1. IDENTIFICATION OF THE PROVIDER AND PURPOSE
1.1 Identification of the Provider. In compliance with the provisions of Article 10 of Ley 34/2002, of 11 July, on Information Society Services and Electronic Commerce (hereinafter, “LSSI-CE”), the following identifying information of the service provider is hereby made available to the User:
- Company name: Additiu Marketing Digital SL
- Tax ID (NIF): B55314066
- Registered office: C/ Sant Maurici 24, 17740 Vilafant (Girona), Spain
- Contact email: info@abency.com
1.2 Purpose. These Terms and Conditions of Use (hereinafter, the “T&C” or the “Terms”) are intended to govern the access, registration and use of the SaaS platform known as “Abency” (hereinafter, the “Platform”), owned by the Provider, through which the connection to and management of Third-Party AI Models and integrations with digital marketing services are facilitated by means of natural language. These Terms constitute a legally binding contract between the Provider and the User.
1.3 Applicable regulatory framework. The Platform operates in accordance with applicable Spanish and European legislation, with particular regard to: (i) the LSSI-CE (Ley 34/2002); (ii) Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data (hereinafter, “GDPR”); and (iii) Ley Orgánica 3/2018, of 5 December, on the Protection of Personal Data and the Guarantee of Digital Rights (hereinafter, “LOPDGDD”);
2. DEFINITIONS
2.1 For the purposes of these Terms, the terms set forth below shall have the meanings ascribed to them in this clause, whether used in the singular or in the plural:
- “Platform”: the software-as-a-service (SaaS) offering known as “Abency,” accessible at https://app.abency.com/, through which the Provider facilitates the Users’ connection with Third-Party AI Models and Third-Party Integrations for the management of digital marketing operations.
- “Provider”: Additiu Marketing Digital SL, the company that owns and operates the Platform, whose identifying information is set forth in Clause 1.
- “User”: any natural or legal person who accesses, registers with or uses the Platform, whether acting in an individual capacity or on behalf of an organisation. Where the context so requires, the term “User” shall encompass both the legal representative of the organisation and the authorised end users under the same Account.
- “Client”: the User who subscribes to a paid or trial Subscription Plan and assumes the contractual and payment obligations arising from these Terms. The Client may be a natural person acting in the course of their professional or business activity, or a legal person.
- “Account”: the personal and non-transferable access profile created by the User on the Platform, protected by authentication credentials, which enables the use of the contracted functionalities.
- “Client Content”: all data, text, images, files, instructions (prompts), configurations and any other material that the Client or its authorised users enter, upload or transmit through the Platform.
- “Third-Party AI Models”: the large language models (LLMs) provided by independent suppliers that enable the connection of the Client’s accounts with such models to the Platform.
- “Third-Party Integrations / Services”: the connections with third-party platforms, APIs and services (such as social media management tools, advertising platforms, CRMs or others) that the Provider makes available to the Client through the Platform.
- “Subscription”: access to the Platform under a given Plan, by means of payment of the applicable fee on a periodic basis (monthly or annually), or under a free or trial Plan, in accordance with the conditions published at https://abency.com/precios.
- “Plan”: the subscription tier selected by the Client, which includes certain functionalities at the time of contracting.
- “Client API”: the API key or access token for a Third-Party AI Model or other external service that the Client configures on the Platform to enable the corresponding integrations. The Client API is exclusively owned by and under the sole responsibility of the Client.
- “Personal Data”: any information relating to an identified or identifiable natural person, as defined in Article 4(1) of the GDPR. The processing of Personal Data within the framework of the Platform shall be governed by the Data Processing Agreement (“DPA”) of these Terms and by the Provider’s Privacy Policy.
- “DPA” (Data Processing Agreement): the agreement governing the processing of Personal Data by the Provider in its capacity as data processor, in accordance with the provisions of Article 28 of the GDPR.
3. ACCEPTANCE OF THE TERMS AND LEGAL CAPACITY
3.1 Acceptance. Access to, registration with or use of the Platform in any manner whatsoever implies the full reading, understanding and unconditional acceptance of these Terms and of the DPA, as well as of any other policy or specific condition that may be published on the Platform. Any User who does not agree with the Terms shall refrain from accessing or using the Platform.
3.2 Modes of acceptance. Acceptance shall occur expressly by means of any of the following acts: (a) ticking the checkbox “I have read and accept the Terms and Conditions” during the registration process; (b) completion of the Account activation process; (c) subscribing to a paid Subscription; or (d) effective use of the Platform once the Terms have been made available to the User, provided such use takes place after the publication of the Terms or any updates thereto.
3.3 Legal capacity. In order to access and use the Platform, the User hereby represents and warrants that: (a) the User is over eighteen (18) years of age and possesses full legal capacity to act under Spanish law; (b) if acting on behalf of a legal person, the User holds sufficient authority to bind such entity contractually, and acceptance of these Terms shall bind such entity in all respects; (c) the User is not subject to any circumstance that would prevent the User from entering into valid contracts under applicable law.
3.4 Duty to read. The Provider makes these Terms permanently available to the User at Condiciones del Servicio | Abency, in an easily accessible, reproducible and archivable format, in accordance with the requirements of Article 27 of the LSSI-CE. The User shall be obliged to read the Terms before proceeding with acceptance thereof. Ignorance of their content shall not exempt the User from the obligations arising therefrom.
4. DESCRIPTION OF THE SAAS SERVICE
4.1 Nature of the service. Abency is a software-as-a-service (SaaS) platform hosted on cloud infrastructure that enables marketing agencies and industry professionals to manage their digital operations and strategies. The Provider grants the Client remote access to the Platform via the internet, without transferring any software component to the Client or granting the Client any intellectual property rights other than the licence of use provided herein.
4.2 Functionalities. The Platform offers a range of functionalities depending on the Plan subscribed.
4.3 Position of the Provider: intermediary and facilitator. The Provider acts exclusively as a technological intermediary and facilitator of access to the Third-Party AI Models and to the Third-Party Integrations that the Client has contracted. The Provider does not develop, train, operate or control the third-party artificial intelligence models. Outputs are generated entirely by the Third-Party AI Models, and the Provider assumes no liability whatsoever for their content, accuracy, legality or fitness for purpose.
4.4 Connection with AI Models: The Platform enables connection with the Client’s AI Model accounts, without the Provider making any underlying AI Model available.
4.5 Evolution of the service. The Provider reserves the right to modify, expand, reduce or temporarily suspend any functionality of the Platform.
5. REGISTRATION, ACCOUNT AND CREDENTIAL SECURITY
5.1 Registration process. In order to access the functionalities of the Platform, the User shall complete the registration process provided, supplying truthful, accurate, up-to- date and complete information. The User undertakes to keep the Account information up to date and to notify the Provider of any material changes. The Provider may reject or cancel the registration where the information supplied is false or incomplete, or where circumstances so warrant.
5.2 Account uniqueness. Each User or entity may maintain only one active Account on the Platform, unless the subscribed Plan expressly permits the creation of multiple users under a single organisation. The creation of false, duplicate or fraudulent accounts is strictly prohibited and may result in the immediate cancellation of all accounts involved.
5.3 Safekeeping of credentials. The User shall be solely responsible for maintaining the confidentiality of their access credentials (username, password and, where applicable, additional authentication factors). The User undertakes to: (a) not disclose their credentials to unauthorised third parties; (b) use secure passwords in accordance with the recommendations published on the Platform; (c) enable two-factor authentication (2FA) whenever available; (d) not access the Platform from untrusted devices or networks without taking due security precautions.
5.4 Liability for Account activity. The User assumes full liability for all actions, transactions and uses carried out through their Account, regardless of whether they were performed by the User or by a third party who accessed the Account using the User’s credentials, whether with or without the User’s authorisation. The Provider shall be held harmless from any liability arising from unauthorised access to an Account resulting from the User’s lack of diligence in safeguarding their credentials.
5.5 Notification of unauthorised access. The User shall immediately notify the Provider, via info@abency.com or through the channel made available on the Platform, of any unauthorised access to their Account, loss or theft of credentials, or any other security incident that affects or may affect their Account. The Provider shall, in turn, adopt reasonable technical and organisational measures to mitigate the consequences of the reported incident, but shall not be liable for any damages arising from unauthorised access occurring prior to receipt of the notification.
5.6 Cancellation of the Account. The Provider may suspend or cancel the User’s Account on a temporary or permanent basis in the circumstances provided for in these Terms, without prejudice to any legal actions to which it may be entitled. The User may request the cancellation of their Account at any time through the channels indicated on the Platform, prior to the renewal of the Subscription, without prejudice to any outstanding payment obligations or commitments already assumed.
6. PLANS, PRICING, BILLING, RENEWAL AND TRIAL PERIOD
6.1 Subscription Plans. The Provider offers various Plans for access to the Platform, the details, included functionalities, usage limits and pricing of which are published on an up-to-date basis on the Provider’s website. The Client may select the Plan that best suits their needs and change Plans at any time in accordance with the applicable conditions. The Provider reserves the right to create, modify or discontinue Plans, in all cases respecting the acquired rights of Clients who have already subscribed to a Plan in force.
6.2 Prices and taxes. The prices published on the Platform are expressed in euros (€) and, unless expressly stated otherwise, are exclusive of Value Added Tax (VAT) and any other applicable tax, levy or charge, which shall be passed on to the Client in accordance with the tax legislation in force.
6.3 Recurring billing. The Subscription shall be billed on a recurring basis with monthly or annual periodicity, as selected by the Client at the time of contracting. Payment shall be collected in advance at the beginning of each billing period by means of the payment method designated by the Client (credit/debit card or other methods enabled on the Platform). Should the charge fail for reasons attributable to the Client, the Provider may suspend access to the Platform until the payment situation is regularised, upon prior notice to the Client.
6.4 Automatic renewal. Unless the Client cancels the Subscription prior to the renewal date, the Subscription shall automatically renew at the end of each billing period for an additional period of equal duration and at the same price, unless the Provider has cancelled prior to renewal. The Client may manage automatic renewal and cancel the Subscription from the Account management section of the Platform.
6.5 Price modifications. The Provider may modify the prices of the Subscription Plans at any time, provided that the Client is notified at least 30 calendar days in advance by email to the address associated with the Client’s Account and/or by means of a notice on the Platform. If the Client does not accept the new prices, the Client may terminate the contract without penalty before the effective date of the modification by notifying the Provider through the channels made available. Continued use of the Platform after the new price takes effect shall be deemed acceptance thereof.
6.6 Plan Changes: During the subscription period, you may change your plan; if you upgrade to a higher-tier plan, you will be billed on a pro-rated basis for the time remaining until renewal, and if you downgrade to a lower-tier plan, the change will take effect at the time of renewal.
6.7 Refund Policy: Paid fees are non-refundable.
7. ACCEPTABLE USE AND PROHIBITIONS
7.1 Use in accordance with the Terms and the law. The User undertakes to use the Platform in compliance with these Terms, with applicable Spanish and European legislation, with accepted standards of conduct and with public order, refraining from any use that may cause harm or damage to third parties, the Provider or the Platform itself. The User shall be solely responsible for the Client Content entered into the Platform and for the use made of the Outputs generated.
7.2 Prohibited uses. The following shall be expressly prohibited, without limitation:
(a) Using the Platform to create, distribute, transmit or store content that is illegal, defamatory, obscene, threatening, discriminatory on grounds of racial or ethnic origin, sex, religion, sexual orientation, disability or any other personal or social circumstance, or that in any other manner infringes fundamental rights or public freedoms.
(b) Reverse-engineering, decompiling, disassembling or attempting to extract the source code of the Platform or any component thereof, except where such activity is expressly permitted by applicable law.
(c) Scraping, crawling, mass indexing or any other automated data extraction technique on the Platform without the prior express written authorisation of the Provider.
(d) Interfering with, disrupting, overloading or damaging the Platform or the servers and infrastructure on which it relies, including the transmission of viruses, malware, ransomware, spyware, harmful code, denial-of-service attacks (DoS/DDoS) or any other cybersecurity threat.
(e) Impersonating the Provider, other Users, Third-Party AI Model providers or any other person or entity, or falsifying or concealing the true identity of the User.
(f) Using the Platform to infringe third-party intellectual or industrial property rights, including trademarks, patents, copyrights or trade secrets.
(g) Using the Platform to engage in practices contrary to unfair competition legislation, misleading advertising rules or data protection regulations, including the sending of unsolicited commercial communications (spam).
(h) Assigning, sublicensing, reselling, leasing or otherwise transferring to third parties access to the Platform or the rights arising from the Subscription, without the prior express written authorisation of the Provider.
7.3 Consequences of breach. Breach of the acceptable use obligations may result, at the Provider’s discretion and depending on the severity of the infringement, in: (a) temporary or permanent suspension of access to the Platform; (b) cancellation of the Account and the Subscription, with no right to a refund; (c) the pursuit of any applicable legal actions, including claims for damages; and (d) notification to the competent authorities where the conduct may constitute a criminal or administrative offence.
8. THIRD-PARTY AI MODELS AND INTEGRATIONS
8.1 Intermediary nature. The Platform enables the Client to connect with its licences for Third-Party AI Models and with Third-Party Integrations. The Provider is not a supplier, developer or operator of such models or services.
8.2 Through a connector, the Client may, within its AI Model accounts, connect to the Platform.
8.3 Third-Party Integrations. The Provider facilitates integrations with third-party services and platforms. The use of such Integrations shall be subject to the terms and conditions of the respective providers. The Provider shall not be liable for the availability, accuracy, security or operation of Third-Party Services, nor for any damages that may arise from their use. The Client shall ensure that it holds the necessary permissions and licences to integrate its data and that of its own clients with such services.
9. INTELLECTUAL PROPERTY
9.1 Ownership of the Platform. The Platform and all its constituent elements, including, without limitation, its graphic design, architecture, source code, object code, user interfaces, databases, logos, trademarks, trade names, technical documentation and any other content or development owned by the Provider, are protected by the applicable intellectual and industrial property regulations, in particular by Real Decreto Legislativo 1/1996, de 12 de abril, approving the consolidated text of the Ley de Propiedad Intelectual, and by Ley 17/2001, de 7 de diciembre, de Marcas. The Provider owns, or holds a licence over, all intellectual and industrial property rights in the Platform.
9.2 Licence to Use the Platform. The Provider grants the Client a non-exclusive, non- transferable, non-sublicensable, revocable licence, limited to a worldwide territorial scope, to access and use the Platform solely in accordance with these Terms and for the duration of the Client’s Subscription. This licence does not comprise any right over the source code, technical architecture, databases or software components of the Platform, beyond the functional access necessary for the use of the service. Any use of the Platform outside the limits of this licence shall require the prior express written authorisation of the Provider.
9.3 Ownership of Client Content. The Client shall retain at all times full ownership of all intellectual property rights over the Client Content uploaded to the Platform. The Provider shall not acquire any ownership rights over such Content.
9.4 Client Licence to the Provider. The Client grants the Provider a non-exclusive, royalty- free licence, sublicensable to the extent necessary for the provision of the service, to reproduce, host, process and transmit the Client Content to the extent strictly necessary to deliver the contracted services, including to improve the Platform and develop new functionalities, in which case the Client Content shall be anonymised or aggregated to the extent possible.
9.5 Prohibition of Reproduction and Distribution of the Platform. The User is expressly prohibited from: (a) reproducing, distributing, publicly communicating or transforming the Platform or any of its elements without the prior express written authorisation of the Provider; (b) removing, altering or concealing any intellectual or industrial property notices of the Provider or third parties appearing on the Platform; and (c) using the trademarks, logos or other distinctive signs of the Provider without its prior written consent.
9.6 The Client authorises the Provider to use its brand solely for the purpose of publicising that the Client has contracted the services.
10. CLIENT/USER OBLIGATIONS AND RESPONSIBILITIES
10.1 Legal Use in Accordance with the Terms. The Client shall use the Platform in accordance with applicable law, these Terms and the instructions and guidelines provided by the Provider. In particular, the Client warrants that the Client Content and the use it makes of the Outputs shall not infringe any legal provision or third-party rights.
10.2 Processing of Personal Data and Legal Bases. The Client acknowledges that it is the data controller of the Personal Data it uploads to the Platform or that is processed as a consequence of its use, in accordance with the GDPR and the LOPDGDD. Accordingly, the Client shall: (a) not upload to the Platform special categories of personal data (sensitive data pursuant to Article 9 of the GDPR) without having an enhanced and adequate legal basis pursuant to Article 9(2) of the GDPR; (b) not upload personal data of third parties (including data of its own clients) without having the legitimate legal basis authorising such processing, as well as the contractual instruments required by law, including execution of the DPA with the Provider; (c) obtain all necessary consents, notices and authorisations from the data subjects whose data is processed through the Platform.
10.3 Responsibility for Content and Use. The Client shall assume full and exclusive responsibility for: (a) the legality, accuracy and suitability of the Client Content; (b) its use of the Platform; (c) the marketing campaigns or other actions it carries out using the Platform; (d) compliance with data protection, advertising, unfair competition and any other sector-specific regulations applicable to its activity.
10.4 Specific Regulatory Compliance. To the extent that the Client uses the Platform in the context of digital marketing, advertising or commercial communication activities, the Client shall be solely responsible for ensuring compliance with the regulations specifically applicable to such activities, including Ley 3/1991, de 10 de enero, de Competencia Desleal, Ley 34/1988, de 11 de noviembre, General de Publicidad, Ley 34/2002 (LSSI-CE) regarding electronic commercial communications, and Regulation (EU) 2016/679 (GDPR) with respect to direct marketing.
11. CONFIDENTIALITY
11.1 Reciprocal Confidentiality Obligation. Each party (hereinafter, the “Receiving Party”) that receives confidential information from the other party (hereinafter, the “Disclosing Party”) in the context of these Terms or the contractual relationship between them shall:
(a) maintain such information in strict confidence and not disclose it to any third party without the prior written consent of the Disclosing Party; (b) use the confidential information solely for the purpose contemplated by these Terms; and (c) adopt the necessary protective measures to safeguard the confidentiality of such information, employing at least the same level of diligence it applies to protect its own confidential information, and in all cases a degree of diligence no less than that which may reasonably be required.
11.2 Definition of Confidential Information. For the purposes of these Terms, “Confidential Information” shall mean any information of a technical, commercial, operational, financial, strategic or any other nature that one party discloses to the other, whether orally, in writing, visually, electronically or in any other medium, and that is expressly designated as confidential or that, by its nature or the circumstances of its disclosure, should reasonably be understood as confidential. Without prejudice to the foregoing definition, the following shall be deemed Confidential Information of the Provider, by way of illustration and without limitation: (a) the source code, technical architecture, algorithms and design of the Platform; (b) internal technical documentation, product plans and technology roadmap; (c) unpublished commercial terms, tariffs and discounts; (d) business data and client lists; and (e) any know-how or proprietary methodology of the Provider. The following shall be deemed Confidential Information of the Client: (a) the Client Content; (b) the data of its own end clients; and (c) the marketing strategies, briefings and business plans shared with the Provider.
11.3 Exceptions to Confidentiality. The confidentiality obligation shall not apply with respect to information that the Receiving Party can conclusively demonstrate: (a) was in the public domain at the time of its disclosure or has subsequently become public through no fault of the Receiving Party; (b) was already known to the Receiving Party prior to its disclosure by the Disclosing Party, without being subject to any confidentiality obligation; (c) has been independently developed by the Receiving Party without use of the Confidential Information received; (d) has been disclosed to the Receiving Party by a third party lawfully and without confidentiality restrictions; or (e) must be disclosed in compliance with a legal or regulatory obligation or a final judicial or administrative order, in which case the Receiving Party shall: (i) notify the Disclosing Party with as much advance notice as possible, to the extent permitted by law, so that the Disclosing Party may take appropriate measures; and (ii) limit disclosure to only the information strictly required by the legal obligation, cooperating with the Disclosing Party to preserve confidentiality to the greatest extent possible.
11.4 Employees and Subcontractors. Each party may disclose Confidential Information only to its employees, officers, legal or financial advisors, and subcontractors who have a strict need to know for the fulfilment of the purpose of these Terms, provided that such persons are bound by confidentiality obligations no less restrictive than those set forth in these Terms. Each party shall be liable for any breach of the confidentiality obligation by its employees, officers, advisors or subcontractors as if it were its own breach.
11.5 Post-Contractual Survival. The confidentiality obligations set forth in this clause shall remain in full force and effect during the contractual relationship and for a period of 5 years from the date of termination or resolution of the contract for any reason, without prejudice to the fact that certain Confidential Information constituting a trade secret within the meaning of Ley 1/2019, de 20 de febrero, de Secretos Empresariales, may be protected for a longer period under such legislation.
11.6 Return or Destruction. Upon termination of the contract, or at any time upon request of the Disclosing Party, the Receiving Party shall return or destroy, at the Disclosing Party’s election, all Confidential Information received and any copies thereof in its possession, unless retention is required by a legal or regulatory obligation. In the latter case, the Receiving Party shall notify the Disclosing Party of the information that must be retained and the legal basis for such retention, and shall remain bound to ensure its confidentiality.
12. WARRANTIES AND DISCLAIMER OF WARRANTIES
12.1 Provision of the Service “As Is.” To the maximum extent permitted by applicable Spanish and European law, the Platform is provided in its current state (“as is”), with its functionalities available at any given time and without additional warranties of any kind, whether express, implied or statutory, other than those that are legally non- waivable. The Provider does not warrant, in particular, that the Platform shall fully meet the Client’s expectations, requirements or specific needs.
12.2 No Guarantee of Uninterrupted Availability. The Provider does not warrant that access to the Platform shall be uninterrupted, continuous, secure or error-free. The Platform may be temporarily unavailable due to maintenance, updates, technical failures, cyberattacks, incidents affecting third-party cloud infrastructure services, disruptions in connections with Third-Party AI Model services, or any other cause beyond the Provider’s reasonable control.
12.3 Maximum Scope of Disclaimer of Warranties. To the maximum extent permitted by law, the Provider expressly disclaims any implied warranty of merchantability, fitness for a particular purpose, non-infringement of third-party rights, or any warranty arising from the course of dealing or trade usage. This disclaimer applies to the Platform as a whole and to all of its components.
13. LIMITATION OF LIABILITY
13.1 Aggregate Liability Cap. Without prejudice to the absolute exclusions provided herein, the Provider’s total and aggregate liability to the Client arising from these Terms or the use of the Platform, regardless of the nature of the action brought, shall be limited to the total amount of Subscription fees actually paid by the Client to the Provider during the 12 months immediately preceding the event giving rise to the claim.
13.2 Exclusion of Indirect and Consequential Damages. To the maximum extent permitted by applicable law, the Provider shall in no event be liable to the Client or to any third party for: (a) indirect, incidental, special or consequential damages; (b) loss of profits, loss of revenue or loss of earnings; (c) loss or corruption of Client data, whether in whole or in part; (d) loss of business opportunity or contracts; (e) loss of reputation or goodwill; (f) damages arising from the use of, or the inability to use, the connection with Third-Party AI Models or Third-Party Integrations.
13.3 Absolute Exclusions: Non-Limitable Scenarios. The limitations of liability set forth in this clause shall not apply and the Provider shall be liable in full in the following cases:
(a) liability arising from wilful misconduct or gross negligence of the Provider or its employees or representatives; (b) liability for personal injury (bodily injury, harm to health or death) caused by an act or omission of the Provider; (c) liability for fraud or fraudulent misrepresentation; (d) any other liability that cannot be excluded or limited under mandatory Spanish or European law.
13.4 Duty to Mitigate. The Client shall be obliged to take all reasonable measures to mitigate the damages suffered as a consequence of any breach by the Provider. Failure to comply with this duty to mitigate may be taken into account when quantifying the Provider’s liability.
14. INDEMNITY
14.1 Client’s Indemnity Obligation. The Client shall defend, indemnify and hold harmless the Provider, its affiliated companies, officers, directors, partners, employees, agents and service providers (collectively, the “Provider’s Indemnitees”) against any claim, demand, judicial or administrative action, investigation, sanctioning proceeding, damage, loss, liability, cost and expense of any nature, including reasonable attorneys’ and solicitors’ fees (“Claims”), arising from or related to:
(a) The Client’s breach of any of the obligations, representations or warranties set forth in these Terms.
(b) The Client Content, including any third-party claim alleging that the Client Content infringes intellectual or industrial property rights, personality rights, privacy or data protection rights, or any other third-party right.
(c) The use of the Platform by the Client or its authorised users in violation of these Terms, applicable law or third-party rights.
(d) The marketing campaigns, commercial communications or advertising content that the Client creates, disseminates or executes through the Platform, including any claim arising from misleading advertising, unfair competition, data protection breaches, or violation of third-party image or reputation rights.
(e) Claims from the Client’s own end clients or from the agencies managed through the Platform.
14.2 Indemnification Procedure. In the event that any of the Provider’s Indemnitees receives a Claim in respect of which the Client has an obligation to indemnify under this clause:
(a) the Provider shall notify the Client of the existence of the Claim as promptly as possible, provided that any delay in notification shall not relieve the Client of its indemnity obligation, except to the extent that such delay has caused material prejudice to the Client; (b) the Provider shall cooperate reasonably with the Client in the defence and resolution of the Claim, at the Client’s expense; (c) the Provider reserves the right to assume exclusive control of the defence and management of any Claim in respect of which the Client has an obligation to indemnify, in which case the Client shall provide its cooperation and support, and shall not reach any settlement or compromise without the prior written consent of the Provider.
15. TERM, SUSPENSION AND TERMINATION
15.1 Term of the Contract. The Subscription contract shall have the duration corresponding to the Plan contracted by the Client (monthly or annual, as applicable), commencing on the date on which the Subscription is activated or, in the case of a Trial Period, upon expiry thereof and the commencement of recurring billing. The Subscription shall automatically renew for successive periods of the same duration, unless either party cancels it in accordance with these Terms.
15.2 Cancellation by the Client. The Client may cancel its Subscription at any time through the Account management section of the Platform. For the cancellation to take effect before the next automatic renewal, it must be submitted before the renewal date. Cancellation shall not entitle the Client to a refund of fees already paid for the current period, except in the circumstances provided for in these Terms or under applicable law. Once the cancellation becomes effective, the Client shall retain access to the Platform until the end of the paid billing period.
15.3 Suspension of Access by the Provider. The Provider may temporarily suspend the Client’s access to the Platform, in whole or in part, in the following circumstances: (a) non-payment of Subscription fees; (b) use of the Platform in violation of the acceptable use policy; (c) material or repeated breach of any obligation under these Terms; (d) well-founded suspicion of fraudulent or illegal activity or activity that compromises the security of the Platform or of other Users; or (e) a requirement from competent authorities. Suspension due to non-payment shall be lifted once the Client has settled its outstanding debt. Suspension shall not relieve the Client of its payment obligations.
15.4 Termination for Material Breach. Either party may terminate the contract early and with immediate effect by written notice to the other party in the event of: (a) material breach of any essential obligation under these Terms that is not remedied within 15 business days from notice of the breach by the non-breaching party; (b) commencement of insolvency proceedings, creditor arrangements, bankruptcy or liquidation of the other party; or (c) breaches of the acceptable use clause which, due to their severity or urgency, do not allow for the aforementioned cure period, including in particular the carrying out of illegal activities through the Platform.
15.5 Effects of Termination. Upon termination of the contract for any reason: (a) the Client’s and its authorised users’ access to the Platform shall cease immediately; and (b) the licences of use granted to the Client shall be automatically revoked.
16. AMENDMENTS TO THE TERMS AND THE SERVICE
16.1 Right to Amend the Terms. The Provider reserves the right to amend, update or replace these Terms at any time, for legal, regulatory, technical or business reasons. Amendments shall be notified to the Client with a minimum of 30 calendar days’ notice before they come into effect, by means of a communication to the email address associated with the Client’s Account and/or by means of a prominent notice on the Platform.
16.2 Acceptance of Amendments. The Client’s continued use of the Platform after the amended Terms come into effect shall constitute full and unconditional acceptance of the new Terms. If the Client does not agree with the amendments introduced, it shall notify the Provider before the effective date of the amendments and cancel its Subscription, without incurring any penalty for early cancellation arising from the rejection of the new Terms.
16.3 Urgent Amendments. Notwithstanding the foregoing, the Provider may introduce amendments to the Terms with immediate effect and without prior notice where such amendments are necessary due to immediately applicable legal or regulatory requirements, or to address security or cybersecurity emergencies requiring urgent action. In such cases, the Provider shall inform the Client of the amendments introduced as soon as reasonably practicable.
16.4 Modifications to the Service. The Provider reserves the right to modify, expand, reduce, temporarily suspend or discontinue functionalities of the Platform, for the purpose of improving the service, adapting it to technological advances, or complying with new legal or business requirements.
17. DATA PROTECTION AND COOKIES
17.1 General Data Protection Framework. The processing of personal data in the context of these Terms shall be governed by Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR), Ley Orgánica 3/2018, de 5 de diciembre, de Protección de Datos Personales y garantía de los derechos digitales (LOPDGDD), and any other implementing or supplementary regulations that may apply. Both the Provider and the Client shall assume their respective responsibilities in the area of data protection, the roles of data controller and data processor being distinguished as set out below.
17.2 Processing as Data Processor: Reference to the DPA. With regard to the Personal Data that the Client, in its capacity as data controller, uploads or processes through the Platform, the Provider acts as data processor within the meaning of Article 28 of the GDPR. The processing of such Personal Data by the Provider shall be governed entirely by the Data Processing Agreement (“DPA”), which forms an integral and inseparable part of these Terms. The Client acknowledges having read, understood and accepted the DPA upon subscribing to these Terms. In the event of a conflict between these Terms and the DPA regarding data protection matters, the provisions of the DPA shall prevail.
17.3 Processing by the Provider as Data Controller. The Provider also processes personal data of the Client (including registration, billing, communication and Platform usage data) in its capacity as data controller, for the management of the contractual relationship, the provision of the service, billing, communication with the Client and the improvement of the Platform.
17.4 Data Subject Rights. The Client and, where applicable, its authorised users may exercise their rights of access, rectification, erasure, objection, restriction of processing and data portability, as well as the right not to be subject to automated individual decision-making with significant effects, in accordance with Articles 15 to 22 of the GDPR and the LOPDGDD, by contacting the Provider at info@abency.com. In the event that the Client considers that the Provider has not respected its data protection rights, the Client shall have the right to lodge a complaint with the Agencia Española de Protección de Datos (AEPD), located at calle Jorge Juan, 6, 28001 Madrid (www.aepd.es).
17.5 Cookie Policy. The Provider uses cookies and similar tracking technologies on the Platform for technical, analytical, functional and, where applicable, advertising purposes, in accordance with Article 22.2 of the LSSI-CE. The use of cookies that are not strictly necessary for the provision of the service shall be subject to the prior, informed and freely given consent of the User, which may be granted, denied or revoked at any time through the cookie management panel accessible on the Platform. Detailed information on the types of cookies used, their purpose, duration, owners and how to manage them is set out in the Provider’s Cookie Policy, available at https://abency.com/politica-de-cookies. Acceptance of non-technically necessary cookies upon first access to the Platform is voluntary and shall not affect the provision of the basic contracted services.
18. FORCE MAJEURE
18.1 Definition of Force Majeure. For the purposes of these Terms, “Force Majeure” shall mean any event or circumstance that: (a) is beyond the reasonable control of the affected party; (b) could not have been reasonably foreseen at the time the contract was entered into, or which, having been foreseen, could not have been avoided or overcome through reasonably required diligence; and (c) prevents, temporarily or permanently, the total or partial performance of the obligations of the affected party. Without prejudice to the illustrative nature of the foregoing definition, the following shall be considered Force Majeure events, by way of example and without limitation: (i) natural disasters (earthquakes, floods, natural fires, storms, volcanic eruptions, epidemics or pandemics declared by the competent authorities); (ii) acts of war, armed conflicts, acts of terrorism or sabotage; (iii) decisions, acts or omissions of national, European or international public authorities, including immediately applicable legislative or regulatory changes, embargoes, sanctions, or judicial or administrative orders; (iv) widespread failures or prolonged disruptions of public telecommunications networks or electricity supply services; (v) large-scale cyberattacks (massive DDoS attacks, ransomware or similar) affecting the infrastructure of the Provider or its cloud service providers that cannot be mitigated within a reasonable timeframe.
18.2 Suspension of Obligations. In the event that either party is affected by a Force Majeure event, its contractual obligations shall be suspended for as long as such event and its direct effects persist, without such suspension constituting a contractual breach or giving rise to a right to compensation by the other party, provided that the notification conditions set forth in this clause are met. The suspension of obligations shall extend solely to those obligations directly affected by the Force Majeure event, and not to payment obligations in respect of fees already accrued prior to the event.
18.3 Notification Obligation. The party affected by a Force Majeure event shall: (a) notify the other party of the existence of the Force Majeure event as soon as reasonably practicable from the time it becomes aware thereof, and in any event within a maximum period of 5 business days from its commencement, describing the nature of the event, its expected duration and the obligations affected; (b) take all reasonable measures within its power to mitigate or reduce the effects of the Force Majeure event and resume performance of its obligations as soon as possible; and (c) keep the other party informed of the evolution of the event and its effects, with such frequency as the circumstances may require. Failure to comply with the notification obligation within the period indicated shall deprive the affected party of the right to invoke Force Majeure as a ground for exoneration from liability, to the extent that such failure has caused additional prejudice to the other party.
18.4 Termination Due to Prolonged Force Majeure. If the Force Majeure event persists or is reasonably foreseeable to persist for a period exceeding 90 consecutive calendar days, either party may terminate the contract by written notice to the other party, with effect from the date of receipt of such notice, without either party being entitled to compensation for such termination. In such event, the Provider shall refund to the Client the pro-rata portion of the Subscription fees paid corresponding to the unexpired period of the contract.
19. GENERAL PROVISIONS
19.1 Assignment of the Contract. The Client shall not assign, transfer or otherwise convey its rights or obligations arising from these Terms, nor access to the Platform or the rights derived from its Subscription, to any third party, whether for consideration or gratuitously, without the prior written consent of the Provider. The Provider may assign or transfer these Terms and the rights and obligations arising therefrom, in whole or in part, to any company within the group to which it belongs, or to any third party in the context of a merger, acquisition, corporate reorganisation, asset sale or any other similar corporate transaction, without prior notice being required.
19.2 Waiver. The failure of either party to require strict performance of any obligation under these Terms, or to exercise any right or remedy available to it, at any given time, shall not constitute or imply a waiver of such obligations, rights or remedies in the future, nor shall it be construed as a novation of the Terms. A waiver of a specific right or remedy shall only be valid and binding if made in writing and signed by the waiving party.
19.3 Communications and Notices. Unless expressly stated otherwise in these Terms, all communications, notifications and notices to be exchanged between the parties under this contract shall be made in writing and shall be addressed: (a) to the Client, at the email address registered in its Account, which the Client shall be obliged to keep up to date; and (b) to the Provider, at the email address info@abency.com or to the postal address indicated in the identification details of the provider in clause 1. Communications made by email shall be deemed received at the time of their transmission, unless the sending party receives an automatic non-delivery notification. The Client shall be responsible for keeping the email address of its Account up to date. Notices sent to an expired, incorrect or outdated email address shall likewise be deemed received if they have been sent to the last registered address.
19.4 Language of the Contract. These Terms are drafted in English, which shall be the language of reference and interpretation of the contract. In the event that the Provider makes available to the User a version of the Terms in another language and any contradiction, discrepancy or ambiguity arises between the Spanish version and any translation, the Spanish version shall prevail in all cases, unless mandatory law provides otherwise.
19.5 Relationship Between the Parties. The parties are independent contractors. Nothing in these Terms creates or is intended to create any relationship of agency, partnership, joint venture, representation, franchise, employment or any other analogous relationship between the Provider and the Client. Neither party shall have authority to assume obligations on behalf of the other party.
20. GOVERNING LAW, JURISDICTION AND DISPUTE RESOLUTION
20.1 Governing Law. These Terms and the contractual relationship between the Provider and the Client shall be governed by and construed in accordance with Spanish law.
20.2 For the resolution of any dispute, discrepancy or claim arising from or in connection with these Terms, their interpretation, performance, breach or termination, the parties, with express waiver of any other jurisdiction to which they may be entitled, submit to the exclusive jurisdiction of the Courts and Tribunals of Girona.
PERSONAL DATA PROCESSING AGREEMENT (DPA)
1. PARTIES AND LEGAL FRAMEWORK
1.1 Identification of the parties. This Data Processing Agreement (hereinafter, the “DPA”) is entered into between the following parties:
- Controller: the Client, acting as controller of the personal data that is the subject of this DPA within the meaning of Article 4.7 of the GDPR.
- Processor: Additiu Marketing Digital S.L, with NIF B55314066, registered office at C/ Sant Maurici 24, 17740 Vilafant (Girona), Spain, which provides the Client with access to the Platform, acting as processor within the meaning of Article 4.8 of the GDPR.
1.2 Applicable legal framework. This DPA is governed by Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter, the “GDPR”), in particular Article 28 thereof, and by Ley Orgánica 3/2018, of 5 December, on the Protection of Personal Data and the guarantee of digital rights (hereinafter, the “LOPDGDD”).
1.3 Relationship with the main agreement. This DPA forms an integral and inseparable part of the main agreement entered into between the parties under the Terms and Conditions of Use. In the event of a conflict between the provisions of this DPA and those of the main agreement regarding personal data protection, the provisions of this DPA shall prevail. In all matters not addressed by this DPA, the provisions of the main agreement shall apply.
1.4 Prevalence of the GDPR. No provision of this DPA shall be construed so as to restrict or limit the rights of data subjects or the obligations of the parties established by the GDPR and the LOPDGDD, whose mandatory provisions shall prevail in all cases.
2. PURPOSE, DURATION, NATURE AND OBJECTIVE OF THE PROCESSING
2.1 Purpose. The purpose of this DPA is to regulate the conditions under which the Processor shall process personal data on behalf of the Controller in the context of access to the Platform in accordance with Article 28 of the GDPR.
2.2 Duration. The processing of personal data under this DPA shall be linked to the term of the main agreement. Upon termination of the main agreement, for any reason, all processing activities shall cease, except to the extent that the Processor is required to retain the data by virtue of an applicable legal obligation, in which case the data shall be retained exclusively for the legally required period and with appropriate safeguards.
2.3 Nature of the processing. The processing shall primarily take the following forms: (i) automated processing of personal data by sending instructions and content to third- party artificial intelligence models; (ii) temporary storage and transmission of data within the Platform environment; (iii) access to, consultation and management of personal data in the context of the provision of the contracted service.
2.4 Purpose of the processing. The Processor shall process personal data exclusively for the following purposes, which correspond to the object of the contracted service: management and automation of digital marketing campaigns on the integrated platforms, generation of advertising content, creative assets and commercial communications on behalf of the Controller, and any other purpose expressly agreed between the parties in writing.
2.5 Types of Personal Data and categories of data subjects. The types of Personal Data processed and the categories of data subjects concerned are described in Annex I to this DPA, to which reference is made for further detail. In general terms, the data processed may include identification data, contact data, online behavioural data and, depending on the Controller’s use of the Platform, other data that the Controller decides to enter into the system. Under no circumstances shall it be for the Processor to determine the categories of Personal Data that the Controller enters into the Platform.
3. PROCESSOR OBLIGATIONS (Art. 28 GDPR)
3.1 Processing in accordance with documented instructions (Art. 28.3.a GDPR). The Processor shall process personal data only on the basis of the Controller’s documented instructions, including those set out in this DPA. The Processor shall not process the data for purposes other than those set out in clause 2.4 of this DPA, nor disclose them to third parties, except: (i) where the Controller expressly authorises it in writing; (ii) where a legal obligation so requires, in which case the Processor shall inform the Controller prior to the processing, unless such legislation prohibits this on grounds of public interest. If the Processor considers that an instruction from the Controller infringes the GDPR, the LOPDGDD or other applicable data protection legislation, it shall immediately notify the Controller in accordance with clause 3.9 of this DPA.
3.2 Confidentiality of authorised personnel (Art. 28.3.b GDPR). The Processor shall ensure that persons authorised to process the Controller’s personal data have given an express written undertaking of confidentiality, or are subject to a statutory duty of confidentiality. The Processor shall adopt the necessary organisational measures to ensure that only personnel who need access to the data for the provision of the contracted service may access them, in accordance with the principle of access minimisation.
3.3 Technical and organisational security measures (Art. 28.3.c and Art. 32 GDPR). The Processor shall implement and maintain appropriate technical and organisational security measures to ensure a level of security appropriate to the risk presented by the processing, in accordance with Article 32 of the GDPR.
3.4 Sub-processors (Art. 28.2 and 28.4 GDPR). The Processor shall comply with the conditions set out in the DPA for engaging sub-processors. The Processor shall not sub- contract any processing of the Controller’s personal data to a third party without the Controller’s prior authorisation, whether specific or general.
3.5 Assistance with data subject rights (Arts. 15–22 GDPR). The Processor shall assist the Controller, by appropriate technical and organisational measures, insofar as this is possible, in fulfilling its obligation to respond to requests for the exercise of the rights recognised in Articles 15 to 22 of the GDPR (rights of access, rectification, erasure, objection, restriction of processing, portability, and the right not to be subject to automated individual decision-making). Where the Processor receives a data subject rights request directly, it shall forward it to the Controller as soon as possible and in any event within no more than 15 business days, without responding to the request on its own account unless expressly instructed to do so by the Controller.
3.6 Assistance regarding security, breach notification, DPIAs and prior consultation (Arts. 32–36 GDPR). The Processor shall assist the Controller in complying with the obligations laid down in Articles 32 to 36 of the GDPR, in particular: (i) implementing appropriate technical and organisational security measures (Art. 32); (ii) notifying personal data breaches to the competent supervisory authority (Art. 33); (iii) communicating data breaches to the affected data subjects where appropriate (Art. 34); (iv) carrying out Data Protection Impact Assessments (DPIAs); and (v) prior consultation with the supervisory authority where a DPIA indicates that the processing would result in a high risk that the Controller cannot mitigate (Art. 36).
3.7 Deletion of data upon termination of the processing (Art. 28.3.g GDPR). The Processor shall delete all personal data and destroy existing copies, unless European Union or Member State law requires retention of the data for a specified period.
3.8 Information, audits and inspections (Art. 28.3.h GDPR). The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 of the GDPR and in this DPA, and shall allow for and contribute to audits and inspections carried out by the Controller or an auditor mandated by the Controller. Audits shall be carried out upon written notice with a minimum of 30 days’ prior notice, during normal business hours, with reasonable frequency and without unduly disrupting the Processor’s operations. The costs of the audit shall be borne by the Controller.
3.9 Duty to inform regarding unlawful instructions. The Processor shall immediately inform the Controller in writing if it considers that an instruction received infringes the GDPR, the LOPDGDD or other European Union or Member State data protection provisions. In such a case, the Processor may suspend the execution of the instruction until the Controller confirms or amends it, without this constituting a breach of contract on the part of the Processor.
4. SUB-PROCESSORS (Arts. 28.2 and 28.4 GDPR)
4.1 General authorisation. The Controller grants the Processor a general authorisation to engage the sub-processors listed in Annex II to this DPA.
4.2 Contract with sub-processors. The Processor shall enter into a data processing agreement, or an equivalent legal instrument, with each sub-processor, imposing on the sub-processor the same data protection obligations as those set out in this DPA, in accordance with Article 28.4 of the GDPR. The Processor shall be liable to the Controller for the sub-processors’ compliance with those obligations.
4.3 Prior notification of changes to the sub-processor list. The Processor shall notify the Controller, with a minimum of 30 days’ advance notice, of any intended change to the list of sub-processors, whether by addition of new sub-processors or replacement of existing ones. The notification shall be made in writing, by email to the Controller’s contact address or through the Platform’s administration panel, and shall include the identity of the new sub-processor, its location and the nature of the processing it will carry out.
4.4 Controller’s right to object. The Controller shall have the right to object to any change in the sub-processor list by means of a written notification addressed to the Processor within 15 days of receipt of the notification. If the Controller objects to a proposed change and the Processor is unable to offer a reasonable alternative that satisfies the Controller’s data protection requirements, the Controller shall have the right to terminate the main agreement with effect from the date on which the objected change comes into force, without penalty for early termination on this specific ground, but without the right to a refund of the pro-rata portion of unearned prepaid fees.
4.5 Processor’s liability for sub-processor acts. The Processor shall be liable to the Controller for the acts and omissions of its sub-processors to the same extent as it would be liable for its own acts and omissions under this DPA, without prejudice to the limitations of liability set out in the TYC.
5. INTERNATIONAL DATA TRANSFERS (Chapter V GDPR)
5.1 General principle. The Processor shall not transfer the Controller’s personal data to recipients established outside the European Economic Area (EEA) without the appropriate safeguards required by Chapter V of the GDPR or without one of the derogations set out in Article 49 of the GDPR applying. The Processor shall document all international transfers carried out in the context of this DPA and shall inform the Controller of their legal basis.
5.2 Applicable transfer mechanisms. International transfers of personal data carried out under this DPA shall be based on one of the following mechanisms:
(a) Adequacy decisions (Art. 45 GDPR): For transfers to countries that have an adequacy decision from the European Commission, including, in particular, the EU-US Data Privacy Framework (Commission Implementing Decision (EU) 2023/1795).
(b) Standard Contractual Clauses (SCCs): For transfers to countries without an adequacy decision, the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 of 4 June 2021 shall be used, in particular Module 3 (processor to sub-processor), in cases where the Processor, acting as processor on behalf of the Controller, transfers data to a sub-processor established in a third country. The SCCs shall be incorporated into the contracts with the relevant sub-processors.
(c) Other appropriate safeguards: Any other legitimate transfer mechanism in accordance with Article 46 of the GDPR, duly documented.
5.3 Information on changes to the processing location. The Processor shall inform the Controller of any planned change to the geographical location where the processing of personal data takes place, including changes to sub-processor facilities, that could affect the application of international transfer mechanisms.
5.4 Objection to transfers without appropriate safeguards. If a sub-processor is established in a third country that lacks an adequacy decision from the European Commission and without appropriate safeguards pursuant to Article 46 of the GDPR, the Controller may object to such transfer.
6. PERSONAL DATA BREACHES (Arts. 33–34 GDPR)
6.1 Obligation to notify the Controller. The Processor shall notify the Controller, without undue delay and in any event within a maximum of 48 hours of becoming aware of a potential personal data breach covered by this DPA, through any communication channel enabled for this purpose and with subsequent written confirmation. The notification shall be made even if the Processor does not yet have complete information about the breach, in which case the information shall be provided in phases, as it becomes available, without unjustified delay.
6.2 Minimum content of the notification. The data breach notification to the Controller shall contain, to the extent possible and in accordance with Article 33.3 of the GDPR, the following information:
- The nature of the data breach, including, where possible, the categories and approximate number of data subjects affected, and the categories and approximate number of personal data records affected.
- The contact details of the data protection officer or the Processor’s data protection point of contact.
- The likely consequences of the personal data breach.
- The measures taken or proposed by the Processor to address the data breach, including, where applicable, measures taken to mitigate its possible adverse effects.
6.3 Assistance with notification to the supervisory authority and data subjects. The Processor shall assist the Controller in complying with its obligations to notify the data breach to the competent supervisory authority (Agencia Española de Protección de Datos, “AEPD”, or other competent supervisory authority as the case may be) within the 72-hour period provided for in Article 33.1 of the GDPR, and in communicating to the affected data subjects where the breach is likely to result in a high risk to their rights and freedoms, in accordance with Article 34 of the GDPR. To this end, the Processor shall make available to the Controller all necessary technical and operational information.
6.4 Record of data breaches. The Processor shall maintain an internal record of all personal data breaches occurring in the context of this DPA, regardless of whether they have been notified to the supervisory authority, in accordance with Article 33.5 of the GDPR. Such record shall include the facts relating to the breach, its effects and the corrective measures taken, and shall be available for review by the Controller upon request.
7. DATA PROTECTION IMPACT ASSESSMENTS (DPIAs) AND PRIOR CONSULTATION (Arts. 35–36 GDPR)
7.1 Processor’s assistance in carrying out DPIAs. The Processor shall assist the Controller, by appropriate technical and organisational measures, in carrying out Data Protection Impact Assessments (DPIAs) that are necessary in relation to the processing covered by this DPA, in particular with regard to the use of third-party artificial intelligence models and processing operations that may entail a high risk to the rights and freedoms of natural persons. To this end, the Processor shall provide the Controller with the relevant technical information regarding the systems, processing operations and security measures used on the Platform.
7.2 Cooperation in prior consultation with the AEPD. If, as a result of a DPIA, the Controller determines that the processing entails a high residual risk that cannot be mitigated by appropriate measures and therefore requires prior consultation with the competent supervisory authority (AEPD) pursuant to Article 36 of the GDPR, the Processor shall provide the Controller with the necessary cooperation to prepare and document such consultation, supplying the technical and operational information requested.
7.3 Recommendation to carry out a DPIA prior to processing data through AI models. In accordance with Article 35.3.a of the GDPR, which requires a DPIA where the processing involves a systematic and extensive evaluation of personal aspects of natural persons based on automated processing, including profiling, on which decisions producing legal effects concerning them or similarly significantly affecting them are based, the Processor expressly recommends that the Controller carry out a DPIA before processing personal data through third-party artificial intelligence models integrated into the Platform, having regard to the nature, scope, context and purposes of the intended processing, as well as the risks to the rights and freedoms of data subjects.
7.4 Processor’s Record of Processing Activities. The Processor shall maintain a record of all categories of processing activities carried out on behalf of the Controller, in accordance with Article 30.2 of the GDPR. Such record shall be available for review by the competent supervisory authority upon request.
8. LIABILITY
8.1 Liability regime under the GDPR. Each party shall be liable for damage caused to data subjects by a breach of the GDPR obligations incumbent upon it, in accordance with Article 82 of the GDPR. The Processor shall be exempt from liability if it proves that it is not in any way responsible for the event giving rise to the damage, pursuant to Article 82.3 of the GDPR. The parties shall cooperate in good faith in the management of any liability claim related to the processing of personal data covered by this DPA.
8.2 Processor’s liability as controller. If the Processor, in breach of the provisions of the GDPR or this DPA, determines the purposes and means of the processing on its own, it shall be regarded as a controller with respect to such processing, in accordance with Article 28.10 of the GDPR, assuming the corresponding liabilities towards data subjects and supervisory authorities.
8.3 Limitation of liability. Without prejudice to the mandatory provisions of the GDPR and the LOPDGDD, the Processor’s financial liability towards the Controller arising from this DPA shall be governed by the limitation of liability clauses set out in the main agreement. Under no circumstances may the limitations of liability set out in the main agreement be applied in a manner that contravenes the mandatory obligations established by the GDPR or prevents data subjects from obtaining effective compensation for damage suffered.
8.4 Indemnification between parties. Where a party has paid full compensation for the damage suffered, it shall be entitled to claim back from the other party the part of the compensation corresponding to the latter’s share of responsibility for the damage, in accordance with Article 82.5 of the GDPR.
9. DURATION AND TERMINATION OF THE DPA
9.1 Link to the main agreement. This DPA shall enter into force on the date of acceptance of the main agreement by the Client and shall remain in force for the entire duration of the main agreement. Termination of the main agreement for any reason shall automatically entail the termination of this DPA, without prejudice to the provisions of the following clauses.
9.2 Survival of confidentiality and security obligations. The personnel confidentiality obligations (clause 3.2), the obligations relating to security measures (clause 3.3), the data breach notification obligations in relation to events occurring during the term of the DPA, and the duty of cooperation in the case of ongoing audits or inspections shall survive the termination of this DPA to the extent necessary for the protection of the interests of data subjects and of the Controller, and for such time as is required by applicable law.
9.3 Deletion. Following the termination of the main agreement and of this DPA, the Processor shall delete all personal data that was the subject of the processing. The Processor shall provide the Controller with documentary evidence of compliance with this obligation by delivering a certificate of secure erasure.
9.4 Amendment of the DPA. Any amendment to this DPA must be made in writing. The Processor may unilaterally update the DPA where necessary to adapt its content to regulatory changes or binding guidelines of the supervisory authorities, by notifying the Controller with a minimum of 30 days’ advance notice.
ANNEX I — DESCRIPTION OF THE PROCESSING
In accordance with Article 28.3 of the GDPR, the processing of personal data covered by this Data Processing Agreement (DPA) is described in the following terms:
- Categories of data subjects
The personal data processed may correspond to the following categories of data subjects:
- Registered users of the Client on the Platform (employees, collaborators or persons authorised by the Client to access the service).
- Contacts included in marketing campaigns managed through the Platform (recipients of commercial communications, leads, prospects).
- Recipients of communications generated through the artificial intelligence service integrated into the Platform.
- Employees or collaborators of the Client, if the Client uses the Platform for purposes related to the internal management of its organisation.
- Any other category of natural persons whose personal data the Client decides to enter into the Platform in the exercise of its autonomy as Controller.
- Categories and types of Personal Data
In general terms, the personal data processed may include:
- Identification data: first and last name, email address, telephone number, user identifiers on the Platform.
- Professional data: job title or role, company or organisation name, sector of activity.
- Browsing and interaction data: Platform usage logs, session data, IP address, device identifiers, service usage metadata.
- Usage metadata: activity logs, timestamps, history of conversations and interactions with the Platform.
- Any other personal data that the Client, in its capacity as Controller, decides to enter into the Platform. The Processor does not determine or control the categories of personal data that the Client enters into the system.
- Purposes of the processing
The processing is carried out exclusively for the following purposes:
- Provision of the service contracted by the Client, including access to and use of all the functionalities of the Platform.
- Management and automation of digital marketing campaigns on the platforms integrated with the service.
- Service analysis and optimisation: improvement of the Platform’s technical performance, error detection, aggregated and anonymised usage statistics.
- Technical support: handling and resolution of incidents reported by the Client, to the extent that this involves access to personal data.
- Duration of the processing
The processing of personal data shall be linked to the term of the main agreement. Upon termination of the main agreement, the Processor shall delete the data of the Controller.
- Special categories of data (Art. 9 GDPR)
The processing of special categories of personal data within the meaning of Article 9 of the GDPR (health data, racial or ethnic origin, political opinions, religious or philosophical beliefs, genetic or biometric data, data concerning sexual orientation, among others) is not envisaged, except upon specific, express and documented instruction from the Controller, which must be accompanied by the prior completion of a Data Protection Impact Assessment (DPIA) and the establishment of appropriate safeguards in accordance with the GDPR and the LOPDGDD.
ANNEX II — LIST OF SUB-PROCESSORS
In accordance with the DPA and Article 28.2 of the GDPR, the Processor has the Controller’s general authorisation to engage the following sub-processors:
| Sub-processor name | Purpose of the processing | Processing location | International transfer safeguards |
|---|---|---|---|
| DigitalOcean LLC | Infrastructure Hosting Service | European Union | N/A |