01Subject matter and scope
These General Terms and Conditions of Service (the “General Terms”) govern the provision, by Ciberseg — Consultoria em Soluções Informáticas, Sociedade Unipessoal, Lda (“Ciberseg”), of managed cybersecurity services and further information-technology services to its business customers.
Ciberseg’s customer is exclusively the reseller or managed service provider (MSP) that contracts for the Services in order to resell them or integrate them into the services it provides to its own end customers (the “End Customers”). These General Terms apply only to business customers and not to consumers.
Ciberseg provides the Services from the Republic of Cape Verde. The available categories of Services comprise, as agreed in the Order Form: managed cybersecurity (including the 24/7 Managed SOC service), software development, IT consulting, data and artificial intelligence, and governance, risk and compliance.
02Definitions
“Framework Agreement” means the signed framework agreement between the Parties; “Order Form” means the document specifying the Services, plans, volumes and prices; “SLA” means the Service Level Agreement; “AVV/DPA” means the data processing agreement.
“Services” means the services provided by Ciberseg under the Framework Agreement and the Order Form; “SOC” means Ciberseg’s security operations centre; “Security Incident” means a confirmed security event affecting or potentially affecting the confidentiality, integrity or availability of the monitored systems.
03Contract documents and precedence
The contractual relationship is composed, in descending order of precedence, of the following documents: (a) the Framework Agreement; (b) the Order Form; (c) the SLA; (d) the AVV/DPA (always prevailing for data protection matters); (e) the Invoice and Payment Terms; (f) these General Terms.
The Customer’s conflicting or deviating general or purchasing terms do not become part of the contract, even if Ciberseg renders the Services without reservation while aware of them.
04Formation of the contract
The contract is deemed concluded upon signature of the Framework Agreement and the relevant Order Form by both Parties, or upon commencement of the Services by Ciberseg following an accepted Order Form.
Ciberseg’s proposals are valid for 30 days unless stated otherwise. Changes to the scope of Services are made through an additional Order Form or a change request approved in writing.
05Provision of the Services and service levels
Ciberseg provides the Services with the diligence and professional skill required of a specialised provider in the sector. Unless expressly stipulated otherwise, Ciberseg’s obligations are obligations of means and not of result.
Service levels, response times and coverage windows are set out in the SLA. SOC coverage windows depend on the contracted plan: 8×5 for the Starter, Business and Professional plans; 24×5 from the Professional+ plan; and 24×7 for the Enterprise plan.
Ciberseg may carry out scheduled maintenance, notified with reasonable advance notice, and emergency maintenance where necessary to preserve the security or integrity of the Services.
06Onboarding and technical requirements
Provision of the Services presupposes completion of the onboarding process, including deployment of the necessary agents, connectors and data sources. Activation timelines depend on the Customer’s timely cooperation and on compliance with the communicated technical requirements.
The Customer ensures that it holds the rights and authorisations necessary to enable Ciberseg to access, monitor and process the systems and data covered by the Services.
07Customer obligations and cooperation
The Customer cooperates in good faith with Ciberseg, in particular by providing accurate and complete information, the necessary accesses, a competent point of contact and timely approval of actions requiring authorisation.
The Customer uses the Services in compliance with applicable law and does not use them for unlawful purposes nor in a manner that compromises the security or integrity of Ciberseg’s or third parties’ infrastructure.
The Customer is solely responsible for its contractual relationship with the End Customers, including providing information, obtaining consents and complying with legal obligations towards them. Ciberseg assumes no direct obligation towards the End Customers.
08Reseller (white-label) model
The Services are supplied on a wholesale basis and are intended for resale by the Customer in its own name and for its own account. The Customer may present the Services under its own brand, within the terms and limits agreed in writing.
The Customer shall not, on behalf of Ciberseg, make representations, warranties or service-level commitments exceeding those set out in the SLA, and is responsible towards the End Customers for any additional commitments it undertakes.
09Third-party licences and tooling
Provision of the Services may rely on third-party software, platforms and resources. Third-party licences passed through to the Customer are subject to the respective vendors’ terms, which the Customer undertakes to comply with and to have complied with by the End Customers.
Ciberseg may replace technical components with others of equivalent quality and function, provided this does not materially reduce the level of the Services.
10Prices and payment
Prices are set out in the Order Form. Invoicing and payment are governed by Ciberseg’s Invoice and Payment Terms, which form part of the contractual relationship.
Unless the Order Form provides otherwise, recurring Services are invoiced monthly in advance, and prices are net amounts in Euro, exclusive of applicable taxes.
11Intellectual property
Ciberseg retains all intellectual property rights in its methodologies, tools, software, templates, playbooks and know-how, whether pre-existing or developed in the course of providing the Services.
During the term of the contract, Ciberseg grants the Customer a non-exclusive, non-transferable and limited licence, as necessary to use the Services and their outputs, for the purposes set out in the contract.
For software developments specifically commissioned and fully paid for, ownership of or licence to the outputs is governed by the relevant Order Form.
12Confidentiality
Each Party keeps confidential the other Party’s information to which it has access under the contract and uses it exclusively for the performance thereof. This obligation continues for 3 years after termination of the contract and, as regards trade secrets, for as long as the information retains such nature.
Disclosures required by law or by a competent authority are excepted; the bound Party shall, where legally permissible, inform the other Party in advance.
13Data protection and transfers
In the provision of the Services, Ciberseg acts as processor (Auftragsverarbeiter) or sub-processor (Unterauftragsverarbeiter) of the Customer. The processing of personal data is governed exclusively by the AVV/DPA, which prevails over these General Terms in data protection matters.
End Customer data is stored exclusively in Germany. Access by Ciberseg’s analysts from Cape Verde, for monitoring and response purposes, constitutes a transfer of data to a third country within the meaning of articles 44 et seq. of the GDPR.
That transfer relies, primarily, on the European Commission’s adequacy decision regarding Cape Verde (article 45 GDPR) and, subsidiarily, on the Standard Contractual Clauses, Module 3, and the appropriate safeguards set out in the AVV/DPA.
14Security and incident response
Ciberseg monitors the systems in scope and responds to Security Incidents in accordance with the SLA and the agreed playbooks, notifying the Customer of confirmed Incidents without undue delay.
Ciberseg implements technical and organisational measures appropriate to the state of the art. No security measure eliminates risk entirely; Ciberseg does not warrant that all attacks or incidents will be prevented or detected.
15Warranties and conformity of the Services
Ciberseg warrants that the Services are provided in substantial conformity with the Order Form and the SLA. In the event of non-conformity attributable to Ciberseg, it shall, within a reasonable period, remedy or re-perform the affected Service.
Implied warranties not expressly assumed in the contract are excluded to the extent legally permitted. The service credits provided for in the SLA constitute the agreed remedy for the service-level failures regulated therein.
16Liability
Ciberseg’s total aggregate liability arising under the contract, per contract year, is limited to the amount of fees paid by the Customer to Ciberseg in the 12 months preceding the triggering event, save in the cases set out in clause 16.3.
Ciberseg is not liable for indirect damages, loss of profit, loss of data not attributable to intent or gross negligence, loss of goodwill or reputational damage.
The limitations and exclusions in this clause do not apply in cases of intent or gross negligence, of harm caused to life, physical integrity or health, nor in the further cases in which mandatory law does not permit limitation of liability.
Any claim for damages must be brought within 12 months of becoming aware of the fact giving rise to it, without prejudice to mandatory statutory limitation periods.
17Indemnification
The Customer holds Ciberseg harmless from third-party claims, including by End Customers, arising from use of the Services in breach of the contract or the law, or from commitments undertaken by the Customer beyond those set out in the SLA.
18Suspension of the Services
Ciberseg may suspend the Services, in whole or in part, upon written notice, in the event of material payment default, of use that threatens the security of the infrastructure, or of a legal requirement.
Suspension does not extend to measures required to handle a Security Incident ongoing at the time of suspension and to hand over operational responsibility in an orderly manner. Suspension does not release the Customer from obligations already due.
19Term and termination
The contract runs for the term stated in the Order Form, with a minimum initial term of 12 months, renewing automatically for 12-month periods, unless terminated by either Party with 3 months’ notice before the end of the current period.
Either Party may terminate the contract, for cause, in the event of a material breach not remedied within 30 days of written notice, or of the other Party’s insolvency.
Upon termination, Ciberseg provides, on request and against payment of reasonable costs, transition assistance for a period of up to 30 days and returns or deletes the Customer’s data in accordance with the AVV/DPA.
20Force majeure
Neither Party is liable for non-performance resulting from force majeure, understood as an unforeseeable event beyond its reasonable control, including natural disasters, widespread power or telecommunications outages, acts of authority and large-scale cyberattacks on third-party infrastructure.
The affected Party informs the other without delay and uses reasonable efforts to mitigate the effects. Where force majeure persists for more than 60 days, either Party may terminate the affected part of the contract.
21Subcontracting and assignment
Ciberseg may use subcontractors in providing the Services, remaining responsible for their conduct; sub-processing of personal data is governed by the AVV/DPA.
Ciberseg may assign the contract or the receivables arising from it in the context of a corporate reorganisation or financing, upon notice to the Customer. The Customer may assign its contractual position only with Ciberseg’s prior written consent.
22Amendments
Ciberseg may amend these General Terms and the SLA for objective reasons, in particular technical developments, legal or security requirements, upon 30 days’ notice to the Customer. If the amendment significantly disadvantages the Customer, the Customer may terminate the contract up to the date the amendment takes effect.
Amendments to the Order Form and the Framework Agreement require the written agreement of both Parties.
23Notices
Notices of contractual relevance are made in writing, to the contacts stated in the Framework Agreement, text form (including e-mail) being deemed sufficient, save where the contract requires signed written form.
24Governing law and dispute resolution
The contract is governed by the laws of the Republic of Cape Verde, excluding its conflict-of-law rules and the UN Convention on Contracts for the International Sale of Goods.
The courts of Mindelo, São Vicente, have jurisdiction. Alternatively, the Parties may agree in the Framework Agreement that disputes be finally settled by arbitration, with the arbitral institution, the seat and the language of the proceedings specified in that agreement.
25Final provisions
The Framework Agreement, the Order Forms, the SLA, the AVV/DPA, the Invoice and Payment Terms and these General Terms constitute the entire agreement between the Parties as to their subject matter.
The invalidity of any provision does not affect the validity of the remaining provisions, the invalid provision being replaced by one that approximates the intended economic result. Amendments to these Terms require written form.
The Portuguese version prevails; the English version is provided for ease of understanding.