Master Service Agreement
This Master Service Agreement (the "MSA") is entered into between the Service Provider White Label Consultancy AS, Fjordalléen 16, 0250 Oslo, Norway or any of its Affiliates, as designated in the applicable Order Form (hereinafter "WLC", "we", "us", or "Service Provider") and Customer as listed on the Order Form. Service Provider provides access to its software-as-a-service platform branded as "Pritect" or "Pritect.ai" (the "Platform"). Service Provider and Customer may also be referred to individually as "Party" or collectively as the "Parties." It is effective as of the date of Customer's acceptance of the Order Form to which this MSA is incorporated by reference.
Capitalized terms used herein will have the definitions designated in the applicable section where they are defined.
1. Definitions
For purposes of this Master Service Agreement ("MSA"), the following capitalized terms shall have the meanings set forth below. Capitalized terms not defined in this Section shall have the meanings assigned to them elsewhere in this MSA or in an applicable Order Form.
2. Provision of Services
Customer's access to the Platform is limited to the selected Platform Tier and the subscribed Suites, and is subject to the usage limits and technical constraints described in the Documentation and the applicable Order Form.
Each Platform Tier defines the scope of Platform functionality, security features, and the maximum number of permitted Users. Suites are modular solution components that provide specific functionality within the Platform. Customer may subscribe to one or more Suites concurrently.
Customer acknowledges that access to the Platform without an active Suite subscription is not available.
Customer is solely responsible for selecting the Platform Tier and Suites that meet its needs. Under this MSA, the Services are provided for informational and operational purposes only and do not constitute legal, regulatory, or professional advice. WLC does not guarantee that any specific Platform Tier or Suite will ensure compliance with applicable law.
Implementation Services are governed by the Implementation Services Terms, which form an integral part of this MSA by reference. In the event of any conflict between this MSA and the Implementation Services Terms, the Implementation Services Terms shall prevail with respect to Implementation Services only.
Service Provider maintains administrative, technical, and organizational measures designed to protect Customer Data, including non-personal confidential Customer Data, against unauthorized access, loss, or disclosure, taking into account the nature of the Platform, the state of the art, and applicable legal requirements.
Service Provider shall not materially reduce the core functionality of the subscribed Platform Tier or Suites during the Term. Minor changes, user interface adjustments, or changes required to comply with applicable law or security requirements shall not be deemed material.
If actual measured monthly uptime falls below 99.5% in any calendar month, Customer may request a service credit equal to five percent (5%) of the Fees paid for that calendar month. Such service credit constitutes Customer's sole and exclusive remedy for failure to meet the availability commitment set out in this Section.
Subject to the foregoing, the Platform and Services are provided on an "as-is" and "as available" basis, and Service Provider does not warrant uninterrupted availability or error-free operation of the Platform.
Nothing in this MSA excludes or limits any rights or remedies that Customer may have under mandatory provisions of applicable law.
3. Customer Responsibilities
Customer shall ensure that only authorized Users access and use the Platform and that such access is limited to Customer's internal business and compliance purposes.
Customer remains responsible for all actions taken by its Users in connection with the use of the Platform, except to the extent such actions result directly from Service Provider's breach of this MSA.
Customer is responsible for maintaining the confidentiality and security of User login credentials and for ensuring that appropriate internal controls are in place to prevent unauthorized access to the Platform.
Customer shall promptly notify Service Provider if it becomes aware of any actual or suspected unauthorized access to the Platform or misuse of User accounts.
If Customer exceeds the permitted number of Users, Service Provider may, upon notice to Customer, require Customer to upgrade its Platform Tier, restrict access for excess Users, or take other reasonable measures to restore compliance with the applicable limits.
Customer shall ensure that Customer Data does not infringe third-party rights or violate applicable law.
Service Provider is not responsible for any issues arising from Customer's equipment, systems, or internet connectivity.
Customer shall not, and shall not permit any User or third party to:
- (a) resell, sublicense, lease, or otherwise make the Platform available to any third party, other than Customer's Affiliates and authorized Users acting within Customer's Tenant, except as expressly permitted under this MSA;
- (b) use the Platform for unlawful, fraudulent, misleading, or unethical purposes;
- (c) attempt to gain unauthorized access to the Platform, systems, or data;
- (d) interfere with the integrity, security, or performance of the Platform;
- (e) introduce or transmit Malicious Code;
- (f) use the Platform to build or support a competing product or service;
- (g) conduct benchmarking or comparative analysis intended for publication without Service Provider's prior written consent; or
- (h) use the Platform or any Service Provider Confidential Information to train artificial intelligence, machine learning, or similar models, except as expressly permitted by Service Provider in writing.
Customer acknowledges that the Platform is a tool designed to support compliance efforts and does not replace Customer's independent legal, regulatory, or risk assessments.
In particular, Customer shall not:
- (a) use a single Tenant to generate, store, or maintain compliance records, assessments, registries, or Platform outputs on behalf of, or for the benefit of, separate legal entities that are not Affiliates of Customer;
- (b) grant Platform access to individuals acting primarily on behalf of, or for the benefit of, a legal entity that is not an Affiliate of Customer; or
- (c) structure its use of the Platform in a manner that allows multiple independent legal entities that are not Affiliates of Customer to derive the benefit of Platform access through a single Customer subscription.
For the avoidance of doubt, this Section does not prohibit Customer from:
- (i) producing compliance outputs, reports, or assessments that reference or relate to third parties in the ordinary course of Customer's own compliance activities, where such references are incidental to Customer's own compliance program; or
- (ii) using the Platform in connection with services provided under a separate written agreement with Service Provider expressly authorising such use, including where Customer is an authorised partner or reseller of Service Provider.
Breach of this Section 3.12 shall constitute a material breach of this MSA and shall entitle Service Provider to immediate suspension or termination of access pursuant to Sections 13.4 and 13.5.
4. License Grant and Use of the Platform
No rights are granted to Customer other than those expressly set out in this Section.
- (a) Customer's right to use the Platform is limited to the selected Platform Tier and the subscribed Suites;
- (b) access to the Platform is limited to the number of Users permitted under the applicable Platform Tier; and
- (c) the Platform may be used only within Customer's own organization, including Customer's Affiliates as permitted under this MSA, and for its internal purposes.
Customer acknowledges that the Platform is provided as a software-as-a-service solution and that Customer is not provided with, and has no right to access, the source code of the Platform.
- (a) provide access to, sublicense, resell, lease, or otherwise make the Platform or Documentation available to any third party, except as expressly permitted under this MSA;
- (b) copy, modify, translate, reverse engineer, decompile, disassemble, or otherwise attempt to derive the source code or underlying structure of the Platform, except to the extent such restriction is prohibited by mandatory applicable law;
- (c) use the Platform in violation of this MSA, the Documentation, or applicable law;
- (d) interfere with or disrupt the integrity, security, or performance of the Platform;
- (e) introduce or transmit Malicious Code; or
- (f) use the Platform in a manner that infringes intellectual property rights or misappropriates Confidential Information.
Use of such open-source components is governed by the terms of the applicable open-source licenses and not by this MSA, except to the extent that this MSA imposes additional restrictions permitted by such licenses.
A current list of open-source software components and the applicable open-source licenses used by Service Provider is available at: https://www.pritect.ai/trust/licenses.
5. Proprietary Rights and Licenses
This includes all Updates, enhancements, modifications, derivatives, templates, configurations, designs, workflows, and other developments relating to the Platform, whether created by or on behalf of Service Provider.
Except for the limited license expressly granted under Section 4, no rights or licenses are granted to Customer by implication or otherwise.
Customer grants Service Provider and its authorized sub-processors a limited, non-exclusive, worldwide license, for the duration of the Term, to process Customer Data solely as necessary to provide, operate, maintain, support, and improve the Platform and the subscribed Suites in accordance with this MSA and the DPA.
Usage Data shall be processed only in an aggregated and anonymized form and shall not identify Customer or any individual.
6. Fees and Payment
Except as expressly stated in this MSA or required by applicable law, all payment obligations are non-cancellable and all Fees paid are non-refundable.
Where Platform access is included in fees payable under a separate agreement, that agreement shall govern pricing and payment for such access, and this MSA shall apply only to the extent not otherwise regulated.
Customer authorizes Service Provider to charge the selected payment method for all applicable Fees in accordance with the billing cycle selected by Customer.
If the Term is limited, recurring payments may be automatically set up through Customer's chosen payment system to renew the subscription upon expiration of the initial Term. Customer may cancel such recurring payments directly through the applicable payment system.
Before submitting an Order Form, Customer will be informed of the applicable Fees. The final charge will be displayed prior to completion of the Order Form.
- (a) Customer's acceptance of an Order Form through an online checkout, click-through process, or similar electronic means made available by or on behalf of the Service Provider;
- (b) Customer's written confirmation of an Order, including by email; or
- (c) issuance of an invoice by Service Provider in response to Customer's request for invoice-based payment.
For purchases with total Fees of three hundred euros (EUR 300) or more (or the equivalent amount in another currency), Customer may request payment by invoice by contacting Service Provider at hello@pritect.ai. If accepted by Service Provider, the applicable Fees and payment due date shall be set out in an Order Form and reflected in the issued invoice.
Invoices shall be payable within the timeframe specified in the applicable Order Form, without deduction or set-off. Service Provider reserves the right to decline to issue an invoice.
Service Provider shall have no obligation to provide access to the Platform during any period of suspension resulting from non-payment in accordance with this Section.
Customer is responsible for paying all applicable Taxes associated with its purchases under this MSA. If Taxes are required to be charged by Service Provider, they will be added to the invoice unless Customer provides a valid tax exemption certificate.
Taxes not invoiced by Service Provider shall be Customer's responsibility to report and remit to the relevant tax authorities.
7. Third-Party Applications
Use of Third-Party Applications is subject solely to the terms and conditions agreed between Customer and the applicable third-party provider. Service Provider does not control and is not responsible for Third-Party Applications or their availability, functionality, or performance.
Customer is solely responsible for ensuring that its use of Third-Party Applications complies with applicable law and any contractual obligations owed to third-party providers.
Service Provider shall not be liable for any damage, loss, or interruption arising from Customer's use of or reliance on Third-Party Applications.
8. AI-Supported Features
Customer acknowledges that the use of AI-Supported Features is strictly optional and will not be activated unless Customer uses and interacts with an AI-Supported Feature.
Such outputs are intended to support, not replace, Customer's independent judgment, legal analysis, or compliance decision-making. Customer remains solely responsible for reviewing, validating, and determining how to use any AI-generated output.
Use of AI-Supported Features does not relieve Customer of its obligation to comply with applicable laws, including data protection and regulatory requirements.
Nothing in this MSA shall be interpreted as creating an obligation for Service Provider to ensure Customer's compliance with such laws.
9. Confidentiality
Confidential Information includes, without limitation, information relating to the Platform, the Services, Documentation, security measures, pricing, business plans, product roadmaps, technical information, Customer Data, and the terms of this MSA and any Order Form.
Confidential Information does not include information that the Receiving Party can demonstrate:
- (a) is or becomes publicly available without breach of this MSA;
- (b) was lawfully known to the Receiving Party prior to disclosure;
- (c) is independently developed by the Receiving Party without use of the Disclosing Party's Confidential Information; or
- (d) is lawfully obtained from a third party without restriction.
- (a) use the Confidential Information solely for the purposes of performing its obligations or exercising its rights under this MSA;
- (b) not disclose Confidential Information to any third party except to its employees, contractors, or advisors who have a legitimate need to know and are bound by confidentiality obligations no less protective than those set out herein; and
- (c) protect the Confidential Information using at least the same degree of care it uses to protect its own confidential information of a similar nature, and in no event less than reasonable care.
10. Disclaimer and Warranty
- (a) it has the legal authority and capacity to enter into and perform its obligations under this MSA; and
- (b) it will comply with all applicable laws in connection with its performance under this MSA.
Service Provider does not warrant that:
- (a) the Platform will be uninterrupted, error-free, or available at all times;
- (b) the Platform will meet Customer's specific requirements or expectations; or
- (c) all defects or errors will be corrected.
- (a) it has obtained and will maintain all necessary rights, permissions, and legal bases to provide Customer Data to Service Provider for processing in accordance with this MSA and the DPA; and
- (b) its use of the Platform complies with applicable law and does not infringe third-party rights.
11. Indemnification
Service Provider shall indemnify Customer for any direct damages finally awarded by a court of competent jurisdiction or agreed in a settlement approved by Service Provider, provided that such IP Claim arises solely from the Platform as provided by Service Provider and used in accordance with this MSA.
- (a) procure for Customer the right to continue using the Platform;
- (b) modify the Platform to make it non-infringing without materially reducing its functionality;
- (c) replace the affected part of the Platform with a non-infringing alternative with substantially similar functionality; or
- (d) if none of the foregoing is commercially reasonable, terminate the affected Order Form or this MSA upon written notice and refund any prepaid, unused Fees for the remaining portion of the applicable Term.
- (a) Customer Data or content provided by or on behalf of Customer;
- (b) use of the Platform in violation of this MSA or the Documentation;
- (c) modifications to the Platform not made by or on behalf of Service Provider;
- (d) combination of the Platform with third-party software, systems, or services not provided by Service Provider; or
- (e) use of the Platform after Service Provider has notified Customer to discontinue such use due to an IP Claim.
- (a) Customer Data, including allegations that Customer Data infringes third-party rights or violates applicable law; or
- (b) Customer's use of the Platform in violation of this MSA or applicable law.
Customer shall indemnify Service Provider for any direct damages finally awarded by a court of competent jurisdiction or agreed in a settlement approved by Customer.
- (a) promptly notifying the indemnifying Party in writing of the claim, provided that failure to give prompt notice shall not relieve the indemnifying Party of its obligations unless materially prejudiced;
- (b) granting the indemnifying Party reasonable control over the defence and settlement of the claim, provided that no settlement admitting liability on behalf of the indemnified Party may be entered into without its prior written consent, not to be unreasonably withheld; and
- (c) providing reasonable cooperation at the indemnifying Party's expense.
The indemnified Party may participate in the defence with its own counsel at its own expense.
12. Limitation of Liability
- (a) a Party's breach of its confidentiality obligations under this MSA;
- (b) a Party's willful misconduct or gross negligence;
- (c) Customer's payment obligations under this MSA;
- (d) Customer's indemnification obligations under Section 11.4; or
- (e) Service Provider's indemnification obligations under Section 11.1, provided that such indemnification liability shall in any event be limited to direct damages only.
13. Term and Termination
The Term of each subscription shall be as specified in the applicable Order Form and may include an initial term and one or more renewal terms.
Upon cancellation, Customer shall retain access to the Platform until the effective date of cancellation, unless access is suspended or terminated earlier in accordance with this MSA.
Customer shall not be charged for any subscription period following the effective date of cancellation.
Notwithstanding the foregoing, where Customer terminated this MSA or an applicable Order Form for cause pursuant to Section 13.5 below due to Service Provider's material breach, Service Provider shall refund to Customer a pro-rata portion of any prepaid Fees attributable to the unused portion of the then-current subscription period following the effective date of the termination.
- (a) Customer is in material breach of this MSA, including failure to pay applicable Fees or violation of Section 3 (Customer Responsibilities); or
- (b) suspension is reasonably necessary to protect the security or integrity of the Platform or Customer Data.
Where reasonably practicable, Service Provider shall provide Customer with prior notice of suspension and an opportunity to cure the breach.
Either Party may terminate this MSA with immediate effect if the other Party commits a material breach that cannot be cured.
- (a) all active Order Forms shall automatically terminate;
- (b) Customer and its Users shall immediately cease all access to and use of the Platform, except as expressly permitted below;
- (c) all outstanding payment obligations shall become immediately due and payable; and
- (d) for a period of thirty (30) days following termination, Service Provider shall, upon Customer's written request, make Customer Data available to Customer solely for the purpose of allowing Customer to retrieve such data, and, where requested, export and deliver it in a commonly accepted machine-readable format and, where applicable, a human-readable format, together with appropriate metadata, at no additional charge.
After the expiration of this thirty (30) day period, Service Provider may delete or anonymize Customer Data, unless retention is required by applicable law, in which case such data shall remain subject to the confidentiality obligations of this MSA.
14. General Provisions
Neither Party has authority to bind the other or to assume any obligation on the other's behalf.
All notices under this MSA shall be made in writing and delivered by email or other customary means with confirmation of receipt to the contact details maintained by Customer in the Platform. Contact details specified in an applicable Order Form or otherwise designated by a Party in writing may be used in addition to the contact information maintained on the Platform.
Notices shall be deemed given upon confirmation of receipt, unless mandatory applicable law requires a different form or timing of notice.
For matters relating to the Platform and the Services, Customer may contact WLC at hello@pritect.ai or at any other contact details communicated by WLC to Customer.
In the event of any conflict or inconsistency, the following order of precedence shall apply:
- (1) the Data Processing Addendum (DPA);
- (2) the applicable Order Form;
- (3) the Implementation Services Terms (if applicable);
- (4) this MSA; and
- (5) any other documents incorporated by reference.
If the Parties are unable to reach agreement within thirty (30) days of Customer's objection, Service Provider may, at its discretion, elect to continue providing Services to Customer under the previous version of the MSA. If Service Provider is not able or willing to continue under the previous version, either Party may terminate the applicable Order Form or this MSA by written notice without financial penalty, save for Fees accrued up to the effective date of termination and any obligations that survive termination under this MSA.
If no objection is raised within the thirty (30) day period, the updated MSA shall be deemed accepted by Customer and shall apply from the date specified in the notice.
For the avoidance of doubt, any amendment to an applicable Order Form requires prior written agreement of both Parties and shall not be the subject of the unilateral update mechanism set out above.
The affected Party shall use reasonable efforts to mitigate the effects of such events.
Notwithstanding the foregoing, either Party may assign this MSA without the other Party's consent (a) to an Affiliate, provided that the assigning Party remains responsible for the performance of the assignee's obligations under this MSA, or (b) in connection with a merger, reorganization, or sale of all or substantially all of its assets, provided that the assigning Party notifies the other Party within a reasonable time.
Any assignment in violation of this Section shall be null and void.
The Parties agree that the courts of Oslo, Norway, shall have exclusive jurisdiction over any dispute arising out of or in connection with this MSA, unless otherwise specified in the applicable Order Form.
