General Terms and Conditions

The terms and conditions applicable to use of the Normatik platform.

Version 1.0 — 1 May 2026

42 BV · Zilverstraat 1, 2718 RP Zoetermeer · Chamber of Commerce 24293804

Article 1. Definitions and applicability

1.1 In these general terms and conditions:

Normatik: the SaaS application for information security management (ISMS), provided by 42 BV, located at Zilverstraat 1 and registered with the Dutch Chamber of Commerce under number 24293804, also referred to as the “Supplier”.

Customer: the legal entity or natural person acting in the course of a profession or business who enters into an agreement with the Supplier for the use of Normatik.

Agreement: the agreement between the Supplier and the Customer concerning use of Normatik, including any annexes, service level agreements and data processing agreements.

Application: the Normatik software, including all updates, patches and new versions that the Supplier makes available during the term of the Agreement.

Customer Data: all data, documents, risk assessments, policies and other information entered into or generated in the Application by or on behalf of the Customer.

User: a natural person authorised by the Customer to access the Application.

Service: all services supplied by the Supplier to the Customer, comprising access to the Application, maintenance, support and any additional services.

1.2 These general terms and conditions apply to all offers, quotations and agreements between the Supplier and the Customer, unless otherwise agreed in writing.

1.3 The applicability of any purchasing or other terms and conditions of the Customer is expressly rejected.

1.4 If any provision of these terms is void or annulled, the remaining provisions remain fully in force. In that case, the parties will consult to agree on a replacement provision that approximates the purpose and intent of the original provision as closely as possible.

1.5 The Supplier is entitled to amend these general terms and conditions. Amendments will be communicated to the Customer in writing or by email at least thirty (30) days before they take effect. If an amendment is materially disadvantageous to the Customer, the Customer may terminate the Agreement with effect from the date on which the amended terms take effect.

Article 2. Formation of the Agreement

2.1 The Agreement is formed when the Customer completes the registration process in the Application and expressly accepts these general terms and conditions, or when the Supplier receives a quotation signed by the Customer.

2.2 The Supplier makes the general terms and conditions available electronically to the Customer before or upon conclusion of the Agreement, in a manner that allows the Customer to save them and access them for later reference.

2.3 All offers and quotations from the Supplier are non-binding unless they expressly state an acceptance period.

Article 3. Licence and right of use

3.1 During the term of the Agreement, the Supplier grants the Customer a non-exclusive, non-transferable and revocable right to use the Application in accordance with the Agreement and its accompanying documentation.

3.2 The right of use is limited to the Customer's internal business purposes and the number of Users agreed in the Agreement.

3.3 The Customer is not permitted to:

copy, modify, translate, decompile or reverse-engineer the Application, or otherwise ascertain its source code, except insofar as permitted by mandatory law;

sublicense, rent, sell or otherwise make the Application or any part of it available to third parties;

reproduce the Supplier's methodologies, templates, checklists or frameworks, in whole or in part, for its own commercial purposes outside the scope of the Agreement.

Article 4. Availability and maintenance

4.1 The Supplier will use its best efforts to keep the Application available but does not guarantee uninterrupted availability unless the parties have agreed on a separate Service Level Agreement (SLA).

4.2 The Supplier may temporarily take the Application out of service for maintenance, modifications or improvements. The Supplier will perform scheduled maintenance outside office hours as far as possible and notify the Customer in advance where reasonably possible.

4.3 The Supplier is not liable for damage resulting from temporary unavailability of the Application, except in cases of intent or deliberate recklessness.

Article 5. Shared responsibility and compliance

5.1 The Supplier ensures an appropriate level of security for the Application and underlying infrastructure, taking account of the state of the art and the nature of the data processed. This includes at least:

encryption of Customer Data both at rest and in transit;

hosting Customer Data within the European Economic Area (EEA);

using multi-factor authentication (MFA) for administrators of the Application;

conducting periodic security audits and penetration tests.

5.2 The Customer is responsible for:

securing and keeping login credentials confidential and managing authorisations within the Application;

taking adequate security measures on its own systems and networks used to access the Application;

the accuracy and completeness of Customer Data entered into the Application.

5.3 The Customer acknowledges and accepts that the Application is a supporting tool for meeting obligations under the Dutch Cybersecurity Act, the Dutch implementation of the NIS2 Directive, and similar legislation and regulations. Use of the Application does not in itself guarantee full compliance. Ultimate legal responsibility for compliance with applicable legislation and regulations remains with the Customer and its management at all times.

5.4 At the Customer's request, the Supplier provides information about the security measures taken to support the Customer's supply chain responsibility under the Dutch Cybersecurity Act, for example through a security statement, certification or audit report.

Article 6. Incident management

6.1 The Supplier notifies the Customer without delay, and no later than twenty-four (24) hours after identification, of any security incident that affects or may reasonably affect the confidentiality, integrity or availability of Customer Data.

6.2 The notification referred to in paragraph 1 contains at least:

a description of the nature of the incident;

its estimated scope and consequences;

the measures already taken and planned.

6.3 The Supplier provides the Customer with all reasonable cooperation needed to meet its own reporting obligations to regulators.

Article 7. Customer Data and ownership

7.1 All Customer Data remains the Customer's property at all times. The Agreement does not transfer any intellectual property rights in Customer Data to the Supplier.

7.2 The Supplier processes Customer Data solely to perform the Agreement and the Service described in it, unless the Customer has expressly consented otherwise or a legal obligation requires it.

7.3 The Supplier makes daily backups of Customer Data and ensures recovery within forty-eight (48) hours after an incident resulting in data loss, provided the Supplier has followed the agreed backup procedures.

Article 8. Prices, indexation and payment

8.1 The Customer owes the Supplier the fee agreed in the Agreement. All prices are exclusive of VAT and other government levies unless expressly stated otherwise.

8.2 The Supplier may index prices annually based on the Consumer Price Index (CPI) published by Statistics Netherlands (CBS). Indexation takes place on the annual renewal date of the Agreement. Negative indexation does not result in a price reduction.

8.3 Payment must be made within thirty (30) days of the invoice date unless otherwise agreed in writing.

8.4 If the payment period is exceeded, the Customer is automatically in default without further notice of default being required. Statutory commercial interest is payable on the outstanding amount from that point.

8.5 If the Customer remains in payment default for more than thirty (30) days, the Supplier may suspend access to the Application until all outstanding invoices are paid. Suspension does not release the Customer from its payment obligations.

Article 9. Term, termination and switching providers

9.1 The Agreement is entered into for the term stated in it. After the initial term, it is tacitly renewed for successive periods of one (1) year, unless either party terminates it with two (2) months' notice before the end of the current term.

9.2 In accordance with the European Data Act, the Customer may initiate the process of switching to another provider at any time, subject to a notice period of no more than two (2) months, regardless of the remaining term of any annual contract.

9.3 Upon termination of the Agreement for any reason, the Customer may export all Customer Data in a commonly used, structured and machine-readable format, including CSV and/or JSON, for thirty (30) days after the termination date.

9.4 The Supplier provides reasonable assistance with migration to another provider for a fee based on its usual hourly rates. From 12 January 2027, no fees will be charged for transferring Customer Data, in accordance with the Data Act.

9.5 During the transition period referred to in paragraph 3, the Application remains fully available to the Customer to safeguard business continuity.

9.6 After the period in paragraph 3 expires, the Supplier deletes all Customer Data from its systems unless a statutory retention obligation prevents this.

Article 10. Liability

10.1 The Supplier's total liability for an attributable failure to perform the Agreement, or on any other legal basis, is limited to compensation for direct damage up to the amount actually paid by the Customer to the Supplier under the Agreement during the twelve (12) months preceding the event that caused the damage.

10.2 Direct damage means only:

reasonable costs incurred by the Customer to bring the Supplier's performance into conformity with the Agreement;

reasonable costs of establishing the cause and extent of the damage;

reasonable costs of preventing or limiting damage, insofar as the Customer demonstrates that these costs reduced the direct damage.

10.3 The Supplier's liability for indirect damage, including but not limited to consequential loss, lost profit, lost savings, business interruption and reputational damage, is excluded.

10.4 The limitations of liability in this article do not apply if the damage results from intent or deliberate recklessness by the Supplier or its management.

10.5 The Supplier's liability for loss of Customer Data is limited to the cost of restoring the data from the most recent backup, provided the Supplier can demonstrate that the agreed backup procedures were followed.

10.6 The Supplier is not liable for fines or sanctions imposed on the Customer by regulators under the Dutch Cybersecurity Act, the GDPR or other applicable regulations where those fines result from the Customer's own negligence or actions.

Article 11. Indemnification

11.1 The Customer indemnifies the Supplier against all third-party claims connected with or arising from the Customer's use of the Application, including but not limited to claims arising from the Customer's failure to comply with applicable legislation and regulations.

11.2 The Supplier indemnifies the Customer against third-party claims for infringement of intellectual property rights relating to the Application, provided the Customer promptly notifies the Supplier in writing and leaves the handling of the claim entirely to the Supplier.

Article 12. Confidentiality

12.1 The parties undertake to keep confidential all confidential information received from the other party under the Agreement and to use it solely for the purpose for which it was provided.

12.2 Confidential information includes, in any event: Customer Data, risk assessments, security measures, financial information and business strategy information.

12.3 The confidentiality obligation does not apply to information that:

was already known to the receiving party at the time of disclosure;

was lawfully obtained from a third party without a confidentiality obligation;

is or becomes publicly known through no act of the receiving party;

must be disclosed under a legal obligation.

12.4 The confidentiality obligation remains in force during the term of the Agreement and for two (2) years after its termination.

Article 13. Intellectual property

13.1 All intellectual property rights in the Application, documentation, underlying software, data structures, methodologies and templates belong exclusively to the Supplier.

13.2 The Agreement does not transfer any intellectual property rights. The Customer acquires only the right of use described in Article 3.

13.3 The Customer may not remove or alter indications concerning copyright, trademarks, trade names or other intellectual property rights in the Application.

Article 14. Processing personal data

14.1 If and insofar as the Supplier processes personal data on the Customer's behalf when performing the Agreement, the Supplier acts as a processor within the meaning of the GDPR.

14.2 The parties enter into a separate data processing agreement for this purpose, attached as an annex to the Agreement. The data processing agreement forms an integral part of the Agreement.

14.3 The Supplier processes personal data solely on the basis of the Customer's written instructions, except where otherwise required by a legal obligation.

Article 15. Force majeure

15.1 Neither party is required to fulfil an obligation if prevented by a circumstance that is not attributable to its fault and for which it is not responsible under the law, a legal act or generally accepted principles.

15.2 In addition to what is recognised in legislation and case law, force majeure under these terms includes: large-scale internet outages, DDoS attacks or other cyberattacks of exceptional scale, power failures, epidemics, government measures and failures by the Supplier's suppliers over which the Supplier has no control.

15.3 If a force majeure situation continues for more than ninety (90) days, either party may terminate the Agreement in writing without any obligation to pay compensation arising as a result.

Article 16. Applicable law and disputes

16.1 The Agreement and these general terms and conditions are governed exclusively by Dutch law.

16.2 Disputes arising from or connected with the Agreement are submitted exclusively to the competent court in the district where the Supplier is established, unless mandatory law provides otherwise.

16.3 Before submitting a dispute to a court, the parties will endeavour to resolve it through consultation within thirty (30) days after written notification of the dispute.

Article 17. Final provisions

17.1 The Supplier's failure to exercise or enforce any right or provision of these terms does not constitute a waiver of that right or provision.

17.2 The Supplier may transfer its rights and obligations under the Agreement to a third party, provided the Customer is notified in writing at least thirty (30) days in advance. The Customer may not transfer its rights and obligations without the Supplier's prior written consent.

17.3 Notices under the Agreement are given in writing, by email or through the Application, using the Customer's contact details known to the Supplier.

Supplier

42 BV

Zilverstraat 1

2718 RP Zoetermeer

Chamber of Commerce number: 24293804

Email: info@42.nl