
TerraEye Web Application Terms of Service
§ 1. GENERAL PROVISIONS
These Terms of Service (hereinafter: the "Terms") set out the rules for the operation and provision of electronic services within the TerraEye web application (hereinafter: the "Application").
The Application is produced and provided by Remote Sensing Business Solutions sp. z o.o. with its registered office in Wrocław, ul. Długosza 60A, 51-162 Wrocław, Poland, entered into the National Court Register (KRS) under number: 0001105923, NIP (Tax ID): 8952241235, REGON: 521932803, share capital: PLN 1,553,401.44 (hereinafter: the "Provider" or the "Company").
The Terms apply to all legal relationships established between the Provider and the users of the Application.
§ 2. DEFINITIONS
For the purposes of these Terms, the following definitions shall apply:
Application – the TerraEye web application provided in the SaaS model, owned by Remote Sensing Business Solutions sp. z o.o., aggregating satellite, geophysical, and geochemical data, providing advanced satellite analytics, spectral analysis, topographical models, and artificial intelligence (AI) solutions designed to optimize mineral exploration processes.
Pricing Plan – the current schedule of Subscription Plan prices and their assigned technological limits, made available to the Client in the Provider's offer.
AI Chat – an interactive functionality provided as part of the AI Services, based on large language models (LLMs) provided by third parties, enabling the User to input queries (prompts) in natural language to obtain automated analytical support and information.
Login Credentials – data enabling login to the User Account, i.e., an e-mail address in the Client's corporate domain and a User password.
Input Data – proprietary datasets, including geochemical and geophysical data, geographical coordinates, and other materials, as well as queries (prompts) directed to the AI Services or introduced into the Application by the Client or the User.
Demo – a time- or functionality-limited version of the Application, provided to the Client free of charge solely for evaluation and testing purposes.
Password – a unique and confidential alphanumeric string chosen by the User, used to gain or secure access to the Application.
Client – a business entity (legal person, organizational unit without legal personality, or natural person conducting business activity) to which the Provider grants access to use the Application in connection with the concluded Agreement.
Consumer – a natural person using the Services for purposes other than those related to their trade, business, or profession, or a natural person using the Services directly related to their business activity, when the content of the agreement indicates that it does not have a professional character for this person.
User Account – an individual, authorized panel in the Application, assigned to a specific User acting on behalf of the Client, enabling the use of the Application's functionalities in accordance with the purchased Subscription Plan.
Login – the act of entering Login Credentials into the login form to gain access to the Application.
Newsletter – a free digital service provided electronically by the Provider, consisting of the periodic dispatch of industry information, educational materials, and commercial (including marketing) information regarding the Provider's products, functionalities, and services, including the Application, to the e-mail address provided by the Client.
Subscription Period – the time for which the Client has purchased access to the Application under the selected Subscription Plan (e.g., a month or a year), which determines the billing cycle.
Subscription Fee – the net remuneration due to the Provider for providing the Services to the Client in the selected billing cycle.
Subscription Plan (Plan) – the Provider's offer specifying the conditions of access to the Application within the scope selected by the Client, defining, among others, query limits (data generated per day), SLA, permission levels, the number of Accounts provided, access to additional AI modules, and the duration of the service.
Report – a digital data compilation, map, topographical model, spectral analysis, or other document generated by the Application's analytical mechanisms (including AI Services) based on parameters and queries inputted by the User.
Registration – a set of actions that must be performed to create a new User Account.
Agreement – the agreement for the provision of electronic services concluded between the Provider and the Client upon successful Registration or payment for a Subscription Plan, under the conditions specified in the Terms, the subject of which is enabling the User to use the Application, providing electronic services, and delivering digital services and content within the Application.
Device – the User's end device enabling the reception, transmission, and processing of data via an Internet connection (e.g., desktop computer, laptop, tablet, smartphone).
Services – digital services and functionalities provided by the Provider via the Application.
AI Services – functionalities integrated into the Application based on artificial intelligence models, including in particular the interactive AI Chat, serving automated analytical support for the User or assistance in generating Reports.
User – an adult natural person with full legal capacity, using the Application on behalf of and for the benefit of the Client.
§ 3. GENERAL CONDITIONS FOR THE PROVISION OF SERVICES
The Provider makes the Application available for use at https://app.terraeye.co/ in the SaaS model. On-premise deployments of the Application are carried out exclusively on the basis of separate implementation agreements concluded with the Client, the provisions of which shall take precedence over these Terms.
The Application is intended exclusively for business-to-business use (b2b). The Provider does not allow Consumers to conclude an Agreement or use the Application.
As part of using the Application, after creating and authorizing a User Account, the User gains access to the Application's Services and functionalities, which include in particular:
aggregating, integrating, and visualizing satellite, geophysical, and geochemical data in a single, cohesive analytical environment;
providing spectral classification algorithms, including SAM (Spectral Angle Mapper), SFF (Spectral Feature Fitting);
providing spectral decomposition algorithms, including MTMF (Mixture Tuned Matched Filtering);
performing Land Segmentation and Masking and generating Bare Earth Composites;
integrating Remote Sensing data with Ground Samples;
using other interactive artificial intelligence modules (AI Services), including the built-in AI Chat and specialized virtual analytical assistants or classification algorithms based on machine learning;
managing the Client's profile, inputting proprietary Input Data, and generating Reports for the Client's internal use;
providing the free Newsletter service.
For the proper operation of the Application, the Device used by the User must meet the following minimum technical requirements:
an active Internet connection;
an active e-mail account;
a modern web browser (e.g., the latest version of Chrome, Firefox, Safari, or Edge) with JavaScript and cookies enabled;
a device supporting a responsive web design (RWD) interface;
modern operating systems: Windows 10 (or newer), macOS 12 (or newer), Android 12 (or newer), and iOS 16 (or newer).
The Provider shall not be liable for difficulties in using the Application's functionalities resulting from technical limitations and problems related to the hardware or Internet connection used by the User.
All data transmission costs required to use the Application are borne by the User, based on relevant agreements concluded with Internet service providers or telecommunications operators.
The Provider informs that using the Application may potentially involve the risk of unauthorized disclosure of or access to the Users' personal data or the Client's business information due to reasons attributable to the Client or the User. To mitigate this risk, the Client or the User shall take all technical and organizational measures necessary to maintain the confidentiality of the Login Credentials and protect the Device against access by third parties in a manner consistent with data security requirements (including personal data) and trade secrets.
§ 4. CREATING AND MAINTAINING A USER ACCOUNT
The Agreement for the provision of the Application is concluded upon the successful completion of Registration, which entitles the User to limited, view-only access to the Application. Full access to the Application's functionalities or associated digital content may be conditional upon the payment of fees for the selected Subscription Plan and occurs upon the successful completion of the Subscription Fee payment.
User Registration is permitted for adult natural persons with full legal capacity designated by the Client.
For the purpose of Registration, the User is obliged to:
provide their own correct and complete personal data;
provide a corporate e-mail address in a domain registered to the Client;
create a secure Password;
confirm that they have read and accepted the provisions of the Terms and the Privacy Policy by checking the appropriate checkbox below the Registration form;
confirm that they do not have the status of a Consumer by checking the appropriate checkbox below the Registration form.
Registration using public, free e-mail domains (e.g., @gmail.com, @yahoo.com) or so-called temporary e-mail addresses is strictly prohibited and will result in the automatic rejection of the Registration or immediate blocking of the Account, unless the Provider permits such an option based on individual arrangements with the Client.
Each access to the User Account occurs after the User enters the Login Credentials.
The User is responsible for all actions performed using access to the User Account and indemnifies the Provider against any claims made by third parties, unless the User is not responsible for the misuse of access to the User Account.
The Client or User is obliged to provide true, current, and complete data during Registration. The Client or User bears the responsibility arising from indicating incorrect or incomplete data in the Client or User Account.
The Provider reserves the right to verify the identity of the Client and the authorization of the User to act on their behalf, both at the Registration stage and during the term of the Agreement. Verification may include, in particular, requesting the presentation of a current extract from the relevant commercial register, verifying the owner of the corporate domain used for Registration, or establishing direct contact with persons authorized to represent the Client.
In the event of a negative result of the verification referred to in section 8, or a lack of cooperation on the part of the Client, the Provider has the right to refuse to create an Account or to suspend the provision of Services with immediate effect.
The User Account is personal and is assigned to a specific natural person. It is prohibited to transfer, share, or assign the Account to third parties.
During the first month of using the Application, the Client, via an authorized administrator account, has the ability to independently manage access and transfer the Account assignment to another employee within their organization. In the subsequent period, changing the e-mail address assigned to the Account or transferring the Account to a new employee of the Client requires the Provider's prior consent, obtained via a technical support ticket, providing a justification and a new e-mail address in the Client's approved corporate domain.
The Provider reserves the right to discontinue maintaining a User Account, in particular if, within 12 months from the date of login, the User has not logged into this Account or has not performed any other activities via the Account. The User will be informed about the discontinuation at least 14 days in advance via e-mail or the telephone number associated with the User Account.
§ 5. USING THE DEMO VERSION OF THE APPLICATION
The Provider may provide the Client with a Demo version of the Application or offer an initial, free data audit (Free audit).
Using the Demo version of the Application does not entail an obligation to pay.
Access to the Demo version of the Application is granted for a period determined by the Provider and may be revoked at any time without providing a reason.
The Provider does not guarantee the archiving or the possibility of recovering data inputted into the Demo Version after the end of the testing period.
The use of the Demo version is at the Client's sole risk, and the Provider's liability in this respect is entirely excluded.
§ 6. USING THE APPLICATION UNDER A SUBSCRIPTION PLAN
The User's use of the Application under a purchased Subscription Plan is possible after full payment of the Subscription Fee.
The fee for using the Application under the Subscription Plan is paid in advance for the entire subscription period specified in the Plan.
The Provider ensures access to the Application for a period corresponding to the Subscription Plan selected by the User.
When selecting a Plan, the Client has the right to choose the Subscription Period. Subscription Periods are available on a monthly or annual basis. The Client selects the Plan and the Subscription Period by choosing the appropriate Service option in the manner specified by the Provider.
The Subscription Period begins the moment the Client gains access to the Application.
After the end of the subscription period under the Plan, the Client or User may reactivate the Plan, provided they have not deleted the User Account and have paid for a subsequent Plan. This provision does not apply to Users whose Account has been suspended or deleted by the Provider.
In connection with using the Plan, the Client may use additional Services offered by the Provider, subject to payment of an additional fee specified in the Pricing Plan.
The Client has the right to change the selected Subscription Plan during the Subscription Period under the following conditions:
in the case of changing to a higher Plan (upgrade), the change takes effect immediately, subject to the Client paying the required additional Subscription Fee;
in the case of changing to a lower Plan (downgrade), the change takes effect at the beginning of the next Subscription Period. The Client is not entitled to claim a refund for the whole or a proportional part of the paid Subscription Fee for the ongoing Subscription Period.
§ 7. PRICING AND SUBSCRIPTION FEES
The Client commits to paying the Subscription Fees for the selected Plan in accordance with the Pricing Plan.
The amount of the Subscription Fees depends on the Plan and the Subscription Period selected by the Client.
Subscription Fees are payable in advance, starting from the date the Agreement comes into force.
Subscription Fees are collected automatically in cycles corresponding to the selected Subscription Period (monthly or annually) by charging the payment card indicated by the Client.
Subscription Fees may be paid, at the Client's discretion:
via the Stripe payment operator, provided by Stripe Payments Europe Limited (...) and Stripe Technology Europe Limited (...) (hereinafter collectively: "Stripe"). Stripe may verify the payment, which may result in a delay in processing the order for reasons beyond the Provider's control;
via a direct bank transfer to the Provider's bank account indicated on the relevant billing document (pro forma or VAT invoice).
The Client bears all costs associated with processing the payment.
The Client commits to making payments in accordance with the instructions and deadlines specified in the Terms and the Plan descriptions.
The VAT invoice/billing document for the subscription will be issued automatically by the Provider after the Subscription Fee has been credited.
The Client consents to receiving VAT invoices in electronic form at the e-mail address indicated by the Client in the order form.
The Subscription Fees indicated in the Pricing Plan are net amounts expressed in USD and do not include Value Added Tax (VAT), Withholding Tax (WHT), or any other taxes, duties, stamp fees, or public levies imposed by any local or foreign state authorities. The Client bears sole responsibility for settling and paying any taxes related to using the Application and acquiring the Services. If, under the laws applicable in the Client's jurisdiction, the Client is obliged to deduct Withholding Tax or another levy from any payment due to the Provider, the payment amount shall be automatically increased so that, after all required deductions and withholdings have been made, the Provider receives and retains the full net amount of the Subscription Fee.
The Provider reserves the right to unilaterally change the amount of the Subscription Fees at any time, in particular due to changes in technological or market costs or the development of the Application's functionalities. The Provider shall inform the Client of the change in the Subscription Fee at least 60 days prior to the planned effective date of the new Pricing Plan. If the Client does not agree to the new fees, they are entitled to cancel the Subscription Plan, which results in the expiration of the Agreement at the end of the aforementioned period. The lack of an explicit declaration of cancellation before the effective date of the new Pricing Plan is considered acceptance of the amended financial terms.
§ 8. CONDITIONS FOR USING THE APPLICATION
The Client and the User are obliged to use the Application in accordance with the law, the Terms, good customs, and principles of community life, as well as to ensure the security of the Application. In particular, it is prohibited to:
introduce any viruses or malicious software (malware) into the Application;
provide, introduce, or generate any content of an unlawful nature;
abuse the Services or use them in a manner inconsistent with their business purpose;
provide false, outdated, or incomplete data (including registration data) by the Client or User;
take actions in the Application on behalf of the Client by a natural person who does not have a valid authorization to represent this entity;
conclude more than one Agreement for the provision of Services by the Client (e.g., creating multiple Accounts to bypass limits in Plans) without the express prior consent of the Provider.
The Client or User may not post or share in the Application any content that is generally considered offensive, untrue, or contrary to generally applicable law, principles of community life, or morality. In particular, it is prohibited to introduce content:
aimed at spreading hatred against specific individuals or social groups;
aimed at abusing or violating the personal rights of specific individuals or social groups;
aimed at inciting the commission of acts prohibited by law, in particular violence;
containing or inciting violence, including the use of threats;
containing drastic elements;
promoting the use of dangerous products, in particular weapons or explosives;
encouraging the reckless consumption of alcohol, tobacco, drugs, medicines, or other intoxicating substances;
referring to harmful or misleading products and services, in particular financial services;
promoting gambling;
of a sexual nature.
Any person or entity has the possibility to report to the Provider the fact that information considered Illegal Content is present in the Application. Reports should be sent to the e-mail address of the contact point indicated in § 21 section 10.
If the Provider learns that the User has placed prohibited content while using the Application, the Provider is entitled to immediately remove it and to block or delete the User Account.
In connection with using the Application, the Client is entitled to share Input Data.
The Client is obliged to ensure that they have full and unrestricted rights (including intellectual property rights and any consents required by law or non-disclosure agreements) to all Input Data introduced into the Application.
The Client commits to indemnifying the Provider against any claims by third parties resulting from the processing of Input Data by the Application or AI Services. If such claims are raised against the Provider, the Client commits to satisfying these claims and covering all costs of the Provider's legal defense, including legal representation costs.
The Provider does not conduct automated, preventive moderation, verification, or filtering of Input Data introduced into the Application by the Client or Users. However, the Provider reserves the right to monitor and audit the activity of the Client and Users in the Application (including, among others, analyzing system logs, IP addresses, unique sessions, and query volumes) to verify compliance with the Terms, in particular regarding adherence to the prohibition on sharing Login Credentials and the limits assigned to the selected Plan.
In the event the Client exceeds the technological limits assigned to a given Plan (e.g., active area limit in km² or AI query credit limit), the Provider is entitled to unilaterally and automatically charge extension fees, in accordance with the current Pricing Plan (based on Grow As You Go / Expansion Priced Separately rates).
In the event a violation of the prohibition on sharing Login Credentials with unauthorized persons is identified, the Provider is entitled to charge the Client a contractual penalty equal to the flat-rate annual fee for an additional Account according to the Pricing Plan (based on Additional active seat rates) for each unauthorized use of the User Account. The right referred to in the preceding sentence is without prejudice to the Provider's right to claim damages exceeding the amount of the contractual penalty under general rules, and the right to immediately block the Account and terminate the Agreement, as referred to in § 20 of the Terms.
In order to protect the stability of the IT infrastructure, protect intellectual property, and prevent abuse, automatic safeguards are implemented in the Application's code. The Provider determines and enforces absolute limits on the number of API queries, the number of Input Data generated and processed per day, and limits on the mass export of generated results and Reports (so-called Rate Limits and Export Limits), adequate to the specifications of the purchased Plan. Attempts to bypass the implemented code safeguards or automated data scraping will result in immediate termination of the Agreement due to the Client's fault.
The Provider reserves the right to automatically collect and process anonymized telemetry data, technical logs, and metadata regarding the User's use of the Application, excluding the possibility of identifying the Client's specific Input Data. The collected data will be used exclusively to ensure the security and continuity of IT systems, diagnose errors, develop and optimize the Application's functionalities, and create aggregated business statistics.
§ 9. RULES FOR USING AI SERVICES
In connection with providing the Application, the Provider enables the Client to use AI Services, including in particular the AI Chat, in accordance with the Plan selected by the Client. The Provider reserves that the scope of provided AI Services may be changed or modified at any time.
The Client bears full and exclusive responsibility for the content of all queries (prompts), materials, and documents introduced into the AI Services.
In the event of introducing trade secrets (including classified geological and concession data) or information of a sensitive or critical nature into the AI Services, the disclosure of which to external cloud providers would violate the law or non-disclosure agreements binding the Client, the Client or User does so at their own and exclusive risk. The Provider bears no responsibility for any consequences and claims arising from the introduction of such data into the Application.
The Client or User strictly commits not to introduce any personal data into the AI Services. The Client is responsible for the full and permanent anonymization of Input Data before introducing it into the Application.
The AI Chat provided within the Application is based on solutions and application programming interfaces (APIs) of third-party providers, including in particular:
Microsoft Foundry – used to create and host the data infrastructure for the AI Chat, provided by Microsoft Ireland Operations Limited (One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland);
GPT-4o – provided by OpenAI Ireland Limited (1st Floor, The Liffey Trust Centre, 117-126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland).
The integration architecture guarantees that the AI Chat processes and transmits only a pseudonymized User Identifier (UserID) to external language models. Neither third-party artificial intelligence models nor their providers are able to identify the Client's or User's identity based solely on the transmitted UserID.
The Provider hereby declares and warrants that queries, prompts, and data inputted by the Client or User into the AI Services (including the AI Chat) are not and will not be used by the Provider or by external providers of artificial intelligence mechanisms to train their public language models or to improve services for other entities.
The AI Services are powered by satellite data and an internal knowledge base to which TerraEye holds exclusive intellectual property rights. The AI Services use this data to generate responses and Reports based on the User's parameters and prompts.
Due to the probabilistic nature of artificial intelligence based on machine learning, the Provider explicitly stipulates that results, responses, and Reports generated by AI Services may be untrue, inaccurate, or erroneous (so-called AI hallucinations). The Client or User is obliged to independently verify the information generated by the AI Services each time, in particular for its accuracy and reliability. The Client accepts that AI Services may be treated solely as a supporting tool in exploration processes and not as a definitive source of business or geological information. Any business, research, or investment decisions (including decisions to drill, purchase concessions, or acquire land) made by the Client based on Reports from the Application are made at their sole risk and responsibility.
The AI Services provided in the Application are not intended for making automated decisions that produce legal effects concerning natural persons.
The Client bears sole responsibility for using the AI Services and their results in a manner consistent with applicable law.
The Provider declares that the AI Services provided within the Application, due to their analytical and advisory function in the field of mineral exploration, do not constitute high-risk artificial intelligence systems within the meaning of Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonized rules on artificial intelligence and amending Regulations (EC) No 300/2008, (EU) No 167/2013, (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and Directives 2014/90/EU, (EU) 2016/797 and (EU) 2020/1828 (the AI Act).
§ 10. LIABILITY OF THE USER AND THE PROVIDER
The Client and the User bear full and exclusive liability for any consequences resulting from using the Application in a manner contrary to its purpose, these Terms, generally applicable law, good customs, principles of community life, and third-party rights, as well as for providing false, inaccurate, or incomplete data.
The Client bears full responsibility for all actions and omissions of Users utilizing the Application on their behalf, for their benefit, or using the Plan purchased by the Client, as if they were their own actions or omissions. The Client indemnifies the Provider against any claims made by third parties resulting from the misuse of access to the User Account.
In the event any claims are made against the Provider by third parties in connection with the infringement of their rights (including intellectual property rights) resulting from the Client's or User's actions in the Application, the Client commits to fully indemnifying the Provider. The Client shall cover all documented costs incurred by the Provider in connection with defending against such claims, including legal representation costs. The Client is also obliged to immediately provide the Provider with all information necessary to investigate the matter and defend its rights.
The Application and Services are provided on a "best effort" and "as is" basis. The Provider makes no express or implied warranties regarding the error-free or uninterrupted operation of the Application (no guaranteed Service Level Agreement – SLA), unless a Plan or a separate agreement concluded with the Client stipulates otherwise.
The Client acknowledges and accepts that the proper functioning of the Application depends on the infrastructure and services provided by third parties, in particular operators providing satellite and remote sensing data, cloud infrastructure providers, and external artificial intelligence model (API) providers.
The Provider is not liable for disruptions, interruptions in the Application's operation, failures, and loss or distortion of data that result from:
interruptions in the operation of third-party infrastructure, referred to in section 5 above;
necessary routine or emergency maintenance, updates, and upkeep of the Application;
disclosure of Login Credentials to third parties due to the fault or lack of due diligence on the part of the Client or User;
improper use of the Application.
Due to the probabilistic nature of machine learning algorithms (AI) and the specifics of remote sensing and satellite image analysis, to the fullest extent permitted by law, the Provider is not liable for:
errors, inaccuracies, defects, or malfunctions of AI models (including so-called AI hallucinations)
the accuracy of generated Reports, analysis results, topographical models, and their compliance with current geological, geochemical, or engineering knowledge;
the results of tests, research, and exploration projects carried out by the Client using the Application;
any damages or lost profits (including, among others, the costs of unsuccessful drilling, erroneous operational decisions, failed investments in land or mining concessions) incurred by the Client or third parties as a result of relying on data generated in the Application.
The Parties mutually exclude the Provider's statutory warranty liability for physical and legal defects of the Application and Services.
The Provider's total contractual and tortious liability towards the Client for non-performance or improper performance of the Agreement, loss of data, or Application downtime is strictly limited to actual damages and may not exceed the equivalent of the net Subscription Fees actually paid by the Client in the 3 (three) months preceding the event causing the damage. This limitation does not apply to damages caused by the Provider's willful misconduct.
The Client represents and warrants that neither they nor their ultimate beneficial owners (UBO), members of management bodies, or affiliated entities are listed on sanctions lists maintained by the Republic of Poland, the European Union, the United Nations, the US Department of the Treasury's Office of Foreign Assets Control (OFAC), or other competent national or international authorities.
The Client commits that the Application, generated Reports, and analytical functionalities will not be used in territories subject to international embargoes, in projects implemented in cooperation with sanctioned entities, or for any purpose related to military and armaments activities.
If the Provider reasonably suspects a breach of the warranties referred to in sections 10 and 11 above by the Client, the Provider is entitled to immediately and permanently block the User Account and terminate the Agreement with immediate effect. In such a situation, the Client is not entitled to a refund of any paid Subscription Fees or the right to any compensation claims against the Provider.
§ 11. FORCE MAJEURE
Neither Party shall be liable for the non-performance or improper performance of any of their obligations under the Agreement to the extent that this is the direct result of force majeure.
Force majeure is considered to be an external, extraordinary event impossible to foresee and prevent, beyond the reasonable control of the Parties, including in particular:
war (declared or undeclared), civil war, riots, disturbances, acts of sabotage, and acts of terrorism;
natural disasters, including earthquakes, floods, hurricanes, lightning strikes, or other extreme weather phenomena;
explosions, fires, extensive destruction of physical infrastructure;
general strikes, boycotts, lockouts, blockades of roads or ports, national or international import and export bans, embargoes;
epidemics or pandemics;
acts and decisions of state or local government authorities, both legal and unlawful;
interruptions in the supply of electricity and other utilities essential for the performance of the Agreement;
specific technological and satellite disruptions, including interruptions or disruptions in the acquisition of satellite and remote sensing data (resulting, among others, from adverse atmospheric phenomena, persistent cloud cover, space anomalies, or failures of external operators' satellites) and sudden restrictions imposed by third-party API providers, including drastic bandwidth limits (rate limits);
failures and disruptions of IT infrastructure, including widespread failures of global or regional telecommunications or internet networks, cyberattacks (e.g., DDoS, ransomware), failures on the part of cloud service or data center providers, as well as failures of operating systems, dedicated computing infrastructure (including servers and GPU clusters essential for AI modules), or the Application's database systems, independent of the Provider.
The Party invoking the occurrence of force majeure is obliged, without undue delay, but no later than within 5 (five) business days from the date of learning about the event, to notify the other Party in documentary form (e-mail), indicating the nature of the event and its expected impact on the ability to fulfill obligations. Failure to fulfill this obligation results in the loss of the right to invoke force majeure to be released from liability.
The Party affected by force majeure is obliged to immediately notify the other Party in the event the obstacle ceases.
If the state of Force Majeure preventing the performance of the Agreement continues uninterrupted for a period exceeding 30 (thirty) days, either Party is entitled to terminate the Agreement with immediate effect, without the right to formulate any claims for damages in this respect.
§ 12. INTELLECTUAL PROPERTY
All intellectual property rights to the Application, including in particular its source code, software, graphical user interface (UI/UX), artificial intelligence mechanisms, satellite and spectral analysis algorithms, databases, as well as the name, TerraEye logo, pictures, descriptions, operating principles, or Newsletter content, are the exclusive property of the Provider or third parties with whom the Provider cooperates.
No element of the Application, nor any materials made available in it, may be copied, modified, distributed, published, downloaded, displayed, recorded, compiled (creating derivative works), or used in any form and by any means (electronic, mechanical, photographic, recording), without the Provider's prior written consent, otherwise null and void.
Due to the innovative nature of the Application and the absolute protection of trade secrets and the Provider's know-how, the Client and Users are strictly prohibited from:
copying, duplicating, distributing, publishing, or modifying the Application, its graphic layout, source code, and any content integrated into it;
automated indexing, downloading, and data extraction (including via web crawling or web scraping techniques) in relation to any content, materials, and data placed in the Application;
decompiling, disassembling, reverse engineering, and any attempts to obtain or recreate the Application's source code;
breaking, bypassing, or modifying the Application's technological safeguards, including in particular authorization mechanisms and introduced query limits;
modifying the Application's architecture in any way.
By accepting the Terms, the Client grants the Provider a non-exclusive, royalty-free, and territorially unlimited license to use the Client's business name (trade name) and logo (including registered trademarks) for informational, reference, and marketing purposes. The license includes in particular the right to publicly share and place the name and logo on the Provider's websites, in the Application, in investor and sales presentations, and on the Provider's official social media profiles.
The Provider commits to using the logo in a manner that does not infringe upon the Client's reputation and in accordance with the brand guidelines provided by the Client (so-called brand book), provided such guidelines are explicitly made available to the Provider.
The license referred to in section 4 is granted for the duration of the Agreement and for a period of 5 (five) years after its termination. The Client is entitled to terminate this license solely for important reasons (e.g., change in ownership structure, rebranding), subject to a one-month notice period.
§ 13. LICENSE IN CONNECTION WITH USING THE APPLICATION
The Parties mutually declare that all economic copyrights, intellectual property rights, rights to know-how, algorithms, computational models, artificial intelligence tools, and the entire infrastructure of the Application remain the exclusive property of the Provider.
Upon concluding the Agreement and paying for the selected Plan (or upon providing the Demo Version), the Provider grants the Client a non-exclusive, non-transferable, territorially unlimited license without the right to sublicense, to use the Application.
The license authorizes the use of the Application solely in accordance with its intended purpose, the provisions of the Terms, and within the scope of functionalities and limits assigned to the selected Plan or Demo Version, in order to support the Client's internal exploration and operational processes.
The license is granted for the duration of the paid Plan or for the specified time the Demo version is provided. The fee for granting the license within the Plan is included in the Subscription Fee amount. The license to use the Demo Version is free of charge.
The license expires automatically upon the expiration or termination of the Agreement, the ineffective lapse of the paid subscription period, the end of the provision of the Demo Version, or the termination of access to the User Account.
The Application's source code is not the subject of the license. Subject to mandatorily applicable legal provisions, the Client and User are not entitled to:
duplicate, translate, adapt, rearrange, or make any other modifications to the Application;
decompile, disassemble, reverse engineer, or attempt to recreate the source code;
market the Application or its elements, lend, rent, lease, or make it available to third parties in an as-a-service model.
Exercising any derivative rights to the Application requires the Provider's explicit, prior written consent, otherwise null and void.
By introducing Input Data into the Application, the Client grants the Provider a non-exclusive, royalty-free, and territorially unlimited license to process, record, and duplicate them in order to properly provide the Services.
While maintaining full anonymization and confidentiality of the inputted data with respect to third parties, the Provider is entitled to process it for the purpose of internally improving the Application's algorithms and analytics.
The Parties do not foresee the joint creation of new intellectual property within the framework of the Agreement, nor the joint filing of applications for patents, utility models, industrial designs, or other forms of legal protection for the results of the cooperation.
The Provider remains the sole entity entitled to potentially certify and commercialize the solutions, functionalities, and results of the Application's operation.
§ 14. LICENSE IN CONNECTION WITH GENERATING REPORTS
Any analyses, compilations, models, and Reports generated by the Application constitute separate works (derivative works or databases) to which the economic copyrights belong exclusively to the Provider.
The Provider grants the Client a non-exclusive, non-transferable, and non-assignable license (without the right to sublicense) to use the generated Reports and share them with Users. The license is granted for an indefinite period, however, it authorizes the use of Reports exclusively in the following fields of exploitation: displaying, downloading, reading, duplicating, and analytical use strictly within the Client's organizational structure, solely for their own business, research, and exploration purposes.
The license for Reports does not include the right to share or use them in cooperation with third parties unless the Provider grants explicit written consent, otherwise null and void.
The license for Reports does not include the Client's or User's right to:
modify the Reports;
introduce the Reports into circulation (in whole or in part), including their sale, rent, lease, lending, donation, sharing, or use in cooperation with third parties, for the benefit of external entities, unless the specification of the Plan selected by the Client (e.g., Professional Plan) explicitly entitles to generate and share Reports in a white-label model, or different rules for sharing and modifying Reports arise from separate agreements concluded with the Client;
use the Reports to create, train, fine-tune, or validate their own or external machine learning models, artificial intelligence, large language models, or any other analytical algorithms;
use the Reports to publish the Client's scientific or research and development works.
§ 15. COMPATIBILITY AND INTEGRITY OF THE APPLICATION
The Provider makes every effort to ensure that the Application is designed and provided in a manner guaranteeing its reliability, durability, and security.
The Provider reserves the right to technically modify the method of implementing the Application's functionalities (including updates and upgrades), adequately to technological capabilities, without degrading its quality and key analytical parameters, and without affecting the scope of the rights and obligations of the Parties to the Agreement.
The Provider is not liable for the lack of Device parameters preventing the User from receiving data, nor for any technical problems preventing the provision of services arising due to force majeure or other events for which the Provider is not responsible, nor for the incompatibility of Account functionalities if the User's Device environment is incompatible with the Application's technical requirements.
The Provider reserves the right to conduct maintenance work, renovations, remove faults, erroneous or outdated information, upgrades, as well as change the graphic layout, and interruptions resulting from causes beyond the Provider's control, which may cause temporary difficulties or prevent Users from using the Account or the Application. The Provider will endeavor to keep these interruptions as short as possible, but to the extent permitted by law, is not liable for the consequences of such interruptions.
In emergencies, in particular those threatening the security of Input Data, the stability of the Provider's IT system, or the integrity of the Application (e.g., cyberattacks, identification of critical vulnerabilities), the Provider is entitled to temporarily cease or restrict the provision of Services with immediate effect, without prior notice to the Client, in order to carry out emergency securing work.
The Provider informs the Client about Application updates, including security updates, and any necessary actions to be performed by the Client or User. The Provider is not liable for the Application's non-conformity with the contract if the Client or User fails to perform the actions indicated by the Provider.
In special cases affecting the security or stability of the IT system, the Provider has the right to temporarily cease or restrict the provision of services, without prior notice, and conduct maintenance work aimed at restoring the Application's security and stability.
The Provider reserves the right to change the scope of visibility, functionality, graphic design of the Application, provided AI Services, digital content, and other services provided within the Application as testing, updating, and development of the Application progresses.
If the changes introduced in connection with the Application's development, referred to in section 8 of the Terms, significantly and negatively affect the User's access to content or Services in the Application, the Provider will inform the User about the scope of changes with appropriate advance notice regarding the nature and date of these changes. The User may terminate the agreement without notice within 30 days from the date of the change or receiving information about changes already introduced, unless the Provider ensures the User can retain the Application in an unchanged state.
§ 16. COMPLAINTS
The Client or User may notify the Provider of the non-conformity of the Application or digital content provided within the Account with the agreement (hereinafter: "Complaint") via e-mail, telephone, in writing to the Provider's address, or via another contact channel provided by the Provider.
In the Complaint, the User should provide their e-mail address, Client data, type, and date of occurrence of the causes of the Complaint.
In connection with the Complaint, the Provider will bring the service into conformity with the agreement within a reasonable time from receiving the Complaint, at its own expense. In the case of reports requiring complex systemic diagnostics or the involvement of external providers (e.g., cloud infrastructure or AI model operators), this period may be extended, of which the Provider will notify the Client.
The complaint procedure is strictly technical and organizational in nature. Filing a Complaint does not entitle the Client to withhold or offset any payments due for Subscription Fees, unilaterally reduce the Provider's remuneration, or withdraw from the Agreement.
§ 17. CONFIDENTIALITY AND NON-COMPETE
Each Party is obliged to maintain the confidentiality of information regarding the implementation of cooperation, and in particular commercial terms, technical, and technological information disclosed to it by the other Party, which is not publicly available information (hereinafter: "Confidential Information").
The scope of Confidential Information includes in particular:
know-how, technical, technological information, including algorithms, analytical models, Application architecture, and the Provider's technical documentation;
information regarding server infrastructure, security procedures, data processing, and the Provider's analytical methodology;
Input Data introduced into the AI Services by the User and the Client's internal procedures and business goals;
other classified information related to the technological or operational activities of the Parties.
The Parties commit to using all confidential information obtained during and in connection with the cooperation exclusively for the purposes specified by the Parties and within the scope agreed upon by them.
The Parties commit to protecting the other Party's Confidential Information to at least the same degree as they protect their own information of a similar nature, but always exercising the due diligence required in professional business relations.
The Party receiving Confidential Information commits in particular to:
not disclosing it to any third parties without the prior written consent (otherwise null and void) of the disclosing Party;
using it exclusively for purposes directly related to the execution of the Agreement
sharing it exclusively with its employees, associates, advisors, and affiliated entities for whom this knowledge is necessary to execute the Agreement, provided these persons are bound by confidentiality obligations no less strict than those resulting from these Terms;
not copying or duplicating Confidential Information, except when necessary for the execution of the Agreement.
The obligation of confidentiality does not apply to information:
that is or can be independently obtained by the receiving Party without violating its obligations;
previously published, generally known, or made public without violating the confidentiality obligation;
that the receiving Party obtained from a third party without that third party violating confidentiality obligations;
the disclosure of which is required in connection with the imposition on the receiving Party of an obligation to disclose confidential information in accordance with applicable legal regulations.
The Client acknowledges and accepts that the Provider is part of a global capital group, of which the managing (dominant) entity is International Resource Holding (IRH).
The Provider strictly commits that all Client Input Data (including sensitive geological, location, and geochemical data) and generated Reports are processed exclusively for the technical purpose of providing Services in the Application. Access to this data within the Provider's organization is based on a strict need-to-know basis and is limited to designated technical personnel. Members of the Company's bodies concurrently holding functions within IRH structures are subject to rigorous confidentiality obligations and possess access to data solely to the extent necessary to exercise statutory corporate oversight. The Provider guarantees that the Client's analytical and operational data will under no circumstances be transferred or shared with IRH's exploration, investment, or operational teams, nor will they be used in any way to conduct mining activities or acquire assets by entities from the Provider's corporate group.
The confidentiality obligations for both Parties are valid for the entire duration of the Agreement and for 5 (five) years from the date of its expiration or termination.
During the term of the Agreement and for 5 (five) years after its termination, the Client commits not to conduct, directly or indirectly, activities consisting in creating, developing, or commercializing software, artificial intelligence algorithms, or satellite analytics systems that would constitute competitive systems to the Application, in particular by using Confidential Information, using the User Account, or Reports generated in the Application.
In the event the Client breaches the confidentiality obligation or the non-compete clause, the Provider has the right to demand from the Client payment of a contractual penalty in the amount of USD 100,000.00 (in words: one hundred thousand US dollars) for each breach.
The stipulation of a contractual penalty does not deprive the Provider of the right to seek damages exceeding the amount of the stipulated penalty under general rules.
§ 18. NEWSLETTER SERVICE
Due to the specifics of the Application and the need to provide Users with up-to-date information on new algorithms, AI models, and analytical capabilities, the Provider provides Clients with a free Newsletter delivery service.
The Newsletter service consists of the periodic dispatch of industry information, educational materials, and commercial information regarding new functionalities, products, and services of the Provider to the e-mail address assigned to the User Account.
The provision of the Newsletter service begins automatically upon the successful completion of Registration and the creation of the User Account.
The User has the right to resign from receiving the Newsletter at any time and without giving a reason. Resignation can be accomplished by clicking on a dedicated unsubscribe link located in the footer of each e-mail message sent as part of this service or via the appropriate option in the User Account settings.
Resignation from the Newsletter does not affect the ability to use the Application's remaining functionalities, including the purchased Plan, nor the Provider's sending of information related to the Application's operation and the execution of the remainder of the Agreement.
§ 19. PERSONAL DATA
The Provider processes the personal data of the Client's representatives, contact persons, and persons authorized to conclude the Agreement as a data controller. Detailed rules of this processing are specified in the Privacy Policy available at the link: https://terraeye.co/privacy-policy.
With regard to the personal data of Application Users or other persons, the exclusive data controller is the Client, and the Provider processes them on the basis of a data processing entrustment by the Client in accordance with the Data Processing Agreement (DPA), constituting Annex No. 1 to these Terms.
The User is not entitled to introduce into the Application any personal data that are not required by the Provider, and even less so the data of persons other than the User's data. In the event of a violation of the prohibition referred to in the preceding sentence, the Provider is entitled to delete the personal data and block or delete the User Account.
The Client and the User are not entitled to introduce into the Application any personal data exceeding the scope necessary to create a User Account and properly use the Application's functionalities. In particular, the processing of special categories of personal data (so-called sensitive data) in the Application is strictly prohibited.
The Client and the User commit not to introduce any personal data into the AI Services modules (including the AI Chat). All Input Data, including queries and prompts, directed to the AI Services must be permanently anonymized by the Client beforehand.
§ 20. TERM AND TERMINATION OF THE AGREEMENT
The Agreement is concluded for a definite period, corresponding to the period the Demo version is provided or the paid Plan. After the end of the Agreement term (in the absence of subscription renewal for another period), the Client's or User's access to the Application is automatically blocked.
The Client may cancel the subscription renewal at any time by submitting a relevant instruction in the dedicated panel within the User Account. Canceling the subscription results in the termination of the Agreement effective on the last day of the paid Plan.
The User may resign from the User Account access service at any time by submitting an appropriate instruction provided within the User Account. In such a case, the Client is not entitled to demand a refund of the paid Subscription Fee for the unused duration of the Plan.
The Provider is entitled to terminate the Agreement at any time, subject to a 30-day notice period. In such a situation, the Provider shall refund to the Client a proportional part of the Subscription Fee for the unused period.
In the event the Client fails to make timely payment for the subscription, the Provider reserves the right to suspend or restrict the Client's and Users' access to the Services until the outstanding payments are fully settled.
In the event the Client falls into arrears with the payment of the Subscription Fee for any month of using the Plan for a period longer than 7 calendar days, the Provider is entitled to terminate the Agreement with immediate effect.
The Provider is entitled to temporarily block access to the User Account in the event of suspected or confirmed:
breach of the provisions of these Terms, generally applicable legal provisions, or third-party rights, if the Provider deems blocking necessary until the matter is clarified;
provision by the Client or User during the registration process or use of the Account of false, outdated, fictitious, or incomplete data;
breach by the Client or User of the prohibition on sharing Login Credentials with third parties;
using the Application via automated scripts (e.g., scraping) or intentionally exceeding the set query limits in a manner threatening the stability of the Provider's IT infrastructure;
suspicion of using generated Reports, analysis results, or data from the Application to train external AI models or conduct activities competitive to the Provider;
cancellation of the Plan by the User or after the ineffective lapse of the paid subscription period;
imposition of such an obligation on the Provider by mandatorily applicable law or based on a decision of a competent authority.
In the event of a temporary blockade of access to the Account based on section 7, the Provider shall take appropriate explanatory actions and inform the Client of its decision (unblocking the Account or terminating the Agreement) within 14 days from the date access was blocked. The temporary blocking of the User Account does not result in the deletion of Input Data or Reports stored in the Application and does not entitle the Client to demand a refund of the whole or any proportional part of the paid Subscription Fee for the period during which access to the Services remained suspended.
The Provider reserves the right to terminate the Agreement with immediate effect and permanently delete the User Account for important reasons, in particular in the event of suspected or confirmed:
breach of the provisions of these Terms (including in particular a breach of license prohibitions, non-compete clause, confidentiality rules, or rules for using AI Services), provisions of applicable law, or third-party rights, if the Provider considers implementing a temporary blockade insufficient;
introducing Input Data into the Application in a manner infringing the intellectual property rights of third parties;
attempting or taking actions threatening the stability or security of the Provider's IT systems, the security or continuity of the Application's operation, or the security of other Clients or Users, including reverse engineering attempts or automated data downloading, introducing, transmitting, distributing, or infecting the Application's infrastructure with any viruses, Trojan horses, malicious code, or other software (malware), attempts to intercept data for phishing attacks or other cybercrimes;
the User submitting an explicit request to delete the Account, including as part of exercising the "right to be forgotten" under Article 17 of the GDPR;
imposition of such an obligation on the Provider by mandatorily applicable law or based on a decision of a competent authority;
the Provider reasonably suspecting a breach by the Client of warranties regarding non-subjection to international sanctions and export controls;
abuse of Services, including using the Provider's cloud, analytical, or artificial intelligence infrastructure in a manner inconsistent with its business purpose.
In the event of termination of the Agreement, blocking, or deleting the User Account for reasons attributable exclusively to the Client or User, the Provider is not obliged to refund the Subscription Fee for the unused subscription period under the Plan selected by the Client.
If, after concluding the Agreement and paying for the Plan, the Provider fails to grant the Client access to the Application or the User Account, the Client is entitled to call upon the Provider to immediately perform the obligation and grant access. In the event of an ineffective lapse of an additional, appropriate deadline set by the Client to remedy the breach (not shorter, however, than 5 business days), the Client has the right to withdraw from the Agreement with immediate effect and the right to demand a refund of the paid Subscription Fee.
The declarations referred to in this section of the Terms are submitted by the Provider and the User in electronic form via an appropriate message provided within the User Account or via e-mail correspondence.
Within 30 days from the date of expiration or termination of the Agreement, the Provider permanently deletes the Input Data from the Application systems and closes the User Account. The above does not apply to data whose further processing is necessary to establish, assert, or defend against claims, fulfill accounting and tax obligations, as well as anonymized data used to improve algorithms in accordance with the license granted under these Terms.
§ 21. FINAL PROVISIONS
The Provider reserves the right to change these Terms for important business, legal, technological, or organizational reasons, which are in particular:
changes in the scope, type, or nature of the services provided by the Provider, covered by the provisions of these Terms and the conditions of their provision, in particular for technical reasons or market changes;
changes in the name of any Service covered by these Terms;
disclosure of inaccuracies or non-compliance of the content of these Terms with currently applicable legal provisions;
a change in applicable legal provisions justifying the need to change or delete individual provisions of the Terms;
the necessity to adapt the scope of the Provider's activities to the guidelines, recommendations, decisions, or rulings of a public authority, court, or other entity legally authorized to issue binding orders to the Provider;
organizational and technical changes in the Provider's structure, including in particular transformations, mergers, acquisitions, or name changes.
Every User holding a User Account will be informed of a change to the Terms via information provided on the User Account or via an e-mail message, at least 10 days before its effective date.
The Client's failure to terminate the Agreement or delete the User Account before the effective date of the new Terms is equivalent to their acceptance. In the absence of consent to the changes, the Client is entitled to terminate the Agreement with effect at the end of the currently paid Plan.
The Provider may, at any time, introduce editorial changes and correct clerical or calculation errors in the Terms that do not affect the rights and obligations of the parties.
In the event that any of the provisions of the Terms is or becomes invalid, ineffective, or unenforceable, the remaining provisions of the Terms remain in force as if such invalid, ineffective, or unenforceable provision had not been included in the Terms.
The law applicable to the Agreements, the Terms, and all claims and disputes arising from the Client's or User's use of the Application is exclusively Polish law.
Any disputes related to the Services provided by the Provider within the Application will be resolved by Polish common courts having jurisdiction over the Provider's registered office.
The Terms enter into force on 18.08.2026.
The content of the Terms is available on the Provider's website at: https://terraeye.co/app-terms-of-service. The User may, in particular, download, save, and print these Terms.
In accordance with Articles 11 and 12 of Regulation (EU) 2022/2065 of the European Parliament and of the Council of 19 October 2022 on a Single Market for Digital Services (the Digital Services Act - DSA), the Provider designates a single point of contact enabling direct communication with Member States' authorities, the Commission, the European Board for Digital Services, and Users. Communication with the point of contact takes place electronically at the e-mail address: support@terraeye.co. The supported communication languages are Polish and English.
The User may contact the Provider using the following details:
Remote Sensing Business Solutions sp. z o.o.,
ul. Długosza 60A, 51-162 Wrocław, Poland,
KRS: 0001105923, NIP: 8952241235, REGON: 521932803,
website address: https://terraeye.co/,
e-mail address: sales@terraeye.co.
ANNEX NO. 1
DATA PROCESSING AGREEMENT (DPA)
(hereinafter: the "Agreement")
concluded between:
Remote Sensing Business Solutions sp. z o.o. (operating under the TerraEye brand) with its registered office in Wrocław, ul. Długosza 60A, 51-162 Wrocław, Poland, entered into the register of entrepreneurs of the National Court Register under KRS number: 0001105923, NIP: 8952241235, REGON: 521932803, with a share capital of PLN 1,553,401.44,
hereinafter: the "Processor"
and
The Client (as defined in the Terms of Service)
hereinafter: the "Controller"
jointly referred to as the "Parties", and individually as a "Party".
Whereas the Parties have concluded an agreement for the provision of SaaS services based on the acceptance of the TerraEye Terms of Service (hereinafter: the "Main Agreement"), the Parties have agreed to conclude an Agreement with the following content:
§ 1. SUBJECT OF THE AGREEMENT
The subject of the Agreement is the entrustment of personal data processing, pursuant to Article 28 paragraph 3 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter: the "GDPR").
The Processor commits to performing personal data processing activities on behalf of the Controller strictly for the purpose, scope, and under the rules specified in the Agreement.
§ 2. SCOPE OF PROCESSING ENTRUSTMENT
The Controller entrusts the Processor with the processing of personal data within the following scope:
personal data of Application Users;
other personal data inputted and processed by the Controller and Users authorized by them in connection with the use of the Application.
The Processor is authorized to perform the following processing operations on the entrusted data: recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
The Processor processes the entrusted personal data solely for the purpose of executing the Main Agreement.
§ 3. PROCESSING SOLELY ON THE CONTROLLER'S DOCUMENTED INSTRUCTIONS
The processing of personal data to an extent exceeding § 2 of the Agreement requires an amendment to the Agreement.
§ 2 section 1 of the Agreement does not apply if the Processor acts to fulfill an obligation imposed on it by European Union law or the law of a Member State to which the Processor is subject, and the fulfillment of this obligation cannot be reconciled with the provisions of the Agreement.
In the situation referred to in § 3 section 2 of the Agreement, prior to starting the processing, the Processor shall inform the Controller of this legal requirement, unless that law prohibits such information on important grounds of public interest.
§ 4. OBLIGATION OF CONFIDENTIALITY
The Processor authorizes to process the entrusted personal data only those members of its staff who possess appropriate authorizations, have been trained in personal data protection, and whose involvement is necessary for the execution of the Agreement and the provision of services based on the Main Agreement.
The Processor ensures that the persons referred to in section 1:
process personal data in accordance with the need-to-know principle;
have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
§ 5. SECURITY OF PROCESSING
The Processor ensures the implementation of appropriate technical and organizational measures to ensure the processing complies with the GDPR, including a level of security appropriate to the risk of infringing the rights or freedoms of natural persons whose data are concerned.
§ 6. SUB-PROCESSING
In order to execute the Main Agreement, the Processor may use the services of other processors (e.g., cloud infrastructure providers, artificial intelligence model providers, entities from the IRH Corporate Group), to which the Controller hereby grants general consent. A list of such entities shall be made available by the Processor upon any request by the Controller.
Using the services of another processor is permissible only based on a contract that imposes on that entity at least the same data protection obligations as the initial Processor is subject to under the Agreement.
Where that other processor fails to fulfill its data protection obligations, the initial Processor shall remain fully liable to the Controller for the performance of that other processor's obligations.
§ 7. TRANSFER OF PERSONAL DATA
The Processor may transfer or authorize the transfer of entrusted personal data outside the European Economic Area (EEA) solely on the condition of providing appropriate legal safeguards, in particular based on Standard Contractual Clauses (SCCs) approved by the European Commission or an adequacy decision.
§ 8. RESPONDING TO DATA SUBJECT REQUESTS
Upon the Controller's request, the Processor applies organizational and technical measures assisting the Controller (within the technical capabilities of the Application) in fulfilling the obligation to respond to data subject requests.
In the event a request regarding the exercise of rights of persons whose entrusted data are concerned is received by the Processor, the Processor immediately informs the Controller thereof. When providing information, the Processor transmits the sender's data and the content of the request and specifies the extent to which it can contribute to fulfilling the request. The Processor does not independently respond to such requests without the Controller's consent.
§ 9. DELETION OR RETURN OF PERSONAL DATA
After the end of the provision of services under the Main Agreement, depending on the Controller's decision, the Processor deletes or returns all entrusted personal data to the Controller and deletes any existing copies thereof, unless European Union law or Member State law requires the further storage of personal data.
The Processor is obliged to execute the instruction to delete data within 30 days from the date of terminating the provision of Services (in accordance with § 20 of the Terms) or from the date of receiving an explicit request.
The processing of data to the necessary technical extent until the completion of the obligations specified in this paragraph does not constitute a breach of the Agreement.
§ 10. REPORTING
Upon the Controller's request, the Processor provides all information necessary to demonstrate compliance with the obligations laid down in Article 28 of the GDPR.
The information referred to in § 10 section 1 of the Agreement is provided within 7 days from the date of delivery of the request, subject to § 10 section 3 of the Agreement.
If the request relates to the fulfillment of the obligation to report a personal data breach or mitigate its effects, the Processor provides information at the earliest possible time, but no later than within 48 hours from the delivery of the request.
If the Processor detects a breach of protection of the entrusted personal data, it reports it to the Controller without undue delay, but no later than within 48 hours of its detection.
The Processor immediately informs the Controller of:
any proceedings (in particular administrative or judicial) concerning the processing of entrusted data;
the issuance of any ruling directly affecting the processing of entrusted data;
any planned or ongoing inspections by supervisory authorities concerning the entrusted personal data.
§ 11. INSPECTIONS (AUDITS)
To verify compliance with the obligations arising from the Agreement, the Controller has the right to conduct an inspection (audit).
The right to conduct an inspection covers only areas directly related to the processing of the entrusted data and consists in particular of:
requesting written explanations from designated representatives of the Processor;
reviewing relevant security policy documentation (excluding trade secrets, confidential information concerning other clients, and the Application's source code).
The Controller may exercise the right to conduct an inspection during the standard business hours of the Processor, notifying the Processor of such intent in writing at least 14 days in advance.
The Processor commits to rectifying any deficiencies identified during the inspection within a reasonable technological timeframe agreed upon by the Parties.
§ 12. LIABILITY OF THE PROCESSOR
The Processor is liable for the sharing or use of personal data contrary to the content of the Agreement, and in particular for sharing the personal data entrusted for processing with unauthorized persons.
If, as a result of a breach of the Agreement's provisions by the Processor, the Controller is obliged to pay compensation or is otherwise held liable for violating personal data protection regulations, the Controller may demand from the Processor reparation of the resulting damage, subject to the general limitations of liability provided in the Main Agreement.
§ 13. FINAL PROVISIONS
The Agreement is concluded for the duration of the Main Agreement.
The Controller may terminate the Agreement with immediate effect when the Processor:
despite a summons to remove critical deficiencies found during an audit, fails to remove them within the designated, technically justified deadline;
processes personal data in gross violation of the Agreement.
The Agreement is concluded in documentary form through the acceptance of its terms by the Client via a dedicated order form.
In matters not covered, the provisions of the Polish Civil Code and the GDPR shall apply.
The law applicable to the Agreement is Polish law.
The competent court to resolve disputes arising from the Agreement shall be the court having jurisdiction over the Processor.