GENERAL TERMS AND CONDITIONS OF SALE
AND B2B USE OF VESTA

PREAMBLE

These General Terms and Conditions of Sale and Use, hereinafter the “Terms”, govern the contractual relationship between:

CSQUARE CONNECTING KNOWLEDGE, a French société à responsabilité limitée (SARL - limited liability company) with share capital of EUR 10,000, having its registered office at 17 rue Gazagne, 31300 Toulouse, France, registered with the Toulouse Trade and Companies Register under number 511 894 214 (SIREN 511 894 214 - SIRET 511 894 214 00010 - intra-Community VAT number FR91 511894214), operating the VESTA cybersecurity solution, hereinafter the “Supplier”,

and

any professional customer subscribing to the VESTA Services, hereinafter the “Client”.

The Supplier and the Client are each a “Party” and together the “Parties”.

VESTA is a cybersecurity solution intended to strengthen the protection of files and sensitive data. In particular, VESTA acts as a local security gateway between a business application, users, the Client’s IT environment and protected objects.

Depending on the modules and options subscribed to, VESTA implements contextual authorisation, encryption, cryptographic control, integrity verification, logging, use of HSM hardware modules or security services, backup, restoration and degraded-mode operation.

The Parties expressly acknowledge that no cybersecurity solution can eliminate all risks associated with the use of information systems.

Use of VESTA forms part of the Client’s security policy and does not replace either the security measures that must be applied to its information system or the regulatory obligations applicable to the Client.

1. PURPOSE

These Terms define the conditions under which the Supplier grants the Client a right to use VESTA, provides the subscribed services and functions, provides maintenance, support and updates where applicable, and performs any additional services expressly specified in the Order Form.

The nature and scope of the Services, the number of sites, users, options, service level, backup functions, degraded mode, HSM services, support and any specific services are defined in the Order Form.

Any feature not expressly included in the Order Form shall be deemed not subscribed to.

2. PROFESSIONAL CUSTOMERS

These Terms apply exclusively to customers acting for purposes relating to their trade, business, craft, profession or agricultural activity. They do not apply to consumers purchasing VESTA for private use. These Terms are not intended for consumers.

The Client represents that it has the skills, organisation and resources necessary to operate a professional information system and to secure those elements of its information system that remain under its control.

3. CONTRACTUAL DOCUMENTS

The Agreement consists of the following documents, in descending order of priority:

1. the Order Form or Special Terms;

2. any schedules negotiated and signed by the Parties;

3. the Personal Data Processing Schedule, where applicable;

4. any SLA or service-level commitment;

5. the Security Schedule;

6. these Terms;

7. the applicable functional documentation;

8. the technical specifications and interface agreements applicable to the integration.

For software interfaces, the versioned API contract, when provided to the Client or its application software provider, constitutes the technical implementation contract.

In the event of a conflict, the higher-ranking document shall prevail.

Commercial documents, presentations, brochures, demonstrations, websites and marketing statements have no contractual effect unless expressly incorporated into the Order Form.

4. GENERAL DESCRIPTION OF VESTA

VESTA is a security gateway intended in particular to:

• control requests for access to protected objects;

• take into account the user, session, endpoint, application, object and policy context;

• encrypt and decrypt files within a controlled perimeter;

• verify the integrity and cryptographic consistency of objects;

• manage the cryptographic metadata required for operation of the Service;

• call upon multiple cryptographic control points where the subscribed architecture provides for this;

• use HSMs or equivalent cryptographic services;

• provide logging and traceability of operations;

• manage Service availability and security states;

• manage backup and restoration functions where subscribed to;

• allow temporary operation in degraded mode where configured and authorised in advance.

The architecture is designed so that the Client’s business application does not receive the internal cryptographic secrets required to protect objects.

The Client acknowledges that certain security decisions may cause VESTA intentionally to refuse an operation where the required security conditions are not met. Such refusal is the normal operation of a security mechanism and does not, in itself, constitute a failure of the Service.

5. CRYPTOGRAPHIC RESPONSIBILITY BOUNDARY

The Supplier retains control over the internal cryptographic operations required for VESTA to operate.

Unless otherwise required by law or expressly provided for by a migration mechanism:

• no internal cryptographic secret is disclosed to the Client;

• no internal cryptographic secret is disclosed to the business application;

• no cryptographic value capable of bypassing the authorisation mechanism may be recorded in ordinary logs, interfaces or application files;

• information transmitted to third-party applications is limited to authorisation decisions, opaque identifiers, statuses, references and technical data required for operation.

The Client may not require disclosure in usable form of HSM secrets, root secrets, session secrets, transient cryptographic material or protected cryptographic material.

This provision does not affect the Client’s right to recover its own data in accordance with the reversibility procedures set out in the Agreement.

6. NO GUARANTEE OF ABSOLUTE SECURITY

The Client expressly acknowledges that:

1. information security is an evolving field;

2. new vulnerabilities, attack techniques and bypass methods emerge regularly;

3. no software, cryptographic mechanism, HSM, authentication system, network or IT infrastructure can be guaranteed to be invulnerable;

4. encryption reduces certain risks but does not eliminate all risks of unauthorised access, unavailability, corruption or loss;

5. effective security also depends on the operating system, equipment, users, accounts, networks, third-party software and procedures operated by the Client.

Unless expressly stated otherwise in the Order Form, the Supplier does not warrant that VESTA will:

• prevent every cyberattack;

• prevent every data leak;

• prevent every ransomware infection;

• detect every malicious activity;

• withstand every unknown vulnerability;

• prevent every compromise of a privileged account;

• prevent every human error;

• prevent every malicious act by an authorised user;

• ensure permanent availability;

• make the Client’s information system compliant with all regulations applicable to it.

The Supplier nevertheless undertakes to provide the Services in accordance with the contractual provisions and the legal obligations applicable to it.

7. NATURE OF THE SUPPLIER’S OBLIGATIONS

Except where a mandatory legal obligation or an express contractual provision requires a specific result, the Supplier’s obligations are obligations of reasonable endeavours (obligations de moyens under French law).

The Supplier implements technical and organisational measures reasonably appropriate to the nature of the Service, the state of available knowledge, identified risks, subscribed features and the resources and information reasonably available.

The Supplier assumes no general duty to monitor the Client’s information system beyond the scope of VESTA.

8. GENERAL OBLIGATIONS OF THE CLIENT

The Client remains responsible for the administration and security of resources under its control. In particular, it undertakes to:

• comply with the technical prerequisites communicated by the Supplier;

• use supported operating systems and software;

• apply appropriate security patches and updates;

• maintain the necessary antivirus, EDR, firewall and equivalent protection mechanisms;

• apply the principle of least privilege;

• restrict administrator rights to persons who strictly need them;

• protect administrator accounts;

• implement multi-factor authentication where required or reasonably necessary;

• physically protect workstations, servers, equipment and HSMs for which it is responsible;

• protect its network and remote access;

• ensure the security of third-party software connected to VESTA;

• protect certificates, credentials, service accounts and authentication mechanisms under its responsibility;

• maintain independent backups where these are not part of the subscribed Services;

• maintain a disaster-recovery organisation appropriate to its risks;

• promptly inform the Supplier of any incident likely to affect VESTA;

• not disable the logging and protection mechanisms required for the Service;

• cooperate reasonably in any security investigation;

• apply urgent security instructions communicated by the Supplier.

9. INFORMATION AND CONTEXT PROVIDED BY THE CLIENT

Operation of VESTA may depend on information originating from the Client or its business application, including the user’s identity and role, the endpoint, session and access context, object identifiers, business authorisations, sharing information, file references and the state of the system or application.

The Client is responsible for the accuracy and integrity of information that it provides, or causes to be provided, to VESTA.

The Supplier is not liable for consequences resulting from false, falsified, incomplete or inconsistent information originating from the Client’s system, except where the Supplier should reasonably have detected the anomaly through a control expressly provided for by the Service.

10. SECURITY PROHIBITIONS

The Client shall in particular refrain from:

• bypassing a VESTA authorisation mechanism;

• intentionally altering protected cryptographic data or metadata;

• extracting or attempting to extract cryptographic secrets;

• disabling a security control mechanism;

• using an authorisation identifier outside its intended purpose;

• artificially reproducing or replaying security requests;

• altering security logs;

• intentionally introducing malicious software;

• allowing an unauthorised application to impersonate the approved business application;

• carrying out penetration tests liable to affect a production system without prior agreement on the scope of the test.

Legitimate vulnerability research is permitted where it complies with the responsible disclosure procedure or the testing protocol agreed with the Supplier.

11. CONSEQUENCES OF A CLIENT SECURITY BREACH

If the Client fails to comply with a security obligation having an actual or potential impact on VESTA, the Supplier may:

1. require immediate remediation of the risk;

2. restrict a feature;

3. suspend an authorisation, account, endpoint or site;

4. require re-authentication;

5. revoke authorisations or certificates;

6. temporarily suspend all or part of the Service where reasonably necessary to protect data, infrastructure, the Client, other clients or the Supplier.

In a security emergency, such suspension may occur without prior notice. The Supplier shall inform the Client as soon as reasonably compatible with management of the incident.

The Supplier shall not be liable for the portion of any loss directly caused or aggravated by the Client’s failure to comply with its contractual or security obligations.

12. IDENTITY AND AUTHORISATION MANAGEMENT

Rights assigned to users remain under the Client’s responsibility unless their administration is expressly entrusted to the Supplier.

The Client is responsible for creating and deleting users, correctly assigning roles, removing accounts of persons who have left the organisation, protecting authentication means, declaring authorised endpoints and ensuring consistency of the business rights transmitted to VESTA.

An authorisation originating from the business application does not necessarily constitute a VESTA authorisation. VESTA may refuse an operation that the business application has authorised if VESTA’s own security conditions are not satisfied.

13. FAIL-CLOSED OPERATION AND SECURITY ACCESS DENIAL

The Client acknowledges that VESTA’s operating principle may require refusal of an operation where a mandatory security element is missing, invalid, expired, inconsistent or unavailable.

A refusal may result in particular from:

• insufficient authentication;

• an unsatisfied policy;

• an expired session;

• an unauthorised endpoint;

• an invalid certificate;

• inconsistent metadata;

• failure of an integrity check;

• replay detection;

• absence of a required HSM component;

• corruption of an object;

• absence of a required cryptographic reference;

• unavailability of a mandatory security log;

• expiry of a degraded-mode authorisation.

Such refusal constitutes a protective measure and shall not be treated as data loss.

14. OFFLINE OR DEGRADED MODE

Where this option is subscribed to, VESTA may provide a temporary degraded operating mode. This mode is not a permanent substitute for normal operation.

It may in particular be prepared in advance, limited to specified users, endpoints, sites, objects or operations, subject to a maximum duration or maximum number of operations, subject to local authentication and local logging, and followed by subsequent resynchronisation.

The Supplier may refuse activation or continued operation in degraded mode if the required security conditions are no longer met.

Inability to operate in degraded mode does not constitute non-performance where the contractual or technical conditions required for activation are not met.

15. THIRD-PARTY SERVICES

Operation of VESTA may rely on third-party components or services, including operating systems, IT hardware, HSMs, cloud services, KMS services, certification authorities, identity providers, network operators and third-party software components.

The Supplier selects and administers subcontractors under its control in accordance with the contractual and regulatory obligations applicable to it.

However, the Supplier cannot guarantee the complete absence of incidents affecting a third party. Where an incident originating from a third-party service affects VESTA, the Supplier shall take the reasonable actions available to limit its consequences.

This clause does not release the Supplier from any liability that mandatorily falls upon it as a result of the selection, administration or subcontracting of a component under its control.

16. MAINTENANCE AND UPDATES

The Supplier may carry out preventive, corrective, evolutionary or security maintenance.

Certain updates may be mandatory in order to maintain security, compatibility, regulatory compliance, support for third-party components or continuity of support.

The Client may not require indefinite maintenance of an obsolete version or a version containing a known vulnerability.

The Supplier may require an urgent update where continuing to use the previous version would create a significant security risk. Scheduled maintenance shall, where reasonably possible, be communicated in advance.

17. ZERO-DAY VULNERABILITIES

The existence or exploitation of a vulnerability unknown when the Service was designed or operated does not, by itself, constitute a fault by the Supplier.

When the Supplier becomes aware of a vulnerability materially affecting VESTA, it shall assess its impact and implement remediation or risk-reduction measures within a reasonable period, taking into account its severity, exploitability, the existence of a patch, the availability of a compensating measure and the risks associated with deploying the patch.

The Client undertakes to cooperate in deploying remedial measures that require intervention in its environment.

18. CYBERSECURITY INCIDENTS

Each Party shall inform the other without undue delay when it becomes aware of a security incident likely to have a significant impact on the Services, data or security of the other Party.

The Parties shall cooperate in good faith to characterise the incident, preserve evidence, contain the incident, identify its origin where reasonably possible, remediate the relevant vulnerabilities and comply with applicable regulatory obligations.

Discovery of an incident, intrusion or data leak does not, by itself, create a contractual presumption of fault by the Supplier.

Any liability of the Parties shall be determined by reference to their respective obligations, the circumstances, established faults and causation.

19. BACKUP

Backup services are provided only where expressly included in the Order Form.

Where VESTA backup is subscribed to, protected objects are backed up in their protected form together with the metadata, cryptographic references and elements required for restoration in accordance with the applicable policy.

A backup copy does not constitute a right of access to the data. After restoration, access to content remains subject to VESTA’s normal authorisation and security mechanisms.

Where backup services are not subscribed to, the Client remains fully responsible for its backup and disaster-recovery policy.

20. BACKUP STATUS

The Client acknowledges that a backup may have different states, including pending, in progress, completed locally, completed on secondary storage, awaiting remote replication, verified, partially completed, failed or non-restorable.

Merely starting a backup operation does not guarantee that restoration will be possible.

Where the Service exposes a backup or recoverability status, the Client must take that status into account in its business-continuity policy.

The Supplier is not liable for loss resulting from the Client’s deliberate disregard of an alert indicating that a backup is incomplete, unverified or failed.

21. RESTORATION

Any restoration is a controlled operation. It may require enhanced authorisation, justification, administrative approval, integrity verification, availability of the necessary cryptographic references, availability of required HSM components and a reconciliation procedure.

The Supplier does not warrant restoration of items that were never included within the backup scope or that the Client authorised to be permanently deleted.

Where technically possible, a restorability check may be offered without overwriting production data.

22. CLIENT RESPONSIBILITY FOR CONTINUITY

Even where a VESTA backup service is subscribed to, the Client remains responsible for defining its business requirements concerning RPO, RTO, retention period, business-continuity needs, data criticality, regulatory retention obligations and any copies or archives required independently of VESTA.

No specific RPO, RTO or SLA may be enforced against the Supplier unless expressly set out in a contractual document.

23. CLIENT DATA

The Client remains the owner of, or holder of the necessary rights in, the business data that it entrusts to or makes accessible to VESTA. The Supplier acquires no ownership rights in its content.

The Client warrants that it has the rights and legal bases necessary for such processing.

The Supplier retains its rights in VESTA, its code, architectures, algorithms, interfaces, security mechanisms, proprietary components, trade secrets and the cryptographic elements internal to the Service.

24. PERSONAL DATA

Where the Supplier processes personal data on behalf of the Client, the Client shall in principle act as controller and the Supplier as processor, unless the circumstances or applicable law require a different qualification.

For data processed by the Supplier for its own purposes, including commercial management, billing, management of its own customer accounts or internal security, the Supplier may act as a separate controller.

The roles of the Parties must be assessed on the basis of the processing actually carried out and cannot result solely from the title of the Agreement.

Where Article 28 GDPR applies, the provisions of the Personal Data Schedule form an integral part of the Agreement.

25. PRINCIPLES APPLICABLE TO PERSONAL DATA

When acting as processor, the Supplier undertakes in particular to:

• process data only on the Client’s documented instructions, subject to applicable legal obligations;

• ensure that persons authorised to process the data are bound by confidentiality;

• implement appropriate security measures;

• govern the use of sub-processors;

• reasonably assist the Client in handling data-subject rights;

• assist the Client in complying with its obligations concerning security and personal-data breaches;

• return or delete the data at the end of the services in accordance with the agreed conditions;

• provide the information necessary to demonstrate compliance with its obligations;

• allow audits required by law under reasonable security conditions.

Nothing in these Terms limits rights conferred directly on data subjects or supervisory authorities by mandatory provisions.

26. HEALTH DATA

Where the Services actually cause the Supplier to carry out an activity legally classified as hosting personal health data on behalf of the Client, the Parties shall apply the specific provisions required by applicable law.

No HDS certification, regulatory qualification or sector-specific compliance of the Supplier may be inferred from these Terms.

Any such certification or qualification is contractually warranted only if expressly stated in the Order Form together with its exact scope.

The Client remains responsible for verifying that its overall architecture, service providers and processing activities satisfy the regulatory requirements applicable to its business.

27. NO WARRANTY OF OVERALL COMPLIANCE

VESTA is a technical security measure.

Unless a consulting engagement is expressly subscribed to, the Supplier does not warrant that installing VESTA is sufficient to make the Client compliant with any particular regulation, standard, certification or framework.

Any reference to the GDPR, NIS2, CRA, HDS, ISO 27001, an ANSSI recommendation, a Zero Trust architecture or post-quantum resistance describes an objective, architecture or technical framework unless a specific compliance commitment is expressly warranted in the Order Form.

28. SUBCONTRACTORS

The Supplier may use subcontractors to perform certain functions of the Service.

Where a sub-processor processes personal data on behalf of the Client, its appointment shall be managed in accordance with the applicable GDPR requirements and the Personal Data Schedule.

The Supplier remains responsible for its own obligations to the Client in accordance with applicable law and the Agreement.

29. AUDITS

The Client may exercise audit rights granted to it by law or by the Agreement.

Except in the event of a major incident or a request from a competent authority, audits shall be organised so as not to unduly disrupt operations, to preserve the security of other clients, not to result in disclosure of cryptographic secrets, to protect trade secrets, to avoid access to source code unless specifically required by contract, and to give priority to available certification reports and documentary evidence where sufficient.

An on-site audit requested by the Client shall, unless a material breach by the Supplier is demonstrated, be carried out at the Client’s expense.

30. INTELLECTUAL PROPERTY

VESTA, its documentation, architecture, code, components, interfaces, trademarks, methods and cryptographic elements remain the property of the Supplier or their respective owners.

The Agreement grants the Client only a non-exclusive right of use, non-transferable except with written consent, limited to the term of the Agreement, limited to the subscribed scope and intended for the Client’s internal professional needs.

In particular, the Client shall not reproduce VESTA beyond copies permitted by law, make VESTA available to an unauthorised third party, attempt to extract its source code, bypass licence or security mechanisms, or create a derivative product from protected elements, without prejudice to rights mandatorily granted by law, including in relation to interoperability.

31. CONFIDENTIALITY

Each Party undertakes to keep confidential any non-public information received from the other Party that is technical, commercial, financial, organisational or security-related in nature.

Confidential information includes in particular detailed security architecture, audit results, vulnerabilities, technical identifiers, recovery procedures, HSM configurations, cryptographic information, trade secrets and non-public incident reports.

This obligation does not apply to information that the recipient can demonstrate was already public, lawfully known, lawfully obtained from a third party or independently developed.

Disclosure required by law or by a competent authority remains permitted.

32. PENETRATION TESTING AND TECHNICAL AUDITS

The Client may carry out, or have carried out, security tests on components that it owns.

Any test directly targeting infrastructure, cloud services, HSMs, production APIs or components operated by the Supplier must be coordinated in advance where the test may affect availability or security.

The Supplier may not rely on this provision to prohibit a legally required control or to prevent responsible disclosure of a vulnerability.

33. SUBSCRIPTION

VESTA is provided on a subscription basis. The initial term is specified in the Order Form.

If no term is specified, the subscription is entered into for one month, renews automatically for successive one-month periods, and either Party may terminate renewal by giving thirty days’ notice.

Where the Order Form provides for a minimum commitment period, that period shall prevail. Monthly billing does not necessarily mean that there is no minimum term where the Order Form expressly provides for a commitment.

34. PRICE

Prices are stated exclusive of tax. Applicable taxes are charged in addition.

The price depends in particular on sites, workstations, users, volumes, modules, HSM options, backup, support and installation and integration services.

Services not included in the subscription are billed separately.

35. PRICE REVISION

Unless otherwise provided in the Order Form, the subscription price may be revised annually in line with changes in the SYNTEC index or any successor index.

If the cost of a third-party component essential to the Service changes substantially and unforeseeably, the Supplier may propose a price adjustment.

Where such adjustment goes beyond ordinary contractual indexation and represents a significant increase, the Client may terminate the affected module before the new price takes effect, unless otherwise agreed.

36. BILLING AND PAYMENT

Subscriptions are billed monthly unless otherwise provided in the Order Form.

Invoices are payable within [30] days from the invoice date.

Any amount not paid when due shall automatically give rise to the late-payment penalties provided for by applicable law, the statutory fixed recovery-cost indemnity, and reimbursement of any justified additional recovery costs where legally permitted.

The Supplier may suspend the Services in the event of significant payment delay following a formal notice that remains without effect, subject to applicable mandatory rules.

37. SUSPENSION FOR NON-PAYMENT

Suspension for non-payment must not intentionally result in destruction of the Client’s data.

Where stopping the security Service could make certain objects temporarily inaccessible, the Supplier shall inform the Client before suspension where circumstances permit.

Suspension does not release the Client from its obligation to pay amounts due.

38. SERVICE LEVELS

Commitments concerning availability, response times, restoration times, RPO or RTO are binding on the Supplier only if set out in an SLA or the Order Form.

Support times are response/acknowledgement times unless a resolution time is expressly stated.

A resolution time cannot be guaranteed where resolution depends on a third-party publisher, an external patch, the Client, infrastructure outside the Supplier’s control or an ongoing security analysis.

Any service credits constitute the contractual mechanism provided for SLA deviations, without prejudice to liabilities that may not legally be limited.

39. TERMINATION FOR BREACH

If either Party commits a material breach of one of its obligations, the other Party may terminate the Agreement if the breach is not remedied within thirty days after formal notice.

This period is not required where the breach cannot be remedied, continuation of the Service would create a serious security risk, use is fraudulent, a criminal offence is reasonably suspected, a competent authority requires cessation, or an intentional violation of security mechanisms is identified.

40. REVERSIBILITY / EXIT ASSISTANCE

The Client is responsible for planning the recovery or migration of its data before the end of the Agreement.

Upon request and subject to payment of amounts due, the Supplier shall provide the reversibility services specified in the Order Form.

Depending on the architecture, reversibility may include return of business data, a controlled export, authorised decryption, migration to another architecture, secure re-enrolment of objects, export of required non-secret metadata and a closure report.

Reversibility does not include delivery of VESTA’s internal cryptographic secrets or non-exportable HSM secrets.

Where recovery requires transformation of protected objects, that transformation shall be performed through a controlled cryptographic procedure and not by disclosure of internal secrets.

41. END OF AGREEMENT AND DESTRUCTION

At the end of the reversibility period specified in the Order Form, the Supplier may delete or render permanently unusable Client-specific data and references that it is no longer legally or contractually required to retain.

Where deletion of certain security elements could make recovery of protected objects permanently impossible, the Client shall be informed in advance.

The Client is responsible for requesting and validating reversibility before that deadline.

42. SUPPLIER LIABILITY

The Supplier shall be liable only for a breach of a contractual or legal obligation attributable to it that has caused direct loss to the Client.

Unless a mandatory provision provides otherwise, the Client must establish the breach, the loss and the causal link between them.

The mere occurrence of a cyberattack, ransomware event, credential theft, leak, vulnerability, interruption or third-party compromise is not, in itself, sufficient to establish a breach by the Supplier.

43. EXTERNAL CAUSES OR CAUSES ATTRIBUTABLE TO THE CLIENT

The Supplier shall not be liable to the extent that loss is caused or aggravated by:

• a non-compliant Client configuration;

• a vulnerability in software not under the Supplier’s control;

• an obsolete system;

• refusal to apply a required security update;

• compromised credentials;

• incorrect allocation of rights;

• absence of required MFA;

• a compromised workstation or endpoint;

• malicious software present in the Client’s environment;

• an act of a Client administrator;

• a user error;

• an act of a service provider selected and directly controlled by the Client;

• intentional bypass of security mechanisms;

• use contrary to the documentation;

• an unauthorised modification;

• absence of a backup where backup is the Client’s responsibility.

This exclusion applies only to the extent of the causal contribution of the relevant event to the loss.

44. EXCLUDED LOSSES

Subject to applicable mandatory provisions, the Supplier shall not be liable for indirect losses or losses that are not a direct and foreseeable consequence of a breach attributable to it.

Where they are of such a nature, excluded losses include loss of revenue, loss of margin, loss of profit, loss of customers, loss of opportunity, commercial reputational harm, internal costs that are not reasonably necessary, losses arising from contracts entered into by the Client with third parties, and losses resulting from the Client’s inability to comply with an undertaking that it gave without informing the Supplier.

This clause does not apply where an exclusion is prohibited by a mandatory provision.

45. GENERAL LIABILITY CAP

Subject to the following Article, the Supplier’s aggregate liability for all contractual causes during any single twelve-month period is capped at the amount, exclusive of tax, paid or payable for the directly affected Service during the twelve months preceding the event giving rise to liability.

Where the event giving rise to liability occurs during the first twelve months of the Agreement, the cap shall equal the amount, exclusive of tax, that would have been payable for twelve months of that Service at the contractual rate then applicable.

Events having the same technical or organisational cause shall be treated as a single event for the purpose of this cap.

46. ENHANCED CAP FOR CERTAIN RISKS

To maintain a level of liability consistent with the essential security obligations of the Service, the cap applicable to direct losses arising from a breach by the Supplier of its contractual confidentiality obligation, a personal-data breach directly attributable to the Supplier’s failure to meet its security obligations, or an infringement of a third party’s intellectual-property rights attributable to VESTA, is set at 150% of the annual amount, exclusive of tax, of the affected Service.

This cap applies only to claims between the Parties and only to the extent that applicable law permits contractual limitation.

47. EXCLUSIONS FROM THE CAP

Nothing in these Terms limits any liability whose limitation is prohibited by a mandatory rule.

In particular, the preceding caps are not intended to limit the consequences of fraud (dol), liabilities that may not be limited because of gross negligence under applicable law, bodily injury where limitation is prohibited, statutory liability for defective products where it may not be contractually limited, the direct rights of data subjects under the GDPR, or the powers and sanctions of administrative or judicial authorities.

48. GDPR AND LIMITATION OF LIABILITY

The limitations provided for in the Agreement govern the financial relationship between the Client and the Supplier only to the extent permitted by law.

They do not limit the rights of a data subject, the powers of the CNIL or another authority, or any direct liability imposed on a Party by mandatory law.

Any recourse claim between the Parties relating to personal-data processing shall be allocated according to the liability actually attributable to each Party, subject to applicable mandatory provisions.

49. FINES AND SANCTIONS

Each Party shall bear the administrative, criminal or disciplinary sanctions personally imposed on it as a result of a breach attributable to it.

The Agreement is not intended to transfer a sanction where such transfer would be contrary to public policy or applicable law.

Where one Party faces a civil claim by a third party as a result of a breach attributable to the other Party, the liability and indemnity mechanisms provided for in the Agreement may apply.

50. DUTY TO MITIGATE LOSS

Each Party shall take reasonable measures to prevent an incident from worsening, limit its consequences, preserve useful evidence, restore operation and cooperate with the other Party.

A Party may not claim compensation from the other for the portion of a loss that it could reasonably have avoided and that results directly from its failure to cooperate, subject to applicable mandatory rules.

51. FORCE MAJEURE

Neither Party shall be liable for non-performance of an obligation where the legal conditions for force majeure are met.

A cyberattack, ransomware event, cloud-provider outage or network incident is not automatically treated as force majeure. Classification depends in particular on whether the event is beyond the control of the Party concerned, its reasonable foreseeability and whether its effects could have been avoided through appropriate measures.

The Party invoking force majeure shall inform the other Party and take reasonable measures to limit its consequences.

52. SECURITY EMERGENCY

Independently of force majeure, the Supplier may immediately take protective measures where reasonably necessary to prevent compromise, propagation of an attack, destruction of data, fraudulent use, impairment of cryptographic integrity, exposure of secrets or compromise of other clients.

Such measures may include temporary restriction or suspension of the Service.

The Supplier shall restore the Service when the required security conditions are again satisfied.

Whether such a suspension is treated as an SLA event depends on its cause and on the provisions of the applicable SLA.

53. INSURANCE

Each Party shall maintain, throughout the term of the Agreement, insurance appropriate to its activity, responsibilities and the risks it assumes.

The Supplier may in particular maintain professional liability insurance and, where appropriate, cyber insurance.

The Client is encouraged to maintain cyber insurance appropriate to the nature and volume of the data it processes.

Where specific insurance is mandatory for a deployment, it shall be specified in the Order Form.

54. CHANGES TO THE SERVICE

The Supplier may modify VESTA in particular to improve its security, remediate vulnerabilities, replace an obsolete component, comply with a regulatory obligation, improve performance or improve compatibility.

A change must not substantially reduce the essential subscribed functions during the contractual period without legitimate reason.

Urgent changes required for security reasons may be deployed without prior notice.

55. REGULATORY CHANGE

If a legislative, regulatory or standards-related development, or a decision by a competent authority, requires a material change to the Service, the Parties shall cooperate to adapt the Agreement.

Where such a development results in a significant increase in the cost of providing the Service, the Supplier may propose a reasonably proportionate price adjustment.

If a change makes it legally impossible to continue a particular Service, the Supplier may suspend or terminate the affected Service after informing the Client.

56. CERTIFICATIONS AND SECURITY CLAIMS

No specific certification, qualification or compliance status may be presumed.

Only certifications actually obtained, currently valid, expressly identified and within their exact certified scope may be treated as contractually acquired.

Expressions such as “certification-ready”, “post-quantum ready”, “Zero Trust”, “state of the art” or “compliant with the principles of” do not, by themselves, constitute a regulatory certification or an absolute guarantee.

57. EVIDENCE AND LOGS

Logs and traces generated by VESTA may be used to establish the chronology of an operation, a request identifier, an authorisation decision, the declared identity of an actor, a security status, a cryptographic result or a backup or restoration operation.

The Parties acknowledge the evidential value of electronic records where their integrity can reasonably be demonstrated.

However, the presence of an event in a log does not automatically prove the physical identity of a person where that person’s authentication means have been compromised.

58. ASSIGNMENT

The Client may not assign the Agreement to a third party without the Supplier’s prior written consent, except as part of a restructuring that does not materially affect contractual risk.

The Supplier may assign the Agreement in connection with a merger, acquisition, universal transfer of assets and liabilities, transfer of business or similar transaction, provided that the assignee assumes the corresponding obligations.

59. SEVERABILITY

If any provision of these Terms is declared void, unenforceable or deemed unwritten, the remaining provisions shall remain in force.

The Parties shall endeavour to replace the affected provision with a valid provision having an economic and legal effect as close as possible to the original intention.

60. NO WAIVER

A Party’s failure to exercise a right immediately does not constitute a waiver of that right.

61. ENTIRE AGREEMENT

The Agreement supersedes all prior exchanges, statements or undertakings relating to the same subject matter, unless expressly incorporated into the contractual documents.

No commercial statement made by an employee, distributor or partner shall amend the Agreement without written confirmation from an authorised person.

62. NOTICES

Important contractual notices shall be sent to the contact details specified in the Order Form.

Notices concerning termination, a major security incident, a personal-data breach or a material regulatory change shall be sent to the contacts specifically designated by the Parties.

63. GOVERNING LAW

The Agreement is governed by French law.

64. AMICABLE SETTLEMENT

Before commencing judicial proceedings, the Parties shall endeavour in good faith to resolve their dispute.

The dispute shall first be escalated to the operational managers and, if unresolved, to a management representative of each Party.

This procedure does not prevent interim protective measures, urgent proceedings or actions necessary to preserve a right.

65. JURISDICTION

Where both Parties are merchants (commerçants) within the meaning of French law, any dispute relating to the formation, interpretation, performance or termination of the Agreement shall fall within the exclusive jurisdiction of the Commercial Court of Toulouse, including in the event of multiple defendants or third-party proceedings, subject to mandatory jurisdiction rules.

Where this jurisdiction clause is not legally enforceable against the Client, the ordinary rules of jurisdiction shall apply.

SCHEDULE A - CLIENT MINIMUM CYBERSECURITY BASELINE

Throughout the term of the Agreement, the Client must maintain a level of security reasonably compatible with use of VESTA. At a minimum, this baseline includes:

1. supported operating systems and software;

2. security patches applied within timeframes appropriate to their severity;

3. antivirus or EDR kept active where appropriate for the relevant system;

4. firewall and network protection;

5. MFA for privileged accounts and sensitive remote access where technically available;

6. separation of administrator accounts from ordinary user accounts;

7. the principle of least privilege;

8. prompt deletion of accounts that are no longer required;

9. protection of certificates and service accounts;

10. locking and physical protection of equipment;

11. correct system time synchronisation;

12. appropriate security logging;

13. network segmentation where justified by the level of risk;

14. independent backups where these are not provided by VESTA;

15. an incident-response procedure;

16. reasonable user training;

17. prohibition on sharing individual accounts;

18. maintenance of HSMs or local equipment for which the Client is responsible;

19. prohibition on disabling VESTA controls;

20. prompt notification to the Supplier in the event of compromise.

The Supplier may update this baseline to reflect a new threat or vulnerability. Any material non-urgent change shall be communicated with reasonable notice. An urgent requirement may be applied immediately where necessary to avoid a critical security risk.

SCHEDULE B - PERSONAL DATA PROCESSING

B.1 Purpose

This Schedule applies where the Supplier processes personal data on behalf of the Client.

B.2 Roles

The Client is the controller for the business purposes it determines. The Supplier acts as processor for processing carried out exclusively on behalf of the Client. The Supplier may act as a separate controller for its own administrative and commercial processing, internal security or legal obligations.

B.3 Authorised processing

Depending on the subscribed Services, processing may include: security, encryption, authorised decryption, access management, integrity control, security metadata, logging, backup, restoration, technical support, and incident prevention and investigation.

B.4 Categories of data

Depending on the Client: user identifiers, professional information, technical identifiers, business data, metadata, audit trails, pseudonymous identifiers, sensitive data and health data where provided for by the subscribed Service.

B.5 Data subjects

Depending on the Client’s activity: users, employees, professionals, customers, patients, service users and other persons whose data appears in protected objects.

B.6 Instructions

The Supplier shall process data only on the Client’s documented instructions, unless otherwise required by law. The Agreement, the Order Form, support requests and instructions transmitted by authorised contacts constitute documented instructions. The Supplier shall inform the Client where an instruction appears to be contrary to applicable law.

B.7 Confidentiality

Persons authorised to process personal data are subject to a confidentiality obligation.

B.8 Security

The Supplier shall maintain technical and organisational measures proportionate to the risks, which may include encryption, access control, isolation of cryptographic secrets, privilege limitation, logging, integrity control, backup procedures, vulnerability and incident management, strong authentication, HSMs where part of the Service, and separation between business data and cryptographic secrets.

B.9 Personal-data breach

Where the Supplier becomes aware of a personal-data breach affecting data processed on behalf of the Client, it shall inform the Client as soon as possible. The Supplier shall progressively provide the available information enabling the Client to comply with its own regulatory obligations.

B.10 Sub-processors

The Client gives general authorisation for the use of sub-processors identified in the list maintained by the Supplier. The Supplier shall inform the Client of any material change concerning a sub-processor processing personal data. The Client may raise a reasoned objection based on serious data-protection considerations.

B.11 International transfers

Any transfer of personal data outside the European Economic Area shall be carried out in accordance with the mechanisms provided for by applicable law.

B.12 Data-subject rights

Taking into account the nature of the Service, the Supplier shall reasonably assist the Client in responding to requests to exercise rights where action by the Supplier is necessary.

B.13 Assistance

The Supplier shall provide reasonable assistance to the Client regarding processing security, breaches, data-protection impact assessments and prior consultations, insofar as such assistance concerns processing carried out by the Supplier and information available to it. Significant exceptional services may be charged where they do not result from a breach by the Supplier.

B.14 Audits

The Supplier shall make available the information reasonably necessary to demonstrate compliance with its obligations. Audits shall be conducted under conditions that protect other clients’ data, trade secrets, cryptographic secrets and infrastructure security.

B.15 End of processing

Upon expiry of the Agreement, personal data shall be returned or deleted in accordance with the Client’s instructions and the reversibility arrangements, unless retention is required by law.

SCHEDULE C - AVAILABILITY, BACKUP AND SECURITY PRINCIPLES

C.1 Service states

VESTA may in particular be in the following states: Online - normal operation; Offline degraded - temporary limited operation under a pre-provisioned authorisation; Maintenance - functions temporarily restricted during maintenance; Unavailable - the minimum conditions required for secure operation are not met.

C.2 Security priority

Where the choice is between granting access under insufficiently secure conditions and temporarily refusing access, VESTA gives priority to refusal of access. This policy is an essential function of the Service.

C.3 Backup

Where subscribed to, a backup policy may include several levels: local backup, backup to on-site equipment, remote or cloud backup, integrity verification, manifest and restorability verification. The Order Form defines the levels actually subscribed to.

C.4 Dependencies

The Client acknowledges that certain secure operations may depend on several independent components. Unavailability of a mandatory component may result in refusal of an operation rather than bypassing security.

C.5 No silent degradation

VESTA shall not intentionally weaken an essential security requirement in order artificially to maintain availability, except where degraded operation is expressly authorised by the applicable policy.

Last updated: 9 July 2026