Processor who are authorised to access Personal Data on a ‘need-to-know’ basis.
48.2.1.2.5. The Processor shall maintain a logbook of security breaches, as well as the measures taken in response to such breaches, and shall provide the Controller access to this information upon request.
48.2.2. Employee Awareness
48.2.2.1. The Processor shall ensure that its employees receive appropriate training on their responsibilities regarding the security and processing of Personal Data.
48.3. To ensure the quality and compliance with the agreed Service Level Agreement (SLA) for Cloud services, the Processor shall comply with relevant ISO 27002 standards, including requirements related to: – Access security (logical and physical access control) – Change management – Business continuity
48.4. The Controller shall notify the Processor without unreasonable delay if it receives a directive or notice from a competent authority (such as the Dutch Data Protection Authority – Autoriteit Persoonsgegevens) regarding Personal Data.
49.Audit
49.1. The Processor shall undergo an annual audit conducted by an external auditor.
49.2. The Processor shall provide the Controller with a copy of the audit report upon request. The Controller has the right to monitor the Processor’s compliance with its obligations under this Annex. The Processor shall grant the Controller one audit per year, to be scheduled by mutual agreement on a specific date and time, with a jointly determined scope of investigation. In addition, if the Controller has a well-founded suspicion that the Processor is not complying with its obligations, the Controller shall have the right to conduct additional audits under the same mutual agreement terms.
49.3. The Processor shall reasonably cooperate with the audit and shall be entitled to reimbursement for its costs incurred in relation to the audit.
49.4. The costs of the audit shall be borne by the Controller, unless the audit reveals that the Processor has failed to comply with its obligations under this Annex. In such a case, the reasonable and actual costs of the audit shall be borne by the Processor, upon presentation of supporting invoices.
49.5. The Controller shall engage an independent, certified auditor with expertise in verifying compliance with Applicable Law. The auditor must sign a confidentiality agreement before commencing the audit.
49.6. The audit (including documentation and other relevant information) and its results shall be treated as confidential by the Controller and the external auditor. The audit results may only be shared with third parties with prior written consent from the Processor, which shall not be unreasonably withheld. No consent is required if disclosure is legally mandated or requested by a competent authority.
49.7. The Controller shall ensure that the audit is conducted in a manner that minimises disruptions to the Processor’s operations while ensuring the protection of third-party personal data and the confidentiality of third-party information. The scope of the audit shall be limited to what is necessary to objectively determine the Processor’s compliance with this Annex.
49.8. Controller shall provide the Processor with a full, unaltered copy of the audit results in a readable and durable format as soon as possible, to the extent that the results pertain to the Processor and its sub-processors.
49.9. Following the audit, the Controller and Processor shall consult to determine whether adjustments to organisational and security measures are necessary to comply with current data protection laws, and to agree who shall bear the associated costs.
49.10. In the event that a competent supervisory authority (such as the Dutch Data Protection Authority) issues a binding order requiring modifications to organisational and security measures, the Parties shall immediately consult to determine the necessary steps for compliance and who shall bear the costs.
49.11. In the event of a change in Applicable Law, the Parties shall promptly consult to determine any necessary adjustments to organisational and security measures, as well as potential amendments to this Annex, and who shall bear the costs of such changes.
50. Secrecy
50.1. The Processor shall be obliged to maintain the confidentiality of any Personal Data provided to it by the Controller, except where disclosure or provision is necessary for the execution of the assignment as set out in the Agreement, results from a supplementary written instruction from the Controller, arises from a legal obligation (including where processing is required pursuant to a legally binding judicial order, an official mandate from an authorised body, a legally binding instruction, or a lawful request from the relevant supervisory authority, such as the Dutch Data Protection Authority), or where prior written consent has been obtained from the Controller.
50.2. The Processor shall ensure that any person acting under its authority is also bound by the duty of confidentiality regarding the Personal Data they process, in accordance with the previous clause.
51. Security Incidents (Data-Breach Notification Obligation)
51.1. If the Processor discovers a Breach, it shall (i) without undue delay notify the Controller of the Breach in accordance with Applicable Law; and (ii) take reasonable measures as specified in article 3 to mitigate the Breach and prevent further or future Breaches.
51.2. The Processor shall, taking into account the nature of the processing and the information available to it, provide reasonable support to the Controller and keep it informed of (new developments concerning) the Breach.
51.3. The notification to the Controller shall include at least:
51.3.1. the (currently known and/or anticipated) consequences of the Breach;
51.3.2. which categories of Personal Data were affected by the Breach; 2.3.3. whether and how the Personal Data was cryptographically secured;
51.3.4. the (proposed) measures to mitigate the consequences of the Breach or to prevent further Breaches;
51.3.5. the (currently known) categories of affected data subjects;
51.3.6. the (currently known) approximate number of affected data subjects; and
51.3.7. any alternative contact details for follow-up of the notification. The notification shall be made by email/telephone/text message to the data protection officer of the Controller.
51.4. Where necessary, the Processor shall assist the Controller in properly informing the supervisory authority(ies) and data subjects about the relevant security incident, in accordance with the requirements of Applicable Law.
51.5. Without prejudice to the provisions of Article 5.1, the Parties shall maintain strict confidentiality regarding any Breaches and shall only report such Breaches to the competent supervisory authority(ies) and any affected data subjects in accordance with Applicable Law.
52. Use of Sub-Processors
52.1. The Processor shall be entitled to use sub-processors within the European Economic Area for the purposes of this Annex, as well as third parties in countries that have been recognised by the European Commission as providing an adequate level of data protection. If the sub-processor is located in a country not covered by the foregoing, the Processor shall obtain prior written consent from the Controller before engaging such sub-processor, whose consent shall not be unreasonably withheld. The Processor shall inform the Controller of the type and location of any sub-processors it engages.
52.2. Before replacing an existing sub-processor or engaging a new sub-processor, the Processor shall notify the Controller in writing. If the Controller has reasonable objections to the proposed change or addition of a specific sub-processor, it may submit a written objection within thirty (30) days of the date of the notice. If the Controller submits a justified objection and the Parties cannot reasonably reach an agreement regarding the use of an alternative sub-processor, the Controller shall have the right to terminate the Agreement insofar as it pertains to the relevant sub-processor, effective as of the date the change or addition takes effect, without the Processor being liable for any compensation to the Controller as a result of the termination.
52.3. The Processor shall impose the same obligations on its sub-processors as those that apply to it under this Annex.
53. Liability
53.1. The Processor shall be liable only to the extent and under the conditions agreed in Annex 1 (General Provisions SAP Agreements).
53.2. An administrative fine imposed by the competent supervisory authority (in the Netherlands: the Dutch Data Protection Authority) on the Controller cannot be recovered from the Processor if the supervisory authority has taken the level of culpability of both parties into account when imposing the fine and has assigned the fine accordingly to one or both Parties.
53.3. If claims arise from the same or related circumstances across multiple legal relationships between the Parties, no accumulation of claims shall occur.
53.4. This article shall not apply if and insofar as it conflicts with mandatory law (from which the Parties cannot deviate).
54. Consequences of Termination
54.1. The Controller shall be responsible for determining the retention periods for the Personal Data. Where the Controller can delete or remove Personal Data itself using the functionality provided within the application, it shall do so in a timely manner.
54.2. The Processor shall not retain Personal Data beyond the retention period specified by the Controller in writing, but in any case, not beyond the end of the Agreement, subject to the provisions below. Upon termination of the Agreement, the Processor shall, without undue delay, at the Controller’s choice and unless a legal obligation dictates otherwise: (a) At the request and expense of the Controller, return the Personal Data stored on the Processor’s managed infrastructure within a reasonable timeframe after the end of the Agreement; (b) At the request and expense of the Controller, erase the Personal Data stored on the Processor’s managed system as soon as possible; (c) Delete all existing copies of the Personal Data (including backups) as soon as possible. The Controller must notify the Processor of its choice in writing before the Agreement’s termination, unless it is unreasonable to expect such notification in advance. In that case, a justified request must be received by the Processor no later than two calendar weeks after the end of the Agreement. If the Controller does not notify the Processor in writing within thirty (30) calendar days after the Agreement’s termination that it wishes to receive the Personal Data stored on the Processor’s managed system, the Controller hereby instructs the Processor in advance to delete the remaining Personal Data from its managed infrastructure after the expiry of the aforementioned thirty (30) calendar days.
Table A
Overview of the nature and purpose of processing, categories of personal data, categories of data subjects, processing activities, and retention period(s)
| Categoriesof Personal Data | Purpose of Processing by the Controller | Processing Activities | Categories of Data Subjects(Identified or identifiable natural persons) | Retention Period |
| Type:‘Regular’ personal dataCategories: Name Address and contact details Date of birth Gender Marital status Occupational information Location data (e.g. travel records) Connection data (from employees who actually use the agreed-upon service on behalf of the Controller, such as IP address, activity logs, etc.) | The outsourcing of the processing, storage, and application management of:☐SAP Business One ☐ Magento shop ☐ Retail XML (Please tick all that apply) | Storage (hosting); Access/consultation for the purpose of application management and database management (including helpdesk support); Creating backups and restoring data when necessary; Deletion of data; For further details, refer to the Cloud Agreement Addendum (if applicable). | Any vulnerable groups to be specified separately (for example, employees with an intellectual disability) | Retention period after termination of the Agreement: 1 month Backup retention period: See Annex 5 of the Cloud Agreement |
| Type:Personal data considered (fraud-) sensitive (not special-category personal data)Categories: Identification numbers (e.g., Citizen Service Number (BSN), employee number) Financial and economic data (e.g., bank details, salary information) Copies of identity documents Login credentials (from employees who actually use the agreed-upon service on behalf of the Controller) | The outsourcing of the processing, storage, and application management of: ☐ SAP Business One ☐ Magento shop ☐ Retail XML (Please tick all that apply) | Storage (hosting); Access/consultation for the purpose of application management and database management (including helpdesk support); Creating backups and restoring data when necessary; Deletion of data; For further details, refer to the Cloud Agreement Addendum (if applicable). | Any vulnerable groups to be specified separately (for example, employees with an intellectual disability) | Retention period after termination of the Agreement: 1 month Backup retention period: See Annex 5 of the Cloud Agreement |
| Type:Special-category personal data | Not applicable | Not applicable | Not applicable | Not applicable |
Categories of special-category personal data include: race or ethnic background; health; sexual orientation; genetic data; biometric data for unique identification; religious or philosophical beliefs; political opinions; trade-union membership; criminal records.