Service Agreement / Terms & Conditions

PARTIES:

(1) VeriFi Limited, a company incorporated in England (registration number 7307582) having its registered office at 70 Seabourne Road, Southbourne, Bournemouth, BH5 2HT (the “Licensor” / “Processor”); and

(2) Any individual, company or any other organisation that has been issued with a Username and Password enabling access to and use of VeriFi EIDOS Applications (the “Licensee” / “Controller”).

BACKGROUND:

The Licensor/Processor has copyright in certain Software forming the Service, and the parties have agreed that the Licensor/Processor will license that Service and provide any associated equipment as set out in the Quotation & Schedule to the Licensee/Controller on the terms of this Agreement.

VERSION:

The Licensor/Processor may from time to time amend the terms of this Agreement as it appears electronically. It is the responsibility of the Licensee/Controller to print and retain a hard copy on the “Effective Date”, which shall be the date on which the “Username & Password” are first used by the Licensee/Controller. In the absence of such hard copy the current terms as they appear electronically will apply.

SCOPE OF SERVICE:

The scope of the service provided will be either or both:

a) The UK GDPR Data Compliance Support Service document which can be found at https://www.verifi-eidos.co.uk; and/or

b) VeriFi EIDOS Software as a Service as described in the Quotation & Schedule provided by the Licensor/Processor.

ACCEPTANCE:

By accessing or using the VeriFi EIDOS Service, the Licensee/Controller agrees to these Terms & Conditions, which include the Data Processing Agreement in Schedule 1.

AGREEMENT:

1. Definitions and interpretation

1.1 In this Agreement:

“Agreement” means this Service Agreement (including the appended Quotation and Schedule, and Schedule 1);

“Applicable Laws” means all laws, statutes, regulations and codes from time to time in force and applicable to a party’s performance of its obligations under this Agreement, including (without limitation) the Data Protection Legislation;

“Appropriate Policy Document” means a document of the type described in Schedule 1 to the Data Protection Act 2018 that is required where criminal offence data or special category data is processed in reliance on certain conditions in that Schedule;

“Business Day” means any week day, other than a bank or public holiday in England;

“Business Hours” means between 08:30 and 16:30 on a Business Day, which shall be Monday to Friday excluding Bank Holidays;

“Charges” means the amounts payable by the Licensee/Controller to the Licensor/Processor under or in relation to this Agreement (as set out in the Quotation & Schedule);

“Consumables” means items purchased by the Licensee/Controller from the Licensor/Processor from time to time as required and as referred to and listed in the “Quotation & Schedule”;

“Critical Issues” means defects, errors and bugs that render the system incapable of usefully performing the tasks for which it was intended;

“Effective Date” means the date of execution of this Agreement, which shall be the date on which the “Username & Password” are first used by the Licensee/Controller;

“Equipment” means any equipment issued to the Licensee/Controller by the Licensor/Processor which is referred to and listed in the “Quotation & Schedule”;

“Force Majeure Event” means an event, or a series of related events, that is outside the reasonable control of the party affected (including failures of or problems with the internet or a part of the internet, hacker attacks, virus or other malicious software attacks or infections, power failures, industrial disputes affecting any third party, changes to the law, disasters, explosions, fires, floods, riots, terrorist attacks and wars);

“Intellectual Property Rights” means all intellectual property rights wherever in the world, whether registered or unregistered, including any application or right of application for such rights (and the intellectual property rights referred to above include copyright and related rights, database rights, confidential information, trade secrets, know-how, business names, trade names, trade marks, service marks, passing-off rights, unfair competition rights, patents, petty patents, utility models, semi-conductor topography rights and rights in designs);

“Licensee/Controller’s Agent” means any third party employed by the Licensee/Controller who uses the “Service”;

“NFC Attendance Logging” means the logging of attendance at locations and equipment by staff or contractors scanning Near Field Communications tags with smartphones or computer tablets;

“Non-Critical Issues” means defects, errors and bugs that do not adversely affect the system, in that it is capable of continuing to usefully perform the tasks for which it was intended;

“Quotation & Schedule” means the quotation provided separately to this Agreement;

“Controller”, “Processor”, “Data Subject”, “Personal Data”, “Personal Data Breach”, “processing” and “appropriate technical and organisational measures” have the meanings given to them in the Data Protection Legislation;

“Data Protection Legislation” means the UK Data Protection Legislation and any other legislation relating to personal data and all other legislation and regulatory requirements in force from time to time which apply to a party relating to the use of Personal Data (including, without limitation, the privacy of electronic communications);

“UK Data Protection Legislation” means all applicable data protection and privacy legislation in force from time to time in the UK, including the UK General Data Protection Regulation, the Data Protection Act 2018, the Privacy and Electronic Communications Directive 2002/58/EC (as updated by Directive 2009/136/EC) and the Privacy and Electronic Communications Regulations 2003 (SI 2003/2426) as amended;

“Service” means the computer applications and peripherals identified in the Quotation & Schedule;

“Term” means the term of this Agreement;

“VeriFi EIDOS” is the brand applied to the Licensor/Processor’s product/service.

1.2 In this Agreement, a reference to a statute or statutory provision includes a reference to:

(a) that statute or statutory provision as modified, consolidated and/or re-enacted from time to time; and

(b) any subordinate legislation made under that statute or statutory provision.

1.3 The Clause headings do not affect the interpretation of this Agreement.

2. Term

This Agreement will come into force on the Effective Date and will continue in force for a minimum period of three years unless otherwise specified in the Quotation & Schedule. It may, however, be terminated earlier in accordance with Clause 7.

3. Delivery of Service

3.1 The Licensor/Processor will deliver the Username and Password to the Licensee/Controller by email upon receipt of the Licensee/Controller’s Purchase Order.

3.2 For the avoidance of doubt, nothing in this Agreement requires the Licensor/Processor to deliver to the Licensee/Controller any copies of the source code of the Service software, and nothing in this Agreement constitutes a licence to use the source code of the Service software.

3.3 Unless otherwise indicated in the Quotation & Schedule, the Licensee/Controller will make available and maintain all equipment necessary to operate the Service/Application.

3.4 The Licensee/Controller will be responsible for obtaining and/or granting any necessary permissions for the Licensor/Processor to connect peripherals to the Licensee/Controller’s PC and Wi-Fi network.

3.5 The Licensor/Processor will provide telephone ‘Help Desk’ support during normal Business Hours.

3.6 The Licensor/Processor will, if required by the Licensee/Controller, provide site attendance during normal Business Hours at its current Daily Rate of £600 as at 1 April 2026, subject to RPI thereafter (or such other rate as set out in the Quotation & Schedule), plus travelling expenses.

4. Invoicing and payment

4.1 The Licensor/Processor will issue invoices for the Charges to the Licensee/Controller on or after the invoicing dates set out in the Quotation & Schedule.

4.2 The Licensee/Controller will pay the Charges to the Licensor/Processor within 30 days of the date of an invoice issued in accordance with Clause 4.1.

4.3 All Charges stated in or in relation to this Agreement are stated exclusive of VAT, unless the context requires otherwise.

4.4 Charges must be paid by bank transfer (using such payment details as are notified by the Licensor/Processor to the Licensee/Controller from time to time).

4.5 If the Licensee/Controller does not pay any amount properly due to the Licensor/Processor under or in connection with this Agreement, the Licensor/Processor may suspend the Service until such time as the due amount is paid. The Licensee/Controller will in this case forfeit the period of suspension.

5. Warranties

5.1 The Licensee/Controller warrants and represents to the Licensor/Processor that it has the legal right and authority to enter into and perform its obligations under this Agreement.

5.2 The Licensor/Processor warrants and represents to the Licensee/Controller:

(a) that it has the legal right and authority to enter into and perform its obligations under this Agreement;

(b) that the Service supplied by the Licensor/Processor will at the date of delivery perform substantially in accordance with the documentation accompanying the Service;

(c) that the use by the Licensee/Controller, in accordance with the terms of this Agreement, of the Service supplied by the Licensor/Processor will not:

(i) infringe any person’s Intellectual Property Rights or other legal rights;

(ii) breach any laws, statutes or regulations; or

(iii) give rise to a cause of action against the Licensor/Processor or the Licensee/Controller or any other person, in each case in any jurisdiction and under any applicable law.

5.3 The Licensee/Controller acknowledges that complex software is never wholly free from defects, errors and bugs, and the Licensor/Processor gives no warranty or representation that the Service will be wholly free from such defects, errors and bugs. Provided that any such anomalies are notified to the Licensor/Processor by means of the ‘Feedback’ facilities that are integral to the system:

(i) Critical Issues will be resolved within 24 hours of notification being logged;

(ii) Non-Critical Issues will be resolved in the next software version routinely released at 90-day intervals.

5.4 All of the parties’ warranties and representations in respect of the subject matter of this Agreement are expressly set out in the terms of this Agreement. To the maximum extent permitted by applicable law, no other warranties or representations concerning the subject matter of this Agreement will be implied into this Agreement.

6. Limitations and exclusions of liability

6.1 Nothing in the Agreement will:

(a) limit or exclude the liability of a party for death or personal injury resulting from negligence;

(b) limit or exclude the liability of a party for fraud or fraudulent misrepresentation by that party;

(c) limit any liability of a party in any way that is not permitted under applicable law; or

(d) exclude any liability of a party that may not be excluded under applicable law.

6.2 The limitations and exclusions of liability set out in this Clause 6 and elsewhere in the Agreement:

(a) govern all liabilities arising under the Agreement or any collateral contract or in relation to the subject matter of the Agreement or any collateral contract, including liabilities arising in contract, in tort (including negligence) and for breach of statutory duty; and

(b) will not limit or exclude the liability of the parties under the express indemnities set out in this Agreement.

6.3 The Licensor/Processor will not be liable in respect of any loss of profits, income or revenue.

6.4 Neither party will be liable for any loss of business, contracts or commercial opportunities.

6.5 Neither party will be liable for any loss of or damage to goodwill or reputation.

6.6 Neither party will be liable for any losses arising out of a Force Majeure Event.

6.7 Neither party’s liability in relation to any event or series of related events shall not exceed the total amount paid and payable by the Licensee/Controller to the Licensor/Processor under the Agreement during the 12-month period immediately preceding the event or events giving rise to the claim.

7. Termination

7.1 The Licensee/Controller may terminate this Agreement by giving to the Licensor/Processor not less than 30 days’ prior written notice if:

(a) the Licensee/Controller disposes of the building at which this Service is licensed and applied; or

(b) (where the Licensee/Controller is a contractor to a third party) the Licensee/Controller is contracted to a third party to provide services at the building at which this Service is licensed and applied, and the Licensee/Controller’s contract is terminated.

7.2 Either party may terminate this Agreement with immediate effect by giving written notice if the other party:

(a) commits any material breach of any term of this Agreement, and:

(i) the breach is not remediable; or

(ii) the breach is remediable, but the other party fails to remedy the breach within 30 days of receipt of a written notice requiring it to do so; or

(b) persistently breaches the terms of this Agreement (irrespective of whether such breaches collectively constitute a material breach); or

(c) acts as a contractor to a third party and their contract with that third party is terminated (and documentary evidence of termination is shown), in which case any advance payment made or due in respect of this Agreement will be non-refundable.

7.3 Either party may terminate this Agreement with immediate effect by giving written notice if:

(a) the other party:

(i) is dissolved;

(ii) ceases to conduct all (or substantially all) of its business;

(iii) is or becomes unable to pay its debts as they fall due;

(iv) is or becomes insolvent or is declared insolvent; or

(v) convenes a meeting or makes or proposes to make any arrangement or composition with its creditors;

(b) an administrator, administrative receiver, liquidator, receiver, trustee, manager or similar is appointed over any of the assets of the other party;

(c) an order is made for the winding up of the other party, or the other party passes a resolution for its winding up (other than for the purpose of a solvent company reorganisation where the resulting entity will assume all the obligations of the other party under this Agreement); or

(d) (where that other party is an individual) that other party dies, or as a result of illness or incapacity becomes incapable of managing his or her own affairs, or is the subject of a bankruptcy petition or order.

8. Effects of termination

8.1 Upon termination of this Agreement, all the provisions of this Agreement will cease to have effect, except that the following provisions will survive termination: Clause 6 (Limitations and exclusions of liability), this Clause 8, Clause 11 (General) including the governing law and jurisdiction provisions, and paragraphs 1, 4(F), 4(G), 4(H), 4(J) and 6 of Schedule 1, together with any other provision that is expressly or by implication intended to survive.

8.2 Termination of this Agreement will not affect either party’s accrued liabilities or rights as at the date of termination.

8.3 Within 10 Business Days following the date of termination of this Agreement, the Licensee/Controller will return to the Licensor/Processor, or dispose of as the Licensor/Processor may instruct, all equipment (as set out in the Quotation & Schedule) in its possession.

8.4 In the case of Clause 7.1, no credit or refund will be due to the Licensee/Controller for any unexpired portion of the period for which payment has already been made or has already fallen due.

9. Equipment

9.1 The Licensee/Controller shall provide all equipment and data service required to operate the various VeriFi EIDOS applications.

10. Consumables

10.1 Consumables will be as specified at the rates shown in the Quotation & Schedule, subject to RPI, and supplied exclusively by the Licensor/Processor.

11. General

11.1 No breach of any provision of this Agreement will be waived except with the express written consent of the party not in breach.

11.2 If a Clause of this Agreement is determined by any court or other competent authority to be unlawful and/or unenforceable, the other Clauses of this Agreement will continue in effect. If any unlawful and/or unenforceable Clause would be lawful or enforceable if part of it were deleted, that part will be deemed to be deleted, and the rest of the Clause will continue in effect (unless that would contradict the clear intention of the parties, in which case the entirety of the relevant Clause will be deemed to be deleted).

11.3 Nothing in this Agreement will constitute a partnership, agency relationship or contract of employment between the parties.

11.4 This Agreement may not be varied except by a written document signed by or on behalf of each of the parties.

11.5 Each party may freely assign any or all of its contractual rights and obligations under this Agreement to any successor to all or a substantial part of its business. Save as expressly provided in this Clause or elsewhere in this Agreement, neither party may, without the prior written consent of the other party, assign, transfer, charge, license or otherwise dispose of or deal in this Agreement or any of its contractual rights or obligations under it.

11.6 Notices. Any notice given under this Agreement must be in writing and delivered by email (with confirmation of receipt) or by pre-paid first-class post to the address of the recipient set out in the Quotation & Schedule or otherwise notified in writing. A notice is deemed received: if sent by email, at the time of transmission (or, if sent outside Business Hours, at the start of the next Business Day); if sent by post, at 9.00am on the second Business Day after posting.

11.7 Entire agreement. This Agreement (including the Quotation & Schedule and Schedule 1) constitutes the entire agreement between the parties in relation to its subject matter and supersedes all prior agreements, representations and understandings. Nothing in this Clause limits liability for fraud or fraudulent misrepresentation.

11.8 Governing law and jurisdiction. This Agreement, and any dispute or claim arising out of or in connection with it (including non-contractual disputes or claims), are governed by and construed in accordance with the law of England and Wales. The parties irrevocably submit to the exclusive jurisdiction of the courts of England and Wales.

 

DATA PROCESSING AGREEMENT (SCHEDULE 1)

DATA PROTECTION

In this Schedule, references to the “Controller” are to the Licensee/Controller, and references to the “Processor” are to the Licensor/Processor, as those parties are defined in the Agreement. The terms previously styled “Customer” and “Service Provider” have been harmonised accordingly.

1. Both parties will comply with all applicable requirements of the UK Data Protection Legislation.

2. The parties acknowledge that, for the purposes of the Data Protection Legislation, the Licensee/Controller is the Controller and the Licensor/Processor is the Processor. Paragraph 8 of this Schedule sets out the scope, nature and purpose of processing by the Processor, the duration of the processing and the types of Personal Data and categories of Data Subject.

3. Without prejudice to the generality of paragraph 1, the Licensee/Controller will ensure that it has all necessary rights, lawful bases, consents (where required) and notices in place to enable the lawful transfer of the Personal Data to the Processor, and/or the lawful collection of the Personal Data by the Processor on behalf of the Controller, for the duration and purposes of this agreement.

3.1 Where the processing includes criminal offence data or special category data, the Licensee/Controller confirms that it has in place an Appropriate Policy Document and any other documentation required under the Data Protection Act 2018, and each party shall maintain such records as are required by that Act in respect of such processing.

4. Without prejudice to the generality of paragraph 1, the Processor shall, in relation to any Personal Data processed in connection with the performance by the Processor of its obligations under this agreement:

A. process that Personal Data only on the documented written instructions of the Controller unless the Processor is required by Applicable Laws to otherwise process that Personal Data. Where the Processor is relying on Applicable Laws as the basis for processing Personal Data, the Processor shall promptly notify the Controller of this before performing the processing required by the Applicable Laws, unless those Applicable Laws prohibit the Processor from so notifying the Controller;

B. ensure that it has in place appropriate technical and organisational measures to protect against unauthorised or unlawful processing of Personal Data and against accidental loss or destruction of, or damage to, Personal Data, appropriate to the harm that might result and to the nature of the data to be protected, having regard to the state of technological development and the cost of implementing any measures (those measures may include, where appropriate, pseudonymising and encrypting Personal Data, ensuring the confidentiality, integrity, availability and resilience of its systems and services, ensuring that availability of and access to Personal Data can be restored in a timely manner after an incident, and regularly assessing and evaluating the effectiveness of the measures adopted);

C. ensure that all personnel who have access to and/or process Personal Data are obliged to keep the Personal Data confidential;

D. not transfer any Personal Data outside of the UK unless the prior written consent of the Controller has been obtained and the following conditions are fulfilled: (i) the Controller or the Processor has provided appropriate safeguards in relation to the transfer; (ii) the data subject has enforceable rights and effective legal remedies; (iii) the Processor complies with its obligations under the Data Protection Legislation by providing an adequate level of protection to any Personal Data that is transferred; and (iv) the Processor complies with reasonable instructions notified to it in advance by the Controller with respect to the processing of the Personal Data. Where such a transfer occurs, it shall be effected using the International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, or another transfer mechanism recognised as valid under the UK Data Protection Legislation;

E. assist the Controller, at the Controller’s cost, in responding to any request from a Data Subject and in ensuring compliance with its obligations under the Data Protection Legislation with respect to security, breach notifications, impact assessments and consultations with supervisory authorities or regulators;

F. notify the Controller without undue delay on becoming aware of a Personal Data Breach, and provide the Controller with reasonable information and co-operation to enable the Controller to meet its own obligations to notify the Information Commissioner and affected Data Subjects within the timeframes required by the Data Protection Legislation;

G. at the written direction of the Controller, delete or return Personal Data and copies thereof to the Controller on termination of the agreement unless required by Applicable Laws to store the Personal Data;

H. maintain complete and accurate records and information to demonstrate its compliance with this paragraph 4;

I. immediately inform the Controller if, in the opinion of the Processor, an instruction given by the Controller infringes the Data Protection Legislation; and

J. allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller in relation to the processing of Personal Data under this agreement, subject to reasonable notice and appropriate confidentiality undertakings.

5. The Controller hereby grants its general consent to the Processor appointing third party processors to assist the Processor in processing Personal Data under this agreement. The Processor’s current third party processors are set out in paragraph 8.6. Prior to appointing a new third party processor, the Processor shall notify the Controller in writing of the intended appointment and shall give the Controller a period of not less than 14 days to object to the appointment. If the Controller objects on reasonable data protection grounds and the parties cannot resolve the objection, the Controller may suspend the affected processing or terminate this agreement in respect of the affected services.

6. The Processor confirms that it has entered, or (as the case may be) will enter, into a written agreement with each third-party processor incorporating terms which are substantially similar to those set out in this agreement and which the Processor confirms reflect, and will continue to reflect, the requirements of the Data Protection Legislation. As between the Controller and the Processor, the Processor shall remain fully liable for all acts or omissions of any third-party processor appointed by it pursuant to paragraph 5.

7. Either party may, at any time on not less than 30 days’ notice, revise this agreement by replacing it with any applicable controller-to-processor standard clauses or similar terms forming part of an applicable certification scheme (which shall apply when replaced by attachment to this agreement).

8. Processing, Personal Data and Data Subjects:

8.1 Scope – The processing is limited to that permitted in the agreement between the parties for the provision of services by the Processor.

8.2 Nature and purpose of processing – To assist the Controller in achieving Data Protection Legislation compliance by provision of services, documentation and equipment as defined in the VeriFi Data Compliance Procedures & Policy that may be viewed at https://www.verifi-eidos.co.uk.

8.3 Duration of the processing – The duration will be for the duration of the contract term, which will expire 12 months following the date of submission of the audit report or the commencement of the handover of EIDOS software, unless the contract is extended by the Controller. In either case, any related archive data will be made available on the demand of the client for up to 90 days from the expiry date.

8.4 Types of Personal Data – Surveillance and security-related data that includes the identity or identifiers of individuals. Data processed may include names, job titles, personal appearance and behaviours, visual images and criminal offence data. Where any such data is used for the purpose of uniquely identifying an individual (for example, biometric matching), it constitutes special category data, and the parties shall ensure that an Article 9 UK GDPR condition and, where required, a Data Protection Impact Assessment are in place.

8.5 Categories of Data Subject – The Controller’s staff, customers and clients, offenders and suspected offenders, members of the public, and those inside, entering or in the immediate vicinity of the area under surveillance.

8.6 Third party processors – Amazon Web Services (AWS), a subsidiary of Amazon that provides a cloud computing platform. Personal Data shall be hosted in AWS data centres located in the United Kingdom.

Helpline

Telephone helpline support is available Monday to Friday 08:30 to 17:30 (excluding public holidays) and can be called on free phone number 0800 028 7382. Advice is also available by email at info@verifi-eidos.co.uk outside of these times for matters of an urgent nature.