CONSUMER TERMS OF SALE
AND USE

PREAMBLE

These Consumer Terms of Sale and Use (the “Terms”) govern contracts entered into between CSQUARE CONNECTING KNOWLEDGE, operator of the VESTA solution (“CSQUARE”, the “Supplier”, “we” or “us”), and any natural person acting for purposes outside his or her trade, business, craft, profession or agricultural activity (the “Consumer” or “you”).

VESTA is a cybersecurity solution designed to strengthen the protection of sensitive files and data through authorization, encryption, cryptographic controls, integrity verification, logging, backup, recovery and, depending on the selected plan, HSM services or hardware.

No cybersecurity solution can eliminate all information-security risks. VESTA is an additional protection layer and does not replace the security measures normally expected for the Consumer’s devices, accounts, networks and backups.

1. SUPPLIER IDENTITY

CSQUARE CONNECTING KNOWLEDGE, a French société à responsabilité limitée (SARL) with share capital of EUR 10,000, registered office at 17 rue Gazagne, 31300 Toulouse, France, registered with the Toulouse Trade and Companies Register (RCS) under number 511 894 214, SIRET 511 894 214 00010, intra-Community VAT number FR91 511894214.

Website: https://www.vestasafety.eu.

Consumer contact — email: jlchaptal@csquare.fr

Any complaint, statutory guarantee request, withdrawal notice or contractual query may be sent using the above contact details or any channel expressly identified at checkout.

2. SCOPE AND CONSUMER ELIGIBILITY

These Terms apply only to VESTA plans expressly offered to consumers for private use. They do not apply where VESTA is subscribed to for the purposes of a professional activity, even where the purchaser is a natural person or a sole practitioner.

The selected plan, VAT-inclusive price, duration, options, usage limits, any hardware supplied and support services are specified on the offer page and in the order summary.

3. CONTRACT DOCUMENTS

The contract consists, in descending order of priority, of the order summary and any specific terms, these Terms, the Privacy Policy where applicable to personal-data processing, and then the functional and technical documentation made available to the Consumer.

In the event of inconsistency, the higher-ranking document prevails, without prejudice to mandatory consumer rights. Marketing documents and demonstrations have contractual effect only for characteristics expressly incorporated into the order or required by law.

4. ESSENTIAL CHARACTERISTICS OF VESTA

Depending on the selected plan, VESTA may control access requests to protected objects, encrypt and decrypt files within a controlled perimeter, verify integrity and cryptographic consistency, manage cryptographic metadata, use HSMs or equivalent cryptographic services, log operations, manage service states, back up and restore protected objects and allow a temporary degraded mode where included in the plan.

Certain security decisions may cause VESTA deliberately to refuse an operation when the required security conditions are not met. A security refusal may constitute normal operation of the Service rather than a defect.

The applicable functionality, compatibility, interoperability, installation restrictions and hardware/software requirements are described before checkout and/or in the relevant documentation.

5. COMPATIBILITY, INSTALLATION AND DIGITAL ENVIRONMENT

Before ordering, the Consumer should verify that his or her devices and environment meet the announced prerequisites for the selected plan. Where installation or integration is carried out by or under the responsibility of CSQUARE, it will be performed within the subscribed scope.

Where the Consumer performs installation, the supplied instructions must be followed. The statutory conformity guarantee remains applicable where incorrect integration results from shortcomings in instructions supplied by the Supplier, as provided by law.

6. ACCOUNT, AUTHENTICATION AND CONSUMER SECURITY

The Consumer is responsible for keeping authentication means confidential and for use of the account, except for fraudulent use not attributable to the Consumer. The Consumer must promptly inform CSQUARE of any suspected compromise.

Where VESTA requires or offers multi-factor authentication, a security key or another enhanced mechanism, the Consumer must keep and use those means in accordance with the instructions and must not intentionally bypass VESTA security mechanisms.

7. CRYPTOGRAPHIC BOUNDARY AND HSM

VESTA is designed so that third-party applications and ordinary interfaces do not receive the internal cryptographic secrets required to protect objects. HSM secrets, root secrets, session material and non-exportable secrets are not supplied in usable form unless required by law or by an expressly agreed migration mechanism.

This architecture does not affect the Consumer’s right to recover his or her own data under the applicable exit and reversibility procedures. Where recovery requires protected objects to be transformed, this may be performed through a controlled cryptographic process rather than by disclosing internal secrets.

8. THIRD-PARTY SERVICES AND COMPONENTS

VESTA may rely on operating systems, hardware, HSMs, cloud or KMS services, certificate authorities, identity providers, network operators, payment processors, licensing services or other third-party components. CSQUARE remains responsible for its own statutory and contractual obligations and does not exclude liability that cannot legally be excluded.

The availability of a third-party component may nevertheless affect certain functions. CSQUARE will take reasonably available measures to limit the impact of incidents affecting dependencies under its control.

9. ORDER PROCESS AND CONTRACT FORMATION

Before the order is placed, the Consumer is provided with the essential information about the plan, total VAT-inclusive price, duration, payment terms, relevant functionality and compatibility, any restrictions, cancellation arrangements, withdrawal rights and statutory guarantees.

The Consumer may review and correct the order before confirming it. The contract is formed when the Consumer confirms the order through an action clearly indicating an obligation to pay and CSQUARE acknowledges receipt on a durable medium, subject to acceptance of the payment method.

The version of the Terms accepted at checkout is retained with the order or made available on a durable medium.

10. PRICES, TAXES AND PAYMENT

Consumer prices are displayed inclusive of applicable taxes before the order is concluded. Any additional charges, including delivery charges for optional hardware, are shown before payment.

Payment is made using the methods offered at checkout. For subscriptions, billing dates and frequency are stated in the order summary. No charge not disclosed before checkout may be imposed on the Consumer.

11. TERM, RENEWAL AND NON-RENEWAL

The subscription term is stated in the offer and order summary. Where a fixed-term service contract renews automatically, CSQUARE informs the Consumer of the possibility of non-renewal within the time and manner required by Article L. 215-1 of the French Consumer Code.

Where a plan has no minimum commitment and is billed periodically, the Consumer may cancel it under the arrangements disclosed at checkout. Cancellation stops future billing, subject to any current period where permitted by law and the contract.

12. ELECTRONIC CANCELLATION

Where the contract was concluded electronically, or CSQUARE allows contracts to be concluded electronically at the date of cancellation, CSQUARE provides a free online function enabling the Consumer to carry out the notification and steps required to cancel the contract, in accordance with Article L. 215-1-1 of the French Consumer Code.

This online function does not prevent the Consumer from using any other cancellation method permitted by the contract or by law.

13. RIGHT OF WITHDRAWAL — DISTANCE CONTRACTS

Unless a statutory exception applies, the Consumer has fourteen (14) days from conclusion of a service contract concluded at a distance to withdraw without giving reasons.

For optional physical goods, the withdrawal period generally runs from receipt of the goods, subject to the rules of the French Consumer Code.

The Consumer may withdraw using the form in Annex C or any unambiguous statement expressing the decision to withdraw. The financial consequences and reimbursement rules are those provided by Articles L. 221-18 et seq. of the French Consumer Code.

14. STARTING THE SERVICE BEFORE THE WITHDRAWAL PERIOD EXPIRES

If the Consumer expressly requests that a paid service begin before the withdrawal period expires, CSQUARE records that express request. If the Consumer then withdraws before full performance, the Consumer may owe an amount proportionate to the service supplied up to withdrawal, as provided by law.

Where supply of digital content not supplied on a tangible medium falls within a statutory exception to the right of withdrawal, the right is lost only if the conditions in Article L. 221-28 of the French Consumer Code are satisfied, including prior express consent, acknowledgment of the loss of the right and the required contractual confirmation.

No checkbox relating to waiver of withdrawal or immediate performance shall be pre-ticked.

15. OPTIONAL HARDWARE — HSM OR SECURITY DEVICE

Where a plan includes the sale of an HSM, security key or other hardware, the item description, VAT-inclusive price, delivery costs and times and any specific conditions are disclosed before checkout.

Risk of loss or damage passes to the Consumer when the Consumer physically takes possession of the goods, subject to mandatory law. The Consumer benefits from all statutory guarantees applicable to consumer goods.

Where withdrawal concerns goods, return arrangements and any direct return costs payable by the Consumer are disclosed before the order in accordance with law.

16. MAINTENANCE, UPDATES AND CHANGES

CSQUARE may deploy corrective, security, compatibility and feature updates. Updates necessary to keep the digital service in conformity are supplied and brought to the Consumer’s attention for the period required by law.

If the Consumer fails to install a necessary update within a reasonable time after being informed of its availability and the consequences of not installing it, the rules in Article L. 224-25-25 of the French Consumer Code may apply.

Any change to the Service during the contract complies with mandatory rules applicable to digital services and does not deprive the Consumer of statutory remedies.

17. AVAILABILITY, FAIL-CLOSED OPERATION AND SECURITY EMERGENCIES

VESTA may refuse an operation if a mandatory security element is missing, invalid, expired, inconsistent or unavailable. Examples include insufficient authentication, an unauthorized device, invalid certificate, integrity failure, replay detection, required HSM unavailability or expiry of degraded-mode authorization.

Where there is a serious security risk, CSQUARE may take proportionate protective measures, including temporary restrictions, to prevent compromise, attack propagation, data destruction or exposure of secrets. The Service will be restored when the required security conditions are met again.

These measures do not limit the Consumer’s rights under the statutory conformity guarantee where applicable.

18. BACKUP, RESTORE AND REVERSIBILITY

Backup or restoration services are provided only where included in the plan. A VESTA backup may retain protected objects together with the metadata and cryptographic references required for restoration; a backup does not itself constitute a decryption right.

Where backup is not included, the Consumer remains responsible for independent copies to the extent reasonably expected of a private user. This does not exclude any mandatory rights arising from a lack of conformity of the Service.

At the end of the contract, the Consumer must have a reasonable way to recover his or her data under the reversibility functions offered by the subscribed architecture. Reversibility does not include disclosure of internal or non-exportable cryptographic secrets.

19. PERSONAL DATA AND PRIVACY

CSQUARE processes personal data required for account administration, ordering, payment, support, security, abuse prevention and, where relevant, technical provision of VESTA in accordance with the GDPR and applicable French law.

Purposes, legal bases, data categories, recipients, retention periods, any transfers and data-subject rights are described in the Privacy Policy available on the Site. Unless the plan expressly states otherwise, personal data are not the economic consideration for the Service.

The protected file content remains the Consumer’s content. CSQUARE does not acquire ownership rights in that content merely by supplying VESTA.

20. STATUTORY CONFORMITY GUARANTEE — DIGITAL SERVICES

Where VESTA constitutes digital content or a digital service supplied to the Consumer, it benefits from the statutory conformity guarantee under Articles L. 224-25-12 et seq. of the French Consumer Code.

The statutory notice for continuous digital-service supply is reproduced in Annex D. The guarantee applies throughout the period during which the digital service is supplied under the contract. If several subscription periods are offered, the pre-contract information and notice supplied to the Consumer must identify the period corresponding to the selected plan.

21. HIDDEN-DEFECT WARRANTY

Independently of the statutory conformity guarantee, the Consumer benefits, where its legal conditions are satisfied, from the French-law warranty against hidden defects under Articles 1641 to 1649 of the Civil Code, within the statutory time limits.

22. SUPPORT AND COMPLAINTS

Support arrangements included in the plan are disclosed before checkout. Any support response times are response/handling targets unless an express resolution deadline is guaranteed.

Complaints may be sent to: jlchaptal@csquare.fr or CSQUARE CONNECTING KNOWLEDGE, 17 rue Gazagne, 31300 Toulouse, France. CSQUARE will respond within a reasonable time having regard to the nature of the request.

23. LIABILITY

CSQUARE is liable for breaches attributable to it under applicable law. Nothing in the contract excludes or limits a right or liability where such exclusion or limitation is prohibited by mandatory consumer law.

The occurrence of a cyberattack, ransomware event, credential theft, vulnerability or third-party incident does not by itself establish a breach by CSQUARE. Liability is assessed by reference to the applicable obligations, circumstances and causal link.

Where loss results exclusively from Consumer conduct contrary to security instructions, an unauthorized modification or an environment outside CSQUARE’s control, that circumstance may be taken into account to the extent of its causal contribution, without depriving the Consumer of mandatory rights.

24. NO ABSOLUTE SECURITY GUARANTEE

Information security is an evolving field. No software, cryptographic mechanism, HSM, authentication system, network or infrastructure can be guaranteed to be invulnerable. VESTA is intended to reduce certain risks but does not guarantee the absence of every cyberattack, data leak, ransomware event, unknown vulnerability, outage or human error.

This clause describes the nature of information-security risk and does not limit the statutory conformity guarantee or other mandatory Consumer rights.

25. FORCE MAJEURE

Neither Party is liable for non-performance where the legal conditions of force majeure are satisfied. A cyberattack, cloud outage or network incident is not automatically force majeure; classification depends on the statutory criteria and the circumstances.

The affected Party will inform the other within a reasonable time and take appropriate steps to mitigate the effects.

26. INTELLECTUAL PROPERTY

VESTA, its documentation, architecture, code, interfaces, trademarks, methods, components and cryptographic elements remain the property of CSQUARE or their respective owners. The contract grants the Consumer a personal, non-exclusive right to use VESTA limited to the term and scope of the subscribed plan.

The Consumer must not bypass licensing or security mechanisms, make VESTA available to unauthorized third parties or attempt to extract source code, subject to mandatory rights recognized by law, including interoperability rights.

27. SUSPENSION OR TERMINATION FOR BREACH

In the event of fraudulent use, intentional circumvention of security mechanisms or a serious threat to the security of the Service, CSQUARE may impose a proportionate restriction or suspension and will inform the Consumer as soon as circumstances permit.

For a contractual breach capable of remedy, termination for breach will follow a formal notice that remains unremedied for a reasonable period, unless urgency or impossibility of cure justifies otherwise. Mandatory Consumer rights remain unaffected.

28. END OF CONTRACT AND DATA

Termination ends the right to use paid features covered by the plan. CSQUARE applies the return, recovery or deletion arrangements provided by the contract, Privacy Policy and law.

Before permanently deleting elements whose disappearance would make recovery of protected objects impossible, CSQUARE applies the reversibility or notification procedure provided by the plan and applicable legal obligations.

29. CONSUMER MEDIATION

After first submitting a written complaint to CSQUARE and where no satisfactory solution has been reached, the Consumer may use, free of charge, the consumer mediator competent for CSQUARE, in accordance with Articles L. 612-1 et seq. of the French Consumer Code.

Competent mediator:

SAS Médiation Solution
222 chemin de la Bergerie
01800 Saint-Jean-de-Niost — France

Téléphone : +33 (0)4 82 53 93 06
E-mail : contact@sasmediationsolution-conso.fr

Mediation is optional for the Consumer and does not prevent the Consumer from bringing a claim before a competent court.

30. GOVERNING LAW AND JURISDICTION

The contract is governed by French law, without prejudice to any more protective mandatory provisions that may apply to a Consumer resident in another country.

For disputes, the Consumer may bring proceedings before any court with jurisdiction under ordinary procedural rules and, in particular, the court for the place where the Consumer resided when the contract was concluded or when the harmful event occurred, as provided by Article R. 631-3 of the French Consumer Code.

31. CHANGES TO THESE TERMS

The applicable version is the version accepted when the order is placed. CSQUARE may amend these Terms for future contracts. For an ongoing contract, an amendment is binding only under the conditions permitted by law and the contract, with the required information and, where applicable, rights to refuse or terminate.

Changes required for security or regulatory compliance are implemented proportionately and do not deprive the Consumer of statutory rights.

32. GENERAL PROVISIONS AND ACCEPTANCE

If a provision is held invalid or unenforceable, the remaining provisions continue to apply to the extent permitted by law. Failure to exercise a right immediately does not constitute a waiver.

Confirmation of the order after these Terms have been made available and after explicit confirmation of the obligation to pay constitutes acceptance of the applicable version, subject to rights that the Consumer cannot legally waive.

ANNEX A — CONSUMER CYBERSECURITY BASELINE

To reduce risk and allow VESTA to operate as intended, the Consumer should in particular:

·        Keep supported operating systems and security software up to date.

·        Use a strong password and, where offered or required, multi-factor authentication.

·        Do not share individual accounts or personal security keys.

·        Physically protect devices, media and any HSM under the Consumer’s custody.

·        Do not intentionally disable VESTA security controls.

·        Maintain reasonable network and anti-malware protection where appropriate for the device.

·        Keep independent backups of important data where VESTA backup is not included.

·        Promptly report loss, compromise or anomalies that may affect account or data security.

ANNEX B — PERSONAL DATA

This Annex summarizes the principles applicable to personal data under the contract. It does not replace the Privacy Policy, which describes processing carried out by CSQUARE as controller for service administration, customer relations, support, security, billing and legal obligations.

Where technical operations require personal-data processing to provide VESTA, CSQUARE applies data minimization, access limitation, security and proportionate retention principles. Exact data categories and any processors are identified in the Privacy Policy.

The Consumer may exercise rights of access, rectification, erasure, restriction, objection and, where the legal conditions are met, portability using the contact identified in the Privacy Policy. The Consumer may also lodge a complaint with the French data-protection authority (CNIL).

ANNEX C — MODEL WITHDRAWAL FORM

WITHDRAWAL FORM

(Complete and return this form only if you wish to withdraw from the contract.)

To: CSQUARE CONNECTING KNOWLEDGE, 17 rue Gazagne, 31300 Toulouse, France — email: jlchaptal@csquare.fr

I/We (*) hereby give notice that I/we (*) withdraw from my/our (*) contract for the sale of the following goods (*) / provision of the following service (*):

Ordered on (*) / received on (*): ______________________________

Name of consumer(s): _________________________________________

Address of consumer(s): _______________________________________

Signature of consumer(s) (only if this form is notified on paper): ______________________________

Date: ______________________________

(*) Delete as appropriate.