SUBSCRIPTION AND END USER LICENSE AGREEMENT
This Subscription and End User License Agreement (“Agreement”) is made and entered into effective as of Effective Date between T.R. Björkbom-Trading Oy, a Finnish Corporation, with its principal place of business at Veneentekijäntie 8, Helsinki, Finland (“Company”), and Company’s respective client (“Subscriber”).
Entering into this Agreement by Subscriber is effected by signing this Agreement and filled Order Form, signing filled Order Form or by other means made available to Subscriber by Company e.g. online, from time to time, all subject to Company having accepted the Subscriber’s order.
If a person is using employer’s or an entity’s email address in registering for the Services, such person is deemed as an authorized representative and/or agent of that person’s employer or an entity (as applicable).
By entering into this Agreement, Subsciber agrees to the following terms and conditions governing its use of Helm1 technology software and services, more particularly described in paragraph 2 below (collectively, the “Service”). The person acting on behalf of Subscriber represents that he/she has the authority to bind Subscriber to these terms and conditions.
Background
As part of the Service, Company will provide Subscriber with use of the subscribed Service, including Helm1 Client Software. Subscriber’s signing of this Agreement, registration for, or use of, the Service shall be deemed to be Subscriber’s entering into this Agreement and to abide by this Agreement including any materials available on the Company’s website incorporated by reference or referred to herein, including but not limited to Company’s privacy and security policies and Data Processing Agreement, which shall form an integral part of this Agreement. The Privacy Policy is described more in detail in the schedule “A” attached to this Agreement, available on the Company’s web site in www.helm1.com The Data Processing Agreement is described more in detail in the schedule “B” attached to this Agreement, available on the Company’s web site in www.helm1.com. For reference, a Definitions section is included below in this Agreement.
1 DEFINITIONS
As used in this Agreement and in any Order Forms now or hereafter associated herewith:
a) “Agreement” means this fully executed agreement, any Order Forms, whether written or submitted online, and any materials available on the Company website specifically incorporated by reference or referred to herein. The materials may be updated by Company from time to time in its sole discretion;
b) “Confidential Information” means a party’s business, its financial, business and technical plans and strategies, inventions, products, new products or services, trade secrets, know how, and technology that the Disclosing Party does not make generally available to the public. In addition, the terms and conditions set forth in this Agreement shall be Confidential Information. Confidential Information does not include any information that the Receiving Party can demonstrate by written records: (i) was known to the Receiving Party prior to its disclosure hereunder by the Disclosing Party; (ii) was independently developed by the Receiving Party; (iii) is or becomes publicly known through no wrongful act of the Receiving Party; (iv) has been rightfully received from a third party whom the Receiving Party has reasonable grounds to believe is authorized to make such disclosure without restriction; or (v) has been approved for public release by the Disclosing Party’s prior written authorization.
c) “Content” means the audio and visual information, documents, software, products and services contained or made available to Subscriber in the course of using the Service;
d) “Customer Data” means any data, information or material provided or submitted by Subscriber or User to the Service in the course of using the Service;
e) “Effective Date” means the date this Agreement is accepted by signing this document or otherwise entering into this Agreement according to its terms;
f) “Helm1” is the name for the cloud-based project management enterprise software designed and owned by Company with features for managing different phases and scopes of a project such as procurement, planning, inventory, budgeting, logistics, stock, assembly, architect interior design, payments tracking etc.
g) “Helm1 Technology” means all of Company’s proprietary technology (including software, eventual hardware, products, processes, algorithms, user interfaces, know-how, techniques, designs and other tangible or intangible technical material or information) made available to the Subscriber by Company in providing the Service;
h) “Intellectual Property Rights” means unpatented inventions, patent applications, patents, design rights, copyrights, trademarks, service marks, trade names, domain name rights, mask work rights, know-how and other trade secret rights, and all other intellectual property rights, derivatives thereof, and forms of protection of a similar nature anywhere in the world;
i) “License Administrator(s)” means those Users designated by Subscriber who are authorized to purchase licenses using the written Order Forms and create User accounts and otherwise administer Subscriber’s use of the Service;
j) “License Term(s)” means the period(s) during which a specified number of Users are licensed to use the Service pursuant to the Order Form(s);
k) “Order Form(s)” means the form evidencing the initial subscription for the Service and any subsequent order forms submitted online or in written form, specifying, among other things, the number of licenses and other services contracted for, the applicable fees, the billing period, and other charges as agreed to between the parties, each such Order Form to be incorporated into and to become a part of this Agreement (in the event of any conflict between the terms of this Agreement and the terms of any such Order Form, the terms of this Agreement shall prevail);
l) “Service”, including Helm1 solution, means services provided to the Subscriber under this Agreement or subject to specific subscription of such services (from Company or through e.g. Reseller);
m) “Company” means collectively T.R. Björkbom-Trading Oy;
n) “User(s)” means Subscriber’s employees, representatives, consultants, contractors or agents, resellers and Customers who are authorized to use the Service and have been supplied user identifications and passwords by Subscriber (or by Company at Subscriber’s request).
2. SERVICE AND FUNCTIONALITY DESCRIPTION
Company offers Subscriber Helm1 solution intended for enterprises. Helm1-software provides the Subscriber with project management enterprise software that includes features for managing different phases and scopes of a project such as procurement, planning, inventory, budgeting, logistics, stock, assembly, architect interior design, payments tracking etc. The Service include services provided by Company (or by the Reseller, as the case may be) subscribed by the Subscriber in the Order Form or otherwise included in the Service according to this Agreement.
3. PRIVACY & SECURITY; DISCLOSURE
Company reserves the right to modify its privacy and security policies in its reasonable discretion from time to time. Note that because the Service is a hosted, online application, Company occasionally may need to notify all users of the Service (whether or not they have opted out) of important announcements regarding the operation of the Service. With Subscriber’s advance review of the content and format of the announcement and written consent (which shall not be unreasonably withheld or delayed), Company may disclose the fact that Subscriber is a paying customer and the edition of the Service that Subscriber is using.
Helm1 Technology and Service has on its background third-party providers of ancillary software, hardware or services. Subscriber agrees and accepts that in this Agreement Company grants no rights to Subscriber to such software, hardware or services and Company shall have no liability for or arising out of third-party software, hardware or services. The third-party providers may also process User’s personal data. Company shall not be liable for such processing. In such case the third-party provider’s privacy policy and terms of service shall be applicable.
The Helm1 Technology security features are described in more detail in the schedule “C” attached to this Agreement.
4. LICENSE GRANT & RESTRICTIONS
a) Company hereby grants Subscriber a non-exclusive, non-transferable, worldwide right to use the Service, solely for Subscriber’s own internal business purposes (specifically including granting access to the service to customers in accordance with Sub-section (c) below), subject to the terms and conditions of this Agreement. All rights not expressly granted to Subscriber are reserved by Company and its eventual licensors.
b) Except as expressly provided in Sub-section (c) Subscriber shall not (i) license, sublicense, sell, resell, transfer, assign, distribute or otherwise commercially exploit or make available to any third party the Service or the Content in any way; (ii) modify or make derivative works based upon the Service or the Content; (iii) create Internet “links” to the Service or “frame” or “mirror” any Content on any other server or wireless or Internet-based device; or (iv) reverse engineer or access the Service in order to (a) build a competitive product or service, (b) build a product using similar ideas, features, functions or graphics of the Service, or (c) copy any ideas, features, functions or graphics of the Service.
c) Throughout the License Term(s), Subscriber may use the Service only for Subscriber’s internal business purposes the Service has been provided with. Subscriber shall not, knowingly or deliberately: (i) send spam or otherwise duplicative or unsolicited messages in violation of applicable laws; (ii) send or store infringing, obscene, threatening, libelous, or otherwise unlawful or tortuous material, including material harmful to children or violative of third party privacy rights; (iii) send or store material containing software viruses, worms, Trojan horses or other harmful computer code, files, scripts, agents or programs; (iv)interfere with or disrupt the integrity or performance of the Service or the data contained therein; or (v) attempt to gain unauthorized access to the Service or its related systems or networks.
5. SUBSCRIBER’S RESPONSIBILITIES
Subscriber is responsible for all activity occurring under Subscriber’s User accounts and shall abide by all applicable local, state, national and foreign laws, treaties and regulations in connection with Subscriber’s use of the Service, including those related to data privacy, international communications and the transmission of technical or personal data. Subscriber shall: (i) notify Company immediately of any unauthorized use of any password or account or any other known or suspected breach of security; (ii) report to Company immediately and use reasonable efforts to stop immediately any copying or distribution of Content that is known or suspected by Subscriber or Subscriber’s Users; and (iii) not impersonate another Helm1 User or provide false identity information to gain access to or use the Service.
6. ACCOUNT INFORMATION AND DATA
Company does not own any data, information or material that Subscriber submit to the Service in the course of using the Service (“Customer Data”). Subscriber, not Company, shall have sole responsibility for the accuracy, quality, integrity, legality, reliability, appropriateness, and intellectual property ownership or right to use of all Customer Data, and Company shall not be responsible or liable for the deletion, correction, destruction, damage, loss or failure to store any Customer Data. In the event this Agreement is terminated (or expires) the Company shall have the right to remove and delete Subscriber’s Customer Data within 30 days of termination from the Service and all other records. Company is expressly prohibited from using the Customer Data for its own purposes at any time during or following termination of this Agreement.
7. INTELLECTUAL PROPERTY OWNERSHIP
Company alone (and its licensors, where applicable) shall own all right, title and interest, including all related Intellectual Property Rights, in and to the Helm1 Technology, the Content and the Service and any suggestions, ideas, enhancement requests, feedback, recommendations or other information provided by Subscriber or any other party relating to the Service. This Agreement is not a sale and does not convey to Subscriber any rights of ownership in or related to the Service, the Helm1 Technology or the Intellectual Property Rights owned by Company. The Helm1 name, the Helm1 logo, and the product names associated with the Service are trademarks of Helm1 or third parties, and no right or license is granted to use them.
8. THIRD PARTY INTERACTIONS
During use of the Service, Subscriber may enter into correspondence with, purchase goods and/or services from, or participate in promotions of advertisers or sponsors showing their goods and/or services through the Service. Any such activity, and any terms, conditions, warranties or representations associated with such activity, is solely between Subscriber and the applicable third-party. Company and its licensors shall have no liability, obligation or responsibility for any such correspondence, purchase or promotion between Subscriber and any such third-party. Company does not endorse any sites on the Internet that are linked through the Service. Company provides these links to Subscriber only as a matter of convenience, and in no event shall Company or its licensors be responsible for any content, products, or other materials on or available from such sites. Company provides the Service to Subscriber pursuant to the terms and conditions of this Agreement. Subscriber recognize, however, that certain third-party providers of ancillary software, hardware or services may require Subscriber’s agreement to additional or different license or other terms prior to Subscriber’s use of or access to such software, hardware or services.
9. CHARGES AND PAYMENT OF FEES
Subscriber shall pay all fees or charges to Subscriber’s account in accordance with the fee and payment schedule agreed upon with Company. Subscriber is responsible for paying for all User licenses ordered for the entire License Term, whether or not such User licenses are actively used. Subscriber must provide Company with approved purchase order information as a condition to signing up for the Service. All separately agreed pricing terms are confidential, and Subscriber agrees not to disclose them to any third party.
10. SUPPORT SERVICES.
Software Maintenance and Support Services:
(A) Software Maintenance: For as long as Subscriber is current with its payments, Company will provide Subscriber with the following services:
1. Error corrections. Company will use reasonable efforts to correct verified Errors with a level of effort proportionate with the severity of the Error. Company is not, however, obligated to correct all Errors.
2. Maintenance Upgrades. Within a reasonable time after general commercial publication, Company will make available to Subscriber all maintenance releases.
(B) Support: Company (or Company via Reseller) will make reasonable endeavors to answer all messages promptly, and in any case will acknowledge a request for support within two (2) hours of receiving the message (restricted to between the hours of 9am and 5pm Monday to Friday CET, excluding bank and other public holidays).
11. BILLING
The provisions of this Section 11 are applicable only if Subscriber accesses Helm1 Services directly from Company. If Subscriber purchases access to the Services through a reseller, any payment terms shall be set forth in Subscriber’s agreement with such reseller.
Subscriber shall pay all fees and charges for the Service in accordance with the fees and charges and invoicing terms in effect at that time. As a rule, Company charges and collects in advance for use of the Service. Company’s fees are exclusive of all taxes, levies, or duties imposed by taxing authorities, and Subscriber shall be responsible for payment of all such taxes and levies.
Subscriber agrees to provide Company with complete and accurate billing and contact information. This information includes Subscriber’s legal company name, street address, e-mail address, and name and telephone number of an authorized billing contact and License Administrator. Subscriber agrees to update this information within 30 days of any change to it. If the contact information Subscriber has provided is false or fraudulent, Company reserves the right to terminate Subscriber’s access to the Service in addition to any other legal remedies.
Unless Company in its discretion determines otherwise, entities will be billed in Euros.
If Subscriber believes Subscriber’s bill is incorrect, Subscriber must contact Company in writing within 30 days of the invoice date of the invoice containing the amount in question to be eligible to receive an adjustment or credit.
12. NON-PAYMENT AND SUSPENSION
In addition to any other rights granted to Company herein, Company reserves the right to suspend or terminate this Agreement and Subscriber’s access to the Service if Subscriber’s account becomes delinquent (falls into arrears). Delinquent invoices (accounts in arrears) are subject to interest of 13 % per annum on any outstanding balance, or the maximum permitted by law, whichever is less, plus all expenses of collection reasonably incurred. Subscriber will continue to be charged for User licenses during any period of suspension. If Company initiates termination of this Agreement for breach by Subscriber, Subscriber will be obligated to pay the balance due on Subscriber’s account calculated in accordance with the Charges and Payment of Fees section above. Subscriber agrees that Company may bill Subscriber for such unpaid fees.
Company reserves the right to impose a reconnection fee in the event Subscriber is suspended and thereafter request access to the Service. Subscriber agrees and acknowledges that Company has no obligation to retain Customer Data and that such Customer Data may be irretrievably deleted if Subscriber’s account is 30 days or more delinquent.
13. TERMINATION UPON EXPIRATION
This Agreement commences on the Effective Date and shall expire at the end of Subscriber’s Licence Term(s) or when Subscriber has performed all the duties of Subscriber arising out of this Agreement in an orderly manner, whichever occurs later.
Sections 4 b), 6, 16, 20, 25 and 26 shall survive the termination (or expiry) of this Agreement.
14. TERMINATION FOR CAUSE
Any breach of Subscriber’s payment obligations or unauthorized use of the Helm1 Technology or Service will be deemed a material breach of this Agreement. Company, in its sole discretion, may terminate Subscriber’s password, account or use of the Service if Subscriber breaches or otherwise fails to comply with this Agreement. In addition, Company may terminate a free account at any time in its sole discretion. Subscriber and Company agree and acknowledge that Company has no right or obligation to retain the Customer Data following termination, but Company shall remove and delete such Customer Data, if Subscriber has materially breached this Agreement, including but not limited to failure to pay outstanding fees, and such breach has not been cured within 30 days of written notice of such breach.
15. REPRESENTATIONS & WARRANTIES
Each party represents and warrants that it has the legal power and authority to enter into this Agreement. Company represents and warrants that it will provide the Service in a manner consistent with general industry standards reasonably applicable to the provision thereof and that the Service will perform substantially in accordance with the Company product documentation under normal use and circumstances. Subscriber represents and warrants that Subscriber has not falsely identified Subscriber’s self nor provided any false information to gain access to the Service and that Subscriber’s billing information is correct.
16. MUTUAL INDEMNIFICATION
a) Subscriber shall indemnify and hold Company, its licensors and each such party’s parent organizations, subsidiaries, affiliates, officers, directors, employees, attorneys and agents harmless from and against any and all claims, costs, damages, losses, liabilities and expenses (including attorneys’ fees and costs) arising out of or in connection with: (i) a claim alleging that use of the Customer Data infringes the rights of, or has caused harm to, a third party; (ii) a claim, which if true, would constitute a violation by Subscriber of Subscriber’s representations and warranties; or (iii) a claim arising from the breach by Subscriber or Subscriber’s Users of this Agreement, provided in any such case that Company (a) gives written notice of the claim promptly to Subscriber; (b) gives Subscriber sole control of the defense and settlement of the claim (provided that Subscriber may not settle or defend any claim unless Subscriber unconditionally release Company of all liability and such settlement does not affect Company’s business or Service); (c) provides to Subscriber all available information and assistance; and (d) has not compromised or settled such claim.
b) Company shall indemnify and hold Subscriber and Subscriber’s parent organizations, subsidiaries, affiliates, officers, directors, employees, attorneys and agents harmless from and against any and all claims, costs, damages, losses, liabilities and expenses (including attorneys’ fees and costs) arising out of or in connection with: (i) a claim alleging that the Service directly infringes a copyright, a patent issued as of the Effective Date, or a trademark of a third party; (ii) a claim, which if true, would constitute a violation by Company of its representations or warranties; or (iii) a claim arising from breach of this Agreement by Company; provided that Subscriber (a) promptly give written notice of the claim to Company; (b) give Company sole control of the defense and settlement of the claim (provided that Company may not settle or defend any claim unless it unconditionally releases Subscriber of all liability); (c) provide to Company all available information and assistance; and (d) have not compromised or settled such claim. Company shall have no indemnification obligation, and Subscriber shall indemnify Company pursuant to this Agreement, for claims arising from any infringement arising from the combination of the Service with any of Subscriber’s products, service, and hardware or business process.
17. DISCLAIMER OF WARRANTIES
Company and its licensors make no representation, warranty, or guaranty as to the reliability, timeliness, quality, suitability, truth, availability, accuracy or completeness of the Service or any content. Company and its licensors do not represent or warrant that (a) the use of the Service will be secure, timely, uninterrupted or error-free or operate in combination with any other hardware, software, system or data, (b) the Service will meet Subscriber’s requirements or expectations, (c) any stored data will be accurate or reliable, (d) the quality of any products, services, information, or other material purchased or obtained by Subscriber through the Service will meet Subscriber’s requirements or expectations, (e) errors or defects will be corrected, or (f) the Service or the server(s) that make the Service available are free of viruses or other harmful components. The Service and all content is provided to Subscriber strictly on an “as is” basis. All conditions, representations and warranties, whether express, implied, statutory or otherwise, including, without limitation, any implied warranty of merchantability, fitness for a particular purpose, or non-infringement of third party rights, are hereby disclaimed to the maximum extent permitted by applicable law by Company and its licensors.
18. ESTIMATES OF CO₂ EMISSIONS AND PRICE EVALUATIONS
It is stated here, for avoidance of doubt, that any estimates regarding the CO₂ emissions as well as product prices calculated and provided by the Service are compiled and calculated by using publicly available information and represent average values based on general data sources. The Subscriber acknowledges and agrees that such CO₂ emission estimates and price evaluations are provided for informational purposes only. They do not constitute precise or guaranteed figures. The Company does not warrant the accuracy, completeness, or reliability of these estimates and shall not be held liable for any discrepancies, errors, or decisions made by the Subscriber based on such information.
19. INTERNET DELAYS
Company’s Services may be subject to limitations, delays, and other problems inherent in the use of the internet and electronic communications. Company is not responsible for any delays, delivery failures, or other damage resulting from such problems.
20. LIMITATION OF LIABILITY
In no event shall Company’s aggregate liability exceed the amounts actually paid by and/or due from Subscriber in the twelve (12) month period immediately preceding the event giving rise to such claim. In no event shall either party and/or its licensors be liable to anyone for any indirect, punitive, special, exemplary, incidental, consequential or other damages of any type or kind (including loss of data, revenue, profits, use or other economic advantage) arising out of, or in any way connected with this Service, including but not limited to the use or inability to use the Service, or for any content obtained from or through the Service, any interruption, inaccuracy, error or omission, regardless of cause in the content, even if the party from which damages are being sought or such party’s licensors have been previously advised of the possibility of such damages.
Helm1 Technology and Service has on its background third-party providers of ancillary software, hardware or services. Subscriber agrees and accepts that in this Agreement Company grants no rights to Subscriber to such software, hardware or services and Company shall have no liability for or arising out of third-party software, hardware or services.
21. ADDITIONAL RIGHTS
Certain states and/or jurisdictions do not allow the exclusion of implied warranties or limitation of liability for incidental, consequential or certain other types of damages, so the exclusions set forth above may not apply to Subscriber.
22. NOTICE
In addition to Section 12, Company may give non-legal notice by means of a general notice on the Service provided to all Company’s customers or electronic mail to Subscriber’s e-mail address on record in Company’s account information. Such notice shall be deemed to have been given 12 hours after sending (if sent by email), provided that no bounce-back message or delivery error notice is returned in such period. Company must provide written notice for eventual legal purposes to Subscriber by first class mail or pre-paid post to Subscriber’s address. Legal notice shall be deemed to have been given upon the expiration of 48 hours after mailing or posting (when sent by first class mail or pre-paid post). Subscriber may give notice to Company’s legal notice. Such notice shall be deemed to have been given upon the expiration of 48 hours after mailing or posting at any time by any of the following: letter delivered by nationally recognized overnight delivery service or first class postage prepaid mail to Company at the following addresses (whichever is appropriate): T.R. Björkbom-Trading Oy, Veneentekijäntie 8, Helsinki, Finland, addressed to the attention of Mr. John Björkbom.
23. MODIFICATION TO TERMS
Company reserves the right to modify the terms and conditions of this Agreement or its policies relating to the Service at any time, effective upon posting of an updated version of this Agreement on the Service. Subscriber is responsible for regularly reviewing this Agreement. Continued use of the Service after any such changes shall constitute Subscriber’s consent to such changes.
24. ASSIGNMENT; CHANGE IN CONTROL
This Agreement may not be assigned by Subscriber without the prior written approval of Company. Notwithstanding the foregoing, this Agreement may be assigned by A) Company without Subscriber’s consent to (i) an acquirer of Company’s business activities presented in this Agreement; by B) either party without the other party’s consent to (i) a parent or subsidiary, (ii) an acquirer of all or substantially of all of the assigning party’s assets, or (iii) a successor by merger, acquisition or act of law. Any purported assignment in violation of this section shall be void. Any actual or proposed change in control of Subscriber that results or would result in a direct competitor of Company directly or indirectly owning or controlling 50% or more of Subscriber shall entitle Company to terminate this Agreement for cause immediately upon written notice.
25. CONFIDENTIAL INFORMATION
Confidential Information. Each party acknowledges that by reason of its relationship with the other party hereunder, such party (the “Receiving Party”) might have access to the other party’s (the “Disclosing Party”) Confidential Information. The Receiving Party acknowledges and agrees that the Disclosing Party’s Confidential Information is of substantial value to the Disclosing Party, which value would be harmed if such information were disclosed to third parties. The Receiving Party agrees that it accords the Disclosing Party’s Confidential Information the same degree and methods of protection as it accords its own Confidential Information and will not (i) use the Disclosing Party’s Confidential Information in any way, except in the performance of its obligations under this Agreement; or (ii) disclose such Confidential Information to any third party, except to its employees who need to know such information, provided such employees have signed a confidentiality agreement with terms no less restrictive than the terms in this Agreement. The Receiving Party will not publish in any form the Disclosing Party’s Confidential Information beyond any descriptions published by the Disclosing Party. Confidential Information may be disclosed pursuant to applicable law, regulations or court order, provided that the Receiving Party provides prompt advance notice thereof to enable the Disclosing Party to seek protective order or otherwise prevent such disclosure.
Return of Confidential Information. The Confidential Information of a Disclosing Party is and shall remain the Disclosing Party’s property. In the event of any termination or expiration of this Agreement: (i) the Receiving Party shall promptly, and, in any event within five (5) days after being so requested by the Disclosing Party, return to the Disclosing Party all of the Disclosing Party’s Confidential Information in tangible form that is within the possession or control of the Receiving Party; and (ii) except to the extent the Receiving Party is advised in writing by counsel that it is prohibited by law from so doing, the Receiving Party will also destroy all written material, memoranda, notes and other writings or recordings whatsoever prepared by it or its representatives based upon, containing or otherwise reflecting any Confidential Information. Any Confidential Information that is not returned or destroyed, including, without limitation, any oral Confidential Information, shall remain subject to the confidentiality obligations set forth in this Agreement.
26. GOVERNING LAW AND JURISDICTION
This Agreement shall be governed by and construed in accordance with Finnish law, excluding its choice of law rules.
Any dispute, which may arise between the parties concerning this Agreement, shall be determined by Helsingin käräjäoikeus (District Court of Helsinki).
27. GENERAL
No text or information set forth on any other purchase order, preprinted form or document (other than an Order Form, if applicable) shall add to or vary the terms and conditions of this Agreement. If any provision of this Agreement is held by a court of competent jurisdiction to be invalid or unenforceable, then such provision(s) shall be construed, as nearly as possible, to reflect the intentions of the invalid or unenforceable provision(s), with all other provisions remaining in full force and effect. No joint venture, partnership, employment, or agency relationship exists between Subscriber and Company as a result of this agreement or use of the Service. The failure of Company to enforce any right or provision in this Agreement shall not constitute a waiver of such right or provision unless acknowledged and agreed to by Company in writing. This Agreement, together with any applicable Order Form, comprises the entire agreement between Subscriber and Company and supersedes all prior or contemporaneous negotiations, discussions or agreements, whether written or oral, between the parties regarding the subject matter contained herein.
Questions or Additional Information:
If Subscriber has questions regarding this Agreement or wish to obtain additional information, please send an e-mail to sales(a)helm1.com.
AGREED AND ACCEPTED: | AGREED AND ACCEPTED: |
“Company” | “Subscriber” |
BY | BY |
TITLE | TITLE |
DATE | DATE |
Schedule C to Subscription and End User License Agreement
Security
Helm1 consists of several systems that can be divided into frontend and backend. Both comply to GDPR. Here are questions and answers about Helm1:
Is data encrypted in Transit with TLS 1.2 or greater? Yes.
Is data encrypted at rest (storage)?
Yes, with 256-bit Advanced Encryption Standard.
Would all data be removed from your server if requested? Yes.
Will my data be shared with another entity, software, or 3rd party? No.
Which Cloud Providers will you be using? AWS and Google Cloud
Will Helm1 need to access your organization’s network? No.
Does your product require a software agent running on my organization’s hosts? No.
Does your product need any connection to my organization’s network whatsoever? No.
Frontend
The frontend system does not store data: it displays, processes and passes data to the backend. The frontend system does not have security certifications. Here are questions and answers about the frontend system security:
Where are the physical locations where system data will be stored?
North America.
Do you use a “least access” model with users getting access to only what they need? Yes.
Do you require 2-factor authentication (2FA) for remote access into your internal network?
Yes.
Do you have a vulnerability and patch management program? Yes.
Do you have protections against brute force login attempts? Yes.
Do you have protection against DDoS attacks? Yes.
Is technical maintenance only executed from secured maintenance workstations with encrypted hard drives?
Yes.
When accessed from a public network location, is the maintenance environment only accessible with a strong (multi-factor) authentication?
Yes.
Is there a backup and restore plan for when things go wrong during maintenance? Yes.
Is there a description of the information system, operating procedures, and
configuration?
Yes.
In the production systems, there are no development tools, test tools, or source code? Yes.
Backend
The backend system has the following security certifications:
● SOC 2 Type 2 (Service Organization Controls audit)
● ISO/IEC 27001
● ISO/IEC 27701
● TX-RAMP Level 1
PRIVACY POLICY AS OF 1 June 2026
1. GENERAL
This is the Privacy Policy of T.R. Björkbom-Trading Oy (“Company” or “We”) applicable to Helm1 website and services operated by Company. Some websites, web pages or services of Company may be subject to specific terms of use. In this case the Privacy Policy constitutes an integral part of such terms; however, should any contradictions occur, such terms shall prevail over this Privacy Policy. In the following by user (the “User” or “You”) is meant any individual user of the website and/or thereto related services of Company, and any legal entity represented by such individual user.
Company website may contain links to other websites. Company Privacy Policy applies only to Company website, so if User click on a link to another website, User must read their privacy policy and terms of service.
We operate a software-as-a-service platform (Helm1) which we provide to our business clients and their authorized users. This Privacy Policy explains how we process personal data in our capacity as a data controller — that is, when we determine the purposes and means of processing — in connection with that service provider–client relationship.
When the User has become the User of Helm1 and thereto related services, where applicable, the Google Privacy Policy and Terms of Service and AWS privacy policy and terms of service are applied together with the agreement/s governing the use of Helm1 Technology.
The User agrees to be bound by this Privacy Policy, as amended from time to time, by visiting and/or using the website of Company or by registering and disclosing personal information to Company in connection with its web pages or services as well as by using the services of Company. Any use or disclosure may take place only if the User agrees to this Privacy Policy in its entirety.
Company respects the privacy of the User and commits itself to observe the applicable laws and statutes of Finland and the European Union relating to privacy as well as principles expressed in this Privacy Policy. When Company is the controller of the personal data for the purposes of the Finnish Data Protection Act, with exception where the User is under third-party privacy policy and terms of service according to this Privacy Policy.
This Privacy Policy does not cover personal data that we process on behalf of and under the instructions of our client as a data processor (e.g. data that clients upload or generate within Helm1). The processing of that data is governed by the Data Processing Agreement between us and the relevant client, which Company and client execute separately or which comes into effect by client entering into Helm1 Subscription and End User License Agreement (hereinafter also “SaaS Agreement”). If you have questions about data processed on behalf of a client, please contact that client directly.
If Company and/or Company’s service providers processing personal data on Company’s behalf transfer personal data to countries outside the EU or the EEA, the transfer is subject to standard data protection clauses adopted by the EU Commission or other appropriate safeguards, unless the EU Commission has found that the level of data protection is adequate in the country in question.
2. CONTROLLER INFORMATION
This Privacy Policy concerns personal data that Company processes about User as a controller. Please find below Company’s contact information.
Name: T.R. Björkbom-Trading Oy
Address: Veneentekijäntie 8, Helsinki, Finland
Web address: www.helm1.com
Contact person in data protection issues: John Björkbom
E-mail: john.bjorkbom(a)bjorkbomtrading.fi
3. USE OF DATA
3.1 Personal data
In general the websites of Company can be browsed without providing any personal data about the User. When the User opts to use or purchase the services provided by Company or to otherwise register at the website of Company providing certain contact and identity information, billing information and other personal data will be required.
Company will hold and process any personal data which the User provides via the websites or by submitting emails and/or online forms for its own internal business purposes.
This Privacy Notice applies to the following categories of individuals whose personal data we process as a data controller:
- Representatives, employees, and authorized contacts of our current, prospective, and former clients (including individuals who enquire about or purchase the Helm1 service on behalf of a client organization);
- Individuals who contact our customer support, sales, or account management teams; and
- Other business contacts, partners, suppliers, and professional advisors with whom we interact in connection with the provision of the Helm1 service.
3.2 Data you provide directly to us
We collect personal data that you or your employer provides to us when you:
- Enquire about, purchase, or subscribe to the Helm1 service (e.g. name, job title, work email address, telephone number, employer name and address);
- Contact our sales, customer support, or account management teams (e.g. name, contact details, content of communications);
- Subscribe to our newsletter or marketing communications (e.g. email address, communication preferences); or
- Submit a job application or otherwise correspond with us.
3.3 Data we collect automatically
When you visit our website, we may automatically collect certain technical information, including:
- Device and browser information (e.g. device type, operating system, browser type and version);
- IP address and approximate geographic location derived from it;
- Login timestamps, session duration, and access logs;
- Feature usage data and interaction logs (which pages or features you use, how often, and for how long); and
- Cookies and similar tracking technologies (see Section 3.10 below for further details).
3.4 Data we receive from third parties
We may receive personal data about you from third parties, including:
- Our clients, who may provide us with the contact details of their authorized users when setting up accounts;
- Business directories, professional networks (e.g. LinkedIn), or publicly available sources, where we have a legitimate business reason to do so; and
- Referral partners or resellers who introduce us to prospective clients.
3.5 How we use your personal data
Company shall not pass on or sell online personal data to third parties. Company may, however, share data within its organization. This may include Company’s employees, agents, contractors and sub-contractors and the use of third-party systems to process such data. Company may use email address or other contact information for queries and other contacts in relation to development and improvement of its services as well as for marketing of its own services to the User.
Company may also send proposals and offers based on the usage statistic of the User in a responsible manner.
By sending personal data to Company the User is explicitly consenting to the processing and transfer of such data in ways described above. Company cannot be responsible for personal data which the User uploads and shares between other users of the services of Company. The User and the users of the shared information are responsible to maintain applicable statutory privacy.
The table below sets out the purposes for which we process your personal data as a data controller, the legal basis we rely on under Article 6 GDPR, and how long we retain the data.
Processing Activity
Personal Data Processed
Legal Basis
Retention Period
Recipients / Disclosures
Account and contract management
Name, job title, work email, telephone, employer name and address, account credentials, communication history, contract and order details
Performance of a contract (Art. 6(1)(b)); Legal obligation (Art. 6(1)(c)) — accounting and record-keeping requirements
Duration of the SaaS Agreement + 5 years
Internal account management teams; finance and legal teams; group companies (if any); professional advisors (confidential)
Billing and invoicing
Name, work email, billing address, payment method details (tokenised / card-not-present), VAT/tax number, transaction history, invoice records
Performance of a contract (Art. 6(1)(b)); Legal obligation (Art. 6(1)(c)) — tax and accounting law
Duration of the SaaS Agreement + 5 years (statutory minimum for accounting records under applicable law)
Finance team; payment processor(s) — see Section 6; tax authorities where required by law
Customer support and service delivery
Name, work email, telephone, job title, support ticket content (may include technical details and information you choose to share), device and browser information
Performance of a contract (Art. 6(1)(b)); Legitimate interests (Art. 6(1)(f)) — providing effective support and improving service quality
Duration of SaaS Agreement + 12 months
Customer support team; technical operations team; Sub-Processors providing support tooling
Sending operational and service communications
Name, work email, telephone (where provided)
Performance of a contract (Art. 6(1)(b)) — for essential service communications (e.g. security alerts, maintenance, legal notices, changes to terms)
Duration of SaaS Agreement
Communications platform provider(s) — see Section 6
Sending marketing and product update communications
Name, work email, employer, communication preferences
Consent (Art. 6(1)(a)) — where required; or Legitimate interests (Art. 6(1)(f)) — for business-to-business marketing to existing clients and prospects, subject to opt-out
Until you withdraw consent or opt out, or 3 years from last interaction, whichever is earlier
Marketing platform provider(s)
Service analytics and improvement
Pseudonymised usage data, log data, feature interaction data, performance and stability metrics, error reports
Legitimate interests (Art. 6(1)(f)) — improving the SaaS Service, ensuring platform security and stability, and developing new features
12 months (pseudonymised data); raw logs retained for 30 days
Internal analytics and engineering teams; analytics platform provider(s)
Security monitoring and fraud prevention
IP address, login data, access logs, device information, anomalous activity indicators
Legitimate interests (Art. 6(1)(f)) — protecting our systems, clients, and users from security threats and fraudulent activity
3 years (security logs)
Internal security team; security tooling providers
Legal and regulatory compliance
As required by applicable law (e.g. name, address, transaction data for tax, anti-money laundering, or export control purposes)
Legal obligation (Art. 6(1)(c))
As required by the applicable legal obligation
Relevant regulatory or law enforcement authorities where required by law; legal advisors
Establishing, exercising, or defending legal claims
Personal data relevant to the claim, as determined by the circumstances
Legitimate interests (Art. 6(1)(f)) — access to justice and protection of our legal rights
Duration of relevant legal proceedings + 5 years
Legal advisors; courts and tribunals; counterparties to proceedings
Recruitment and job applications
Name, contact details, CV/resume, employment history, qualifications, references, interview notes
Steps taken at your request prior to entering into a contract (Art. 6(1)(b)); Legitimate interests (Art. 6(1)(f)) — managing recruitment
6 months from conclusion of recruitment process (unsuccessful applicants); duration of employment + 10 years (successful applicants)
HR team; hiring managers; recruitment platform provider(s) — see Section 6
3.6 Automated decision making and profiling
We do not make any decisions about you that are based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 GDPR.
3.7 Who we share your personal data with
Within our organization. Access to your personal data within our organization is restricted to employees and contractors who need it to perform their job functions, including our account management, finance, legal, customer support, security, and engineering teams. All staff are subject to binding confidentiality and data protection obligations.
Third-party service providers. We engage carefully selected third-party service providers to support our operations. These providers process personal data on our behalf (as our processors) or as independent controllers, as:
- Payment processors
- Cloud infrastructure / hosting providers
- Customer support platform
- CRM and marketing automation
- Analytics providers
- Security and monitoring tools
- Email and communications providers
- Recruitment platforms
- Professional advisors
Authorities and legal disclosures. We may disclose personal data to public authorities, law enforcement, regulators, or courts where required to do so by applicable law, by court order, or to protect our legal rights, the safety of our users, or the integrity of our services. We will, where legally permitted, notify you before making such a disclosure.
Business transfers. In the event of a merger, acquisition, reorganization, sale of assets, or insolvency proceedings involving our business, personal data may be transferred to the acquirer or successor entity as part of that transaction, subject to equivalent data protection protections.
3.8 International Data Transfers
We are based in the European Economic Area (EEA) and may transfer personal data to countries outside the EEA. Where we do so, we ensure that appropriate safeguards are in place to protect your data in accordance with applicable data protection law, including the EU General Data Protection Regulation (GDPR).
Such safeguards may include
- Standard Contractual Clauses approved by the European Commission;
- Transfers to countries recognized by the European Commission as providing an adequate level of data protection; or
- Other legally recognized transfer mechanisms where applicable.
3.9 How long we keep your personal data
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any applicable legal, accounting, or regulatory requirements. The retention periods applicable to each processing activity are set out in the table in Section 3.5.
In determining the appropriate retention period, we consider the nature and sensitivity of the personal data, the potential risk of harm from unauthorized use or disclosure, the purposes for which we process the data and whether we can achieve those purposes through other means, and applicable legal requirements.
At the end of the applicable retention period, personal data is securely deleted or anonymized. Where anonymization is not possible (for example, because the data is stored in backup archives), we will securely store the data and isolate it from any further processing until deletion is possible.
3.10 Cookies
We may place in your computer information in the form of a text file known commonly as a “cookie”. A cookie may enable collection of certain information about the computer of the User, including the internet protocol (IP) address, the computer’s operating system, the browser type and the address of any referring sites. The use of cookies is intended to provide benefits to the User, such as eliminating the need to enter password frequently during a session. Cookies are also used for website traffic analysis and anonymous demographic profiling in order to improve services of Company.
3.11 Security
We take the security of your personal data seriously and implement appropriate technical and organizational measures to protect it against unauthorized access, accidental loss, alteration, or disclosure.
These measures include
- Encryption of personal data in transit and at rest;
- Access controls ensuring that only authorized personnel can access your data;
- Regular security assessments and testing of our systems; and
- Staff training on data protection and information security.
While we do our best to protect your personal data, please be aware that no method of transmission over the internet is completely secure. In the event of a data breach that is likely to affect your rights and freedoms, we will notify you and the relevant supervisory authority as required by law.
4. AMENDMENTS
Company may change or modify this Privacy Policy in its sole discretion. Changes become effective immediately upon posting them at Company website. The continued use of the websites or services of Company after any changes or modifications constitutes the User’s acceptance to such. The User should review the most current version of the Privacy Policy at the above-mentioned web address regularly.
5. APPLICABLE LAW
This Privacy Policy shall be construed, governed and enforced in accordance with the laws of Finland without giving effect to any principle of law which would result in the application of laws of any other jurisdiction, and irrespective whether the websites of Company have been accessed from Finland or abroad. Helsinki District Court, Finland (Helsingin käräjäoikeus) shall have exclusive jurisdiction over any dispute arising out of use or non-use of the websites of Company.
6. USER RIGHTS
We would like to make sure you are fully aware of all of your data protection rights. Every user is entitled to the following:
The right to access – You have the right to request Company for copies of your personal data. Company may charge you a small fee for this service.
The right to rectification – You have the right to request that Company corrects any information you believe is inaccurate. You also have the right to request Company to complete information you believe is incomplete.
The right to erasure – You have the right to request that Company erases your personal data, under certain conditions.
The right to restrict processing – You have the right to request that Company restricts the processing of your personal data, under certain conditions.
The right to object to processing – You have the right to object to Company’s processing of your personal data, under certain conditions.
The right to data portability – You have the right to request that Company transfers the data that we have collected to another organization, or directly to you, under certain conditions. If you make a request, Company has one month to respond to you. If you would like to exercise any of these rights, please contact Company at email: john.bjorkbom(a)bjorkbomtrading.fi
In case personal data of a User is removed Company may not be able to continue to provide services to that User.
DATA PROCESSING AGREEMENT
This Data Processing Agreement (“Agreement”) is entered into by and between T.R. Björkbom-Trading Oy, a Finnish Corporation, with its principal place of business at Veneentekijäntie 8, Helsinki, Finland (“Processor”), and Processor’s respective client (“Controller”) having entered into Helm1 Subscription and End User License Agreement (“SaaS Agreement”).
The Processor and the Controller are each referred to individually as a “Party” and collectively as the “Parties”.
Recitals
The Parties have entered into a SaaS Agreement under which the Processor provides the Controller with access to a software-as-a-service platform (“SaaS Service”). In connection with providing the SaaS Service, the Processor will process personal data on behalf of and under the instructions of the Controller.
In addition to acting as processor of the Controller’s personal data, the Processor, in its capacity as a commercial service provider, independently determines the purposes and means of processing certain personal data of the Controller (including personal data of the Controller’s authorized users and employees) for its own legitimate business purposes connected with the service provider–client relationship, including contract management, invoicing, customer support, communications, and service improvement. In relation to such processing, the Processor acts as an independent controller.
This Agreement is entered into to: (i) satisfy the requirement of Article 28(3) of the General Data Protection Regulation (EU) 2016/679 (“GDPR”) for a binding written agreement governing the Processor’s processing of personal data on behalf of the Controller.
This Agreement supplements and is incorporated into the SaaS Agreement. In the event of any conflict between this Agreement and the SaaS Agreement regarding data protection matters, this Agreement shall prevail.
NOW, THEREFORE, in consideration of the mutual covenants set out herein, and for other good and valuable consideration, the receipt and sufficiency of which are hereby acknowledged, the Parties agree as follows:
1. DEFINITIONS AND INTERPRETATION
1.1 In this Agreement, the following terms shall have the meanings set out below. Terms not defined herein shall have the meanings ascribed to them in the GDPR.
a. “Applicable Data Protection Law” means the GDPR, any national law enacted pursuant to the GDPR, and any applicable supervisory guidance issued thereunder, each as amended or replaced from time to time.
b. “Controller Personal Data” means personal data of which the Controller is the controller and which is provided to, or accessed by, the Processor in connection with the SaaS Service, as further described in Annex 1.
c. “Data Subject” means an identified or identifiable natural person as defined in Article 4(1) GDPR.
d. “GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data.
e. “Personal Data Breach” means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored or otherwise processed.
f. “Processor Own-Controller Data” means personal data processed by the Processor as an independent controller in the context of the service provider–client relationship.
g. “Processing” (and cognate terms) has the meaning given in Article 4(2) GDPR.
h. “SaaS Agreement” means the software-as-a-service subscription agreement between the Parties referenced in the Parties table above, including all order forms, schedules, and exhibits thereto.
i. “SaaS Service” means the software-as-a-service platform and related services provided by the Processor to the Controller under the SaaS Agreement.
j. “Standard Contractual Clauses” or “SCCs” means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission pursuant to Article 46(2) GDPR, as currently in force.
k. “Sub-Processor” means any third party engaged by the Processor to carry out specific processing activities on its behalf with respect to Controller Personal Data.
l. “Supervisory Authority” means an independent public authority responsible for monitoring the application of the GDPR, as referred to in Article 51 GDPR.
m. “Technical and Organizational Measures” or “TOMs” means the security and data protection measures implemented by the Processor.
1.2 References to clauses, annexes, and schedules are to clauses, annexes, and schedules of this Agreement. Headings are for convenience only and shall not affect interpretation.
1.3 Where the context requires, the singular includes the plural and vice versa.
2. SCOPE
This Agreement governs Processor processing of Controller Personal Data by the Processor on behalf of and under the instructions of the Controller, where the Processor acts as a processor within the meaning of Article 4(8) GDPR.
3. NATURE, PURPOSE AND DETAILS OF PROCESSING
3.1 The details of the Processor Processing — including the subject matter, duration, nature and purpose of the processing, the type of personal data, and the categories of Data Subjects — are set out in Annex 1 to this Agreement.
3.2 The Processor shall process Controller Personal Data only for the purpose of providing the SaaS Service to the Controller in accordance with the SaaS Agreement and this Agreement, and only to the extent and in such manner as is necessary for that purpose, unless required otherwise by Union or Member State law to which the Processor is subject.
3.3 The Parties shall update Annex 1 if there is any material change in the processing activities, including where the Controller requests a new category of processing or new categories of Data Subjects, prior to such processing commencing.
4. PROCESSING INSTRUCTIONS
4.1 The Processor shall process Controller Personal Data in order to fulfill Prosessor’s obligations according to SaaS Agreement and this Data Processing Agreement. Furthermore, the Processor may may process such data on the documented instructions of the Controller, unless required to do so by Applicable Data Protection Law to which the Processor is subject. In such case, the Processor shall, to the extent permitted by law, inform the Controller of that legal requirement before processing.
4.2 If the Processor considers that any instruction from the Controller infringes Applicable Data Protection Law, the Processor shall promptly inform the Controller. The Processor is not required to follow instructions that are manifestly unlawful.
4.3 The Controller represents and warrants that it has, and will maintain throughout the term of this Agreement, a lawful basis under Applicable Data Protection Law for instructing the Processor to process Controller Personal Data as contemplated by this Agreement.
5. PROCESSOR OBLIGATIONS
5.1 The Processor shall:
a. process Controller Personal Data only in as set out in Clause 4, except where required otherwise by Applicable Data Protection Law;
b. ensure that persons authorized to process Controller Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;
c. implement and maintain the Technical and Organizational Measures, taking into account the nature, scope, context and purposes of processing and the risks to the rights and freedoms of Data Subjects;
d. taking into account the nature of the processing, assist the Controller by appropriate TOMs insofar as this is possible in the fulfilment of the Controller’s obligation to respond to Data Subject requests under Chapter III GDPR, as further set out in Clause 10;
e. assist the Controller in ensuring compliance with its obligations under Articles 32 to 36 GDPR (security, breach notification, DPIAs, and prior consultation), taking into account the nature of the processing and the information available to the Processor, as further set out in Clauses 7 and 8;
f. upon the choice of the Controller, delete or return all Controller Personal Data at the end of the provision of services relating to processing, and delete existing copies unless Union or Member State law requires storage of the personal data, as further set out in Clause 13; and
g. make available to the Controller all information necessary to demonstrate compliance with Article 28 GDPR, and allow for and contribute to audits and inspections by the Controller or an auditor mandated by the Controller, as set out in Clause 14.
6. CONFIDENTIALITY
6.1 The Processor shall ensure that access to Controller Personal Data is limited to those employees, contractors, agents, and authorized personnel of the Processor and its Sub-Processors who have a strict need to know in order to perform the SaaS Service.
6.2 The Processor shall ensure that all such persons are subject to binding obligations of confidentiality with respect to Controller Personal Data, whether by contract, professional rules, or statutory obligation. Such obligations shall survive the termination or expiry of the relevant employment or engagement.
6.3 The Processor shall not disclose Controller Personal Data to any third party except: (a) to authorized Sub-Processors in accordance with Clause 9; (b) as required by Applicable Data Protection Law or other applicable law, in which case the Processor shall, where legally permitted, give the Controller prior written notice; or (c) with the prior written consent of the Controller.
7. SECURITY OF PROCESSING
7.1 The Processor shall implement and maintain the Technical and Organisational ensuring a level of security appropriate to the risk presented by the processing and the nature of the Controller Personal Data to be protected, in accordance with Article 32 GDPR.
7.2 In assessing the appropriate level of security, the Processor shall take into account, in particular, the risks presented by accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Controller Personal Data transmitted, stored or otherwise processed.
7.3 The Processor shall not reduce the level of security provided by the TOMs without the prior written consent of the Controller. The Processor shall keep the TOMs under review and update them in accordance with developments in technology and changes in the risk landscape.
7.4 The Processor shall ensure that any Sub-Processors engaged to process Controller Personal Data are subject to equivalent security obligations.
8. PERSONAL DATA BREACH NOTIFICATION
8.1 The Processor shall notify the Controller of a Personal Data Breach affecting Controller Personal Data without undue delay and, where feasible, no later than twenty-four (24) hours after becoming aware of the breach.
8.2 The notification shall, to the extent the information is available, include
a. a description of the nature of the Personal Data Breach, including, where possible, the categories and approximate number of Data Subjects concerned and the categories and approximate number of personal data records concerned;
b. the name and contact details of the Processor’s data protection officer or other contact point from which more information can be obtained;
c. a description of the likely consequences of the Personal Data Breach; and
d. a description of the measures taken or proposed to address the Personal Data Breach, including, where appropriate, measures to mitigate its possible adverse effects.
8.3 Where the information required in Clause 8.2 is not fully available at the time of initial notification, the Processor shall provide the information in phases as it becomes available, without undue further delay.
8.4 The Processor shall document all Personal Data Breaches, including those not required to be notified to a Supervisory Authority, in accordance with Article 33(5) GDPR. Such documentation shall be made available to the Controller upon request.
8.5 The Processor shall cooperate fully with the Controller in the investigation, remediation, and notification of any Personal Data Breach to Supervisory Authorities and Data Subjects, to the extent required by Applicable Data Protection Law.
8.6 The Processor shall not communicate to any Data Subject or to any third party, including any Supervisory Authority, about a Personal Data Breach affecting Controller Personal Data without the prior written consent of the Controller, unless required to do so by Applicable Data Protection Law.
9. SUB-PROCESSORS
9.1 The Controller grants the Processor general written authorization to engage Sub-Processors, subject to the conditions set out in this Clause 9.
9.2 The Processor shall inform the Controller of any intended changes concerning the addition or replacement of Sub-Processors by providing the Controller with written notice at least 7 calendar days prior to the intended change taking effect. The Controller may object to the addition or replacement of a Sub-Processor on reasonable data protection grounds within 5 calendar days of receiving notice. If the Controller objects and the Parties cannot resolve the objection within a further 7 days, either Party may terminate the SaaS Agreement and this Agreement on written notice.
9.3 Where the Processor engages a Sub-Processor, it shall impose on the Sub-Processor data protection obligations that offer at least equivalent levels of protection to those set out in this Agreement, by means of a binding written sub-processing agreement. In particular, the Sub-Processor shall be required to comply with the obligations applicable to the Processor under Article 28(3) GDPR.
9.4 The Processor remains fully liable to the Controller for the performance of Sub-Processors’ obligations under the sub-processing agreement to the extent that those Sub-Processors fail to fulfil their data protection obligations.
10. DATA SUBJECT RIGHTS
10.1 Taking into account the nature of the processing, the Processor shall assist the Controller, by appropriate technical and organizational measures insofar as this is possible, in fulfilling the Controller’s obligation to respond to Data Subject requests for the exercise of their rights under Chapter III GDPR, including rights of:
a. access (Article 15 GDPR);
b. rectification (Article 16 GDPR;
c. erasure (Article 17 GDPR);
d. restriction of processing (Article 18 GDPR);
e. data portability (Article 20 GDPR); and
f. objection (Article 21 GDPR).
10.2 Should a Data Subject contact the Processor directly with a request to exercise any of the rights listed in Clause 10.1 in relation to Controller Personal Data, the Processor shall promptly, and in any event within 5 business days, forward the request to the Controller and shall not respond to the Data Subject without the Controller’s prior written authorization, unless required to do so by Applicable Data Protection Law.
10.3 Processor shall, upon request, provide the Controller with reasonable assistance in responding to any Data Subject request, including by extracting, rectifying, restricting, porting, or deleting Controller Personal Data within the SaaS Service, within the timeframes reasonably specified by the Controller.
11. DATA PROTECTION IMPACT ASSESSMENTS AND PRIOR CONSULTATION
11.1 The Processor shall provide the Controller with all reasonable assistance in relation to any data protection impact assessment (“DPIA”) that the Controller is required or chooses to carry out pursuant to Article 35 GDPR, taking into account the nature of the processing and the information available to the Processor.
11.2 The Processor shall assist the Controller with any prior consultation with a Supervisory Authority required under Article 36 GDPR, providing such information as may be reasonably requested by the Controller or the relevant Supervisory Authority.
12. INTERNATIONAL TRANSFERS OF CONTROLLER PERSONAL DATA
12.1 The Processor shall not transfer, or permit the transfer of, Controller Personal Data to a country or territory outside the European Economic Area (“EEA”) unless:
a. The European Commission has adopted an adequacy decision in relation to the destination country under Article 45 GDPR;
b. appropriate safeguards are in place in accordance with Article 46 GDPR, including Standard Contractual Clauses; or
c. one of the derogations in Article 49 GDPR applies and the Controller has provided its prior written consent.
12.2 The Processor shall inform the Controller of any circumstances that may affect the availability or validity of a transfer mechanism relied upon under Clause 12.1, including any relevant decisions, laws, or circumstances in the destination country that may impair the protection afforded to Controller Personal Data.
13. RETENTION AND DELETION OF CONTROLLER PERSONAL DATA
13.1 The Processor shall not retain Controller Personal Data for longer than is necessary to provide the SaaS Service or as otherwise instructed in writing by the Controller, subject to any mandatory retention requirements under Applicable Data Protection Law or other applicable law.
13.2 The Processor shall, in respect of Controller Personal Data, apply the retention periods set out in Annex 1.
13.3 Upon termination or expiry of the SaaS Agreement, or upon written request of the Controller at any time, the Processor shall, at the choice of the Controller and within 7 calendar days of receiving such instruction:
a. securely delete or destroy all Controller Personal Data (including all copies and backups) in its possession, custody, or control; or
b. securely return all Controller Personal Data to the Controller in a structured, commonly used and machine-readable format, and in either case provide written certification to the Controller that it has done so, save to the extent that Applicable Data Protection Law or other applicable law requires continued storage of the Controller Personal Data.
13.4 The Processor shall ensure that Sub-Processors are subject to equivalent obligations regarding deletion and return of Controller Personal Data.
14. AUDIT RIGHTS AND INFORMATION
14.1 The Processor shall make available to the Controller, upon reasonable prior written notice of not less than 7 business days, all information reasonably necessary to demonstrate compliance with the obligations laid down in this Agreement and in Article 28 GDPR.
14.2 The Processor shall allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller, subject to the following conditions:
a. audits shall be conducted during normal business hours, subject to reasonable advance written notice;
b. the Controller shall bear all costs and expenses associated with the audit;
c. audits shall be conducted no more than once per calendar year, absent a reasonable cause related to a suspected breach of this Agreement or a Personal Data Breach; and
d. auditors must execute a confidentiality agreement acceptable to the Processor prior to conducting any audit.
14.3 The Processor may satisfy the audit requirements of this Clause, in whole or in part, by providing the Controller with up-to-date third-party audit reports or certifications (e.g. ISO 27001, SOC 2 Type II) that adequately address the subject matter of the requested audit.
14.4 The Processor shall promptly provide any information reasonably requested by the Controller, the Controller’s data protection officer, or a competent Supervisory Authority in connection with any investigation into the processing activities under this Agreement.
15. PROCESSOR’S OWN-CONTROLLER PROCESSING
15.1 This Data Processing Agreement does not cover personal data the Processor processes certain personal data of the Controller’s employees, representatives, and authorized users as an independent data controller. The processing of such data is governed by the Privacy Policy of the Processor forming an integral part of Subscription and End User License Agreement as schedule A, available on the Company’s web site in www.helm1.com.
16. LIABILITY
16.1 Each Party shall be individually and independently liable for its own compliance with Applicable Data Protection Law in relation to the processing activities for which it is responsible under this Agreement.
16.2 Where both Parties have contributed to damage caused by processing in breach of Applicable Data Protection Law, they shall be jointly and severally liable in accordance with Article 82 GDPR, subject to the right of each to be exonerated from liability to the extent they can prove that the damage is not attributable to them.
16.3 Each Party shall indemnify and hold harmless the other Party against any fines, penalties, claims, damages, costs, and expenses (including reasonable legal fees) arising from that Party’s breach of its obligations under this Agreement or under Applicable Data Protection Law.
16.4 Any limitation of liability set out in the SaaS Agreement shall apply to this Agreement to the extent permitted by Applicable Data Protection Law, save that no limitation shall apply to a Party’s liability for: (a) intentional or grossly negligent breaches; (b) fines or administrative penalties imposed by a Supervisory Authority; or (c) liability to Data Subjects under Article 82 GDPR.
17. TERM AND TERMINATION
17.1 This Agreement shall enter into force at the same time with the SaaS Agreement and shall remain in force for as long as the Processor processes Controller Personal Data pursuant to the SaaS Agreement, unless terminated earlier in accordance with this Clause.
17.2 This Agreement shall automatically terminate upon the termination or expiry of the SaaS Agreement, subject to any surviving obligations expressly provided herein.
17.3 Either Party may terminate this Agreement immediately by written notice if the other Party commits a material breach of this Agreement that is incapable of remedy, or fails to remedy a remediable material breach within thirty (30) calendar days of receiving written notice specifying the breach.
17.4 The following clauses shall survive the termination or expiry of this Agreement: Clause 6, Clause 13, Clause 16, Clause 17, Clause 18, and any other provisions which by their nature or express terms should survive.
18. GENERAL PROVISIONS
18.1 Governing law. This Agreement shall be governed by and construed in accordance with Finnish law, excluding its choice of law rules.
18.2 Dispute resolution. Any dispute, which may arise between the parties concerning this Agreement, shall be determined by Helsingin käräjäoikeus (District Court of Helsinki).
18.3 Entire Agreement. This Agreement, together with its Annexes and the SaaS Agreement, constitutes the entire agreement of the Parties with respect to the subject matter hereof and supersedes all prior discussions and agreements. In the event of a conflict between the SaaS Agreement and this Agreement on data protection matters, this Agreement prevails.
18.4 Amendments. No amendment to this Agreement is effective unless made in writing and signed or otherwise agreed to by duly authorized representatives of both Parties.
18.5 Severability. If any provision of this Agreement is found to be invalid or unenforceable under applicable law, such provision shall be modified to the minimum extent necessary to make it valid and enforceable, and the remaining provisions shall continue in full force and effect.
18.6 Notices. All notices under this Agreement shall be in writing and delivered to the contact details set out in the Parties table, or such other address as a Party may designate by written notice to the other Party.
18.7 Counterparts. This Agreement may be executed in counterparts, each of which shall be deemed an original. Electronic signatures shall be valid and binding.
18.8 No Waiver. Failure by either Party to enforce any right under this Agreement shall not constitute a waiver of that right.
Annex 1 to Data Processing Agreement
T.R BJÖRKBOM-TRADING OY
RECORD OF PROCESSING ACTIVITIES PURSUANT TO ARTICLE 30 GDPR / hELM1
1. Processor
T.R. Björkbom-Trading Oy Ab (hereinafter “TRB”)
Business ID | 0723426-4 |
Address | Veneentekijäntie 8, Helsinki, Finland |
Contact person for data protection matters | John Björkbom |
john.bjorkbom@bjorkbomtrading.fi | |
Telephone | +358 50 555 3536 |
2. Personal Data Processed and Data Subjects
TRB processes, on behalf of the Customer acting as Controller in connection with the hELM1 service, the following categories of personal data:
- name
- work email address
- role or user group
- user credentials and status of user credentials
- administrator credentials, administrator role, and status of administrator credentials
- access rights-related data
- login and log data
Categories of data subjects: The Customer’s employees and contact persons using the website in various roles.
3. Purposes of Processing and Legal Basis
- Provision and maintenance of services
- Verification of identity
- Customer support
- Development of services
- Notification of new services and features
- Technical administration of the service
- Maintenance of information security
- Access control
- Support services
- Log data
Legal bases: Performance of a contract (customer relationship), compliance with legal obligations, legitimate interests, and consent.
4. Recipients of Personal Data
Personal data is transferred to the following processors:
IT service providers: Development, maintenance, and management of information systems.
Hosting service providers: Maintenance and development of services.
5. Transfers of Personal Data to Third Countries or International Organizations
Personal data is currently transferred outside the EU/EEA, in particular to cloud service platforms located in the United States. Appropriate safeguards are applied to such transfers, including standard contractual clauses and any necessary supplementary technical, organizational, or contractual measures in accordance with the GDPR. It is intended to modify the system in the near future so that the relevant services will be located within the EU.
6. Retention Periods for Personal Data
Personal data is retained as follows:
Website visitors’ data (cookies): 12 months from the last activity.
Service users: 1 month from the date on which the customer has removed the person as a user of the service.
7. Security Measures for Personal Data
Personal data is protected by appropriate technical and organizational measures. Data is stored in an encrypted database on servers provided by third-party cloud service providers. Access to personal data is restricted to authorized employees and service providers who require the data for the performance of their duties and who are bound by a duty of confidentiality. Access to the internal network requires two-factor authentication.