Privremena verzija. Konačni tekst priprema se s našim pravnim savjetnikom i uskoro će biti objavljen ovdje.
Version 20.08.2026 — These general terms are drawn up in Italian. Versions in other languages are courtesy translations: in case of divergence, the Italian version prevails.
DEFINITIONS
In these general terms of service (the "General Terms"), capitalized terms have the meaning attributed here. Terms in the singular are also understood in the plural and vice versa.
Provider (or "EntryMind"): Flow Motion SA, with registered office at via Pineta 40a, 6979 Brè sopra Lugano, Switzerland, business ID no. CHE-111.990.822, e-mail: info@flow-motion.net.
Client: the person, entrepreneur, professional or entity that subscribes to an Order for the use of the Service in the context of its professional or business activity.
Service (or "Software"): the management software named "EntryMind", usable exclusively in software-as-a-service (SaaS) mode via browser or web app, including the modules activated according to the chosen Plan (by way of example: agenda and appointments, courses, subscriptions and cards, sales and purchase invoicing, warehouse, team and studio management, accounting functions), as described on the Website.
Website: the Provider's website, reachable at https://entry-mind.net, documentation and terms.
Order: the subscription, including online via the checkout procedure, to a Plan and any ancillary services, with indication of the Plan, duration and fees.
Plan: the contractual duration and payment method chosen by the Client among those published on the Website (by way of example: monthly plan without commitment; 12-month plan with advance payment; 12-month plan with monthly payment; any one-off activation fee).
Paddle: Paddle.com Market Ltd (or another company of the Paddle group indicated at checkout), authorized reseller and "merchant of record" of the Provider: the sale, invoicing, application of taxes and management of payments and any refunds take place between the Client and Paddle, according to Paddle's terms and conditions accepted at purchase.
Access Credentials: the authentication system (identifiers, passwords, any codes or tokens) with which the Client and its Users access the Service.
User: each natural person authorized by the Client to use the Service by means of the Access Credentials, within the number of users provided by the Plan; Users must be employees or collaborators of the Client, subject to the provisions for Authorized Third Parties.
Authorized Third Party: the third party (for example the Client's fiduciary, accountant or accounting advisor) to whom the Client, through the relevant features of the Service where available, grants access to certain data and functions of its EntryMind environment.
Client Data: the data, documents, contents and information, including of a personal nature, entered or generated by the Client, the Users and the Authorized Third Parties in the Service.
Updates and Developments: all updates, supplements, adaptations, improvements, new features and changes in general made to the Service, at the Provider's discretion.
Contract: these General Terms, any special conditions (including the Special Conditions "EntryMind + Website" referred to in article 19), Annex A (Data Processing Agreement) and the technical documentation or online instructions that the Provider may make available. In case of conflict, the following prevail, in order: the special conditions, these General Terms.
1. SCOPE AND PROFESSIONAL NATURE OF THE RELATIONSHIP
1.1 These General Terms govern the provision of the Service by the Provider and the use of the Service by the Client, the Users and the Authorized Third Parties. They also apply to all Updates and Developments, unless these are governed by separate supplementary conditions.
1.2 The Client accepts the General Terms by completing the Order procedure (checkout) or, if earlier, upon first access to the Service. The Client is invited to read them carefully before proceeding.
1.3 By accepting the General Terms, the Client declares: (i) to have the rights and powers necessary to conclude and perform the Contract; (ii) to use the Service exclusively in the context of its business, craft, commercial or professional activity. Consumer protection rules therefore do not apply to the relationship, to the extent their exclusion is permitted by applicable law.
1.4 The Definitions form an integral part of these General Terms.
2. SUBJECT OF THE SERVICE
2.1 Against timely payment of the fees provided by the chosen Plan, the Provider grants the Client the non-exclusive right to access and use the Service in SaaS mode, by means of the Access Credentials, for the number of Users and with the modules provided by the Order.
2.2 The Service is provided via the cloud infrastructure of the Provider or of third-party providers selected by the Provider. The Client acknowledges that the Service is usable exclusively online and that it is responsible for obtaining, at its own care and expense, the hardware, basic software, internet connectivity and anything else necessary to access the Service, verifying its suitability against the technical requirements published by the Provider.
2.3 The Provider may make available, at its discretion, features of the Service also via a mobile app or additional interfaces; their use is governed by the Contract. The Client acknowledges that not all features may be available on every channel and that the feature catalogue may vary over time as provided in articles 11 and 17.
2.4 The Client has chosen the product according to its needs and remains solely responsible for that choice and for verifying the suitability of the Service for its purposes.
3. ORDER, FEES, INVOICING VIA PADDLE
3.1 The fees for the Service are those indicated in the price list published on the Website or otherwise shown to the Client at the time of the Order, depending on the chosen Plan (including any one-off activation fees). Unless otherwise indicated, the fees are net of VAT and any other tax or statutory charge, which are calculated and applied at checkout.
3.2 The Client acknowledges and accepts that the sale of the Service takes place via Paddle, which acts as authorized reseller and merchant of record of the Provider. Consequently: (i) payment, invoicing, application of taxes, management of payment renewals and any refunds are governed by Paddle's terms and conditions, accepted by the Client at purchase; (ii) the tax and billing data provided by the Client at checkout must be correct, truthful and complete, also for the purposes of the correct application of VAT or reverse charge (including indication of the VAT number for business clients); (iii) any disputes relating to payments and invoices must be addressed according to Paddle's procedures, with the Provider remaining available to provide reasonable assistance.
3.3 In the event of non-payment or late payment of any sum due (including for default, reversal or chargeback), the Provider may, after notice to the Client, suspend access to the Service until regularization and, in the cases provided by article 18, terminate the Contract. The fees accrued until the end of the current contractual period remain due, including the remaining instalments of the 12-month plans with monthly payment.
3.4 The Provider may change the price lists for subsequent renewal periods, giving notice to the Client with reasonable advance notice before the expiry of the current period; in this case the Client can avoid the application of the new prices by terminating the Contract with effect from expiry, in accordance with article 4. The changes referred to in article 17 remain unaffected.
3.5 The Client waives raising objections without having first fulfilled its payment obligations.
4. DURATION, RENEWAL AND TERMINATION
4.1 The Contract runs from the date of activation of the Service and has the duration provided by the chosen Plan: (i) for the monthly Plan, one month; (ii) for the 12-month Plans (with advance or monthly payment), twelve months.
4.2 At expiry, the Contract is tacitly renewed for successive periods of equal duration, unless termination is communicated by one of the parties before the expiry of the current period, through the subscription management features (including those of Paddle) or in writing to the contacts indicated in the Definitions. Termination takes effect from the expiry of the current period.
4.3 Unless otherwise provided by the Contract or by mandatory rules, early termination of a 12-month Plan does not give the right to a refund of fees already paid nor exempt from payment of the remaining instalments of the current period.
4.4 The Provider may also withdraw from the Contract, in whole or in part, with at least 30 days' notice given in writing (including by e-mail or notice in the Service); in this case the Client is entitled to the return of the portion of fee already paid for the period of non-use.
5. ACCESS CREDENTIALS AND ACCOUNT SECURITY
5.1 The Client and each User access the Service by means of the Access Credentials. The Client is required to keep, and to ensure that each User and Authorized Third Party keeps, the Access Credentials with the utmost confidentiality and diligence, not to transfer them and not to allow their use by unauthorized parties.
5.2 The Client is aware that knowledge of the Access Credentials by third parties would allow them unauthorized use of the Service and access to the Client Data. The choice of weak or easily identifiable passwords, their sharing and their loss fall within the sphere of risk and responsibility of the Client.
5.3 In the event of theft, loss, compromise or unauthorized use of the Access Credentials, the Client must promptly notify the Provider, which will suspend or reset the affected credentials.
5.4 To the maximum extent permitted by law, the Client is solely responsible for any use, authorized or not, of the Service made by means of its own Access Credentials, those of its Users and of the Authorized Third Parties.
6. CLIENT OBLIGATIONS AND PROHIBITED USES
6.1 The Client undertakes to: (a) pay the fees on time; (b) use the Service in accordance with the Contract, the law and the intended use; (c) guarantee the correctness, truthfulness and completeness of the information provided at registration, Order and use, promptly communicating any changes; (d) ensure compliance with the provisions of the Contract by each User and Authorized Third Party, for whose conduct it is solely responsible; (e) reasonably cooperate with the Provider for the performance of the Contract and for support activities.
6.2 It is prohibited to use the Service to enter, store, send, publish, transmit or share data, applications or documents that: (i) infringe the intellectual property rights of the Provider or third parties; (ii) have discriminatory, defamatory, slanderous or threatening content; (iii) contain pornographic, child-pornographic, obscene material or material contrary to public order or morality; (iv) contain viruses, worms, trojans or other harmful IT elements; (v) constitute spamming, phishing or similar activities; (vi) are otherwise contrary to applicable statutory or regulatory provisions.
6.3 Also prohibited are: unauthorized access or attempted access to systems or data; the circumvention of technical limitations or protection measures, including the authentication system; any massive, automated or anomalous use (scraping, stress tests, calls exceeding normal usage volumes) capable of impairing the security, stability or performance of the Service.
6.4 The Client remains solely responsible for the compliance of its use of the Service with the regulations applicable to it, including tax, accounting, employment and personal data protection law, as well as for the correctness of the data entered and the processing carried out through the Service, which it is required to verify. The Service is a management tool and does not constitute tax, accounting or legal advice.
7. USERS
7.1 The Client may enable to the Service the number of Users provided by the Plan. Users must be contracted employees or collaborators of the Client. It is prohibited to grant the use of the Service to persons outside its own organization, whether free of charge or for a fee, subject to the provisions of article 8 for Authorized Third Parties.
7.2 The Client may at any time extend the Plan to additional modules, features or Users, at the list prices in force; the extensions follow the expiry of the main Plan, unless otherwise indicated in the Order.
8. AUTHORIZED THIRD PARTIES (FIDUCIARY / ACCOUNTING ADVISOR)
8.1 Where the Service provides for it, the Client may allow an Authorized Third Party (for example its fiduciary or accountant) to access its EntryMind environment, limited to the functions and data made accessible by the relevant feature (by way of example, the accounting functions necessary for entries and closings).
8.2 The Client acknowledges and declares to be solely responsible for the authorization granted to the Authorized Third Parties and for the conduct of the latter, which is deemed carried out on behalf of the Client. The Client guarantees that the Authorized Third Party's access to the Client Data, including any personal data of third parties, takes place in compliance with applicable data protection regulations and on the basis of suitable legal grounds, holding the Provider harmless from any claim in this regard.
8.3 The Provider, within the mandatory limits of the law, is not liable for damages or losses arising from the use or non-use of the Service by the Authorized Third Parties in a manner not compliant with the Contract, the law or the Client's instructions.
9. CLIENT DATA, BACKUP, EXPORT AND DELETION
9.1 The Client Data is and remains the property of the Client. The Provider acquires no rights over the Client Data, except as strictly necessary for the provision of the Service, support and compliance with legal obligations.
9.2 The Provider adopts reasonable technical and organizational measures, including periodic backup procedures of the infrastructure, for the protection and availability of the Client Data. It remains the responsibility of the Client to periodically export, through the features of the Service where available, a copy of the data it deems useful to keep.
9.3 Following the termination of the Contract, for any cause, the Client may extract a copy of its data through the features of the Service, or request its delivery in a standard format, for a period of 60 (sixty) days from the termination date. After this term, the Provider will proceed with the definitive deletion of the Client Data, in compliance with legal retention obligations, it being understood that residual copies in system backups will be overwritten according to the normal backup rotation cycles.
9.4 The Provider may process, in aggregated and anonymized form, information derived from the use of the Service, for statistical purposes and to improve the Service itself.
10. PROTECTION OF PERSONAL DATA
10.1 The parties undertake to comply with the applicable regulations on the protection of personal data, including, where applicable, the Swiss Federal Act on Data Protection (nFADP) and Regulation (EU) 2016/679 (GDPR).
10.2 In relation to the personal data of the Client and its contacts processed for the conclusion and performance of the Contract, the Provider acts as controller, according to the privacy policy available on the Website.
10.3 In relation to the personal data of third parties entered by the Client in the Service (for example the data of the studio's clients), the Client acts as controller and the Provider as processor, in accordance with the Data Processing Agreement referred to in Annex A, which forms an integral part of the Contract.
10.4 The Client acknowledges that the tax and payment data collected at checkout are processed by Paddle as an autonomous controller, according to Paddle's privacy policy.
11. UPDATES AND DEVELOPMENTS
11.1 The Provider may, at its discretion, release Updates and Developments aimed, by way of example, at improving the performance of the Service, introducing new features, correcting malfunctions or adapting the Service to statutory or regulatory changes.
11.2 The Client acknowledges and accepts that the Updates and Developments may result in the modification or elimination of some features of the Service, or consist of replacements or migrations, even partial, of the Service, subject to articles 13 and 17.
11.3 Except for wilful misconduct or gross negligence, the Provider is not liable for damages arising from Updates and Developments.
12. AVAILABILITY OF THE SERVICE, MAINTENANCE AND SUSPENSION
12.1 The Provider will make every reasonable effort to ensure maximum availability of the Service, without however guaranteeing that the Service is uninterrupted or error-free. The Provider may temporarily suspend or interrupt the Service for ordinary or extraordinary maintenance, undertaking to restore its availability as soon as possible and, where possible, to schedule interventions during periods of lower use.
12.2 The Provider further reserves the right to suspend or limit the Service, in whole or in part: (i) in the cases provided by articles 3.3 and 18; (ii) for security or confidentiality reasons; (iii) in the event of a breach, by the Client, a User or an Authorized Third Party, of legal obligations or the Contract, including article 6; (iv) if the data provided by the Client is incorrect, untruthful or incomplete; (v) in the event of infrastructure problems not remediable without suspending access, subject to prior notice to the Client where possible; (vi) for reasons of force majeure or otherwise not attributable to the Provider. Where possible, the Provider will communicate to the Client the reasons and timing of the suspension.
12.3 Force majeure events are those outside the reasonable control of the Provider, such as, by way of example, unavailability or default of providers of hosting, connectivity or payment services, measures of authorities, natural disasters, fires, epidemics, acts of war, national strikes, large-scale cyberattacks.
13. WITHDRAWAL FROM THE MARKET AND REPLACEMENT
13.1 The Client acknowledges that the Service and the environments in which it operates are subject to constant technological evolution, which may determine its obsolescence and, in some cases, the opportunity of a withdrawal from the market, possibly with replacement by new solutions. In this case: (a) the Provider will communicate in writing to the Client (including by e-mail or notice in the Service), with at least 6 (six) months' notice, the intention to withdraw from the market the Service or one or more modules (the "Obsolete Product"); (b) the communication will contain the description of the possible new replacement product (the "New Product"), which may be based on different technologies; (c) if the Obsolete Product is not replaced, the Contract will cease with reference to it on the date indicated in the communication (in any case not before the expiry of the notice) and the Client will be entitled to the return of the portion of fees possibly already paid for the period of non-use; (d) if the Obsolete Product is replaced by a New Product, the Client may withdraw from the Contract, with reference only to the Obsolete Product, within 15 days of the communication, with effect from the withdrawal date; failing this, the Contract will continue with reference to the New Product.
14. INTELLECTUAL PROPERTY
14.1 All intellectual and industrial property rights on the Service, on the related software, on the infrastructure, on the documentation, on the Updates and Developments, on the APIs and technical connections, as well as on the associated trademarks, logos, names and domain names (including "EntryMind"), are and remain the exclusive property of the Provider or its predecessors in title. The Client is granted exclusively the right of use referred to in article 2, non-exclusive, non-transferable, non-sublicensable and limited to the duration of the Contract.
14.2 Subject to the mandatory limits of the law, the Client may not: (i) copy, reproduce, modify, adapt or translate the Service or create derivative works of it; (ii) decode, decompile or disassemble the Service (reverse engineering); (iii) circumvent technical limitations or protection measures; (iv) transfer, sublicense, rent, distribute or otherwise make the Service available to third parties; (v) use trademarks, logos or distinctive signs of the Provider without prior written authorization; (vi) remove or alter copyright notices or other reservation of rights notices.
14.3 Any suggestions, reports, ideas or other feedback transmitted by the Client in relation to the Service may be freely used by the Provider, without restrictions or obligations of consideration or recognition, to improve and develop its own products and services.
14.4 The Client acknowledges that the Service may contain or require open source software components, subject to their respective licenses, which the Client undertakes to respect; where necessary, these conditions will be made knowable by the Provider.
15. SUPPORT
15.1 The Provider makes available to the Client a technical support service, provided exclusively remotely. Any direct intervention on the Client's IT systems is excluded.
15.2 In the event of a support request, the Client will provide the information necessary to identify the cause of the report. The Client acknowledges and consents that technical information, configuration and diagnostic data relating to its environment may be acquired by the Provider for the purposes of support and improvement of the Service; failing this, the Provider's ability to provide support may be limited.
16. WARRANTIES AND LIMITATIONS OF LIABILITY
16.1 The Service, including Updates and Developments and the documentation, is provided "as is" and "as available". To the extent permitted by law, the Provider makes no representations or warranties, express or implied, as to the suitability of the Service to meet specific needs of the Client, the absence of errors or the presence of features not provided in the documentation.
16.2 The Provider is not liable for damages arising from: (i) use of the Service not compliant with the Contract or the law; (ii) unsuitability or malfunction of the Client's hardware, software, connectivity or systems; (iii) errors, omissions or incompleteness of the data entered by the Client, the Users or the Authorized Third Parties, or processing based on such data, which the Client is required to verify; (iv) unavailability or malfunctions of third-party platforms and services (including hosting and connectivity), subject to what is mandatorily provided by law; (v) force majeure.
16.3 Subject to the mandatory limits of the law, the Provider is not liable for damages, costs, losses or expenses suffered by the Client or third parties as a result of cyberattacks, hacking activities or abusive access by third parties to the systems of the Client or the Provider, from which arise, by way of example, non-use of the Service, loss of data or damage to systems, without prejudice to the Provider's commitment to adopt the security measures referred to in Annex A.
16.4 Except in the case of wilful misconduct or gross negligence, the overall liability of the Provider arising from or connected to the Contract may not in any case exceed the amount of the fees paid by the Client for the Service in the 12 (twelve) months preceding the harmful event. To the extent permitted by law, the Provider's liability for indirect or consequential damages, loss of profit, lost earnings, loss of business opportunities, loss or corruption of data, business interruption, payment of penalties or the Client's liability towards third parties is excluded.
17. AMENDMENTS TO THE CONTRACT
17.1 In consideration of the constant technological, regulatory and market evolution of the sector, the Client accepts that the Provider may amend the Contract (including these General Terms and, within the limits of article 3.4, the fees), giving written notice to the Client (including by e-mail or through a notice in the Service).
17.2 If the amendment is unfavourable to the Client, the latter may withdraw from the Contract by written communication to the Provider within 30 (thirty) days of receipt of the communication, with effect from the date of effectiveness of the amendment; in this case it will be entitled to the return of the portion of fees already paid for the period of non-use. In the absence of withdrawal within the terms, the amendments are deemed known and accepted and become effective and binding.
18. TERMINATION AND EFFECTS OF CESSATION
18.1 Without prejudice to any other legal remedy and compensation for damages, the Provider may terminate the Contract with immediate effect, by simple written communication, in the event of: (i) breach by the Client, a User or an Authorized Third Party even of only one of the obligations of articles 5 (Credentials), 6 (Obligations and prohibited uses), 7 (Users), 8 (Authorized Third Parties), 14 (Intellectual Property) and 20.3 (Prohibition of assignment); (ii) use of the Service for fraudulent or unlawful activities, according to the reasonable and motivated assessment of the Provider; (iii) non-payment, even partial, of the fees, not remedied within 15 days of the reminder; (iv) obligation arising from legal provisions or measures of competent authorities.
18.2 Upon termination of the Contract, for any cause: (i) the Provider will cease the provision of the Service and deactivate the Access Credentials; (ii) the Client must cease all use of the Service; (iii) all rights and licenses granted to the Client will cease; (iv) article 9.3 will apply for the export and deletion of the Client Data; (v) the rights already accrued by the parties will remain unaffected.
18.3 The provisions which by their nature are intended to remain in force survive the termination of the Contract, including those regarding accrued fees, intellectual property, confidentiality, liability, Client data, applicable law and jurisdiction.
19. CONFIDENTIALITY
19.1 Each party undertakes not to disclose and not to use, except for the performance of the Contract, the confidential information of the other party learned on the occasion of the relationship, save for express written authorization or legal or authority obligations. The obligation remains for 3 (three) years from the termination of the Contract, unless the information has become public domain through no fault of the receiving party or constitutes a trade secret protected by law for a longer period.
20. FINAL PROVISIONS, APPLICABLE LAW AND JURISDICTION
20.1 The Contract constitutes the entire agreement between the parties in relation to its subject and supersedes any prior understanding, written or oral.
20.2 The Provider may make use, at its discretion, of the technical, organizational and commercial cooperation of partners and subcontractors, to whom it may entrust in whole or in part the activities provided by the Contract, remaining responsible towards the Client within the limits of the Contract.
20.3 The Client may not assign the Contract, in whole or in part, without the prior written consent of the Provider. The Provider may assign the Contract or the receivables arising from it to companies of its group or in the context of corporate transactions, giving notice to the Client.
20.4 Communications to the Client relating to the Contract may be made to the e-mail address communicated by the Client in the Order; it is the Client's responsibility to keep it active and up to date.
20.5 The failure or delay in exercising a right does not constitute a waiver of it. The possible invalidity or ineffectiveness of a clause does not prejudice the validity of the other clauses, legally and functionally independent.
20.6 The Contract is governed by Swiss law, excluding conflict-of-law rules and the Vienna Convention on the International Sale of Goods. For any dispute arising from or connected to the Contract, the court of Lugano, Switzerland, has exclusive jurisdiction, subject to any applicable mandatory rules protecting the Client.
SPECIAL CONDITIONS "ENTRYMIND + WEBSITE"
These special conditions supplement the General Terms of Service EntryMind and apply only to Clients who subscribe to the "EntryMind + Website" plan. For anything not otherwise provided, the General Terms apply; capitalized terms have the meaning attributed therein.
S.1 Subject. In addition to the Service, the Provider creates and hosts for the Client a showcase website based on predefined templates of the Provider, personalized with the data and contents of the Client's studio (including pre-filled from the data present in EntryMind), and provides, if expressly requested by the Client, for the registration of a domain name chosen by the Client, where available.
S.2 Domain. The domain is registered in the name of the Client (or, where technically necessary, in the name of the Provider on behalf of the Client) and its registration is subject to the conditions of the competent registry. Renewal of the domain is included as long as the "EntryMind + Website" plan is active. Upon termination of the plan, the Client may request the transfer of the domain to another provider, at its own care and expense, within 60 days; failing this, the Provider may let its registration expire.
S.3 Contents. The Client is solely responsible for the texts, images and other contents provided or approved for the site, guaranteeing their lawfulness and ownership of the relevant rights, and holds the Provider harmless from any third-party claim in this regard. The prohibitions referred to in article 6 of the General Terms apply to the site.
S.4 Property. The templates, themes, code and graphic elements of the site other than the contents provided by the Client remain the property of the Provider. Upon termination of the plan, the Client acquires no rights over the Provider's templates; it may request the export of its contents under the terms of article 9.3 of the General Terms.
S.5 Service levels. Articles 11, 12 and 16 of the General Terms (updates, availability, limitations of liability) apply to the site, insofar as compatible.
ANNEX A — DATA PROCESSING AGREEMENT (DPA)
This agreement (the "DPA") governs, pursuant to art. 28 GDPR and art. 9 nFADP, the processing of personal data carried out by the Provider on behalf of the Client within the scope of the Contract. It forms an integral part of the Contract and prevails, for its subject, over the other contractual provisions.
A.1 Roles and subject of the processing
A.1.1 In relation to the personal data of third parties entered in the Service by the Client, the Users or the Authorized Third Parties (the "Personal Data"), the Client acts as controller and the Provider as processor. Should the Client in turn act as processor on behalf of a third-party controller, it guarantees that recourse to the Provider as sub-processor has been authorized by the controller.
A.1.2 Subject and duration: processing necessary for the provision of the Service, for the duration of the Contract and for the subsequent period referred to in article 9.3 of the General Terms. Nature and purposes: hosting, storage, organization, consultation, processing, backup, technical support and deletion. Categories of data subjects: clients, potential clients, suppliers, employees and collaborators of the Client. Categories of data: identity and contact data, accounting and billing data, data relating to appointments, courses, subscriptions and cards, and any other data entered by the Client in the Service. The processing of special categories of data (art. 9 GDPR) is not provided, unless otherwise agreed in writing.
A.2 Provider obligations
The Provider undertakes to: (a) process the Personal Data only on documented instruction of the Client, as resulting from the Contract and the use of the features of the Service, save for legal obligations, in which case it will inform the Client where not prohibited; (b) ensure that the persons authorized to process are bound to confidentiality and adequately trained; (c) adopt adequate technical and organizational measures pursuant to art. 32 GDPR and art. 8 nFADP, including: control of logical accesses according to the principle of least privilege, user authentication, encryption of communications (TLS), periodic backups and restoration procedures, tracing of administrative accesses, incident and breach management procedures; (d) reasonably assist the Client in fulfilling the obligations towards data subjects (response to requests to exercise rights) and the obligations referred to in art. 32-36 GDPR, taking into account the nature of the processing and the information available; (e) notify the Client without undue delay of the Personal Data breaches of which it becomes aware, providing the reasonably available information; (f) at the end of the processing, delete or return the Personal Data in accordance with article 9.3 of the General Terms, save for legal retention obligations; (g) make available to the Client the information reasonably necessary to demonstrate compliance with this DPA and allow, with adequate notice, reasonable verification activities, including through the provision of certifications or reports, with the costs of the verifications borne by the Client.
A.3 Sub-processors
A.3.1 The Client generally authorizes recourse to sub-processors for the provision of the Service. As of the date of this DPA, the sub-processors are: Infomaniak Network SA (hosting and infrastructure, Switzerland). Paddle operates as an autonomous controller for the processing connected to checkout and invoicing.
A.3.2 The Provider will inform the Client, with at least 15 days' notice (including by e-mail or notice in the Service), of the addition or replacement of sub-processors. The Client may object for legitimate reasons within that term; in case of objection, where the Provider cannot reasonably avoid recourse to the sub-processor, each party may withdraw from the Contract with effect from the start date of the new processing, with return to the Client of the portion of fees for the period of non-use. The Provider imposes on the sub-processors data protection obligations substantially equivalent to those of this DPA and is responsible for their conduct.
A.4 Transfers
A.4.1 The Personal Data is stored on servers located in Switzerland or the European Economic Area. Any transfers to third countries will take place only in the presence of an adequacy decision or adequate safeguards pursuant to art. 45-46 GDPR and art. 16-17 nFADP (for example standard contractual clauses), which the Client hereby authorizes the Provider to sign on its behalf where necessary.
A.5 Liability and duration
A.5.1 Each party is responsible for the fulfilment of its own obligations under this DPA and the applicable regulations. The liability limits referred to in article 16 of the General Terms apply to the DPA, to the extent permitted by law. The DPA takes effect from the date of the Contract and ceases automatically upon deletion of all the Personal Data.