Data Privacy Notice

We, Alyne GmbH (“Alyne”, “we”, “us” or “ours”), regard the protection and the confidentiality of your data as very important. We process personal data in accordance with the relevant provisions of data protection legislation in the regions we operate in. In this privacy notice (“Privacy Notice”), we inform the related data subject (“you”, “your”) about how we collect, use, and share which categories of personal data for which purposes through our website (“Website”) and the related Alyne Software as a Service solution (“Alyne Service”), or when you interact with us online. You can access this Privacy Notice on our Website anytime. Your personal information may also be collected through our affiliates (e.g. Alyne Australia Pty Ltd, Alyne USA Inc and Alyne UK Ltd). Our Affiliates collect, use, and share your personal data in accordance with this Privacy Notice.

Data Controller

The data controller related to your personal data is:

Alyne GmbH
Ganghoferstr. 70a
D-80339 Munich
Germany

If you have any questions or concerns about data protection, you are welcome to also contact us by email at this address: [email protected]

Personal Data

Personal data means any information relating to an identified natural person, as well as any information that makes a natural person identifiable, directly or indirectly, in particular by reference to an identifier such as a name, a postal address, an email address, a telephone number or personal usage data, and includes personal data or personal information as defined in privacy or data protection laws that apply to you.

Categories of Personal Data

Alyne processes the personal data you provide to us, as well as Log Files and Cookies in order to operate and run Alyne’s business. We process personal data you provide to us in the following instances:

  • Providing the Alyne Service. We may process personal data in order to fulfil our contractual obligations towards our customers and their end users. This includes processing personal data you upload into the Alyne Service, payment processing, securing the effective and user-related use of the Alyne Service; sending you related information, including confirmations, invoices, technical notices, updates, security alerts, and support and administrative messages.
  • Customer Support, Feedback. If you provide us with feedback or contact our customer support via email, we will process your name and email address, as well as any other content included in the email, in order to send you a reply.
  • Compliance and Legal Protection. Complying with applicable laws and protection of our legitimate business interests and legal rights including to use in connection with legal claims, compliance, regulatory, investigative purposes (including disclosure of such information in connection with legal process or litigation).
  • User Account. If you register a user account, you must enter your email address and select a password. We need these and possibly other data not least in order to respond to your wishes, questions and criticism; and

When you visit our Website or use the Alyne Service, we collect and process certain personal data automatically:

  • Log Files. We gather certain information automatically and store it in log files. This information includes IP addresses, browser type, Internet service provider (“ISP”) data, referring/exit pages, operating system, date/time stamp, and clickstream data. We use this information for purposes including analysing trends, Website administration, tracking users’ movements around the Website and tailoring our Website and the Alyne Service to our users’ needs. Except as noted in this Privacy Notice, we do not link this automatically collected data to other personal data we have collected from you.
  • Cookies. See Cookies Section below.
  • Google Analytics. See Google Analytics Section below.

Purposes and Legal Basis

We process your personal data for the purposes described in this Privacy Notice or as disclosed to you on our Website or in connection with the Alyne Service. We only collect the minimum amount of personal data needed to perform the specific processing activity for which we have collected the personal data.

We would like to give you more detailed information about our purposes for processing this data and the legal basis we rely on for doing so:

Purposes of processing Type of personal data Legal basis of processing
Our contractual obligations and in order to provide the Alyne Service and your user account. Your name, email address, postal address, payment card details (if provided by you) and further account data and business-related personal data you provide to the Alyne Service. Art. 6 para. 1 lit. b) GDPR.
Customer Support, Feedback Your name, email address, postal address, phone number, payment card details (if provided by you) and further business-related personal data you provide in the communication to us. Our legitimate interest in maintaining our relationship with customers according to Article 6 para. 1 lit. f) GDPR.
Compliance with applicable laws and protection of our legitimate business interests and legal rights. Your name, email address, postal address, payment card details (if provided by you) and further account data and business-related personal data you provide to the Alyne Service. Our legitimate interest according to Article 6 para. 1 lit. f) GDPR or the respective laws requiring us to process your personal data (see Art. 6 para. 1 lit. c) GDPR).
Improving our Website and ensuring the safety and security of the Alyne Service. Technical information you provide when using the Website or the Alyne Service. Our legitimate interest according to Art. 6 para. 1 lit. f) GDPR; consent if necessary.
Newsletter Your name, surname and email address. Your consent (Art. 6 para. 1 lit. a) GDPR) or in some cases for existing customers, we may also base our processing on our legitimate interest according to Article 6 para. 1 lit. f) GDPR.
Marketing of the Alyne Service Your name, surname, email address, postal address, location, company name and product preferences. Your consent (Article 6 para. 1 lit. a) GDPR).
Providing the Alyne partner program Your name, your location, email address and further business-related personal data you provide to the Alyne Service. Our legitimate interest to perform the contract with the Alyne Partner according to Article 6 para. 1 lit. b) and lit. f) GDPR.
Web analytics and statistics to monitor; improve and protect our Website and the Alyne Service; providing tailored ads and user experience including facilitating identification and authentication, understanding you and your preferences in order to enhance your experience and enjoyment using our Website and the Alyne Service. Date and time of the request, name of the requested file, page visits, page from which the file was requested, access status (transfer file, file not found, etc.), web browser and operating system used, complete IP address of the requesting computer, transferred amount of data. Your consent (Article 6 para. 1 lit. a) GDPR).

How we share Personal Data

We may share your customer information with Alyne’s affiliates, Alyne partners (consulting, reseller and referral partners) and trusted service providers that need access to your information to provide operational or other support services for the Alyne Service. To ensure the confidentiality and security of your information, any such third party must agree to safeguard your information in strict compliance with our policies. We transfer your personal data to third parties in the following cases:

  • If required for investigating the illegal use of the Alyne Service or for legal proceedings, personal data will be transferred to the criminal investigation authorities and, if appropriate, to injured third parties. We will only do this if there are concrete indications of illegal and/or abusive behaviour. We can only transfer on your personal data if this is used to enforce the Alyne Terms and Conditions or other agreements with Alyne’s customers. We are also legally obliged to give certain public authorities information. These are criminal investigation authorities, public authorities which prosecute administrative offences entailing fines and the German finance authorities.
  • Occasionally we depend on contractually affiliated external companies and external service providers (in the role of Data Processors) to supply services such as the supply of advertising measures (only if you have given your explicit prior consent), processing payments (PayPal, credit card etc.), storing your data and customer service. In such cases, information is transferred to these companies or individuals in order to enable them to process this information further. We carefully select these external service providers and review them regularly to ensure that your privacy is preserved. The service providers may only use the data for the purposes stipulated by us. We also contractually require the service providers (using a Data Processing Agreement) to treat your data solely in accordance with this Privacy Notice and the German data protection laws.
  • In order to further develop our business, we may alter the corporate structure of Alyne by changing its legal form. We may also form, sell or buy subsidiaries, divisions or parts of the company. In such transactions, customer information together with the part of the company to be transferred will be passed on. Every time personal data is transferred to third parties to the extent prescribed, Alyne will ensure that this is done in accordance with this Privacy Notice and the relevant data protection laws.

International Transfers

We share information with our affiliates and certain service providers (such as Google Inc.) outside the European Union /European Economic Area (e.g. our affiliate in the US and Australia) that may be deemed as an international transfer under Art. 44 et. seqq. GDPR or other applicable data protection or privacy laws. Where we transfer personal data outside the European Union /European Economic Area, and where this is to a recipient in a country that is not subject to an adequacy decision by the EU Commission (Art. 45 GDPR), Alyne and its trusted service providers protect your personal data by EU Commission approved standard contractual clauses (Art. 46 para. 2 GDPR) or a trusted service provider’s binding corporate rules (Art. 47 GDPR) and additional necessary supplementary measures. A copy of the relevant transfer mechanism can be provided for your review on request to [email protected].

Newsletter

Alyne provides a newsletter service free of charge subject to your prior consent. We use the newsletter to inform you about new products and send you general information about Alyne. We need your email address in order to send you the newsletter. You can enter your email address on Alyne’s start page, which is available at http://www.alyne.com. We will store and use your email address solely to send you the newsletter.

Of course you can unsubscribe the newsletter at any time. Every newsletter contains the information on how you can unsubscribe the newsletter with effect for the future.

Cookies

A cookie is a very small text document, which often includes an anonymous unique identifier. Cookies are created when your browser loads a particular website. The Website sends information to the browser which then creates a text file. Every time the user goes back to the same website, the browser retrieves and sends this file to the website’s server. Find out more about the use of cookies on https://www.allaboutcookies.org.

We also use other forms of technology (such as web beacons and, in apps, software development kits (usually referred to as SDKs)) which serve a similar purpose to cookies and which allow us to monitor and improve our Website, the Alyne Service and email communications.

What cookies do we use and what information do they collect?

  • Required cookies: these cookies are required to enable core functionality. Without these cookies, certain services you have asked for cannot be provided. If you disable these cookies certain parts of the Alyne Service will not function for you.
  • Analytics cookies: these cookies help us improve or optimise the experience we provide. They allow us to measure how visitors interact with the Alyne Service and we use this information to improve the user experience and performance of the Alyne Service.
    These cookies are used to collect technical information such as the last visit of the Website or use of the Alyne Service, the number of pages visited, whether or not email communications are opened, which parts of our website or email communication are clicked on and the length of time between clicks.
  • Functional cookies: We may use cookies that are not essential but enable various helpful features on our websites.
    For example, these cookies collect information about your interaction with services provided on the Alyne Service, and may be used on the Alyne Service to remember your preferences (such as your language preference), your interests and the presentation of the website (such as the font size). We will ask for your consent to use these cookies when you request the relevant service.
  • Advertising cookies: we use these cookies to collect information about your browsing habits in order to make advertising more relevant to you and your interests. They are also used to limit the number of times you see an advert as well as help measure the effectiveness of an advertising campaign. We may share this information with other parties who help manage online advertising – please see the “Third Party Tools” section below for more details.
  • Social media cookies: These cookies are used when you share information using a social media sharing button or “like” button on our Website, or when you engage with the Alyne Service through a social site such as Facebook or Twitter. These cookies collect information about your social media interaction with the Alyne Service, such as whether or not you have an account with the social media site and whether you are logged into it when you interact with content on the Alyne Service. This information may be linked to targeting/advertising activities.

Third Party Tools

Your use of the Alyne Service may result in some cookies being stored that are not controlled by us. This may occur when the part of the Website or Alyne Service you are visiting or using makes use of a third party analytics or marketing automation/management tool or includes content displayed from a third party website, for example, YouTube or Facebook.

We use third party tools such as Google Analytics in compliance with applicable data protection laws and ask for your consent where necessary. You should review the privacy and cookie policies of these services to find out how these third parties use cookies and whether your cookie data will be transferred to a third country. A list of the third parties who place cookies on the Website or the Alyne Service can be found here.

Purpose Third party
Analytics Google Inc
Advertising Google Inc
Social Media Facebook, Twitter, LinkedIn, YouTube

We keep information collected from cookies for a maximum of 13 months.

Google Analytics Website Analytics

This website uses Google Analytics, a web analytics service provided by Google, Inc. (“Google”). Google Analytics uses cookies to help the website analyse how users use the site. The information generated by the cookie about your use of the website will be transmitted to and stored by Google on servers in the United States.

In case IP-anonymisation is activated on this website, your IP address will be truncated within the area of Member States of the European Union or other parties to the Agreement on the European Economic Area. Only in exceptional cases the whole IP address will be first transferred to a Google server in the USA and truncated there. The IP-anonymisation is active on this website.

Google will use this information on behalf of the operator of this website for the purpose of evaluating your use of the website, compiling reports on website activity for website operators and providing them other services relating to website activity and internet usage.

The IP-address, that your Browser conveys within the scope of Google Analytics, will not be associated with any other data held by Google. You may refuse the use of cookies by selecting the appropriate settings on your browser, however please note that if you do this you may not be able to use the full functionality of this website. You can also opt-out from being tracked by Google Analytics with effect for the future by downloading and installing Google Analytics Opt-out Browser Addon for your current web browser: http://tools.google.com/dlpage/gaoptout?hl=en.

As an alternative to the browser Addon or within browsers on mobile devices, you can click this link in order to opt-out from being tracked by Google Analytics within this website in the future (the opt-out applies only for the browser in which you set it and within this domain). An opt-out cookie will be stored on your device, which means that you’ll have to click this link again, if you delete your cookies.

Google Tag Manager

This website uses Google Tag Manager. Google Tag Manager is a solution that allows marketed website tags to be managed using an interface. The Tag Manager tool itself (which implements the tags) is a cookie-less domain and does not register personal data. The tool causes other tags to be activated which may, for their part, register data under certain circumstances. Google Tag Manager does not access this information. If recording has been deactivated on domain or cookie level, this setting will remain in place for all tracking tags implemented with Google Tag Manager.

More information on the Google Tag Manager is available here:

http://www.google.de/tagmanager/faq.html

http://www.google.de/tagmanager/use-policy.html

Deleting Your Data

We delete your personal data which we process based on your consent if you withdraw your consent, or when you request us to remove your personal data in accordance with this Privacy Notice. We will retain your personal data when we have a legitimate interest to do so. For example, we may retain your personal data to resolve disputes, enforce our Alyne Terms and Conditions or other customer agreements, or comply with legal requirements, including (tax) retention obligations; in that event, your personal data will be blocked from use for any other purpose. In any case, Alyne will not retain your personal data longer than necessary for the purposes set out in this Privacy Notice.

Your Rights as a Data Subject

You have the right to receive information about the data held and stored by Alyne about you (Art. 15 GDPR). Equally, you have the right to have incorrect data corrected or blocked (Art. 16 GDPR), to erasure (Art. 17 GDPR), restriction of processing under certain circumstances (Art. 18 GDPR), as well as the right to data portability (Art. 20 GDPR). You may object to the processing of your personal data under certain circumstances (in particular if we use the data for direct marketing (Art. 21 GDPR). You can withdraw your consent at any time with effect for the future if we use your personal data with your consent.

To have this done, or to complain about a breach of applicable data protection or privacy laws please contact: [email protected] or by post to the address given above. We may need to verify your identity in order to fulfil your request. When addressing us, please always provide your name, address and/or email address as well as information about your request. We will deal with any complaints within a reasonable amount of time. You also have the right to complain to the competent data protection authority.

DPO Appointment and Lead Supervisory Authority

Responsible lead supervisory authority:

Data Protection Authority of Bavaria for the Private Sector (BayLDA)

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 27
91522 Ansbach
Germany

https://www.lda.bayern.de/en/

Alyne’s DPO can be reached at [email protected]

If you are subject to Australian privacy laws and you are not happy with how we have dealt with your complaint, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC). Information on lodging a complaint can be found at the OAIC website at https://oaic.gov.au.

Amendments to this Privacy Notice

We reserve the right to amend this Privacy Notice. You can access the current version of the Privacy Notice at any here: https://www.alyne.com/en/data-privacy/. If we make any material changes in the way we process your personal data, we will notify you by sending you an email to the last email address you provided to us and/or by posting a notice of the changes on our Website.

4. Proprietary rights

4.1 You shall own all right, title and interest in and to Your Data, in the form submitted to the Alyne Service. You shall be the sole controller and responsible for maintaining the accuracy of Your Data. Before terminating these Terms, you are responsible for extracting Your Data, if required.

4.2 Subject to these Terms, and solely to the extent necessary to provide the Alyne Service to you, you grant Alyne a worldwide, limited term licence to access, use, process, copy, transmit, distribute, perform, export, and display Your Data. Solely to the extent that reformatting Your Data for display in the Alyne Service constitutes a modification or derivative work or a modification to a database contained or represented in Your Data, the foregoing licence also includes the right to make such modifications and derivative works and/or create modified databases. We may also access your accounts, End User accounts, and your instance of the Alyne Service with End User permission in order to respond to your support requests.

4.3 You grant Alyne a worldwide, perpetual, irrevocable, royalty-free licence to use and incorporate any suggestion, enhancement request, recommendation, correction or other feedback provided by you or your End Users into the Alyne Service.

4.4 Alyne shall own and retain all right, title and interest in and to: (a) the Alyne Service and all improvements, enhancements or modifications thereto; (b) any software, applications, inventions or other technology developed in connection with Professional Services or support; and (c) all intellectual property rights related to any of the foregoing. No rights or licences are granted except as expressly set out in these Terms. Nothing in these Terms shall operate to assign or transfer any intellectual property rights from Alyne to you.

4.5 All of the Alyne Service and related documentation is copyrighted by Alyne. Unauthorised copying, distribution, modification, public display, communication to the public or public performance of copyrighted works is an infringement of Alyne’s copyrights.

4.6 Selecting a value for a variable in an Alyne Control Statement, adding a custom value to an Alyne Control Statement, creating a Custom Control Set or Funnel or Assessment or generating an Alyne Report does not affect Alyne’s intellectual property rights or provide you usage rights beyond the Subscription Term.

5. Payment of Fees

5.1 You shall pay Alyne the fees described in the Order for the Alyne Service and Professional Services in accordance with the terms stated on the Order (the “Fees”). If your use of the Alyne Service exceeds the User Quota set out on the Order or otherwise requires the payment of additional fees (per these Terms), you shall be billed for such usage and you agree to pay the additional fees at our then current rates.

5.2 Alyne reserves the right to change the Fees or applicable charges and to institute Fees and charges at the end of the Initial Term or then current renewal term, upon 30 days’ prior notice to you (which may be sent by email); in case you do not raise an objection to that increase, the change in Fees shall be deemed as accepted; in all other case, you shall have the right to terminate the Alyne Service under these Terms with 15 days’ notice prior to the applicable Initial Term. If you believe that Alyne has billed you incorrectly, you must contact Alyne no later than 60 days after the closing date on the first billing statement in which the error or problem appeared, in order to receive an adjustment or credit. Inquiries should be directed to [email protected].

5.3 Alyne or one of its Affiliates at Alyne’s instruction may choose to bill through an invoice, in which case, full payment for invoices issued in any given month must be received by Alyne no later than 30 days after the mailing date of the invoice. Unpaid amounts are subject to a finance charge of 9 percentage points per year above the basic interest rate published by the German Federal Bank (Section 288, 247 BGB) on any outstanding balance, plus all expenses of collection. Failure to pay may result in immediate termination of Alyne Service.

5.4 Your Fees under these Terms exclude any taxes or duties payable in respect of the Alyne Service in the jurisdiction where the payment is either made or received. To the extent that any such taxes or duties are payable by Alyne, you must pay to Alyne the amount of such taxes or duties in addition to any fees owed under these Terms. Notwithstanding the foregoing, if you have obtained an exemption from relevant taxes or duties as of the time such taxes or duties are levied or assessed, you may provide Alyne with such exemption information, and Alyne shall use reasonable efforts to provide you with invoicing documents designed to enable you to obtain a refund or credit from the relevant revenue authority, if such a refund or credit is available.

5.5 Purchased subscriptions and paid Fees are not refundable; provided, however, that your warranty rights under clause 7 (Warranty and disclaimer) and the Non-excludable Australian Conditions shall remain unaffected. Without affecting your termination rights under clauses 6.2 and 6.5 and subject to the Non-excludable Australian Conditions, partial refunds of usage costs for the current term are also not refundable upon termination.

5.6 If you make any purchases through an authorised partner or reseller of Alyne (“Reseller”):

  1. instead of paying Alyne, you shall pay the applicable amounts to the Reseller, as agreed between you and the Reseller;
  2. your order details (for example, the User Quota, the Initial Term, etc.) shall be as stated in the order placed with Alyne by the Reseller on your behalf, and the Reseller is responsible for the accuracy of any such Order as communicated to Alyne;
  3. if you are entitled to a refund under these Terms, then unless Alyne otherwise specifies and subject to Non-excludable Australian Conditions, it shall refund any applicable fees to the Reseller and the Reseller shall be solely responsible for refunding the appropriate amounts to you; and
  4. Resellers are not authorised to modify these Terms or make any promises or commitments on Alyne’s behalf, and Alyne is not bound by any obligations to you other than as set forth in these Terms.

6. Term and termination

6.1 Subject to earlier termination as provided below, these Terms are for the Initial Term as specified in the Order, and shall be automatically renewed for additional periods of the same duration as the Initial Term (collectively, the “Subscription Term”), unless either party requests termination at least 30 days prior to the end of the then-current term. For the avoidance of doubt, if you terminate before the end of the Subscription Term, subject to the Non-excludable Australian Conditions, you shall not be entitled to any refund of any prepaid amounts.

6.2 Either party may also terminate these Terms upon 30 days’ notice (or without notice in the case of non-payment), if the other party fails to remedy a material breach of any of the terms or conditions of these Terms within 30 days after notice. You shall pay in full for the Alyne Service up to and including the last day on which the Alyne Service is provided, except where you terminate these Terms due to a culpable breach of these Terms by Alyne and subject to the Non-excludable Australian Conditions.

6.3 Upon any termination, you must cease use of the Alyne Service and delete (or at our request, return) all confidential Information and intellectual property of Alyne in your possession.

6.4 Upon any termination, Alyne will make Your Data available to you for electronic retrieval for a period of 30 days (in a common file format as reasonably required), but thereafter Alyne will delete Your Data according to its obligations by law; provided that Alyne’s statutory obligations of data retention shall remain unaffected.

6.5 If you terminate these Terms in accordance with clause 6.2, we will refund you any prepaid Fees covering the remainder of the then current term after the effective date of termination. If we terminate these Terms in accordance with clause 6.2, you shall pay any unpaid Fees covering the remainder of the then-current term after the effective date of termination. In no event shall termination relieve you of your obligation to pay any fees payable to us for the period prior to the effective date of termination, subject to the Non-excludable Australian Conditions.

6.6 Except where an exclusive remedy may be specified in these Terms, the exercise by either party of any remedy, including termination, shall be without prejudice to any other remedies it may have under these Terms, by law or otherwise.

6.7 All clauses of these Terms which by their nature should survive termination shall survive termination or expiration of these Terms, including, without limitation, accrued rights to payment, confidentiality obligations, warranty disclaimers, indemnities and limitations of liability.

6.8 In addition to any other remedies it may have, Alyne reserves the right to suspend your access to the Alyne Service, without prior notice, if: (a) any amount you owe to Alyne is more than 30 days overdue; or (b) if Alyne believes you or your End Users have violated any of these Terms.

7. Warranty and disclaimer

7.1 Alyne will use commercially reasonable efforts consistent with prevailing industry standards to maintain the Alyne Service in a manner which minimises errors and interruptions in the Alyne Service and will perform the Professional Services in a manner which enables you to use the Alyne Service in accordance with these Terms. The Alyne Service may be temporarily unavailable for scheduled maintenance or for unscheduled emergency maintenance, either by Alyne or by third-party providers, or because of other causes beyond Alyne’s reasonable control, but Alyne will use commercially reasonable efforts to provide advance notice by email of any scheduled service disruption. The Alyne Service may also be temporarily unavailable due to circumstances beyond our control, including, but not limited to, natural disasters, acts of governments, civil unrest, acts of terror, strike, cyber security incidents or service provider failures.

7.2 Alyne will provide basic support to you at no additional cost. Support requests may be raised by emailing [email protected] and Alyne will take commercially reasonable efforts to respond within 2 business days. Alyne reserves the right to define additional commercial arrangements for the resolution of complex support requests.

7.3 Subject to the Non-excludable Australian Conditions, your statutory rights in respect of defects in the Alyne Service are limited as follows:

  1. Alyne does not assume any liability for initial material defects in the Alyne Service;
  2. You are entitled to terminate the Alyne Service if Alyne has not successfully remedied a defect, despite that you have notified and set consecutively to Alyne two reasonable periods to remedy the defect;
  3. Your right to reduction of Fees is excluded. This does not affect your right of reimbursement of overpayment of Fees; and
  4. Your right to claim damages resulting from defects is limited as per clause 8 (Limitation of liability).

7.4 Subject to Non-excludable Australian Conditions, your rights against Alyne for defects shall expire 12 months after the beginning of the statutory warranty period. For clarification: the parties agree that updates or upgrades that Alyne provides for the Alyne Service during the Subscription Term shall not extend the warranty period.

7.5 The parties agree that any guarantee within the meaning of Sections 443, 444 German Civil Code shall require an express written commitment on the part of Alyne, in which the terms “guarantee” or “guaranteed” are used.

7.6 The Alyne Service (including Control Statements, Control Sets, Reports, Insights, Assessments and Funnels) are advisory in nature and do not constitute assurance, legal advice or audit results. Consequently, no opinions or conclusions intended to convey assurance are expressed through the Alyne Service. Due to the nature of the Alyne Assessment approach, it is possible that errors, unidentified risks or other irregularities may occur and remain undetected. Alyne cannot guarantee completeness of its content libraries or your usage of the Alyne Service. Relying solely on the results produced through the Alyne Service does not alleviate your Management’s responsibility to implement and maintain adequate controls over your entire operation, or to detect and prevent fraud and other violations of regulatory or legal responsibilities.

8. Limitation of liability

8.1 Subject to the provisions in clause 8.2, Alyne’s statutory liability for damages shall be limited as follows:

  1. Alyne shall be liable only up to the amount of damages as typically foreseeable at the time of entering into the contract in respect of damages caused by a slightly negligent breach of a material contractual obligation (i.e. a contractual duty the fulfilment of which is essential for the proper execution of the contract, the breach of which endangers the purpose of the contract and on the fulfilment of which a customer regularly relies); and
  2. Alyne shall not be liable for damages caused by a slightly negligent breach of a non-material contractual obligation.

8.2 The aforesaid limitation of liability shall not apply to any mandatory statutory liability (in particular to liability under the German Product Liability Act), liability for assuming a specific guarantee or liability for damages caused by wilful misconduct or gross negligence, or any kind of wilfully or negligently caused personal injuries, or liability pursuant to the Non-excludable Australian Conditions.

8.3 You shall take all reasonable measures to mitigate and/or to avoid damages, including, in particular, an obligation for you to make back-up copies of data on a regular basis and to carry out security checks (in particular for the purpose of defending or detecting viruses, malware and other disruptive programmes within your own IT System).

8.4 Regardless of the legal grounds giving rise to liability, subject to Non-excludable Australian Conditions, Alyne shall not be liable for indirect and/or consequential damages, including, in particular, loss of profit and loss of interest, unless any such damage has been caused by Alyne’s wilful misconduct or gross negligence.

8.5 Unless otherwise specified in an Order and other than in case of wilful misconduct or gross negligence and subject to the Non-excludable Australian Conditions, Alyne’s liability shall be capped to a sum equivalent of 100% of the Fees paid or payable under the Agreement per year regardless of the number of incidents.

8.6 To the extent Alyne’s liability is limited or excluded, the same shall apply in respect of any personal liability of Alyne’s legal representatives, employees and vicarious agents.

9. Indemnity

9.1 You agree to indemnify and hold harmless Alyne (and its Affiliates, officers and representatives) from and against any claims, costs, damages, losses, liabilities and expenses (including attorneys’ fees under the applicable statutory fee schemes) resulting from any claim culpably caused by you, finally awarded against Alyne by a court of competent jurisdiction once all appeal rights are exhausted or agreed to in a written settlement agreement signed by you arising out any claim or allegation by any third party and arising from or related to: (a) any claims or disputes brought by your End Users arising out of their use of the Alyne Service; (b) your culpable breach of clause 2 (Customer restrictions and responsibilities; audit right); or (c) Your Materials.

9.2 Alyne will defend and indemnify you against any and all costs, damages, and expenses (including attorneys’ fees under the applicable statutory fee schemes) finally awarded against you by a court of competent jurisdiction once all appeal rights are exhausted or agreed to in a written settlement agreement signed by Alyne arising out of any claim or allegation by a third party that the Alyne Service infringes, misappropriates or violates any intellectual property rights of any third party. In the event that the Alyne Service is held to infringe a third party’s intellectual property rights, Alyne may, at its option and expense (a) replace or modify the Alyne Service to be non-infringing, without materially adversely affecting the Alyne Service’s specified functionalities; (b) obtain for you a licence to continue using the Alyne Service; or (c) terminate this Agreement and return to you any prepaid fees unearned by Alyne. Alyne’s liability for claims of infringement for damages under this clause 9.2 shall be subject to the limitation of liability under clause 8. Alyne shall not be obligated to defend, and indemnify you for any claims to the extent based on: (i) any of your or any third party’s intellectual property or software incorporated in or combined with the Alyne Service where in the absence of such incorporated or combined item, there would not have been infringement, but excluding any third party software or intellectual property incorporated into the Alyne Service at Alyne’s discretion; or (ii) the Alyne Service that has been altered or modified by you, by any third party or by Alyne at the request of you (where Alyne had no discretion as to the implementation of modifications to the Alyne Service or Documentation directed by you), where in the absence of such alteration or modification the Alyne Service would not be infringing.

9.3 Each party’s obligations under this clause 9 are conditioned upon (a) prompt written notification by the indemnified party of any threatened or actual claim or suit; provided that a failure of prompt notification shall not relieve the indemnifying party of liability hereunder except to the extent that defences to such claim are materially impaired by such failure of prompt notification; (b) allowing the indemnifying party to have sole control of the defence or settlement of any claim or suit, except that the indemnifying party may not, without the indemnified party’s prior written consent, enter into any settlement that does not unconditionally release the indemnified party from liability; and (c) the indemnified party providing the indemnifying party, at the indemnifying party’s request and expense, with the assistance, information and authority necessary to perform the indemnifying party’s obligations under this clause 9.

10. Privacy

10.1 You acknowledge that Alyne collects, uses, stores and otherwise processes Your Data, including your or your End Users’ personal information, utilisation data and any data created, stored or uploaded through you, and your End Users using the Alyne Service and may share such data with third party service providers for the purposes of improving or providing the Alyne Service. For more information please refer to Alyne’s Data Privacy Notice, available here.

10.2 Processed data includes your name, email address, postal address including this data from your End Users. If you have provided credit card details, our PCI-DSS compliant payment processor will store and use this data for purposes of performing authorised payment transactions.

10.3 All personal data will be treated confidentially and in compliance with the EU General Data Protection Regulation 2016/679 (“GDPR”) and other applicable legislation.

10.4 You acknowledge that Alyne may access, preserve and disclose your personal information and Your Data created, stored or uploaded to the Alyne Service if required to do so by law or to comply with a legal process.

10.5 Without prejudice to the restrictions in clause 2.3, you further agree to inform Alyne if you are using the Alyne Service to process Sensitive Personal Data.

10.6 Alyne will use domestic and international service providers to support the provision of the Alyne Service. Alyne will apply the Terms as defined in clauses 10 and 11 to the contracts with these subcontractors. A subcontractor outside of the European Economic Area will only be selected by Alyne, if an adequate level of data privacy and protection is provided.

11. Commissioned data processing

11.1 If you are operating in the European Union and intend on processing personally identifiable information (as defined in the GDPR) with the Alyne Service, the requirements from Article 28 of the GDPR apply to these Terms.

11.2 Alyne will not assume data ownership or control of Your Data and will only process this data on your behalf and upon your request.

11.3 You shall be responsible for implementing the requirements defined in the GDPR as the data controller, while Alyne shall be responsible for technical and organisational protection measures for Your Data.

11.4 If the requirements stated in clause 11.1 of these Terms are met you can request that Alyne and you agree a contractual addendum meeting the legal requirements for commissioned data processing.

12. Miscellaneous

12.1 If any provision of these Terms is found to be unenforceable or invalid, that provision shall be eliminated, but this Agreement shall otherwise remain in full force and effect and enforceable.

12.2 The claims under these Terms are not assignable or sublicensable by you except with Alyne’s prior written consent. Alyne may assign any of its claims under these Terms without consent.

12.3 These Terms is the complete and exclusive statement of the mutual understanding of the parties and supersedes and cancels all previous written and oral agreements, communications and other understandings relating to the subject matter of these Terms.

12.4 All waivers and modifications must be in writing signed by both parties including this written form clause, except as otherwise provided herein.

12.5 The Alyne Service and derivatives thereof may be subject to export laws and regulations of the United States and other jurisdictions. Alyne and you each represent that it is not named on any U.S. government denied-party list. You shall not permit any End User to access or use the Alyne Service in a U.S.-embargoed country or region or in violation of any U.S. export law or regulation.

12.6 No joint venture, or employment is created as a result of these Terms and you do not have any authority of any kind to bind Alyne in any respect whatsoever.

12.7 All notices under these Terms shall be in writing. There are no third-party beneficiaries under these Terms.

12.8 We may identify you as an Alyne customer in our promotional materials and on our website, without disclosing any further detail of your usage of the Alyne Service or any other commercial arrangements. We will promptly stop doing so upon your request sent to [email protected].

13. Alyne contracting entity; governing law

13.1 The Alyne entity entering into these Terms, the law that shall apply in any dispute or lawsuit arising out of or in connection with these Terms, and the courts that have jurisdiction over any such dispute or lawsuit, shall depend on where you are domiciled. The terms of the United Nations Convention on Contracts for the Sale of Goods do not apply to these Terms. The Uniform Computer Information Transactions Act (UCITA) shall not apply to these Terms regardless of when or where adopted. Each party agrees to the applicable governing law below without regard to choice or conflicts of law rules, and to the exclusive jurisdiction of the applicable courts below.

13.2 If you are domiciled in Australia the Alyne entity entering into these Terms is Alyne Australia Pty Ltd (an Australian corporation), the governing law is the laws of the State ofVictoria, Australia, and the courts of Victoria, Australia shall have exclusive jurisdiction.

13.3 If you are domiciled outside of Australia, the Alyne entity entering into these Terms is Alyne GmbH (a German corporation), the governing law is the laws of Germany, and the courts ofMunich, Germany shall have exclusive jurisdiction.

14. Definitions

Certain capitalised terms used in the Terms are defined in this clause 14, and others are defined contextually in these Terms.

“Affiliate” means an entity which, directly or indirectly, owns or controls, is owned or is controlled by or is under common ownership or control with a party, where “control” means the power to direct the management or affairs of an entity, and “ownership” means the beneficial ownership of greater than 50% of the voting equity securities or other equivalent voting interests of the entity.

“Alyne Policies” means Alyne’s standard published policies, as updated from time to time.

“Alyne Service” means the Alyne Software as a Service, including Alyne’s content libraries (specifically the Alyne Control Statement Library and the Alyne Risk Library), reference material, glossary, and help text purchased by you and made available online by Alyne.

“End User” means an individual you or an Affiliate permitted or invited to use the Alyne Service. For the avoidance of doubt: (a) individuals invited by your End Users, (b) individuals under managed accounts, (c) individuals interacting with the Alyne Service as your customer, (d) Admin & Expert Users, Expert Users and Business Users (as specified in your instance of the Alyne Service), and (e) individuals who respond to an Assessment in your instance of the Alyne Service, are also considered End Users.

“HIPAA” means the Health Insurance Portability and Accountability Act, as amended and supplemented.

“Initial Term” means your initial permitted subscription period for the Alyne Service, as set out in the applicable Order.

“Laws” means all applicable local, state, federal and international laws, regulations and conventions, including those related to data privacy and data transfer, international communications and the exportation of technical or personal data.

“Non-excludable Australian Conditions” means any statutory or implied condition, warranty or guarantee under Australian law including applicable Australian Consumer Law as set out the Australian Specific Terms, the exclusion of which from a contract would contravene any statute or cause any part of these Terms to be void.

“Order” means Alyne’s approved ordering document or process describing the Alyne Service you are ordering from Alyne, including the agreed: (a) User Quota; (b) Initial Term; (c) Professional Services (if any); and (d) Fees.

“PCI DSS” means the Payment Card Industry Data Security Standards.

“Professional Services” means any professional services related to Customer’s use of the Alyne Service, such as consulting, implementation, or training services, provided by Alyne to Customer as expressly identified in the Order, which – if subject to German law – are of a service contractual nature within the meaning of Sections 611 et. seq. German Civil Code and shall in no case be interpreted in such a way that Alyne owes a certain outcome to the customer when performing the Professional Services, unless the parties have expressly specified in writing that Ayne shall provide an implementation service under a works contract (“Werkvertrag”) within the meaning of Sections 631 et. seq. German Civil Code.

“Sensitive Personal Data” means any: (a) categories of data enumerated in European Union Regulation 2016/679, Article 9(1) or any successor legislation; (b) patient, medical or other protected health information regulated by HIPAA; (c) credit, debit or other payment card data subject to PCI DSS; (d) other information subject to regulation or protection under specific laws such as the Gramm-Leach-Bliley Act (or related rules or regulations); (e) social security numbers, driver’s licence numbers or other government ID numbers; or (f) any data similar to the foregoing that is protected under foreign or domestic laws or regulations.

“Subscription Term” has the meaning given in clause 6.1.

“User Quota” means the User Quota specified in the Order.

“Your Data” means any data, content, code, video, images or other materials of any type that you (including any of your End Users) submit to the Alyne Service, including personal information of you or your End Users, comments, object descriptions, file attachments, and fully custom created control statements or risks. In this context, “submit” (and any similar term) includes submitting, uploading, transmitting or otherwise making available Your Data to or through the Alyne Service.

“Your Materials” means your materials, systems, personnel or other resources.

Addendum

Australian Specific Terms

Each party agrees that the following Australian Specific Terms shall apply in addition to the Terms above if the laws of Australia are applicable due to clause 13.2 and provided that Australian Consumer Law is applicable to the Customer.

If there is a conflict between the Terms above and these Australian Specific Terms, these Australian Specific Terms shall prevail.

1. Definitions

Capitalised terms have the meaning given in the Terms above unless otherwise defined below:

“ACL” or “Australian Consumer Law” means the Australian Consumer Law set out at Schedule 2 to the Competition and Consumer Act 2010 (Cth).

“Non-excludable Australian Conditions” shall have the meaning set forth in clause 14 of the Terms.

“Sensitive Personal Data” includes, without limiting the definition set out in the Terms above, sensitive information as defined in the Privacy Act 1998 (Cth) and health information, or any similar term, as defined in any applicable Australian Federal, State or Territory legislation relating to the handling of health records or health information.

2. Consumer Laws

2.1 If Alyne is liable for a failure to comply with a Non-excludable Australian Condition, including in respect of the guarantees described in paragraphs 2.5 and 2.6 below, where it would be permitted by law, Alyne limits its liability (at its absolute discretion and option) to:

  1. in the case of goods, either the repair or replacement of the goods, or the supply of equivalent goods or payment of the cost of having the goods repaired or replaced or of acquiring equivalent goods; and
  2. in the case of services, the supply of the services again or payment of the cost of supplying the services again.

2.2 Any warranty against defects (as defined in the ACL) set out in the Terms above are provided by the following Alyne entity:

Alyne Australia Pty Ltd
Level 1 Front Suite, 19 to 21 Toorak Rd
South Yarra VIC, Australia 3141
+49 89 4581 9940
[email protected]

2.3 Claims under a warranty against defects set out in the Terms above must be made by written notice to Alyne Australia Pty Ltd using the address above, setting out the nature of the defect. You are responsible for the costs of claiming under a warranty against defects.

2.4 The benefits of any warranties against defects provided in the Terms above are in addition to your other rights and remedies under a law in relation to the goods and services to which the warranty relates.

2.5 If you are obtaining our goods or services as a consumer under the Australian Consumer Law, our goods and services come with guarantees that cannot be excluded under the Australian Consumer Law. For major failures with the Alyne Service, you are entitled to cancel your service contract with us and to a refund for the unused portion, or to compensation for its reduced value.

2.6 You are also entitled to choose a refund or replacement for major failures with goods. If a failure with the goods or a service does not amount to a major failure, you are entitled to have the failure rectified in a reasonable time. If this is not done you are entitled to a refund for the goods and to cancel the contract for the service and obtain a refund of any unused portion. You are also entitled to be compensated for any other reasonably foreseeable loss or damage from a failure in the goods or service.

3. Privacy

For the purpose of clause 10.3 in the Terms above, other applicable legislation includes, without limitation, the Privacy Act 1998 (Cth).