Terms of service
Effective date: 1st of January, 2025
IT IS HEREBY AGREED1. Interpretation1.1 The definitions and rules of interpretation in this clause apply in this Agreement."Additional Use" as defined in clause 3.1."Additional Use Fee" in addition to the Annual Subscription Fees set out in the Order Form, the fees payable by the Customer to Trig for any Additional Use."Annual Subscription Fee" the annual subscription fee payable by the Customer to Trig for each year of the Subscription Term."Agreement" the Order Form and these Terms of Service."Business Day" a day other than a Saturday, Sunday or bank or public holiday in England/United States (as applicable)."Change" an amendment to the scope, nature or execution of the Permitted Use, an addition of a Permitted Use, or any other term or schedule of this Agreement."Confidential Information" information that is proprietary or confidential and is either clearly labelled as such or identified as Confidential Information in clause 10.6 or clause 10.7 or would be understood as confidential by a reasonable businessperson."Customer Data" means data inputted by the Customer, the Customer Users, or Trig on the Customer's behalf."Customer System" the hardware, software and networks used by the Customer."Customer Users" the employees, contractors, agents and representatives of the Customer who access and/or use the Platform, the Services and/or the Documentation."Customisations" means any customisations or modifications to the Platform."Documentation" any documentation related to the Platform, including technical literature and user instructions."DPA" the data protection addendum set out at Schedule 1."Effective Date" the date set out in the Order Form."LCIA" means the London Court of International Arbitration."Minimum Term" the minimum term of this Agreement as set out in the Order Form and commencing on the Effective Date."Normal Business Hours" [9am to 5pm] local time, each Business Day."Order Form" the order form, attached to these Terms of Service."Outcome Fee" the outcome fee payable by the Customer to Trig calculated in accordance with the Order Form and clause 8.3."Permitted Use" the Customer's permitted use of the Platform, Services and Documentation, as set out in the Order Form."Platform" the Trig online incentives toolkit (including the relevant software applications and any Updates)."Renewal Period" the period described in clause 13.1."Rules" means the Arbitration Rules of the LCIA, as in effect from time to time."Services" any services provided by Trig in relation to the Platform, including but not limited to advisory services in respect of incentives and consumer activation and the support services set out in the Order Form."Services Data" the data presented to the Customer as outputs as a result of the Customer's use of the Platform (excluding the Customer Data)."Subscription Fees" the subscription fees payable by the Customer to Trig which include both the Annual Subscription Fee, the Outcome Fee and any Additional Use Fees."Subscription Term" has the meaning given in clause 13.1 (being the Minimum Term together with any subsequent Renewal Periods)."Updates" any updates or upgrades to the Platform released by (or on behalf of) Trig or its licensors from time to time."Virus" anything or device (including any software, code, file or programme) which may: prevent, impair or otherwise adversely affect the operation of any computer software, hardware or network, any telecommunications service, equipment or network or any other service or device; prevent, impair or otherwise adversely affect access to or the operation of any programme or data, including the reliability of any programme or data (whether by re-arranging, altering or erasing the programme or data in whole or part or otherwise); or adversely affect the user experience, including worms, trojan horses, viruses and other similar things or devices."Vulnerability" a weakness in the computational logic (for example, code) found in software and hardware components that when exploited, results in a negative impact to the confidentiality, integrity, or availability, and the term Vulnerabilities shall be construed accordingly.1.2 The headings in this Agreement shall not affect its interpretation.1.3 A reference to legislation or a legislative provision is a reference to it as amended, extended or re-enacted from time to time and includes all subordinate legislation made from time to time under that legislation or legislative provision.1.4 References to clauses and schedule are to the clauses and schedule of this Agreement, and references to paragraphs and annexes are to paragraphs and annexes of the schedule to this Agreement.1.5 In the event of any conflict between the Order Form and these Terms of Service, the Order Form shall prevail.2. Platform licence2.1 Subject to the Customer paying the Subscription Fees and subject to clause 2.2, Trig grants the Customer a non-exclusive, non-transferable, worldwide licence, without the right to grant sublicences, to permit the Customer Users to use the Platform, the Services and the Documentation during the Subscription Term.2.2 The licence granted in clause 2.1 is limited to use of the Platform, Services and Documentation for the Customer's own internal business purposes and within the scope of the Permitted Use.2.3 The Customer undertakes that:2.3.1 each Customer User shall keep a secure password for their use of the Platform, and that each Customer User shall keep their account login and password confidential. If the Customer or Customer User becomes aware that the account login or password is known to any third parties or has been compromised, they shall notify Trig without delay so it can be deactivated;2.3.2 it shall maintain a written, up to date list of current Customer Users and provide such list to Trig on request; and2.3.3 it shall permit Trig or Trig's designated auditor to audit the Customer's use of the Platform in order to establish the Customer's compliance with this Agreement.2.4 The Customer shall not access, store, distribute or transmit any Viruses, or any material during the course of its use of the Platform that is unlawful, infringing or offensive.2.5 The Customer shall not, and it shall procure that the Customer Users shall not:2.5.1 except as may be allowed by applicable law which is incapable of exclusion by agreement between the parties and except to the extent expressly permitted under this Agreement:(a) attempt to copy, modify, develop, duplicate, create derivative works from, frame, mirror, republish, download, display, transmit, or distribute all or any portion of the Platform and/or Documentation (as applicable) in any form or media or by any means;(b) attempt to de-compile, reverse compile, disassemble, scan, reverse engineer or otherwise reduce to human-perceivable form all or any part of the Platform or attempt to discover any source code or underlying ideas or algorithms of the Platform;(c) perform penetration tests on the Platform without Trig's written consent;2.5.2 access, view or use the Platform and/or Documentation in order to build a product or service which competes with the Platform;2.5.3 use the Platform and/or Documentation to provide services to third parties or for any unauthorised or unlawful purposes;2.5.4 license, sell, rent, lease, transfer, assign, distribute, display, disclose, or otherwise commercially exploit, or otherwise make the Platform and/or Documentation available to any third party except the Customer Users;2.5.5 attempt to obtain, or assist third parties in obtaining, access to the Platform and/or Documentation, other than as permitted under this clause 2;2.5.6 circumvent or otherwise interfere with the authentication or security measures of the Platform or remove, obscure or alter any copyright notice, trademarks, logos or trade names or any other notice or identification that appear on the Platform or Documentation;2.5.7 interfere with or disrupt the integrity or performance of the Platform or include any part of the Platform in any other service or item;2.5.8 list or otherwise display or copy any code for the Platform;2.5.9 allow the transfer, transmission, export or re-export of the Platform or Documentation whether in whole or in part; or2.5.10 introduce or permit the introduction of, any Virus or Vulnerability into the Platform or Trig's network and information systems.2.6 The Customer shall not, and shall ensure the Customer Users shall not, access and/or use the Platform, Services or Documentation outside the scope of the licence granted in clause 2.1.2.7 The Customer shall use all reasonable endeavours to prevent any unauthorised access to, or use of, the Platform and/or the Documentation and, in the event of any such unauthorised access or use, promptly notify Trig.2.8 The Customer shall comply with the licence terms applicable to any third party or open source software used in the Platform where the Customer has been informed of such licence terms by Trig.2.9 Trig may deactivate any Customer User's account login and password where Trig deems it reasonably necessary, including for breaches of this Agreement.2.10 The restrictions in this clause 2 apply to each part of the Platform and to the Platform as a whole.2.11 The rights provided under this clause 2 are granted to the Customer only.3. Additional Permitted Use and Additional Use Fees3.1 Subject to clauses 3.2 and 3.3, the Customer may, from time to time during any Subscription Term, purchase the right to make additional use of the Platform, Services and Documentation in excess of the Permitted Use set out in the Order Form ("Additional Use") and Trig shall grant access to the Platform, the Services and the Documentation for such Additional Use in accordance with the provisions of this Agreement.3.2 If the Customer wishes to purchase Additional Use, the Customer shall notify Trig in writing. Trig shall evaluate such request for Additional Use and respond to the Customer with approval or rejection of the request in writing. Where the request for Additional Use is approved by Trig, the definition of Permitted Use is automatically amended to include the Additional Use.3.3 If Trig approves the Customer's request to purchase Additional Use, the Customer shall, within thirty (30) days of the date of Trig's invoice, pay to Trig the relevant Additional Use Fees as set out in the Order Form (or, if not set out in the Order Form, calculated at Trig's prevailing rates) for such Additional Use.3.4 If the Customer or the Customer Users access and/or use the Platform, Services or Documentation outside the scope of the licence granted in clause 2.1, then without prejudice to Trig's other rights and remedies, Trig may treat such access and/or use as Additional Use and charge the Customer, and the Customer shall pay Trig, the Additional Use Fees.4. Services4.1 Trig shall, during the Subscription Term, make the Platform, the Services and the Documentation available to the Customer on and subject to the terms of this Agreement.4.2 Trig shall use commercially reasonable endeavours to make the Platform available 24 hours a day, seven (7) days a week, except for planned maintenance which shall be carried out outside of Normal Business Hours where practicable and unscheduled emergency maintenance.4.3 Trig will, as part of the Services:4.3.1 provide the Customer with Trig's customer support services during Normal Business Hours; and4.3.2 implement the Updates as Trig makes them generally commercially available (and the Customer shall take such steps as Trig reasonably requires to implement the Updates).5. Data protection5.1 Trig processes Customer PI (as defined in Schedule 1) related to the Customer Users in accordance with its privacy notice which is available at https://www.tryTrig.com/.5.2 Each party shall comply with its obligations under the Data Protection Laws (as defined in Schedule 1). Where Trig processes Customer PI related to the Customer's use of the Services as the Customer's processor, the parties shall comply with the data processing obligations set out in the DPA appended at Schedule 1.6. Trig's obligations6.1 The Customer acknowledges that the Platform and the Services are provided on an "as is", "as available" basis, without warranty of any kind, whether express or implied, and that your use of the Platform and the Services is at the Customer's sole risk.6.2 Trig:6.2.1 does not warrant that the Platform or the Services will meet the Customer's specific requirements;6.2.2 does not warrant that the Customer's use of the Platform will be uninterrupted, timely or error-free;6.2.3 does not warrant that any errors in the Platform will be corrected; and6.2.4 is not responsible for any delays, delivery failures, or any other loss or damage resulting from the transfer of data over communications networks and facilities, including the internet, and the Customer acknowledges that the Platform may be subject to limitations, delays and other problems inherent in the use of such communications facilities.6.3 Whilst Trig takes appropriate steps for an organisation of its size and resources to minimise the risk of the Platform containing Vulnerabilities and Viruses, Trig cannot guarantee the same, and the Customer acknowledges its responsibility to protect its hardware, software and network (which includes implementing appropriate firewalls and anti-virus software).6.4 Trig shall follow its archiving procedures for Customer Data and Services Data. In the event of any loss or damage to Customer Data or Services Data, the Customer's exclusive remedy against Trig shall be for Trig to use reasonable commercial endeavours to restore the lost or damaged Customer Data or Services Data from the latest back-up maintained by Trig in accordance with its archiving procedure.7. Customer's obligations7.1 The Customer shall:7.1.1 provide Trig with:(a) all necessary co-operation in relation to this Agreement;(b) access to such information as may be reasonably required by Trig, in order to perform this Agreement; and(c) access to the Customer Data as reasonably required by Trig to perform this Agreement. Where the Customer Data is stored within the Customer System, the Customer shall procure for Trig the right to take such steps as are reasonably necessary to secure the transfer of the Customer Data from the Customer System to the Platform, including the implementation of application programming interfaces (APIs);7.1.2 without affecting its other obligations under this Agreement, comply with all applicable laws, including all applicable trade control and sanctions laws, relevant to its use of the Platform, and not cause Trig or its licensors to breach such laws;7.1.3 carry out its responsibilities under this Agreement in a timely and efficient manner. In the event of any delays caused by the Customer or its contractors or agents, Trig may adjust any agreed timetable or delivery schedule as reasonably necessary;7.1.4 ensure that the Customer Users are aware of, and use the Platform and the Documentation in accordance with, this Agreement and shall be responsible for any Customer User's breach of this Agreement;7.1.5 obtain and shall maintain all necessary licences, consents, and permissions necessary for Trig, its contractors and agents to access and use the Customer System and the Customer Data as envisaged by this Agreement;7.1.6 ensure that its network and systems comply with the relevant specifications provided by Trig from time to time; and7.1.7 be, to the extent permitted by law and except as otherwise expressly provided in this Agreement, solely responsible for procuring, maintaining and securing its network connections and telecommunications links from its systems to the Platform, and for all problems, conditions, delays, delivery failures and all other loss or damage arising from or relating to the Customer's network connections or telecommunications links or caused by the internet.7.2 As between the parties, the Customer shall own all right, title and interest in and to all of the Customer System and the Customer Data and shall have sole responsibility for the legality, reliability, integrity, accuracy and quality of all such Customer System and Customer Data. The Customer grants Trig a non-exclusive, royalty-free, worldwide licence, together with the right to grant sublicenses, to:7.2.1 access and use the Customer System and Customer Data for the Subscription Term to perform this Agreement; and7.2.2 use the Customer Data in anonymous or pseudonymised form on an irrevocable and perpetual basis to improve Trig's products and services.7.3 The Customer acknowledges that Trig and its licensors may collect metrics, analytics, metadata, statistics or other data related to the Customer's use of the Platform:7.3.1 to provide the Platform and Services to and for the benefit of the Customer; and7.3.2 to analyse, maintain and improve the Platform and Services, including for security purposes.7.4 The Customer warrants that Trig's use of the Customer System and the Customer Data as envisaged by this Agreement will not infringe the rights of any third party.8. Charges and payment8.1 The Customer shall pay the Subscription Fees to Trig.8.2 Unless otherwise stated in the Order Form, Trig shall invoice the Customer:8.2.1 for the Annual Subscription Fee annually in advance (the first of which shall be invoiced prior to the Effective Date and thereafter on the commencement of each Renewal Period);8.2.2 for any Outcome Fee monthly in arrears; and8.2.3 for any Additional Use Fees in advance for any Additional Use purchased in accordance with clause 3.8.3 The Outcome Fee shall be calculated on a flat fee basis or on a tiered basis dependent on the number of outcomes (as set out in the Order Form.8.4 The Customer shall pay Trig's invoices that are submitted in accordance with this Agreement within thirty (30) days of the invoice date.8.5 If Trig has not received payment within fourteen (14) days after the due date, and without prejudice to any other rights and remedies of Trig:8.5.1 Trig may, without liability to the Customer, disable the Customer's password, account and access to all or part of the Platform and Trig shall be under no obligation to provide any or all of the Platform or Services while the invoice(s) concerned remain unpaid; and8.5.2 interest shall accrue on a daily basis on such due amounts at an annual rate equal to 4% over the then current base lending rate of Bank of England from time to time, commencing on the due date and continuing until fully paid, whether before or after judgment.8.6 All amounts and fees stated or referred to in this Agreement:8.6.1 shall be payable in the currency on Trig's invoice; and8.6.2 are exclusive of value added tax, which shall be added to Trig's invoice(s) at the appropriate rate.8.7 Trig shall be entitled to increase and/or amend the Subscription Fees at the start of each Renewal Period upon at least thirty (30) days' prior notice to the Customer and the Order Form shall be deemed to have been amended accordingly.9. Proprietary rights9.1 The Customer acknowledges and agrees that Trig and/or its licensors own all intellectual property rights in the Platform, the Services, the Services Data and the Documentation. Except as expressly stated herein, this Agreement does not grant the Customer any rights to, under or in, any patents, copyright, database right, trade secrets, trade names, trademarks (whether registered or unregistered), or any other rights or licences in respect of the Platform, the Services, the Services Data or the Documentation.9.2 Where Trig agrees to carry out Customisations for the Customer (as set out in the Order Form), the intellectual property rights in such Customisations shall:9.2.1 belong to Trig so Trig can use and exploit them without restriction; and9.2.2 are licensed to the Customer as part of the Platform under this Agreement.10. Confidentiality10.1 Each party may be given access to Confidential Information from the other party. A party's Confidential Information shall not be deemed to include information that:10.1.1 is or becomes publicly known other than through any act or omission of the receiving party;10.1.2 was in the receiving party's lawful possession before the disclosure;10.1.3 is lawfully disclosed to the receiving party by a third party without restriction on disclosure; or10.1.4 is independently developed by the receiving party, which independent development can be shown by written evidence.10.2 Subject to clause 10.4, each party shall hold the other's Confidential Information in confidence and not make the other's Confidential Information available to any third party, or use the other's Confidential Information for any purpose other than the implementation of this Agreement.10.3 Each party shall ensure that the other's Confidential Information to which it has access is not disclosed, distributed or used by its officers, employees, contractors or agents in violation of this Agreement.10.4 A party may disclose Confidential Information to the extent such Confidential Information is required to be disclosed by law, by any governmental or other regulatory authority or by a court or other authority of competent jurisdiction, provided that, to the extent it is legally permitted to do so, it gives the other party as much notice of such disclosure as possible and, where notice of disclosure is not prohibited and is given in accordance with this clause 10.4, it takes into account the reasonable requests of the other party in relation to the content of such disclosure.10.5 Each party shall use at least the same degree of care with respect to the other party's Confidential Information as it uses to prevent the disclosure of its own Confidential Information, which in any event shall be no less than a reasonable standard of case.10.6 The Customer acknowledges that the Platform, the Documentation and the results of any performance tests of the Platform, are part of Trig's Confidential Information.10.7 Trig acknowledges that the Customer Data is part of the Customer's Confidential Information.10.8 Trig may use the Customer's name and logo(s) on Trig's website and marketing materials to highlight how Trig and the Customer are working together including in respect of a Customer case study. Trig shall comply with the Customer's reasonable branding guidelines in such usage. Pursuant to the foregoing, Trig and Customer shall jointly collaborate (at Trig's reasonable cost) to create a customer case study which Trig shall be entitled to publish on its website and in its marketing materials. Save for the Customer's name and logo(s), all intellectual property rights in such customer case study shall belong to Trig. Save as set out in this clause 10, no party shall make, or permit any person to make, any public announcement concerning this Agreement without the prior written consent of the other parties (such consent not to be unreasonably withheld or delayed), except as required by law, any governmental or regulatory authority (including, without limitation, any relevant securities exchange), any court or other authority of competent jurisdiction.11. Indemnity11.1 The Customer shall defend, indemnify and hold harmless Trig against claims, actions, proceedings, losses, damages, expenses and costs (including without limitation court costs and reasonable legal fees) arising out of or in connection with the Customer's use of the Services and/or Documentation and/or Trig's use of the Customer Data as permitted by this Agreement, provided that:11.1.1 the Customer is given prompt notice of any such claim;11.1.2 Trig provides reasonable co-operation to the Customer in the defence and settlement of such claim, at the Customer's expense; and11.1.3 the Customer is given sole authority to defend or settle the claim.11.2 Trig shall defend the Customer against any claim that the Customer's use of the Platform or Documentation in accordance with this Agreement infringes any third party patent, copyright or trademark, and shall indemnify the Customer for any costs, legal fees and damages awarded against the Customer pursuant to a non-appealable judgment by a court of competent jurisdiction or in settlement of such claims, provided that:11.2.1 Trig is given prompt written notice (in no event to exceed three (3) days) of any such claim;11.2.2 the Customer does not make any admission, or otherwise attempt to compromise or settle the claim and provides reasonable co-operation to Trig in the defence and settlement of such claim, at Trig's reasonable expense; and11.2.3 Trig is given sole authority to defend or settle the claim.11.3 In the defence or settlement of any claim, Trig may procure the right for the Customer to continue using the Platform, replace or modify the Platform so that it becomes non-infringing or, if such remedies are not, in Trig's reasonable opinion commercially viable, terminate this Agreement on written notice to the Customer without any additional liability or obligation to pay liquidated damages or other additional costs to the Customer.11.4 In no event shall Trig, its employees, agents and sub-contractors be liable to the Customer to the extent that the alleged infringement is based on:11.4.1 a modification of the Platform or Documentation by anyone other than Trig;11.4.2 the Customer's use of the Platform or Documentation in a manner contrary to the instructions given to the Customer by Trig;11.4.3 the Customer's use of any non-Trig products, software, services or data;11.4.4 the Customer's failure to implement any Update issued by Trig; or11.4.5 the Customer's use of the Platform or Documentation after notice of the alleged or actual infringement from Trig or any appropriate authority.11.5 The foregoing and clause 12.4.2 state the Customer's sole and exclusive rights and remedies, and Trig's entire obligations and liability, for infringement of any patent, copyright or trademark.12. Limitation of liability12.1 Except as expressly provided in this Agreement:12.1.1 the Customer assumes sole responsibility for results obtained from the use of the Platform, Services and the Documentation by the Customer, and for conclusions drawn from such use. Trig makes no guarantee or warranty that the Customer's use of the Platform, Services and Documentation will result in an increase in the Customer's revenue or activation rates with its clients;12.1.2 Trig shall have no liability for any damage caused by errors or omissions in any information or instructions provided to Trig by the Customer in connection with the Platform, or any actions taken by Trig at the Customer's direction;12.1.3 all warranties, representations, conditions and all other terms of any kind whatsoever implied by statute or common law are, to the fullest extent permitted by applicable law, excluded from this Agreement; and12.1.4 the Platform and the Documentation are provided to the Customer on an "as is" basis.12.2 Whist Trig confirms the Platform will substantially conform to the Documentation, Trig shall not be liable for the results generated from the Platform or the decisions the Customer makes as a result of using the Platform. Without prejudice to the foregoing, the Customer acknowledges that:12.2.1 the results generated by the Platform and advice provided as part of the Services are entirely dependent on the Customer Data inputted into the Platform which is the Customer's sole responsibility;12.2.2 Trig cannot guarantee that the Platform will always generate results which meet the Customer's requirements;12.2.3 Trig cannot guarantee that the Services provided on the Platform will be a perfect analysis of the Customer's business or that the recommended future actions and predicted outcomes will be accurate; and12.2.4 the results generated by the Platform and advice provided as part of the Services must not be used as the sole basis for making business decisions. The Customer must perform its own appraisal of its products, services and customer engagement using various resources to make sure its requirements are fulfilled.12.3 Nothing in this Agreement limits or excludes the liability of Trig:12.3.1 for death or personal injury caused by its negligence;12.3.2 for fraud or fraudulent misrepresentation; or12.3.3 for any other liability that cannot be lawfully limited or excluded.12.4 Subject to clause 12.3:12.4.1 Trig shall not be liable whether in tort (including for negligence or breach of statutory duty), contract, indemnity, misrepresentation, restitution or otherwise:(a) for any loss of profits, loss of business, cost of procurement of substitute products or services, depletion of goodwill and/or similar losses or pure economic loss; or(b) for any special, indirect or consequential loss, costs, damages, charges or expenses however arising under this Agreement; and12.4.2 Trig's total aggregate liability in tort (including negligence or breach of statutory duty), contract, indemnity, misrepresentation, restitution or otherwise, arising under or in connection with the performance or contemplated performance of this Agreement, shall be limited to the amount of the Subscription Fees paid by the Customer to Trig under the relevant Order Form during the Minimum Term or Renewal Period in which the claim arose.12.5 Nothing in this Agreement excludes the liability of the Customer for any breach, infringement or misappropriation of Trig's intellectual property rights.13. Term and termination13.1 This Agreement shall, unless otherwise terminated as provided in this clause 13, commence on the Effective Date and shall continue for the Minimum Term and, thereafter, this Agreement shall be automatically renewed for successive periods of one (1) months (each a Renewal Period), unless:13.1.1 the Customer notifies Trig of termination within the Minimum Term, in writing, at least thirty (30) days before the end of the Minimum Term in which case this Agreement shall terminate upon the expiry of the Minimum Term;13.1.2 the Customer notifies Trig of termination within a Renewal Period giving, in writing, at least thirty (30) days' notice to Trig;13.1.3 Trig notifies the Customer of termination at any time, whether during the Minimum Term or a Renewal Period, in writing, at least sixty (30) days' notice to the Customer; or13.1.4 otherwise terminated in accordance with this Agreement;and the Minimum Term together with any subsequent Renewal Periods shall constitute the Subscription Term.13.2 Without affecting any other right or remedy available to it, either party may terminate this Agreement with immediate effect by giving written notice to the other party if:13.2.1 the other party fails to pay any amount due under this Agreement on the due date for payment and remains in default not less than fourteen (14) days after being notified in writing to make such payment;13.2.2 the other party commits a material breach of any other term of this Agreement and (if such breach is remediable) fails to remedy that breach within a period of ten (10) Business Days after being notified in writing to do so;13.2.3 the other party is insolvent or causes an assignment for the benefit of creditors or if a resolution is passed or an order is made for the winding up of the other party (otherwise than for the purpose of solvent amalgamation or reconstruction) or if the other party becomes subject to an administration order or a receiver or administrative receiver is appointed over or an encumbrancer takes possession of any of the other party's property, or any event occurs, or proceeding is taken, with respect to the other party in any jurisdiction to which it is subject that has an effect equivalent or similar to any of the events aforementioned;13.2.4 the other party suspends or ceases, or threatens to suspend or cease, carrying on all or a substantial part of its business; or13.2.5 the other party's financial position deteriorates so far as to reasonably justify the opinion that its ability to give effect to the terms of this Agreement is in jeopardy.13.3 On termination of this Agreement for any reason:13.3.1 except for the perpetual licence in clause 7.2.2, all licences granted under this Agreement shall immediately terminate and the Customer shall cease all use of the Platform and the Documentation;13.3.2 each party shall return and make no further use of any equipment, property, documentation and other items (and all copies of them) belonging to the other party;13.3.3 unless otherwise agreed with the Customer in writing, Trig may destroy or otherwise dispose of or anonymise any of the Customer Data and Services Data in its possession;13.3.4 any rights, remedies, obligations or liabilities of the parties that have accrued up to the date of termination, including the right to claim damages in respect of any breach of the agreement which existed at or before the date of termination shall not be affected or prejudiced; and13.3.5 clauses which expressly or impliedly survive termination continue in force including clauses 5, 7.2.2, 8, 9, 10, 11, 13.3, 13.4, 14, 26, 27 and Schedule 1.13.4 Trig shall not be liable to the Customer for the refund of any Subscription Fees paid in advance where the Customer purports to terminate this Agreement part way through the Subscription Term except where this Agreement is terminated by the Customer under clause 13.2.2. In such instance, (provided the material breach is proven) the Customer shall become entitled to a refund of the Annual Subscription Fee paid by the Customer to Trig on a pro rata basis calculated by reference to the remaining time period between the date of termination and the expiry of the then current Minimum Term or Renewal Period.13.5 The Customer acknowledges Trig may suspend access to the Platform and the Services where Trig or its licensor reasonably believe their business or operation is at risk of harm, where the Customer has breached this Agreement or where Trig reasonably concludes that continued performance would cause it to breach applicable law.14. Non-competeThe Customer undertakes to Trig that it will not at any time during the term of this Agreement or for five (5) years from the Effective Date (whichever is less) develop, promote, supply or sell (directly or indirectly) any product or service which is similar to, or which competes with, the Platform.15. Force majeureTrig shall have no liability to the Customer under this Agreement if it is prevented from or delayed in performing its obligations under this Agreement, or from carrying on its business, by acts, events, omissions or accidents beyond its reasonable control, including, without limitation, strikes, lock-outs or other industrial disputes (whether involving the workforce of Trig or any other party), failure of a utility service or transport or telecommunications network, act of God, Covid-19, pandemic, endemic, war, riot, civil commotion, malicious damage, compliance with any law or governmental order, rule, regulation or direction, accident, breakdown of plant or machinery, fire, flood, storm or default of suppliers or sub-contractors, provided that the Customer is notified of such an event and its expected duration.16. ConflictIf there is an inconsistency between any of the provisions in the main body of this Agreement and the Order Form, the Order Form shall prevail.17. VariationNo Change to this Agreement shall be effective unless it is in writing and signed by the parties on a new Order Form.18. WaiverNo failure or delay by a party to exercise any right or remedy provided under this Agreement or by law shall constitute a waiver of that or any other right or remedy, nor shall it prevent or restrict the further exercise of that or any other right or remedy. No single or partial exercise of such right or remedy shall prevent or restrict the further exercise of that or any other right or remedy.19. SeveranceIf any provision or part-provision of this Agreement is or becomes invalid, illegal or unenforceable, it shall be deemed deleted, but that shall not affect the validity and enforceability of the rest of this Agreement.20. Entire agreement20.1 This Agreement constitutes the entire agreement between the parties and supersedes and extinguishes all previous agreements, promises, assurances, warranties, representations and understandings between them, whether written or oral, relating to its subject matter.20.2 Each party acknowledges that in entering into this Agreement it does not rely on, and shall have no remedies in respect of, any statement, representation, assurance or warranty (whether made innocently or negligently) that is not set out in this Agreement.20.3 Each party agrees that it shall have no claim for innocent or negligent misrepresentation or negligent misstatement based on any statement in this Agreement.21. Assignment21.1 The Customer shall not, without the prior written consent of Trig, assign, transfer, charge, sub-contract or deal in any other manner with all or any of its rights or obligations under this Agreement.21.2 Trig may at any time assign, transfer, charge, sub-contract or deal in any other manner with all or any of its rights or obligations under this Agreement and the Customer shall promptly enter into such agreements as Trig reasonably requires to give effect to any such assignment or transfer.22. No partnership or agencyThis Agreement is being entered into on a principal-to-principal basis. Nothing in this Agreement is intended to or shall operate to create a partnership between the parties, or authorise either party to act as agent for the other, and neither party shall have the authority to act in the name or on behalf of or otherwise to bind the other in any way (including, but not limited to, the making of any representation or warranty, the assumption of any obligation or liability and the exercise of any right or power).23. Third party rightsThis Agreement does not confer any rights on any third party pursuant to the Contracts (Rights of Third Parties) Act 1999 or otherwise.24. CounterpartsThis Agreement may be executed in any number of counterparts, each of which shall constitute a duplicate original, but all the counterparts shall together constitute the one agreement.25. Notices25.1 Any notice required to be given under this Agreement shall be in writing and shall be delivered by hand or sent by pre-paid first-class post or recorded delivery post to the other party at its registered office address, or sent by email to the other party's email address as set out in the Order Form, or such other address or email address as may have been notified by that party for such purposes.25.2 A notice delivered by hand shall be deemed to have been received when delivered (or if delivery is not in business hours, at 9am on the first Business Day following delivery). A correctly addressed notice sent by pre-paid first-class post or recorded delivery post shall be deemed to have been received at the time at which it would have been delivered in the normal course of post. A notice sent by email shall be deemed to have been received at the time of transmission (as shown by the timed printout obtained by the sender) provided a delivery failure notification is not received by the sender.25.3 This clause does not apply to the service of any proceedings or other documents in any legal action or, where applicable, any arbitration or other method of dispute resolution.26. Dispute Resolution26.1 Any dispute arising out of or in connection with this Agreement, including any question regarding its existence, validity or termination shall be discussed in good faith by members of the senior management of the parties with a view to an amicable resolution thereof within a thirty (30) day period, failing which the dispute, shall be referred to and finally resolved by arbitration under the LCIA Rules, which Rules are deemed to be incorporated by reference into this clause:26.1.1 The number of arbitrators shall be one.26.1.2 The seat, legal place or venue of arbitration shall be London26.1.3 The language to be used in the arbitral proceedings shall be English.26.1.4 The governing law of the contract shall be the law of England and Wales.27. Governing lawThis Agreement and any dispute or claim arising out of or in connection with it or its subject matter or formation (including non-contractual disputes or claims) shall be governed by and construed in accordance with the law of England and Wales.
Schedule 1
DATA PROCESSING ADDENDUM1. Definitions and Interpretation1.1 Definitions:"Breach" means any actual or reasonably suspected unauthorized acquisition, access, use, disclosure, loss, or modification of Customer PI processed by , or its sub processors, including any "breach" or "personal data breach" in respect of Customer PI (as the term "breach," "personal data breach," "incident" and similar terms are defined under Data Protection Laws)."Customer Personal Information" or "Customer PI" means personal information or personal data that is received, collected or accessed by  in the course of performing the Services or Agreement."Consumer Rights Request" means a communication from a consumer or other data subject requesting to exercise their individual rights under Data Protection Laws."collected," "consumer," "controller," "data subject", "process(ing)," "processor," "personal information," "personal data," "personal data breach," "sell," "sensitive data," "sensitive personal information," "share," "sell," "sale," "sold," and "targeted advertising," shall have the meanings given to such terms in Data Protection Laws."Data Protection Laws" means all applicable laws and regulations related to the processing of personal data or personal information, including (i) all applicable U.S. federal and/or state laws, rules, regulations, directives, governmental and regulatory requirements and guidance including, but not limited to, security, confidentiality, and/or privacy laws, standards, guidelines, policies, regulations, and procedures that are applicable to , the Services, Customer PI, and/or any other programs or products provided pursuant to the Agreement, including but not limited to the California Consumer Privacy Act of 2018 (California Civil Code § 1798.100 et seq.), as amended (including, without limitation, by the California Privacy Rights Act ("CPRA")("CCPA"), Colorado Privacy Act, Colorado Revised Statute Title 6 Article 1 Part 13 § 6-1-1301 et seq. ("CPA"), the Virginia Consumer Data Protection Act, Code of Virginia Title 59.1 Chapter 52 § 59.1-571 et seq. ("CDPA"), the Utah Consumer Privacy Act (Utah Code Annotated 1953, § 13-61-101, et seq.) ("UCPA"), Connecticut's Act Concerning Personal Data Privacy and Online Monitoring (Public Act No. 22-15) ("CTPA"), and all laws implementing, supplementing or amending the foregoing, including any regulations promulgated thereunder, in each case applicable to this DPA as and when legally effective; and (ii) all applicable EU and UK laws and regulations related to the processing of personal data or personal information, including, but not limited to, the EU GDPR, the UK GDPR and the UK Data Protection Act 2018."EU GDPR" means the General Data Protection Regulation ((EU) 2016/679)."Services" means the services and other processing activities that  shall provide or carry out for Customer as set forth in the Agreement, including all provisions related to the use of 's Platform by Customer."UK GDPR" has the meaning given to it in section 3(10) (as supplemented by section 205(4)) of the Data Protection Act 2018.1.2 Unless otherwise defined in this Schedule 1, expressions defined in the Order Form and Terms of Service and used in this Schedule have the meaning set out therein. The rules of interpretation set out in the Terms of Service apply to this Schedule.2. Appointment2.1 With effect from the Effective Date, the Customer, as the controller, hereby appoints  as its processor to process the Customer PI for the purposes and on the terms of this Agreement.2.2 The Customer acknowledges its responsibility to provide all notices and obtain all consents needed for  to process the Customer PI on the Customer's behalf in accordance with Data Protection Laws.2.3 In performing the Services,  will process Customer PI, and is hereby authorized to process Customer PI, on Customer's behalf as set forth in the Agreement and this DPA, and in accordance with Data Protection Laws.3. Data types and processing purposes3.1 The Customer retains control of the Customer PI and remains responsible for its compliance obligations under the applicable Data Protection Laws, and for the processing instructions it gives to .3.2 The Customer acknowledges its responsibility to provide all notices and obtain all consents needed for  to process the Customer PI on the Customer's behalf in accordance with Data Protection Laws.3.3 The subject matter and duration of the processing, the nature and purpose of the processing, the types of Customer PI and the categories of consumers or data subjects are set out in Annex 1.4. 's obligations4.1  shall, where  processes the Customer PI on the Customer's behalf:4.1.1 process the Customer PI only to supply the Platform and the Services, as permitted by this Agreement, and on the documented instructions of the Customer, unless  is required by applicable laws to otherwise process that Customer PI;4.1.2 inform the Customer if, in the opinion of , the instructions of the Customer infringe Data Protection Laws;4.1.3 not sell, share, or process for targeted advertising Customer PI, as those terms are defined by Data Protection Law;4.1.4 not retain, use, disclose, or otherwise process Customer PI outside of the direct business relationship between  and Customer, including by: (i) combining, amending, or supplementing Customer PI with personal information received from another source; or (ii) using Customer PI for Pavolv's commercial purposes;4.1.5 implement appropriate technical and organisational measures to protect against the unauthorised or unlawful processing of the Customer PI and against accidental loss or destruction of, or damage to, the Customer PI as per the Data Protection Laws, as detailed in Annex 1. In the event of a conflict between Annex 1 and this DPA, the DPA shall govern. It is acknowledged that the technical and organizational measures will be subject to technical progress, development and improvements for the protection of Customer PI and any such measures shall automatically apply hereto.  will not materially decrease the overall security of the Services with respect to processing of Customer PI;4.1.6 ensure that any personnel engaged and authorised by  to process the Customer PI have committed themselves to confidentiality or are under an appropriate statutory or common law obligation of confidentiality;4.1.7 Assistance and Co-operation:(a) assist the Customer where reasonably practicable, and at the Customer's reasonable cost and written request, in responding to any request from a consumer or data subject including but not limited to: (i) identifying, retrieving, deleting, and rectifying Customer PI in response to a Consumer Rights Requests submitted to Customer, and (ii) in ensuring the Customer's compliance with its obligations under Data Protection Laws with respect to security, breach notifications, impact assessments and consultations with supervisory authorities or regulators, conducting and documenting data protection assessments and privacy impact assessments (whether or not required by Data Protection Laws), and any other assessment required by Data Protection Laws;(b) not respond to any Consumer Rights Requests concerning Customer PI unless expressly instructed to do so by Customer. Should  receive a Consumer Rights Request from a consumer or data subject applicable to Customer PI,  shall inform the consumer data subject that it cannot act on such requests because the request was sent to a "processor" and shall immediately redirect the Consumer Rights Requests to Customer;(c) if Customer requests that  delete Customer PI, within five (5) Business Days, notify its own sub-processors to delete immediately all Customer PI identified by Customer, to the extent that such Customer PI has been collected and retained by such sub-processors, unless retention of the Customer PI is required by law in which case retention shall be only for so long as for such purposes as required by applicable law and shall remain subject to this DPA;4.1.8 Breach:(a) notify the Customer without undue delay, and within a maximum of 48 hours, on becoming aware of a Breach involving the Customer PI;(b) investigate the Breach and take reasonable measures to identify its root cause(s) and, where such Breach is caused by  or its sub processor, take steps to mitigate, remediate the effects of the Breach, and to prevent a similar Breach from occurring. As information is collected or otherwise becomes available, to the extent legally permitted,  will provide Customer with a description of the Breach, the type of the Customer PI to which the Breach relates, and other information Customer may reasonably request concerning the affected consumers or data subject(s) where such information is available to ;(c) in the event of a Breach caused by the acts or omissions of  (or 's sub-processors), directly pay (or promptly reimburse Customer upon request) all reasonable costs and expenses (including reasonable attorneys' fees and expenses) related to investigating, mitigating, and remediating the effects of the Breach ("Costs"), including but not limited to Costs relating to notification letters, regulatory investigations or litigation (including but not limited to litigation under applicable laws and damages that may be recovered as a result of such litigation, including a settlement thereof), and credit monitoring and other services that entities commonly make available to individuals impacted by a Breach;(d) not (and shall ensure its sub processors shall not) notify any third party (including any regulatory authority or individual) of any Breach relating to Customer PI without first obtaining Customer's prior written consent. Further, unless otherwise required by applicable laws,  agrees that Customer shall have the sole right to determine: (i) whether notice of a Breach relating to Customer PI is to be provided to any individuals, regulators, law enforcement agencies, or others; and (ii) the form and contents of such notice;4.1.9 upon written request from Customer, and in any event within six (6) months if the termination of the Agreement, securely delete or return Customer PI to Customer and delete existing copies at the end of the provision of Services, unless retention of the Customer PI is required by applicable laws in which case retention shall only be for so long and for such purposes as required by applicable laws and shall remain subject to this DPA. Upon request,  shall provide Customer with a certification of destruction executed by an officer of Pavolv; and4.1.10 maintain records to demonstrate its compliance with this clause, and allow for reasonable audits by the Customer or the Customer's designated auditor, for this purpose, on reasonable written notice, and the Customer acknowledges that such audit requirements may be satisfied by  providing an independent third party report certifying its compliance with Data Protection Laws.4.2  certifies that it understands the requirements and restrictions set forth in this DPA and will comply with them.  represents and agrees that it is, and will maintain its status as, a processor under all Data Protection Laws and will comply with its obligations under the Data Protection Laws, the Agreement, and this DPA.  will ensure a level of privacy protection that may be required under Data Protections Laws.4.3  will promptly, but in no event later than five (5) days from the date of such determination, inform Customer if, in its determination: (i) any instruction or request violates Data Protection Laws; or (ii) it can no longer meet its obligations under Data Protection Laws.  is not entitled to condition the full and unlimited compliance with Customer's instructions on payment of outstanding invoices etc., and Pavolv has no right of retention over Customer PI.4.4  hereby grants Customer the right to take reasonable and appropriate steps to stop and remediate 's unauthorized use of Customer PI. Such rights include but are not limited to the right to mandate the temporary or permanent cessation of processing of Customer PI, the right to demand deletion or destruction of Customer PI at any time, and right to require Pavolv to notify any third party to whom  has sold, shared, or disclosed Customer PI without authorization to delete or return such Customer PI.4.5 Notwithstanding any provision to the contrary and in addition to any other obligations set forth herein, if Customer PI includes sensitive personal information/data,  agrees to comply with (and to provide reasonable assistance to Customer to comply with) Data Protection Laws and Customer's policies and procedures governing sensitive personal information/data that are subject to heightened legal requirements.4.6 This DPA shall not prevent  using Customer PI for the purposes in clause 7.35. Sub-processors5.1 The Customer provides its prior general authorisation for  to:5.1.1 delegate the processing of the Customer PI to its sub-processors, provided that :(a) shall ensure the terms on which it appoints such sub-processors comply with Data Protection Laws, and are consistent with the obligations imposed on  in this Schedule 1;(b) shall remain responsible for the acts and omission of any such sub-processor as if they were the acts and omissions of ; and(c) complies with clause 6 of this DPA.5.2 The list of 's current sub-processors is set out at Annex 1 (as may be amended from time to time).  shall provide the Customer with notification of new sub-processor(s) at least 30 days before authorizing such new Sub-processor(s) to process Customer PI in connection with the provision of the applicable services, and Customer shall have the right to reasonably object within 10 (ten) days of such notification. If objected to by the Customer, then,  will use commercially reasonable efforts to make available to Customer a change in the services or recommend a commercially reasonable change to Customer's configuration or use of the services to avoid processing of Customer PI by the objected to new sub-processor without unreasonably burdening the Customer.6. Location of Processing, International transfers of data6.1  shall process Customer PI in the locations indicated in Annex 1 (as may be updated from time to time).6.2 The Customer provides its prior general authorisation for  to transfer the Customer PI internationally, provided that  shall ensure that all such transfers are carried out in accordance with Data Protection Laws.6.3 The Parties shall enter into any trans-border data flow agreements as may be required under the applicable Data Protection Law, and to maintain such additional trans-border data flow agreement (with any updates and amendments as may be required to reflect changes in the applicable Data Protection Law, and/or in any other transfer mechanism required under the applicable Data Protection Law) for the entire period during which Customer PI is Processed by .7. Disclosure of DPAAs required or upon request,  acknowledges that Customer may provide a summary or copy of this DPA to any supervisory authority or governmental authority.8. Choice of Law and JurisdictionThis DPA shall be governed by and construed in accordance with the governing law and jurisdiction provisions in the Agreement, unless required otherwise by applicable Data Protection Law.
Annex 1
Scope and purposeTo supply the Platform and the Services to the Customer under this Agreement.DurationThe duration of this Agreement plus a short period afterwards to allow the Customer PI to be anonymised or deleted and as per Customer's documented instructions (if any).NatureThe receipt, hosting, using, accessing, transferring, anonymisation and deletion of the Customer PI.Types of dataCustomer PI related to individuals involved in the Customer's use of the Platform including their names and details of work undertaken.Customer PI related to individuals that purchase goods or services from the Customer, including their names and purchase history.Categories of consumers or data subjectsThe individuals involved in the Customer's use of the Platform for the Permitted Use.The individuals that purchase goods or services from the Customer.Sub ProcessorsAnthropicAmazon Web Services1PasswordDocuSignDovetailFigmaGhost InspectorGitHubGoogle WorkspaceHoneycombHubspotIntercomLoomMailchimpMixpanelPitchPosthogSalesforceSendgridSentryVantaVercelWork OSXeroTechnical And Organizational Measures Including Technical And Organizational Measures To Ensure The Security Of The DataTrig shall maintain reasonable administrative, organizational, technical and physical (if applicable) controls designed to ensure the privacy, security, and confidentiality of the Customer PI ("Safeguards"), that comply with this DPA and Data Protection Law, including:SOC 2 type 2In absence of the foregoing, Trig agrees to the following:Physical Access. If applicable, Trig will maintain physical access controls designed to secure relevant facilities, infrastructure, hard copy files, and equipment (including mobile devices) used to access Customer PI, including controls to prevent, detect, and respond to attacks, intrusions, or other system failures;User Authentication. Trig will maintain user authentication and access controls within operating systems, applications, equipment, and media;Personnel Security. Trig will maintain personnel security policies and practices restricting access to Customer PI, including written confidentiality agreements and background checks consistent with Data Protection Law for all personnel with access to Customer PI or who maintain, implement, or administer Trig's information security program and Safeguards;Logging and Monitoring. Trig will log and monitor the details of all access to Customer PI on networks, systems, and devices operated by Trig. Trig's logging and monitoring systems shall meet generally accepted standards and Trig shall maintain all access logs for at least 90 days;Malware Controls. Trig will maintain reasonable and up-to-date controls to protect all networks, systems, and devices that access Customer PI from malware and unauthorized software;Security Patches. Trig will maintain controls and processes designed to ensure that networks, systems, and devices (including operating systems and applications) that access Customer PI are up-to-date, including prompt implementation of all security patches when issued;User Account Management. Trig must implement reasonable user account management procedures to securely create, amend, and delete user accounts on Trig's networks, systems, and devices, including monitoring redundant accounts and ensuring that information owners properly authorize all user account requests;Infrastructure and network security. Trig must implement and maintain confidentiality by implementing endpoint security, network security protocols, network identification services, data encryption services, integrity by firewall services, communications security management, intrusion detection services and intrusion prevention systems, data availability safeguards (back-ups, redundant disk systems), reliable and interoperable security processes and network security mechanisms;Security architecture and design. Trig must enforce appropriate security policies that can be applied to all aspects of Trig's IT infrastructure (e.g. workstations, servers, storage area network, switches, fireworks, routers, visualization, or cloud computing);Business continuity and disaster recovery planning. Trig must put in place appropriate technical and organizational systems to preserve and continue business in the wake of a disaster;Encryption Requirements. Using a reasonable encryption standard, Trig will encrypt all Customer PI that is (a) stored on portable devices or portable electronic media; (b) stored or maintained outside of Customer's or Trig's facilities, excluding hard copy documents; or (c) transferred across any network other than an internal Trig network owned and managed by Trig;Access Controls. Trig will: (a) maintain reasonable controls to ensure that only individuals who have a legitimate need to access Customer PI under the Agreement will have such access; (b) promptly terminate an individual's access to Customer PI when such access is no longer required for performance under the Agreement; (c) log the appropriate details of access to Customer PI on Trig's systems and equipment, and retain such records for no less than 90 days; and (d) be responsible for any unauthorized access to Customer PI under Trig's custody or control or sub-processor's custody or control;Training and Supervision. Trig will provide reasonable ongoing privacy and information protection training and supervision for all Trig's personnel who access Customer PI.