4 DATA PROTECTION, CYBER SECURITY, AND CONFIDENTIALITY
4.1 The Service is used for the processing of technical and commercial data, including personal data, in accordance with European data protection legislation. The processing of personal data is described in a separate Fliq data protection document.
4.2 In particular, it is noted that, in connection with the provision of the Service under this Agreement, the Supplier processes personal data relating to the Customer’s employees, decision-makers, or other individuals (e.g. the Customer’s technical or administrative contacts) for the purposes of providing the Service, troubleshooting, customer relationship management, customer service, billing, communication, marketing, service development, and other similar purposes (“Supplier Personal Data”). In respect of such data, the Supplier acts as the controller in accordance with applicable data protection legislation and is responsible for the lawfulness of the processing. Unless otherwise agreed in writing, the Customer may not issue instructions regarding the Supplier Personal Data. Further information on the processing of Supplier Personal Data is available at www.fliq.io/en/privacy-statement/.
4.3 The Supplier shall implement appropriate measures in accordance with industry standards to protect the Service and the Data from data breaches.
4.4 Neither Party nor its employees or group companies may use or disclose the other Party’s confidential information to third parties except as permitted under these Terms. The Parties shall treat confidential information with at least the same degree of care as they use for their own confidential information and, in any event, with no less than reasonable care.
5 IDENTIFICATION DATA
5.1 The Customer shall ensure that the usernames and passwords of the Customer and all Users designated by it are kept secure and separate. The Customer shall ensure that the above-mentioned credentials are not disclosed to any third party. If such credentials are disclosed to a third party, or if the Customer suspects that this has occurred, the Customer shall promptly notify the Supplier in order to prevent unauthorized use. The Supplier shall have the right to suspend the use of the Service until new credentials have been implemented.
5.2 The Customer shall be responsible for all actions carried out using its credentials until the Supplier has received notice of a possible disclosure of the credentials and has had a reasonable time to prevent use of the Service.
5.3 If a User has stored their credentials negligently or otherwise contributed to their disclosure to a third party, the Customer shall be liable for any damages caused to the Supplier or to third parties.
6 GENERAL RIGHTS AND OBLIGATIONS OF THE SUPPLIER
6.1 The Supplier grants the Customer and the Users a limited, non-exclusive, non-transferable, and non-sublicensable right to use the Service during the subscription term for the purposes specified in these Terms. The Customer and the Users acknowledge that the Service is provided under a license and not sold, and that no ownership rights to the Service are granted to them.
6.2 The Supplier shall provide the Service in a professional and diligent manner in accordance with these Terms. The Supplier shall have the right to include open source software or modules in the Service.
6.3 The Supplier shall promptly notify the Customer of any circumstances that may prevent the use of the Service in accordance with these Terms or that may compromise the privacy of the Customer’s Data.
7 GENERAL RIGHTS AND OBLIGATIONS OF THE CUSTOMER
7.1 The Customer shall have the right to use the Service for its internal operations in accordance with these Terms.
7.2 The Customer or the User shall not resell or otherwise distribute the Service to third parties without a separate agreement.
7.3 The Customer shall be responsible for procuring and maintaining the equipment, connections, software, and operating environment required to use the Service. The Customer shall ensure that these meet the requirements specified by the Supplier and that the Service is suitable for the Customer’s needs.
7.4 Unless otherwise agreed, the Service is hosted on a server maintained by the Supplier or a third party. The Customer shall ensure that neither it nor any Users designated by it attempt to copy the Service, examine, modify, or copy its source code, interfere with the operation of the Service, or gain unauthorized access to the database, customer data, or data stored by other customers.
7.5 The Customer shall not permit the use of the Service in any country where export control laws, restrictions on use, or additional requirements applicable to the Service differ from those under Finnish law.
7.6 The Customer shall be responsible for the use of the Service, the content of the Data stored, and any exchange of data carried out through the Service.