Terms of Service | Pepposh – e-invoicing | Dativery
TERMS AND CONDITIONS FOR THE PEPPOL INTEGRATION SERVICE (PEPPOSH)
(hereinafter the “Terms”) issued by Dativery s.r.o., Company ID: 055 74 617, registered office at Olešná 51, 338 24 Němčovice, represented by Ing. Petr Ferschmann, Managing Director, registered in the Commercial Register kept by the Regional Court in Plzeň, file ref. C 33457 (hereinafter the “Provider” or “we”).
Before you begin using our Pepposh service, please read these Terms carefully. Your access to and use of the service is conditioned on your acceptance of and compliance with these Terms and the Data Processing Agreement (DPA). These Terms apply to all Users and others who access or use the service.
By accessing or using the service, you agree to be bound by these Terms. Once you start using the service, these Terms, including all URL references, shall constitute the entire legally binding agreement between you as a user of the service and us. If you disagree with any part of the Terms or the DPA, you may not access the service.
TERMS AND DEFINITIONS
Unless otherwise specified in these Terms or clearly implied by context, capitalised terms used in these Terms in the singular or plural have the following meanings:
| AML | a set of measures and procedures to prevent money laundering and terrorist financing (Anti-Money Laundering) required by applicable law |
|---|---|
| Price List | sets the amount of the Fee for the Service provided under these Terms to the User; it forms part of the Terms and is published on the Service website, in the pricing section, or directly in the Dashboard; |
| Additional User | a person invited by the User into their User Account via an invitation sent to the Additional User’s email address after it has been entered in the relevant section of the Dashboard; |
| Dashboard | the user interface available at app.peppos.cz, which is made available to the User for proper use of the Service; |
| Billing Period | the time period for payment of the Subscription, generally one month; |
| GDPR | Regulation (EU) 2016/679 of the European Parliament and of the Council; |
| Unit Fees | a fixed rate charged for each individual electronic document sent or received that exceeds the basic limit (the number of documents included in the price) set within the agreed Tariff Plan for the given Billing Period. The specific amount of Unit Fees for each Tariff Plan is set out in the applicable Price List and these fees are charged by deduction from the User’s Credit; |
| Credit | a prepaid financial balance in the User Account, from which the Provider automatically deducts charges for documents transferred in excess of the limit, at the rate stated in the Price List under the selected Tariff Plan or for supplementary services; |
| KYC | the process of verifying the identity of the User and their end clients (Know Your Customer) in accordance with the applicable laws of the relevant EU member state; |
| Necessary Maintenance | means regular maintenance required to maintain the properties of Pepposh, carried out at the Provider’s initiative and constituting a period during which the Service is wholly or partially unavailable; |
| Fee | a collective term for the remuneration paid by the User to the Provider for the provision of the Service, in the amount set out in the applicable Price List; |
| Personal Data | any information about a data subject by which they can be directly or indirectly identified; |
| Peppol | a standardised network for the electronic exchange of business documents known as Pan-European Public Procurement Online, managed by OpenPeppol AISBL, ID: 0848 934 496. |
| Pepposh or Service | a service provided in the form of software as a service that connects to the Peppol network via the Provider’s software interface and related infrastructure, primarily using an API key, enabling the sending and receiving of electronic documents within the Peppol network without the Users being directly connected to it, as they are provided access by the Provider as a certified Peppol partner, and enabling KYC facilitation; |
| Business Hours | the Provider’s working hours, being working days from 9:00 to 16:00. During these hours, the Provider provides Users with technical support either by phone at +420 377 477 761 or by email at peppol@dativery.com. |
| Subscription | a regular recurring flat-rate payment for the use of the Service within the selected Tariff Plan. The amount of the Subscription is set out in the Price List and is paid for the agreed Billing Period (generally one month); |
| Consumer | any natural person who deals with us outside the scope of their business activity or independent professional activity; |
| Tariff Plan | the mode of using the Service, within which the scope of features provided depends on the plan purchased. The price for each plan is stated per Billing Period. |
| User | a registered customer of the Provider who has been given a User Account for Pepposh following successful registration (also referred to as “you”); |
| User Account | a Pepposh account created by the User under these Terms exclusively for the purpose of using the Service; |
| Force Majeure | has the meaning given in Section 10 (Force Majeure); |
(the Provider and the User together the “Parties” and individually a “Party”)
-
CONDITIONS OF SERVICE
-
User Representations. The User represents and warrants that:
-
they have full legal capacity;
-
all information they provide to Pepposh is true, complete, accurate and correct;
-
they will not use Pepposh in contravention of the applicable laws of the Czech Republic;
-
they will use Pepposh only for the purpose for which it is intended;
-
they have carefully read these Terms prior to using Pepposh, agree to them unconditionally, and will not use Pepposh in contravention of them.
-
-
Obligations of the Parties. The Provider provides the User with the Services subject to the conditions set out below. The User accepts the Services subject to the conditions set out below and undertakes to pay the Provider the Fee in accordance with the Price List for their use.
-
Scope of the Service. The provision of the Service includes in particular:
-
the User’s right to use the Service;
-
the User’s right to have and use a User Account for Pepposh;
-
the User’s right to create and provide one or more accesses to Additional Users to Pepposh through the User Account;
-
the right to use AML identification (KYC) as part of the Service;
-
the User’s obligation to pay the agreed Fee in accordance with the current Price List.
-
-
User Age. The Provider declares that the Services are not intended for persons under the age of 16.
-
Service Not Intended for Consumers. The Services are not intended for Consumers, but for businesses or persons carrying on an independent professional activity, or public authorities. You declare that you will use the Services as a business, a public authority, or on its behalf, exclusively for purposes related to such activity.
-
Use of the Service by a Consumer. If you as a Consumer wish to use the Service, you are required to inform us before creating a User Account so that you can be advised of your rights.
-
-
INTELLECTUAL PROPERTY
-
Pepposh. Pepposh, as well as all software associated with it, is the intellectual property of the Provider.
-
Scope of Rights (Licence). Nothing in these Terms shall be construed as an assignment of copyright. The Provider grants the User, for the duration of the contractual relationship, a non-exclusive, non-transferable, and territorially unrestricted licence (right of use) to access the Service and the Dashboard exclusively for the purpose of their proper use in accordance with these Terms for the duration of the contractual relationship under these Terms (but not longer than the duration of the property rights to the Dashboard). The User is not entitled to grant sublicences to third parties or to assign the licence to a third party.
-
Licence Fee. The licence fee is included in the total Fee.
-
Infringement of Intellectual Property Rights by the User. If the User breaches the obligations set out in this section, the Provider shall be entitled to withdraw from the contractual relationship under these Terms and to claim from the User compensation for all damage arising from such breach, including non-material harm.
-
Further Intellectual Property. If, in the course of the Provider’s performance under these Terms, any work is created that is protected under copyright law (in particular a work or a database) or as any other protected intangible asset, such work shall become part of Pepposh and the Terms for the use of Pepposh shall also apply to such work.
-
-
USER REGISTRATION
-
User Registration as a Condition of Use. Registration is a prerequisite for access to Pepposh and proper use of the Service; the User acknowledges this condition and undertakes to complete a proper registration.
-
How to Register. Registration is completed by filling in the registration form at https://app.peppos.cz/login. By completing registration, the User confirms that they have read and agree to these Terms of Use of the Service.
-
Accuracy, Completeness, and Updates. The User undertakes to provide correct and complete personal data in the registration form. The User is obliged to keep such data up to date. The User also has the right to change and supplement their registration data during the use of the Service.
-
Reporting Obligation in the Event of Misuse of Access Credentials. The User is obliged to immediately notify the Provider of any misuse or even an attempt to misuse their access credentials and must immediately choose new access credentials for their User Account. The User is obliged to choose a secure password.
-
-
REGISTRATION OF ADDITIONAL USERS
-
Inviting an Additional User. The User has the right to invite Additional Users to their User Account. In such a case, they are obliged to provide the correct identifying details of the new Additional User.
-
Registration of an Additional User as a Condition of Use. Registration is a prerequisite for access to Pepposh and proper use of the Service by an Additional User. The Additional User acknowledges this condition and undertakes to complete a proper registration.
-
Agreement to the Terms. Upon registration after clicking on the invitation sent by the User to the Additional User’s email address, the Additional User agrees to use the Service under these Terms, and all conditions of the Service applicable to the User, including the relevant rights and obligations, shall apply mutatis mutandis to the Additional User.
-
Access Level of the Additional User. The User may set the access level for Additional Users they have invited. The individual levels determine the scope of Pepposh features to which the relevant Additional User has access within the User’s User Account. The access levels for Additional Users are as follows:
-
Administrator. Has authorisation for all activities within the User Account, including adding and removing Additional Users;
-
Member. Uses the basic features within the User Account; cannot remove Additional Users.
-
Reader. Has the right to view the User Account only; has no right to change, add or remove anything.
-
-
Liability for Damage. The Provider shall not be liable for any damage caused to the User as a result of the access level settings for Additional Users. The Provider shall also not be liable for any damage caused to the User by an Additional User invited by them.
-
-
KYC/AML RULES
-
KYC/AML Responsibility. The Peppol network and the associated facilitation of electronic document transmission (i.e. Peppol integration) are subject to strict rules for the identification and verification of entities (KYC – Know Your Customer) and applicable regulations on the prevention of money laundering and terrorist financing (AML). The Provider serves as the User’s entry point to the Peppol network.
-
KYC/AML Process Modes. The User chooses one of two modes of ensuring KYC/AML compliance:
-
User’s Own Process. The User carries out the KYC/AML process for their individual customers themselves and bears full responsibility for ensuring that no data of unverified or sanctioned entities is transmitted via the Peppol Integration.
-
Provider’s Interface. The User activates the Provider’s KYC/AML interface, which will carry out technical and administrative verification of entities on the User’s behalf.
-
-
Need to Complete KYC/AML. Without correctly and fully completed identification (KYC) in accordance with AML regulations, the User cannot use the actual connection to Peppol, send invoices or otherwise interact with Peppol through the Provider.
-
Obligation to Cooperate. The User undertakes to carry out the identification and verification of their end customers in accordance with applicable laws. The User is obliged, upon the Provider’s request and without undue delay, to demonstrate that a specific end customer has duly completed the KYC/AML process and to provide the Provider or the relevant authorities of the Peppol network with all necessary cooperation.
-
Right to Suspend the Service. The Provider reserves the right to immediately and without any compensation restrict or fully suspend the provision of the Service for any User (or their end customer) where there is a reasonable suspicion of a breach of KYC/AML rules, international sanctions lists, or if the User fails to cooperate as required by the preceding paragraph (Obligation to Cooperate).
-
-
FEE
-
The Service is Fee-Based. The Service is provided for a fee at several Tariff Plan levels in accordance with the current Price List. The User undertakes to pay the Provider the Fee in the prescribed form and amount, which may consist of the following components:
-
Subscription. A regular flat-rate charge for the selected Tariff Plan, which determines the basic functionalities of the Service.
-
Unit Fees. The price for sending or receiving 1 document beyond the basic limit of the Tariff Plan. The amount of Unit Fees varies according to the Tariff Plan selected by the User.
-
Supplementary Services. Charges for optional services such as SMS notifications.
-
-
All prices are listed in the Price List exclusive of VAT, which will be added to the Fee at the statutory rate.
-
Subscription Payment and Credit System. The Subscription is paid by non-cash means and is automatically debited from the User’s account each month via the payment method (credit card or direct debit) entered in the User Account. The User acknowledges that automatic deduction occurs at the beginning of each Billing Period. The prepaid Credit system is used for payment of Unit Fees and any supplementary services. The User tops up their Credit in the User Account, from which these fees are then automatically deducted at the rate applicable to the selected Tariff Plan.
-
Changing the Tariff Plan. The User may change their Tariff Plan at any time via their User Account in the Dashboard. The Tariff Plan is not automatically changed by the Provider – it is the User’s sole responsibility to assess the operational and financial appropriateness or suitability of the selected Tariff Plan relative to the current volume of documents transferred or the number of companies (Company ID numbers) managed. Any change to the Tariff Plan takes effect immediately. In the case of upgrading to a more expensive Tariff Plan, only a pro-rata amount corresponding to the price difference for the remaining days until the end of the current month will be automatically charged from the payment method. When downgrading to a cheaper or free Tariff Plan, the Subscription already paid for the current month is non-refundable and the new (lower) Subscription amount will only begin to be charged from the first day of the next Billing Period.
-
Changes to the Price List. The Price List may be unilaterally amended by the Provider. Information about any planned changes to the Price List will always be available on our website. Planned changes to the Price List will be notified to the affected Users at least one month before the changes take effect, in the form of a notification by email and/or in the User Account.
-
Inflation Clause. In addition to changes to the Price List under the preceding paragraph, the Fee may be increased to account for inflation such that, with effect from 1 January of each subsequent calendar year during which the contract under these Terms is in force, the Fee may be increased in line with the published values of the 12-month average inflation rate expressed as the annual change in the Harmonised Indices of Consumer Prices in the Czech Republic, as announced for the relevant calendar year by the Czech Statistical Office in Prague.
-
Application of the Inflation Clause. The Provider is not obliged to apply an increase to the Fee under the inflation clause every year. However, if the Provider did not apply the inflation-based increase in a given year, it may apply it in subsequent years; accordingly, an increase based on the inflation clause may also be applied for several prior years if the inflation clause was not used in those years. The Provider may apply an increase based on the inflation clause at a lower percentage than it is entitled to under the inflation calculation in paragraph 6.5.
-
Notice of Change Under the Inflation Clause. The Provider is obliged to notify all affected Users of the increase to the Fee under the inflation clause, as reflected in the Price List, at least 7 days before the change takes effect, by email notification and/or in the User Account. The contract under the Terms cannot be terminated earlier than at the end of the Billing Period, even if the Fee is increased under the inflation clause during that period.
-
Inflation Clause and Changes to the Price List. Application of the inflation clause does not preclude a simultaneous change to the Price List under paragraph 6.4, which may occur independently of inflation at any time during the year.
-
Payment Information. The User is obliged, when selecting the method of payment of the Fee, to provide accurate, valid and complete billing information and information about the valid payment method. If any such information changes, the User is obliged to update it in their User Account.
-
Time of Fee Payment and Service Provision. The Fee is considered paid upon receipt of funds in the agreed amount in the Provider’s bank account. The Provider is not obliged to begin providing the Service before the Subscription has been paid.
-
User Default and Temporary Restriction of Service. In the event of default in payment of the Subscription or any part thereof, in particular where for any reason the automatic deduction of the payment does not occur when the Subscription is renewed, the Provider is entitled to restrict the provision of the Service to the User under these Terms and to restore it only after the outstanding Subscription has been paid and a new or corrected payment method has been selected.
-
Overview of Payments and Tax Documents. Where the Provider is obliged to issue a tax document, it will be issued in electronic form in PDF format and sent by email.
-
-
USER RIGHTS AND OBLIGATIONS
-
User’s Commitment Regarding Use of the Service. The User undertakes that:
-
they will not take any action that would be capable of disrupting or damaging the Provider or jeopardising or preventing the provision of the Service;
-
they will not attempt to use, nor will they use, any interface other than that provided for this purpose by the Provider to access Pepposh;
-
they will not disclose to any third party any identification details and passwords required for the User’s access to Pepposh, and if they become aware of any misuse of their identification details and passwords by any third party, they will immediately inform the Provider; if the User intentionally discloses their identification details or passwords to a third party (e.g. an employee), the User shall be liable for all damage caused to the Provider by such third party;
-
they will choose a password for Pepposh that meets a high level of security for the User Account.
-
-
User Breach of These Terms. It is not a breach of the Terms if the Service is not properly provided because the User has breached a provision of these Terms. If the User breaches the obligations under the preceding paragraph of these Terms, the Provider is entitled, without prior notice, to immediately stop providing the Service to the User, deny access to the Service, and withdraw from the contractual relationship under the Terms.
-
Compensation for Damage Caused to the Provider by the User’s Breach. If the User breaches these Terms, they are obliged to compensate the Provider for all damage arising from such breach, including non-material harm.
-
User’s Technical Equipment. The User is obliged to obtain adequate technical equipment that will enable them to use the features of Pepposh under these Terms. The User is obliged to verify that their technical equipment meets Pepposh’s technical requirements before starting to use Pepposh.
-
-
PROVIDER RIGHTS AND OBLIGATIONS
-
Changes to the Service. The Provider is entitled at any time to make changes (updates) to the content and features (adding or removing content/features) of Pepposh. This occurs automatically and these Terms also apply to the updated Service. The User is not entitled to refuse changes, as the Service is provided “as is”. The User will be informed of updates to Pepposh via email, the Pepposh website, or through the User Account.
-
Objection to Changes. If the User does not agree with a change to Pepposh under the preceding paragraph, they have the right to give notice of termination within the meaning of paragraph 12.2 (Termination) of these Terms.
-
Procedure in the Event of Failures on the User’s Side. The Provider reserves the right, in the event of technical failures on the User’s side or in the Internet network, to restrict or temporarily suspend the provision of the Service, and shall inform the User thereof without undue delay. This applies in particular to Internet network outages or circumstances requiring cooperation from third parties.
-
Use of the User’s Designation in References. The User agrees that the Provider may use any trademarks, logos and trade names to identify the User as its user/customer alongside any marketing materials, on websites and/or within the Provider’s Service. For this purpose, the User grants the Provider a non-exclusive, worldwide licence to use such trademarks, logos or trade names for the duration of the contractual relationship between the User and the Provider. The User may revoke their consent and withdraw from the licence granted by sending an email to peppol@dativery.com.
-
Confidentiality. The Provider is obliged to maintain confidentiality regarding all confidential information that constitutes the User’s trade secret, obtained from the User in connection with the provision of the Service, in particular:
-
confidential accounting data received or otherwise obtained from the User;
-
other information received or otherwise obtained, expressly marked by the User as confidential.
-
-
Online Data Register. If the User has data within the Service that can be exported, the Provider will provide full assistance in the event of a transition to another provider. In particular, the Provider will supply the necessary data in an appropriate format, inform the User of the technical requirements for migration and the countries where data may be stored. For clarity, this information is set out in the online data register available on the Provider’s website.
-
Data Transfer. Users do not generally have exportable data with the Provider; however, if a particular User does have such data, the export will be provided. At the same time, the User is not entitled to any data that belongs to the Provider.
-
Option to Switch. The Provider enables termination of the Service provision with a notice period in accordance with applicable law. After termination of the contract, the Provider will provide the necessary assistance with transitioning to another provider within 30 days. The User’s data will then be retained for a further 30 days before being deleted. The User’s data is therefore retained for 60 days from the end of the Contract until deletion.
-
-
PROVIDER LIABILITY
-
Nature of the Service. The Service is a software solution (SaaS) provided exclusively on an “as-is” and “as-available” basis. The Provider gives no warranties as to the availability of the Service, its error-free operation, suitability for the User’s specific business purpose, or compliance with specific performance metrics, unless a separate service level agreement is concluded in writing between the Parties.
-
Exclusion of Liability for the Peppol Network and Other Third Parties. Given that the subject of the Service is the technical facilitation of access (connection) to the international Peppol network, the Provider shall not be liable for any delay, non-delivery, loss, or data damage to electronic documents that occurred outside the infrastructure directly controlled by the Provider. This includes in particular outages, latencies, or processing errors on the part of the Peppol network itself, end recipients, operators of other access points, or caused by the use of third-party websites, services, or software solutions to which the Service may link or with which it is connected.
-
Exclusion of Liability for the User’s Actions. The Provider shall not be liable for any material or non-material harm or for any restriction of the Service’s availability if it arose as a direct or indirect result of (i) incorrect technical integration (API), (ii) defective hardware or software on the User’s side, (iii) the User sending damaged, incomplete, incorrectly formatted or false data, (iv) the authorised suspension of the Service by the Provider due to the User’s default in paying the Fee or exhaustion of Credit, (v) non-completion, delay or failure of mandatory AML/KYC verification by the User or their end customers (including transmission blocks due to the appearance of an entity on international sanctions lists).
-
Exclusions Due to Maintenance and Force Majeure. The Provider shall not be liable for damage or harm arising from the temporary restriction or interruption of the Service for the purpose of carrying out Necessary Maintenance or necessary system updates. The Provider shall not be liable for failure to fulfil contractual obligations in cases of Force Majeure. The Provider nonetheless undertakes to make reasonable efforts to restore the Service as quickly as possible.
-
Limitation of the Provider’s Liability. The Provider shall not be liable for lost profits, loss of revenue, loss of data, damage to the User’s reputation, or any indirect, consequential, special or punitive damages arising from these Terms or in connection with the provision of the Service, regardless of the legal basis for their occurrence. The total aggregate liability of the Provider for direct actual damage caused to the User under or in connection with these Terms is limited to the amount of the Fee (exclusive of VAT) actually paid by the User for the Service for the 6-month period immediately preceding the event giving rise to the damage. If the User is on a free Tariff Plan, the Provider’s liability for damage is entirely excluded.
-
-
FORCE MAJEURE
-
Definition. For the purposes of these Terms, Force Majeure means a temporary or permanent extraordinary, unforeseeable and insurmountable obstacle arising independently of the Provider’s will that prevents the Provider from fulfilling its obligations (in particular ensuring the provision of the Service).
-
What Constitutes Force Majeure. Force Majeure includes in particular a natural disaster, fire, explosion, war, terrorist attack, epidemic, measures taken by public authorities, as well as a widespread power outage or a large-scale failure of telecommunications networks and third-party services required for the operation of the Service (e.g. global outages of hosting centres).
-
Consequences of Force Majeure. If the Provider fails to fulfil its obligations as a result of Force Majeure, it is not in default and is not obliged to compensate the User for any damage or harm. During the period of Force Majeure, the User shall have no claim to a reduction of the Fee or any other compensation.
-
Notification of Force Majeure. The Provider is obliged to immediately inform the User of the occurrence of Force Majeure and its impact on the provision of the Service, generally through the Dashboard or by email.
-
-
SUPPORT AND NECESSARY MAINTENANCE
-
Provision of Support. The Provider provides Users with technical support during Business Hours, being working days from 9:00 to 16:00. The User may contact the Provider’s technical support either by phone at +420 377 477 761 or by email at peppol@dativery.com.
-
Necessary Maintenance. It is not a breach of these Terms if the Services are not provided as a result of Necessary Maintenance. Necessary Maintenance is generally announced in advance via the User Account.
-
Notice of Necessary Maintenance. The User is obliged to tolerate a short-term shutdown of the Service consisting of its restriction or interruption; the User will generally be notified of this via a notification in the User Account or by email at least 12 hours in advance. Such notice will state the type of maintenance to be carried out and the expected start and end times.
-
Updates. In addition to Necessary Maintenance, the Provider will also carry out free updates to Pepposh. The aim of these updates is to improve the provision of the Service and ease of use within the User Account. The Provider is also entitled to restrict or suspend the provision of the Service for the time strictly necessary to carry out an update. The Provider generally notifies the User of updates via the User Account or by email.
-
-
DURATION AND TERMINATION OF THE CONTRACTUAL RELATIONSHIP
-
Duration of the Contractual Relationship. This contractual relationship is concluded for an indefinite period from the moment the User registers for the Service.
-
Termination. The Provider and the User each have the right to unilaterally terminate this contractual relationship under these Terms without stating a reason. The contractual relationship under these Terms shall be deemed terminated on the last day of the Billing Period in which the notice of termination was delivered to the other Party.
-
Deemed Termination. The contractual relationship under these Terms shall be deemed terminated after 2 years have elapsed since the last login to the User Account. In such a case, the Provider is entitled to delete the User’s User Account.
-
Loss of Capacity to Provide the Service. The User agrees that, in the event the Provider loses, through no fault of its own, the capacity to provide the Service – for example, due to a change in applicable law – the contractual relationship under these Terms shall be deemed terminated at that moment, and this shall not be considered a breach of these Terms.
-
Material Breach of the Terms. The Provider has the right to restrict or withhold the Service, block the User Account, and immediately withdraw from the contractual relationship under these Terms upon discovering a material breach. A material breach of the Terms includes in particular:
-
any action by the User that is capable of endangering in any way the software required to provide the Service;
-
the User acting in contravention of these Terms;
-
the User using Pepposh in a manner that could damage the Provider and/or the User having even attempted to misuse, block, modify, or otherwise alter any component of the Service;
-
the User having even attempted to obtain the login names and/or passwords of other Pepposh Users.
-
-
Fee Already Paid and Material Breach of the Terms. In the event of termination of the contractual relationship under the preceding paragraph of these Terms, the User shall have no right to a refund of any pro-rata portion of the Fee already paid for the use of the Service.
-
-
PROTECTION OF PERSONAL DATA
-
Provider as Data Processor. Users entrust us with Personal Data about their customers or other persons. Details of our obligations as a data processor are set out in the Data Processing Agreement (DPA), which is Annex No. 1 and an integral part of these Terms.
-
Provider as Data Controller. Information on how we handle Personal Data can be found in the Privacy Policy.
-
-
FINAL PROVISIONS
-
Governing Law. These Terms are governed by the laws of the Czech Republic, and the conflict-of-law rules of private international law are expressly excluded.
-
Amicable Dispute Resolution, Jurisdiction. We will always attempt to resolve any dispute arising between us amicably. If an amicable resolution is not possible, the matter shall be referred to the courts. We agree that any disputes arising in connection with the use of the Service shall be resolved by the court with subject-matter and local jurisdiction for the municipality of Němčovice in the Czech Republic.
-
Survival of Provisions Following Termination. The rights and obligations set out in Section 2 (Intellectual Property), Section 9 (Provider Liability) and paragraph 12.6 (Fee Already Paid and Material Breach of the Terms) shall remain in force after termination of the contractual relationship under these Terms.
-
Amendments to the Terms. These Terms may be unilaterally amended or revoked in writing by the Provider.
-
Statement on Legal Succession. The Parties declare and agree that the rights and obligations arising from these Terms shall, in the event of dissolution or any other legal event resulting in the transfer of rights and obligations, pass to their legal successors.
-
Validity and Effectiveness. These Terms become valid and effective on the date of conclusion of the contractual relationship via the internet, upon submission of the User’s registration or by clicking the “I agree” button in the User Account.
-
ANNEX NO. 1 TO THE TERMS AND CONDITIONS FOR THE PEPPOL INTEGRATION SERVICE (PEPPOSH)
DATA PROCESSING AGREEMENT
(hereinafter the “Processing Agreement”) concluded between:
- You, who have decided to use the Pepposh service;
(hereinafter the “Controller” or “you”)
and
- Dativery s.r.o., Company ID: 05574617, registered office at Olešná 51, 338 24 Němčovice, represented by Ing. Petr Ferschmann, Managing Director, registered in the Commercial Register kept by the Regional Court in Plzeň, file ref. C 33457,
(hereinafter the “Processor”, “Dativery” or “we”)
(the Processor and the Controller together the “Parties” and individually a “Party”).
If you use the Pepposh service (hereinafter the “Service”), Dativery will act as the processor of the Personal Data you entrust to us. The Service is provided under the Pepposh Terms and Conditions (hereinafter the “Terms”). By entering into the contractual relationship under the Terms, you confirm that you have read and agree to this Processing Agreement, and it is legally binding on you. This Processing Agreement applies to all users who have access to or use the Service.
Please read this Processing Agreement carefully, as it defines the conditions of personal data processing under which the Service is provided. If you have any questions about the processing of Personal Data, you can contact us at any time at privacy@dativery.com.
The Parties process Personal Data in connection with the concluded contract in accordance with applicable law, in particular in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (hereinafter “GDPR”). Under the GDPR, the Parties must set out the rules of processing in writing, which they do in this Processing Agreement.
-
INTRODUCTION AND BRIEF OVERVIEW OF THE PROCESSING AGREEMENT
-
Subject Matter and Purpose of the Processing Agreement. By entering into this Processing Agreement as the Controller, you authorise the Processor to carry out the processing of Personal Data on your behalf in connection with the provision of the Service. The aim is to ensure the protection of Personal Data to the extent required by law. The scope of Personal Data processed is set out in Annex A of this Processing Agreement.
-
Pepposh Service. The Pepposh Service is provided as software as a service that connects to the Peppol network via the Provider’s software interface and related infrastructure, primarily using an API key, enabling the sending and receiving of electronic documents within the Peppol network without the Users being directly connected to it, as they are provided access by the Provider as a certified Peppol partner.
-
What the Processor and Controller Roles Mean. When using the Service, you provide us with Personal Data of which you are the Controller, which we then process on your instructions and to the extent you have chosen. When processing Personal Data, you act as the Data Controller within the meaning of Article 4(7) GDPR and Dativery acts as the Data Processor within the meaning of Article 4(8) GDPR.
-
Written Form. Pursuant to Article 28 GDPR, the Parties set out the rules of processing in writing in this Processing Agreement.
-
Definitions. The definitions of terms in the Terms shall carry the same meaning in this Processing Agreement.
-
Duration. This Processing Agreement is concluded for the duration of the contractual relationship under the Terms.
-
Conclusion and Termination. The Processing Agreement is concluded upon completion of registration to use the Service (conclusion of the contract). The Processing Agreement may be terminated under the same conditions as the termination of the use of the Service under the Terms.
-
Effects of Termination. Termination of this Processing Agreement shall also result in termination of the contractual relationship in the areas to which this Processing Agreement relates, unless the Parties agree otherwise. Termination of the Terms shall also terminate this Processing Agreement. Termination of this Processing Agreement shall not affect the Processor’s obligations regarding the return of Personal Data to the Controller or their destruction, and the obligation of confidentiality.
-
-
JOINT OBLIGATIONS OF THE CONTROLLER AND PROCESSOR
-
Lawfulness of Processing. The Controller and Processor undertake to comply with personal data protection regulations.
-
Cooperation. The Controller and Processor undertake to assist each other to the necessary and reasonable extent in fulfilling their obligations in the processing of Personal Data arising from the mutually concluded contracts and applicable law, in particular in connection with responses to the exercise of data subjects’ rights, security incidents, impact assessments, and dealings with supervisory authorities. The Parties undertake to provide the necessary materials for handling requests relating to the processing of Personal Data under the Terms. A Party shall provide such materials without undue delay, and no later than 10 working days from receipt of the request for cooperation from the other Party.
-
Incident. A Party shall notify the other party that it has become aware of a security breach within 48 hours of becoming aware of the breach. A breach means any case of breach of security of Personal Data that could potentially lead to the accidental or unlawful destruction, alteration, or unauthorised disclosure of or access to Personal Data processed under the contract in accordance with the Terms.
-
-
PROCESSOR RIGHTS AND OBLIGATIONS
-
Access Restriction. The Processor shall ensure that access to Personal Data is limited to (a) employees who process Personal Data as part of their job duties, and (b) persons who cooperate with the Processor and may process Personal Data for it in the course of such cooperation, in accordance with the conditions of this Processing Agreement and for the purpose of providing the Service under the contract in accordance with the Terms. If such persons are not subject to a statutory obligation of confidentiality, the Processor shall ensure their contractual confidentiality.
-
Processor’s Commitment Regarding Measures Taken. The Processor has adopted and undertakes to maintain throughout the duration of this Processing Agreement appropriate technical and organisational measures in accordance with the GDPR applicable to the Processor. An overview of the measures taken is set out in Annex B of this Processing Agreement.
-
Processor’s Obligations. The Processor undertakes to:
-
comply with all obligations applicable to processors of Personal Data under relevant legislation when processing personal data;
-
process Personal Data exclusively on the basis of the Controller’s instructions given under this Processing Agreement, including in matters of the transfer of Personal Data to a third country or an international organisation;
-
notify the Controller without undue delay of any inspection or other administrative proceeding initiated by the Personal Data Protection Authority or other administrative body in relation to the Processor’s processing of Personal Data, and to provide the Controller with all information about the course and results of such inspection or proceeding;
-
assist the Controller in ensuring compliance with the Controller’s obligations relating to the security of Personal Data under Articles 32 to 36 GDPR, taking into account the nature of the processing to be carried out by the Processor;
-
allow the Controller to conduct internal audits, including inspections carried out by the Controller or another auditor mandated by the Controller, provided that these are notified to the Processor one month in advance; the Processor may raise objections to any auditor mandated by the Controller who is not independent or who is in a competitive or similar position relative to the Processor. Upon objection by the Processor, the Controller is obliged to mandate a different auditor;
-
report to the Controller every breach of security of Personal Data of which it becomes aware, without undue delay and no later than 48 hours from the time it becomes aware of the security breach. The minimum content of such notification is set out in Article 33(3) GDPR;
-
keep records of all security breaches of Personal Data and remedial measures taken to ensure an appropriate level of processing security. The Processor is obliged to provide the Controller with all necessary cooperation in connection with the investigation of security breaches and the fulfilment of the Controller’s obligations under Articles 33 to 34 GDPR;
-
assist the Controller in demonstrating processes or documents that prove the Controller’s compliance with the GDPR.
-
-
Cost Reimbursement. The Parties agree that the Processor is entitled to claim from the Controller reimbursement of reasonable costs associated with providing cooperation.
-
Processor’s Duty of Confidentiality. The Processor undertakes to observe a duty of confidentiality regarding all Personal Data provided by the Controller, and shall keep it secret, shall not disclose it, and shall not make it available to a third party, whether in whole or in part, unless it is to be transferred on the basis of the Controller’s instructions or as required by law.
-
Trade Secret. All information and documents made available by the Processor to the Controller in connection with an audit or inspection form part of the Processor’s trade secret and, unless otherwise provided, are subject to the confidentiality requirements of this Processing Agreement. Such information and documents may only be disclosed to the competent supervisory authority.
-
Lawfulness of Processing. The Processor undertakes to fulfil its personal data protection obligations for the entire duration of the contract in accordance with the Terms, unless the provisions of the Terms, this Processing Agreement, or applicable law indicate that they should remain in force after its expiry.
-
Sub-processors and Engagement of a New Sub-processor. The Processor has engaged the sub-processors listed in Annex C in the processing of Personal Data. If the Processor intends to engage other processors, it shall inform the Controller before such change by email or directly in the Dashboard. If the Controller does not consent to the engagement of a new processor, it may raise an objection within 5 days of receiving the Processor’s notification. Raising an objection – and thus preventing the engagement of the new (sub-)processor – may result in the inability to use the Service.
-
Programmers and Other Specialists of the Processor. The Controller expressly consents to the engagement of additional processors – programmers and other specialists of the Processor acting as self-employed individuals who provide services to the Processor under a cooperation agreement.
-
Processor’s Obligations Upon Termination. The Processor undertakes that, upon termination of the provision of the Service, it will delete all Personal Data and, at the Controller’s request, return it, including all copies, unless EU or Czech law requires their retention. If the Controller wishes, the Processor will ensure that all commonly exportable data is transferred to the Controller, generally within 60 days of the termination of the Contract; after that period, the Processor will delete the Controller’s data.
-
-
FINAL PROVISIONS
-
Governing Law. Matters not specifically governed by this Processing Agreement are subject to generally applicable law. The Processing Agreement is governed by and shall be interpreted in accordance with the laws of the Czech Republic, in particular Act No. 89/2012 Coll., the Civil Code, as amended. The Parties agreed that trade usage shall not prevail over any provisions of the law, including provisions of the law that are not mandatory.
-
Force Majeure. The Processor shall not be liable for situations in which it was unable to fulfil its obligation under the Processing Agreement due to an event of force majeure (war, unrest, terrorism, riots, strikes, fires, epidemics or natural disasters).
-
Communication between the Parties. The Parties agree that their communication regarding the Processing Agreement (including notification of a security incident) will take place via the following email addresses:
-
Controller: the email address with which the Controller registered for the Service;
-
Processor: privacy@dativery.com.
-
-
Prohibition on Assignment. Neither Party may in any way assign or transfer the rights and obligations arising from or related to this Processing Agreement without the prior written consent of the other Party.
-
Updates and Amendments. The Processor reserves the right to amend or update this Processing Agreement. If we make changes that alter the rights and obligations under the Processing Agreement, you will be notified in a timely manner by email. If you continue to use the Service, you agree to the updated version of the Processing Agreement. If you do not agree with the changes, please stop using the Service.
-
Effectiveness. This Processing Agreement is effective in its current version from the date of effectiveness of the Terms of which it forms an annex.
-
Annexes. The following annexes form part of the Processing Agreement:
-
-
Annex A: Nature, scope, duration and purpose of the processing of Personal Data,
-
Annex B: Technical and organisational measures,
-
Annex C: List of sub-processors.
ANNEX A
TO THE DATA PROCESSING AGREEMENT
NATURE, SCOPE, DURATION AND PURPOSE OF THE PROCESSING OF PERSONAL DATA
Nature of Processing. Personal Data is processed automatically through the Processor’s systems used by the Processor to provide the Service.
Purpose. The purpose of the processing is to enable the Controller to use the Service (performance of contract), in particular by transferring data under the selected Tariff Plan.
Legal Basis for Processing. The legal basis for the processing of Personal Data in connection with the provision of the Service is the performance of a contract (in accordance with the Terms).
Scope of Processing: Depending on how the Controller uses the Service, the following Personal Data may be processed in connection with the provision of the Service:
-
Contact details: Name, surname, email, phone number, address, company registration number, registered office, order number, account number;
-
Data on tax documents: Contact details, order number, account number, invoice number; or
-
Other Personal Data transferred within the use of the Service, processed exclusively on the Controller’s instructions.
Special Categories of Personal Data. The Controller undertakes not to make available to the Processor any Personal Data falling within a special category of Personal Data within the meaning of Article 9 GDPR. Special categories of Personal Data may only be processed after express prior agreement with the Processor. What are special categories of Personal Data? These are Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, health status, or sexual life or sexual orientation of a natural person. Genetic and biometric data are also considered a special category of data if processed for the purpose of uniquely identifying a natural person.
Data Subjects. These are generally Personal Data of the Controller’s customers or clients, employees, and other cooperating persons including suppliers, users of the Controller’s websites, business partners or their employees or representatives.
Duration of Processing. Personal Data is processed for the period specified in paragraph 3.10 of the Processing Agreement.
ANNEX B
TO THE DATA PROCESSING AGREEMENT
TECHNICAL AND ORGANISATIONAL MEASURES
Technical and Organisational Measures. Security is very important to us and we continuously work to ensure your Personal Data is protected. When selecting measures, we take into account the scope of processing, the risk of processing and the state of our technology.
-
We regularly back up data;
-
We update anti-virus software systems;
-
We encrypt data using SSL/TLS (“secure sockets layer / transport layer security”) for all data transfers;
-
We use a secure https protocol;
-
Our data on servers is encrypted;
-
Access passwords to information systems (where Personal Data will be processed) and access authorisations are controlled at the individual level.
Organisational Measures. We have adopted and undertake to observe the following measures:
-
Our employees are bound by confidentiality obligations;
-
Our employees are properly trained and also regularly trained on GDPR and informed about the rules for safe working on work devices;
-
We remove authorisation data when storing API keys;
-
Access to all systems including the information system is personalised and protected by secure passwords;
-
We store passwords in the operating environment in a separate location (Safe store) where logs are kept so that we can monitor employee access to individual Users’ Personal Data.
ANNEX C
LIST OF SUB-PROCESSORS
| Processor | Address | Purpose of Use | Where is data stored? | Transfer of data outside the EU (Art. 44 GDPR and basis) | Data Processing | US/EU Framework |
|---|---|---|---|---|---|---|
| Hetzner Online GmbH | Industriestraße 25 91710 Gunzenhausen Germany | Web service | EU and outside EU | Data is transferred outside the EU on the basis of the guarantees under Articles 45 and 46 GDPR pursuant to Hetzner’s DPA and is not processed by Hetzner for its own purposes. | DPA | No |